Privacy Policy
Effective date: 1 January 2025 | Version 1.0 | Last reviewed: 1 January 2026
At Intouch Healthcare, we value your trust and are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, store and protect your personal and health information when you use our website or telehealth services in Australia.
Intouch Healthcare Pty Ltd (ABN 92 689 545 560) is an Australian telehealth service led by AHPRA registered Nurse Practitioners. As a provider of health services, we are bound by the Privacy Act 1988 (Cth) (Privacy Act) regardless of our annual turnover, and we comply with the thirteen Australian Privacy Principles (APPs). We also handle health information, which the Privacy Act treats as sensitive information and protects to a higher standard.
By using our website or services, you agree to the handling of your personal information as described in this policy.
1. The kinds of personal information we collect
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. Depending on how you interact with us, we may collect:
- Identity and contact details — your name, date of birth, gender, postal and email addresses, and phone number.
- Health information — your medical history, symptoms, current and past medications, allergies, the reasons for your consultation, clinical notes, prescriptions, referrals, pathology requests, and other information relevant to the care our Nurse Practitioners provide. Health information is sensitive information under the Privacy Act.
- Government and healthcare identifiers — such as your Medicare number, Individual Healthcare Identifier (IHI), pension or concession card details, where relevant to your care or to claiming.
- Payment information — details required to process payments. Card details are handled directly by our payment gateway, Stripe, and are not stored by us.
- Technical and usage information — collected automatically when you use our website, such as your IP address, device and browser type, pages visited and interactions, collected through cookies and similar technologies.
- Correspondence — the content of enquiries, feedback, complaints and other communications you send us.
If you do not provide the information we request, we may be unable to provide a consultation, issue a prescription, certificate or referral, or otherwise deliver the service you have asked for.
2. How we collect your information
Wherever it is reasonable and practicable, we collect personal information directly from you. We collect it when you:
- create an account, complete an online intake or consultation form, or book an appointment;
- speak or message with one of our Nurse Practitioners or support team during a consultation or follow up;
- make a payment, or contact us by phone, email or through our website; or
- browse our website, where technical information is collected through cookies and analytics tools.
In some cases we may collect information about you from a third party, for example a referring practitioner, a pharmacy, a pathology provider, or a person authorised to act on your behalf, where it is necessary for your care and you would reasonably expect us to do so, or where the law permits or requires it. Because we collect health (sensitive) information, we will generally only do so with your consent, unless an exception under the Privacy Act applies.
3. Why we collect, hold, use and disclose your information
We collect, hold, use and disclose personal information so that we can:
- verify your identity and assess your suitability for our services;
- provide telehealth consultations and clinical care through our Nurse Practitioners;
- issue prescriptions, medical certificates, referrals and pathology requests;
- communicate with you about your care, including reminders and follow ups;
- process payments and manage our accounts and records;
- respond to your enquiries, feedback and complaints;
- operate, maintain, secure and improve our website and services;
- send you service and, where you have not opted out, marketing communications; and
- comply with our legal, regulatory and professional obligations.
We will only use or disclose your personal information for the purpose for which it was collected, for a directly related secondary purpose you would reasonably expect, where you have consented, or where the Privacy Act otherwise permits or requires it.
4. Who we disclose your information to
We may disclose your personal information to:
- our Nurse Practitioners and authorised personnel involved in your care;
- pharmacies, pathology providers, specialists and other healthcare providers, where necessary to give effect to a prescription, referral or request, or to coordinate your care;
- our service providers, including our clinical and practice management system (Halaxy), our payment gateway (Stripe), and our IT, cloud hosting, communications and analytics providers, who handle information on our behalf under contractual confidentiality and security obligations;
- a person you have authorised to act on your behalf;
- government agencies, regulators, insurers or law enforcement, where required or authorised by law; and
- professional advisers such as our lawyers, accountants and auditors.
We do not sell, rent or trade your personal information.
5. Disclosure of information overseas
Most of your personal and health information is stored in Australia. We use Halaxy as our clinical and practice management system, and Halaxy stores Australian practitioner and patient data on secure servers located in Australia. Our website and email are hosted in Australia by VentraIP.
When you make a payment, your payment information is handled by our payment gateway, Stripe. To provide its services, Stripe processes and stores payment related personal information in the United States. We take reasonable steps to ensure that Stripe and any other overseas recipient handles your personal information consistently with the Australian Privacy Principles.
We use Google Analytics on our website to understand how the site is used so we can improve it and support our search engine optimisation. Google Analytics may process limited technical information about your use of our website overseas, including in the United States, in accordance with Google’s own privacy terms.
6. Direct marketing
We may use your contact details to send you information about our services that may be of interest to you. Every marketing communication will include a simple way to opt out, and you can ask us to stop sending marketing material at any time by contacting our Privacy Officer. We will not use your sensitive health information for marketing without your consent.
7. How we store and protect your information
We hold personal information in electronic systems, including our clinical and practice management system, Halaxy, and secure cloud storage. We take reasonable technical and organisational measures to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These measures include:
- storing clinical and patient records in Halaxy, which provides encryption of data in transit and at rest, daily backups, and Australian based hosting;
- hosting our website and email in Australia with VentraIP, over secure encrypted (HTTPS) connections;
- processing card payments through Stripe, a PCI DSS compliant payment provider, so that card details are not stored by us;
- requiring multi factor authentication on the applications and systems we use to access personal information;
- restricting access to personal information to authorised personnel who need it for their role, using individual logins and role based permissions; and
- requiring our staff and contractors to maintain the confidentiality of personal information.
While we take these steps to safeguard your information, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Retention, destruction and de-identification
We keep personal information only for as long as it is needed for the purposes described in this policy, or for as long as we are required to keep it by law. Health records are subject to minimum retention periods under Australian law, generally seven years from the date of last service for adults, and for a child until they reach 25 years of age, or as otherwise required.
When personal information is no longer required and we are not legally obliged to retain it, we will take reasonable steps to securely destroy it or to permanently de-identify it.
9. Cookies and website analytics
Our website uses cookies and similar technologies to help it function, to remember your preferences, and to understand how the site is used so we can improve it. You can manage or disable cookies through your browser settings, although some parts of the website may not work properly if you do. We use Google Analytics to measure website traffic and performance, and Google may collect information about your use of the site in accordance with its own privacy terms.
10. Automated decision-making
Clinical decisions about your care are always made by one of our AHPRA registered Nurse Practitioners. We do not use computer programs to make, or to substantially make, decisions about your treatment or eligibility for our services without the involvement of a Nurse Practitioner. We may use technology to support administrative tasks such as scheduling, reminders and routing enquiries, but these tools do not make clinical decisions about you.
11. Accessing and correcting your personal information
You have the right to ask for access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, please contact our Privacy Officer at support@intouchhealthcare.com.au or using the details below.
We will respond within a reasonable period. We may need to verify your identity before acting on a request. In most cases access is free, although we may charge a reasonable cost for retrieving and providing the information. If we are unable to give you access or to make a correction, we will explain why in writing and tell you how you can complain about that decision.
12. Data breaches
We have procedures in place to identify, contain and assess suspected data breaches. If a data breach is likely to result in serious harm to any individual whose personal information is involved, we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under the Privacy Act.
13. How to make a complaint
If you believe we have mishandled your personal information or breached the Australian Privacy Principles, please contact our Privacy Officer at support@intouchhealthcare.com.au with the details of your concern. We will acknowledge your complaint promptly, investigate it, and respond to you in writing, usually within 30 days. If we need more time, we will let you know.
If you are not satisfied with our response, you can refer your complaint to the OAIC at www.oaic.gov.au, by phone on 1300 363 992, or by writing to GPO Box 5288, Sydney NSW 2001.
14. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or in the law. The current version will always be available on our website, and the effective date at the top of this policy shows when it was last updated. We encourage you to review it periodically.
15. How to contact us
If you have any questions about this policy or about how we handle your personal information, please contact our Privacy Officer:
Privacy Officer, Intouch Healthcare
Email: support@intouchhealthcare.com.au
Phone: 07 3303 8561
Postal address: Level 19, 10 Eagle Street, Brisbane QLD 4000