Privacy Policy
Last updated: 1 June, 2025
Introduction
Grow Insight is committed to protecting your privacy and ensuring the security of operational data collected from your practice. This Privacy Policy details how Grow Insight handles data collected through your use of our analytics and reporting platform.
Information Collection
Grow Insight collects operational data provided by your practice through manual uploads by authorised users. Practices export operational data from their Practice Management System (e.g., Zanda) and manually upload these data files to Grow Insight.
The operational data collected includes:
- Appointments:
- Appointment ID (as assigned by your practice management system)
- Date and time
- Practitioner name
- Client ID (non-identifiable numeric code unique only within your account context)
- Appointment length, type, location, and status
- Payments and Invoices:
- Invoice/payment IDs (linked to specific appointments)
- Payment amounts
- Payment and invoice statuses
Grow Insight explicitly does not retain personally identifiable information (PII) such as client names, addresses, phone numbers, emails, or other sensitive details. Any PII included in uploaded files is automatically discarded during Grow Insight’s data processing.
Use of Information
Grow Insight uses operational data exclusively for:
- Reporting: Comprehensive reports on appointments, practitioner utilisation, and revenue performance.
- Analytics and Benchmarking: Analysing performance metrics and identifying areas for improvement.
- Forecasting: Predicting future appointment volumes, revenue, and resource utilisation.
- Deriving Meaningful Business Insights: Identifying trends and opportunities to support strategic decisions.
- Identifying Trends: Monitoring trends related to operations, revenue, client retention, and practitioner performance.
Grow Insight does not use operational data for marketing or advertising, nor sell or disclose data to third parties for such purposes.
Information Sharing
Grow Insight does not share, sell, or otherwise disclose operational data for external marketing, advertising, or commercial purposes.
Grow Insight employs third-party analytics services (Clarify, Pendo and Google Analytics) solely for internal use, collecting superficial, non-sensitive information, including:
- Page names visited
- User IDs
- Account names
- Interactions with page elements (clicks)
Access to these tools is securely controlled, requiring authentication and authorisation, and is used exclusively for platform improvement.
Operational data is typically aggregated either during data ingestion or dynamically for reporting purposes. Aggregated data does not include personally identifiable information.
Data Storage and Security
Geographic Location
Operational data uploaded by your practice is securely stored on servers provided by Amazon Web Services (AWS) located in the Sydney region, Australia.
Data Retention
Uploaded data files are temporarily stored in AWS S3 and automatically deleted after 30 days. Processed operational data, excluding PII, is securely stored only for as long as necessary to provide services or until account termination.
Security Measures
Grow Insight ensures data security through:
- Encryption: Data is encrypted at rest in AWS-managed storage and databases.
- Secure Data Transmission: All platform communications use HTTPS connections secured by API key authentication.
- Principle of Least Privilege: Access to data is strictly limited to necessary services.
- Access Controls: AWS S3 buckets are exclusively accessible by Grow Insight’s dedicated ingest service.
- User Authentication and Authorisation: Platform access requires username/password authentication and role-based authorisation.
Data Subject Rights
You have the right to request deletion of your data. Requests for data deletion or withdrawal of consent must be submitted in writing to admin@growinsight.io. Grow Insight will promptly process and confirm completion of your request. Aggregated or anonymised data without PII may be retained for internal analytics.
Compliance with Laws
Grow Insight complies with applicable Australian privacy laws and regulations, including the Australian Privacy Act. Should a data breach occur, Grow Insight follows strict notification procedures to inform affected parties promptly.
Changes to this Privacy Policy
Grow Insight reserves the right to update this Privacy Policy. Any changes will be communicated by posting the revised Privacy Policy on the Grow Insight website. Those changes will go into effect on the effective date disclosed in the revised Privacy Policy.
Contact Information
If you have privacy-related questions or requests, please contact us at privacy@growinsight.io