Legal
Privacy Policy
How Pracsie collects, uses, stores and protects personal and health information, in line with the Privacy Act 1988 (Cth) and the Health Records and Information Privacy Act 2002 (NSW).
The short version
- We collect only what we need to talk to you, deliver our services and run our business.
- When we work inside your clinic’s systems, we may see patient and staff information. We treat it as confidential and use it only to do the work you’ve engaged us for.
- We don’t sell personal information, and we don’t use it for anyone else’s marketing.
- You can ask to see or correct your information, or make a complaint, at any time.
1. Who we are
This policy explains how Pracsie (Pracsie, we, us, our), handles personal information. Pracsie provides practice management consulting, clinic setup, accreditation support, training and mentoring to medical and allied health practices across Australia.
It applies to everyone we deal with: practice owners and staff, people who enquire or book a call, training participants, suppliers, job applicants, and visitors to pracsie.com.
2. The laws we follow
We handle personal information in line with:
- the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs) and the Notifiable Data Breaches scheme; and
- the Health Records and Information Privacy Act 2002 (NSW) and its Health Privacy Principles (HPPs), which apply to private sector organisations that collect or hold health information in New South Wales.
Where we work with practices in other states or territories, we also follow any local health records laws that apply to that work.
3. What we collect
Depending on how you deal with us, we may collect:
- Contact and business details: name, role, practice name, email, phone, business address, ABN and practice type.
- Service information: what you’ve asked us to help with, notes from calls and site visits, reports, and records of the work we do.
- Billing information: invoicing contacts and payment records. Card details are processed by our payment provider; we don’t store full card numbers.
- Training information: your background, goals, session attendance and progress, and completion records.
- Recruitment information: when we help a practice recruit or someone applies to work with us, we may collect CVs, qualifications, referee details and interview notes.
- Information in client systems: when a practice engages us, we may access its practice management software, rosters, HR files and billing records. These can include patient health information and staff employment information (see section 6).
- Website information: the details you enter into our enquiry form, and basic technical information like your IP address and browser type.
We only collect sensitive information, including health information, with consent or where the law otherwise allows it.
4. How we collect it
Usually we collect it directly from you: through our website form, by email or phone, in meetings and site visits, and while delivering services. Sometimes it comes from someone else, like a practice owner who gives us staff details, a referee, or a practice’s own systems when we’re engaged to work in them. If we collect information about you from someone else, we’ll take reasonable steps to let you know, unless it’s obvious from the situation or the law says we don’t need to.
5. Why we use it
We collect, use and disclose personal information to:
- respond to enquiries and book calls;
- deliver our consulting, one-off consultation, accreditation, clinic setup, training and mentoring services;
- manage our client relationships, invoicing and payments;
- manage recruitment for clients or for ourselves;
- improve our services and keep our templates and resources up to date, using de-identified information wherever possible;
- send service updates and, if you agree, marketing (see section 9); and
- meet our legal, insurance, tax and regulatory obligations.
If you don’t give us the information we ask for, we may not be able to provide some or all of our services.
6. Health information in client systems
Practice management often means working inside a clinic’s systems, which may hold patient health information. When this happens:
- the practice remains responsible for its patient records and for its own privacy obligations to patients;
- we access patient information only when it’s necessary for the work the practice has engaged us to do (for example billing reconciliation, Medicare compliance checks or accreditation audits);
- we don’t copy, extract or keep patient information outside the practice’s systems unless the task requires it and the practice agrees;
- we never use patient information for our own purposes, including marketing; and
- everyone at Pracsie who may access client systems is bound by confidentiality obligations.
We handle this information in line with both the APPs and the NSW HPPs. Patients who have questions about their records should contact their practice first.
7. Who we share it with
We may share personal information with:
- the practice that engaged us, where the information relates to that engagement;
- accreditation bodies, AHPRA, Services Australia (Medicare), the NDIS Commission and similar bodies, when we lodge or manage applications for a practice with its authority;
- service providers who help us run our business, such as website and form hosting, email, cloud storage, video-call, accounting and payment providers. We only give them what they need, and they must protect it;
- our professional advisers and insurers; and
- anyone else if you consent, or where the law requires or allows it.
We don’t sell, rent or trade personal information.
8. Overseas disclosure
Some of our service providers store data on servers outside Australia, including in the United States. For example, our website and enquiry form host, email and video-call tools may do this. When we use overseas providers, we take reasonable steps to make sure they handle personal information consistently with the APPs.
We do not deliberately store patient health information outside Australia.
9. Marketing
We’ll only send you marketing emails or messages if you’ve agreed to receive them, or if the Spam Act 2003 (Cth) otherwise allows it. Every marketing message includes an easy way to unsubscribe, and you can also opt out any time by emailing us. We never use patient information for marketing.
10. Our website, cookies & analytics
Our website doesn’t set its own tracking cookies. It loads fonts from Google Fonts, which means your browser sends your IP address to Google when the page loads. Our website host keeps standard server logs for security and performance.
If we add analytics or advertising tools in the future, we’ll update this policy and, where required, ask for your consent.
11. Storage & security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, change or disclosure. These include:
- secure, access-controlled cloud systems with multi-factor authentication;
- encryption in transit (HTTPS) for our website and forms;
- giving staff and contractors access only to what their role needs;
- confidentiality obligations for everyone who works with us; and
- following each client practice’s own security and access policies when we work in its systems.
No system is completely secure, but we work hard to keep your information safe.
12. Data breaches
If we have a data breach that is likely to cause serious harm, we’ll notify affected people and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. If the breach involves a client’s systems or patient information, we’ll tell the practice straight away so it can meet its own obligations.
13. How long we keep it
We keep personal information only as long as we need it for the purposes in this policy, or as long as the law requires. For example, tax and business records are generally kept for 7 years. Patient records we access in a client’s systems stay with that practice, which is responsible for keeping them for as long as the law requires. When we no longer need information, we securely delete or de-identify it.
14. Access & correction
You can ask for access to the personal information we hold about you, or ask us to correct it, by contacting us (see section 18). We’ll respond within 30 days. We may need to confirm your identity first. If we refuse a request, we’ll explain why in writing and tell you how to complain. We don’t charge for making a request. If giving access involves significant work, we may charge a reasonable fee, which we’ll tell you about first.
15. Anonymity
You can make general enquiries without identifying yourself or by using a pseudonym. To book services, send invoices or deliver training, we’ll need your real details.
16. Complaints
If you think we’ve mishandled your personal information, please tell us first (see section 18). We’ll acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you’re not happy with our response, you can complain to:
- Office of the Australian Information Commissioner (OAIC): oaic.gov.au · 1300 363 992
- Information and Privacy Commission NSW, for complaints about health information under the HRIP Act: ipc.nsw.gov.au · 1800 472 679
17. Changes to this policy
We may update this policy from time to time. The latest version will always be on this page, with the date it was last updated.
18. Contact us
Privacy Officer, Pracsie
Email: sales@pracsie.com
Phone: 02 8552 8609