Skip to content
moirai
Product
Pricing
Buyers
Follow-up previewSynthetic follow-up evidence loopSecurityPrivacy and control posturePublic verifierHash-only evidence lookup
Research
Demo
Take the tour15-minute compatibility loopInteractive demoFollow-up status walkthroughBlogEvidence and operations notes
About
Sign inVerifyPreview
Menu
ProductPricing
Buyers
OverviewFollow-up previewSecurityPublic verifier
Research
Demo
OverviewTake the tourInteractive demoBlog
About
Sign inPreviewOpen Follow-up Preview
placeholder
Public ledger · Live
12 most recent records · click to verifyVerify a hash →
f60d…6495CXR-2026-0847
f60de9172ecabc80520a858d55dfbed0e2b81592e14e977747adba47ec416495
caseCXR-2026-0847toolAnnalise CXRsealed2026-05-07 04:03:00Z · 1h agoprevGENESIS
Click to verify →
0ee5…d64bBCT-2026-0848
0ee5c76a771351aeb9f5789dca3cae2ea0d17b927bccf4234c543667998ed64b
caseBCT-2026-0848toolAidoc PE Detectionsealed2026-05-07 04:12:00Z · 1h agoprevf60de9…416495
Click to verify →
8d13…8a63MMG-2026-0849
8d13c08f55491bceb02cfa16c2ab998182e7c8cc0430d353d50d33be1c238a63
caseMMG-2026-0849toolLunit INSIGHTsealed2026-05-07 04:24:00Z · 1h agoprev0ee5c7…8ed64b
Click to verify →
26dc…0b39BCT-2026-0850
26dca762f427713a5a07bb7a007d140efd6c2b707840f9518a37b664e39a0b39
caseBCT-2026-0850toolHarrison CT Brainsealed2026-05-07 04:31:00Z · 1h agoprev8d13c0…238a63
Click to verify →
c46d…c0f1MRI-2026-0851
c46d98269a4511d23796f04dda7bb4c23097f4d30fb38975ad3fd15bb587c0f1
caseMRI-2026-0851toolBehold MRI Spinesealed2026-05-07 04:35:00Z · 1h agoprev26dca7…9a0b39
Click to verify →
ff8b…6ff8CXR-2026-0852
ff8b19d90abe87a193139a04ea3e2f8dd63c952ad7a71ba6aeabf82fe4606ff8
caseCXR-2026-0852toolAnnalise CXRsealed2026-05-07 04:53:00Z · 47m agoprevc46d98…87c0f1
Click to verify →
fcf0…e6dfCXR-2026-0853
fcf0d27e31534501679a76f801e9291abd85149ffdc999941194a3c93855e6df
caseCXR-2026-0853toolEnlitic Curiesealed2026-05-07 05:04:00Z · 36m agoprevff8b19…606ff8
Click to verify →
febb…06bfBCT-2026-0854
febba551c829cb79d994e89ad476d1f9c7772d7d79cb1e315bab55d7132406bf
caseBCT-2026-0854toolAidoc PE Detectionsealed2026-05-07 05:10:00Z · 30m agoprevfcf0d2…55e6df
Click to verify →
da0c…0f60MMG-2026-0855
da0c4d1526765c82512b24518182cea1d286d3ca170d6115dedc0cc2b7c80f60
caseMMG-2026-0855toolLunit INSIGHTsealed2026-05-07 05:13:00Z · 27m agoprevfebba5…2406bf
Click to verify →
e5e1…a25aMRI-2026-0856
e5e1bce89de66f165094659458f7fb6754f25deaf6ad5bede7ca75a586aea25a
caseMRI-2026-0856toolBehold MRI Kneesealed2026-05-07 05:27:00Z · 13m agoprevda0c4d…c80f60
Click to verify →
6614…b55aBCT-2026-0857
6614270dbc4b3897b06f125b16af3269ecaf29183809961e53803c1bd46db55a
caseBCT-2026-0857toolHarrison CT Brainsealed2026-05-07 05:35:00Z · 5m agopreve5e1bc…aea25a
Click to verify →
2a97…ffe3CXR-2026-0858
2a971540cfd15abf745fd77c58b214a45ef5af5788f861d81ca7549930b5ffe3
caseCXR-2026-0858toolAnnalise CXRsealed2026-05-07 05:40:00Z · 0s agoprev661427…6db55a
Click to verify →
f60d…6495CXR-2026-0847
f60de9172ecabc80520a858d55dfbed0e2b81592e14e977747adba47ec416495
caseCXR-2026-0847toolAnnalise CXRsealed2026-05-07 04:03:00Z · 1h agoprevGENESIS
Click to verify →
0ee5…d64bBCT-2026-0848
0ee5c76a771351aeb9f5789dca3cae2ea0d17b927bccf4234c543667998ed64b
caseBCT-2026-0848toolAidoc PE Detectionsealed2026-05-07 04:12:00Z · 1h agoprevf60de9…416495
Click to verify →
8d13…8a63MMG-2026-0849
8d13c08f55491bceb02cfa16c2ab998182e7c8cc0430d353d50d33be1c238a63
caseMMG-2026-0849toolLunit INSIGHTsealed2026-05-07 04:24:00Z · 1h agoprev0ee5c7…8ed64b
Click to verify →
26dc…0b39BCT-2026-0850
26dca762f427713a5a07bb7a007d140efd6c2b707840f9518a37b664e39a0b39
caseBCT-2026-0850toolHarrison CT Brainsealed2026-05-07 04:31:00Z · 1h agoprev8d13c0…238a63
Click to verify →
c46d…c0f1MRI-2026-0851
c46d98269a4511d23796f04dda7bb4c23097f4d30fb38975ad3fd15bb587c0f1
caseMRI-2026-0851toolBehold MRI Spinesealed2026-05-07 04:35:00Z · 1h agoprev26dca7…9a0b39
Click to verify →
ff8b…6ff8CXR-2026-0852
ff8b19d90abe87a193139a04ea3e2f8dd63c952ad7a71ba6aeabf82fe4606ff8
caseCXR-2026-0852toolAnnalise CXRsealed2026-05-07 04:53:00Z · 47m agoprevc46d98…87c0f1
Click to verify →
fcf0…e6dfCXR-2026-0853
fcf0d27e31534501679a76f801e9291abd85149ffdc999941194a3c93855e6df
caseCXR-2026-0853toolEnlitic Curiesealed2026-05-07 05:04:00Z · 36m agoprevff8b19…606ff8
Click to verify →
febb…06bfBCT-2026-0854
febba551c829cb79d994e89ad476d1f9c7772d7d79cb1e315bab55d7132406bf
caseBCT-2026-0854toolAidoc PE Detectionsealed2026-05-07 05:10:00Z · 30m agoprevfcf0d2…55e6df
Click to verify →
da0c…0f60MMG-2026-0855
da0c4d1526765c82512b24518182cea1d286d3ca170d6115dedc0cc2b7c80f60
caseMMG-2026-0855toolLunit INSIGHTsealed2026-05-07 05:13:00Z · 27m agoprevfebba5…2406bf
Click to verify →
e5e1…a25aMRI-2026-0856
e5e1bce89de66f165094659458f7fb6754f25deaf6ad5bede7ca75a586aea25a
caseMRI-2026-0856toolBehold MRI Kneesealed2026-05-07 05:27:00Z · 13m agoprevda0c4d…c80f60
Click to verify →
6614…b55aBCT-2026-0857
6614270dbc4b3897b06f125b16af3269ecaf29183809961e53803c1bd46db55a
caseBCT-2026-0857toolHarrison CT Brainsealed2026-05-07 05:35:00Z · 5m agopreve5e1bc…aea25a
Click to verify →
2a97…ffe3CXR-2026-0858
2a971540cfd15abf745fd77c58b214a45ef5af5788f861d81ca7549930b5ffe3
caseCXR-2026-0858toolAnnalise CXRsealed2026-05-07 05:40:00Z · 0s agoprev661427…6db55a
Click to verify →
moirai

The evidentiary backbone for clinical AI oversight. Built around current Australian governance references.

Stay informed

Monthly digest of regulatory changes and clinical AI best practices.

Platform

  • Overview
  • Security
  • Trust Center
  • Pricing
  • Changelog
  • Demo

Proof

  • Research Ledger
  • Follow-up Preview
  • Public Verifier

Resources

  • Follow-up Preview
  • Security
  • Blog

Company

  • About
  • Contact
  • System Status

AU data sovereignty·Encryption at rest & in transit·Trust Center →

Trust signals

Hash VerifiedSHA-256 sealed
Enterprise SecurityAES-256, RLS, audit
External RefsRANZCR, TGA, Ahpra
Risk ControlsMonitoring + incidents
on the record.
Mapped toRANZCRChapter 9TGASaMDAhpraAI obligationsACSQHCNSQHSDISRAI plan
© 2026 Moirai Health Pty Ltd. All rights reserved.
Privacy PolicyTerms of ServiceSecurityTrust CenterDPA
All systems operational

Legal

Data Processing Agreement

Last updated: 28 March 2026

Contents

1. Parties & Scope2. Definitions3. Data Processing Details4. Processor Obligations5. Security Measures6. Sub-processors7. International Transfers8. Data Subject Rights9. Breach Notification10. Audits11. Term & Termination12. Governing Law13. Contact

1. Parties & Scope

This Data Processing Agreement ("DPA") forms part of the Service Agreement between Moirai Health Pty Ltd (ABN pending), a company incorporated under the laws of Australia with its registered office in Canberra, ACT ("Processor", "Moirai", "we", "us"), and the entity that has executed the Service Agreement ("Controller", "Customer", "you").

This DPA applies to the Processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the Moirai clinical AI governance infrastructure (the "Service"). It reflects the parties' commitment to comply with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles ("APPs"), and where applicable, the EU General Data Protection Regulation ("GDPR").

In the event of any conflict between this DPA and the Service Agreement, this DPA shall prevail with respect to the Processing of Personal Data.

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person that is Processed by the Processor on behalf of the Controller in connection with the Service.
  • "Processing" means any operation or set of operations performed on Personal Data, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.
  • "Sub-processor" means any third party engaged by the Processor to Process Personal Data on behalf of the Controller in connection with the Service.
  • "Data Subject" means the identified or identifiable natural person to whom the Personal Data relates.
  • "Controller" means the entity that determines the purposes and means of Processing Personal Data, being the Customer under the Service Agreement.
  • "Processor" means the entity that Processes Personal Data on behalf of the Controller, being Moirai Health Pty Ltd.
  • "Data Breach" means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data transmitted, stored, or otherwise Processed by the Processor.

3. Data Processing Details

Subject matterProvision of the Moirai clinical AI governance infrastructure, including tool registration, compliance tracking, policy management, evidence storage, and reporting.
DurationFor the term of the Service Agreement, plus any period required for data deletion or return as specified in Section 11.
Nature & purposeProcessing Personal Data as necessary to provide, maintain, and improve the Service, including user authentication, access control, governance record-keeping, compliance scoring, report generation, and customer support.
Types of dataUser account information (name, email, role), practice details (practice name, address, ABN), AI tool metadata (tool names, vendors, risk classifications, deployment dates), governance documents (policies, evidence records, compliance assessments), and usage/audit logs.
Categories of Data SubjectsPractice staff (clinicians, administrators, IT personnel), practice administrators and authorised users of the Service.

Important note: Moirai is designed to process practice-level governance and compliance data. The Service is not intended to process, and the Customer shall not submit, Protected Health Information (PHI), patient records, or individually identifiable health information through the platform.

4. Processor Obligations

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data outside Australia, unless required to do so by applicable law. In such case, the Processor shall inform the Controller of that legal requirement before Processing, unless prohibited by law.
  • Ensure that persons authorised to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as detailed in Section 5.
  • Assist the Controller, taking into account the nature of the Processing, by appropriate technical and organisational measures insofar as possible, in fulfilling the Controller's obligations to respond to Data Subject requests under the Australian Privacy Act and APPs.
  • Assist the Controller in ensuring compliance with breach notification obligations, taking into account the nature of Processing and the information available to the Processor.
  • At the choice of the Controller, delete or return all Personal Data to the Controller upon termination of the Service Agreement, and delete existing copies unless applicable law requires retention.
  • Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, as detailed in Section 10.
  • Immediately inform the Controller if, in the Processor's opinion, an instruction from the Controller infringes applicable data protection legislation.

5. Security Measures

The Processor implements and maintains the following technical and organisational security measures to protect Personal Data:

CategoryMeasure
EncryptionAES-256 encryption at rest for all stored data. TLS 1.2+ encryption for all data in transit.
Access controlRole-based access control (RBAC) at the application layer. Row Level Security (RLS) enforced at the database layer, scoped to practice_id.
AuthenticationSecure authentication via Supabase Auth with cookie-based sessions. Row Level Security enforced at the database layer with practice-scoped isolation.
InfrastructureHosted on infrastructure operated by independently certified sub-processors where available, including Supabase and Vercel. Automatic patching and security updates are managed by hosting providers.
MonitoringReal-time error monitoring via Sentry. Audit logging of data access and modifications. Anomaly detection on authentication events.
Data isolationLogical tenant separation at the database level via RLS policies. No cross-practice data access.
BackupsAutomated daily backups with point-in-time recovery. Backups encrypted at rest and stored in the same region (ap-southeast-2).
Incident responseDocumented incident response procedures with defined escalation paths. Regular review and testing of response plans.
PersonnelBackground checks for all personnel with access to production systems. Mandatory security awareness training. Principle of least privilege enforced.

The Processor shall regularly assess the effectiveness of these measures and update them as necessary to address evolving threats and industry best practices.

6. Sub-processors

The Controller provides general authorisation for the Processor to engage the following Sub-processors. The Processor has entered into data processing agreements with each Sub-processor that impose data protection obligations no less protective than those set out in this DPA.

Sub-processorPurposeLocation
Supabase Inc.Database hosting and backend servicesap-southeast-2 (Sydney, Australia)
Vercel Inc.Application hosting and CDNGlobal CDN (edge network)
Stripe Inc.Payment processing and billingUnited States
Sentry (Functional Software Inc.)Error monitoring and performance trackingUnited States
PostHog Inc.Product analytics and feature flagsEuropean Union
Resend Inc.Transactional email deliveryUnited States
Loops Inc.Lifecycle email and user communicationsUnited States
Anthropic PBCAI-generated governance content (no patient data sent)United States

The Processor shall notify the Controller at least 30 days before engaging any new Sub-processor or replacing an existing Sub-processor. The notification shall include the Sub-processor name, purpose, and location. The Controller may object to the engagement of a new Sub-processor by providing written notice within 14 days of receiving the notification, including reasonable grounds for the objection. If the parties cannot resolve the objection within 30 days, the Controller may terminate the affected Service with no penalty.

7. International Data Transfers

The primary datastore for the Service is located in ap-southeast-2 (Sydney, Australia). All core application data, including governance records, compliance assessments, and evidence documents, is stored in this region.

Where Sub-processors Process Personal Data outside of Australia, the Processor ensures that adequate safeguards are in place in accordance with APP 8 (cross-border disclosure of personal information). These safeguards include:

  • Contractual obligations requiring Sub-processors to handle Personal Data in accordance with standards substantially similar to the APPs.
  • Where applicable, EU Standard Contractual Clauses (SCCs) for transfers involving EU-based data protection laws.
  • Sub-processor certifications, data processing terms, and compliance frameworks where available as additional assurance measures.
  • Regular assessment of the data protection laws and practices of destination countries.

The Controller acknowledges that certain ancillary services (authentication, billing, error monitoring, email delivery) may involve the Processing of limited Personal Data in the United States and European Union, as specified in the Sub-processor table above.

8. Data Subject Rights

The Processor shall assist the Controller in responding to requests from Data Subjects exercising their rights under the Australian Privacy Act 1988 (Cth), including:

  • Access (APP 12): the right to request access to Personal Data held about the Data Subject.
  • Correction (APP 13) , the right to request correction of inaccurate, out-of-date, incomplete, irrelevant, or misleading Personal Data.
  • Deletion:right to request erasure of Personal Data where it is no longer necessary for the purpose for which it was collected, subject to any applicable legal retention obligations.
  • Complaint:right to complain to the Office of the Australian Information Commissioner (OAIC) about the handling of Personal Data.

The Processor shall promptly notify the Controller upon receiving a request from a Data Subject directly and shall not respond to the request without the Controller's prior written authorisation, unless required by law.

9. Data Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Data Breach affecting Personal Data Processed under this DPA.

The notification shall include, to the extent available:

  • A description of the nature of the Data Breach, including the categories and approximate number of Data Subjects and Personal Data records affected.
  • The name and contact details of the Processor's point of contact for further information.
  • A description of the likely consequences of the Data Breach.
  • A description of the measures taken or proposed to be taken to address the Data Breach, including measures to mitigate its possible adverse effects.

Where it is not possible to provide all information at the time of notification, information may be provided in phases without undue delay. The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of each Data Breach, including compliance with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988.

10. Audits

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits and inspections conducted by the Controller or an independent auditor mandated by the Controller.

Audit requests are subject to the following conditions:

  • The Controller shall provide at least 30 days written notice of an intended audit, unless a Data Breach or regulatory investigation requires more urgent action.
  • Audits shall be conducted during normal business hours and in a manner that minimises disruption to the Processor's operations.
  • The Controller shall bear its own costs associated with the audit, unless the audit reveals material non-compliance by the Processor.
  • The Processor may satisfy audit requests by providing copies of relevant certifications, third-party audit reports (e.g., SOC 2 Type II), or summaries of its security and data protection practices where such documentation reasonably addresses the scope of the audit.
  • Audits shall not exceed one per twelve-month period unless required by regulatory authority or following a Data Breach.

11. Term & Termination

This DPA shall become effective upon the date the Controller executes the Service Agreement and shall remain in effect for the duration of the Service Agreement. The obligations of the Processor under this DPA shall survive termination of the Service Agreement to the extent necessary to complete the Processing activities described herein.

Upon termination or expiry of the Service Agreement:

  • The Controller may request the return of all Personal Data in a commonly used, machine-readable format within 30 days of termination.
  • If no return request is made, the Processor shall securely delete all Personal Data within 30 days of termination, including all copies held by Sub-processors.
  • The Processor may retain Personal Data to the extent required by applicable Australian law (including the Privacy Act 1988, tax legislation, or court orders), provided that the Processor shall continue to protect such data in accordance with this DPA and shall limit Processing to the purposes required by law.
  • The Processor shall certify in writing to the Controller that deletion has been completed upon request.

12. Governing Law

This DPA shall be governed by and construed in accordance with the laws of New South Wales, Australia, without regard to its conflict of laws provisions. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of New South Wales.

To the extent that the GDPR applies to the Processing of Personal Data under this DPA, the relevant provisions of the GDPR shall apply in addition to the terms of this DPA, and in the event of conflict, the GDPR provisions shall prevail.

13. Contact

For questions, requests, or notifications relating to this DPA, please contact:

Moirai Health Pty Ltd

Data Protection Contact

Email: privacy@moirai.health

Canberra, ACT 2601, Australia

The Processor shall respond to all DPA-related enquiries within 10 business days.