Privacy Policy
Last updated 8 September 2026
2PAY Pty Ltd (“2PAY”, “we”, “us”, or “our”) provides automated service-fee, fund-distribution, and reconciliation software for Australian medical practices. This policy explains how we collect, use, disclose, and protect personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It applies to practice managers, doctors, and other users of the 2PAY platform and website.
Information We Collect
We collect information you and your organisation provide directly, information generated through your use of the platform, and limited information from trusted third parties who help us deliver the service. The categories we collect include:
- Identity and contact information — name, email address, phone number, job title, and the practice or organisation you are associated with, collected when an account is created or a user is invited.
- Practice and provider details — practice name, ABN, provider numbers, and doctor onboarding details submitted during onboarding or by a practice manager on your behalf.
- Financial and payment information — bank account (BSB and account number) details used for fund distribution, and mandate or direct debit information collected and processed by our payment partners. We do not store full payment card numbers ourselves.
- Billing and transaction data — invoices, MBS item numbers, service fee configurations, payment cycle records, and reconciliation and tax invoice (RCTI) data generated through the platform. This is billing metadata required to reconcile and distribute funds — we do not collect or store clinical or medical records.
- Technical information — IP address, device and browser type, log data, and cookie identifiers collected automatically when you use our website and platform.
- Support communications — any information you provide when you contact our support team or report an issue.
How We Use It
We use personal information for the following purposes:
- To provide, operate, and maintain the 2PAY platform, including invoicing, service-fee calculation, fund distribution, ledger reconciliation, and RCTI generation.
- To create and administer user accounts, verify identity, and enforce role-based and tenant-based access controls.
- To process payments and disburse funds to doctors and practices in accordance with each practice's configured fund-flow arrangements.
- To meet our legal, taxation (including GST and record-keeping), and regulatory obligations.
- To communicate with you about your account, service updates, security notices, and support requests.
- To monitor, secure, and improve the platform, including detecting and preventing fraud, error, or misuse.
- Where you have consented, to send you marketing communications, from which you may opt out at any time.
Disclosure to Third Parties
We do not sell personal information. We disclose personal information only:
- Within your organisation's own tenancy — for example, a practice manager may see billing and payment information for doctors within their practice, consistent with their assigned role.
- To trusted service providers who process information on our behalf, including cloud hosting providers, our identity and authentication provider, payment and direct-entry processing partners, and analytics and support-tooling providers. These providers are bound by contractual confidentiality and data-handling obligations.
- To professional advisers, auditors, insurers, or regulators where reasonably necessary to obtain advice or comply with our obligations.
- To government bodies or law enforcement where required or authorised by law.
- In connection with a business transaction such as a merger, acquisition, or sale of assets, in which case we will take reasonable steps to ensure the recipient handles your information consistently with this policy.
Data Security
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These measures include encryption of data in transit and at rest, role-based access control, logical separation between tenant organisations, authentication via a dedicated identity provider, infrastructure monitoring, and regular access reviews.
No method of transmission or storage is completely secure. If we become aware of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
Data Retention
We retain personal information for as long as your account remains active and as necessary to provide the platform. Financial, invoicing, and tax-related records are retained for at least seven years to meet Australian record-keeping obligations, including those imposed by the Australian Taxation Office. Where information is no longer required and we are not obliged to retain it, we take reasonable steps to securely destroy or de-identify it.
We separately keep a record of enquiries submitted through our public website even where no account is created — including requests raised through our support form, and enquiries submitted through tools such as the payroll tax risk indicator, our downloadable guides, and requests to book a walkthrough. These records typically include the name, email address, practice name, and message or answers you provide. We retain them until the enquiry or request has been resolved or responded to, and you may ask us to delete a record sooner at any time using the contact details below.
Your Rights & Access
Under the Australian Privacy Principles you have the right to request access to the personal information we hold about you and to request that we correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
To make a request, contact us using the details below. We will respond within a reasonable period, and in any event within 30 days. We may need to verify your identity before providing access or making corrections, and in limited circumstances permitted by law we may need to refuse a request, in which case we will explain why.
If you believe we have handled your personal information in a way that breaches the Privacy Act 1988 (Cth), you may lodge a complaint with us in the first instance, or with the OAIC at oaic.gov.au.
Overseas Disclosure
Our primary infrastructure is hosted in Australia. However, some of our service providers — for example, our identity and authentication provider and certain analytics or support platforms — may store or process information on servers located outside Australia, including in the United States. Before disclosing personal information to an overseas recipient, we take reasonable steps, as required by Australian Privacy Principle 8, to ensure the recipient handles that information in a manner consistent with the Australian Privacy Principles, including through contractual data-protection commitments.
Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, the law, or the platform. We will post the updated policy on this page with a revised “Last updated” date, and where changes are material we will take reasonable steps to notify you, such as by email or an in-app notice. Your continued use of the platform after an update takes effect constitutes acceptance of the revised policy.
Contact
If you have questions about this Privacy Policy, or wish to make a request or complaint about how we handle your personal information, please contact our Privacy Officer:
2PAY Pty Ltd
ABN 92 671 936 575
Brisbane QLD 4000, Australia
Email: support@2pay.com.au
Questions about this policy
Write to support@2pay.com.au and a member of the team will answer in writing.
Contact us