Privacy Policy
Last updated: September 2026 · Version 1.2
1. Who we are (APP 1)
Acacia Medical (ACN 660 687 525) is a health service provider bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We operate telehealth services from Mermaid Beach / Burleigh Heads, QLD.
We have appointed a Privacy Officer who can be contacted at privacy@acaciamedical.com.au.
2. Information we collect (APP 3)
We collect the following categories of information:
- Identity information: name, date of birth, gender, contact details
- Health information (sensitive): medical history, current conditions, medications, treatment plans, prescriptions
- Government identifiers: Medicare number, IHI, concession card details
- Financial information: payment details processed securely via Stripe (Australia)
- Technical information: session cookies, device type, IP address for security
We only collect information that is reasonably necessary for providing healthcare services. Collection of sensitive health information requires your express consent.
3. Notice at collection (APP 5)
Before collecting your information, we tell you:
- Why we are collecting the information
- Who we may disclose it to (e.g., your chosen pharmacy)
- What happens if you don't provide it
- How you can access and correct your information
- Whether we disclose information overseas
This notice is displayed on every form where personal information is collected, including our consent page, booking wizard, and registration form.
4. Use & disclosure (APP 6)
We use your information for the primary purpose it was collected — providing telehealth care. Secondary uses require your separate, express consent:
- Treatment: providing consultations, issuing prescriptions
- Pharmacy sharing: sending eScripts to your chosen pharmacy (separate consent)
- My Health Record: uploading to MHR (separate, optional consent — never required)
- Research: de-identified data for clinical research (separate consent)
5. Direct marketing (APP 7)
We do not use your health information for direct marketing. Any marketing communications are opt-in only and can be unsubscribed at any time.
6. Cross-border disclosure (APP 8)
Where any service provider stores or processes data outside Australia, we take reasonable steps to ensure APP-consistent handling. Currently:
- Payment processing: Stripe (data stored in Australia)
- Hosting infrastructure: Cloudflare (Australian edge nodes, data may transit globally)
We ensure overseas recipients are bound by similar privacy protections through contractual obligations.
7. My Health Record (APP 2 / MHR Act)
Enrolment in My Health Record is entirely optional and is never a condition of receiving care from Acacia Medical. You may choose to opt in or out at any time via your consent settings.
8. Data retention & destruction (APP 11)
We retain your records in accordance with Australian healthcare records retention requirements:
Adult patient health records
Clinical notes, prescriptions, consultation records
Minor patient health records
Retained until the patient turns 25
Consent records
Proof of each consent granted or withdrawn
Billing & payment records
Transaction history, receipts
Audit logs
Login, access, and consent change events
Session cookies
Authentication tokens
Cookie preferences
Your cookie consent choice
After the retention period expires, records are securely destroyed using industry-standard methods. Health records may be retained longer if required by law, court order, or ongoing clinical need.
You may request early deletion of non-mandatory records by contacting our Privacy Officer. Note that health records required by law cannot be deleted before the minimum retention period.
9. Security of personal information (APP 11)
We protect your information through:
- Encryption in transit (TLS 1.3) and at rest
- Role-based access control (RBAC) — staff only access data necessary for their role
- Comprehensive audit logging of all data access events
- Regular security assessments and vulnerability testing
- Multi-factor authentication for practitioner accounts
- Automatic session expiry after inactivity
10. Access to your information (APP 12)
You have the right to request access to the personal information we hold about you. You can:
- View your records via the patient dashboard
- Download your data at any time
- Request a full copy of your health record from our Privacy Officer
We will respond to access requests within 30 days. Access may be refused in limited circumstances allowed by law (e.g., if providing access would pose a serious threat to health).
11. Correction of information (APP 13)
If your personal information is inaccurate, out of date, incomplete, irrelevant, or misleading, you can request correction via your patient settings or by contacting us. We will correct information within 30 days of a valid request.
12. Cookies & technical data
Our website uses the following cookies:
Essential cookies (always active)
acacia.session-token— authentication sessionacacia.theme— dark/light mode preferenceacacia.cookie-consent— your cookie choice
Analytics cookies (with your consent)
Anonymous usage patterns to improve our services. No health data is included. You can opt out at any time via the cookie banner or by clearing your browser cookies.
13. Data breaches (NDB scheme)
We maintain a data breach response plan in accordance with the Notifiable Data Breaches (NDB) scheme. If a breach is likely to result in serious harm, we will:
- Notify affected individuals as soon as practicable
- Notify the OAIC (Office of the Australian Information Commissioner)
- Take steps to contain the breach and mitigate harm
14. Complaints
If you believe we have breached your privacy, you may:
- Contact our Privacy Officer at privacy@acaciamedical.com.au
- Lodge a complaint with the OAIC at oaic.gov.au
We will investigate and respond to complaints within 30 days.
15. Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with an updated revision date. We will notify patients of material changes via email or in-app notification.