Your records are personal.
Privacy policy for VacciFly, operated by Healthigence Pty Ltd, Australia. For families, nurses and clinics. Read this notice before uploading. Updated 10 September 2026.
Feedback and testimonials
After downloading a report, you can choose to send a star rating, comments and an optional display name to our team. Please do not include patient names or medical details. Feedback is private by default. Only feedback with your permission and administrator approval is displayed publicly. We do not automatically include the patient name, contact details, route, vaccination history or private report link in a testimonial. Separately submitted feedback remains for service improvement after automatic download cleanup; only permissioned, approved feedback may be displayed as a testimonial. You can contact support@vaccifly.com to request removal or withdraw publication permission. A separate verified privacy deletion request removes associated feedback during cleanup. Automatic deletion after download does not withdraw your feedback or publication permission. We do not send feedback to the document-reading AI services.
Who is responsible
Healthigence Pty Ltd, Australia, operates VacciFly and is responsible for the personal information it processes to provide the service. Contact info@vaccifly.com for general enquiries or support@vaccifly.com for privacy requests, concerns or security reports. When a healthcare organisation uses the service, its own responsibilities and privacy notice also apply.
Information we use
Your check includes a name, date of birth, optional recorded sex, email address, origin, destination, purpose and any planned departure date. Uploaded records can contain sensitive health information, handwriting, clinician details and identifiers. We store extracted observations, corrections, assessments, reports, private-link identifiers and operational audit information. Payment providers return transaction references and status; full card details are entered with the payment provider. Contact messages and technical security logs may also contain personal information. Upload only documents relevant to the named traveler. Do not add passports, unrelated medical histories or another person's records unless specifically needed and authorised.
Why we process information
We use information to read the vaccination evidence, prepare and deliver the requested report, support corrections, handle payment or service problems and protect the service against misuse. We ask for permission to process health records for the requested check. You can choose not to proceed or contact us to withdraw permission for further processing. Withdrawal may prevent us from providing the report and does not reverse processing that has already occurred. Where EU or UK data protection law applies, health-data processing requires an appropriate lawful basis and a condition for sensitive data. The self-service health-record workflow seeks explicit permission for the requested processing. Service administration, payment, legal obligations and proportionate security activities can have separate legal bases. Healthcare organisations must establish their own lawful authority before submitting patient records.
AI and service providers
Uploaded documents are sent through the configured AI processing services to read and cross-check evidence. These providers must process the document content. VacciFly then applies destination mapping rules to the extracted information. This is a cloud service, not an offline-only or end-to-end encrypted workflow from the AI processors. Hosting and private-storage providers operate the service. Stripe or Razorpay handles checkout according to the selected origin. Configured email providers process information needed for report delivery or support. Provider locations, retention and account settings can differ. Contact us before uploading if you require a particular location, contract or provider restriction. VacciFly does not promise zero retention by every provider or claim identical model-training settings across every API account.
Sharing and advertising
VacciFly does not sell vaccination records or use them for targeted advertising. Records are not published in public pages, the destination directory, search sitemap or public AI-discovery files. Service providers receive information needed for their roles. Information may also need to be disclosed to meet a lawful obligation, handle a dispute or protect rights and security. Anyone you give a report or private check link to may be able to read it. Copies downloaded, emailed or passed to a clinician are outside the website's access controls and cannot be recalled by deleting a saved check.
Storage, expiry and deletion
VacciFly temporarily stores uploaded records, extracted history and reports to prepare and deliver your check. When your browser receives the complete PDF and starts saving it, the check closes and automatic cleanup deletes its uploaded records, extracted observations, assessment, report and personal check details from active VacciFly storage. Save your PDF securely: a completed check cannot be reopened. Other family members remain available until their own reports are downloaded. Shared family contact details are cleared once every member's check has been removed. If a PDF transfer is interrupted or its completion message is lost, a recovery window of up to one hour allows another download attempt. Each retry refreshes that window for the same report. The automatic worker then closes the transferred check and retries any incomplete storage removal. Newly created unfinished check links otherwise expire after seven days; expiry closes access and is separate from storage cleanup. A verified deletion request can also close a check and request cleanup before download. Minimal payment, legal and security records and separately submitted feedback have different purposes and retention periods. A feedback-only invitation remains available for 24 hours after download confirmation; it cannot reopen the health record. Provider retention, backups and copies already downloaded or emailed are separate from active application storage. Removal is confirmed only after the relevant storage cleanup succeeds. Contact support@vaccifly.com for retention details or a deletion request.
Private links and safeguards
The saved-check link is an access credential. Someone with it may be able to open the record. Keep it private and avoid public channels or shared devices. Private check and report responses are marked to prevent normal browser caching and search indexing. Access is checked against the requested record and its expiry. These controls reduce exposure but cannot protect a link you share. Use the HTTPS website for encrypted browser transport. The live hosting environment must also protect databases, object storage, report files, backups and encryption keys. Encryption does not eliminate every security risk. The security overview explains the application's safeguards and deployment responsibilities.
Children and clinical use
A parent, guardian or appropriately authorised person must manage a child's records. Each traveler has a separate history and assessment. Nurses and clinics must have authority to process patient information and follow applicable professional, privacy and record-keeping requirements. An organisation subject to HIPAA must confirm required business associate agreements, eligible provider services and safeguards before using VacciFly for protected health information. The website does not itself establish those contracts or provide HIPAA certification. GDPR obligations also depend on the parties, purpose and jurisdiction; this notice is not a compliance certificate.
Your choices and rights
You can ask for access, correction of inaccurate personal details or deletion. Depending on applicable law, you may also have rights to restrict or object to processing, withdraw consent or receive portable data. Rights can have exceptions, including legal obligations and disputes. Email support@vaccifly.com with the type of request. Do not attach medical records or full identity documents to the first email. We may need proportionate verification of your identity and authority before releasing, changing or removing information. We will respond in accordance with applicable legal time limits. The assessment is informational; it does not make a binding school, immigration or treatment decision about you.
International processing
VacciFly is operated from Australia and its providers may process information in other countries. Selecting a destination for a report does not select the hosting region or guarantee that data stays in that country. Where cross-border transfer rules apply, the responsible parties must establish appropriate contractual and other safeguards. Ask support for live processing-location and agreement details before submitting records subject to a location restriction.
Cookies, logs and public content
The standalone website does not include advertising trackers or a patient-record analytics feed. Essential browser functions and hosting/security logs support operation and abuse prevention. Payment-provider pages can have their own cookies and notices. Public explainer videos contain no customer records. Search and AI-discovery pages describe the product, not private checks.
Questions, complaints and updates
Contact support@vaccifly.com for a privacy concern or suspected disclosure; use info@vaccifly.com for general enquiries. If a concern is not resolved, you may complain to the applicable privacy regulator, such as Australia's OAIC, the UK's ICO or an EU supervisory authority. Updated notices show a revised date. Material changes to health-data processing may require further notice or consent.
Need help? Contact VacciFly.
