top of page

Website Privacy Policy

Authentic Self Psychology & Consulting, trading as Authentic Self Psychology | ABN 52 684 607 302

Effective date: 25 August 2026 | Routine review: 24 months after the effective date, or earlier following a material change.

1. Purpose and scope

This policy explains how Authentic Self Psychology handles personal information associated with visits to www.authenticselfpsychology.com.au and its website-enabled functions.


It applies to website visits, Wix forms, the availability email register, password-protected general resource pages, website-associated emails and any enquiry-call booking link enabled by the practice. The practice does not operate an online store or public website account system.


Some functions described in this policy are conditional. References to enquiry-call booking and Calendly apply only when the practice enables those functions. Their inclusion does not mean that enquiry calls, appointments or a waitlist are currently available. The availability email register is not a waitlist and does not create priority, a therapeutic relationship or a guarantee of future availability.


The Clinic Privacy Policy applies when information is handled as part of assessing, providing or administering psychological services. Both policies may apply when website information is transferred into practice systems or becomes part of an enquiry or client record. The Clinic Privacy Policy governs that information as part of the health service.

2. Information that may be collected through the website

The information collected depends on how the website is used and may include:

  • an email address, consent record and communication preference associated with the availability email register;

  • information included in an email or website form;

  • when enquiry calls are enabled, booking information supplied through the linked booking service, such as name, contact details, selected time, time zone and information voluntarily provided;

  • technical information associated with password-protected general resource access;

  • technical information generated by use of site search; the practice does not knowingly review or retain visitors’ search terms; and

  • IP address, approximate location, device and browser information, pages visited, referral source, interaction information and cookie or analytics identifiers generated by Wix or other enabled website technologies; and

  • security, consent and communication-preference information.

  • Website forms are designed to collect only the information reasonably needed for the relevant function. Detailed or sensitive health information should not be submitted through ordinary website forms, email or social media. The practice’s designated secure upload pathway should be used when sensitive documents are required.

3. How information is collected

Information may be collected when a person:

  • submits a website form or joins the availability email register;

  • uses a Calendly booking link when enquiry calls are enabled;

  • sends an email through an address or link on the website;

  • uses the password-protected general client resource area or another linked practice service; or

  • browses or interacts with the website through cookies, analytics, accessibility, security or performance technologies.

 

4. How website information is used

Website information may be used to:

  • respond to enquiries and provide information about the practice;

  • administer the availability email register and requested notifications;

  • assess and manage enquiry-call bookings when that function is enabled;

  • operate, secure, troubleshoot and improve the website;

  • understand website use and performance through appropriately configured analytics;

  • detect and respond to suspected misuse, security incidents or fraud;

  • maintain consent and communication-preference records; and

  • meet legal, privacy, security, records-management and complaint-handling obligations.

5. Availability notifications and communications

 

Availability notifications are sent only where a person has provided the required consent through the register. A subscriber may unsubscribe through the link in a message or by contacting the practice. Unsubscribing from availability notifications does not prevent administrative or service communications supported by another lawful basis.


Joining the availability email register does not create a waitlist position, priority, therapeutic relationship or guarantee of future availability.

6. Automated tools and AI Use

Automated tools may support limited website functions such as traffic analytics, technical performance monitoring, consent logging, spam prevention and routing of form communications. The website does not provide an AI chatbot or automated clinical service.


The practice does not currently use website information to make solely automated decisions that significantly affect a person’s rights or interests. A person reviews decisions about responding to enquiries, offering an enquiry call or engaging with the practice. The policy will be updated before materially different automated decision-making is introduced.

7. Website platforms and service providers

Principal website-facing providers include Wix for website hosting, forms, site search, inbox, consent tools, analytics and password-protected general resources; Calendly for enquiry-call booking when enabled; Google services for business email, communications and spam prevention where configured; and UserWay for the website accessibility widget. Minor or changeable security, accessibility, communications and technical services are described by category rather than exhaustively named.


Providers handle information under their own privacy terms and the practice’s applicable arrangements. The practice maintains a provider and data-governance register covering relevant information handling, locations, subprocessors, safeguards, retention, deletion, incident notification and exit arrangements. Higher-risk providers are reviewed at least annually and after material change.

8. Overseas handling

Some website providers or their subprocessors operate internationally and may store, process or permit authorised access to information outside Australia. Current provider verification confirms that Wix processes website-user information through Wix.com Ltd and uses data centres including the United States and Ireland. Calendly processes information in the United States and may use subprocessors in additional jurisdictions. Google and other technical providers also operate through multi-country infrastructure and support arrangements.


The countries involved can change as providers update infrastructure and subprocessors. Not every provider or subprocessor receives every category of website information. The practice therefore describes principal confirmed overseas pathways proportionately rather than implying that every listed country receives every visitor's information.


Where personal information is disclosed to an overseas recipient, the practice takes reasonable steps required by applicable privacy law and limits information shared to what is necessary for the enabled function. Provider and overseas-processing arrangements are reviewed after material changes and through the practice's provider-governance review process.

9. Cookies, analytics and tracking

Cookies and similar technologies may store or access information on a device to support essential website functions, security, accessibility, preferences and performance. Online identifiers and usage data may constitute personal information depending on the circumstances.


The practice assesses and minimises website tracking. Current technical review confirms that no Wix Marketing Tags are configured and no advertising pixels, behavioural-profiling tags or session-replay tools have been identified through the reviewed Wix mechanisms. The only current Wix Custom Code entry is an essential Bing Webmaster Tools site-verification meta tag and does not contain executable tracking or visitor-data processing code. Velo Dev Mode is off and no active custom Velo code is configured.


The cookie banner and settings panel allow visitors to review and manage non-essential categories where available. Withdrawal controls are provided through the consent interface. Essential technologies may not be capable of being disabled through the banner.


The UserWay accessibility widget is active on the Free Widget plan. Its Google Analytics integration is off and the additional advanced functions and add-ons reviewed are not enabled. Current provider information states that accessibility preferences are stored through local or session browser storage rather than persistent tracking cookies and are not used for tracking, profiling, analytics or marketing.


The practice will re-review this section before enabling materially different analytics, advertising, session-replay, custom-code or accessibility functionality.

10. Administrative access and service providers

Authorised administrative support may access information only to the extent required for appointments, forms, fees, payments, correspondence and other approved duties. Administrative personnel are required to maintain confidentiality, do not provide clinical advice or make clinical decisions, and may act only within approved procedures and recorded authority.

The practice uses principal providers including Zanda Health for practice management and health records; NovoPsych for assessments; NovoNote for optional digital scribing; Google Workspace for business email and communications; GoCardless and Stripe for payment processing; Xero for accounting; Wix and Calendly for the public website and associated enquiry functions. Minor or changeable technical services are described by category rather than exhaustively named in this policy.

The practice maintains a provider and data-governance register covering information handled, locations, subprocessors, safeguards, retention, deletion, incident notification, access, export, correction and account-closure arrangements. Higher-risk providers are reviewed at least annually and after material change. Current administrative and integration access is also reviewed using a least-privilege approach, with access restricted where practicable to the Google services and permissions required for the verified workflow.

11. Password-protected general resources

The Nature of Services and Consent and Existing Client Resources areas use shared page passwords rather than individual Wix member accounts. Existing clients may be given the applicable password to access general practice information or resources. Password protection limits ordinary public access but does not make these areas suitable for confidential, client-specific or sensitive health information.


Clients cannot use the area as a secure upload service and should not redistribute passwords or direct file links. The area is not a clinical record system or substitute for direct discussion in an appointment. Technical information associated with page or file access may be generated by Wix.

12. Disclosure and sharing

Website information may be disclosed:

  • to website, booking, email, accessibility, spam-prevention, analytics, security and technical providers where reasonably necessary for the relevant enabled function;

  • to practice systems and authorised personnel when an enquiry progresses or the information is handled under the Clinic Privacy Policy;

  • with consent or at the person’s request;

  • where required or authorised by law, court order, regulatory process or another lawful basis;

  • where the applicable legal requirements for lessening or preventing a serious threat are met; or

  • as part of a business transfer subject to appropriate confidentiality and privacy arrangements.

 

The practice does not sell personal information.

13. External links, social media and communication boundaries

The website may link to social media, booking, provider and other external services. Selecting an external link takes the visitor to a service governed by that provider’s privacy practices.

Practice social-media accounts are not used for client communication, appointment management or support. Personal or sensitive health information should not be sent through social-media messaging. Administrative enquiries should be sent to admin@authenticselfpsychology.com.au.

For further information, see our Communication & Social Media Policy, as well as our Website Disclaimer.

14. Security

The practice takes reasonable technical and organisational steps to protect website information from misuse, interference, loss, unauthorised access, modification and disclosure. Measures may include HTTPS, account-security controls, restricted access, trusted and supported devices and networks, secure service providers, software and configuration updates, email-domain controls, phishing safeguards and privacy-incident procedures.


No internet transmission or online system can be guaranteed to be completely secure. Detailed or sensitive health information should not be sent through ordinary website forms, email or social media.

 

15. Retention and deletion

Website information is retained only for as long as reasonably necessary for the relevant enquiry, communication, subscription, analytics, security, legal or practice purpose. Retention varies according to the type of information, configured provider settings, legal obligations, whether an enquiry progresses and whether information is needed to establish or respond to a complaint or legal claim.


Availability-register information is retained while a person remains subscribed and for a limited period afterwards where reasonably necessary to record the preference or meet legal obligations. Analytics and cookie information is retained according to verified configured settings and applicable provider terms.


A person may ask the practice to delete website information. Deletion is not an absolute right and may be refused or limited where information is lawfully required, has become part of an enquiry or health record, is needed for a legal, security or complaint purpose, or cannot reasonably be separated from required records. Information transferred into practice systems is retained under the Clinic Privacy Policy.

16. Access and correction

A person may request access to, or correction of, website personal information held about them. The practice may verify identity, authority and scope and clarify a broad or unclear request. A representative must provide evidence of identity and written authority or legal capacity to act.


The practice responds without unreasonable delay and aims to respond within 30 calendar days. If website information has become part of a health record, the Clinic Privacy Policy and applicable health-record access requirements apply, including the applicable maximum of 45 days for access and 30 days for a correction decision.


If access or correction is refused or limited, written reasons and available complaint options are provided where required.

17. Privacy questions and complaints

Privacy questions and complaints may be sent to the practice using the details below. The practice acknowledges complaints promptly and aims to provide a substantive response within 30 calendar days where reasonably practicable. If more time is required, an update will be provided before that deadline explaining the reason, any further information needed and the revised response date.


A person may also contact the Office of the Australian Information Commissioner at oaic.gov.au. The Victorian Health Complaints Commissioner at hcc.vic.gov.au may also be relevant where health information or a Victorian health service is involved.

18. Privacy incidents and data breaches

Actual or suspected privacy or data-security incidents are contained, investigated, assessed and documented. The practice takes reasonable steps to reduce harm and determines whether notification to affected people, the Office of the Australian Information Commissioner, the Victorian Health Complaints Commissioner or another authority is required or otherwise appropriate.

People under 18

The practice provides psychological services to adults aged 18 and over, and the website is not directed to children. If the practice becomes aware that information has been submitted by or about a person under 18, it assesses why it was provided and takes reasonable steps to handle, transfer, retain, delete or de-identify it as appropriate and lawful.
 

19. Policy updates

The final policy will take effect on its approval or publication date and will be routinely reviewed 24 months later, or earlier if website functions, providers, technologies, law or professional requirements materially change.

 

Conditional website functions described in this policy do not become active merely because they are mentioned. The practice will review privacy notices, forms, provider settings and this policy before enabling a materially different function. The current version and last-updated date will be published on the website, with notice of material changes where appropriate.

Privacy contact

Book a new enquiry call with Darcy

bottom of page