Section 01Overview

This policy explains how Radgentix ("we", "our", or "us") collects, uses, discloses, and protects personal information across our websites, products, and advisory services.

Radgentix builds software and provides advisory services to diagnostic imaging providers. Our work sometimes involves clinical operational data. Where that is the case, we act as a data processor on behalf of our customers under written agreements — this policy explains the personal information we handle in our own capacity as controller (or its equivalent under applicable law).

Summary of what we do with your data: we collect a limited set of information needed to run our business, respond to enquiries, deliver our products, and meet legal obligations. We do not sell personal information. We do not use analytics or advertising cookies on this website.

Section 02Who we are

The data controller for the purposes of this policy is:

Radgentix
Contact: privacy@radgentix.com

For enquiries from data subjects in the European Economic Area or United Kingdom, you may contact us at the same address. If we appoint an EU representative, their details will be listed here.

Section 03Information we collect

We collect the following categories of personal information, depending on how you interact with us:

Information you provide directly

  • Contact and enquiry information — name, email address, organisation, role, and any information you include when you contact us via email or through the website.
  • Commercial and engagement information — information exchanged during commercial discussions, proposals, contracting, and delivery of advisory engagements.
  • Product account information — where you or your organisation are provisioned to use a Radgentix product, we collect account identifiers, user role, and configuration information necessary to deliver the service.

Information we collect automatically through our products

  • Product usage telemetry — for licensed products such as RadIVWL, we collect audited operational metadata (report counts, timestamps, license identifiers, integration health signals) needed to operate the platform, meter usage, and produce commercial reporting to license partners. This telemetry does not include patient-identifiable clinical content in ordinary operation.
  • System diagnostics — application logs, error events, and performance data used to maintain service quality.

Information we receive from partners

  • Partner-provided information — where a reporting vendor, integrator, or channel partner introduces you to a Radgentix product, we may receive contact and engagement details necessary to onboard and support you.

Information we do not collect

  • We do not use tracking cookies, third-party analytics, or advertising pixels on this website.
  • We do not collect patient clinical content through our website or advisory engagements. Where our products are involved in clinical workflows, data handling is governed by the applicable customer or partner agreement.

Section 04How we use information

We use the personal information we collect for the following purposes:

  • To respond to enquiries and correspond with you
  • To provide, operate, and improve our products and services
  • To fulfil our contractual obligations to customers and partners
  • To meter and bill for product usage under licensing arrangements
  • To detect, prevent, and respond to security incidents and misuse
  • To comply with legal, tax, and regulatory obligations
  • To conduct business operations including record-keeping, accounting, and legitimate business planning

We do not use personal information for automated decision-making that produces legal or similarly significant effects on you.

Section 05Legal bases for processing

Where the General Data Protection Regulation (GDPR) or UK GDPR applies, we rely on the following legal bases:

  • Contract — to enter into and perform contracts with you or your organisation.
  • Legitimate interests — to operate and improve our business, respond to enquiries, ensure security, and communicate with commercial contacts, where such interests are not overridden by your rights and freedoms.
  • Legal obligation — to comply with laws that require us to hold or disclose information.
  • Consent — where we ask for and receive your explicit consent, for example to send you optional communications. You may withdraw consent at any time.

Section 06Sharing and disclosure

We do not sell personal information. We share information only in the following limited circumstances:

  • Service providers — cloud infrastructure, hosting, communications, and professional service providers who process information on our behalf under written agreements. Our primary infrastructure providers include Microsoft (Azure, Microsoft 365).
  • Licensing and channel partners — where the arrangement requires it, we share operational data with reporting vendors and channel partners under contractual data handling obligations. This is limited to what is necessary to deliver the integrated service.
  • Legal and regulatory — where required by law, court order, or a regulatory authority with jurisdiction, or to establish, exercise, or defend legal claims.
  • Corporate transactions — in the context of a merger, acquisition, restructuring, or sale of assets, subject to the recipient being bound by equivalent privacy commitments.

Section 07International transfers

Radgentix is based in Australia and uses cloud infrastructure that may store or process personal information in Australia, the United States, and other jurisdictions where our service providers operate.

Where personal information originating in the European Economic Area, United Kingdom, or other jurisdictions with cross-border transfer restrictions is transferred outside those jurisdictions, we rely on lawful transfer mechanisms including standard contractual clauses (SCCs), adequacy decisions where applicable, and equivalent safeguards.

Note: transfers involving health information are subject to additional restrictions in some jurisdictions. Where such transfers occur through our products, they are governed by the customer or partner agreement and any applicable data processing addenda.

Section 08Security

We maintain reasonable and appropriate technical and organisational safeguards designed to protect personal information against unauthorised access, use, disclosure, alteration, and destruction. These include:

  • Encryption of data in transit (TLS) and at rest for stored data
  • Role-based access controls and multi-factor authentication for administrative access
  • Audit logging of privileged operations
  • Vendor risk management for material third-party service providers
  • Incident response procedures

No system can be guaranteed to be completely secure. If we become aware of a data breach that meets applicable notification thresholds, we will notify affected individuals and regulators in accordance with applicable law.

Section 09Data retention

We retain personal information only for as long as necessary for the purposes for which it was collected, or as required by applicable law, regulation, or contract. Retention periods depend on the nature of the information:

  • Enquiry and correspondence data — retained for the duration of the enquiry and up to seven years thereafter for legitimate business record-keeping.
  • Commercial and contractual records — retained for the duration of the engagement plus statutory retention periods (typically seven years in Australia).
  • Product operational telemetry — retained per the terms of the applicable licensing or customer agreement.
  • Legal and regulatory records — retained as long as required by the relevant regime.

When retention is no longer required, we delete or anonymise personal information.

Section 10Your rights

Subject to applicable law and any lawful basis to retain information, you have the right to:

  • Request access to the personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Request deletion of information where retention is no longer required
  • Object to or restrict processing in certain circumstances
  • Request portability of information you have provided to us
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with a supervisory authority

To exercise any of these rights, please contact us at privacy@radgentix.com. We will respond within the timeframes required by applicable law.

Section 11Children

Our services are directed to businesses and healthcare organisations, not to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we may have collected information about a child, please contact us and we will delete it.

Section 12Health information

Radgentix products may be used within radiology workflows that involve health information. Where that occurs:

  • Radgentix acts as a service provider or data processor to the customer or partner operating the workflow.
  • The customer or partner is the controller of the health information and is responsible for the lawful collection, use, and disclosure of that information under applicable law.
  • Our processing of health information is governed by the applicable customer or partner agreement, data processing addendum, and any Business Associate Agreement (where HIPAA applies) or equivalent instrument.

In Australia, health information is sensitive information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We handle it in accordance with those obligations and the terms of the applicable customer agreement.

If you are a patient enquiring about your own health records, please contact the diagnostic imaging provider or hospital that holds those records. Radgentix does not maintain patient records in its own right.

Section 13Regional rights

European Economic Area and United Kingdom (GDPR)

Individuals in the EEA and UK have the rights listed in Section 10 above. You also have the right to lodge a complaint with your local data protection authority. A list of EEA supervisory authorities is available on the European Data Protection Board website. UK residents may contact the Information Commissioner's Office (ICO).

Australia (Privacy Act 1988 and APPs)

Individuals in Australia have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including the right to access and correct personal information we hold about you. Complaints may be directed to us in the first instance and, if not resolved, to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

California (CCPA / CPRA)

California residents have the right to know what personal information we collect, to request deletion, to correct inaccurate information, to opt out of the sale or sharing of personal information (Radgentix does not sell or share personal information as those terms are defined under the CCPA), and to limit the use of sensitive personal information. California residents may also designate an authorised agent to make requests on their behalf. To exercise any of these rights, contact privacy@radgentix.com. We will not discriminate against you for exercising any of these rights.

Other jurisdictions

Where you reside in a jurisdiction whose privacy law extends specific rights to you, we will honour those rights to the extent required by that law.

Section 14Cookies and analytics

This website does not use analytics cookies, advertising cookies, or third-party tracking scripts. We do not use Google Analytics, marketing pixels, or session recording tools.

If we introduce cookies or analytics in the future, we will update this policy and, where required, obtain your consent before deployment.

Section 15Changes to this policy

We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Where the changes are material, we will provide reasonable notice through our website or by direct communication where appropriate.

Section 16Contact us

If you have questions about this policy, wish to exercise your rights, or want to raise a concern:

Radgentix
Privacy enquiries: privacy@radgentix.com
General enquiries: hello@radgentix.com

We aim to respond to privacy enquiries within 30 days, or sooner where required by applicable law.