WoundLane Privacy Policy
Version 1.0 · Last updated: 8 October 2026
WoundLane is operated by RecoverOS Technologies Pty Ltd (ABN 93 701 897 216) ("WoundLane", "we", "us", "our"). This Privacy Policy explains how we handle personal information in connection with:
- the WoundLane website at woundlane.com;
- the WoundLane wound and skin-care software service (the "Service"); and
- the public WoundLane demonstration at demo.woundlane.com (the "Demo").
We handle personal information in accordance with applicable Australian privacy laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply to us, and we have regard to applicable state and territory health-records laws such as the Health Records Act 2001 (Vic).
If you have a question about this policy or about your personal information, contact us at business@woundlane.com.
1. Who this policy is about
WoundLane is business software used by aged-care, disability, supported independent living (SIL), community and home-care providers ("Customer Organisations") to record and manage wound and skin care.
We handle personal information in two different ways:
- Information we handle on behalf of Customer Organisations. When a Customer Organisation's staff use WoundLane, they enter information about the people they care for ("residents" or "clients") and about their own staff. The Customer Organisation decides what information to record, who in its organisation can see it, and who it shares it with. We store and process that information to provide the Service to the Customer Organisation, under our Terms of Service and this policy.
- Information we collect for our own purposes. We also collect information to run our business, for example to set up and bill subscriptions, provide support, answer enquiries and keep the Service secure.
If you are a resident, client, family member or representative and you have a question about information a care provider has recorded about you, please contact that provider first. They are best placed to help, and we will assist them. You can also contact us directly.
2. Personal information we handle
2.1 Resident and client information (entered by Customer Organisations)
Depending on how a Customer Organisation uses WoundLane, this can include:
- Identity and service details: name, preferred name, date of birth, an optional client identifier chosen by the organisation, room or unit, the site where the person receives care, and their status with the organisation (for example, whether they have left the service or have died, and the reason). An optional profile photo may be added to help staff identify the right person.
- Health information, which is sensitive information, including:
- wounds and skin findings: location on the body, type, cause, measurements, tissue, healing progress and closure;
- wound and skin assessments and pressure-injury risk assessments (for example Waterlow, Braden or Norton), including the answers given and the resulting scores;
- relevant clinical background, such as health conditions, mobility, continence, nutrition, weight, allergies and certain medicines that affect healing;
- treatment and dressing plans, records of care given, escalations, clinical reviews and clinical notes;
- concerns reported by staff;
- referrals to external wound clinicians, and their reviews and recommendations.
- Photographs of wounds and skin, together with who took them, when they were taken and the consent status recorded for each photograph.
WoundLane does not ask for residents' home addresses, Medicare numbers or NDIS numbers. Free-text fields can contain whatever staff type, so we ask Customer Organisations to record only what is needed for care.
2.2 Staff and user information
For people who use WoundLane (including Customer Organisation staff, administrators and external wound clinicians):
- name, work email address, role, the sites they can access, and the organisation they work for (for external clinicians);
- invitation details (who invited them and when);
- account security information: a password (stored only in hashed form, never in readable form), two-factor authentication settings (stored encrypted), and sign-in history;
- a record of what they do in the Service, such as which records they created, changed or viewed in certain sensitive areas, so that clinical records show who did what and when.
2.3 Account and billing information
When an organisation subscribes:
- organisation name, and the name and email address of the person setting up the subscription;
- billing contact name and email;
- subscription details: plan, price, status, billing dates, cancellation and payment-status information;
- references to the organisation's customer and subscription records held by our payment provider.
We do not receive or store card details. Payments are processed by our payment provider, Stripe, which collects payment and billing details directly on its own secure pages under its own privacy policy.
2.4 Technical and security information
When you use the website, the Service or the Demo, we collect:
- your IP address and browser/device information (user agent);
- session information needed to keep you signed in;
- security and audit records of significant events, such as sign-ins, failed sign-in attempts, access to restricted areas, changes to records and data exports. For failed sign-ins we store a coded fingerprint rather than the email address that was typed;
- server logs used to operate and troubleshoot the Service.
2.5 Enquiries
If you email us, we receive your name, email address and anything you include in your message.
2.6 The public Demo
You do not need to give us your name or email address to use the Demo. The Demo contains only fictional (synthetic) residents and sample images.
- Please do not enter real resident or patient information into the Demo.
- Photos you try to upload in the Demo are not stored; the Demo uses sample images instead.
- The Demo does not send emails.
- To protect the Demo from automated abuse, we use a human-verification service (Cloudflare Turnstile), which receives your IP address and information about your browser.
- We keep security records (including IP address and browser information) while your demo exists, and in server logs for a short period. Each demo organisation, including anything entered into it, is deleted automatically after it ends.
3. How we collect personal information
We collect personal information:
- from Customer Organisations and their staff, when they enter it into the Service;
- from external wound clinicians, when they respond to referrals;
- from the person who subscribes on behalf of an organisation;
- from our payment provider (for example, whether a payment succeeded);
- automatically, when you use our website, the Service or the Demo;
- from you directly, when you contact us.
Residents' information is collected by the Customer Organisation, usually from the resident, their representatives, the organisation's staff or other health professionals. The Customer Organisation is responsible for telling residents how it handles their information and for having the authority or consent it needs, including for photographs.
You can browse our website and use the Demo without identifying yourself. It is not practicable to use the Service itself anonymously, because clinical records must show who recorded what.
4. Why we collect, use and hold personal information
We use personal information to:
- provide, operate and maintain the Service for Customer Organisations;
- create and manage user accounts, authenticate users and control access according to the roles and sites set by each Customer Organisation;
- keep the Service secure, detect and prevent misuse, and maintain audit records;
- process subscriptions, payments and billing notices;
- send service emails, such as invitations, password-reset links and billing notices;
- provide support and respond to enquiries and requests;
- diagnose problems and maintain the reliability of the Service;
- comply with our legal obligations and respond to lawful requests; and
- establish, exercise or defend legal claims.
We do not sell personal information. We do not use resident health information or photographs for advertising, and we do not use them to train artificial-intelligence models. Photo-based measurement features in WoundLane run within the Service itself, not through external AI providers.
Risk scores and suggestions
WoundLane calculates pressure-injury risk scores and shows prompts or suggestions based on the information staff enter. These are tools to support clinical decision-making. WoundLane does not make decisions about a person's care; those decisions are made by the Customer Organisation's staff and health professionals.
5. Who we disclose personal information to
We disclose personal information only as described here:
- Within the Customer Organisation. Information is available to the Customer Organisation's authorised users according to the roles, permissions and sites the organisation sets. WoundLane keeps each Customer Organisation's information separate from other organisations' information.
- External wound clinicians. When a Customer Organisation creates a referral, the external clinician it chooses can see the information that referral includes, for the period the referral allows.
- Service providers who help us run WoundLane, including providers of hosting and data storage, payment processing (Stripe), email delivery, website security and human verification, and a password-safety check. These providers receive only the information they need to perform their services. When you choose a new password, we check whether it has appeared in known data breaches using a method that sends only a small, partial code derived from the password, never the password itself or your email address.
- Professional advisers, such as lawyers and accountants, where needed.
- As required or authorised by law, including to regulators, courts or law-enforcement agencies, or where we reasonably believe disclosure is necessary to lessen or prevent a serious threat to someone's life, health or safety.
- A successor business, if all or part of our business is sold or restructured, subject to that business handling the information consistently with this policy.
WoundLane staff do not access Customer Organisations' clinical information except where reasonably necessary to provide support requested by the Customer Organisation, maintain or secure the Service, or comply with the law.
6. Overseas disclosure
We use third-party service providers for hosting, payments, email delivery and security. Some of these providers may store or process personal information outside Australia, including in the United States and other countries where they or their own service providers operate.
We take reasonable steps when selecting and using service providers, including considering their security and privacy practices and the terms on which they handle information. If you would like more information about how overseas service providers are used, contact us and we will provide further information where appropriate.
7. How we store and protect personal information
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Our measures include:
- encrypted connections (HTTPS) for the website, the Service and the Demo;
- access controls based on each user's role, permissions and sites, set by their organisation, with each organisation's information kept separate;
- external clinicians' access limited to the scope and time window of each referral;
- photographs stored privately and shown only through short-lived links after checking the viewer's permission;
- removal of location (GPS) and other device information embedded in photographs before they are stored;
- passwords stored only in hashed form; two-factor authentication available to every user, and required for WoundLane platform operators;
- automatic sign-out after a period of inactivity;
- audit records of significant actions, which cannot be edited through the Service;
- clinical records that keep a history of corrections rather than silently overwriting earlier entries; and
- regular backups.
No method of transmitting or storing information is completely secure, and we cannot guarantee absolute security. Customer Organisations are responsible for controlling who in their organisation has access, removing access promptly when staff leave, and keeping their own devices secure.
8. How long we keep personal information
We keep personal information only for as long as reasonably necessary for the purposes described in this policy, including to provide the Service, maintain security, keep accurate records, and meet legal, regulatory, contractual and legitimate business requirements.
In practice:
- Customer Organisation information (including resident and clinical information) is kept while the organisation's subscription continues, and for a period after cancellation so the organisation can access and export its records and so that legal and regulatory requirements can be met. Customer Organisations remain responsible for their own record-keeping obligations and should keep copies of the records they need.
- Account, billing and security records may be kept for longer where reasonably necessary, for example to meet accounting and tax obligations or to investigate security incidents.
- Short-lived technical data, such as expired sign-in sessions and server logs, is kept only for a short period.
- Backups are kept for a limited period and then replaced.
- Demo organisations are deleted automatically after the demo ends.
We manage retention having regard to the purposes for which information is held and applicable legal, regulatory and contractual requirements. Customer Organisations may contact us about access, export or deletion requests, which we assess having regard to those requirements.
9. Accessing and correcting your personal information
You may ask to access or correct personal information we hold about you.
- Residents, clients and their representatives: please contact the care provider that recorded the information. They control those records and can usually help directly. We will assist them as needed. If you contact us, we will refer your request to the relevant organisation or help you in another appropriate way.
- WoundLane users: you can update some details yourself in your account settings, or ask your organisation's administrator. You can also contact us.
- Other people (for example, subscribers or people who have contacted us): contact us at business@woundlane.com.
We will respond within a reasonable time, usually within 30 days. We do not charge for making a request. If we refuse a request, we will explain why (unless it would be unreasonable to do so) and how you can complain.
10. Data breaches
If we become aware of a data breach involving personal information we hold, we will act promptly to contain and assess it. Where a breach affects information we hold for a Customer Organisation, we will notify that organisation without undue delay and work with it. Where required, we will notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.
11. Cookies and similar technologies
WoundLane uses only cookies and browser storage that are needed for the website and Service to work:
- a session cookie that keeps you signed in, and a security token that protects forms;
- a cookie that helps the sign-in page recognise a returning user on the same device;
- preferences, such as light or dark appearance and whether the side menu is open;
- for the Demo, a cookie that links your browser to your demo session; and
- browser storage used to sign you out after inactivity and to protect recently viewed pages after you sign out.
We do not use advertising cookies or third-party analytics or tracking tools on WoundLane. If this changes, we will update this policy first.
12. Direct marketing
We may send business contacts information about WoundLane where permitted by law. Marketing communications will identify the sender and provide a way to unsubscribe. We do not use resident or health information for marketing.
Service emails, such as invitations, password resets and billing notices, are not marketing; they are part of providing the Service.
13. Complaints
If you have a complaint about how we have handled your personal information, contact us at business@woundlane.com with details of your concern. We will acknowledge your complaint, investigate it and aim to respond within 30 days.
If you are not satisfied with our response, you may contact:
- the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au, phone 1300 363 992; or
- for health information in Victoria, the Health Complaints Commissioner: hcc.vic.gov.au; or
- the privacy or health-complaints regulator in your state or territory.
14. Changes to this policy
We may update this policy from time to time, for example when we change how WoundLane works or when the law changes. We will publish the updated policy on our website with a new "last updated" date. If we make a significant change, we will take reasonable steps to tell Customer Organisations' administrators, for example by email or in the Service.
15. Contact us
WoundLane is operated by RecoverOS Technologies Pty Ltd (ABN 93 701 897 216) Email: business@woundlane.com