Privacy policy

Privacy Policy

CoHearent Pty Ltd (ABN 28693063400) Effective date: July 29, 2026, Last Updated: July 29, 2026

 

1. About this policy

CoHearent Pty Ltd ("CoHearent", "we", "us", "our") builds AI-enabled clinical software for the hearing care sector. Our products are:

  • COSI 2.0 — a platform used by hearing care clinics to capture patient listening goals and measure hearing outcomes; and
  • NAL Virtual Personas — an AI roleplay training platform for hearing care professionals and students.

This policy explains how we handle personal information in connection with our website at cohearent.com.au, our products, and our business generally. It is our privacy policy for the purposes of Australian Privacy Principle (APP) 1 under the Privacy Act 1988 (Cth).

We also handle health information, which is subject to additional protections under the Privacy Act and, in some cases, under state and territory health records legislation.

By using our website or our products, you agree to the handling of your personal information as described in this policy.

2. The two roles we play

It matters which role we are performing when you deal with us.

As a service provider to clinics. When a hearing care clinic or clinic group uses COSI 2.0, that clinic is the health service provider and holds the primary relationship with its patients. The clinic decides what information is collected, obtains patient consent, and remains responsible for the clinical record. We process that information on the clinic's behalf under our agreement with them, and only for the purposes that agreement permits. If you are a patient and want to know how your information is handled at the point of care, contact your clinic in the first instance.

In our own right. When you visit our website, contact us, subscribe to our updates, apply for a job, or use NAL Virtual Personas as a registered professional, we handle your personal information as an APP entity in our own right, and this policy applies directly.

3. What personal information we collect

Website visitors. IP address, device and browser type, pages viewed, referring URL, approximate location derived from IP, and interaction data collected through cookies and analytics tools. Where you submit a form, we collect the details you provide — typically name, email address, organization, role, country, and the content of your message.

Hearing care professionals and business contacts. Name, work email address, phone number, employer, professional role, registration or credentialing details where relevant, training progress and performance data within NAL Virtual Personas, account credentials, and records of your communications with us.

Patients (via clinics using COSI 2.0). Listening goals and related free-text responses, hearing assessment and outcome data, device fitting information, and identifiers assigned by the clinic. Depending on the clinic's configuration, this may include name, date of birth, and contact details. This is health information and is treated as sensitive information under the Privacy Act.

Job applicants. Contact details, resume, work history, qualifications, right-to-work information, and referee feedback.

We do not knowingly collect personal information from children through our website. Where a minor is a patient of a clinic using COSI 2.0, the clinic is responsible for obtaining consent from a parent or guardian.

4. How we collect it

We collect personal information directly from you wherever it is reasonable and practicable to do so — when you fill in a form, email or call us, register for an account, attend one of our webinars or events, or use our products.

We also collect information:

  • from clinics and enterprise customers, in the course of delivering our products to them;
  • from your employer or organization, where they have arranged your access to our products;
  • from publicly available professional sources, where we are researching potential customers or partners;
  • automatically, through cookies and analytics, when you use our website.

If we receive personal information about you that we did not solicit and could not lawfully have collected, we will destroy or de-identify it as required by APP 4.

5. Why we use your personal information

We use personal information to:

  • provide, operate, support, and improve COSI 2.0 and NAL Virtual Personas;
  • deliver services to clinics under our customer agreements, including reporting and analytics;
  • authenticate users and administer accounts;
  • respond to enquiries, provide customer support, and manage our commercial relationships;
  • send service communications, product updates, and — where you have opted in — marketing communications;
  • conduct research and product development, generally using de-identified or aggregated data;
  • meet our legal, regulatory, contractual, insurance, and record-keeping obligations;
  • protect the security and integrity of our systems, and detect and prevent misuse.

We will only use or disclose your personal information for a secondary purpose where you would reasonably expect it, where you have consented, or where the law otherwise permits or requires it.

6. Sensitive and health information

We collect health information only where it is necessary to provide our services and where the individual has consented, or where an exception under the Privacy Act applies. In the COSI 2.0 context, consent is obtained by the treating clinic at the point of care as part of its own privacy notice and consent process.

We do not use patient health information for advertising, and we do not sell personal information to any third party.

Where we use patient data for product improvement or research, we do so using de-identified or aggregated data, subject to the terms of our agreement with the relevant clinic. We apply controls designed to prevent re-identification and do not attempt to re-identify de-identified data.

7. Artificial intelligence and automated processing

Our products use artificial intelligence, including large language models, to generate outputs — for example, structured summaries of patient listening goals in COSI 2.0, and simulated patient dialogue and coaching feedback in NAL Virtual Personas.

Some important points about how this works:

  • Our outputs are decision support, not decisions. COSI 2.0 assists clinicians in documenting and measuring outcomes. It does not make clinical diagnoses, determine treatment, or decide a patient's eligibility for any service. A qualified clinician remains responsible for all clinical judgments.
  • Human oversight is built in. Clinician review is a required step in the COSI 2.0 workflow before AI-generated content enters the clinical record.
  • We restrict downstream use. Where we use third-party AI services, we do so under contractual terms that prohibit the provider from using our customers' data to train their general-purpose models.
  • Training simulations are synthetic. NAL Virtual Personas uses fictional patient personas. Personas are not derived from any identifiable real patient.

Automated decision-making transparency. From 10 December 2026, new APPs 1.7–1.9 require Australian organizations to disclose in their privacy policies where a computer program uses personal information to make, or to substantially and directly support, a decision that could reasonably be expected to significantly affect an individual's rights or interests. We are assessing our products against that threshold and will update this section before the commencement date, and in line with the guidance the Office of the Australian Information Commissioner (OAIC) is expected to publish.

8. Who we disclose information to

We may disclose personal information to:

  • Clinics and enterprise customers, where the information relates to their patients, staff, or accounts;
  • Service providers who support our operations — cloud hosting and infrastructure, AI model providers, analytics, email and CRM platforms, customer support tools, and professional advisers — all under obligations of confidentiality and appropriate data protection terms;
  • The National Acoustic Laboratories (NAL), in connection with our licensed intellectual property, on a de-identified or aggregated basis unless otherwise agreed;
  • Regulators, courts, or law enforcement, where required or authorized by law;
  • Acquirers or investors, in connection with a corporate transaction, subject to confidentiality undertakings.

We do not sell, rent, or trade personal information.

9. Overseas disclosure

Our primary production infrastructure for Australian customer data is hosted in [Australia — confirm region].

Some of our service providers may store or process personal information outside Australia, including in [list jurisdictions — e.g., the United States and the European Union]. Before disclosing personal information overseas, we take reasonable steps under APP 8.1 to ensure the recipient does not breach the APPs, including through contractual data protection commitments and vendor due diligence.

Where a clinic customer requires that patient data remain within Australia, we accommodate that requirement through our service configuration and contractual terms.

10. Cookies and website analytics

We use cookies and similar technologies on cohearent.com.au to keep the site functioning, remember your preferences, and understand how the site is used.

We use [Google Analytics / other — confirm] for traffic analysis, and [list any marketing or tracking tools]. These tools may set their own cookies and are subject to their own privacy policies.

You can control or disable cookies through your browser settings. Blocking cookies may affect how parts of our site function.

11. Marketing and how to opt out

We may send you information about our products, events, and research if you have subscribed, requested information from us, or are an existing business contact who would reasonably expect to hear from us.

Every marketing email includes an unsubscribe link, and we honor unsubscribe requests promptly, consistent with the Spam Act 2003 (Cth). You can also email us at info@cohearent.com.au to opt out. Opting out of marketing does not stop essential service and account communications.

12. How we protect your information

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorized access, modification, or disclosure. Our controls include:

  • encryption of data in transit and at rest;
  • role-based access controls and least-privilege access provisioning;
  • multi-factor authentication for administrative access;
  • audit logging of access to clinical data;
  • security assessment of vendors before engagement;
  • staff confidentiality obligations and privacy training;
  • documented incident response and business continuity procedures.

No system is completely secure. If you believe your account or data has been compromised, contact us immediately at info@cohearent.com.au.

13. How long we keep information

We retain personal information only as long as necessary for the purposes it was collected, or as required by law or contract.

  • Clinical data processed for a clinic is retained per our agreement with that clinic. On termination, we return or securely delete the data as directed, subject to legal retention obligations.
  • Business contact and marketing data is retained while the relationship is active and for a reasonable period afterward.
  • Website analytics data is retained per the settings of the analytics tools we use.
  • Unsuccessful job applications are retained for [12] months unless you ask us to delete them sooner.

Where information is no longer needed, we destroy it or de-identify it.

14. Data breaches

We maintain a data breach response plan. If we experience an eligible data breach that is likely to result in serious harm, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. Where a breach involves data we process for a clinic, we will notify that clinic promptly and support its own notification obligations.

15. Accessing and correcting your information

You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant, or misleading. Email info@cohearent.com.au.

We will respond within a reasonable period, normally within 30 days. We may need to verify your identity before releasing information. In limited circumstances we may refuse access — for example where doing so would pose a serious threat to someone's life or health, or unreasonably affect another person's privacy. If we refuse, we will tell you why in writing and explain how to complain.

If you are a patient, please direct requests about your clinical record to your hearing care clinic, which holds that record. We will support the clinic in responding.

16. Complaints

If you think we have breached the Australian Privacy Principles or otherwise mishandled your personal information, please contact our Privacy Officer:

Privacy Officer, CoHearent Pty Ltd Email: info@cohearent.com.au Post: Level 10, 2 Park St. Sydney NSW 20000 Australia

We will acknowledge your complaint within [5] business days and aim to resolve it within 30 days. If you are not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner:

Website: oaic.gov.au Phone: 1300 363 992 Post: GPO Box 5218, Sydney NSW 2001

17. Third-party links

Our website may link to third-party sites. We are not responsible for their content or privacy practices, and we encourage you to review their privacy policies before providing them with personal information.

18. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or the law. The current version is always published at cohearent.com.au/privacy, with the effective date shown at the top. Where changes are material, we will take reasonable steps to notify affected individuals and customers.

19. Contact us

CoHearent Pty Ltd ABN 28693063400 Level 10, 2 Park St., Sydney NSW] Email: info@cohearent.com.au Web: cohearent.com.au

This policy is available in an alternative format on request.