Bio Health Therapies

Privacy Policy

This Privacy Policy explains how Bio Health International Pty Ltd (ACN 700 859 650) trading as Bio Health Therapies of 86 Valcan Road, Orange Grove, Perth WA 6109 (ā€˜we’, ā€˜us’ or ā€˜our’) collects, holds, uses, discloses and protects your personal information, including your health information. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (ā€˜APPs’). Because we provide a health service, we are bound by the Privacy Act regardless of our annual turnover.

1. Scope of this policy

1.1 This Privacy Policy applies to all personal information we collect through our website, our online learning platform, our education courses (both online and in person), our membership program, our social media channels, and any other dealings you have with us.

1.2 It applies to participants, prospective participants, members, guest speakers, contractors, and visitors to our website.

1.3 By providing your personal information to us, or by using our website or enrolling in a course, you agree to your information being handled in accordance with this Privacy Policy.

2. What we mean by personal and health information

ā€˜Personal information’ means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or not and whether it is recorded in a material form or not.

ā€˜Sensitive information’ is a subset of personal information and includes health information. Sensitive information attracts a higher level of protection under the APPs and generally cannot be collected without your consent.

ā€˜Health information’ means information about your physical or mental health, any disability, any health service provided to you, and includes information collected in connection with a health service. In this Privacy Policy, health information includes information about a course participant’s own health, and de-identified information used in case studies.

3. The personal information we collect

Depending on your dealings with us, we may collect:

(a) identity and contact details: your name, email address, postal address, telephone number and date of birth;

(b) professional details: your AHPRA registration number and registration status, your qualifications, your employer or practice, your years of experience, and your student enrolment details;

(c) professional indemnity insurance details, where we ask you to confirm you hold cover;

(d) payment information: billing details and transaction records. We do not store your full card number, which is handled by our payment provider, Stripe;

(e) course engagement information: modules accessed, progress, assessment responses, attendance and completion records;

(f) photographs, video and audio recordings of you, where you have given separate written consent;

(g) your correspondence with us, feedback and survey responses; and

(h) technical information collected through our website, such as your IP address, browser type and pages visited.

4. The health information we collect and why

We collect health information in two distinct circumstances. Both are explained below, and different rules apply to each.

4.1 Your own health information. Before you take part in the hands-on practical component of a course, we ask you to complete a health declaration in the Consent Form. This may include information about injuries, medical conditions, pregnancy, allergies, skin conditions, medication and any other matter that may make hands-on participation unsafe.

We collect your own health information for the sole purpose of:

(a) assessing whether it is safe for you to participate in hands-on practical activities;

(b) adapting activities so that you can participate safely; and

(c) responding appropriately in the event of an incident or emergency.

4.2 Case study material. Our courses involve the discussion of clinical case studies. Any case study material we prepare is de-identified before it is used, so that the individual cannot reasonably be identified. Where a case study cannot be adequately de-identified, we obtain the express written consent of the individual concerned before it is used.

4.3 If you contribute case study material about your own patient or client to a course, you must have obtained that person’s informed, express consent for its use in education, and you must de-identify the material before you share it. You remain responsible for your own privacy obligations to your patients and clients.

4.4 We collect sensitive information, including health information, only with your consent and only where it is reasonably necessary for our functions or activities, or where the collection is otherwise permitted by law.

5. How we collect information

We collect personal information:

(a) directly from you, when you enquire, enrol, complete a form, sign a Consent Form, attend a course, join our membership, subscribe to our mailing list, or contact us;

(b) through our website and online learning platform, including through cookies and analytics tools;

(c) from our payment provider, in relation to transactions; and

(d) from third parties, such as AHPRA’s public register, where we verify your registration status.

5.1 Where it is lawful and practicable, you may deal with us anonymously or by pseudonym. However, we cannot enrol you in a course, verify your eligibility, or allow you to participate in hands-on practical activities without your identifying information and health declaration.

6. How we use your information

We use personal information to:

(a) verify your eligibility to enrol, including your AHPRA registration or student status;

(b) process your enrolment, payment and membership;

(c) deliver the course and the online learning platform to you, and issue certificates of completion or attendance;

(d) assess and manage the safety of hands-on practical activities;

(e) communicate with you about your course, membership and account;

(f) respond to your enquiries, feedback and complaints;

(g) improve our courses, materials and services;

(h) send you marketing communications, where you have consented or where you would reasonably expect it, and always with an unsubscribe option; and

(i) meet our legal, insurance, accounting and record-keeping obligations.

6.1 We use your health information only for the purposes set out in clause 4, and for no other purpose, unless you consent or the use is required or authorised by law.

7. Direct marketing

7.1 We may send you marketing communications about our courses, membership and educational content. Every marketing communication contains a simple way to opt out.

7.2 We do not use sensitive information, including health information, for direct marketing purposes.

7.3 We do not sell, rent or trade your personal information to any third party for their marketing purposes.

8. Who we disclose your information to

We may disclose your personal information to:

(a) our service providers, including our online learning platform, website host, email and marketing platform, payment provider, and cloud storage provider;

(b) our contractors, trainers and guest speakers, but only to the extent necessary for them to deliver the course, and always subject to confidentiality obligations;

(c) our insurer, insurance broker and legal advisers, where necessary in connection with a claim or potential claim;

(d) our accountant and other professional advisers;

(e) emergency services or a treating practitioner, if you require urgent medical assistance during a course; and

(f) a court, regulator, professional body or government agency, where required or authorised by law.

8.1 We do not disclose your health information to any other course participant. Where health information must be shared to keep you safe during a practical activity, we will discuss this with you first and seek your agreement.

8.2 Other participants are required, under our course terms, to keep confidential any personal or health information disclosed during a course. However, we cannot guarantee the conduct of another participant.

9. Overseas disclosure

9.1 Some of our service providers, including our online learning platform, email platform and cloud storage provider, may store data on servers located outside Australia. Where this occurs, we take reasonable steps to ensure the recipient handles your information consistently with the APPs.

9.2 Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure that the recipient does not breach the APPs, including by entering into contractual arrangements requiring the recipient to protect the information.

9.3 We do not routinely disclose health information overseas. Where health declarations are stored electronically, they are held with a provider that stores data in Australia.

10. How we store and protect your information

10.1 We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These steps include password protection, access controls, secure cloud storage, encryption in transit, and staff and contractor confidentiality obligations.

10.2 Health declarations and Consent Forms are stored separately from general course records, and access is restricted to those who need it to run the course safely.

10.3 No method of transmission or storage is completely secure. While we take reasonable steps, we cannot guarantee the absolute security of your information.

10.4 If we become aware of a data breach that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme.

11. How long we keep your information

11.1 We retain personal information for as long as it is needed for the purpose it was collected, and then for as long as we are required to keep it by law, by our insurer, or to defend a potential claim.

11.2 Health declarations and Consent Forms are retained for seven (7) years from the date of the course, reflecting limitation periods for personal injury claims.

11.3 When information is no longer required, we destroy it or de-identify it.

12. Cookies and our website

12.1 Our website uses cookies and similar technologies to make the site work, to remember your preferences, and to understand how the site is used.

12.2 We use Google Analytics to collect aggregated information about site usage. This information is generally not personally identifying.

12.3 You can disable cookies through your browser settings, but some parts of our website may not function properly if you do.

12.4 Our website may contain links to third party websites. We are not responsible for the privacy practices of those websites, and we encourage you to read their privacy policies.

13. Accessing and correcting your information

13.1 You may request access to the personal information we hold about you at any time by contacting us using the details in clause 15.

13.2 We will respond to your request within thirty (30) days. We may need to verify your identity before we release information. In limited circumstances permitted by the APPs we may refuse access, in which case we will tell you why in writing.

13.3 If you believe the information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may ask us to correct it and we will take reasonable steps to do so.

13.4 We generally do not charge for access requests. If a request is complex or requires substantial work, we may charge a reasonable fee, and we will tell you the amount before we proceed.

14. Complaints

14.1 If you believe we have breached the APPs or mishandled your personal information, please contact us using the details in clause 15. Set out the nature of your complaint and the outcome you seek.

14.2 We will acknowledge your complaint within seven (7) days and aim to respond substantively within thirty (30) days.

14.3 If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at www.oaic.gov.au, by telephone on 1300 363 992, or by writing to GPO Box 5288, Sydney NSW 2001.

15. How to contact us

If you have a question, an access request or a complaint about privacy, please contact our Privacy Officer:

Privacy Officer, Bio Health Therapies (Bio Health International Pty Ltd)

Email: [email protected]

Post: 86 Valcan Road, Orange Grove, Perth WA 6109

Telephone: 0461 507 648

16. Changes to this policy

16.1 We may update this Privacy Policy from time to time. The current version is always available on our website and is effective from the date shown below.

16.2 Where a change is material, we will take reasonable steps to notify you, for example by email or by a notice on our website.

| Updated: August 2026 | Ā© Bio Health International Pty Ltd t/as Bio Health Therapies