PRIVACY POLICY


How we handle your personal and health information

Your privacy matters to us — especially when it comes to your health. This policy explains how we collect, use, store, share and protect your personal information, including your health information. We’re a homeopathy and naturopathy practice, working with people by telehealth and in person across Australia. We handle your information in line with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and health-records laws including the Health Records and Information Privacy Act 2002 (NSW). Because we provide health services, these rules apply to us no matter our size.

What we collect

The information we collect depends on how you interact with us. It can include:

  • Identity and contact details — your name, date of birth, gender, postal and email addresses, and phone number.

  • Health information — your medical history, symptoms, current and past conditions, medications and supplements, family and lifestyle history, our notes and treatment plans, and any test results or reports you share.

  • Payment information — records of fees charged and paid (your card details are handled by our payment provider, Stripe, and aren’t stored by us).

  • Our communications — emails, messages, intake forms and appointment records.

  • Technical information — limited data when you use our website or booking platform, such as your IP address and browser type.

Health information is treated as “sensitive information” and given a higher level of protection. We generally only collect it with your consent and where it’s reasonably necessary to provide health services to you.

How we collect it

We collect information mostly directly from you — through intake and consent forms, consultations (by video, phone or in person), emails and calls. We also collect it through Practice Better, our practice-management system, which handles bookings, records, forms and communications; from other health practitioners such as your GP, where you ask us to obtain or share information; and automatically through our website and online booking tools. Where it’s reasonable and practical, we’ll always collect it directly from you. If we receive information we didn’t ask for, we deal with it in line with the APPs.

Why we collect and use it

We collect, hold and use your information to provide your consultations and care, to assess your concerns and develop and manage your treatment plans, to communicate with you (including appointment confirmations and reminders by SMS and email through Practice Better), to manage bookings, billing and payments, to keep accurate clinical and business records, to answer your enquiries, and to meet our legal and regulatory obligations. We only use your information for the reason we collected it, a closely related reason you’d reasonably expect, or where you’ve consented or the law allows.

Marketing and communications

Appointment reminders and confirmations are about your care — they’re not marketing. If we ever send newsletters or promotional material, we’ll only do so with your consent (or where the law otherwise allows), every message will include an easy way to unsubscribe, and we’ll stop as soon as you opt out. Our marketing follows the Spam Act 2003 (Cth).

When we share your information

We never sell your information. We only share it where we need to:

  • Our service providers — including Practice Better (practice management, records, bookings, reminders), Google Workspace (files, email, calendar), Squarespace (website and bookings), Stripe (payments), Annature (e-signatures), Xero (accounting), any email-marketing platform we use, and our IT and professional advisers. They’re bound by contract and law to protect it.

  • Other health practitioners — such as your GP or a specialist, where you consent or it’s necessary for your care.

  • Regulators, courts or authorities — where required or authorised by law.

  • A person responsible for you — such as a parent, guardian or carer, in the circumstances the Privacy Act allows.

Overseas storage

Some of our providers store data outside Australia. In particular, Practice Better (Greenly Health Inc.) stores data on servers in the United States, using Amazon Web Services and Box.com, which means your information may be subject to US laws such as the CLOUD Act. Others — including Google Workspace, Squarespace and Stripe — may also process data overseas. Some providers store data in Australia; for example, Annature, which we use for e-signatures. Wherever information goes, we take reasonable steps to make sure it’s handled consistently with the APPs, including through our contracts with these providers. By giving us your information, you accept it may be stored and processed overseas as described.

Keeping your information secure

We take reasonable steps to protect your information from misuse, loss and unauthorised access — using reputable platforms with encryption and access controls, limiting access to authorised people on a need-to-know basis, using a secure password manager and strong, regularly updated credentials, keeping our security software up to date, and storing records securely. No method of storage or transmission is ever completely secure, so we can’t guarantee the security of information sent over the internet or held on third-party platforms. If an eligible data breach ever happens, we’ll respond under the Notifiable Data Breaches scheme, including notifying you and the OAIC where required.

How long we keep it

We keep your health records for as long as we need to care for you and meet our legal and professional obligations. In line with health-records law and the ATMS Record Keeping Policy, that’s generally at least seven years from your last visit for adults, and until age 25 for anyone treated as a child. After that, we securely destroy or de-identify them.

Accessing and correcting your information

You can ask to see the information we hold about you and to correct anything that’s inaccurate, out of date, incomplete or misleading. Just get in touch with us — we’ll respond within a reasonable time and may need to confirm your identity first. There’s usually no charge to ask, though we may charge a reasonable fee for the cost of providing access. In limited circumstances the law lets us decline; if so, we’ll explain why in writing and let you know how to take it further.

Complaints

If you’re ever concerned about how we’ve handled your information, please tell us first so we can try to put it right. If you’re not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or on 1300 363 992.

Changes and questions

We may update this policy from time to time, and the current version will always be on our website, with the date it was last reviewed at the top. If you have a question about your privacy, want to see or correct your information, or would like to raise a concern, please get in touch with us — we’ll be glad to help.

COOKIE NOTICE

How we handle your personal and health information

Your privacy matters to us — especially when it comes to your health. This policy explains how we collect, use, store, share and protect your personal information, including your health information. We’re a homeopathy and naturopathy practice, working with people by telehealth and in person across Australia. We handle your information in line with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and health-records laws including the Health Records and Information Privacy Act 2002 (NSW). Because we provide health services, these rules apply to us no matter our size.

What we collect

The information we collect depends on how you interact with us. It can include:

  • Identity and contact details — your name, date of birth, gender, postal and email addresses, and phone number.

  • Health information — your medical history, symptoms, current and past conditions, medications and supplements, family and lifestyle history, our notes and treatment plans, and any test results or reports you share.

  • Payment information — records of fees charged and paid (your card details are handled by our payment provider, Stripe, and aren’t stored by us).

  • Our communications — emails, messages, intake forms and appointment records.

  • Technical information — limited data when you use our website or booking platform, such as your IP address and browser type.

Health information is treated as “sensitive information” and given a higher level of protection. We generally only collect it with your consent and where it’s reasonably necessary to provide health services to you.

How we collect it

We collect information mostly directly from you — through intake and consent forms, consultations (by video, phone or in person), emails and calls. We also collect it through Practice Better, our practice-management system, which handles bookings, records, forms and communications; from other health practitioners such as your GP, where you ask us to obtain or share information; and automatically through our website and online booking tools. Where it’s reasonable and practical, we’ll always collect it directly from you. If we receive information we didn’t ask for, we deal with it in line with the APPs.

Why we collect and use it

We collect, hold and use your information to provide your consultations and care, to assess your concerns and develop and manage your treatment plans, to communicate with you (including appointment confirmations and reminders by SMS and email through Practice Better), to manage bookings, billing and payments, to keep accurate clinical and business records, to answer your enquiries, and to meet our legal and regulatory obligations. We only use your information for the reason we collected it, a closely related reason you’d reasonably expect, or where you’ve consented or the law allows.

Marketing and communications

Appointment reminders and confirmations are about your care — they’re not marketing. If we ever send newsletters or promotional material, we’ll only do so with your consent (or where the law otherwise allows), every message will include an easy way to unsubscribe, and we’ll stop as soon as you opt out. Our marketing follows the Spam Act 2003 (Cth).

When we share your information

We never sell your information. We only share it where we need to:

  • Our service providers — including Practice Better (practice management, records, bookings, reminders), Google Workspace (files, email, calendar), Squarespace (website and bookings), Stripe (payments), Annature (e-signatures), Xero (accounting), any email-marketing platform we use, and our IT and professional advisers. They’re bound by contract and law to protect it.

  • Other health practitioners — such as your GP or a specialist, where you consent or it’s necessary for your care.

  • Regulators, courts or authorities — where required or authorised by law.

  • A person responsible for you — such as a parent, guardian or carer, in the circumstances the Privacy Act allows.

Overseas storage

Some of our providers store data outside Australia. In particular, Practice Better (Greenly Health Inc.) stores data on servers in the United States, using Amazon Web Services and Box.com, which means your information may be subject to US laws such as the CLOUD Act. Others — including Google Workspace, Squarespace and Stripe — may also process data overseas. Some providers store data in Australia; for example, Annature, which we use for e-signatures. Wherever information goes, we take reasonable steps to make sure it’s handled consistently with the APPs, including through our contracts with these providers. By giving us your information, you accept it may be stored and processed overseas as described.

Keeping your information secure

We take reasonable steps to protect your information from misuse, loss and unauthorised access — using reputable platforms with encryption and access controls, limiting access to authorised people on a need-to-know basis, using a secure password manager and strong, regularly updated credentials, keeping our security software up to date, and storing records securely. No method of storage or transmission is ever completely secure, so we can’t guarantee the security of information sent over the internet or held on third-party platforms. If an eligible data breach ever happens, we’ll respond under the Notifiable Data Breaches scheme, including notifying you and the OAIC where required.

How long we keep it

We keep your health records for as long as we need to care for you and meet our legal and professional obligations. In line with health-records law and the ATMS Record Keeping Policy, that’s generally at least seven years from your last visit for adults, and until age 25 for anyone treated as a child. After that, we securely destroy or de-identify them.

Accessing and correcting your information

You can ask to see the information we hold about you and to correct anything that’s inaccurate, out of date, incomplete or misleading. Just get in touch with us — we’ll respond within a reasonable time and may need to confirm your identity first. There’s usually no charge to ask, though we may charge a reasonable fee for the cost of providing access. In limited circumstances the law lets us decline; if so, we’ll explain why in writing and let you know how to take it further.

Complaints

If you’re ever concerned about how we’ve handled your information, please tell us first so we can try to put it right. If you’re not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or on 1300 363 992.

Changes and questions

We may update this policy from time to time, and the current version will always be on our website, with the date it was last reviewed at the top. If you have a question about your privacy, want to see or correct your information, or would like to raise a concern, please get in touch with us — we’ll be glad to help.