Legal

Privacy Policy

Last updated 2 June 2026

MedicalCertificateGP (“we”, “us”, “our”) is committed to protecting the privacy of every person who uses our telehealth service. This policy explains how we collect, hold, use and disclose your personal and health information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the My Health Records Act 2012 (Cth) where applicable, and the Medical Board of Australia’s telehealth guidelines.

1. Who we are

MedicalCertificateGP is an Australian telehealth platform that connects patients with AHPRA-registered Australian medical practitioners for the purpose of assessing and, where clinically appropriate, issuing short-form medical certificates.

2. Information we collect

  • Identity & contact: full legal name, date of birth, gender, residential address, email and phone.
  • Health information: symptoms, onset, severity, medical history, medications, allergies, pregnancy status, and your reason for requesting leave.
  • Certificate request details: the type of certificate, dates requested, and (for aviation crew) airline employer.
  • Payment information: processed directly by our payment provider (Stripe Payments Australia Pty Ltd). We never see or store your full card number.
  • Technical data: IP address, user agent and timestamps, used for fraud prevention and clinical audit.

3. How we use your information

We use your information to:

  • verify your identity and that you are located in Australia at the time of the consultation;
  • enable the treating doctor to make a safe clinical assessment and decide whether to issue a certificate;
  • produce and deliver your certificate;
  • process payment and, where applicable, refunds;
  • meet our legal, regulatory and clinical record-keeping obligations (we are required to retain clinical records for a minimum of 7 years from the date of the consult, or until age 25 if the patient was a minor);
  • investigate misuse, fraud or abuse of the service.

4. What appears on your certificate

For standard certificates, in line with Australian medical privacy guidelines, the issued certificate states only that you are suffering from a medical condition for the dates noted — it does not name the specific diagnosis. Your employer or institution sees only the dates of leave, the treating doctor’s name and AHPRA number, and a verification reference. They do not see your symptoms, diagnosis or medical history.

For Cabin Crew and Flight Crew certificates, the certificate is marked URTI (upper respiratory tract infection)as required by Australian airline employer policy.

5. Who we share information with

  • The AHPRA-registered doctor who reviews your request.
  • Our cloud hosting and email delivery providers, who process data on our behalf under contract.
  • Stripe, our payment processor, in respect of payment information only.
  • Law enforcement, regulators (including AHPRA) or courts where we are required by law to do so.

We do not sell your personal or health information. We do not use your health information for marketing.

6. Storage & security

All data is encrypted in transit and at rest, and stored on servers located in Australia. Access is restricted to the treating doctor and a limited number of authorised staff on a need-to-know basis, with multi-factor authentication required for all administrative access.

7. Your rights

Under the APPs you may:

  • request access to a copy of your personal and health information;
  • request correction of inaccurate information;
  • make a complaint about how we have handled your information.

To exercise any of these rights, email privacy@medicalcertificategp.com.au. If you are not satisfied with our response you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

8. Cookies

We use a small number of strictly necessary cookies to keep you signed in to the consultation flow and to remember your progress. We do not use third-party advertising cookies.

9. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by updating the “last updated” date at the top of this page.

10. Contact

Privacy enquiries: privacy@medicalcertificategp.com.au
General enquiries: /contact