Privacy Policy

Thank you for choosing NuLeaf Clinics. We are dedicated to safeguarding the information you provide to us, and understand the importance of your privacy.

1. Information collection introduction

1.1 This Privacy Policy (Privacy Policy) is provided to ensure you understand your rights and obligations when you access and navigate our website located at https://nuleafclinics.com.au/ (Website). NuLeaf Clinics, operated by NuLeaf Clinics (ABN: 39 660 934 421, ACN: 660 934 421) is committed to protecting your Personal Information and complying with the Australian Privacy Principles and the Privacy Act 1988 (Cth).

1.2 This policy sets out:

  • what is considered personal information;
    what personal information we collect and hold;
  • how we collect, hold, use or disclose personal information;
  • the purposes for which we collect personal information;
  • what happens if we are not able to collect personal information;
  • how to seek access to and correct your personal information;
  • whether we disclose personal information outside Australia; and
  • how to contact us.

1.3 We respect the rights and privacy of all individuals and are committed to complying with the Privacy Act 1988 (Cth) (the Act) and the Australian Privacy Principles and protecting the personal information we hold.

1.4 We may, from time to time, review and update this policy, including taking into account new or amended laws, new technology and/or changes to our operations. All personal information held by us will be governed by the most recently updated policy and we will give you notice of our revised policy by posting to our Website.

2. What is personal information?

When used in this policy, the term “personal information” has the meaning given to it in the Act. In general terms, it is any information that can be used to personally identify you. This may include (but is not limited to) your name, age, gender, postcode and contact details (including phone numbers and email addresses) and possibly financial information, including your credit card or direct debit account information. If the information we collect personally identifies you, or you are reasonably identifiable from it, the information will be considered personal information.

3. What personal information do we collect and hold?

3.1 We collect the type of personal information required to assist with providing you with and also access to the Website.

3.2 This may include personal information such as:

  • Personal or Company name;
  • mailing or street address;
  • email address;
  • telephone number;
  • age or birth date;
  • occupation;
  • any additional information relating to you that you provide to us directly through our Website, by phone or in person, or information you have provided indirectly through the use of our website or online presence through our representatives or otherwise;

3.3 Our medical practitioners may also collect this information from you.

4. How and why do we collect this personal information?

4.1 We collect your personal information directly from you unless it is unreasonable or impractical to do so. We do this in ways including:

  • when you submit any online form through the Website;
  • when you submit an enquiry through the Website;
  • during conversations between you and us via phone (if any);
  • administration of our services or other necessary actions to manage our business effectively.

4.2 We may also collect personal information from third parties including third party companies such as law enforcement agencies and other government entities, e-commerce platforms, data suppliers, advertisers, mailing lists and contractors and business partners.

4.3 We may also provide your information to third parties engaged by us to perform functions on its behalf, such as processing credit card information, order fulfilment, mailouts, shipping, debt collection, marketing, research and advertising; and third parties authorised by you to receive information held by us.

4.4 We may collect and disclose personal information to third parties for the purposes described in this policy. These purposes include but are not limited to:

  • efficient communications between you and us.
  • secure storage and management of your files to allow us to provide you with proper access to the Website.
  • notifying you of promotional material which may be suited to you.

4.5 The primary purpose for which we collect information about you is to enable us to perform our business activities and functions and to provide the best customer experience.

4.6 We generally collect personal information as part of providing you with access to Website, informing you about them, complying with our contractual and other legal obligations, running promotions and other marketing activities or administering our relationship with you by responding to your enquiries and providing you with information about our activities that may be of interest to you.

4.7 We may use your personal information for those purposes, in developing, maintaining or updating the system accessed by You through the Website or in any other way if we ask for your consent first.

4.8 Your personal information will not be shared, sold, rented or disclosed other than as described in this Privacy Policy.

4.9 We may disclose your personal information to:

  • our employees, contractors, licensees or external service providers for the operation of our website or our business, fulfilling requests by you, including without limitation IT systems administrators or payment processors;
  • specific third parties authorised by you to receive information held by us;
  • the police, any relevant authority or enforcement body, or your Internet Service Provider or network administrator, for example, if we have reason to suspect that you have committed a breach of any of our terms and conditions, or have otherwise been engaged in any unlawful activity, and we reasonably believe that disclosure is necessary;
  • as required or permitted by any law (including the Privacy Act).

5. What happens if we can’t collect your personal information?

5.1 When calling our team via telephone, you may choose not to identify yourself.

5.2 In some instances, if you do not provide us with the required personal information described in this policy, we may not be able to provide you with our services, either to the same standard as if you had provided the required personal information, or at all.

6. Maintaining the quality of your personal information

We strive to ensure that your Personal Information is accurate, complete, and up-to-date. We take reasonable steps to achieve this goal. If you find that the information we hold about you is inaccurate or needs updating, please notify us promptly so that we can update our records and continue to provide you with quality services.

7. Sensitive information

7.1 Sensitive information, as defined in the Privacy Act, includes details about an individual’s racial or ethnic origin, political opinions, membership in associations, religious or philosophical beliefs, trade union membership, criminal record, or health information.

7.2 We will only use sensitive information for the primary purpose it was obtained, for a secondary purpose directly related to the primary purpose, with your consent, or as required or authorised by law.

7.3 We take the security of your sensitive information very seriously. Sensitive information is encrypted both in transit and at rest using industry-standard encryption protocols. Access to sensitive information is restricted to authorised personnel only, and we use robust access control measures to prevent unauthorised access.

8. Use of financial information

8.1 If you use our Website to make purchases or other financial transactions (such as payment through the Website for products or services you purchase from a third-party user), we collect information about the purchase or transaction. This includes payment information, such as your credit card or debit card number, billing details and other account and contact information (Financial Information).

8.2 We will only collect Financial Information from you with your prior knowledge and consent. You can access and browse our website without disclosing Financial Information.

8.3 We use your Financial Information solely to process payments for services you request or purchase through the use of our Website. We only use and retain your Financial Information to complete payments you initiate, any Financial Information that is collected is solely for the purpose of transaction approval and the transfer of funds.

8.4 We provide data encryption throughout the payment process and only share your Financial Information with your credit card provider, third-party payment processor or financial institution to process payments. The Financial Information we collect from you is strictly confidential and held on secured servers in controlled facilities.

8.5 We do not retain your Financial Information after the transaction is complete.

8.6 We may use third-party agents to manage online payment processing. These agents are not permitted to store, retain, or use your Financial Information or other personally identifiable information, except for the sole purpose of payment processing on our behalf. Any third-party agent used by us is not authorized to use your Financial Information in any way other than to process payments and is required to keep any Financial Information it uses or collects confidential.

9. Direct marketing materials

9.1 We may send you direct marketing communications and information about services that we consider may be of interest to you. These communications may be sent in various forms, including SMS or email, in accordance with applicable marketing laws, such as the Spam Act 2004 (Cth).

9.2 In addition, at any time, you may opt-out of receiving marketing communications from us by contacting us (details below) or by using the opt-out facilities provided (e.g. an unsubscribe link). We will then ensure that your name is removed from the specific mailing list as requested. We do not provide your personal information to other organisations for the purposes of direct marketing unless expressly authorised by you.

9.3 Even if you do opt out of receiving marketing communications from us, you agree that we may still send you information relevant to the supply of any professional services arranged by us or goods or services purchased by you through our Website.

9.4 If you receive communications from us that you believe have been sent to you other than in accordance with this policy, or in breach of any law, please contact us using the details provided below.

10. Third party hosting

10.1 Our Website is hosted by third-party service providers.

10.2 In order for us to allow you access to the Website, we at times may allow access to personal information to third-party providers.

10.3 We make no representations or warranties in relation to the privacy practices of any third-party service providers and we are not responsible for the privacy policies or the content of any third-party service provider.

11. How can you access and correct your personal information?

11.1 You may request access to any personal information we hold about you at any time by contacting us at hello@NuLeaf Clinics.com.au;

11.2 Where we hold information that you are entitled to access, we will try to provide you with suitable means of accessing it (for example, by mailing or emailing it to you). We will not charge for simply making a request and will not charge for making any corrections to your personal information. If you make an access request, we will ask you to verify your identity. There may be instances where we cannot grant you access to the personal information we hold. For example, we may need to refuse access if granting access would interfere with the privacy of others, or if it would result in a breach of confidentiality. If that happens, we will give you written reasons for any refusal.

11.3 If you believe that personal information we hold about you is incorrect, incomplete or inaccurate, then you may request us to amend it. We will consider if the information requires amendment. If we do not agree that there are grounds for amendment, then we will add a note to the personal information stating that you disagree with it.

11.4 We request that you keep your information as current as possible so that we may continue to improve our service to you.

12. How will we make sure your personal information is secure?

12.1 We will take all reasonable steps to protect the personal information that we hold from misuse, loss, or unauthorised access, including by means of firewalls, password access, secure servers and encryption of credit card transactions.

12.2 If you suspect any misuse or loss of, or unauthorised access to, your personal information, please let us know immediately.

12.3 If we suspect any misuse or loss of, or unauthorised access to, your personal information we may inform you of that suspicion and take immediate steps to limit any further access to, or distribution of, your personal information. If we determine that the breach is likely to result in serious harm to you and we are unable to prevent the likely risk of serious harm with remedial action, we will take action in accordance with the Privacy Act 1988 (Cth).

12.4 If we receive unsolicited personal information that we are not permitted to collect under this privacy policy, or within the confines of the law, we will destroy or de-identify the unsolicited personal information as soon as practicable if it is lawful and reasonable to do so. We will destroy or de-identify your personal information if we no longer require it to deliver our services as soon as practicable if it is lawful and reasonable to do so.

13. How We Treat Protected Health Information (PHI)

We collect, use, and disclose Protected Health Information (PHI) only as necessary to provide our services, meet legal obligations, and support your treatment. PHI may include any information related to your health, treatment, or payment for healthcare services that can identify you.

  • Collection: We collect PHI directly from you or your authorised representatives when you interact with our services, either online or in person. This may include information such as your medical history, prescription details, and contact information.
  • Use: We use your PHI to deliver healthcare services, manage your treatment, process payments, and conduct healthcare operations, including quality assessments and improvements.
  • Disclosure: We may share your PHI with healthcare providers, pharmacies, insurers, and other entities involved in your care as necessary. We do not share your PHI with third parties for marketing purposes without your explicit consent.

14. Patient Rights Regarding Protected Health Information (PHI)

As a patient, you have specific rights regarding your PHI under Australian privacy law, including:

  • Right to Access: You have the right to access and obtain a copy of your PHI, subject to certain exceptions under Australian law. You may request access by contacting our Privacy Officer.
  • Right to Request Corrections: If you believe your PHI is incorrect or incomplete, you have the right to request that we amend the information. We may deny your request in certain circumstances, but we will provide an explanation for any denial.
  • Right to Request Restrictions: You have the right to request restrictions on how we use or disclose your PHI for treatment, payment, or healthcare operations. While we are not required to agree to your request, if we do agree, we will comply with it except in emergencies.
  • Right to Confidential Communications: You have the right to request that we communicate with you about your medical matters in a specific way or at a specific location.
  • Right to an Accounting of Disclosures: You have the right to request a list of certain disclosures of your PHI that we have made, other than those made for treatment, payment, healthcare operations, or with your authorization.
  • Right to a Copy of This Privacy Policy: You may request a paper copy of this Privacy Policy at any time, even if you have agreed to receive the policy electronically.

15. Privacy Officer Contact Information

If you have any questions about this Privacy Policy or your rights under Australian privacy law, or if you wish to exercise any of your rights, don’t hesitate to get in touch with our Privacy Officer:

Title: Privacy Officer
Email: hello@NuLeafClinics.com.au

16. Do we use ”cookies”?

16.1 When you use our Website, we or our service providers may obtain information using technologies such as cookies, tags, web beacons, and navigational data collection (log files, server logs, and clickstream data) to better understand your user experience. For example, we or our service providers may collect information like the date, time and duration of visits and which web pages are accessed.

16.2 When you access our Website, we may send a “cookie” (which is a small summary file containing a unique ID number) to your computer. This enables us to recognise your computer and greet you each time you visit our website, without bothering you with a request to register or log-in. It also helps us keep track of products or services you view so that we can send you news about those products or services.

16.3 We also use cookies to measure traffic patterns, to determine which areas of our websites have been visited, and to measure transaction patterns in the aggregate. We use this to research our users’ habits so that we can improve our online services. If you do not wish to receive cookies, you can set your browser so that your computer does not accept them.

16.4 We may also log IP addresses (the electronic addresses of computers connected to the internet) to analyse trends, administer the website, track user movements, and gather broad demographic information.

16.5 This information is generally not linked to your identity, except where it is accessed via links in our emails or where you have identified yourself. We may also collect anonymous data (which is not personal information) relating to your activity on our website (including IP addresses) via cookies. We generally use this information to report statistics, analyse trends, administer our services, diagnose problems, and target and improve the quality of our services. To the extent this information does not constitute personal information because it does not identify you or anyone else, the Australian Privacy Principles do not apply and we may use this information for any purpose and by any means whatsoever.

17. Universal (Google) Analytics

17.1 The Website uses Universal (Google) Analytics to analyse the use of the Website. Google Analytics generates statistical and other information about website use by means of cookies, which are stored on users’ computers. The information generated relating to our website is used to create reports about the use of the Website. Google will store and use this information. Google’s privacy policy is available at: http://www.google.com/privacypolicy.html.

18. How can you complain about privacy breaches?

18.1 If you believe your privacy has been breached by us, have any questions or concerns about our Privacy Policy please, contact us using the email hello@NuLeafClinics.com.au and provide details of the incident so that we can investigate it.

18.2 We are genuinely committed to the rules, ethos, and intent detailed in this Privacy Policy and we aim to ensure that your requests or complaints are treated confidentially. Our representative will contact you within a reasonable time after receipt of your complaint to discuss your concerns and outline options regarding how they may be resolved. We will aim to ensure that your complaint is resolved in a timely and appropriate manner.

18.3 If you are not satisfied with the outcome of our investigation, then you may request that an independent person (usually the Commonwealth Privacy Officer) investigate your complaint.

19. Who can you contact about your personal information?

To contact us about your personal information, concerns, or complaints, email hello@NuLeafClinics.com.au.

20. Policy updates

20.1 This Privacy Policy may change from time to time, and the most up-to-date version will be available on our website (https://nuleafclinics.com.au/). We encourage you to periodically review our Privacy Policy to stay informed about any updates or changes.

20.2 If we make significant changes to our Privacy Policy, we will notify you by email or by placing a prominent notice on our website.
I have read and agree to Privacy Policy and Terms of Service.