Health Village Pty Ltd
Privacy Policy
Effective date: [insert date policy is uploaded to app and updated in the future]
This document (privacy policy) describes how Health Village Pty Ltd ACN 681 624 055 of Unit 525 368 Sussex Street, Sydney NSW 2000 (“Health Village” “we”, “us” and “our”) collects, uses, discloses and otherwise handles personal information (as defined in this privacy policy) that we collect from you, including through your access to and use of our mobile phone application titled “Health Village” for connecting people to services (Application).We take our obligations under the Privacy Act 1988 (Cth) (Privacy Act) seriously. We are committed to providing quality products and services to you. This privacy policy outlines our ongoing obligations to you in respect of how we manage your personal information and sensitive information, including in relation to the Australian Privacy Principles (APPs) under the Privacy Act. A copy of the APPs may be obtained from the website of the Office of the Australian Information Commissioner at www.oiac.gov.au.
We reserve the right to change, replace or update this privacy policy from time to time. We will make the new version of the privacy policy available on our Application. We encourage you to regularly review the Application to ensure that you are familiar with our current privacy policy.
By submitting your personal information and sensitive information (including health information) to us, using our application, or accessing our services, you consent to the collection, use, disclosure, sharing, transferring, storing and handling of your personal information and sensitive information (including health information) in accordance with this privacy policy.
In this privacy policy, a reference to “you” can mean:
- you, if you are an individual using the Application for services for yourself;
- if you are a responsible person for an individual for the purposes of section 6AA of the Privacy Act, the individual you are responsible for;
- if you are an authorised representative of a healthcare recipient for the purposes of section 6 of the My Health Records Act 2012 (Cth), the healthcare recipient you are an authorised representative for; or
- if you are a nominated representative of a healthcare recipient for the purposes of section 7 of the My Health Records Act 2012 (Cth), the healthcare recipient you are the nominated representative for.
To the extent that you are accessing this privacy policy and the Application on behalf of an individual as above, you warrant that you are a responsible person for that individual and have their authority to review this privacy policy on their behalf, and provide any of their personal information and/or sensitive information to us.
- What is personal information and what personal information do we collect from you?
For the purposes of this privacy policy, personal information is any information or opinion about an identified individual or an individual who is reasonably identifiable, regardless of whether the information or opinion is true or not.
As described in detail below, we may collect certain personal information about you in connection with your use of, or your submissions to, the Application and the services made available on the Application. We may collect one or more of the following type(s) of personal information, depending on how you interact with us:
- your name and other information that may be used to identify you;
- your mail and/or street address information;
- your email address and your telephone number (including land line and mobile phone number);
- information that you provide to us when completing client surveys, questionnaires and promotions;
- your Medicare, DVA, private health insurer, or NDIS details;
- your device identity and type, your IP address, geo-location information, page view statistics, advertising data and standard web log information; and
- any other information that can be used (either singly or in combination with other information) to identify you.
This privacy policy explains why we collect this personal information, how we may use this information and potential recipients of our usual disclosures of personal information.
- How do we collect personal information about you?
We collect personal information in a number of ways, as explained in further detail below. While we use reasonable efforts to collect personal information about you directly from you, we may also collect personal information about you from third parties.
We only collect personal information which is reasonably necessary for one or more of our functions or activities and we only collect personal information by lawful and fair means, in accordance with the Privacy Act.
We may collect personal information using any one or more of the following means:
- When you communicate with us, sign up for our services, agree to receive materials from us, and when you interact with us via our application: We may collect personal information when you communicate with us and when you submit information to us via the Application. We may also collect personal information about you when you interact with our Application, or use the Application’s features, tools and functionality, and when you sign up to receive our services, including any email updates or other information from us.
- When we leverage and/or collect information from cookies, device IDs, geo-location data, data from the environment and data from other tracking technologies: We may collect personal information about you by using cookies and other technologies (such as web beacons, device IDs, geo-location information, HTML 5 local storage, Flash cookies and IP addresses). For further information about our use of such technologies, please see below at section 17 of this privacy policy.
- When we collect personal information from third parties or from publicly available sources of information: in certain circumstances, we may obtain certain personal information about you from third party sources. We may combine your personal information with data that we obtain from our services, other users and third parties.
- When we receive personal information from your health insurance company: in certain circumstances, we may receive certain personal information about you from your health insurance company. With your prior consent, your health insurance company may provide us with your personal information. For further information on how your personal information is collected by your insurance company and provided to us please review your insurance company policies.
- Why do we collect personal information?
We may collect, use, disclose and process personal information for a number of different purposes as set out in detail below. We collect and use personal information for one or more of the following purposes:
- To operate our business and to provide the Application (including to maintain the Application and to communicate with you regarding the Application, such as to provide you with notices regarding changes to the Terms of Use and/or this privacy policy and to enforce the Terms of Use, and to develop, provide and improve the Application, such as to better tailor the features, performance, security and support of the Application and for statistical and analytics purposes in relation to the Application);
- To provide products, services and information to you, to our service providers, and to take steps in response to information requests or inquiries you may submit prior to entering into a contract with us;
- To ask that you participate in and to complete questionnaires and surveys, to administer questionnaires and surveys that you have agreed to complete, and to gather information and feedback about our performance;
- To comply with our contractual and legal obligations, to resolve disputes and to enforce our agreements with third parties;
- For record keeping and administrative purposes, and to consider applications for employment with us;
- For fraud, loss, and other crime prevention purposes;
- For direct marketing purposes, including to enable us to send you marketing and promotional messages and other information that may be of interest to you, via email, SMS, social media or direct mail (subject to you not exercising your right to opt out of your receipt of such messages);
- To assist in the investigation of suspected illegal or wrongful activity, and to protect and to defend our rights and property, or the rights or safety of third parties;
- To comply with laws, regulators, court orders and other legal obligations, or pursuant to legal processes;
- Subject to applicable contractual or legal restrictions, in connection with contemplated reorganisation or an actual reorganisation of our business, in connection with financing, a sale or other transaction involving the disposal of all or part of our business or assets, including for the purpose of permitting due diligence required to decide whether to proceed with a transaction; and
- To maintain a safe working environment for our staff and contractors.
- What third parties do we disclose your personal information to, and why?
We may disclose personal information we collect to third parties but only on an as-needs basis and only to fulfil one or more of the purposes for which we collected the information, any secondary purpose related to the primary purpose(s) of collection, and otherwise as required or authorised by law.
- Related bodies corporate. We may disclose some or all of your personal information to its related bodies corporate for the purposes described in this privacy policy. Where we disclose such information with our related bodies corporate, we will require its related bodies corporate to honour this privacy policy.
- Service providers. We may disclose personal information to our business partners, distributors, service providers, marketing providers, and vendors in order to maintain the Application and to provide, improve and personalise the products and services. We may also disclose personal information for other technical and processing functions, such as sending emails on its behalf, technical support, or otherwise operating the Application, for analytics, and for marketing purposes. Such third parties may have access to personal information only as needed to perform their functions for us, and they may not use personal information for other purposes.
- Persons authorised by you. We may disclose some or all of your personal information to persons to whom you authorise us to disclose your personal information.
- As authorised by law. We may also disclose some or all of your personal information to comply with applicable laws and regulations, to respond to a lawful request for information we received, or as otherwise pursuant, authorised or required by law (including under the Privacy Act). We may also use and disclose personal information to establish or exercise our legal rights, to enforce our Terms of Use and other contracts with you or your organisation, this Privacy Policy, or agreements with third parties, to assert and defend against legal claims, or if we believe such disclosure is necessary to investigate, prevent, or take other action regarding actual or suspected illegal or fraudulent activities or potential threats to the physical safety or well-being of any person.
- Professional advisers, insurers and auditors. We may also disclose some or all of your personal information to our professional advisers (including its lawyers and accountants), its insurers and its auditors for the purpose of its advisers, insurers and auditors completing their obligations owed to us.
- New owner. If the ownership or control of all or part of our business changes, we may transfer your personal information to the new owner.
- What is sensitive information and what sensitive information do we collect from you?
- As outlined in the Privacy Act, sensitive information is personal information that includes information or an opinion about an individual’s racial or ethnic origin, political opinions, professional or political or religious affiliations or memberships, sexual orientation or practices, criminal record, health, genetics and/or biometrics.
- As described in detail below, we may collect certain sensitive information about you only where the collection of this information is reasonably necessary for, and directly related to our functions and activities and with your consent through your use of the Application and for social prescribing services made available on the Application. We may collect one or more of the following type(s) of sensitive information, depending on how you interact with us:
- racial or ethnic origin;
- sexual orientation or practices;
- criminal record;
- health or genetic information;
- some aspects of biometric information.
- How do we collect sensitive information about you?
We collect sensitive information in a number of ways, as explained in further detail below.
We only collect sensitive information which is reasonably necessary for one or more of our functions or activities and we only collect sensitive information by lawful and fair means, in accordance with the Privacy Act.
We may collect sensitive information using any one or more of the following means:
- When you interact with us via our application for our services: we may collect sensitive information when you communicate with us and when you submit information to us (including via the Application). We may also collect sensitive information about you when you interact with our Application, or use the Application’s features, tools and functionality, and when you sign up to receive notifications or other information from us.
- When your health insurance provider provides us with your sensitive information: in certain circumstances, we may receive certain sensitive information about you from your health insurance company. With your prior consent, your health insurance company may provide us with your sensitive information. For further information on how your sensitive information is collected by your insurance company and provided to us please review your insurance company policies.
- Why do we collect sensitive information?
We may collect, use, disclose and process sensitive information for a number of different purposes as set out in detail below. We collect and use personal information for one or more of the following purposes:
- To operate our business and to provide the Application and connecting people to services to you through the Application;
- To provide information to our service providers;
- To comply with laws, regulators, court orders and other legal obligations, or pursuant to legal processes;
- Subject to applicable contractual or legal restrictions, in connection with contemplated reorganisation or an actual reorganisation of our business, in connection with financing, a sale or other transaction involving the disposal of all or part of our business or assets, including for the purpose of permitting due diligence required to decide whether to proceed with a transaction.
- What third parties do we disclose your sensitive information to, and why?
We may disclose sensitive information we collect to third parties but only to fulfil one or more of the purposes for which we collected the information, and otherwise as required or authorised by law.
- Service providers. We may disclose sensitive information to our business partners, distributors, service providers, marketing providers, and vendors to provide, improve and personalise the products and services.
- Persons authorised by you. We may disclose some or all of your sensitive information to persons to whom you authorise us to disclose your sensitive information.
- As authorised by law. We may also disclose some or all of your sensitive information to comply with applicable laws and regulations, to respond to a lawful request for information we received, or as otherwise pursuant, authorised or required by law (including under the Privacy Act). We may also use and disclose sensitive information to establish or exercise our legal rights, to enforce our Terms of Use and other contracts with you, this Privacy Policy, or agreements with third parties, to assert and defend against legal claims, or if we believe such disclosure is necessary to investigate, prevent, or take other action regarding actual or suspected illegal or fraudulent activities or potential threats to the physical safety or well-being of any person.
- Anonymity and pseudonymity
- Where it is lawful and reasonable for you to do so, you have the right to deal with us on an anonymous or pseudonymous basis. As permitted by law, and subject to the following, we will give you the option of not identifying yourself, or of using a pseudonym, in dealing with us.
- However, if you choose to interact with us in an anonymous or pseudonymous fashion, or you do not provide us with personal information on request, then we may be unable to provide you with the products or services you request.
- Further, we reserve the right to verify your identity in certain circumstances. For example, we may need to verify your identity when you request that we provide certain services to you, in order to liaise with other service providers and in order to comply with its statutory and regulatory obligations. Additionally, when you request access to or correction of the personal information we hold about you, or when you wish to make a complaint regarding how we have handled your personal information, we reserve the right to verify your identity and contact details in order to facilitate its satisfaction of your access or correction request, or to investigate and to deal with your complaint.
- We may create de-identified or anonymous data from personal information by removing data components (such as your name, email address, or linkable tracking ID) that makes the data personally identifiable to you or through obfuscation or through other means. Our use of de-identified or anonymised data is not subject to this privacy policy.
- Receipt of unsolicited personal information
- Generally, we only collect personal information when it is specifically requested or when we take active steps to collect that information. From time to time, however, personal information about an individual may be provided or volunteered to us on an unsolicited basis.
- Where we receive personal information on an unsolicited basis, then (in accordance with our statutory obligations), we will promptly determine whether such personal information could lawfully have been collected had we requested the information or had otherwise actively sought the provision of such information.
- Disclosure of personal information to recipients located outside Australia
- Generally, We do not disclose personal information to recipients located outside Australia.
- If you communicate with us via email, through a social network service or through some other electronic process, the communication may be routed through servers that are located outside Australia and, in relation to a message sent to us through a social network service (such as Twitter or Facebook), the social network provider and its partners may collect, hold and process personal information in a jurisdiction outside Australia.
- Links to other websites or applications
The Application may contain links or otherwise provide access to other websites, mobile applications or Internet locations (Third Party Sites). This privacy policy does not apply to Third Party Sites. We encourage you to read the privacy policies of any Third Party Site with which you choose to interact.
- Security
We take reasonable steps to ensure that your personal information and sensitive information is kept secure and protected from misuse, interference and loss, and from unauthorised access, modification or disclosure. We use technical and organisational security measures designed to secure and protect personal information. Please note, however, that we cannot eliminate security risks associated with the storage and transmission of personal information.
- Quality of personal information
We take reasonable steps to ensure that personal information collected, used and disclosed is accurate, complete and up-to-date. However, the accuracy, completeness and currency of the personal information we hold largely depends on the accuracy of the information you supply to us. If at any time you discover that any personal information held about you is inaccurate, incomplete, outdated, irrelevant or misleading, please contact us to request correction of the information. We will handle a correction request in accordance with the procedures set out in this privacy policy. In doing so, we reserve the right to verify the identity of the person making a correction request before processing the request.
- Access to and correction of personal information and sensitive information
- We will provide access to your personal information and / or sensitive information within a reasonable period of time following our receipt of your request, unless an exception applies. The exceptions include:
- where the access poses a serious threat to the life or health or safety of the individual, public health or public safety;
- where giving access would have an unreasonable impact on the privacy of other individuals;
- where the request is frivolous or vexatious;
- where the request relates to existing or anticipated legal proceedings or to current negotiations between you and us;
- the request is unlawful, would impede or prejudice any investigation of unlawful activity; or
- where we are required or authorised by or under Australian law or a court/tribunal order to not comply with the request.
- Where we do not provide you with access to your personal information and / or sensitive information, we will explain to you the reason for denying access and provide details in relation to the relevant complaint process, should you not agree with our reasons.
- While we will not charge a fee for making an access request, we are authorised by law to charge a reasonable fee to cover our costs incurred in providing access to your personal information, and we reserve the right to charge a reasonable fee to cover our costs incurred in providing access to your personal information and / or sensitive information.
- If you can establish that the personal information and / or sensitive information that we hold about you is not accurate, complete or up-to-date, or is irrelevant or misleading, we will take reasonable steps to correct the information. If we have disclosed inaccurate, incomplete, out-of-date, irrelevant or misleading information to a third party, we will take reasonable steps to ensure that the recipient is aware of the correction.
- We may request from you information in order to verify your identity and, if relevant, your connection to the individual about whom you request personal information and / or sensitive information, if required. Further, we reserve the right to redact information included in the personal information, in order to protect the privacy of other individuals.
- Retention of information
- You may de-activate your account for the Application if you no longer require access to the Application and our services.
- After you de-activate your account for the Application, we will do either of the following:
- destroy your personal information and/or sensitive information;
- de-identify your personal information and/or sensitive information to the extent necessary.
- You acknowledge that once your account is de-activated and your personal information and/or sensitive information is destroyed or de-identified, you will no longer be able to request access to your information in accordance with paragraph [15] herein.
- Cookies
- We may utilise "cookies" and other tracking software which enable us to monitor traffic patterns and to serve you more efficiently if you revisit the website and to assist with your use of our services as well as for our general analytics purposes.
- A cookie does not identify you personally but it does identify your computer or device. You can set your browser to notify you when you receive a cookie and this will provide you with an opportunity to either accept or reject it in each instance. If you turn cookies off, some features that may make your experience of our website more efficient may not function properly.
- If you have registered with us and have an account on our Application, our software may identify you personally based on the information you have provided on your account. Otherwise, non-registered users will not be personally identified by our software.
- Complaints procedure If you have any query or complaint about how we have handled your personal information and / or sensitive information, please contact us, at the details set out below. We will provide a response to you within a reasonable time period following receipt, in accordance with applicable law. We reserve the right to verify the identity of the person making the complaint and to seek (where appropriate or reasonable) further information from the complainant about the circumstances of the complaint. We reserve the right to refuse to investigate or to otherwise deal with a complaint where permitted by law. For example, we may refuse to investigate or to otherwise deal with a complaint if we consider the complaint to be vexatious or frivolous. If you are not satisfied with our determination, then you may escalate the complaint to the Office of the Australian Information Commissioner.
- Contact us For further information about our privacy policy or practices, or to request access to or correction of your personal information and / or sensitive information we hold about you, or to make a complaint, please contact us using the details below:
- Email: info@healthvillage.com.au
- Mail address: Suite 5, Level 26 , 368 Sussex Street, Sydney NSW 2000
For more information about privacy generally, or if your concerns are not resolved to your satisfaction, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au and on 1300 363 992.