Privacy Policy
Effective date: 19 July 2026
Florin ("Florin," "we," "us") helps junior doctors in Australia analyse their pay against their applicable Enterprise Bargaining Agreement (EBA) and identify potential underpayments. This page explains, in plain language, what we collect, how we use it, and how we keep it safe.
Who we are
- Operated by: Bella Dixon and Charlie Dixon, trading as Florin (not a formally registered partnership)
- Contact for privacy queries: privacy@getflorin.com
- Jurisdiction: Australia. We aim to comply with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
What data we collect
We only collect data needed to analyse your pay:
- Account data — your name, email address, classification (e.g. HM25), employer/health service, and EBA selection.
- Payslip data — the contents of payslip PDFs you upload or forward to your personal Florin forwarding address: pay period, line items, hours, rates, gross/net amounts, and superannuation. If you save a PDF password so Florin can auto-unlock forwarded payslips, that password is stored encrypted.
- Roster data — the contents of roster files (PDF, XLSX, or calendar exports) you upload or forward to your personal Florin forwarding address: shift dates, times, locations, and shift codes.
- Logged extras — recall, phone calls, or ad-hoc overtime you log, including times, durations, and any notes or voice recordings you provide.
- Calendar data (if you connect Google Calendar) — read-only event titles, start/end times, and recurrence, used to calculate hours worked.
- Technical data — IP address, browser type, and access timestamps, used solely for security and abuse prevention.
We do not collect financial account numbers, tax file numbers (beyond what appears on your payslip and is used purely for display), Medicare numbers, or any health information about patients.
How we use your data
We use your data only to extract pay and roster information from documents you provide, compute your expected pay under the applicable EBA, compare it to your actual payslips, surface discrepancies, and — on your request — help draft dispute emails to your payroll team. We do not use your data for advertising, profiling, or any purpose unrelated to pay analysis.
AI processing
To turn a payslip or roster document into structured data, Florin sends the document contents to Anthropic's Claude API for extraction. If you log an extra by voice, the recording is sent to OpenAI's Whisper API for transcription. Neither provider trains models on this data by default.
Google Calendar access
If you connect your Google account, Florin requests the calendar.readonly scope — read-only access to view event titles, start/end times, and recurrence in the calendars you authorise. We cannot create, edit, or delete any calendar events.
Google API Services User Data Policy — Limited Use disclosure
Florin's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data only to provide the features described on this page, we do not use it for advertising, we do not transfer it to others except as necessary to provide the service or comply with the law, and we do not allow humans to read it except with your consent, for legal compliance, or to investigate abuse.
How we share your data
We do not sell your data. We share data only with the processors needed to run Florin:
- Railway — application hosting and database. See Railway's privacy policy.
- Cloudflare, Inc. — DNS, and email routing for payslip and roster documents you forward to your personal Florin forwarding address (see "Email forwarding" below). See Cloudflare's privacy policy.
- Anthropic, PBC — payslip and roster extraction via the Claude API. See Anthropic's privacy policy.
- OpenAI, L.L.C. — voice transcription for logged extras. See OpenAI's privacy policy.
- Resend — sending magic-link login emails and notifications.
- Stripe — billing, if you subscribe to a paid plan. See Stripe's privacy policy.
We do not share your data with payroll teams, employers, or any other third party without your explicit instruction.
Email forwarding
You can also send Florin a payslip or roster by email instead of uploading it. In Settings you'll find two private, unique addresses — one for payslips, one for rosters. Forward the relevant email there and Florin ingests the attachment automatically. This does not connect to, read, or scan your inbox in any way: the receiving address only accepts mail sent to that exact, hard-to-guess address, anything else is rejected, and we never see any other email you send or receive. Keep your forwarding addresses private — anyone who has them could submit documents to your account. Contact us at privacy@getflorin.com if you ever need one rotated.
How long we keep your data
- Payslip and roster records: retained while your account is active, plus 7 years after closure, matching Fair Work Act record-keeping practice so your data is available if you ever need to substantiate a back-pay claim.
- OAuth tokens: retained while an integration stays connected; deleted within 24 hours of disconnecting.
- Technical logs: 90 days, then deleted.
You can request earlier deletion at any time — see "Your rights" below.
Security
- Passwordless login: Florin uses magic-link authentication — there is no password to leak.
- Encryption in transit and at rest: TLS 1.2+ for all traffic; data encrypted at rest.
- Secure cookies: HTTPS-only, HttpOnly (not accessible to JavaScript), and SameSite=Lax.
- Read-only Calendar access: only
calendar.readonlyis requested.
We're a small team and don't claim enterprise security certifications (ISO 27001, SOC 2). If your employer requires these before you connect a work email account, check with them first.
Your rights
- Access the data we hold about you — request via privacy@getflorin.com.
- Correct any inaccurate data.
- Delete your account and all associated data — actioned within 30 days.
- Withdraw consent for any processing, including disconnecting a connected email or calendar account at any time.
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Cookies
Florin uses only essential cookies needed to keep you logged in. We do not use tracking, advertising, or analytics cookies that profile you.
Changes to this policy
We'll notify you by email at least 14 days before any material change takes effect. Minor changes (typos, clarifications) may be made without notice.
Contact
Questions about this policy or your data: privacy@getflorin.com.