Privacy Policy

Tūāhu Wellness

Effective Date: 28/05/2026

1. COMMITMENT Tūāhu Wellness is committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

2. COLLECTION OF DATA We collect personal and health information directly from you (intake forms, sessions) and via our website/Halaxy software. This includes contact details, health/medical history, and session notes.

3. THIRD-PARTY DATA & OVERSEAS STORAGE We use third-party service providers (e.g., cloud storage, booking platforms like Halaxy) to deliver our services. These providers may process or store data on servers located outside of Australia. We select providers that demonstrate high standards of data security.

4. USE AND DISCLOSURE Your information is used to provide clinical services, manage administration, and ensure safety. We do not sell your data. We disclose information only:

  • With your informed consent.

  • For quality assurance via de-identified professional supervision.

  • When required by law (e.g., mandatory reporting).

  • In exceptional circumstances where there is a serious risk of harm to you or another person.

5. DATA SECURITY & BREACHES We use industry-standard technical measures (encrypted digital files, password protection). In the event of a data breach, we will notify you and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, as required by law.

6. RETENTION AND DESTRUCTION

  • Clinical Records: 5 years post-final session.

  • Financial/Tax Records: 7 years. After these periods, we use secure digital wiping and cross-cut shredding for paper records.

7. YOUR RIGHTS You have the right to access or correct your information. Send written requests to Pamela@tuahuwellness.com.au. We will respond within 10 business days.