Privacy Policy - Chrome Extension
Overview
The Clinically Chrome Extension ("the Extension") connects the Clinically healthcare practice management platform with the Xestro EMR system. This privacy policy explains what data the Extension accesses, how it is used, and how it is protected.
Data We Access
Patient Information
The Extension reads patient demographic information from two sources:
Clinically (
app.clinically.com.au): Patient name, date of birth, age, gender, phone numbers, email address, and EMR identifier, as provided by the Clinically application via page metadata.Xestro (
my.xestro.com): Patient name, date of birth, phone number, email address, Medicare number, address, and EMR identifier, as displayed in the Xestro patient details interface.
This information is used solely to match patient records between the two systems and to facilitate synchronisation of contact details. Patient data is not stored persistently by the Extension. It is held in session memory and cleared when the browser is closed.
Medicare numbers are read from Xestro for display purposes within the Xestro page only. They are not transmitted to Clinically or stored by the Extension.
Clinical Documents
When a user explicitly chooses to send a document from Xestro to Clinically's clinical inbox, the Extension downloads the document from Xestro and uploads it directly to the user's Clinically account. Documents are transmitted in transit only and are not cached or stored by the Extension.
Authentication Credentials
The Extension stores a short-lived API authentication token to communicate with the Clinically API. This token:
Is scoped to the individual user's account
Expires after the web session lifetime (typically 2 hours) if not refreshed
Is stored in
chrome.storage.session, which is automatically cleared when the browser closesIs never transmitted to any party other than the Clinically API server
EMR Integration Consent
A single boolean flag indicating whether the user has acknowledged the EMR integration features is stored in chrome.storage.local. This contains no personal or patient information.
Data We Do NOT Collect
We do not collect browsing history or web activity
We do not track which pages you visit outside of Clinically and Xestro
We do not collect financial or payment information
We do not store patient data persistently on your device
We do not use analytics, telemetry, or tracking services within the Extension
We do not transmit data to any third-party services
How Data Is Used
All data accessed by the Extension is used exclusively to:
Authenticate with the user's Clinically account
Display patient context and practice notifications within the Extension popup
Match patient records between Clinically and Xestro by EMR identifier or demographics
Synchronise patient contact details between systems at the user's explicit request
Transfer clinical documents from Xestro to Clinically's clinical inbox at the user's explicit request
Navigate between corresponding patient records in both systems
Data Transmission
All data transmitted by the Extension uses HTTPS encryption. The Extension communicates only with:
app.clinically.com.au— the Clinically application servermy.xestro.com— the Xestro EMR system (read-only data access and document download)
No data is sent to any other server, service, or third party.
Data Sharing
We do not sell, trade, or transfer patient data or any other information to third parties. Data flows exclusively between the user's Clinically account and their Xestro EMR session.
User Control
Consent: EMR integration features (Xestro reading and interaction) require explicit user acknowledgement before activation.
Disconnect: Users can disconnect the Extension at any time via the popup menu, which immediately clears the authentication token and consent flag.
Browser close: All session data (including the authentication token) is automatically cleared when the browser is closed.
Uninstall: Removing the Extension from Chrome deletes all stored data.
Permissions
The Extension requests the minimum permissions necessary:
Permission | Purpose |
|---|---|
| Store authentication token (session) and consent preference (local) |
| Periodic badge updates for unread notifications |
| Interact with the Xestro jQuery interface for patient search and document access |
Host: | Read page context and authenticate |
Host: | Read patient data and transfer documents |
Third-Party Disclaimer
The Clinically Chrome Extension is developed by CCMx Pty Limited t/a Clinically. It is not reviewed, endorsed, approved, or associated with Xestro or its developers. The Extension interacts with the Xestro web interface as a user-driven automation tool and may stop functioning if Xestro modifies their system.
Australian Privacy Act
CCMx Pty Limited t/a Clinically complies with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Patient information handled by the Extension is subject to the same privacy obligations as information handled within the Clinically platform. For the Clinically platform privacy policy, visit policies.clinically.com.au/PRV-001.
Changes to This Policy
We may update this privacy policy to reflect changes in the Extension's functionality. Material changes will be communicated through the Chrome Web Store listing and within the Extension itself.
Contact
For privacy enquiries or data access requests:
Email: support@clinically.com.au
Website: https://clinically.com.au