Kinex Health (“Kinex Health”, “we”, “us” or “our”) is committed to protecting the privacy of the people whose personal information we hold. This policy explains how we collect, use, disclose, store and secure your personal information, and how you can access it, correct it or make a complaint.
We are bound by the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). More information about the APPs is available from the Office of the Australian Information Commissioner at www.oaic.gov.au.
1. What is personal information and why we collect it
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. The personal information we collect may include names, addresses, email addresses, phone numbers, employer details, and health and wellbeing information.
We collect personal information so that we can deliver our services, communicate with you, respond to your enquiries, report to our client organisations (in aggregate or de-identified form), and carry out related administrative and marketing activities. Where we collect your information, we will, where practicable, explain why we are collecting it and how we intend to use it.
You may opt out of our marketing communications at any time using the unsubscribe link in our emails or by contacting us.
2. Sensitive and health information
Some of the information we collect is “sensitive information” under the Privacy Act, including health information gathered through wellbeing surveys, consultations and support sessions. We collect, use and disclose sensitive information only:
- for the primary purpose for which it was collected;
- for a directly related secondary purpose you would reasonably expect;
- with your consent; or
- where required or authorised by law.
Health and clinical records created through our psychology and wellbeing services are treated with a high level of confidentiality and are stored in Australia (see sections 5 and 6).
Where we collect wellbeing survey responses, they are recorded against a participant’s name and email so the correct survey reaches the correct person. Before any analysis is carried out, each response is assigned a unique identifier code and the name and email are separated from the dataset, so results can be matched to the same person over time without the analysis being performed against identifying details.
3. How we collect personal information
Where reasonable and practicable, we collect personal information directly from you, for example through surveys, bookings, consultations, correspondence, our website and email. In some cases, we may receive information from a third party, such as an employer arranging a wellbeing program on your behalf. Where this happens, we take reasonable steps to make you aware of the information we have received.
4. Service providers we use
We use a small number of established third-party platforms to deliver our services, including survey tools, clinical practice management and booking systems, and email and communication tools. These providers process personal information on our behalf under their own privacy and security obligations, and we take reasonable steps to ensure they handle your information appropriately.
If we change providers, hosting locations, or introduce a new platform in a way that affects your personal information, we will give affected client organisations at least 21 days’ advance written notice, or notify them as soon as reasonably practicable where a change is unexpected. Any such change is made on the basis that protections are maintained at an equivalent or higher standard.
5. Overseas storage and disclosure
Some of the platforms we use store data outside Australia:
- Wellbeing and program survey responses are collected through a survey platform that stores data on servers in the United States.
- Consultation notes, clinical records and mental health support records are stored in Australia.
- Appointment bookings are currently managed through a provider based in the United States, and we are moving this function to an Australian-hosted system.
- General program emails are managed through an email platform and contain contact details only, not survey, consultation or health information.
Where personal information is stored or disclosed overseas, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.
6. Security and storage of personal information
We store personal information in systems that protect it from misuse, interference, loss and unauthorised access, modification or disclosure. Our clinical and consultation records are held in encrypted, Australian-hosted practice management software, with access limited to authorised practitioners.
In addition to the protections provided by the platforms we use, we operate a number of controls directly. We enforce multi-factor authentication on the accounts and platforms where personal or sensitive information is stored or accessed. We apply a least-privilege approach to access, so that team members and practitioners can only access the information relevant to their role, and access is fully revoked when a person offboards. Access to raw identifiable survey data is restricted to a single authorised person. All clinical and non-clinical personnel are bound by signed confidentiality obligations, and our clinicians are additionally bound by the professional confidentiality requirements of their registration. We are also undertaking an independent security review as part of our current platform build.
When personal information is no longer required, we take reasonable steps to destroy or de-identify it. Health and clinical records are retained for a minimum of seven years, or longer where required by law or professional obligations.
7. Data breaches
We take reasonable steps to prevent data breaches. If a data breach occurs that is likely to result in serious harm, we will respond in line with the Notifiable Data Breaches scheme under the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner where required.
Where a breach, or suspected breach, affects a client organisation’s data, we will notify that organisation’s nominated contact within 48 hours of becoming aware of it. This applies whether the incident originates with Kinex or with one of the providers we use to deliver the service. We maintain a documented breach response process to guide how we contain, assess and communicate about an incident.
8. Disclosure of personal information
We may disclose your personal information:
- to the service providers described above, so they can help us deliver our services;
- to your employer or program sponsor, always in aggregate form and never for a group of fewer than nine people, to protect against re-identification;
- where you have consented to the disclosure; or
- where required or authorised by law.
- We do not sell your personal information.
9. Access and correction
You may request access to the personal information we hold about you, and ask us to update or correct it, subject to certain exceptions under the Privacy Act. Please contact us in writing. To protect your information, we may ask you to verify your identity before we release it.
10. Keeping your information accurate
We take reasonable steps to ensure the personal information we hold is accurate, complete and up to date. If your details change or you believe our records are inaccurate, please let us know so we can update them.
11. Complaints and enquiries
If you have a question or complaint about how we have handled your personal information, please contact us at [email protected]. We will respond within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au or on 1300 363 992.
12. Changes to this policy
We may update this policy from time to time. The current version will always be available on our website.
