Privacy Policy

Peace & Quiet Pty Ltd (ABN [to be inserted]) (Peace & Quiet, we, us, our) values your privacy and works to protect the information you provide to us. We operate an Australian telehealth clinic www.peaceandquiet.au (our Platform).

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Privacy Policy explains how we collect, use, hold and disclose your personal information, and your rights in relation to it.

By using our Platform, completing a patient brief survey, or booking a consultation, you consent to the collection and use of your information as described in this Policy.

Consent to Collect Your Personal Information

By providing us with your personal information, you consent to our Health Care Practitioners and authorised staff accessing and using that information to provide you with the best possible care. Only staff who need to see your information will have access to it. You also consent to us sharing your information with third parties as set out in this Policy. If we need to use your information for any other purpose, we will seek your additional consent.

What Personal Information We Collect

The personal information we collect includes:

•     Identity and contact details: name, date of birth, email address, phone number, residential state, preferred pronouns

•     Health information: presenting symptoms and concerns, diagnoses, medical history, current and past medications, allergies, mental health background, lifestyle and wellbeing information, pregnancy status, and other clinically relevant information you provide through the patient brief survey or during consultations

•     GP and treating practitioner details: name, practice, and consent for GP correspondence

•     Consultation information: consult preferences, follow-up responses, clinical notes

•     Platform information: session authentication tokens (stored securely and not accessible by JavaScript), IP address for security purposes only

We will only collect sensitive health information with your consent. Where you do not wish to provide us with your personal information, we may not be able to provide you with our services.

How We Collect Your Personal Information

We aim to collect your personal information directly from you. We do this through:

•     the online patient brief survey at clinic.peaceandquiet.au

•     appointment booking and clinical communications

•     telehealth consultations with your Wellness Team

•     email, phone or other correspondence with our team

•     follow-up surveys and check-in forms

We may also collect information from your treating GP, specialists or other healthcare providers with your consent, or from partner pharmacies involved in your care.

How We Use Your Personal Information

We collect, hold, use and disclose your personal information to:

•     provide you with our clinical services, including preparing your Brief, conducting consultations and issuing prescriptions (subject to clinical discretion)

•     communicate with you about appointments, survey links, treatment and follow-up care

•     facilitate the dispensing and delivery of Medicine through partner pharmacies

•     maintain accurate clinical records and administer our services

•     comply with our legal and regulatory obligations

•     improve the quality of our services

Automated Brief Generation

Your patient brief survey responses are processed by an automated algorithm to generate a de-identified clinical summary (your Brief) for your Wellness Team. No personally identifiable information — including your name, email, date of birth or contact details — is included in this process. All processing occurs within Australian infrastructure. The Brief is linked back to your patient record using an internal reference token only.

Disclosure of Your Personal Information

We may disclose your personal information to:

•     your Wellness Team — Health Care Practitioners and authorised clinical staff involved in your care

•     partner pharmacies — to dispense and deliver Medicine prescribed through our Platform, with your authorisation

•     your treating GP or specialists — to coordinate your care, with your consent

•     technology and infrastructure providers — cloud hosting, appointment and clinical workflow platforms, all subject to data processing agreements

•     CareEffect / ScriptTech — clinical workflow and appointment management (Australia-based)

•     HubSpot — patient relationship management, Australian data residency, storing operational information only (name, email, appointment status — no health data)

•     regulatory and government bodies — where required or authorised by law, including AHPRA, the TGA, state health departments and law enforcement

•     emergency services — where disclosure is necessary to protect the immediate safety of any person

We do not sell, rent or trade your personal information to any third party for commercial or marketing purposes. If we disclose your information to a third party, we require them to protect it to the same standard we do.

Overseas Disclosure

Our primary infrastructure — including patient data, clinical records and platform services — is hosted within Australia on Amazon Web Services (Sydney region). HubSpot, which stores operational contact information only, maintains Australian data residency for our account. We do not routinely transfer your health information outside Australia.

Where any service provider stores or processes data overseas, we take reasonable steps to ensure your information is handled in accordance with the APPs. In the event a recipient is required to disclose your information under a foreign law, such disclosure does not constitute a breach of the Privacy Act.

How We Store and Protect Your Personal Information

We take reasonable steps to protect your personal information from misuse, loss, unauthorised access, modification or disclosure. Our security measures include:

•     all data transmitted over HTTPS encryption

•     authentication tokens stored as secure, httpOnly cookies — not accessible via JavaScript

•     patient brief survey links are single-use, expire after 48 hours, and are cryptographically random

•     access to patient records is controlled by role-based permissions

•     all backend services run inside a private network — the database is not accessible from the public internet

•     staff access to clinical records is logged in an auditable access log

We retain health information for a minimum of 7 years from the date of last entry in your record, or longer where required by law. We destroy or de-identify personal information once it is no longer required.

Direct Communications

We may contact you by email or SMS about your care, appointments, survey links and follow-up communications. We may also, with your consent, send you information about our services.

You may opt out of promotional communications at any time by contacting hello@peaceandquiet.au or using the unsubscribe link in any marketing email. Opting out of promotional communications will not affect clinical communications necessary for your ongoing care.

Website and Cookies

Our clinical platform uses session tokens stored as secure, httpOnly cookies to authenticate your access. These are technically necessary and are not used for advertising or cross-site tracking.

Our public website may use standard analytics tools to understand visitor behaviour. You can manage cookie preferences through your browser settings.

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites.

Accessing and Correcting Your Personal Information

You have the right to request access to and correction of the personal information we hold about you. To make a request, please contact our Privacy Officer at hello@peaceandquiet.au. We will respond within 30 days. We may charge a reasonable fee to cover administrative costs in some circumstances.

If you believe information we hold is inaccurate, incomplete or out of date, please contact us and we will take reasonable steps to correct it at no charge.

Complaints

If you have a complaint about how we have handled your personal information, please contact our Privacy Officer in writing at hello@peaceandquiet.au. We will respond within 30 days.

If you are not satisfied with our response, you may contact:

•     Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au or 1300 363 992

•     NSW Health Care Complaints Commission — ecomplaints.hccc.nsw.gov.au

•     Australian Health Practitioner Regulation Agency (AHPRA) — www.ahpra.gov.au

Changes to This Policy

We reserve the right to update this Privacy Policy from time to time. Updated versions will be published on our website with a revised effective date. We encourage you to check our website periodically to stay informed of any changes.

Contact Us

Please address all correspondence to:

Privacy Officer

Peace & Quiet Pty Ltd

Email: info@peaceandquiet.au

Phone: +61 2 7248 5545

Website: www.peaceandquiet.au