Introduction
1.1 Commitment to Privacy
Melbourne Myotherapy Centre (“we”, “us”, or “our”), a trading name of Bayside Allied Health Pty Ltd is committed to protecting the privacy of the personal information you provide to us through our website (“Website”). This Privacy Policy explains what information we collect, how we use it, and your rights regarding your information.
1.2 Scope of this Policy
This Privacy Policy applies to information collected through the Website. It does not apply to information collected by third-party services, including but not limited to our service providers, Siteground, Google, Microsoft, Cliniko, Stripe, CrazyTel, Hicaps and/or TyroHealth even if they are linked to our Website. Please refer to their respective privacy policies via the links in this paragraph for information on how they handle your data.
1.3 Definitions
The following terms used in this Privacy Policy have the meanings set forth below:
- Personal Information: This refers to any information that identifies an individual or can be reasonably linked to an individual. This may include your name, contact details (phone number, email address), IP address (in some cases), and any other information you provide through our website forms.
- Sensitive Information: This refers to information about an individual’s health (subjective and objective), religion, race, political opinions, biometric information, or membership in a trade union or professional, social or political association. We do not collect or store sensitive information directly on our website. Any health information you provide is collected through secure intake forms or entered into clinical notes during appointments and is stored securely on third-party healthcare applications.
- Website: This refers to the Melbourne Myotherapy Centre website located at melbournemyotherapycentre.com.au.
- Third-Party Service Providers: These are companies that we use to provide specific services related to the operation of our website and our business. This may include but is not limited to website hosting providers, appointment booking software, email providers, telephony services, payment processors, and private health rebate/refund processing services.
- Cookies: These are small data files stored on your device (computer, phone, tablet) when you visit a website. They typically include an anonymous unique identifier and allow a website to remember your preferences (like login information) and improve your browsing experience.
- Data Breach: This is an incident where unauthorised access is gained to personal information.
Information We Collect
2.1 Personal Information
We collect personal information that you provide to us through our contact form. This may include your name, telephone number, email addresses, and also IP addresses, browser information, how you interact with our website, and any other information that you provide within these forms.
We also collect personal information for the purpose of undertaking necessary business practices and to comply with State and National Laws. You can refer to the following section for more information.
2.3 Recording and Monitoring
For the safety and security of our staff, clients, and visitors, we operate closed-circuit television (CCTV) surveillance systems at all of our premises. These systems have been installed in compliance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) and relevant health services regulations. Surveillance equipment is limited to public areas such as reception, waiting rooms, and corridors, and is never installed in private treatment rooms, consultation spaces, or bathroom facilities.
Where our clinics are located within office buildings or shared facilities, please note that we are not responsible for, nor do we have access to, any CCTV systems operated by the building management outside our operating premesis. Our privacy policy applies only to surveillance equipment owned and operated by Melbourne Myotherapy Centre within our business premises. By entering our facilities, you acknowledge and consent to being recorded by video and audio monitoring systems in these public areas.
In our commitment to providing comprehensive care and accurate clinical documentation, we may utilise audio transcription and AI-assisted note-taking software during consultations. These technologies help our practitioners maintain detailed records of your treatment while allowing them to focus on delivering quality care. All recordings and AI-generated notes are treated with the same level of confidentiality as handwritten clinical notes, in accordance with the Australian Privacy Principles and relevant health records legislation. These records are securely stored in your confidential patient file and are used solely for the purposes of your ongoing treatment. You will be informed prior to any consultation where recording or AI note-taking will be utilised, and you maintain the right to decline this service without affecting your treatment quality. If you have any concerns regarding this practice, please discuss them with your practitioner before your appointment.
2.4 Sensitive Information Disclaimer
We do not collect or store sensitive information on our website, such as health or medical records, medical conditions, medications, credit card details, etc. Any health information that you provide is collected through a secure intake form or entered into clinical notes by our practitioners and/or administration team leading up to, during or post your appointments and is stored securely on third-party healthcare applications (e.g. Cliniko). Any sensitive information associated with finances including but not limited to credit/debit cards, transactions, or private health details are managed by Stripe, Tyro Health and/or HICAPS. You can read their privacy policies by referring to the hyperlinks in Section 1.2 of this privacy policy.
How We Use Your Information
3.1 Personal Information
We use your personal information for communication only between our administration staff and/or practitioners and our clients (or any other person enquiring via our telephone or email services). We will use your provided details to respond to your online inquiries and provide you with the information or services you request where possible or within our scope. We will also use this information to contact you for the purpose of undertaking our business including but not limited to appointment reminders and/or follow-up emails and/or phone calls, payment/refund enquiries, etc. We do not share your personal information with any third-parties for the purpose of marketing without your explicit consent.
3.2 Sensitive Information
We use your sensitive information for undertaking our business which includes but it not limited to treatments and clinical notes. We will use your sensitive information to compile assessment notes, develop treatment plans and to record progress reports. We will also use this information to provide referals with other health care professionals but only with your explicit and written consent. We do not share your sensitive information with any third-parties for the purpose of marketing.
Sharing Your Information
4.1 Service Providers
We use third-party service providers to host our website (SiteGround) and the information is stored on Amazon Cloud located in Sydney, Australia. Our appointment, booking and scheduling software (Cliniko), email and communication software (SiteGound, Google), Telephone services (Crazytel), Private Health Rebate/Refund processing services (HICAPS and/or TyroHealth), and payment processing services (Stripe) may have access to your personal information in order to perform their services on our behalf. Please refer to their privacy policies (Section 1.2) for more information about how they handle your data.
4.2 Legal Requirements
In accordance with applicable state and federal laws, we may be required to disclose your personal and sensitive information in response to lawful requests from authorised entities, such as regulatory bodies, courts, or law enforcement agencies or under such requirements such as mandatory reporting. Such disclosures will only be made where mandated by law and in compliance with the Privacy Act 1988 (Cth) and other relevant legislation.
Data Security
5.1 Protecting Your Data
We take reasonable steps to protect your personal information from unauthorised access, disclosure, alteration, or destruction. These steps include:
- Secure Passwords and Access Controls: We limit access and implement strong password policies for all authorised staff and system administrators with access to your information. We also limit access to your information on a “need-to-know” basis.
- Data Encryption: We encrypt your personal information both in transit (using technologies like HTTPS) and at rest (using secure storage methods).
- Firewalls and Intrusion Detection Systems: We use firewalls and intrusion detection systems to monitor and prevent unauthorised access to our systems.
- Regular Security Updates: We keep our software and systems up to date with the latest security patches to address known vulnerabilities.
- Data Backup and Recovery: We maintain regular backups of your data to ensure its recovery in case of a disaster or system failure.
In addition to the above, we also require our third-party service providers to maintain appropriate security safeguards for your information. We enter into agreements with them that obligate them to protect your data in accordance with our standards.
Whilst we aim to provide exceptional service in the realm of data protection, we cannot guarentee your data is safe. In the event of a data breach, we will notify you and the relevant regulators as required by law. We will also take steps to mitigate the impact of the breach and prevent similar incidents from occurring in the future.
Cookies and Tracking Software
6.1 Cookies
We may use cookies and other tracking technologies including but not limited to Google Analytics to collect non-personal information about your use of the Website. Cookies are small data files stored on your device (computer, tablet, phone) when you visit a website. They typically include an anonymous unique identifier and allow a website to remember your preferences (e.g., login information, language preference) and improve your browsing experience. You can control the use of cookies through your web browser settings.
6.2 Tracking Software
We may use tracking technologies including but not limited to Google Analytics, Google Ads and/or Microsoft Claity to collect non-personal information about your use of the Website. This information may include the pages you visit, the geographical location when you visit, the buttons or links you click, the ways in which you interact with our website and the amount of time you spend on the Website. You can control the use of cookies through your web browser settings.
6.3 How We Use This Information
We use cookies and tracking software for the following purposes:
- To remember your preferences and personalise your experience on the Website.
- To understand how you use the Website and improve its overall functionality and user experience.
- To analyse website traffic and usage patterns.
- To deliver targeted advertising on third-party websites based on your interests and/or search intent with your consent (where required).
6.4 Types of Cookies
- Essential Cookies: These cookies are strictly necessary for the Website to function properly. They allow you to navigate the Website and use its features.
- Performance Cookies: These cookies collect information about how you use the Website, such as the pages you visit and any errors you encounter. We use this information to improve the Website’s performance and user experience.
- Functionality Cookies: These cookies allow the Website to remember your choices (e.g., language preference, login information) and provide you with a more personalised experience.
- These cookies may be used to deliver targeted advertising based on your interests and browsing behavior. We will only use these cookies with your consent (where required).
6.5 Your Cookie Preferences
You have several options for managing cookies:
- Most web browsers allow you to control, manage or disable cookies in your browser settings. Please refer to your specific browser’s documentation for instructions on how to do this.
- You can opt-out of interest-based advertising from certain ad networks by visiting https://optout.aboutads.info/ and https://thenai.org/opt-out/.
- You can also opt-out of Google Analytics tracking by visiting Google Analytics Opt-out: https://tools.google.com/dlpage/gaoptout.
Please note that disabling cookies may limit your ability to use certain features of our Website and third-party websites which we use to undertake our business operations.
Children’s Privacy
7.1 Personal Details of Persons Under 18
We recognise the importance of protecting the privacy of minors (persons under the age of 18). In accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), we do not knowingly collect, use, or disclose personal information from individuals under the age of 18 without verifiable parental or legal guardian consent.
We implement appropriate security measures to protect any personal or health information collected from minors, ensuring compliance with APP 11 (Security of Personal Information) and monitor legislative updates, including any future Children’s Privacy Code introduced by the Australian Government, and will adjust our practices accordingly.
7.2 Parental or Guadian Consent
If a minor seeks to engage with our services, we may require parental or guardian consent before collecting or processing any personal or health-related information. Parents or legal guardians may contact us at any time to review, update, or request deletion of a minor’s personal information.
Where parental or guardian consent has been obtained, we will only collect, use, and store a minor’s personal or health information for the purpose of providing our services, in accordance with the Australian Privacy Principles (APPs).
7.3 Unintentional Data Collection and Removal
If we become aware that we have collected personal or sensitive information from a minor under the age of 18 without proper consent, we will take immediate steps to:
- Delete or de-identify the information as soon as practicable, unless retention is required by law.
- Notify the parent or legal guardian, where possible.
If you believe we have collected a child’s personal information without consent, please contact us immediately and we will act in accordance with this legislation.
Retention Period
8.1 Personal Information
We will retain your personal information for as long as it is necessary for us to fulfil the purposes for which it was collected, and as required by law. This may include:
- Responding to your inquiries and requests.
- Providing you with appointment reminders and follow-up communication.
- Maintaining accurate records for billing and administrative purposes (as required by law).
- The specific retention period for your personal information will vary depending on the nature of the information and the purposes for which it is used, however, we will not retain your personal information for longer than is necessary.
- For information on the specific retention periods used by our third-party service providers, please refer to their respective privacy policies via the hyperlinks in Section 1.2.
You also have the right to request the deletion of your personal information held by us, subject to some exceptions outlined in the Australian Privacy Principles. The request for deletion of personal information may reduce or exclude you from the services we can provide.
Your Rights
9.1 Personal Information
Under the Australian Privacy Act 1988, you have certain rights in relation to your personal information. These rights include:
- The right to access your personal information.
- The right to request correction of inaccurate personal information.
- The right to request deletion of your personal information (subject to some exceptions).
- The right to object to the collection or use of your personal information.
- The right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe that your privacy rights have been breached.
- You also have the right to be notified of any data breaches that may compromise your personal information.
For more information about your privacy rights under the Act, you can visit the website of the OAIC at https://www.oaic.gov.au/.
Policy Changes
10.1 Modification to Policies
We reserve the right to modify this Privacy Policy at any time. We will notify you of any material changes by posting the revised Privacy Policy on our Website. It is your responsibility to check our Website periodically for updates. We will also provide a reasonable period of time for you to review the changes before they come into effect. Your continued use of the Website following the posting of any revised Privacy Policy signifies your acceptance of the changes.
Version History
11.1 Privacy Policy
This Privacy Policy was last updated on the 22nd of October, 2024. We may update this Privacy Policy from time to time. We reserve the right to make changes to this privacy policy without notice and encourage you to review this Privacy Policy periodically for any changes.
10/03/2025 – Version 1.1 (Current): Updated Section 2.1 Personal Information.
22/10/2024 – Version 1.0: Drafted and Published Privacy Policy.
Contact Us
You can contact us regarding your privacy concerns or to exercise your rights under the Australian Privacy Act 1988.
Additionally, you can access further information about your privacy rights by visiting the Office of the Australian Information Commissioner (OAIC) website: https://www.oaic.gov.au/.
