You are viewing version 1 of this document. View the current version.
Privacy Policy - Sidekick by Clinically
Overview
Sidekick by Clinically (“Sidekick” or “the Extension”) is developed by CCMx Pty Limited t/a Clinically (“we”, “us”, “our”). It helps healthcare practitioners search Pharmaceutical Benefits Scheme (PBS) listings, save reusable prescribing preferences and complete repetitive steps in PRODA / HPOS authority workflows.
This policy explains what Sidekick accesses, stores and shares. It applies to Sidekick, rather than the separate Clinically–Xestro extension or the Clinically practice management platform. Our broader privacy practices are described in Clinically’s Privacy Policy (PRV-001).
Data We Access and Store
Authority pages and reusable templates
On supported Services Australia pages, Sidekick inspects page content and form fields to identify the workflow, selected medicine, PBS item, indication, restriction, prescription settings and reusable steps. This processing takes place in your browser. Supported pages may also contain patient information.
Saved templates can contain medicine and listing details, indication and treatment phase, quantities, repeats, dose and frequency, reusable field labels and values, your template name, creation and update dates. They are stored in your Chrome profile. Chrome synchronisation is off by default and requires you to enable it in the sidebar.
Sidekick is designed to exclude patient identifiers, authority prescription numbers, patient-specific comments and declarations from reusable templates. Its checks recognise selected field names and identifier patterns; they cannot reliably detect every identifying detail in free text. Do not enter patient names, Medicare numbers, dates of birth or other identifying details in search queries or template names. Review templates before saving or sharing them.
Provider numbers and work in progress
Sidekick can read a provider number from the authority page and hold it in page memory while you work. It does not include the number in its stored work-in-progress recording. Saving it in a reusable template requires you to select the provider-number option. Updating a template without that option removes the saved provider number and its generated name suffix.
Work-in-progress recordings contain selected item, prescription and workflow details in temporary browser-session storage. They survive page navigation but are cleared when the browser closes or the Extension restarts. Saved templates retain only anchored replay steps and the limited question context needed to detect changed forms; clinical-question and row-selection steps are excluded.
Preferences and diagnostics
Sidekick stores basic interface, search and PBS redirect preferences. Where prescribing-location settings have been explicitly configured, these may include a location name and provider number. Sidekick does not collect template use counts or selection history.
Diagnostics are off by default. You can enable them in the sidebar for 15 minutes to troubleshoot a problem. During that period, Sidekick keeps up to 250 diagnostic entries and a limited set of page-structure snapshots in browser-session storage and writes diagnostic messages to the browser console. These can include workflow events, item codes, prescription values, field descriptions and errors. Pattern-based redaction cannot guarantee removal of every identifying detail. Nothing is automatically uploaded to Clinically.
Stopping diagnostics clears stored logs and snapshots. After the 15-minute period, further diagnostic collection stops and the next diagnostic attempt clears the stored entries. Closing the browser also clears session storage. Browser-console retention depends on your developer-tool settings.
Support enquiries
If you contact us, we receive the contact details, message and any attachments you provide so we can respond and investigate. Please remove patient information from screenshots, logs and other material before sending it to support.
How Data Is Used
Sidekick uses this information to find PBS listings, remember your preferences, offer reusable templates, fill supported workflow fields, reconnect the sidebar to the relevant page and diagnose problems. Clinical attestations and final submission remain your responsibility. Sidekick does not automate PRODA login or multi-factor authentication and does not store PRODA passwords or authentication tokens.
The Extension contains no advertising trackers, analytics SDKs or remote telemetry service and does not send information to an AI service. We do not sell Extension data or use it for targeted advertising. Sidekick does not collect a general browsing history.
Data Transmission and Sharing
PBS Search by Clinically
Live search sends the text entered in the medicine search field to pbs.clinically.com.au as you type. Requests can also include medicine names, forms, listing filters, page numbers and PBS item codes. Requests use HTTPS and omit browser credentials. The receiving service processes connection information such as your IP address to respond to requests. PBS search requests are not logged on the server.
Sidekick does not upload its saved library, provider-number field or authority-page contents to the PBS API. However, anything you type in a live search query is transmitted as search text. Use medicine or listing terms only.
Chrome synchronisation
Templates stay on your device by default. If you enable “Sync saved templates with Chrome” in Sidekick’s sidebar, the Extension attempts to synchronise them through Google’s Chrome service. Templates include any provider number you explicitly saved, template names and prescribing preferences. Other browsers using the same synchronised profile may receive them when Sidekick synchronisation is enabled there. Storage limits or unavailable synchronisation may leave some templates local.
Google operates infrastructure internationally, including in the United States. Sidekick does not restrict synchronised storage to Australia. See Google’s Privacy Policy. Turning off the Sidekick sync preference stops reads and writes for template synchronisation and attempts to delete the Extension’s cloud template entries. Local copies on other devices may remain.
Sharing a template
The template Share action copies an encoded template to your clipboard. It removes the saved provider-number field, its generated template-name suffix and usage metadata. You must still review free text for personal information. Encoding is not encryption: anyone receiving the code can read it. Sidekick does not send it to a recipient; you choose where to paste or send it. Clipboard managers may retain copies.
The sidebar’s general Share control copies only the public PBS Search website link.
Government websites and external links
Sidekick interacts with the supported PRODA / HPOS pages in your existing browser session. Information entered into those pages is handled by Services Australia under its own arrangements. Sidekick does not automatically lodge or authorise an application.
On pbs.gov.au and www.pbs.gov.au, Sidekick offers a link to PBS Search by Clinically. If you choose “Always take me there”, it redirects future visits to the PBS Search homepage. This feature does not forward the government page’s path or query string. You can change the preference in the sidebar. Websites opened through links have their own privacy practices.
Retention, Deletion and Your Controls
Saved templates: Remain until you delete them or clear extension storage. Use the saved library to delete templates. Deletion also attempts to remove their cloud entries; copies on other devices or previously shared copies may remain.
Work in progress: Stored only for the browser session. A recording older than 12 hours is discarded when next restored. A detected new authority or completed template save also clears the recording.
Upgrades: Sidekick removes legacy persistent recordings, logs and selection history, strips usage metadata when loading saved templates, and removes previously automatic cloud template copies unless sync has been explicitly enabled. Your saved local library is retained.
Stop access: Disable or remove Sidekick through Chrome. Removing it clears local extension storage but does not recall shared codes, clipboard copies, backups, support correspondence or records held by Services Australia. Check other devices and Google’s controls for remaining synchronised data.
Security and Permissions
Sidekick uses browser-managed storage and HTTPS for its configured PBS API connection. It does not add its own encryption layer to local templates or share codes. Protect your device and Chrome profile, particularly where provider numbers or prescribing preferences are stored.
| Permission or website access | Purpose |
|---|---|
storage | Keep saved templates and preferences locally, work in progress and optional diagnostics in session storage, and synchronise templates only when enabled. |
sidePanel | Display the search and saved-template sidebar. |
clipboardWrite | Copy a template share code or website link when requested. |
proda.humanservices.gov.au, proda.servicesaustralia.gov.au, www2.medicareaustralia.gov.au, www2.servicesaustralia.gov.au, hpos.servicesaustralia.gov.au | Recognise supported authority workflows and read or fill relevant fields. |
pbs.clinically.com.au | Retrieve public PBS search and listing data. |
pbs.gov.au, www.pbs.gov.au | Show the PBS Search reminder and apply your redirect preference. |
Access, Correction and Privacy Complaints
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may contact support@clinically.com.au to request access to or correction of personal information we hold, ask for help removing Extension data, or make a privacy complaint. We may need to verify your identity. We cannot remotely inspect your local Chrome library simply because you use Sidekick.
Please describe your concern and the outcome you seek without including unnecessary patient details. We will acknowledge complaints within 5 business days and aim to resolve them within 30 business days, consistent with PRV-001. We will investigate and explain our response. If you are dissatisfied, you may contact the Office of the Australian Information Commissioner. Requests concerning an authority record held by your healthcare provider or Services Australia should be directed to that record holder.
Third-Party Disclaimer
Sidekick is an independently developed Clinically product. It is not endorsed by or affiliated with Services Australia, PRODA, HPOS or the Australian Government.
Changes to This Policy
We may update this policy when Sidekick’s functionality or data practices change. Material changes will be communicated through the Chrome Web Store listing or the Extension. The controlled document’s published version and date identify the applicable policy.
Contact
CCMx Pty Limited t/a Clinically
Email: support@clinically.com.au
Website: clinically.com.au