Legal stuff

Privacy Policy

Legal stuff

Privacy Policy

Legal stuff

Privacy Policy

Introduction

This Privacy Policy explains how I Got My Life Back collects, uses, stores and shares your personal information—including your health information. It outlines how your information is handled within our service and the situations in which it may be disclosed to third parties.


Why and when your consent is required

When you register as a patient with I Got My Life Back, you consent to our practitioners and support staff accessing and using your personal information so they can deliver appropriate healthcare. Your information is only accessible to team members who need it to perform their role. If we ever require your information for a purpose outside of your direct care, we will request additional consent.


Why we collect, use, hold and share personal information

We collect personal information primarily to provide you with safe, effective healthcare. Your information may also be used for activities directly related to the delivery of our services—such as billing, audits, accreditation requirements, and internal business processes (e.g., staff training).


What personal information we collect

The types of information we collect may include:

  • your name, date of birth, address and contact information

  • medical details such as your history, medications, allergies, immunisations, family and social history, risk factors and adverse events

  • healthcare identifiers

  • health fund details


Your right to anonymity

You may choose to interact with us anonymously or under a pseudonym unless it is impractical for us to do so, or if we are legally required to deal only with identified individuals.


How we collect your personal information

We may collect your information in several ways:

  • During your initial registration, our staff gather personal and demographic information.

  • Throughout your care, we may collect additional clinical details.

  • We may also collect information when you visit our website, contact us via email, SMS, phone, or interact with us through social media or online booking systems.

In some situations, we may receive information from other sources when it is not feasible to obtain it from you directly. These may include:

  • your guardian or responsible person

  • other healthcare providers (specialists, hospitals, allied health, pathology and imaging services)

  • Medicare, your health fund, or the Department of Veterans’ Affairs


When, why and with whom your information may be shared

We may share your personal information:

  • with third-party organisations engaged for business operations such as IT providers or accreditation bodies (who must comply with applicable privacy laws and this policy)

  • with other healthcare providers involved in your treatment

  • when required or authorised by law (e.g., subpoenas)

  • where it is necessary to reduce or prevent a serious threat to your health, safety, or the public

  • to assist with locating a missing person

  • to establish, exercise or defend a legal or equitable claim

  • as part of a confidential dispute-resolution process

  • when specific health conditions require mandatory reporting

  • via eTP or My Health Record during medical care (e.g., Shared Health Summary or Event Summary)

We do not share your information with third parties for purposes unrelated to your care unless you provide explicit consent.

We do not disclose personal information outside Australia unless permitted by law and with your consent.

We will not use your information for direct marketing without your express permission, and you may withdraw consent at any time by notifying us in writing.

We may use non-identifiable, de-identified data for service improvement or population health research. If you prefer not to participate, please let our support team know.


How we store and protect your information

Your information may be stored in paper or electronic form.

All personal information is stored securely. Our systems and patient management software comply with Australian Privacy Principles and international security standards, including GDPR, PIPEDA and HIPAA. Our hosting partner, Webcentral, maintains certifications such as:

  • PCI DSS Level 1

  • ISO 27001

  • FIPS 140-2


Accessing and correcting your personal information

You have the right to request access to your personal information or ask for corrections if details are inaccurate or outdated.

Requests must be submitted in writing to:
[email protected]

We will respond within approximately 30 days.

We will take reasonable steps to ensure your information remains accurate and current. You may request corrections at any time by writing to the address above.


Making a privacy complaint

If you have concerns about how your information has been handled, please contact us in writing. We take all privacy concerns seriously and will aim to resolve them through our internal processes.

Contact details:
[email protected]
We will respond within 30 days.

You may also lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
www.oaic.gov.au | 1300 363 992


Privacy and our website

We collect personal information when you use our website, complete forms or make appointments. Our website uses HTTPS encryption, ensuring that all transmitted data is secure.


Policy review statement

This policy is reviewed regularly and updated to reflect changes in legislation and business operations.