Consultation
How True Active Physiotherapy collects, uses, discloses and protects your personal and health information.
Last updated: 19 June 2026
True Active Physiotherapy Pty Ltd (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal and health information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and Victoria’s Health Records Act 2001. This policy explains how we collect, hold, use and disclose your information, and how you can access it or make a complaint.
As a physiotherapy practice, much of the information we collect is health information, which is treated as sensitive information under the Privacy Act and attracts a higher level of protection. The information we collect may include:
Where the patient is a minor, we collect information from the patient and from a parent or legal guardian. By providing us with a minor’s information, the parent or guardian confirms they have authority to consent to that minor’s assessment and treatment and to the handling of their personal and health information as described in this policy. Mature minors may consent to their own treatment where clinically and legally appropriate.
Wherever practicable, we collect information directly from you — for example, during a consultation, via our intake forms, through our online booking system, or when you contact us by phone, email or social media. We may also collect information from third parties where it is reasonably necessary for your care or where you have authorised us to do so, including:
We collect, hold, use and disclose your information for purposes directly related to providing physiotherapy services and operating our practice, including to:
We will not use your health information for direct marketing without your consent. You may opt out of marketing communications at any time using the unsubscribe link in any email or by contacting us.
We will not sell your personal information. We may disclose your information to third parties only where it is necessary for the purposes described in this policy or otherwise required or permitted by law. This may include:
Payments and private health fund claims are processed through our payments and invoicing platform (currently HaltH). Your card details are entered directly into HaltH’s secure system and are not stored or seen by our clinic. HaltH maintains its own independent security certifications for handling payment data, including ISO 27001 and PCI-DSS Level 1. If you would prefer not to enter your details online, you are welcome to call the clinic.
We use an AI-assisted documentation tool (currently Preve) to help prepare clinical notes, treatment plans and letters. With your consent, your consultation may be recorded and transcribed to generate a draft note, which your physiotherapist reviews and edits before it is saved to your record. You may opt out of recording at any time — simply let your physiotherapist know — and signage at reception explains this. Recordings and transcripts are stored by Preve on secure infrastructure and are handled in accordance with Preve’s privacy and security commitments and this policy. If you would like more information about Preve, please ask your physiotherapist or contact us.
Where appropriate, we may offer consultations by video or phone. We use reasonable measures to keep these consultations secure and private, and we will not record a telehealth consultation without your consent. Telehealth may not be suitable for every condition, and your physiotherapist will advise if an in-person assessment is needed.
We store clinical records primarily in our practice management system (Cliniko), which holds data on secure cloud infrastructure. Audio recordings and transcripts generated by our AI documentation tool (Preve) are stored on the provider’s secure infrastructure. Business and administrative records may be stored in other secure cloud services. We take reasonable steps to protect your information from misuse, interference, loss, and unauthorised access, modification or disclosure, including through access controls, encryption in transit, staff training and confidentiality obligations.
We retain health records for the periods required by law and professional standards — generally a minimum of seven years from your last appointment for adults, and for minors until they reach 25 years of age. When information is no longer required and we are not legally obliged to keep it, we take reasonable steps to securely destroy or de-identify it.
Our website uses cookies and analytics tools to understand how visitors use our site and to improve and promote our services. These may include Google Analytics (GA4), Google Ads, Google Business Profile, the Meta (Facebook) Pixel, and our website host (Wix). They may collect information such as your IP address, device and browser type, and the pages you visit. You can control cookies through your browser settings; disabling them may affect how the website functions.
You may request access to the personal and health information we hold about you, and ask us to correct it if it is inaccurate, out of date or incomplete. Please contact our Privacy Officer using the details below. We may need to verify your identity before providing access. In the limited circumstances permitted by law where we cannot grant a request, we will explain why in writing.
If you have a concern about how we have handled your information, please contact our Privacy Officer first so we can try to resolve it. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, or the Victorian Health Complaints Commissioner at hcc.vic.gov.au.
If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the OAIC as required under the Notifiable Data Breaches scheme.
We may update this policy from time to time to reflect changes in our practices or legal obligations. The current version will always be available on our website, with the effective date shown above.