RIFT - billing leak detection RIKO - the AI front desk RISE - social media (coming soon) Is it for me? Security Philanthropy Blog Login Cart Free leak report
What we do

Trust, in the things that actually matter.

No vague badges - just concrete choices we've made in how RIKO and RIFT are built and run.

(01)

Your data stays in Australia

  • Your account data and conversation logs are stored in Australia (Sydney).
  • The live database is encrypted at rest - the data is scrambled on disk, not just protected by a password.
  • Backups are encrypted before they ever leave the server, and stored in Australia too.
  • Backups are restore-tested - so they actually work when they're needed.
(02)

Safety comes first

  • RIKO watches for crisis and sensitive moments and surfaces real help immediately.
  • Anything serious is handed straight to your team - the bot never tries to "handle" it.
  • A 10-type escalation system, with the triggers and sensitive topics set by you.
(03)

Private by design

  • Your patients' conversations are never used to train AI models.
  • Error monitoring is configured to exclude message content - no patient text leaves with it.
  • Your data is yours. Ask us to delete a customer's data, or all of it, any time.
(04)

Built for clinics, not bolted on

  • Works with Cliniko, Zanda and Calendly - the tools you already run on.
  • Trained only on your own website, documents and content - it answers as your practice.
  • Purpose-built for allied health and professional services, not a generic widget.
(05)

Privacy & legal, ready to go

  • Built and operated in compliance with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs).
  • Designed to help practices meet their AHPRA advertising obligations - the AI never makes unsubstantiated health claims or gives clinical advice.
  • Acceptance of terms is recorded per account, with the version and date.
  • A Data Processing Agreement is in place with every client - accepted at signup, recorded with its version, and published in full.
  • A Master Services Agreement is available on request.
(06)

You stay in control

  • Set the tone, the rules, the escalation triggers and the topics RIKO must never handle.
  • See every conversation in your dashboard - full visibility, nothing hidden.
  • White-labelled as your own practice, end to end.
(07)

RIFT reads, and never writes

  • Read-only on your practice management data. RIFT never writes to Zanda.
  • Clinical notes, case files, intake forms and diagnoses are excluded outright - not merely unused.
  • Your billing data is stored in Australia (Sydney), encrypted at rest, alongside everything else.
  • Patient contact details are held only while that patient has an open item on your recovery list.
(08)

Nothing goes to a patient without you

  • Every account reminder is drafted for your approval - nothing sends until you say so.
  • Reminders go out in your practice's name, using wording you control.
  • Hands-off sending exists, but only if you deliberately turn it on.
  • Every sent reminder is logged - what went out, to whom, and who approved it.
Full transparency

How your data is handled.

Plain English on what RIKO and RIFT touch, what they never touch, and where your data lives - the kind of detail your privacy officer will want to see.

Your patients' records stay in Cliniko & Zanda - untouched

When RIKO handles a booking it sends only the details the person gives the chatbot, through Cliniko's and Zanda's official, permission-based APIs - the appointment is created directly in Cliniko, while in Zanda - for practices with Zanda API access, which Zanda grants clinic by clinic during its API beta - the client record is created and your patient completes the booking in your own Zanda portal. It never reads, downloads, or stores your existing patient records, and our AI never sees them. We operate to the privacy and security standards those platforms require of their integration partners. Read why Zanda works this way →

What RIFT reads from your practice management system

RIFT is read-only. It never writes to Zanda and never changes anything in your system. It reads the billing side of your practice - clients, appointments, invoices, payments, invoice items, referrals, funding claims and session packs - to find work you completed but were never paid for. Clinical notes, case files, intake forms, diagnoses and patient communications are excluded outright, not merely left unread. The one piece of free text it reads is reception's scheduling notes on appointments, because a note like "paid $50 cash" is exactly how money goes missing from an invoice. Patient contact details are kept only while that patient has an open item on your recovery list, and removed automatically once they don't. Full detail in our Privacy Policy →

DataWhat it isHow we handle it
Your knowledge baseThe website content and documents you choose for your botStored in Australia (Sydney)
Bot conversationsQuestions visitors ask and the answers RIKO givesStored in Australia (Sydney), encrypted at rest; never used to train AI models
Patient dataSensitive information about your patients in Cliniko / ZandaNever read or stored by RIKO or its AI
AI repliesHow the bot turns your knowledge base into answersGenerated by a specialist AI provider; your data is never used to train AI models
BackupsEncrypted copies of your data, for recoveryEncrypted, stored in Australia (Sydney)
Practice billing records (RIFT)Appointments, invoices, payments, funding claims and session packs from your practice management systemRead-only; stored in Australia (Sydney), encrypted at rest; never used to train AI models
Clinical records (RIFT)Notes, case files, intake forms, diagnoses and patient communicationsNever read - excluded outright, not merely left unread
Patient contact details (RIFT)Names, emails and phone numbers needed to send an account reminderHeld only while that patient has an open item on your recovery list, then removed automatically
Social accounts (RISE)The Facebook, Instagram or LinkedIn pages you connect to RISEAccess keys encrypted at rest; RISE only publishes posts you've approved - it never reads your messages or followers' data
Common questions

What clinics ask us.

Do you train AI on our patients' conversations?

No. Your conversations are used to answer questions in the moment - they are never used to train AI models.

Where is our data stored?

Your account data, conversation logs and backups are stored in Australia (Sydney). The live database is encrypted at rest, and backups are encrypted before they leave the server.

Does RIKO read our patients' records in Cliniko or Zanda?

No. RIKO only sends the details someone gives the chatbot, through the platforms' official APIs - creating the appointment directly in Cliniko, or - for practices with Zanda API access - creating the client record in Zanda with your patient completing the booking in your Zanda portal. It never reads, downloads, or stores your existing patient records, and our AI never sees them.

What happens if a patient is in crisis?

RIKO is built to recognise crisis and self-harm language and respond immediately with real support options (including emergency and crisis-line details), rather than trying to handle it as a normal chat. It also alerts your team straight away so a person can follow up.

What does RISE (social media) get access to?

When RISE launches, connecting a social account grants it permission to publish posts only - through each platform's official login, with the access keys encrypted at rest. It writes from your website content and services, never from patient data, and nothing is published without your approval unless you switch on hands-off mode yourself.

Can we get a Data Processing Agreement?

You already have one. Our DPA is accepted at signup and recorded against your account with its version and date, so it is in force from the day you start - you can read it in full here. A Master Services Agreement (MSA) is available on request - just ask and we'll send it through.

Does RIFT change anything in our practice management system?

No. RIFT is read-only and never writes to Zanda. It reads the billing side of your practice to find work you completed but were never paid for, and everything it produces is a list for your team to action. Nothing in your system is altered.

Does RIFT read our clinical notes?

No. Clinical notes, case files, intake forms, diagnoses and patient communications are excluded outright, not merely left unread. The one piece of free text RIFT reads is reception's scheduling notes on appointments, because a note like "paid $50 cash" is exactly how money goes missing from an invoice.

Can RIFT email our patients without us knowing?

No. Every account reminder is drafted for your approval and nothing sends until you approve it. Reminders go out in your practice's name, using wording you control, and every one is logged with what was sent, to whom, and who approved it. Hands-off sending exists, but only if you deliberately turn it on.

Can we delete our data?

Yes. You can ask us to delete an individual customer's data, or all of your data, at any time - and we action it.

Is RIKO a medical device, or does it give medical advice?

No. RIKO answers questions about your practice (services, fees, hours, bookings) and escalates anything clinical or sensitive to your team. It does not provide medical, legal or financial advice.

Does RIKO help with AHPRA advertising compliance?

Yes. AHPRA's advertising guidelines prohibit unregistered practitioners from making unsubstantiated claims about treatment outcomes. RIKO is designed to stay well within those guidelines - it answers questions about your practice (services, fees, how to get started) and never makes clinical claims, promises outcomes, or gives health advice. If a question goes beyond what your content covers, it escalates to your team rather than guessing.

Want the detail for your compliance check?

Book a free intro call and we'll walk your team through exactly how RIKO handles your clinic's and patients' data - and send over the MSA/DPA if you need them.