Skip to content Welcome offer 10% off your initial consultation Book now
000 — Legal

Privacy policy.

This policy explains how Zendra Health Pty Ltd collects, uses, stores and protects your Personal Information, in accordance with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth). As a telehealth service, we treat the health information you share with us as sensitive information, with the care that warrants.

Last updated: 15 June 2026

001

Our commitment

Zendra Health Pty Ltd (ABN 60 696 084 983) provides telehealth services to people across Australia. This policy explains how we collect, use, store, disclose and protect your personal information and your health information. It applies to everyone who uses our website, our services and our care.

We follow the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We also follow applicable state and territory health privacy legislation. This includes the Health Records Act 2001 (Vic) and the Health Privacy Principles where they apply. These laws set extra rules for handling health information.

You can get a copy of the Australian Privacy Principles from the Office of the Australian Information Commissioner at www.oaic.gov.au .

Our registered and contact address is Level 2, 525 Collins Street, Melbourne VIC 3000.

002

What is personal information and why do we collect it?

Personal information is information or an opinion that identifies you, or could reasonably identify you. Examples include your name, date of birth, postal and email address, and phone number.

We collect personal information so we can provide our services to you, run our business, meet our legal duties, and (with your consent) send you updates. We may also use it for a related purpose that you would reasonably expect.

We collect personal information in several ways. This includes when you contact us by phone or email, when you use our website, when you complete a form or health questionnaire, and when you receive care from one of our practitioners. Where it is reasonable and practical, we collect this information directly from you.

When we collect personal information, we will explain why we are collecting it and how we plan to use it, where it is reasonable and practical to do so.

003

Health information we collect

Health information is a type of sensitive information under the Privacy Act 1988 (Cth). We handle health information in accordance with the Australian Privacy Principles and any applicable state or territory health privacy laws and principles.

Because we provide health services, much of the personal information we collect in connection with your care is considered health information. We treat this information with additional care and take reasonable steps to protect it.

The health information we collect may include:

  • Your medical history, symptoms, health conditions, diagnoses and clinical assessments
  • Information provided through health questionnaires and eligibility assessments
  • Clinical notes and records made by your healthcare practitioner
  • Pathology requests, test results and other clinical reports
  • Medicines you currently take, medicines prescribed to you, and information about allergies, side effects or adverse reactions
  • Referrals, correspondence and reports received from other healthcare providers
  • Care plans, clinical recommendations and follow-up arrangements
  • Details of your consultations, including their date, time, duration and method
  • Information about your health goals, lifestyle, nutrition, movement, sleep and other relevant daily habits
  • Medicare, private health insurance, billing and payment information where needed to provide services, process a claim or manage payment
004

How we use sensitive information

Sensitive information includes health information. It also includes information about things such as your racial or ethnic origin, religious beliefs and criminal record. We collect sensitive information only when it is needed for our services or where the law allows it.

Where required, we obtain express and informed consent before collecting, using, or disclosing health information. Consent may be provided through digital acknowledgement, written consent, or documented verbal consent during a consultation.

We use sensitive information only:

  • For the main purpose it was collected, which is providing your care
  • For a related purpose you would reasonably expect
  • With your consent, or where required or authorised by law
005

Dealing with us anonymously

Under the Australian Privacy Principles, you can usually deal with an organisation without identifying yourself. This is not practical for the health services we provide.

Due to the nature of the health services we provide, it is generally impracticable for us to deal with individuals who have not identified themselves. We need accurate identification for three reasons. It keeps your clinical care safe and continuous. It lets us meet our legal and professional obligations under applicable health legislation. It also lets us meet Medicare and private health insurance billing requirements.

006

Unsolicited information

From time to time, we may receive personal or health information that we did not solicit. Where we receive unsolicited personal information, we will promptly assess whether that information is of a kind we could have collected under our standard collection practices.

If we could not have collected that information under this policy, and we are not required by law to keep it, we will destroy or de-identify it as soon as it is lawful and reasonable to do so.

007

Privacy during telehealth consultations

We deliver care by telehealth. To keep your care safe, your practitioner will verify your identity before each consultation. You may be asked to confirm details such as your full name and date of birth.

At the start of a consult, your practitioner will let you know who else is present, such as a supervising practitioner, a student or an interpreter. You can ask who is present at any time. We ask that you take the consult somewhere private so others cannot overhear your health information.

Telehealth is not right for every situation. If your practitioner decides telehealth is not suitable or safe for your needs, they will tell you and help you arrange in-person care or another appropriate option.

008

AI and automated tools

We may use software and automated tools to support our service. For example, an online questionnaire may flag responses for a practitioner to review, or a tool may help draft notes or organise information.

Where AI-assisted transcription or administrative tools are used, they support administrative or documentation processes only. They do not replace practitioner judgement. No diagnosis, prescribing, or treatment decision is made solely by an automated system.

An AHPRA-registered Australian healthcare practitioner reviews your information and makes the clinical decision. Any prescription is issued by an appropriately authorised AHPRA-registered prescriber.

We take reasonable steps to ensure AI providers maintain appropriate privacy and security safeguards. We do not allow identifiable patient information to be used to train general-purpose AI models unless you have expressly consented.

009

Who makes clinical decisions

Clinical decisions, including whether treatment is appropriate, are made independently by the treating practitioner based on clinical assessment.

Administrative systems, website questionnaires, commercial considerations, and marketing activities do not determine clinical outcomes.

010

How we disclose your information

We may disclose your personal and health information so we can provide and support your care. We only disclose it for a purpose set out in this policy or where the law allows.

We may disclose your information to:

  • Practitioners and care staff involved in your care
  • Pharmacies that dispense a medicine prescribed for you
  • Pathology, imaging or other health providers involved in your care, with your consent
  • Service providers who help us run our business, such as secure IT, payment and communication providers, under contracts that protect your information
  • Medicare, your private health fund, or another payer, to process a claim or payment
  • Any person or body where you have consented, or where we are required or authorised by law
011

Direct marketing

We will only send you direct marketing, such as updates and offers, where you have given us your express consent. We do not use your health information to target marketing to you.

Every marketing message includes a simple way to opt out. You can also opt out at any time by contacting us at [email protected]. Once you opt out, we will stop sending you marketing messages.

Marketing communications will not advertise prescription-only medicines, unapproved therapeutic goods, compounded medicines, or specific therapeutic goods to the public.

012

Government and healthcare identifiers

You may give us government and healthcare identifiers, such as your Medicare number or your Individual Healthcare Identifier (IHI). We collect these only where we need them, for example to provide care or process a Medicare claim.

We do not use a government or healthcare identifier as our own reference number for you. We only use or disclose these identifiers in the limited ways the law allows.

013

My Health Record

My Health Record is a national system run by the Australian Government. It is separate from our own records.

Zendra Health Pty Ltd does not currently access or upload information to the My Health Record system. If this changes, we will update this Privacy Policy and provide information about how My Health Record will be used.

014

Overseas disclosure of information

Your patient and clinical records are stored in Australia through our practice management provider, Halaxy.

Some service providers we use, including technology, cloud hosting, communication, payment, and website providers, may store or process limited personal information overseas. These providers may be located in countries including the United States, European Union countries, or other jurisdictions where their services operate.

We take reasonable steps to ensure these providers handle information consistently with Australian privacy requirements, including through contractual and security safeguards. Any overseas disclosure is made in line with APP 8.

015

Cookies and website tracking

Our website uses cookies and similar tools to help it work, to remember your choices, and to understand how the site is used. Some cookies are essential. Others are used for analytics and, with your consent, for marketing.

Information about the health pages you view can reveal sensitive interests. We treat website information with care and we ask for your consent before using non-essential cookies. You can manage or refuse cookies in your browser settings, and through our cookie consent banner. Refusing some cookies may affect how the site works.

016

Security of your information

We store your information in a way that protects it from misuse, loss, and unauthorised access, change or disclosure. We use measures such as access controls, encryption and staff training.

No system is completely secure. We work to reduce the risk and to respond quickly if a problem occurs.

017

How long we keep your records

We retain clinical records in accordance with applicable Commonwealth, state and territory privacy and health records laws, professional standards and our record-retention policies.

As a general minimum, we retain an adult patient's clinical records for at least seven years after the last occasion on which we provided a health service. Where health information was collected while a patient was under 18, we retain the records until the patient turns 25 or for seven years after the last health service was provided, whichever is later.

We may retain records for a longer period where required or permitted by law, professional obligations, insurance requirements or the ongoing clinical needs of the patient.

When personal or health information is no longer required and we are not legally required or authorised to retain it, we take reasonable steps to securely destroy or de-identify it.

018

Notifiable data breaches

We follow the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). A data breach happens when personal information is lost, or accessed or disclosed without authorisation.

Where we suspect a data breach may have occurred, we will conduct a reasonable and expeditious assessment. We aim to complete this assessment within 30 days.

If we determine that an eligible data breach has occurred and is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable. Our notice will explain the breach and the steps you can take to protect yourself.

019

Access to and correction of your information

You can ask to see the personal and health information we hold about you, and to have it corrected, subject to some exceptions in the law. To make a request, please contact us in writing.

Zendra Health Pty Ltd will not charge a fee to make a request. We may charge a reasonable fee for the cost of giving you a copy. We may ask you to confirm your identity before we release any information.

020

Keeping your information accurate

It helps your care if your information is correct and current. We take reasonable steps to keep your information accurate, complete and up to date. If anything we hold is wrong or out of date, please tell us as soon as you can so we can fix it.

021

Changes to this policy

We may update this policy from time to time. The current version is always available on our website. The date at the top shows when it was last updated.

022

Complaints and how to contact us

If you have a question or a complaint about how we handle your information, please contact us. We will respond as soon as we can. You can reach us at:

If you are not satisfied with our response, you can also contact:

  • The Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or 1300 363 992
  • The health complaints commissioner or ombudsman in your state or territory. In Victoria, this is the Health Complaints Commissioner at hcc.vic.gov.au or 1300 582 113
Questions about your information

We are glad to talk it through.

If you have a query or complaint about how we handle your Personal Information, reach out and a member of our team will help.