Aperture Privacy Policy

Last updated: 6 September 2026

Aperture is a practice management platform for medical imaging clinics, operated by Radly. This policy explains how information is handled inside Aperture. It is separate from the privacy policy for the Radly patient marketplace at radly.com.au - if you booked a scan through a clinic's Radly page, both may apply to different parts of your booking.

The short version

  • Your imaging clinic controls your health information; Aperture stores and processes it on the clinic's behalf so the clinic can run its appointments.
  • All data is hosted in Australia (Sydney).
  • Each clinic's data is fully isolated - no clinic can ever see another clinic's patients, staff or reports.
  • We never sell personal information, and we never use health information for advertising.

1. Whose information we handle

Patients

When you book with a clinic that uses Aperture, or attend one, the clinic records information needed to provide your imaging service: name, date of birth, contact details, address, Medicare or DVA details, health fund details, emergency contact, your referral (including the referring practitioner and clinical notes), appointment history, safety screening answers, payment status and, where the clinic uses Aperture reporting, the report of your examination.

Clinic staff

Name, role, work email, mobile number (used for SMS sign-in) and an audit trail of actions taken in the system, which clinics are required to keep for accountability.

Referring practitioners

Name, practice and address details as they appear on referrals and report letters.

2. Who is responsible

Your clinic is the health service provider and decides what is collected and why. Radly operates Aperture as the clinic's service provider and handles the information only to deliver the platform - storing records, computing availability, sending appointment messages the clinic configures, and producing documents the clinic requests. For questions about your health information, or to access or correct it, contact your clinic first. We will assist the clinic with any request.

3. How information is used

  • Running the clinic's appointment book, worklists and patient records.
  • Sending appointment communications: booking confirmations, reminders, preparation instructions and reschedule notices, by SMS and email.
  • Producing referral-response report letters where the clinic uses Aperture reporting.
  • Showing the clinic's live availability on its Radly page or its own website when the clinic enables online booking. Only availability is exposed publicly - never patient information.
  • Security, audit and fault diagnosis.

We do not sell personal information. We do not use health information for marketing or advertising. Aggregated, de-identified statistics (for example, how many bookings a clinic received in a month) may be used to operate and improve the service.

4. Where information lives, and who else touches it

Aperture's database is hosted in Sydney, Australia. We use a small number of service providers to run the platform:

  • Neon (database hosting, Sydney) and Vercel (application hosting, Sydney region).
  • Twilio - sends appointment SMS to the mobile numbers involved.
  • Resend - sends appointment and notification emails.
  • Google Cloud (Firebase Storage) - stores referral files and clinic logos.

Each provider receives only what it needs to do its job (for example, Twilio receives the phone number and message text). Where a provider processes data overseas in transit, we rely on their contractual safeguards consistent with Australian Privacy Principle 8.

5. How information is protected

  • Encryption in transit (TLS) for all connections, and encryption at rest in the database.
  • Strict tenant isolation: every query is scoped to the signed-in clinic, and this is enforced in the application layer, not just the interface.
  • Role-based access: reception, radiographers, radiologists and managers each see only what their role requires.
  • SMS-verified staff sign-in, and an append-only audit log of access and changes.
  • Automatic backups, retained on a rolling cycle.

6. Retention and deletion

Clinical records are retained for as long as the clinic requires - health records law typically requires clinics to keep records for at least 7 years (longer for children). If a clinic leaves Aperture, its data is exported to the clinic on request and deleted from production systems 90 days after termination.

7. Your rights

You can request access to or correction of your information at any time. For health information, contact your clinic - they hold the relationship and the record. For anything about the platform itself, contact us at support@radly.com.au. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

8. Data breaches

We maintain a data breach response process consistent with the Notifiable Data Breaches scheme. If a breach involving your information is likely to result in serious harm, the affected clinics and individuals will be notified as the scheme requires.

9. Changes

We will post any changes to this policy here and notify clinics by email of material changes at least 14 days before they take effect.

Contact

Privacy questions: support@radly.com.au - Radly, Melbourne, Australia.