Privacy Policy

Your Privacy

Last Updated: 1st June 2026

We are committed to protecting your privacy as a patient, customer, or visitor to our website. We handle your personal and health information responsibly, in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), relevant state and territory privacy legislation, and applicable cybersecurity standards. This policy explains how we collect, use, disclose, and secure your information, your rights to access and correct your information, and how you may raise a privacy complaint. This Privacy Policy also addresses the responsible use of Artificial Intelligence (AI) technologies within our practice.

1. Scope and Purpose

This Privacy Policy applies to all patients, clients, and website visitors. It covers:

  • Collection, use, and disclosure of personal and health information
  • Collection and use of information for research, quality improvement, and marketing
  • Use of Artificial Intelligence (AI) in clinical and administrative processes
  • Data storage, security, retention, and destruction
  • Your rights to access, correct, or remain anonymous/pseudonymous
  • How to make complaints and how we review our policy

2. Consent

When you attend the Clinic, we will request your information and obtain your consent to collect, use, and disclose your personal and health information for the purpose of providing healthcare.

  • We will seek additional consent if your information is to be used for purposes beyond your care, including research or marketing.
  • Consent may be withdrawn at any time; however, this may affect the delivery of some services.

3. Collection of Personal and Health Information

We may collect the following information, where necessary for your healthcare:

  • Personal identifiers: name, date of birth, address, contact details
  • Health information: medical history, clinical notes, diagnostic results, treatment plans
  • Financial information: Medicare details, private health insurance, billing information
  • Images: clinical photographs or scans with your consent
  • AI-generated data: outputs from AI-assisted transcription
  • CCTV footage: collected on premises for security and safety purposes
  • Website use data: cookies, pixels, and analytics data

We collect information primarily from patients, but may also obtain it from:

  • Other treating practitioners, hospitals, diagnostic providers (with your consent)
  • Relatives or carers in certain circumstances

We collect and handle personal and health information of individuals under the age of 18 when it is necessary for providing healthcare services. In these cases, we collect this information with the consent of a parent, legal guardian, or as otherwise permitted by law for mature minors.

4. Use and Disclosure of Personal Information

Your information may be used for:

  • Provision of medical treatment and care
  • Coordination with other healthcare providers involved in your care
  • Administrative purposes: billing, compliance, and recordkeeping
  • Legal compliance, court orders, or law enforcement requests
  • We communicate with you via phone, SMS, email, or secure messaging systems. Standard SMS and email are unencrypted and are strictly reserved for general administrative notifications, such as appointment reminders. Sensitive health information and clinical data will only be transmitted via secure, encrypted messaging channels, unless you expressly authorise us in writing to use alternative methods.

We do not disclose your personal or health information overseas unless necessary for your care and where appropriate safeguards are in place.

5. Research, Quality Improvement, and Marketing

We are committed to continuously improving the quality of our services and supporting clinical education

Quality Improvement: We may use your information (de-identified where possible) for clinical audits, staff training, and accreditation activities.

Research: Identifiable data may be used only with your express consent, and research will only proceed if ethically approved and legally compliant.

De-identified Data Sharing: We may contribute anonymised data to registries or improvement initiatives. You may opt out by contacting reception.

Marketing: Personal information will only be used for marketing if you provide consent. You may opt out at any time.

6. Use of Artificial Intelligence (AI)

We use AI to enhance administrative and clinical documentation, appointment scheduling, and patient engagement.

  • AI is not used to make clinical decisions.
  • Personal information is not used to train AI models without express consent.
  • All AI outputs are reviewed by humans and clinical staff.
  • The platform complies with the APPs and ethical standards, and our platforms hold relevant certifications (e.g., ISO 27001).

7. Anonymity and Pseudonymity

You may request to remain anonymous or use a pseudonym where practicable. Due to the nature of healthcare, identification may be required by law or for safe provision of care.

8. Data Security and Retention

We take reasonable steps to protect your information from misuse, interference, loss, and unauthorised access. Measures include:

  • Secure electronic medical records with role-based access
  • Staff training on privacy and cybersecurity
  • Regular audits and software updates

We retain records in line with legal, professional, and operational requirements. Once information is no longer required, it will be destroyed securely.

In the event of an unauthorised access, disclosure, or loss of your personal information, we will follow our data breach response plan. If the breach is likely to result in serious harm, we will assess it promptly within 30 days and formally notify both you and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme.

9. Access and Correction

You have the right to request access to or correction of your personal information. Requests should be made in writing to our Privacy Officer.

  • We will respond within 30 days (unless otherwise required by law)
  • Corrections will be made promptly to maintain accuracy

10. Complaints and Enquiries

You can contact the privacy team about any privacy issues as follows:

Privacy Officer Team
Role: Business Development Manager
Email: manager@garrybuckland.com
Phone: 02 8969 2400

If unsatisfied, you may contact the Office of the Australian Information Commissioner (OAIC):
Website: www.oaic.gov.au
Phone: 1300 363 992

11. Cookies and Website Tracking

Our website uses cookies and pixels to analyse traffic, improve functionality, and provide relevant advertising. Cookies do not access information stored on your device. You may disable cookies, but some features may not function.

12. Sharing Information with Third Parties

We may share your information with third parties:

  • When legally required (court, law enforcement)
  • For services purchased or required (billing, IT, labs)
  • To protect our legal rights or the safety of others

All third parties are contractually obligated to comply with our privacy standards.

13. Policy Review and Updates

This policy is reviewed at least annually, or when changes occur in operations, law, or technology. Significant updates will be communicated via email, website, or in-practice notices.