Vocara is an AI-assisted clinical documentation tool built for New Zealand allied health practitioners. Vocara is operated by Vocara Limited (NZBN 9429053850393), a company registered in New Zealand, with its registered office at 12 Ridings Road, Auckland 1050, New Zealand. Vocara Limited was founded by Lachlan Kennedy. In this policy, "Vocara", "we", "us" and "our" refer to Vocara Limited. This Privacy Policy explains how we collect, use, and protect information in connection with your use of Vocara.
For privacy enquiries, contact: lachlan@vocara.co.nz
Account information: Your name, discipline, practice name, ACC provider number, and email address when you sign up.
Patient records and clinical notes: To provide the service, Vocara stores the patient records you create (such as name, date of birth, NHI number, contact details, and ACC claim details) and the clinical notes generated and signed from your sessions. This clinical information is encrypted at the field level before it is stored (see How your data is protected in section 5 below).
Session metadata: Timestamps, session duration, ACC claim codes, and note generation activity, used to operate the service and for billing.
Usage data: Basic app usage logs (page views, feature usage) to help us improve the product. These logs contain no patient or clinical information.
The patient's name is sent to AssemblyAI. Vocara sends the patient's name to AssemblyAI as a vocabulary hint, so their name is spelled correctly in the transcript. It is sent alongside the audio for that session.
The patient's name and up to three prior signed notes are sent to Anthropic. When a note is generated, Vocara sends the session transcript, the patient's name, and up to three of that patient's prior signed notes to Anthropic (United States) so the new note follows on from their treatment so far. Nothing sent to Anthropic is used to train AI models.
Documents you produce are stored. Every clinical document Vocara produces, including session notes, rehab plans, referral letters, ACC32 requests, discharge summaries and the patient and employer copies of ACC forms, is saved to your account with its full content, so it can be found again, reissued and audited. Document content is encrypted at the field level like the rest of your clinical data.
ACC submission receipts. Every call Vocara makes to ACC on your behalf writes a receipt in your account recording what was sent, what ACC said back, and whether it succeeded. Receipts are encrypted and are deleted with your account.
Vocara is built for ACC work, and ACC work means sending information to ACC. None of the following happens on its own: each is an action you take, on a claim the patient has made.
Health New Zealand (Te Whatu Ora). Vocara can look up a patient's NHI against Health New Zealand's National Health Index service. When you use it, we send either the NHI number you are checking, or the name, date of birth and gender you are searching on, along with an identifier for the person making the request, which Health New Zealand requires. This connection is enabled only where Health New Zealand's approval is in place; where it is not enabled, the lookup returns test data and nothing leaves Vocara. Every NHI lookup is recorded in an access log that stores a one-way hash of the identifier, never the identifier itself.
Outside ACC and the National Health Index, we do not disclose your information or your patients' information to any government agency unless the law requires it.
A practice-system connection exists only if you create it, using your own practice's credentials, and you can remove it in Settings at any time.
Information sent to a practice management system is going to your own practice's system, under your own account with that provider, and is then held under that provider's terms rather than ours.
Email is sent through Resend (United States). Three of these carry clinical content, and all three are actions you take:
Service email (sign-up, password reset, account notices) carries only your email address and name.
We do not sell your information to third parties. We do not use your clinical content to train AI models.
You: You have full access to all information in your account.
Vocara operator: Vocara Limited may access account metadata when required to operate or troubleshoot the service. Patient clinical content is encrypted field by field and is not readable from the database itself; the keys that would unwrap it are held separately in AWS KMS. We do not decrypt or read your patients' clinical content as part of support.
Role clarification: You are the data controller for your patients' health information. Vocara acts as a data processor on your behalf, processing data only as directed by your use of the service and in accordance with this policy.
Sub-processors: We use the following third-party services (sub-processors) to operate Vocara:
| Service | Purpose | Data processed | Location |
|---|---|---|---|
| Anthropic (Claude API) | AI note generation | Session text transcript, patient name, up to three prior signed notes | USA |
| AssemblyAI | Real-time speech-to-text transcription | Session audio (streamed live, not stored by Vocara), patient name as a vocabulary hint | USA |
| Google Firebase | Authentication & database | Account data, session metadata | Australia / USA |
| Resend | Transactional and clinical email | Recipient email address and name. Where you send one: the full text of a referral letter, the text of a patient session summary, or a clinical note as a PDF attachment, with the patient's name in the subject line | USA |
| ACC (Accident Compensation Corporation) | Lodging ACC45 claims, uploading clinical documents, invoicing, checking claim and treatment status | Patient name, date of birth, NHI number, contact details, ACC claim number, accident, injury and diagnosis details, the document PDF itself, treatment dates, service codes and amounts | New Zealand |
| Health New Zealand / Te Whatu Ora (National Health Index) | Looking up or confirming a patient's NHI, where enabled | NHI number, or the name, date of birth and gender being searched, plus an identifier for the person making the request | New Zealand |
| Cliniko (only if you connect it) | Practice management sync and note push | Patient demographics, appointments, cases, medical alerts, intake forms and attachments read from your account; the signed note's sections written into it | Your Cliniko account's own region (Australia for NZ practices) |
| Nookal (only if you connect it) | Practice management sync and note push | Patients and cases read from your account; the signed note written into it as a treatment note | Australia |
| Gensolve (only if you connect it) | Appointment lookup. Read only: no clinical note is sent | Appointment and patient name data read from your account | New Zealand or Australia, by your Gensolve region |
| Amazon Web Services (AWS KMS) | Encryption key management | Encryption keys only, no patient or clinical content | Australia |
| Sentry | Error monitoring | Error logs (PII-scrubbed) | EU |
Offshore disclosure: Some sub-processors listed above are located outside New Zealand, and patient clinical content does leave New Zealand. It does so in these ways:
Information sent to ACC and to Health New Zealand stays in New Zealand. By using Vocara you acknowledge these transfers. Each is made on the basis of contractual commitments with the sub-processor to maintain equivalent privacy protections.
ACC, Health New Zealand and other agencies. Vocara sends information to ACC and, where enabled, to Health New Zealand's National Health Index, because that is what the tool does and because you ask it to. Section 2a sets out exactly what goes to each. Outside those two, we do not share your information or your patients' information with any government agency unless the law requires it.
Vocara stores your account data, patient records, and clinical notes in Google Firestore, hosted in Australia. All data is encrypted in transit (TLS 1.2+) and at rest.
How your data is protected. On top of standard at-rest encryption, every patient record and clinical note is additionally protected with field-level AES-256 encryption. Each record is encrypted with its own key, and that key is itself locked ("wrapped") by a master key held in Amazon Web Services Key Management Service (AWS KMS), in Australia, kept separate from the database. The master key never leaves AWS KMS. In practice this means patient names, NHI numbers, and clinical content are unreadable to anyone, including Vocara staff, without access to both systems.
We recommend exporting signed notes as PDF for your own records, in line with your professional record-keeping obligations.
Under the New Zealand Privacy Act 2020, you have the right to:
To exercise these rights, contact us at lachlan@vocara.co.nz. We will respond within 20 working days as required by law.
Vocara is a tool for practitioners - we do not hold a direct relationship with patients. Under the Health Information Privacy Code 2020, the treating practitioner is responsible for:
Patients seeking access to their clinical records should contact their treating practitioner directly, not Vocara.
You may request deletion of your account at any time by contacting lachlan@vocara.co.nz. Upon receiving your request, we will:
You can also delete your account yourself, from Settings in the app, in which case the deletion runs immediately rather than within 48 hours.
What deletion also destroys. Deleting your account destroys your ACC submission receipts, the record in Vocara of what was sent to ACC and what ACC said back. ACC holds its own record of every lodgement, and we keep a count of how many receipts were destroyed, but no content. It also destroys clinical records that a practice may be legally required to keep for ten years under the Health (Retention of Health Information) Regulations 1996. Vocara does not block a deletion you have asked for, so export what you need to keep before you delete. Our full position is in our retention policy, available on request.
Note: Vocara may keep a temporary local copy of an in-progress note in your browser for crash recovery. That local copy clears when you sign out, or you can clear it in your browser settings; it is separate from the encrypted records we delete from our servers.
Vocara uses essential cookies only - for session management and authentication. We do not use advertising cookies or third-party tracking pixels.
We use anonymised analytics to understand how practitioners use the product. These analytics contain no personally identifiable or patient information.
If you access Vocara from within the European Economic Area (EEA), the General Data Protection Regulation (GDPR) may apply to our processing of your personal data. In addition to the rights under the NZ Privacy Act 2020, you have the right to:
Our lawful basis for processing your account data is contract performance (to provide the Vocara service you signed up for). We process health-related data only as a data processor on your behalf, under your control.
To exercise any GDPR rights, contact lachlan@vocara.co.nz.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by a prominent notice in the app. The date at the top of this page reflects the most recent update.
Continued use of Vocara after changes are posted constitutes your acceptance of the updated policy.
For any privacy concerns, requests, or complaints:
Email: lachlan@vocara.co.nz
Vocara Limited · NZBN 9429053850393 · 12 Ridings Road, Auckland 1050, New Zealand
Response time: Within 20 working days (NZ Privacy Act 2020 requirement)
If you are not satisfied with our response, you may complain to the NZ Privacy Commissioner at privacy.org.nz.