Back to policies
PRV-005 Policy

Privacy Policy - Chrome Extension

Download PDF
Version: 1
Effective: 03 Apr 2026
Category: Privacy & Information
Organisation: Clinically
Contact: hello@clinically.com.au
Phone: +61 2 4092 7710
Website: https://clinically.com.au

Overview

The Clinically Chrome Extension ("the Extension") connects the Clinically healthcare practice management platform with the Xestro EMR system. This privacy policy explains what data the Extension accesses, how it is used, and how it is protected.

Data We Access

Patient Information

The Extension reads patient demographic information from two sources:

  • Clinically (app.clinically.com.au): Patient name, date of birth, age, gender, phone numbers, email address, and EMR identifier, as provided by the Clinically application via page metadata.

  • Xestro (my.xestro.com): Patient name, date of birth, phone number, email address, Medicare number, address, and EMR identifier, as displayed in the Xestro patient details interface.

This information is used solely to match patient records between the two systems and to facilitate synchronisation of contact details. Patient data is not stored persistently by the Extension. It is held in session memory and cleared when the browser is closed.

Medicare numbers are read from Xestro for display purposes within the Xestro page only. They are not transmitted to Clinically or stored by the Extension.

Clinical Documents

When a user explicitly chooses to send a document from Xestro to Clinically's clinical inbox, the Extension downloads the document from Xestro and uploads it directly to the user's Clinically account. Documents are transmitted in transit only and are not cached or stored by the Extension.

Authentication Credentials

The Extension stores a short-lived API authentication token to communicate with the Clinically API. This token:

  • Is scoped to the individual user's account

  • Expires after the web session lifetime (typically 2 hours) if not refreshed

  • Is stored in chrome.storage.session, which is automatically cleared when the browser closes

  • Is never transmitted to any party other than the Clinically API server

EMR Integration Consent

A single boolean flag indicating whether the user has acknowledged the EMR integration features is stored in chrome.storage.local. This contains no personal or patient information.

Data We Do NOT Collect

  • We do not collect browsing history or web activity

  • We do not track which pages you visit outside of Clinically and Xestro

  • We do not collect financial or payment information

  • We do not store patient data persistently on your device

  • We do not use analytics, telemetry, or tracking services within the Extension

  • We do not transmit data to any third-party services

How Data Is Used

All data accessed by the Extension is used exclusively to:

  1. Authenticate with the user's Clinically account

  2. Display patient context and practice notifications within the Extension popup

  3. Match patient records between Clinically and Xestro by EMR identifier or demographics

  4. Synchronise patient contact details between systems at the user's explicit request

  5. Transfer clinical documents from Xestro to Clinically's clinical inbox at the user's explicit request

  6. Navigate between corresponding patient records in both systems

Data Transmission

All data transmitted by the Extension uses HTTPS encryption. The Extension communicates only with:

  • app.clinically.com.au — the Clinically application server

  • my.xestro.com — the Xestro EMR system (read-only data access and document download)

No data is sent to any other server, service, or third party.

Data Sharing

We do not sell, trade, or transfer patient data or any other information to third parties. Data flows exclusively between the user's Clinically account and their Xestro EMR session.

User Control

  • Consent: EMR integration features (Xestro reading and interaction) require explicit user acknowledgement before activation.

  • Disconnect: Users can disconnect the Extension at any time via the popup menu, which immediately clears the authentication token and consent flag.

  • Browser close: All session data (including the authentication token) is automatically cleared when the browser is closed.

  • Uninstall: Removing the Extension from Chrome deletes all stored data.

Permissions

The Extension requests the minimum permissions necessary:

Permission

Purpose

storage

Store authentication token (session) and consent preference (local)

alarms

Periodic badge updates for unread notifications

scripting

Interact with the Xestro jQuery interface for patient search and document access

Host: app.clinically.com.au

Read page context and authenticate

Host: my.xestro.com

Read patient data and transfer documents

Third-Party Disclaimer

The Clinically Chrome Extension is developed by CCMx Pty Limited t/a Clinically. It is not reviewed, endorsed, approved, or associated with Xestro or its developers. The Extension interacts with the Xestro web interface as a user-driven automation tool and may stop functioning if Xestro modifies their system.

Australian Privacy Act

CCMx Pty Limited t/a Clinically complies with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Patient information handled by the Extension is subject to the same privacy obligations as information handled within the Clinically platform. For the Clinically platform privacy policy, visit policies.clinically.com.au/PRV-001.

Changes to This Policy

We may update this privacy policy to reflect changes in the Extension's functionality. Material changes will be communicated through the Chrome Web Store listing and within the Extension itself.

Contact

For privacy enquiries or data access requests:

  • Email: support@clinically.com.au

  • Website: https://clinically.com.au