Privacy policy.

This is the Privacy Policy of By Blu Naturopathy 64 476 435 320. If you have any questions or need further information, please email Briana Surkitt: briana@byblunaturopathy.com.

We are committed to protecting your privacy, whether you are a client or customer of ours, employee or supplier.

This document describes how we collect and manage your personal and sensitive information when you interact with our business. We take this responsibility very seriously. If you have any questions or concerns about how your personal or sensitive information is being handled, please do not hesitate to contact us.

We comply with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth) (Privacy Act).

We understand that visitors from the EU may access this site, so we also aim to comply with the General Data Protection Regulations (GDPR).

Personal Information

If you engage with us via this website, or choose to become our client or customer, we may ask to collect the following kinds of personal information from you, including:

-       Contact details including your name, email address & phone number, aswell as residential address if signing up for 1:1 consultations.

-       Interests and preferences including information relating to your personal circumstances applicable to our offerings and information including your opinion about future topics, products or services that may be of value for you.

-       Information that allows us to tailor our content to your needs when you sign up for one of our events.

-       Your IP address, and information about your browsing history to help us improve the usability and appeal of our website. More information about this can be found in the Cookie policy below.

-       If you are an employee or contractor, or propose working with me in that capacity, information about your qualifications, skill and work experience may be required.

-       If you are a supplier or prospective supplier, information about your business skills, services, products & prices.

Collection and Use

We may collect your personal information by various means including:

·       You contact us with a question, comment or inquiry

·       You subscribe to our newsletter

·       You attend a webinar, seminar or event where we are hosting or presenting

·       You correspond with us on a social media platform such as Facebook, LinkedIn, Instagram or similar sites

·       You opt in to receive a free resource from us

·       You book a consultation or purchase a product or service from us.

·       You provide us with a testimonial

·       We search your website or social media in preparation for working with you

·       Our website automatically collects information about you and your activities on our site (including analytics and cookies)

·       A third party supplies information to us

Where practicable we will only collect personal information about you directly from you. However, in some circumstances we may obtain personal information from a third party. If this information is obtained contrary to this Privacy Policy and the Privacy Act, we will destroy or de-identify such information within a reasonable period.

If you do not provide us with information when requested to do so, we may not be able to carry out your instructions or achieve the purpose for which the information has been sought.

We use your information to:

·       Respond to your enquiries

·       Provide you with our products or services at your request

·       Monitor or improve the use of and satisfaction with our website, products or services

·       Share the latest news and developments relevant to our work.

·       Let you know about our expertise, and products or services that may be of interest to you

We will only collect your information:

·       With your full awareness and consent, such as when you email us, tick a checkbox or fill in a form to provide us with information

·       If we need it to provide you with information or services that you request

·       If we are legally required to collect it

·       If collecting the information is necessary to preserve life or keep someone safe from harm

·       For necessary administrative processes if you become our client

·       If we believe that we can demonstrate a legitimate interest in using your data for marketing purposes, although we will always give you a choice to opt out

 

Where practicable we will only collect personal information about you directly from you. However, in some circumstances we may obtain personal information from a third party. If this information is obtained contrary to this Privacy Policy and the Privacy Act, we will destroy or de-identify such information within a reasonable period.

As a Naturopath I am required to identify clients by collecting their specific details. Failure to provide this information means I cannot offer or may limit my services to you.

 

Sensitive Information

We understand that some information is particularly sensitive, and that you are trusting us to keep this information confidential.

The sensitive information we collect from you may include:

·       Your birth date

·       Your personal medical history and family medical history

·       Information on your lifestyle

We will only collect sensitive information by methods that are reasonably secure, such as:

·       Through our intake form and case notes in Cliniko when you book an appointment

·       In a telehealth consultation via Cliniko or face to face

·       When you send us information in an email please note that email may not be sufficiently secure. If the information is extremely sensitive, ask us about alternative ways to share it with us.

The reason why we collect your sensitive information is:

·   So that we can provide you with the services you have requested from us.

·   To ensure we are providing you with the most effective health services.

Secure Storage of Sensitive Information

We are committed to securely storing and handling your sensitive information.

·       Sensitive information is stored on password protected computer and two factor authenticated software.

·       Only your practitioner & authorised team members have access to your sensitive information and only as necessary for your optimal treatment and benefit.

·       Sensitive information may be stored online through Cliniko. You can find out more about their security provisions in the section on Security below.

Collection of Information from Minors

Sensitive information may be collected from children under the age of 18 in the following circumstances:

- In the presence of their parent or guardian, or

- With their guardian’s full knowledge and consent.

All information collected from minors is securely stored in accordance with this privacy policy.

Disclosure of Information

We may disclose your information if required under the following circumstances:

·       To provide you with the services you have requested

·       To send you products that you have purchased

·       Where disclosure is necessary to carry out your instructions, such as corresponding with someone else on your behalf, requesting pathology tests and ordering supplements.

·       Where we use support services to assist us in our business

·       To engage in professional supervision, although any information we share under these circumstances is de-identified to preserve client confidentiality

·       To refer you to other service providers at your request

Who disclosures are made to

You consent to us sharing relevant information, on a strictly need-to-know basis, with:

·       People you authorise us to correspond with, as reasonably required to carry out your instructions

·       Our employees

·       Third party providers who assist with

o   Accounting

o   Administration

o   Professional supervision

o   Email marketing

o   Legal or financial advice

o   Website maintenance

o   Technological services.

Legal disclosure

We will also disclose your information if required by law to do so or in circumstances permitted by the Privacy Act – for example, where we have reasonable grounds to suspect that someone is engaging in unlawful activity, or misconduct of a serious nature, that relates to our functions or activities, and in response to a subpoena, discovery request or a court order.

Disclosure overseas

We will use all reasonable means to protect the confidentiality of your information while in our possession or control. We will not knowingly share any of your information with any third party other than the service providers who assist us with necessary business activities or the services we are providing to you. To the extent that we do share your information with third-party service providers, we only do so if we are satisfied that the service provider has a suitably protective privacy policy of their own, or they have signed a confidentiality agreement with us. Some of our service providers may be overseas and may not be subject to Australian Privacy Laws. You can find further information under the Security section below.

Invitation to discuss

If you have any concerns regarding the disclosure of your information, please do not hesitate to get in touch with us.

Security

We take reasonable physical, technical and administrative safeguards to protect your personal and sensitive information from misuse, interference, loss, and unauthorised access, modification and disclosure.

We manage risks to your information by:

·       Storing files securely

·       Ensuring that only key personnel have access to sensitive information

·       Releasing information to service providers on a strictly need-to-know basis

·       conducting regular audits of our security systems

As mentioned above, your information may also be stored with a third-party provider, where it will be managed under their security policy. The following security policies may apply during our work together:

·       Cliniko - https://www.cliniko.com/security/

·       Mailchimp - https://mailchimp.com/about/security/

·       Squarespace - https://www.squarespace.com/privacy

·       Stripe - https://stripe.com/docs/security

·       Xero - https://www.xero.com/au/security/

 

Cookies and Google Analytics

We use Google Analytics to collect information about your use of our website so that we can get strategic information about how our website is being used and improve its functionality. You can find out more about the information Google collects and how it is used here:

https://support.google.com/analytics/answer/6004245.

Google also provides an add-on for your browser that you can use to opt-out and prevent your data being used by Google Analytics. You can access that add-on here:

https://tools.google.com/dlpage/gaoptout.

Squarespace also sets cookies to prevent cross-site request forgery (CSRF). You can find out more about the information squarespace collects here:

https://www.squarespace.com/cookie-policy

 

Access to Information

You can contact us to access, correct or update your personal information at any time. Unless we are subject to a confidentiality obligation or some other restriction on giving access to the information which permits us to refuse you access under the Privacy Act, and we believe there is a valid reason for doing so, we will endeavour to make your information available you within 30 days.

Complaints

If a breach of this Privacy Policy occurs, or if you wish to a request a change to your personal information, you may contact us by sending an email outlining your concerns to us at briana@byblunaturopathy.com.

If you are not satisfied with our response to your complaint you may seek a review by contacting:

·       The Office of the Australian Information Commissioner using the information available at http://www.oaic.gov.au/privacy/privacy-complaints

·       The health ombudsman in your state or territory

Notification of Change

When we update our Privacy Policy, we will post a copy of the revised policy on our website.

Notification of Breach

If we have reason to suspect that a serious data breach has occurred and that this may result in harm or loss to you, we will immediately assess the situation and take appropriate remedial action. If we still believe that you are at risk, we will notify the Office of the Information Commissioner and either notify you directly, or if that is not possible, publicise a notification of the breach on this website.

This Privacy Policy was created with the support of Carefree Counsel. Copying it without permission is an infringement of our copyright and Carefree Counsel’s.