Know more about our certification process. Learn More

Doctors are online now

Privacy Policy

Privacy Policy // MinuteHealth

1. Overview

Thank you for using the MinuteHealth platform provided by MinuteHealth Pty Ltd (MinuteHealth), a platform that connects individuals with health practitioners for the purposes of the health practitioner running telehealth consultations and, if appropriate, providing other health services. Your privacy is important to us and we are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) (Privacy Act), which includes the Australian Privacy Principles (APPs) and any related privacy codes. This Policy outlines how we collect, use, disclose and store your personal information and lets you know how you can access that information. This Policy applies to our obligations when handling information in Australia. Please read this Policy carefully and contact us using the details below if you have questions.

2. Consent

By providing personal information, you consent to us collecting, using, storing and disclosing your personal information in accordance with this Policy or as required or permitted by law. If you continue using our services, then we will treat your use as your consent to us handling your personal information in accordance with this Policy. We will generally obtain consent from the owner of personal information to collect their personal information. Consent will usually be provided in writing; however, sometimes it may be provided orally or may be implied through a person’s conduct. We endeavour to only ask for your personal information if it is reasonably necessary for the activities that you are seeking to be involved in.

3. What personal information do we collect and why do we collect it?

Information Collected about our users
  • Your name, address, and contact details.
  • Date of birth.
  • Gender.
  • Any photos or records that you upload, such as a medical record.
  • Your device ID, device type and information, geo-location information, Internet Protocol (IP) address, standard web log information, browser session data, device and network information, statistics on page views, acquisition sources, search queries, browsing behaviour and information gathered through internet cookies.
  • Information contained in any communications between you and us.
Why we collect it
  • For the purpose for which the personal information was originally collected.
  • To identify and interact with you.
  • To perform administrative and operational functions.
  • To comply with any legal requirements, including any purpose authorised or required by an Australian law, court or tribunal.
  • For any other purpose for which you give your consent.
How we collect it
  • use our services;
  • provide information to us on our platform;
  • set up a profile with us;
  • interact or share personal information with us via our social media; and communicate with us.
  • Through our third party service providers
About our general users that have may not subscribed to our Service but interact with us
  • Information you have provided in communications we have with you.
  • Information you have provided in the platform before you submit it to us, such as through cart abandonment.
  • Information about your access and use of our website, including browser session data, device and network information, statistics on page views, acquisition sources, search queries, browsing behaviour and information gathered through internet cookies.
  • To identify and interact with you.
  • To perform administrative and operational functions.
About contractors or prospective staff members (including health practitioners)
  • Your name, address, contact details (including email address and phone number) and date of birth.
  • Your nationality and which countries you hold citizenship of.
  • Educational details, such as schools you have attended, any qualifications you have received, transcripts and/or English language test results.
  • Employment details, such as a CV, qualifications attained or examples of work.
  • Any licences with relevant regulatory boards and/or other bodies, councils or authorities.
  • To enable us to carry out our recruitment functions.
  • To correspond with you.
  • To fulfil the terms of any contractual relationship.
  • To ensure that you can perform your duties.

If you choose not to provide information as requested, we may not be able to service your needs. For example, it will not be possible for us to provide you with our service if you want to remain anonymous or use a pseudonym. We sometimes receive unsolicited personal information. In circumstances where we receive unsolicited personal information we will usually destroy or de-identify the information as soon as practicable if it is lawful and reasonable to do so unless the unsolicited personal information is reasonably necessary for, or directly related to, our functions or activities.

4. Sensitive information

We may collect sensitive information from you. This includes health information, for example, details regarding your medical history, symptoms, or any health information contained in any documents you upload. If you consent to providing us with this information, we will only use it for facilitating our provision of services and to enable you to use our platform. You provide us with your health information when you enter it onto our platform. When you enter your health information, you are consenting to MinuteHealth: (a) collecting and handling it in accordance with this Privacy Policy; and (b) sharing it with the health practitioners who have agreed to our terms for the purpose of providing our services to you and the health practitioners, and to facilitate the health practitioner’s provision of their services to you. If you do not agree to this, you should not provide us with your health information.

5. Disclosing your personal information

We may disclose your personal information to the following third parties: (a) our business or commercial partners; (b) the health practitioners who have agreed to our terms; (c) our professional advisers, dealers and agents; (d) third parties and contractors who provide services to us, including customer enquiries and support services, IT service providers, data storage, webhosting and server providers, marketing and advertising organisations, payment processing service providers; (e) payment system operators and debt-recovery functions; (f) third parties to collect and process data, such as Amazon Web Services, Microsoft Azure, Hotjar, Google Analytics, Airtable, Zapier or other third parties; and (g) any third parties authorised by you to receive information held by us. We may also disclose your personal information if we are required, authorised or permitted by law. We may send information to third parties that are located outside of Australia for the purposes of providing our services. These third parties are located in the United Kingdom and the European Union, although this list may change from time to time. Disclosure is made to the extent that it is necessary to perform our functions or activities.

6. Using your personal information for direct marketing

From time to time, and in support of our future development and growth, we may use your personal information to contact you to promote and market our products and services. You can opt-out from being contacted for direct marketing purposes by contacting us at contact@minutehealth.com.au or by using the unsubscribe facility included in each direct marketing communication we send. Once we receive a request to opt out from receiving marketing information, we will stop sending such information within a reasonable amount of time.

7. Security

We take all reasonable steps to protect personal information under our control from misuse, interference and loss, and from unauthorised access, modification or disclosure. We hold your personal information electronically in secure databases operated by our third-party service providers. We protect the personal information we hold through a number of different layers including: (a) encrypted browsing through HTTPS; (b) storing authentication details, such as passwords, in hashed or non reversible formats; (c) actively monitoring errors and logs using industry level tooling; (d) operating within a secure cloud environment; and (e) relying on TLS security to interact with the databases. Our servers are hosted with Amazon Web Services and Microsoft Azure and we use the provided security functionality and monitoring to detect and prevent persistent access to rogue services. Server access and deployment are limited to revokable access keys that can only be regenerated on a master account. Access to servers can only be gained by using industry standard encryption keys that are generated and regularly updated, including when employees leave MinuteHealth. User logs redact certain types of information, such as passwords, before they are logged to prevent user information leaking to third parties. Servers and databases are limited to internal access only to prevent database access to the public, unless it relates to certain whitelisted services or for monitoring and troubleshooting. While we take reasonable steps to ensure your personal information is protected from loss, misuse and unauthorised access, modification or disclosure, security measures over the internet can never be guaranteed. We encourage you to play an important role in keeping your personal information secure, by maintaining the confidentiality of any passwords and account details used on our website.

8. Accessing or correcting your personal information

If you would like to access your personal information, please contact us using the details below. In certain circumstances, we may not be able to give you access to your personal information, in which case we will write to you to explain why we cannot comply with your request. We try to ensure any personal information we hold about you is accurate, up-to-date, complete and relevant. If you believe the personal information we hold about you should be updated, please contact us using the details below and we will take reasonable steps to ensure it is corrected if appropriate.

9. Destroying or de-identifying personal information

We destroy or de-identify personal and sensitive information when we no longer need it unless we are otherwise required or authorised by law to retain the information.

10. Making a complaint

If you believe your privacy has been breached or you have a complaint about our handling of your personal information, please contact us using the details below. We take privacy complaints seriously. If you make a complaint, we will respond within 5 days to acknowledge your complaint. We will try to resolve your complaint within 30 days. When this is not reasonably possible, we will contact you within that time to let you know how long we will take to resolve your complaint. We will investigate your complaint and write to you to explain our decision as soon as practicable. If you are not satisfied with our decision, you can refer your complaint to the Office of the Australian Information Commissioner by phone on 1300 363 992 or online at www.oaic.gov.au.

11. Changes

We may, from time to time, amend this Policy. We will notify you of any changes to this Policy and any changes to this Policy will be effective immediately upon the posting of the revised Policy on our website. By continuing to use the services following any changes, you will be deemed to have agreed to such changes.

12. Contact us

All questions or queries about this Policy and complaints should be directed to: Privacy Officer Email: privacy@minutehealth.com.au. This Policy was last updated in March 2023.

© 2023 MinuteHealth Pty Ltd.
ALL RIGHTS RESERVED.