Clinic Privacy Policy
Last updated: 18 August 2025
1. Our Commitment to Your Privacy
Welcome to Authentic Self Psychology and Consulting (trading as Authentic Self Psychology). Your privacy and the confidentiality of your personal information are paramount to us. This policy outlines how we collect, use, store, and protect your information in accordance with our legal and ethical obligations, including the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth) and the Health Records Act 2001 (Vic). This policy should be read in conjunction with our Nature of Service & Consent form, which you will receive before commencing our services.
2. What Information We Collect
To provide you with safe and effective psychological care, we need to collect and hold personal information. This may include:
-
Personal Information: Your name, date of birth, address, email, and phone number.
-
Sensitive (Health) Information: Information gathered during sessions, including your medical history, presenting concerns, session notes, treatment plans, psychological assessment results, and communications with other health professionals involved in your care.
-
Third-Party Information: Referrals, reports, and correspondence from your GP, psychiatrist, or other relevant third parties (e.g., family members, schools), collected with your consent.
-
Medicare & Funding Information: Your Medicare number and details of any third-party funding arrangements to process payments and rebates.
-
Financial Information: Payment details required for processing session and cancellation fees, managed securely via our payment processor, Go Cardless.
3. How We Collect Your Information
Your personal information is collected in several ways:
-
Directly from you: When you complete intake forms, communicate with us via email, or during your psychology sessions.
-
From referring professionals: When you are referred by a GP or other healthcare provider, we receive a referral letter containing your personal and health information.
-
From third parties: With your explicit consent, we may collect information from other sources, such as family members or other health professionals.
If you choose not to provide the necessary personal information, we may be unable to provide you with the psychological service you require.
4. Why We Collect, Hold, and Use Your Information
Your information is used for the primary purpose of providing high-quality psychological services. This includes:
-
Assessing your needs and developing a collaborative treatment plan.
-
Diagnosing and treating your presenting psychological concerns.
-
Documenting your therapeutic journey to ensure continuity of care.
-
Communicating with other healthcare professionals involved in your care (with your consent).
Your information may also be used for related secondary purposes, such as:
-
Administration: Processing fees, issuing invoices, and managing appointments.
-
Medicare Rebates: Disclosing necessary information (your name, date of birth, Medicare number, session date, and item number) to Services Australia to process your Medicare rebate. This is a mandatory requirement for accessing the rebate.
-
Professional Supervision: To ensure high ethical and professional standards, your psychologist may discuss your case with a supervisor. In these instances, all identifying details are removed to protect your identity.
-
Legal & Safety Obligations: Fulfilling our legal and ethical duties, as outlined in the "Disclosure of Your Information" section below.
​
5. How We Store and Protect Your Information
We take the security of your information very seriously.
​
-
Secure Digital Systems: Your clinical file is held securely in Zanda Health, an encrypted, cloud-based practice management system with medical-grade security. All our digital tools, including NovoPsych (for assessments) and Go Cardless (for payments), are chosen for their high standards of security and compliance with Australian privacy laws.
-
Access Control: Access to your information is strictly limited to your psychologist and authorised administrative staff.
-
Data Retention & Destruction: In line with legal requirements, we retain client files for a minimum of 7 years after the last contact (or until a client who was a minor turns 25). After this period, your file is securely and permanently destroyed.
-
Data Breach Plan: In the unlikely event of a data breach involving unauthorised access, disclosure, or loss of your information, we will activate our data breach response plan to minimise any risk of harm and notify you and the Office of the Australian Information Commissioner (OAIC) as required by law.
6. Disclosure of Your Information & Limits to Confidentiality
All information you share with us is confidential and will not be disclosed without your consent, except in the following specific circumstances:
-
Risk of Harm: If we hold a reasonable belief that you or another person is at serious and imminent risk of harm, we have a duty of care to take protective action.
-
Child Safety: As mandated reporters, we are legally required to report any concerns about a child's safety to relevant child protection authorities, in line with the Victorian Child Information Sharing Scheme (CISS) and Family Violence Information Sharing Scheme (FVIS).
-
Legal Requirement: If your file is subpoenaed by a court of law, or if disclosure is otherwise required or authorised by law.
-
With Your Consent: If you provide written consent for us to share information with another person or agency (e.g., a GP, lawyer, or family member).
7. Specific Privacy Considerations
-
Telehealth: We use the secure, encrypted Zanda Health platform for telehealth sessions. While we take all reasonable steps to ensure the privacy of these sessions, you are responsible for ensuring your own environment is private and secure (e.g., using a private Wi-Fi network and a confidential space for the call).
-
Digital Scribing (AI-Assisted Notes): We may use the AI-assisted scribing tool NovoNote to help create session notes. This service is only used with your separate, explicit consent. The process is designed with privacy at its core: audio is temporarily processed to generate a draft note, the audio file is immediately deleted, and your psychologist reviews and edits the final note. All data is stored securely in Australia. For more details, please see: Digital Scribing
8. Your Rights: Access and Correction
You have the right to request access to the personal information we hold about you. You may also request that we correct any information you believe is inaccurate or out of date.
-
How to Make a Request: Please lodge your request in writing with Authentic Self Psychology.
-
Our Response: We will respond to your request within 30 days. We may arrange an appointment to discuss the contents of your file with you.
-
Exceptions: In some circumstances, access may be denied in accordance with exceptions outlined in the Privacy Act 1988 (Cth) (e.g., if access would pose a serious threat to the life or health of any individual).
9. Concerns and Complaints
If you have any concerns about how we have managed your personal information, please discuss them with us first. We are committed to resolving your concerns promptly and transparently. If you are not satisfied with our response, you have the right to lodge a formal complaint with the Office of the Australian Information Commissioner (OAIC):
-
Phone: 1300 363 992
-
Online: http://www.oaic.gov.au/privacy/making-a-privacy-complaint
-
Post: GPO Box 5218, Sydney, NSW 2001
10. Change in Privacy Policy
As we plan to ensure our privacy policy remains current, this policy is subject to change. We may modify this policy at any time, in our sole discretion and all modifications will be effective immediately upon our posting of the modifications on this website. Please return periodically to review our privacy policy.