Back to home

Privacy Policy

Last updated: July 16, 2026

Introduction

HolliHQ (“we”, “our”, or “us”) operates Holli, a practice management platform with a built-in AI assistant for holistic and complementary health practitioners. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.

We are based in Australia and handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where the EU General Data Protection Regulation (GDPR) applies to a user, we aim to meet its requirements as well.

Holli is currently in private beta. Features described in this policy may change as the product develops, and we will update this policy when they do.

Who This Policy Covers

Holli handles information about two groups of people:

  • Practitioners: people who create a Holli account to run their practice. We collect their information directly when they sign up and use the platform.
  • Clients of practitioners: people whose information a practitioner enters into Holli, or who submit information themselves through a practitioner's public booking page or intake form. Clients do not have Holli accounts. See the “Clients of Practitioners” section below for how this works.

Information We Collect

Practitioner Account Information

  • Name and email address
  • Password (stored as a secure hash, never in plain text)
  • Practice details, professional credentials, and branding (business name, logo, signature, brand tone)
  • Subscription and billing records (see “Payments and Billing” below)

Practice Data Entered by Practitioners

  • Client records (names, contact details, notes, and health-related information the practitioner enters)
  • Session notes, live transcripts (where the transcription feature is used with consent), and session summaries
  • Documents uploaded to the knowledge base (PDFs, Word documents, and similar files) and the search indexes built from them
  • Chat history with the Holli assistant, including AI-generated drafts and documents
  • Intake forms, booking settings, and calendar data

Information Submitted by Clients

  • Booking requests submitted through a practitioner's public booking page (name, email, phone, preferred time, notes)
  • Intake form responses submitted through a practitioner's shared intake link, which may include health-related information the practitioner has chosen to ask about

Usage and Technical Information

  • Log data such as IP address, browser type, and pages visited
  • Aggregate product usage events (for example, that a document was uploaded or a chat query was sent) via Vercel Analytics
  • Error reports and diagnostic data via Sentry, our error monitoring service
  • Rate-limit and security logs

How We Use Your Information

  • Provide the service: store your practice data, generate AI-assisted drafts and summaries, manage bookings and intake, and produce documents
  • Improve the service: understand aggregate usage patterns to fix problems and improve features
  • Communicate: send transactional emails (booking notifications, intake confirmations, account emails), service updates, and support responses
  • Billing: manage subscriptions and payments through Stripe
  • Security: detect and prevent fraud, abuse, and security incidents
  • Legal compliance: meet our legal obligations and enforce our terms

AI Processing

When you use Holli's AI features, the relevant content (which may include client names, session notes, intake responses, and excerpts from your uploaded documents) is sent to OpenAI to generate the response. When you use live transcription, audio is sent to Deepgram for speech-to-text conversion.

We use these providers via their business APIs. Your data is not used to train their AI models. For more detail on how the AI assistant works, what it can and cannot do, and the consent requirements for recording, see our AI Policy.

Payments and Billing

All payments are processed by Stripe. Card details are entered directly on Stripe-hosted payment pages and are handled by Stripe under its own security standards (PCI DSS). Holli never receives or stores your card number.

  • Subscriptions: when a practitioner subscribes to a Holli plan, we store the subscription status, plan, and Stripe customer reference so we can manage the account. Invoices and payment methods are managed in Stripe's customer portal.
  • Client booking payments: practitioners can optionally connect their own Stripe account to collect payment when a client books. In that case the client pays the practitioner directly, the practitioner is the merchant of record, and the payment appears on the practitioner's Stripe account. Holli stores the payment status of the booking (for example, paid or unpaid) but not the card details.

Data Storage & Security

Where Your Data Is Stored

Your data is stored with Supabase, our database, authentication, and file storage provider, in the Sydney, Australia region (AWS ap-southeast-2). The application itself is hosted on Vercel, which operates a global network.

Security Measures

  • Encryption in transit (TLS) for all connections to the platform
  • Encryption at rest provided by our infrastructure providers
  • Row-level security in the database, so practitioners can only access their own data (with defined exceptions for clinic managers within a clinic)
  • Passwords stored as secure hashes
  • Rate limiting on API endpoints and AI features
  • Automated database backups

To be clear about what we do not currently offer: Holli does not use end-to-end encryption (we and our infrastructure providers can technically access stored data in order to operate the service), and multi-factor authentication is not yet available. We have not yet commissioned an independent security audit or penetration test. We will update this policy as our security program matures.

Data Sharing & Service Providers

We Do Not Sell Your Data

We will never sell, rent, or trade your personal information or practice data to third parties for marketing purposes.

Service Providers (Subprocessors)

We share data with the following service providers, solely so they can help us operate Holli:

  • Supabase: database, authentication, and file storage (data stored in Sydney, Australia)
  • OpenAI: AI language model processing for chat, summaries, and document generation (processed in the United States; not used for model training)
  • Deepgram: speech-to-text transcription for live sessions (processed in the United States)
  • Vercel: application hosting, content delivery, and privacy-focused analytics
  • Stripe: payment and subscription processing
  • Resend: transactional email delivery (booking, intake, and referral emails)
  • Sentry: error monitoring and diagnostics

Each provider processes data under its own published data processing and security terms, and only for the purpose of providing its service to us. We review the providers we use and will update this list if it changes.

Legal Requirements

We may disclose information if required by law, court order, or subpoena, or where necessary to protect our rights, property, or safety, or the rights, property, or safety of others.

Cross-Border Data Transfers

Your data is stored in Australia. However, some processing happens overseas: AI requests are processed by OpenAI and audio transcription by Deepgram, both based in the United States, and other providers (such as Vercel, Stripe, Resend, and Sentry) may process data in the United States or other countries where they operate. Where we disclose personal information overseas, we take reasonable steps as required by APP 8, including relying on our providers' contractual and security commitments.

Clients of Practitioners

If you are a client of a practitioner who uses Holli, your practitioner is responsible for the information they collect about you and enter into the platform. This includes obtaining your consent for collecting your information, recording or transcribing sessions, and generating AI-assisted notes or summaries about your sessions.

  • You interact with Holli only through public booking pages and intake forms shared by your practitioner. You do not need, and cannot create, a Holli account.
  • Information you submit is stored against your practitioner's account and is only accessible to them (and their clinic, if they practise within one on Holli).
  • To access, correct, or delete information held about you, contact your practitioner. Practitioners can view, edit, and delete client records, sessions, and transcripts within the platform. If you cannot resolve a request with your practitioner, you can contact us at hello@hollihq.com and we will help where we can.

Data Retention & Deletion

  • While your account is active: we retain your account and practice data so the service works for you.
  • In-app deletion: practitioners can delete individual clients, sessions, and transcripts at any time from within the application.
  • Account deletion: practitioners can delete their account from account settings (with email confirmation). This removes the authentication record and cleans up stored files. We aim to permanently remove remaining personal data within 30 days of account deletion, except where we are required by law to retain records.
  • Backups: deleted data may persist in encrypted backups for a limited period before those backups expire.

Your Rights & Choices

Under the Australian Privacy Principles (and the GDPR where it applies), you have the right to:

  • Access: request a copy of the personal information we hold about you
  • Correction: update inaccurate or incomplete information, either in the application or by contacting us
  • Deletion: delete your account and data as described above
  • Opt out: unsubscribe from non-essential communications

On data portability: Holli currently supports downloading individual generated documents (such as recaps, referral letters, and journey summaries) as PDFs. We do not yet offer a one-click bulk export of all practice data. If you need a copy of your data beyond what the application provides, contact us at hello@hollihq.com and we will work with you to provide it in a usable format.

Cookies & Analytics

We use essential cookies to keep you signed in and to keep the service secure. These include authentication tokens and session management cookies. The service does not work without them.

For analytics we use Vercel Analytics, which is designed to be privacy friendly. It does not use cookies, does not track you across other websites, and does not build advertising profiles. It records anonymised page views and a small set of product events (for example, that a document was uploaded) so we can understand how the platform is used in aggregate. We do not use third-party advertising or cross-site tracking cookies.

Data Breach Notification

We are subject to the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required, and we will tell you what happened, what information was involved, and what we are doing about it.

Children's Privacy

Holli accounts are intended for practising professionals and are not directed at children. Practitioners are responsible for meeting their own legal and professional obligations when their practice involves clients who are minors, including obtaining consent from a parent or guardian where required. If you believe a child has provided personal information to us directly, please contact us and we will delete it.

Changes to This Policy

We may update this Privacy Policy from time to time, especially while Holli is in beta. We will notify you of material changes by email or through the application. The “last updated” date at the top of this page always reflects the current version.

Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us:

Email: hello@hollihq.com

Mail: HolliHQ, [Address], Australia

Complaints

If you believe we have not handled your personal information appropriately, please contact us first at hello@hollihq.com so we can try to resolve it. You also have the right to lodge a complaint with:

  • Australia: Office of the Australian Information Commissioner (OAIC) atwww.oaic.gov.au
  • EU: your local data protection authority

Related Policies