Privacy Policy
Introduction
This is the Privacy Policy of Georgie Duncan (ABN 85 592 602 034). If you have any questions or need further information, please email georgie@georgieduncan.com.au.
I am committed to protecting your privacy and all personal and medical information you share with me.
This document describes how I collect and manage your personal and sensitive information when you interact with my business. I take this responsibility very seriously. If you have any questions or concerns about how your personal or sensitive information is being handled, please do not hesitate to contact me.
I comply with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth) (Privacy Act).
I choose to voluntarily comply with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth) (Privacy Act).
I understand that visitors from the EU may access this site, so I also aim to comply with the General Data Protection Regulations (GDPR).
Personal Information
If you engage with me via this website, or choose to become my client, I may ask to collect the following kinds of personal information from you, including:
-
CONTACT DETAILS
Your name, email address and phone number and the country that you live in
-
INTERACTION
Information that allows me to tailor my content and advice to your needs when you sign up for one of my webinars or promotional events
-
INTERNET
Your IP address, and information about your browsing history to help [me/us] improve the usability and appeal of my website (more information about this is found in the section on Cookies below)
-
EMPLOYEE/CONTRACTORS
If you are an employee or contractor, or propose working with me in that capacity, information about your qualifications, skills and work experience
-
SUPPLIERS
If you are a supplier or prospective supplier, information about your business skills, services, products and prices
Collection & Use of Personal Information
Where practicable I/we will only collect personal information about you directly from you or sources managed by you. However, in some circumstances I/we may obtain personal information from a third party. If this information is obtained contrary to this Privacy Policy and the Privacy Act, I/we will destroy or de-identify such information within a reasonable period.
I/We may collect your personal information by various means including when:
-
you contact [me/us] with a question, comment or inquiry
-
you subscribe to [my/our] newsletter
-
you attend a webinar, seminar or event where [I am/we are] hosting or presenting
-
you correspond with [me/us] on a social media platform such as Facebook, LinkedIn, Instagram or similar sites
-
you opt in to receive a free resource from [me/us] or sign up for [my/our] newsletter
-
you book a consultation or purchase a product or service from [me/us]
-
you share general information relating to your business or personal life
-
you provide [me/us] with a testimonial
-
[I/we] visit your website or social media profiles in preparation for working with you
-
[my/our] website automatically collects information about you and your activities on [my/our] site (including analytics and cookies – more information on this is set out below)
-
a third-party supplies information to [me/us], such as when you are referred or introduced to me by a mutual acquaintance
I/We may collect and use your personal information to:
-
respond to your enquiries
-
provide you with [my/our] products or services at your request
-
monitor or improve the use of and satisfaction with [my/our] website, products or services
-
share the latest news and developments relevant to [my/our] work
-
let you know about [my/our] expertise, and products or services that may be of interest to you
[I/We] may, from time to time, send you newsletters, invitations and updates about [my/our] services. [I/We] will only do so if you have requested to receive such communications through a double opt-in process. You can opt out of receiving any further such communications by replying to the message you received, or by clicking the “unsubscribe” option at the bottom of any marketing e-mail received from [me/us].
[I/We] will only collect your information:
-
with your full awareness and consent, such as when you email [me/us], tick a checkbox or fill in a form to provide [me/us] with information
-
if [I/we] need it to provide you with information or services that you request
-
if [I am/we are] legally required to collect it
-
if collecting the information is necessary to preserve life or keep someone safe from harm
-
for necessary administrative processes if you become [my/our] client
-
if [I/we] believe that [I/we] can demonstrate a legitimate interest in using your data for marketing purposes, although [I/we] will always give you a choice to opt out
If you do not provide [me/us] with information when requested to do so, [I/we] may not be able to carry out your instructions or achieve the purpose for which the information has been sought.
Sensitive Information
I understand that some information is particularly sensitive, and that you are trusting [me/us] to keep this information confidential.
The sensitive information [I/we] collect from you may include:
[I/We] will only collect sensitive information by methods that are reasonably secure, such as:
-
through [my/our] intake form in Acuity when you book an appointment
-
in a zoom consultation or face to face
-
when you send [me/us] information in an email.
-
When you willingly give me log in information to view or access your data such as Fertility Friend or I-medical.
The reason why [I/we] collect your sensitive information is:
-
So that [I/we] can provide you with the services you have requested from [me/us]
-
to ensure that [I am/we are] providing you with the most appropriate services
Secure Storage of Sensitive Information
I am committed to securely storing and handling your sensitive information.
-
Sensitive information is stored on a password protected computer and in password protected devices with a high level of cybersecurity.
-
Only [I / the therapist responsible for your treatment / authorised team members] have access to your sensitive information[, and only on a need to know basis].
-
[I/We] do not store sensitive information online or in the cloud.
Collection of Information from Minors
Sensitive information may be collected from children under the age of 18 under the following circumstances:
-
in the presence of their parents
-
with their parent or guardian’s full consent
This information is collected for the sole purpose of providing [services/products] and is handled with heightened security. Parents/guardians can request access to, correction of, or deletion of their child’s data at any time.
Destruction of Sensitive Information
[I/We] retain personal information only for as long as necessary to fulfill [my/our] obligations to you, or as required by law. Personal information is archived for 7 years and then securely deleted or de-identified.
Archived data is reviewed annually, and any information no longer required is securely destroyed. Physical records are shredded, and digital records are permanently deleted from [my / our] systems, including backups.
Disclosure of Information
[I/we] may disclose your information if required under the following circumstances:
-
to provide you with the services you have requested
-
to send you products that you have purchased
-
where disclosure is necessary to carry out your instructions, such as [corresponding with someone else on your behalf / requesting pathology tests / ordering supplements / etc]
-
where [I/we] use support services to assist [me/us] in [my/our] business
-
to engage in professional supervision, although any information [I/we] share under these circumstances is de-identified to preserve client confidentiality
-
to refer you to other service providers at your request
​
You consent to [me/us] sharing relevant information [on a strictly need-to-know basis] with:
-
people you authorise [me/us] to correspond with, as reasonably required to carry out your instructions
-
[my/our] employees / subcontractors
-
Third party providers who assist with
-
accounting
-
administration
-
archiving
-
auditing
-
business consulting
-
email marketing
-
legal or financial advice
-
professional supervision
-
website maintenance
-
technological services
-
[I/We] will also disclose your information if required by law in response to a subpoena, discovery request or a court order, in compliance with mandatory reporting obligations, or in circumstances permitted by the Privacy Act – for example, where [I/we] have reasonable grounds to suspect that someone is engaging in unlawful activity, or misconduct of a serious nature, that relates to [my/our] work with you. [I/We] may also make a disclosure to an appropriate authority if [I/we] have serious concerns about your health, safety or wellbeing.
​
[I/We] will use all reasonable means to protect the confidentiality of your information while in [my/our] possession or control. [I/We] will not knowingly share any of your information with any third party other than the service providers who assist [me/us] with necessary business activities or the services [I am/we are] providing to you. To the extent that [I/we] do share your information with third-party service providers, [I/we] only do so if [I am/we are] satisfied that the service provider has a suitably protective privacy policy of their own, or they have signed a confidentiality agreement with [me/us]. Some of [my/our] service providers may be overseas and may not be subject to Australian Privacy Laws. You can find further information under the Security section below.
If you have any concerns regarding the disclosure of your information, please do not hesitate to get in touch with [me/us] to discuss this personally.
Security
[I/We] take reasonable physical, technical and administrative safeguards to protect your personal and sensitive information from misuse, interference, loss, and unauthorised access, modification and disclosure.
​
[I/We] manage risks to your information by:
-
storing files securely
-
ensuring that only [I / key personnel] have access to sensitive information
-
releasing information to service providers on a strictly need-to-know basis
-
conducting regular audits of [my/our] security systems
As mentioned above, your information may also be stored with a third-party provider, where it will be managed under their security policy. The following security policies may apply during our work together:
​
-
Acuity - https://help.acuityscheduling.com/hc/en-us/articles/219149587-Security-Privacy-Compliance
-
Dropbox - https://www.dropbox.com/security
-
Facebook ads - https://www.facebook.com/business/m/privacy-and-data
-
Google Workspace - https://workspace.google.com/intl/en_au/security/
-
Paypal - https://www.paypal.com/re/webapps/mpp/paypal-safety-and-security
-
Squarespace - https://www.squarespace.com/privacy
-
Stripe - https://stripe.com/docs/security
If you are communicating with me via electronic means such as email, Zoom, contact forms or Facebook/Instagram/Meta, I may not have full control over the transmission or storage of any personal information disclosed (although I try to employ best practice cybersecurity standards at all times). You agree that by participating in such forms of communication you understand and accept that there is an inherent risk of disclosure or loss of your personal information for which I cannot be held responsible. If you are concerned about transferring particularly sensitive information, please ask me about alternative options that may be more secure.
From time to time [I/we] may combine information provided by you with information gathered from:
-
your website
-
Facebook
-
Instagram
-
LinkedIn
[I/We] may use AI-powered tools to enhance [my/our] efficiency, streamline operations, and improve the services [I/we] provide. These tools may assist with tasks such as notetaking, content drafting, scheduling, and customer interactions. [I am/We are] committed to ensuring that all AI-related data processing aligns with the Australian Privacy Principles and that your information is handled securely and transparently. [I/We] take steps to minimise the data shared with AI tools, including:
-
anonymising personal details (e.g., using initials instead of names)
-
limiting AI processing to non-sensitive information unless [I/we] have your explicit consent
The AI tools we use are selected based on their privacy and security policies. Below is an overview of the AI tools we use and their purpose:
-
[Heidi Health / Otter AI / Fireflies/ai]: notetaking assistant and transcription app for session documentation to improve accuracy and record-keeping
-
[ChatGPT / Copilot / Claude]: drafting, summarising, brainstorming, and improving communications
Cookies and Google Analytics
Cookies are small text files that are commonly used by websites to improve a user’s experience, collect statistics or marketing information and provide access to secure areas. [My/Our] website uses [cookies and tracking technologies] to [enhance user experience / analyze site performance / provide personalized content].
​
You can choose to configure your browser settings not to accept cookies but this may interfere with the functioning of this website.
​
I/We use Google Analytics to collect information about your use of [my/our] website so that [I/we] can get strategic information about how [my/our] website is being used and improve its functionality. You can find out more about the information Google collects and how it is used here:
https://support.google.com/analytics/answer/6004245.
​
Google also provides an add-on for your browser that you can use to opt-out and prevent your data being used by Google Analytics. You can access that add-on here:
https://tools.google.com/dlpage/gaoptout.
I/We use third-party tracking pixels from [provider] to analyse user interactions and improve our marketing efforts. These pixels may collect information such as your browsing activity, IP address, and interaction with ads. You can opt out of targeted advertising by adjusting your browser settings or [specific opt-out instructions].
Automated Decision Making
My business does not use fully automated decision-making processes that significantly impact customers. All key decisions are made with human oversight.
Access to Information
You can contact me (Georgie) to access, correct or update your personal information at any time. Please send your email to georgie@georgieduncan.com.au and expect a reply within 7 days. Unless [I am/we are] subject to a confidentiality obligation or some other restriction on giving access to the information which permits [me/us] to refuse you access under the Privacy Act, and [I/we] believe there is a valid reason for doing so, [I/we] will endeavour to make your information available to you within [30] days.
Complaints
If a breach of this Privacy Policy occurs, or if you wish to a request a change to your personal information, you may contact [me/us] by sending an email outlining your concerns to me at georgie@georgieduncan.com.au
If you are not satisfied with [my/our] response to your complaint you may seek a review by contacting:
-
the Office of the Australian Information Commissioner using the information available at http://www.oaic.gov.au/privacy/privacy-complaints
-
the health ombudsman in your state or territory
Notification of Change
When [I/we] update [my/our] Privacy Policy, [I/we] will post a copy of the revised policy on [my/our] website. It is your responsibility to check whether any changes have been made since your last visit.
Notification of Breach
If [I/we] have reason to suspect that a serious data breach has occurred and that this may result in harm or loss to you, [I/we] will immediately assess the situation and take appropriate remedial action.
If [I/we] still believe that you are at risk, [I/we] will notify the Office of the Information Commissioner and either notify you directly, or if that is not possible, publicise a notification of the breach on this website.