Your privacy policy was true when you wrote it

Privacy disclosure is a timing question. Where the tools enter your process, whether what you've said is still true, and the part your team is deciding for you.

26 September 20268 min read

You've seen the privacy policy box in Splose. It goes on your forms, it links to a page on your website, and once a client has ticked it the privacy side feels handled.

The Privacy Policy field on a Splose form: a link to the policy and a single tick box.
The Privacy Policy field on a Splose form. One link, one tick box, and the feeling that privacy is done.

I'm not a lawyer, and this isn't advice on what your policy should say. It's a prompt to step back and look at how a client moves through your clinic, and to ask three questions about what they were told, and when. I'm writing it because I recently walked through this with a clinic that had done everything right on paper, and the answers still surprised them.

Where do the tools enter, and have you said so yet?

The document can be perfectly good and still arrive after the thing it describes has already happened.

Here's the intake at that clinic as it was. Someone sends an enquiry through the website. The clinic rings them for a ten minute intake call to check they're the right fit. That call goes through the phone system, which transcribes it. Then a billing and privacy consent form goes out, then an initial appointment, and after that a service agreement, tailored to what the clinician saw in the session. The service agreement was where they explained that they use AI to help with notes and documentation in Splose.

Count back. By the time a family read that sentence, their call had been transcribed and a session note had been drafted with AI. It had been disclosed. Three steps too late.

Hand-drawn client journey from website enquiry to service agreement, with markers showing where the intake call is transcribed and where AI drafts a note, and the disclosure landing at the final step.
The client journey from enquiry to service agreement, with markers where transcription and AI enter and where the disclosure actually lands.

The calls were the other one. They weren't recorded, the transcripts were deleted after three days, and neither of those things was said anywhere. It took drawing the steps out on a page to see it. Nobody was hiding anything. The tools had arrived one at a time, and the paperwork was written before most of them existed.

Draw your own. First contact through to first session, every step. Mark each point where a call is transcribed, a session is recorded, or AI touches a note. Beside each mark, write where the client was told. If the telling sits later in the list than the mark, that's the gap.

A few that come up often:

  • Telehealth sessions recorded for notes, with no question asked at the start of the call. Splose reminds you to ask. Plenty of clinics still don't.
  • A phone system that transcribes calls or voicemails. There's no "this call is recorded" announcement because technically it isn't recorded, but there's still a written record sitting somewhere.
  • Splose AI switched on, and the first note it helps write is for a client who has only ever seen the website policy.

The consent part is simpler than people make it. "Are you okay for this call to be recorded so I can focus on our conversation?" If yes, thanks, carry on. If no, no worries, I'll take some notes, and stop the recording. You've said what you're doing and why. Consent rules on recording differ by state, so check yours.

Is what you've said still true?

What Splose does with AI today is not what it did six months ago. That's not a criticism of Splose, it's the whole industry. My laptop has a physical key on the keyboard for Copilot. AI is being built into platforms you already pay for, whether or not it's obvious, and each new feature changes what happens to information you're responsible for.

So a policy written last year describes last year's tools. Two things to look at when you review it.

Offshore processing. The major players in AI are based overseas. Some of the tools you use will process and store on Australian servers, some won't, and some will do part of each. An Australian company doesn't settle it either, because the product can be local and the model behind it can be anything. Under the Australian Privacy Principles, information processed overseas is an offshore disclosure, and stored versus processed carry different weight. You don't need to become an expert. You need to ask each platform three things: where is the information processed, where is it stored, and how long is it kept. Then your policy says what's actually happening today rather than what was happening when you wrote it.

The tools you've since adopted. For me this meant Plaud. I like it and I've written about it before. For a long time you couldn't get a data processing agreement from them without an enterprise plan, so it couldn't go on an approved list, and I used it for local recordings only, uploading to Splose myself. That's since changed and they now offer one. Things move in both directions, which is the point. A review picks that up. An assumption doesn't.

Does your team know what they can do?

This is the one that applies even if you haven't switched Splose AI on.

If there's no written AI policy and you haven't told your team what they may and may not put where, don't assume nothing is happening. Assume someone is tidying up a report in ChatGPT on their own account, and that a client's first name, address and date of birth went in with it. Not maliciously. They just haven't thought it through, because nobody has asked them to.

A good one is short. Why it exists, which tools are approved, what each one is used for, what protections are in place and where they're up to. It also answers the question the consent script raises: if a client says no to recording, or no to AI, does the clinician know what to do next? Or do they say "oh, okay" and hang up?

If your team is using consumer tools at all, the bare minimum is training turned off in the account settings. It's usually one tick box. Beyond that, decide as a business which platform is approved and say so in writing.

And if you're a clinician working for someone who hasn't done any of this, it's still your responsibility as well as theirs. If it doesn't sit right, ask.

Block out a Monday

None of this is the exciting part of running a clinic. But "I didn't realise the tool did that" isn't a good enough excuse, and the fix is a few hours, not a project.

  1. Draw the client journey, first contact to first session.
  2. Mark where transcription, recording or AI enters. Check the disclosure comes before each one.
  3. Reread the privacy policy against the tools you actually use today.
  4. Write the internal AI policy, even if you're a solo clinician. Approved tools, what for, training off.
  5. Give the team a script for asking, and a plan for when someone says no.

Then put a date in the diary to do it again, because the tools will have moved by then.

Keep reading

Next step

Let's help your clinic find its rhythm.

A 30-minute call. No pitch, no pressure. Just a conversation about where your week is getting stuck and whether I can help.