Privacy Policy
Postal/records address: 1/30 Gumbeel Court, Highland Park QLD 4211.
Privacy enquiries: hello@vibeplus.com.au.
1. Purpose
This Privacy Policy ("Policy") outlines how we collect, use, store, disclose, and protect your personal information, including sensitive and health information, in accordance with:
- Privacy Act 1988 (Cth)
- Australian Privacy Principles (APPs)
- My Health Records Act 2012 (Cth)
- Applicable State and Territory health privacy laws
We are committed to safeguarding your privacy and complying with all relevant legislation.
2. Scope
This Policy applies to all individuals who interact with us, including patients, website visitors, service users, contractors, and employees, and covers all methods of personal information collection, whether electronic, verbal, or written.
3. Definitions
- Personal Information: Information or an opinion about an identifiable individual, recorded in any form, including names, contact details, or other details from which a person's identity can reasonably be ascertained.
- Sensitive Information: A subset of personal information that includes racial or ethnic origin, political opinions, religious beliefs, sexual preferences, criminal records, or membership in professional/trade associations.
- Health Information: Information about your health, disabilities, or use of health services.
- Third-Party Website Visitors: Individuals who visit the clinic's website but are not current patients or users of our services.
4. What Information We Collect
For patients
- Full name, date of birth, gender
- Contact details: phone number, email, residential address
- Medicare number, private health insurance details
- Medical history, current health status, referrals, pathology results, prescriptions
- Payment and billing details
- Telehealth session records and usage data
Website visitors
- Technical Data: IP address, browser type, operating system, device information, and website usage data.
- Personal Data: Any personal information you choose to provide through contact forms, newsletter sign-ups, or online queries.
Pre-consultation questionnaire
Before you book a consultation, we offer an optional short questionnaire on our website. If you choose to complete it, we collect health information you provide, which may include:
- Whether you are aged 18 or over
- The health concern or symptoms you would like to discuss
- How long you have experienced them
- Whether you are pregnant or breastfeeding
- Relevant personal or family medical history
- Your name and contact details, if you choose to proceed to booking
Health information is sensitive information under the Privacy Act 1988 (Cth). We only collect it with your express consent, which we ask for by way of a separate, tick-box consent shown at the start of the questionnaire before any health information is entered. You do not have to complete the questionnaire to contact us or book a consultation, and you can stop at any time. If you do not proceed to booking, we do not collect your contact details.
5. How We Collect Information
- Direct interactions with patients during consultations, via telehealth platforms, phone calls, or emails.
- Online forms, such as appointment booking or contact forms on our website.
- Our optional pre-consultation questionnaire, if you choose to complete it and consent to us collecting the health information you enter.
- Automatic collection through cookies and similar technologies when you visit our website.
- Third-party referrals from other healthcare providers, insurers, or authorised representatives.
6. Legal Basis for Collection
We collect personal information: with your consent; when necessary for the performance of healthcare services; to comply with legal obligations; and to pursue legitimate interests (e.g. improving services).
7. How We Use Your Information
For patients
- To provide healthcare services, including telehealth consultations, diagnosis, treatment, and follow-up care.
- To communicate with you regarding appointments, treatment plans, and health-related information.
- To process payments, including Medicare and private health insurance claims.
- To comply with legal and regulatory obligations, such as reporting notifiable diseases or responding to court orders.
- To improve our services, telehealth platforms, and website functionality.
- To provide you with updates about our services, appointment reminders, or health-related information. You can opt out at any time via the "unsubscribe" instructions in the communication or by contacting us directly. We will not use your health information for direct marketing without your explicit consent.
For website visitors
- Respond to your inquiries or requests made through our website.
- Analyse website usage and improve user experience.
- Manage our website's functionality and security.
8. Disclosure of Information
We do not sell or rent your personal information to third parties. We may share your personal information in the following circumstances:
- Healthcare Providers: With your consent, we may share your health information with other healthcare providers involved in your care.
- Third-Party Service Providers: We may share your information with providers who assist us in delivering our services (e.g. IT service providers, payment processors) under strict confidentiality agreements.
- Legal Requirements: Where required or authorised by law (e.g. to comply with a subpoena or court order).
- Regulatory Authorities: As required for compliance with health regulations.
Overseas disclosure
We do not routinely disclose personal or health information to overseas recipients. If it becomes necessary to transfer your information outside Australia (for example, where a third-party service provider stores data on secure overseas servers), we will only transfer the information where permitted by law; take reasonable steps to ensure the overseas recipient complies with the Australian Privacy Principles or equivalent safeguards; and inform you in advance, including which country the information will be transferred to, where possible.
9. Data Security Measures
We implement the following measures to protect your personal information from misuse, interference, loss, unauthorised access, modification, or disclosure:
- Encryption: personal information is encrypted in transit using secure (SSL/TLS) technology.
- Access Controls: access is restricted to authorised personnel who need it to perform their duties.
- Secure Storage: digital data is stored on secure servers protected by firewalls and regularly updated security software, hosted on Australian-based infrastructure.
- Regular Audits: we conduct regular security audits and assessments to identify and mitigate vulnerabilities.
- Multi-Factor Authentication (MFA): staff must use MFA to access systems containing sensitive information.
10. Cookies and Tracking Technologies
We use cookies and similar technologies on our website to improve your browsing experience, analyse traffic, and support the functionality and security of our online services.
What are cookies?
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work, improve efficiency, and provide reporting information.
Types of cookies we use
- Strictly Necessary: essential for the website to operate (navigation, secure access, session management).
- Performance & Analytics: anonymised information about how visitors use the site, to help us improve it.
- Functionality: remember your preferences and settings for a more personalised experience.
- Third-Party: some third-party services (e.g. embedded videos or social plug-ins) may set cookies; those providers are responsible for their own cookie use.
You can accept, decline, or customise cookies through your browser settings. Disabling certain cookies may affect website functionality. Where required by law, we will seek your consent before placing non-essential cookies.
11. Data Retention
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, to comply with our legal and regulatory obligations, and for legitimate operational requirements.
Health records
- Adult patients: at least 7 years from the date of the last consultation or entry.
- Child patients: until the patient turns 25, or 7 years from the last entry, whichever is longer.
- Deceased patients: retained per the above timelines unless a longer period is legally or clinically necessary.
Website/technical data (cookies, IP addresses, analytics) is retained for up to 2 years, or longer if required. Administrative, financial, or communication records are retained in line with legal obligations, typically 5–7 years. Once no longer required, we securely delete or de-identify information (secure electronic deletion, shredding of physical documents, certified data-destruction services).
12. Your Rights
Under the Privacy Act 1988 (Cth) and relevant health privacy laws, you have the right to:
- Request access to your personal information;
- Request correction or updating of your information;
- Request deletion of your data where no longer required;
- Object to processing for marketing purposes;
- Request a portable copy of your data where technically feasible;
- Withdraw consent (where consent is the basis for processing).
To exercise these rights, contact us in writing at hello@vibeplus.com.au. We may request verification of your identity. We aim to respond within 30 days. There is no charge to submit a request, though we may charge a reasonable administrative fee for physical copies or for excessive/repetitive requests. If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
13. Data Breach Notification
We comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth). If we have reasonable grounds to believe a data breach is likely to result in serious harm, we will: promptly assess the breach under our internal response plan; contain it where possible; notify affected individuals as soon as practicable (including the information involved and recommended steps); notify the OAIC via a Notifiable Data Breach Statement; document the breach and our response; and review our safeguards to prevent recurrence. Where a breach does not meet the notification threshold but may still carry risk, we will take proactive steps to inform affected individuals where appropriate.
14. Children and Minors
Our services are intended for individuals aged 18 and over. We do not knowingly collect personal information from anyone under 18 except where a person is lawfully acting as an authorised representative. If you believe we have inadvertently collected information from a minor, please contact us so we can address it.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or services. The updated version will be published on our website and take effect from the effective date shown above. Where material changes affect your rights, we will take reasonable steps to bring them to your attention before they take effect.
16. Complaints & Enquiries
If you have any questions, concerns, or complaints regarding this Policy or how your personal information is handled, please contact us at hello@vibeplus.com.au. We will acknowledge your enquiry within a reasonable timeframe, investigate, and provide a written response outlining the outcome and any steps taken. All complaints are handled in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, and relevant health privacy legislation.
Website: www.oaic.gov.au · Phone: 1300 363 992 · Mail: GPO Box 5218, Sydney NSW 2001
17. Governing Law
This Policy is governed by the laws of the State of Queensland, Australia, and the Commonwealth of Australia.