Wellifiy is an integrated health management platform that allows clinicians, health care organisations and patients to manage their care (“Platform”). The Platform is comprised of a patient-facing Patient App and a clinician-facing Clinical Portal.
Wellifiy Pty Ltd (ACN 644 326 125) (“we”, “us” or “our”) and our operation of the Platform is committed to respecting your privacy. This privacy policy sets outs out how we collect, use, process, store, share and disclose your Personal Information on our Platform (“Privacy Policy”). You can view our terms and conditions [www.wellifiy.com/terms-of-use] and contact us at [email protected].
In this Privacy Policy, “User”, “you” or “your” means:
We are committed to protecting your privacy and respecting and upholding your rights under the Australian Privacy Principles (“APPs”) contained in the Privacy Act 1988 (Cth) and the General Data Protection Regulation (EU 2016/679) (the “GDPR”) (collectively, “Privacy Laws”). We are a data controller for the purposes of the GDPR. We ensure that we will take all necessary and reasonable steps to comply with the relevant Privacy Laws and to deal with inquiries or complaints from individuals about compliance with the relevant Privacy Laws.
By accessing and using our Platform, products and services, you freely and expressly consent to the collection, use, processing, storage and disclosure of Personal Information by us as set out in this Privacy Policy.
We will collect Personal Information only by lawful and fair means and not in an unreasonably intrusive way. Generally, we will collect Personal Information directly from you, and only to the extent necessary to provide the Platform and our services to you and to carry out our administrative functions or as required by a relevant Privacy Law.
We will not collect sensitive personal information (as defined under the relevant Privacy Laws) from you. We ask that you do not send us, or do not disclose, any sensitive personally identifiable information (such as information related to racial or ethnic origin, religion or other beliefs, health, criminal background or trade union membership) on or through the Platform or otherwise. If, contrary to this request, you do provide any sensitive personal information, in doing so you consent to us collecting and handling that information in accordance with this Privacy Policy.
If you use a pseudonym when dealing with us or you do not provide identifiable information to us, we may not be able to provide you with any or all of our services as requested. If you wish to remain anonymous when you use our Platform, do not sign into it or provide any information that might identify you.
We require individuals to provide accurate, up to date and complete Personal Information at the time it is collected.
We collect personal information from Clinician and Health Organisations who use the Platform.
“Personal information” is information or an opinion about an individual whose identity is apparent, or can be reasonably ascertained, from that information or opinion (whether true or not, and whether recorded in a material form or not).
We collect the health information of Patients who use the Platform.
“Health information” means:
The types of health information we may seek to collect in relation to Patients are:
Personal Information
We will collect personal information only by full and fair means and not in an unreasonably intrusive way. Generally, we collect personal information directly from Clinicians and Health Organisations, and only to the extent necessary to provide our products and services, to carry out our administrative functions, and as required by law.
We may also collect personal information from you when you fill in an application form, communicate with us, visit our website, provide us with feedback, complete online surveys or participate in competitions.
Health information
We will collect health information on the registration of a new Patient via the Platform.
Under the GDPR, we must have a legal basis to process Personal Information collected from individuals residing in the European Union. We rely on several legal bases to process your Personal Information, including:
Clinician and Health Organisations
We use and disclose the personal information of Clinician and Health Organisations for the purposes for which the information is collected, or for a directly related purpose, including (but not limited to):
We may disclose the personal information of Clinicians and Health Organisations to:
Any person or entity to whom you have consented to us disclosing your personal information to;
Any person or entity to whom we are required or authorised to disclose your personal information to in accordance with the law.
We do not sell or share personal information with third party marketers.
Patients
We will disclose the health information of a Patient only as directed by the Clinician or Health Organisation providing health services to that Patient, in accordance with the express consent of that Patient, or as required to do so in accordance with the law.
Clinicians and Health Organisations
Where we:
We may use and process your Personal Information to send you information about products and services we believe are suited to you and your interests or we may invite you to attend special events.
At any time, you may opt out of receiving direct marketing communications from us. Unless you opt out, your consent to receive direct marketing communications from us and to the handling of your Personal Information as detailed above will continue. You can opt out by following the unsubscribe instructions included in the relevant marketing communication, or by contacting us in writing at [email protected].
Patients
No health information will be used to market directly to Patients. As discussed below, all health information is stored securely in an anonymised format, and Wellifiy staff and service providers will not have access to such information except in very limited, exceptional circumstances.
We use cookies, web beacons and similar technologies (collectively “Cookies”) on our Website. By accessing or using this Website, you agree that we can store and access Cookies in accordance with this Privacy Policy.
Cookies are small files that can be stored on and accessed from a user’s device when the user accesses a website. They enable authorised web servers to recognise you across different websites, services, devices and browsing sessions.
We may use Cookies to enable users to access and use our Website and Services, including to:
The data collected through Cookies will not be kept for longer than is necessary to fulfil the purposes mentioned above.
We will handle any Personal Information collected by Cookies in the same way that we handle all other Personal Information.
You can delete and refuse to accept browser Cookies by activating the appropriate setting on your browser. However, if you select this setting you may be unable to access certain parts of the Website.
Unless you have adjusted your browser setting so that it will refuse Cookies, our system will issue Cookies when you direct your browser to our Website.
When transmitting Personal Information via the Platform, you must keep in mind that the transmission of information over the internet is not always completely secure or error-free. Other than liability that cannot lawfully be excluded, we will not be liable in any way in relation to any breach of security or any unintended loss or disclosure of that information.
We may hold your personal or health information in either electronic or (in rare circumstances) hard copy. We take reasonable steps to protect all personal and health information from misuse, interference and loss, as well as unauthorised access, modification or disclosure.
We have implemented best practice processes to protect personal information and health information from unintended disclosure, misuse and loss. This includes a number of physical, administrative, personnel and technical measures, including by:
Further, in accordance with our obligations under the Health Records and Information Privacy Act 2002 (NSW), Health Practitioner Regulation (NSW), Health Records Act 2001 (Vic), Health Records (Privacy and Access) Act 1997 (ACT) and the Privacy Act 1988 (Cth), we are obliged to retain health information in Australia for a period of:
However, we cannot guarantee the security of any personal or health information transmitted over the internet and therefore you disclose information to us at your own risk. To the maximum extent permitted under law, we are not liable for any unauthorised access, modification or disclosure, or misuse of personal or health information.
Under the GDPR, an individual residing in the European Union has enhanced privacy rights, including the right to:
Subject to some exceptions provided by the relevant Privacy Laws, you may request access to your Personal Information in our customer account database, or seek correction of it, by contacting us. See section 15: Contact information. Should we decline you access to your Personal Information, we will provide a written explanation setting out our reasons for doing so.
If you believe that we hold Personal Information about you that is not accurate, complete or up-to-date then you may request that your Personal Information be amended. We will respond to your request to correct your Personal Information within a reasonable timeframe and you will not be charged a fee for correcting your Personal Information.
If we no longer need your Personal Information for any of the purposes set out in this Privacy Policy, or as otherwise required by the relevant Privacy Laws, we will take such steps as are reasonable in the circumstances to destroy your Personal Information or to de-identify it.
This clause applies to Clinician and Health Organisations who use our services.
In providing or receiving the health information of a Patient via the Platform, you warrant that you have sought all required consents from the Patient to do so and that you have otherwise fully complied with the Privacy Act and all other relevant legislation and regulations pertaining to the collection, storage, use and disclosure of health information.
You agree to indemnify us for any liability, costs and expenses (including our reasonable legal costs) which we incur as a result of a breach by you of your privacy obligations.
We disclaim any liability whatsoever for information collected or shared outside the Platform.
In the circumstances where Wellifiy suffers a data breach that contains personal or health information, we will take all necessary steps to comply with the Notifiable Data Breach Scheme outlined under the Privacy Act and any other laws that apply to the type of information the subject of the data breach.
This means we will immediately make an objective assessment of whether a breach of personal information is likely to result in serious harm to individuals, and if this is the case, endeavour to notify the affected individual(s) and the Australian Information Commissioner.
You will be notified of any data breach affecting your health information.
If you require further information regarding our Privacy Policy or wish to make a privacy complaint, please contact us in writing at [email protected].
We reserve the right to modify this Privacy Policy in whole or in part from time to time without notice. Non-material changes and clarifications will take immediate effect, and material changes will take effect immediately after the posting of the amended Privacy Policy on the Platform.
We will cooperate with the appropriate regulatory authorities, including local data protection authorities, to resolve any complaints regarding the transfer of personally identifiable information that cannot be resolved between us and the individual.
Dated: 07/07/2021