Your health information, handled with the same care as a clinic visit.
Doccy is built by doctors and engineers who treat your privacy as part of clinical care. Your records are encrypted, access is limited to people involved in your care, and we do not sell your health information.
Compliance & standards
The regulation and clinical governance that apply to your care today, as an Australian telehealth provider.
Australian Privacy Act 1988
Applies todayAs an Australian telehealth provider we operate under the Privacy Act and the Australian Privacy Principles (APPs) governing how health information is handled.
AHPRA clinical governance
Applies todayAll consults are delivered by doctors registered with the Australian Health Practitioner Regulation Agency, under the same credentialing standards used across the Medlo network.
Security FAQ
Is my health data safe with Doccy?
Yes. As an Australian telehealth provider, Doccy operates under the Privacy Act 1988 and the Australian Privacy Principles (APPs).
For you, that means:
- Your information is encrypted when sent and when stored
- Only authorised clinicians and support staff involved in your care can access your records — not other patients, and not advertisers
- We collect only what we need to provide safe care
- We do not sell your health data to third parties
Your information should feel as confidential here as it would at a traditional clinic.
How does Doccy handle my payment details?
Card payments are processed by Stripe, which meets PCI DSS Level 1 — the highest standard for payment security.
Your full card number goes directly to Stripe and is never seen or stored by Doccy.
Who can see my medical records?
Your medical records are tied to your account — another patient cannot view your information.
Access is limited to the doctors and authorised staff delivering your care, and we maintain records of who accesses patient information.
Is Doccy SOC 2 or ISO 27001 certified?
We are actively pursuing SOC 2 Type II and aligning our information security practices to ISO 27001, supported by continuous compliance monitoring.
Today we already operate under Australian healthcare regulation — the Privacy Act 1988 and AHPRA clinical governance — and follow SOC 2-aligned controls across our stack.
How do I report a security vulnerability?
Please contact our team by email with clear steps to reproduce and the potential impact.
Please don't access, modify, or delete other users' data while researching, and give us reasonable time to remediate before any public disclosure. We acknowledge reports promptly and keep you updated throughout.
Does Doccy sell or share my data with advertisers?
No. We do not sell your health data, and we do not share it with advertisers.
We use a small number of trusted service providers to run Doccy — for example, payment processing and email — only for what's needed to deliver the service, and under strict privacy terms.
Working towards
We are actively investing in the leading international security frameworks, building the controls and evidence each one requires. Certification is in progress and not yet complete, and alongside this work your care is already protected by the Australian regulation and clinical governance above.
SOC 2 Type II
Not certified yetWe are working toward SOC 2 Type II — an independent audit of how we protect data. This is in progress; we are not certified yet.
ISO/IEC 27001
Not certified yetWe are aligning our security practices with the ISO 27001 framework. This is in progress; we are not certified yet.
Responsible disclosure
Security researchers keep everyone safer. If you believe you've found a vulnerability, please report it privately so we can investigate and fix it before any details are made public. We commit to acknowledging reports promptly and keeping you updated.
- Share clear steps to reproduce and the potential impact.
- Do not access, modify, or delete other users' data.
- Give us reasonable time to remediate before disclosing.
Explore more
The credentials, safeguards, and story behind Australia's doctor-led telehealth.
Trust & Safety
Verified credentials, regulatory registration, and clinical governance behind every consult.
View trust & safetyPrivacy Policy
How we collect, use, and protect your personal information under Australian privacy law.
View privacy policyMedia & Newsroom
Brand assets, press coverage, and media contacts for Australia's doctor-led telehealth.
Visit newsroom