Privacy Policy

Australia

Effective date: 26 August 2026

This Privacy Policy explains how DoulaOne, operated by Aku Online Limited (“DoulaOne”, “we”, “us”, or “our”), collects, holds, uses, and discloses personal information when you visit doulaone.com or use our practice-management platform (the “Service”). It applies to individuals in Australia. If you are in the United Kingdom, European Union, or European Economic Area, our UK/EU Privacy Policy applies instead; if you are in the United States, see our US Privacy Policy.

We handle personal information in accordance with the Privacy Act 1988(Cth) and the Australian Privacy Principles (“APPs”). DoulaOne is operated from the United Kingdom and our systems are hosted in the European Union — please read Section 7 before you enter client information.

1. Who is responsible for what

Information about you, site visitors, and enquiries. When you create an account, visit our website, or request a demo, we decide how and why your personal information is handled. This Policy describes that handling.

Information you enter about your clients. When you store client records, notes, contracts, birth preferences, intake forms, invoices, and documents in DoulaOne, your practice is responsible for that information and we hold it on your behalf to provide the Service. Our handling of it is governed by our Data Processing Agreement. You are responsible for telling your clients what you collect and why (an APP 5 collection notice), for obtaining consent where the Privacy Act requires it — which it generally does for health information — and for the accuracy of what you record.

If you are a client of a birth worker who uses DoulaOne and want to access, correct, or complain about information held about you, please contact that birth worker directly. We will assist them as the provider of their software.

2. The personal information we collect

Account and authentication

  • Name and email address
  • Password (stored securely via our authentication provider)
  • Google account information if you choose “Continue with Google” (email and basic profile details)
  • Workspace name, team membership, and role
  • Business details you add for invoicing, such as trading name, address, and your ABN

Practice and client information you enter

  • Client names, contact details, and due dates
  • Pipeline stage, appointments, and calendar information (including the timezone a family chose when they booked)
  • Care notes (prenatal, birth, postpartum), birth preferences, and follow-up records
  • Contracts, intake form responses, and e-signatures
  • E-signature audit information captured when a client signs a document (signer name, IP address, browser/user-agent, the signature image, and a tamper-evidence hash of the signed document)
  • Invoices, service packages, GST details, and payment records. Card details are handled by Stripe and are not stored by DoulaOne (see Section 10).
  • Documents and files you upload, and documents we generate for you
  • Messages and communications you record in the platform

Technical and usage information

  • IP address, browser type, device information, and access logs
  • Session and authentication cookies (see Section 17)
  • Error and performance data necessary to operate the Service
  • Approximate region derived from your IP address (country and timezone) so we can show AUD pricing and Australian defaults. We use hosting-provider location headers and, where needed, a lookup via ipapi.co.
  • First-party interaction counts on public profile and directory pages so birth workers can see how their public pages perform. These aggregate counts do not store your IP address or otherwise identify you.

Demo and enquiry information

When you request a demo, we collect the details you submit: your name, email, optional phone number, practice name, role, team size, and how you plan to use DoulaOne. We record whether you agreed to this Policy and whether you opted in to product updates. These records are kept only as long as needed to follow up and are then deleted automatically.

3. Sensitive information and health information

Birth work routinely involves health information, which is sensitive information under the Privacy Act. Pregnancy and birth details, care notes, and intake responses will usually fall into this category.

Under the APPs, sensitive information generally may only be collected with the individual's consent and where it is reasonably necessary for your functions or activities. Because your practice — not DoulaOne — decides what to record about a client, you are responsible for obtaining that consent and for telling your clients that their information will be stored in a practice-management platform hosted overseas.

To help you protect this information, DoulaOne provides workspace isolation enforced in the database, notes that can be restricted to the workspace owner, consent-gated and reduced access for backup doulas, and private document storage. Optional AI features are off unless a workspace owner turns them on.

The only sensitive information we collect about you as an account holder is your log-in credentials, used solely to secure and provide the Service.

4. How and why we use personal information

We use personal information to:

  • Create, secure, and manage your account and workspace
  • Provide, maintain, and improve the Service
  • Authenticate you and keep your session secure
  • Store and display the practice information you enter
  • Enable client-facing features such as contract signing and intake forms
  • Process subscription billing and, where you enable it, online client payments through Stripe
  • Detect your approximate region to show AUD pricing and Australian defaults
  • Send transactional emails you request, such as appointment reminders
  • Sync appointments to Google Calendar, Zoom, or Calendly where you connect them
  • Respond to demo requests and support enquiries
  • Detect, prevent, and address fraud, abuse, and security incidents
  • Comply with our legal obligations and enforce our Terms of Service
  • Understand how birth workers use features so we can improve the product (feature-usage metadata only — never your clients' content or health information)

We use personal information only for the purpose we collected it for, for a directly related purpose you would reasonably expect, or where you have consented or the law permits or requires it. We do not use personal information to make automated decisions that have legal or similarly significant effects on you.

Product analytics.To improve DoulaOne, we collect privacy-conscious analytics about how you (the birth worker) use the app — for example, that an invoice was created or an appointment was scheduled. This is collected server-side, tied to a pseudonymous account identifier, and does notinclude your clients' names, contact details, notes, or any health information, and it does not set cookies on your device. You can turn it off under Settings → Privacy.

5. Direct marketing

We send marketing or newsletter emails only where you have opted in — for example by joining our waitlist, subscribing to our directory newsletter, or ticking the updates box when requesting a demo. Every marketing email identifies us and includes a working unsubscribe link, as required by the Spam Act 2003 (Cth), and we action unsubscribe requests promptly.

You can also opt out at any time by emailing contact@doulaone.com or changing your notification preferences in Settings. Opting out of marketing does not affect the transactional emails required to operate your account.

We do not sell personal information, we do not disclose it to third parties for their own direct marketing, and we do not use third-party advertising trackers.

6. Who we disclose personal information to

We disclose personal information to the service providers below, which process it on our behalf under written agreements limiting their use of it:

  • Supabase— database, authentication, and file storage (European Union, Paris region)
  • Vercel— website and application hosting
  • Brevo— transactional email and, where you opt in, marketing email
  • Stripe— subscription billing and optional online client payments
  • Mapbox— map display on our public birth worker directory
  • ipapi.co— IP-based region lookup, used only where hosting-provider location data is unavailable
  • Google, Zoom, Calendly, and OpenAI — optional integrations, used only if you connect or enable them (see Sections 8 and 9)
  • Mixpanel— privacy-conscious analytics, stored in the EU; on public pages only after you opt in, and in-app for feature-usage metadata only

We may also disclose personal information where required or authorised by law, to respond to lawful requests, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets.

7. Overseas disclosure (APP 8)

DoulaOne stores information outside Australia. Our database, authentication, and file storage run in the European Union (Supabase, Paris region), and we operate from the United Kingdom. By using the Service you acknowledge that the information you enter, including your clients' health information, will be disclosed to and held by recipients in those countries.

The service providers listed in Section 6 may also handle information in other countries, including the United States and countries in the European Union and the United Kingdom.

Before disclosing personal information overseas we take steps that are reasonable in the circumstances to ensure the recipient does not breach the APPs, including entering written agreements that require them to protect the information, use it only on our instructions, and keep it confidential. You should be aware that we may not be able to guarantee that an overseas recipient will handle personal information in the way an Australian entity would, and that enforcing Australian privacy protections against an overseas recipient may be difficult.

You can request details of the safeguards we rely on for a particular provider by emailing contact@doulaone.com. If your practice, funding body, or professional association requires Australian-only data residency, please contact us before storing client information in the Service.

8. Google user data

This section describes how DoulaOne accesses, uses, stores, and deletes information received from Google when you use Continue with Google to sign in or connect Google Calendar in Settings. Both are optional and require your consent.

Data accessed. With your permission, we may access your Google account email (userinfo.email), basic profile information if you sign in with Google, Google Calendar events (calendar.events) only when you connect Google Calendar, and the OAuth tokens Google issues so the integration can operate.

How we use it.We use Google user data only to authenticate you, to sync appointments you create in DoulaOne to your Google Calendar (one-way — we do not read or import your existing events), to optionally add Google Meet links, to show which account is connected, and to operate and troubleshoot these features. We do not use Google user data for advertising, profiling, or to train artificial intelligence or machine learning models, and we do not sell it.

DoulaOne's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Retention and deletion. We keep Google tokens and connection data only while the integration is connected. Click Disconnectunder Settings → Integrations to delete the stored tokens, or revoke access at myaccount.google.com/permissions.

9. Zoom and Calendly

Zoom. When you connect Zoom, we access your Zoom account email to show which account is connected, create scheduled meetings for appointments you book in DoulaOne, and store the OAuth tokens Zoom issues. We do not read your existing meetings, join meetings on your behalf, or access recordings or transcripts.

Calendly.When you connect Calendly, we access your account email and OAuth tokens and register a webhook so Calendly can notify us of new and cancelled bookings. For each booking we receive the invitee's name, email address, event name, and scheduled time, which we use to create or update a matching client and appointment.

We do not sell Zoom or Calendly data or use it for advertising, profiling, or model training. Tokens are kept only while the integration is connected and are deleted when you disconnect it under Settings → Integrations.

10. Payments (Stripe)

We use Stripe to process payments. Stripe handles card and transaction data under its own privacy policy. DoulaOne does not receive or store full card numbers.

When you subscribe to a paid plan, Stripe processes your payment method and billing details and we store references such as your Stripe customer and subscription IDs, plan, billing status, and renewal dates. If you enable online client payments, you connect your own Stripe account and become the merchant for payments your clients make to you; Stripe collects their payment details directly and we record the payment status and Stripe references against the invoice. A processing fee (including Stripe's card processing) is taken from your payout as described in our Terms.

11. Security (APP 11)

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure, including:

  • Row-level security isolating each workspace's data
  • Private, access-controlled file storage with signed URLs
  • Encryption in transit (HTTPS/TLS) and encryption at rest
  • Server-side authentication, session controls, and idle logout
  • Owner-only access controls for sensitive notes
  • Restricted access to production systems and secrets

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. We take reasonable steps to destroy or de-identify personal information once it is no longer needed for any purpose for which it may be used or disclosed and we are not required by law to retain it.

12. Data breaches

If we become aware of unauthorised access to, unauthorised disclosure of, or loss of personal information, we will assess the incident promptly and take steps to contain and remediate it.

Where an eligible data breach affects information we hold on your behalf, we will notify you without undue delay and give you the information reasonably available to us so you can meet your own obligations under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act, including any assessment and any notification to affected individuals and the Office of the Australian Information Commissioner (OAIC). Where a breach concerns information we handle in our own right, we will assess and notify as required. Notifying you of an incident is not an admission of fault or liability.

13. How long we keep information

We keep your account and workspace information for as long as your account is active. If you close your account, we delete or de-identify your information within a reasonable period, except where we must retain it to comply with the law, resolve disputes, prevent fraud, or enforce our agreements.

Client information you store in DoulaOne is retained according to your instructions and our Terms of Service. You can export or delete it through the platform at any time. Note that your own record-keeping obligations — including any professional, insurance, or state and territory health-records requirements that apply to your practice — are yours to determine and meet.

Automated jobs also delete demo and enquiry records, support messages, email event logs, and stored email bodies on fixed schedules.

14. Access and correction (APP 12 and APP 13)

You can ask us for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant, or misleading. Most of it is available directly in the app: you can edit your profile and workspace details, export your full workspace as JSON from Settings, and delete individual clients or your entire account.

To make a request, email contact@doulaone.com from the address associated with your account. We will verify your identity, respond within a reasonable period (usually within 30 days), and will not charge you for making a request. If we refuse access or correction, we will tell you why in writing and how to complain.

If you are a client of a birth worker who uses DoulaOne, direct your access or correction request to that birth worker, who controls the record. We will assist them in responding.

15. Complaints

If you think we have breached the Australian Privacy Principles or mishandled your personal information, please contact us first at contact@doulaone.com with “Privacy complaint” in the subject line. We will acknowledge your complaint, investigate it, and respond in writing, normally within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:

16. Anonymity and identifiers

You can browse our public pages without telling us who you are. An account is required to use the Service itself, because the platform exists to keep identifiable practice records, so it is not practicable to offer DoulaOne accounts anonymously or under a pseudonym.

We do not collect or use government related identifiers such as Tax File Numbers, Medicare numbers, or driver licence numbers, and we do not use them as our own identifiers. The ABN you may add for invoicing is business information you choose to display on your own invoices.

17. Cookies and similar technologies

We use essential cookies and local storage required for authentication, session management, security, and remembering your preferences. These are strictly necessary for the Service to function.

With your opt-in through our cookie banner, we also use Mixpanel for privacy-conscious analytics on our public pages. We do not use third-party advertising cookies. A Global Privacy Control signal is treated as a rejection of analytics cookies. You can change your choices at any time via Manage cookies in the footer.

Inside the app, our product analytics are collected server-side and do notuse cookies. They never include your clients' information or any health information, and you can turn them off under Settings → Privacy.

18. Children

The Service is intended for professional use by adults and is not directed at children. We do not knowingly collect personal information directly from children. Information a birth worker records about a baby or a young family member forms part of their client record, and the birth worker is responsible for collecting it appropriately.

19. Third-party links

The Service may link to third-party websites and services we do not control. This Policy does not apply to them, and we encourage you to review their privacy notices.

20. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. For material changes, we will provide notice through the Service or by email where appropriate.

21. Contact us

For privacy questions, access and correction requests, or complaints:

contact@doulaone.com

Aku Online Limited, 167-169 Great Portland Street, London, W1W 5PF, United Kingdom

See also our Terms of Service and Data Processing Agreement.