Mindscape Therapy Privacy Policy
Last Updated: [Insert Date]
1. Introduction
Mindscape Therapy (“we,” “our,” or “us”) is committed to protecting your privacy and the confidentiality of your personal information. This Privacy Policy explains how we collect, use, disclose, and store your information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
If you have any questions about this policy or how we handle your information, please contact us using the details provided at the end of this document.
2. Who We Are and Contact Details
Entity Name: Mindscape Therapy Pty Ltd
ABN: 91 631 627 266
Address: Francis Chambers, Level 3 Suite 15/40 Corinna St, Phillip
Contact Email: admin@mindscapetherapy.com.au
Phone: (02) 5110 3700
3. What Personal Information We Collect
We may collect various types of personal information about you, including but not limited to:
- Identifiers: Name, date of birth, address, contact details
- Health Information: Medical history, treatment notes, diagnosis, psychological assessments
- Financial Information: Billing details, Medicare number (if claiming rebates), private health insurance details
- Technical Data: IP address, browser type, device information, cookies (when browsing our website)
- Communication Records: Emails, phone call notes, correspondence
4. How We Collect Your Information
We collect personal information through:
- Direct Interaction: During consultations, appointments, and intake sessions
- Website Forms: Contact forms, booking requests, newsletter subscriptions via Elementor popups
- Third Parties: Referrers (GPs, psychiatrists), insurance providers, family members (with your consent)
- Automated Means: Website analytics, cookies, and similar tracking technologies
5. Purposes for Collecting and Using Your Information
We use your personal information for the following primary purposes:
| Purpose | Description |
|---|---|
| Treatment & Care | Providing DBT, EMDR, psychotherapy, and related mental health services |
| Administrative Functions | Booking appointments, billing, record keeping |
| Clinical Communication | Coordination with other healthcare providers (with consent) |
| Legal & Compliance | Meeting obligations under the Health Practitioner Regulation National Law, mandatory reporting requirements |
| Service Improvement | Understanding service usage patterns (anonymised where possible) |
| Marketing | Sending promotional communications (only with your explicit opt-in consent) |
6. Disclosure of Your Personal Information
We will not sell or rent your personal information. We may disclose your information to:
Clinical & Administrative Providers
- Halaxy practice management software
- Microsoft Cloud Services (for secure document storage)
- Australian-hosted infrastructure providers
- Supervisors or consultants involved in your care (with appropriate confidentiality agreements)
With Your Consent
- Referring healthcare professionals (GPs, psychiatrists, specialists)
- Private health insurance providers for claims
- Family members or support persons (as directed by you)
Required by Law
- Mandatory reporting authorities (as required under Victorian/NSW child protection laws)
- Courts or tribunals (by subpoena or court order)
- Australian Taxation Office for taxation purposes
- Police or emergency services (in situations involving serious risk to life or safety)
International Disclosure Some of our service providers (e.g., Microsoft Cloud Services) may store data overseas, including in countries such as Singapore, Japan, or the United States. Where this occurs, we ensure appropriate safeguards are in place in accordance with Australian Privacy Principle 8.
7. How We Store Your Information
We take reasonable steps to protect your information from misuse, interference, loss, unauthorised access, modification, or disclosure.
Storage Systems Used:
| Platform | Purpose | Security Measures |
|---|---|---|
| Halaxy | Client records, scheduling, billing | HIPAA-equivalent encryption, two-factor authentication |
| Microsoft Cloud Services | Document storage, email communications | AES 256-bit encryption, enterprise security protocols |
| Australian Hosting Providers | Website data, contact form submissions | Localised data centres, SSL encryption |
Physical Records: Any physical documents (intake forms, session notes printed for clinical use) are stored in locked cabinets at our clinic premises and are destroyed securely when no longer required.
Retention Period: Personal and clinical records are retained for a minimum of 7 years from the date of last contact, or longer if required by law (particularly for minors, where records are kept until age 25).
8. Cookies and Website Tracking
Our website uses cookies to improve your experience. We use:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential Cookies | Site functionality, security | Session |
| Analytics Cookies | Understanding traffic patterns (Google Analytics) | Up to 26 months |
| Preference Cookies | Remembering your settings | Up to 1 year |
You can configure your browser to decline cookies, though this may limit some website functionality.
9. Your Rights and Choices
Under the Australian Privacy Principles, you have the right to:
- Access: Request access to your personal information held by us
- Correction: Request correction of inaccurate, out-of-date, incomplete, irrelevant, or misleading information
- Complaint: Lodge a complaint about a breach of your privacy rights
- Withdraw Consent: Withdraw consent for certain types of information processing (note: this may affect our ability to provide services)
- Opt-Out: Unsubscribe from marketing communications at any time
To exercise any of these rights, please contact us using the details in Section 2. We will respond within a reasonable timeframe (typically 30 days).
Exceptions: Some requests may be denied where allowed or required by law (e.g., where disclosure would pose a serious threat to life or health).
10. Data Breaches
In the unlikely event of an eligible data breach (where there is likely to be serious harm resulting from unauthorised access or disclosure), we will:
- Contain and assess the breach
- Notify affected individuals promptly
- Report to the Office of the Australian Information Commissioner (OAIC) where required
- Take steps to prevent recurrence
If you believe your information may have been compromised, please contact us immediately.
11. Complaints Process
If you have a concern about how we’ve handled your personal information:
- Submit in Writing: Email or post your complaint to the contact details below
- Acknowledgement: We will acknowledge receipt within 5 business days
- Investigation: We aim to investigate and respond within 30 days
- Escalation: If unresolved, you may lodge a complaint with the OAIC: www.oaic.gov.au
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. Any material changes will be notified to you via our website or direct communication where appropriate.