Francis Chambers, Level 3 Suite 15/40 Corinna St, Phillip

Canberra

MENU


Mindscape Therapy Privacy Policy

Last Updated: [Insert Date]

1. Introduction

Mindscape Therapy (“we,” “our,” or “us”) is committed to protecting your privacy and the confidentiality of your personal information. This Privacy Policy explains how we collect, use, disclose, and store your information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

If you have any questions about this policy or how we handle your information, please contact us using the details provided at the end of this document.

2. Who We Are and Contact Details

Entity Name: Mindscape Therapy Pty Ltd
ABN: 91 631 627 266
Address: Francis Chambers, Level 3 Suite 15/40 Corinna St, Phillip
Contact Email: admin@mindscapetherapy.com.au
Phone: (02) 5110 3700

3. What Personal Information We Collect

We may collect various types of personal information about you, including but not limited to:

4. How We Collect Your Information

We collect personal information through:

5. Purposes for Collecting and Using Your Information

We use your personal information for the following primary purposes:

PurposeDescription
Treatment & CareProviding DBT, EMDR, psychotherapy, and related mental health services
Administrative FunctionsBooking appointments, billing, record keeping
Clinical CommunicationCoordination with other healthcare providers (with consent)
Legal & ComplianceMeeting obligations under the Health Practitioner Regulation National Law, mandatory reporting requirements
Service ImprovementUnderstanding service usage patterns (anonymised where possible)
MarketingSending promotional communications (only with your explicit opt-in consent)

6. Disclosure of Your Personal Information

We will not sell or rent your personal information. We may disclose your information to:

Clinical & Administrative Providers

With Your Consent

Required by Law

International Disclosure Some of our service providers (e.g., Microsoft Cloud Services) may store data overseas, including in countries such as Singapore, Japan, or the United States. Where this occurs, we ensure appropriate safeguards are in place in accordance with Australian Privacy Principle 8.

7. How We Store Your Information

We take reasonable steps to protect your information from misuse, interference, loss, unauthorised access, modification, or disclosure.

Storage Systems Used:

PlatformPurposeSecurity Measures
HalaxyClient records, scheduling, billingHIPAA-equivalent encryption, two-factor authentication
Microsoft Cloud ServicesDocument storage, email communicationsAES 256-bit encryption, enterprise security protocols
Australian Hosting ProvidersWebsite data, contact form submissionsLocalised data centres, SSL encryption

Physical Records: Any physical documents (intake forms, session notes printed for clinical use) are stored in locked cabinets at our clinic premises and are destroyed securely when no longer required.

Retention Period: Personal and clinical records are retained for a minimum of 7 years from the date of last contact, or longer if required by law (particularly for minors, where records are kept until age 25).

8. Cookies and Website Tracking

Our website uses cookies to improve your experience. We use:

Cookie TypePurposeDuration
Essential CookiesSite functionality, securitySession
Analytics CookiesUnderstanding traffic patterns (Google Analytics)Up to 26 months
Preference CookiesRemembering your settingsUp to 1 year

You can configure your browser to decline cookies, though this may limit some website functionality.

9. Your Rights and Choices

Under the Australian Privacy Principles, you have the right to:

To exercise any of these rights, please contact us using the details in Section 2. We will respond within a reasonable timeframe (typically 30 days).

Exceptions: Some requests may be denied where allowed or required by law (e.g., where disclosure would pose a serious threat to life or health).

10. Data Breaches

In the unlikely event of an eligible data breach (where there is likely to be serious harm resulting from unauthorised access or disclosure), we will:

  1. Contain and assess the breach
  2. Notify affected individuals promptly
  3. Report to the Office of the Australian Information Commissioner (OAIC) where required
  4. Take steps to prevent recurrence

If you believe your information may have been compromised, please contact us immediately.

11. Complaints Process

If you have a concern about how we’ve handled your personal information:

  1. Submit in Writing: Email or post your complaint to the contact details below
  2. Acknowledgement: We will acknowledge receipt within 5 business days
  3. Investigation: We aim to investigate and respond within 30 days
  4. Escalation: If unresolved, you may lodge a complaint with the OAIC: www.oaic.gov.au

12. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. Any material changes will be notified to you via our website or direct communication where appropriate.