Last updated: July 16, 2026
HolliHQ (“we”, “our”, or “us”) operates Holli, a practice management platform with a built-in AI assistant for holistic and complementary health practitioners. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.
We are based in Australia and handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where the EU General Data Protection Regulation (GDPR) applies to a user, we aim to meet its requirements as well.
Holli is currently in private beta. Features described in this policy may change as the product develops, and we will update this policy when they do.
Holli handles information about two groups of people:
When you use Holli's AI features, the relevant content (which may include client names, session notes, intake responses, and excerpts from your uploaded documents) is sent to OpenAI to generate the response. When you use live transcription, audio is sent to Deepgram for speech-to-text conversion.
We use these providers via their business APIs. Your data is not used to train their AI models. For more detail on how the AI assistant works, what it can and cannot do, and the consent requirements for recording, see our AI Policy.
All payments are processed by Stripe. Card details are entered directly on Stripe-hosted payment pages and are handled by Stripe under its own security standards (PCI DSS). Holli never receives or stores your card number.
Your data is stored with Supabase, our database, authentication, and file storage provider, in the Sydney, Australia region (AWS ap-southeast-2). The application itself is hosted on Vercel, which operates a global network.
To be clear about what we do not currently offer: Holli does not use end-to-end encryption (we and our infrastructure providers can technically access stored data in order to operate the service), and multi-factor authentication is not yet available. We have not yet commissioned an independent security audit or penetration test. We will update this policy as our security program matures.
We will never sell, rent, or trade your personal information or practice data to third parties for marketing purposes.
We share data with the following service providers, solely so they can help us operate Holli:
Each provider processes data under its own published data processing and security terms, and only for the purpose of providing its service to us. We review the providers we use and will update this list if it changes.
We may disclose information if required by law, court order, or subpoena, or where necessary to protect our rights, property, or safety, or the rights, property, or safety of others.
Your data is stored in Australia. However, some processing happens overseas: AI requests are processed by OpenAI and audio transcription by Deepgram, both based in the United States, and other providers (such as Vercel, Stripe, Resend, and Sentry) may process data in the United States or other countries where they operate. Where we disclose personal information overseas, we take reasonable steps as required by APP 8, including relying on our providers' contractual and security commitments.
If you are a client of a practitioner who uses Holli, your practitioner is responsible for the information they collect about you and enter into the platform. This includes obtaining your consent for collecting your information, recording or transcribing sessions, and generating AI-assisted notes or summaries about your sessions.
Under the Australian Privacy Principles (and the GDPR where it applies), you have the right to:
On data portability: Holli currently supports downloading individual generated documents (such as recaps, referral letters, and journey summaries) as PDFs. We do not yet offer a one-click bulk export of all practice data. If you need a copy of your data beyond what the application provides, contact us at hello@hollihq.com and we will work with you to provide it in a usable format.
We use essential cookies to keep you signed in and to keep the service secure. These include authentication tokens and session management cookies. The service does not work without them.
For analytics we use Vercel Analytics, which is designed to be privacy friendly. It does not use cookies, does not track you across other websites, and does not build advertising profiles. It records anonymised page views and a small set of product events (for example, that a document was uploaded) so we can understand how the platform is used in aggregate. We do not use third-party advertising or cross-site tracking cookies.
We are subject to the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required, and we will tell you what happened, what information was involved, and what we are doing about it.
Holli accounts are intended for practising professionals and are not directed at children. Practitioners are responsible for meeting their own legal and professional obligations when their practice involves clients who are minors, including obtaining consent from a parent or guardian where required. If you believe a child has provided personal information to us directly, please contact us and we will delete it.
We may update this Privacy Policy from time to time, especially while Holli is in beta. We will notify you of material changes by email or through the application. The “last updated” date at the top of this page always reflects the current version.
If you have questions about this Privacy Policy or how we handle your data, please contact us:
Email: hello@hollihq.com
Mail: HolliHQ, [Address], Australia
If you believe we have not handled your personal information appropriately, please contact us first at hello@hollihq.com so we can try to resolve it. You also have the right to lodge a complaint with: