Omi Scribe Cloud — Australia and New Zealand Privacy Addendum

Version: 1.1

Effective: 14 May 2026

Provider: Omi Health B.V., Eindhoven, Netherlands

Australian entity (sales/contracting): Omi Health Pty Ltd, Perth, Australia

Contact: [email protected] · [email protected]


This addendum supplements the Omi Scribe Cloud — Privacy Notice at /legal/cloud-privacy and the Omi Scribe Cloud — Data Processing Addendum (DPA) for Customers established in, or processing personal information subject to the laws of, Australia or New Zealand.

Where this addendum conflicts with the Privacy Notice or DPA, this addendum controls for ANZ personal information.


1. Applicable law

Australia

New Zealand


2. Hosting

ANZ Customers using the cloud version are served from the cloud deployment in Azure Sweden Central (EU) under GDPR. The cloud Service runs in any modern browser and stores Customer Content in the EU under the technical and organisational measures described in the Privacy Notice.

2.1 Local data residency options

For Customers requiring data residency in Australia or New Zealand, two options are available:


3. International transfers (cloud version)

3.1 Customer Content

Customer Content of ANZ Customers using the cloud version is stored and processed in Azure Sweden Central (EU). The following technical and organisational measures protect Customer Content during processing and any authorised remote support access:

3.2 APP 8 (Cross-border disclosure)

For Australian Customers using the cloud version, disclosure to Microsoft Corporation as the cloud sub‑processor in the EU is treated as a cross‑border disclosure under APP 8 of the Privacy Act 1988. Omi Health takes the following reasonable steps to ensure overseas recipients do not breach the APPs:

Customers requiring data residency within Australia should select the on‑device Mac option or customer‑managed self‑hosted in their own tenant.

3.3 NZ IPP 12 (Disclosure of personal information outside New Zealand)

For New Zealand Customers using the cloud version, disclosure of Customer Content to Microsoft Corporation as the cloud sub‑processor in the EU is treated as a disclosure outside New Zealand under IPP 12 of the Privacy Act 2020. Omi Health relies on:

Customers requiring data residency within New Zealand should select the on‑device Mac option or customer‑managed self‑hosted in their own tenant.


4. Notifiable data breaches

4.1 Australia (NDB scheme)

Where a data breach occurs that is likely to result in serious harm to one or more individuals, Omi Health will, without undue delay:

1. Notify the affected Customer in accordance with the DPA

2. Provide the Customer with the information required to make an eligible data breach notification under Part IIIC of the Privacy Act

3. Assist the Customer in any notification to the Office of the Australian Information Commissioner (OAIC) at https://oaic.gov.au

Where Omi Health is the entity required to notify under Part IIIC (for example, where Omi Health is the APP entity in respect of its own Service Data), Omi Health will notify the OAIC and affected individuals as required.

4.2 New Zealand (Privacy Act 2020 Part 6)

Where a notifiable privacy breach occurs in respect of Customer Content of an NZ Customer, Omi Health will:

1. Notify the Customer in accordance with the DPA

2. Assist the Customer in any notification to the Office of the Privacy Commissioner at https://privacy.org.nz and to affected individuals


5. Supervisory authorities and complaints

ANZ data subjects may exercise rights of access and correction by contacting [email protected]. Where Omi Health is a Processor for Customer Content, data subject requests should be directed to the Customer (the Controller) in the first instance; Omi Health will assist the Controller in fulfilling such requests as required by the DPA.


6. My Health Record and ADHA conformance

Where Customer Content includes information from the My Health Record system:

Omi Health will support customer audits, DSPT-equivalent self‑assessments, and DPIA inputs on request under NDA.


7. Aboriginal and Torres Strait Islander health data

Customers handling health information relating to Aboriginal and Torres Strait Islander peoples are subject to additional principles, including the AIATSIS Code of Ethics, Maiam nayri Wingara Indigenous Data Sovereignty Principles, and (where applicable) state-level guidance. Omi Health does not make secondary use of any Customer Content. The Customer retains full control over consent, governance, and use of Indigenous health data within the Service.


8. Sub‑processors

The list of sub‑processors at /legal/sub-processors applies. The cloud Service is hosted in Azure Sweden Central (EU); the sub‑processor list reflects this single deployment.


9. Liability and order of precedence

In the event of conflict between this addendum and the Privacy Notice or DPA, this addendum controls for ANZ personal information. All other terms of the Privacy Notice and DPA remain in full force and effect.


10. Contact

Omi Health Pty Ltd — Perth, Australia

Omi Health B.V. — Eindhoven, Netherlands