← Back home

Privacy Policy

Effective Date: 12 July 2026 | Version 1.1

1. Introduction

Nureo Pty Ltd ('Nureo', 'we', 'us', 'our') is committed to protecting your privacy and handling your personal information responsibly. This Privacy Policy explains how we collect, hold, use, and disclose your personal information, including your sensitive information and health information, when you use the Nureo platform.

This Privacy Policy is prepared in accordance with the Privacy Act 1988 (Cth) ('Privacy Act') and the Australian Privacy Principles ('APPs') contained in Schedule 1 of the Privacy Act. Because the Platform collects health information, which is classified as 'sensitive information' under the Privacy Act, additional protections and obligations apply.

YOUR CONSENTBy using the Platform, you consent to the collection, use, and disclosure of your personal information (including health information) as described in this Privacy Policy. You may withdraw your consent at any time, subject to legal and contractual restrictions.

This Policy should be read together with our Terms of Service. If there is any inconsistency between this Policy and our Terms of Service on a privacy matter, this Policy prevails.

2. Who We Are

Nureo Pty Ltd (ABN: 84 696 935 154) operates the Nureo health and wellness platform. We are based in Australia and subject to the Privacy Act 1988 (Cth).

Contact details for privacy matters:

Privacy Officer: privacy@nureo.com.au

General contact: support@nureo.com.au

Website: www.nureo.com.au

Registered address: 25 South Street, West Wodonga VIC 3690

3. What Personal Information We Collect

We collect personal information that is reasonably necessary for the proper performance of our functions as a health and wellness platform. The types of information we collect include:

3.1 Account and Identity Information

Full name and preferred name

Email address

Date of birth and age

Password (stored in hashed/encrypted form — we do not store plain-text passwords)

Profile photograph (if provided)

Subscription tier and billing information

3.2 Health Information (Sensitive Information)

HEALTH DATA NOTICEHealth information is 'sensitive information' under the Privacy Act 1988 (Cth) and attracts heightened privacy protections. We will only collect your health information with your express consent, and will take all reasonable steps to protect it.

We collect the following health and wellness information, which may constitute sensitive information:

Daily check-in data: sleep duration and quality, water intake, exercise type and duration, energy levels, and mood ratings.

Health focus area: nutrition, fitness, mental wellbeing, or general health.

Active and historical health goals and milestone progress.

Food scanner data: photographs of food items, identified nutritional content, and meal logs.

Progress photographs (uploaded voluntarily in the milestone goals feature).

AI health assistant conversation history (messages sent to and received from Nuri).

Wellness streaks and gamification data (check-in streaks, badges earned).

Any other health or wellbeing information you voluntarily provide through the Platform.

3.3 Financial and Payment Information

Subscription plan and billing history.

Payment method type and last four digits of card number (stored via our payment processor).

Transaction records for Practitioner appointment bookings.

We do not store your full credit card or bank account details on our servers. Full payment card data is processed and stored by our third-party payment processors (such as Stripe) who are PCI-DSS compliant.

3.4 Location Information

Approximate location data used to show relevant Practitioners in your region (Premium users).

Location may be derived from your IP address or, if you grant permission, from your device's GPS.

You may disable location access through your device settings. Disabling location access may limit the functionality of the Practitioner Directory.

3.5 Technical and Device Information

Device type, operating system, and app version.

IP address and approximate geographic location derived from IP.

App usage data, session duration, and feature interactions.

Crash reports and error logs.

Push notification token (for sending in-app and push notifications).

3.6 Communications

Messages you send to Practitioners through in-app messaging (Premium only).

SMS and email messages exchanged with a clinic you book through Nureo — including appointment confirmations, reminders, and two-way replies. These are sent using our email and SMS delivery providers (see clause 7.2) so the clinic can communicate with you about your care.

Customer support communications.

Feedback and survey responses.

Correspondence with our team.

3.7 Information from Third Parties

If you sign in using a third-party service (such as Apple Sign-In or Google Sign-In), we may receive your name and email address from that service. We only collect the information permitted by your settings on that third-party service.

3.8 Live Seminar and Streaming Data

Where you take part in a live seminar or webinar on the Platform, we collect information about your participation, including the seminars you join, questions you submit to the host, and interaction signals (such as on-screen reactions). Most participants join as view-only audience members and do not transmit their own camera or microphone. If you are a host or presenter, we also process your live video and audio for the duration of the broadcast.

Live seminars are delivered using a third-party real-time streaming provider. Because this involves streaming infrastructure that may operate outside Australia, please read clause 7 (Disclosure) and clause 8 (Cross-Border Disclosure) for important information about how live-stream data is handled.

4. How We Collect Your Information

We collect personal information in the following ways:

Directly from you: when you register an Account, complete your profile, submit check-ins, use the food scanner, set health goals, upload progress photos, communicate with Practitioners, or contact our support team.

Automatically: through your use of the Platform, including app usage analytics, device information, IP address, and technical logs.

From third parties: from payment processors (transaction data), identity verification services (if applicable), and sign-in providers (Apple, Google) where you choose to use them.

From Practitioners: Practitioners may add notes or information to your appointment record where you have consented to share that information.

Where practicable and lawful, you may interact with the Platform without identifying yourself or by using a pseudonym. However, certain features (such as Practitioner bookings and payment) require you to be identified. If you choose not to provide certain information, some Platform features may not be available to you.

5. Why We Collect and How We Use Your Information

We collect, hold, and use personal information only for the purposes for which it was collected, or for directly related purposes, or where you have consented, or where otherwise permitted by law. Our primary purposes include:

5.1 Providing the Platform and Services

Creating and managing your Account.

Processing your Subscription and payments.

Providing personalised health and wellness features (check-ins, food scanner, AI assistant, courses, goals).

Facilitating Practitioner discovery, appointment booking, and in-app messaging.

Delivering push notifications, reminders, and in-app communications.

Providing customer support.

5.2 Personalisation

Personalising the Nuri AI assistant responses based on your health focus, goals, and check-in history.

Tailoring Platform content and course recommendations to your stated health interests.

Displaying relevant Practitioners based on your location and health needs.

5.3 Platform Improvement and Analytics

Analysing aggregated, de-identified usage data to improve Platform features and performance.

Monitoring for technical issues, errors, and security incidents.

Conducting research and development to improve our services.

We use aggregated and de-identified data for analytics and improvement purposes. This data cannot be used to identify any individual user.

5.4 Legal and Compliance Obligations

Complying with applicable laws, regulations, and legal processes.

Responding to lawful requests from regulatory authorities and law enforcement.

Enforcing our Terms of Service and protecting our legal rights.

Detecting and preventing fraud, security breaches, and illegal activity.

Maintaining records as required by applicable tax and financial laws.

5.5 Direct Marketing

We may use your email address and push notification token to send you information about new features, promotions, and health content. We will only send you direct marketing communications where you have consented, or as permitted by the Spam Act 2003 (Cth). You may opt out of marketing communications at any time by:

To manage email marketing, we use a third-party marketing platform (Klaviyo). Only basic contact details — your name, email address, and subscription/account type — are shared with this platform, and only where you have consented to marketing. We do not share your health information with our marketing platform, and your health information is never used to target marketing. Klaviyo is located in the United States; see clause 8 (Cross-Border Disclosure).

Clicking the 'unsubscribe' link in any marketing email.

Adjusting notification settings in the Platform.

Contacting us at privacy@nureo.com.au.

Opting out of marketing communications will not affect transactional communications necessary for the operation of your Account (such as billing confirmations, subscription renewal notices, or security alerts).

6. Sensitive Information and Health Information

6.1 Consent Basis

Under the Privacy Act 1988 (Cth), health information is a subset of 'sensitive information' and may only be collected with your express consent (or in limited circumstances permitted by law). By voluntarily entering your health data into the Platform (including completing daily check-ins, logging food, uploading progress photos, and interacting with the AI assistant), you expressly consent to the collection and use of that health information for the purposes described in this Privacy Policy.

6.2 Use of Health Information

Your health information is used exclusively to:

Provide you with personalised health and wellness tracking features within the Platform.

Personalise AI assistant responses based on your health goals and check-in history.

Display your own progress and history back to you.

Where you have consented, share relevant data with Practitioners you engage through the Platform.

Improve Platform features through analysis of de-identified, aggregated data.

6.3 Health Information is Not Used for Advertising

We do not use your health information for targeted advertising or sell your health information to advertisers or data brokers. Health data is never shared with third parties for commercial purposes.

6.4 AI Processing of Health Data

When you use the Nuri AI assistant or food scanner, the messages, images, and contextual data you provide (including your check-in history, health focus, streak data, and active goals) are sent to Google's Vertex AI to generate personalised responses. Google acts as our data processor under the Google Cloud Data Processing Addendum and processes this data only on our instructions and to provide the service.

This processing is configured to take place in Google's australia-southeast1 (Sydney, Australia) region, so your health data is processed onshore. Your prompts, images, and the responses generated are not used to train or improve Google's AI models, are not reviewed by Google for product development, and are not used by us or Google for advertising. AI-generated responses are not stored as part of your health record. Conversation context within a session may be retained temporarily to maintain conversation coherence.

6.5 AI Consult Scribe (Practitioner Feature)

If you consult a practitioner through Nureo, the practitioner may use an AI 'scribe' to help draft their clinical notes, but only after telling you and obtaining your agreement. The scribe transcribes the consult audio on the practitioner's own device — the audio is never uploaded to Nureo or to any third party. Only the resulting draft text note, which the practitioner reviews, is saved to your clinical record, together with a record that your consent was confirmed. Where the practitioner generates the draft with AI assistance, the transcript text is processed in Google's australia-southeast1 (Sydney, Australia) region and is not used to train AI models. You can ask your practitioner not to use the scribe at any time.

6.6 Connected Health Services and Google User Data

You may choose to connect a third-party health service — such as Google Health (which surfaces Fitbit, Pixel and other Google-connected health data) — so that the Platform can display your activity, sleep, heart rate, energy and distance and share your progress with your practitioner. Connecting is optional and requires you to grant access through Google's own consent screen. You can disconnect at any time in the Platform, or revoke Nureo's access directly in your Google Account settings.

GOOGLE API LIMITED USENureo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: (a) we use Google user data only to provide and improve the user-facing health and wellness features you connected it for; (b) we do not transfer this data to others except as necessary to provide or improve those features, with your consent, for security purposes, or to comply with applicable law; (c) we do not use Google user data for advertising, and we do not sell it; and (d) we do not allow humans to read this data unless we first obtain your affirmative consent, it is necessary for security purposes (such as investigating abuse) or to comply with applicable law, or the data has been aggregated and de-identified.

We do not store your Google account password or long-lived Google credentials on our servers. Access tokens are handled on your device by Google's official sign-in libraries. Health data retrieved from Google is stored in your own private area of the Platform under the same protections as the rest of your health information, and is deleted when you delete your account or disconnect the service.

7. Disclosure of Your Personal Information

7.1 When We May Disclose Your Information

We do not sell, rent, or trade your personal information to third parties. We may disclose your personal information to third parties only in the following circumstances:

7.2 Service Providers and Processors

We engage trusted third-party service providers who process personal information on our behalf under strict contractual obligations. These providers are permitted to use your information only to perform services for us and are required to maintain appropriate security standards. Categories of service providers include:

Cloud infrastructure and hosting providers (for storing Platform data securely).

Payment processors (for processing Subscription fees and Practitioner booking payments).

AI and machine learning service providers (for powering the Nuri AI assistant).

Analytics providers (using de-identified data only).

Customer support tools.

Email and push notification delivery services (including Amazon Web Services (AWS SES) for transactional and clinic email).

SMS delivery providers (for appointment confirmations, reminders, and two-way messaging with clinics).

Email marketing platform (Klaviyo — receives basic contact details of consented members only, never health information).

Live video and audio streaming providers (for hosting and delivering live seminars and webinars).

7.3 Practitioners

If you book an appointment with a Practitioner through the Platform, we will share the information necessary to facilitate that booking, including your name, contact details, and any health information you choose to share in your appointment request. Practitioners receiving your health information are bound by their own professional confidentiality obligations and the Privacy Act.

Before sharing any health information with a Practitioner, we will obtain your specific consent. You can choose what health information, if any, you share with a Practitioner.

7.4 Legal Requirements

We may disclose your personal information if required to do so by law, including in response to a subpoena, court order, warrant, or other lawful request from a government authority or law enforcement agency. We will take reasonable steps to notify you of such disclosure unless legally prohibited from doing so.

7.5 Business Transfers

If Nureo is involved in a merger, acquisition, restructure, or sale of all or a portion of its assets, your personal information may be transferred to the successor entity. We will notify you by email and/or prominent in-app notice before your personal information is transferred and becomes subject to a different privacy policy.

7.6 Protecting Rights and Safety

We may disclose your information if we believe disclosure is necessary to protect the safety, rights, or property of Nureo, our users, or the public, or to investigate, prevent, or take action regarding suspected fraud or security incidents.

7.7 With Your Consent

We may disclose your personal information for any other purpose with your express consent.

7.8 Practitioners and Clinics Using Nureo

Practitioners and clinics use Nureo to run their practices — for example to manage bookings, keep clinical notes, send appointment messages, issue invoices, and (where you consent) view health information you have chosen to share with them. When Nureo holds this information for a practitioner or clinic, the clinic is responsible for that information as the entity that collected it, and Nureo acts as its service provider, handling the information on the clinic's instructions and under this Policy and our agreement with the clinic.

A clinic that moves to Nureo from another practice system may transfer existing client records (such as your name, contact details, and appointment history) into Nureo. The clinic is responsible for having the authority to do so and for telling its clients that their records are now held in Nureo. If you have questions about how a particular clinic uses your information, contact the clinic directly; you can also contact us at privacy@nureo.com.au.

8. Cross-Border Disclosure of Personal Information

Your personal information, including your account information and your health information, is stored on cloud infrastructure provided by Google (Firebase and Google Cloud Platform) located in the Sydney, Australia region (australia-southeast1). This includes your account data, daily check-ins, food logs, goals, progress photos, AI conversation history, and seminar recordings. Our AI health assistant (Nuri) also processes your prompts and health context onshore, using Google's Vertex AI in the same Sydney region.

DATA STORAGE LOCATIONNureo is an Australian company, and your personal information — including your sensitive health information — is stored and processed in Australia. A limited number of third-party service providers operate outside Australia: payment processing is handled by overseas payment providers (such as Stripe); our email marketing platform (Klaviyo) is located in the United States and receives basic contact details (name, email, and account type) of members who have consented to marketing, but never your health information; and live seminar video and audio are delivered by a real-time streaming provider whose network may route traffic through Singapore and other regions (see the Live Seminar Streaming note below). Where information is disclosed to an overseas recipient, we take reasonable steps to ensure it is handled in a manner consistent with the Australian Privacy Principles, and by using the Platform you consent to those limited overseas disclosures.
LIVE SEMINAR STREAMINGWhen you join a live seminar, the live video and audio are carried in real time by our third-party streaming provider's global network and may be routed or processed on servers located outside Australia, including in Singapore and other regions. The short-lived access tokens that authorise you to join a seminar are currently issued by a server function hosted in the United States. The live stream is encrypted in transit and is not retained by Nureo, except where a seminar is recorded — in which case the recording is stored by our cloud storage provider and made available to you within the Platform. We do not control the specific servers through which the live-stream provider routes traffic at any given moment.

Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the overseas recipient does not breach the Australian Privacy Principles in relation to your information. This may include:

Entering into data processing agreements that contractually bind the recipient to APP-equivalent standards.

Transferring to countries assessed as having adequate privacy protections.

Implementing standard contractual clauses or other approved transfer mechanisms.

By using the Platform, you consent to the transfer of your personal information to overseas recipients for the purposes described in this Privacy Policy. Please be aware that if you consent, APP 8.1 will not apply, meaning you will not be able to seek redress under the Privacy Act if the overseas recipient breaches the APPs. However, we will only transfer information to recipients where we have taken the steps described above.

A list of the countries in which our service providers are located is available on request by contacting privacy@nureo.com.au.

9. Quality of Your Personal Information

We take reasonable steps to ensure that the personal information we hold about you is accurate, up-to-date, complete, and relevant for the purposes for which it is held. You are responsible for keeping your account information current. You can update your profile information at any time through the account settings in the Platform.

If you believe that any information we hold about you is inaccurate, incomplete, out-of-date, irrelevant, or misleading, please contact us at privacy@nureo.com.au and we will take reasonable steps to correct it.

10. Security of Your Personal Information

10.1 Security Measures

We take the security of your personal information seriously, particularly given that we hold health information. We implement technical, administrative, and physical safeguards designed to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These measures include:

Encryption of personal data in transit using TLS (Transport Layer Security).

Encryption of personal data at rest, particularly health information and payment tokens.

Passwords stored using industry-standard one-way cryptographic hashing.

Access controls limiting employee and contractor access to personal information on a need-to-know basis.

Regular security assessments and penetration testing.

Secure cloud infrastructure with reputable providers.

Staff training on privacy and data security obligations.

Incident response procedures for data breaches.

10.2 Limitations

While we take all reasonable steps to protect your personal information, no method of electronic transmission or storage is 100% secure. We cannot guarantee the absolute security of your information. You should also take steps to protect your own information, including using a strong, unique password and keeping your device secure.

10.3 Reporting Security Issues

If you become aware of any security vulnerability or incident relating to the Platform, please notify us immediately at privacy@nureo.com.au.

11. Data Retention

We retain your personal information for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our general retention periods are:

Account information: retained for the duration of your account plus 7 years after account closure (to comply with legal and tax obligations).

Health information (check-ins, food scans, goals, progress photos, AI conversations): retained for the duration of your account. Premium users may retain full AI conversation history.

Financial records and transaction data: retained for 7 years from the transaction date, as required by Australian tax law.

Practitioner booking records: retained for 7 years, consistent with healthcare record-keeping obligations.

Clinical records held by a practitioner or clinic (consult notes, prescriptions, pathology, and related financial records): retained for at least 7 years (or, for a minor, until they turn 25) to meet health-records retention law, even if the practitioner closes their Nureo account. These records are kept by the clinic as custodian; if you are a client, you can ask the clinic about access, correction, or deletion of your clinical record.

Security and audit logs: retained for 12 months.

De-identified analytics data: may be retained indefinitely.

After the applicable retention period, we will securely delete or de-identify your personal information. You may request earlier deletion of your personal information where we have no legal obligation to retain it (see clause 12).

12. Your Privacy Rights

12.1 Access to Your Information (APP 12)

You have the right to request access to the personal information we hold about you. To make an access request, please contact us at privacy@nureo.com.au. We will respond to your request within 30 days. We may charge a reasonable fee to cover the cost of providing access, which we will disclose to you before proceeding.

We may decline your access request in limited circumstances permitted by the Privacy Act, such as where access would unreasonably impact the privacy of another individual, where the request is frivolous or vexatious, or where access would be unlawful. We will provide you with written reasons for any refusal.

12.2 Correction of Your Information (APP 13)

If you believe that any personal information we hold about you is inaccurate, incomplete, out-of-date, irrelevant, or misleading, you may request that we correct it. We will take reasonable steps to correct the information within 30 days. If we disagree that the information requires correction, we will explain our reasons and, if requested, attach a statement of correction to the record.

12.3 Deletion of Your Information

You may request the deletion of your personal information by contacting privacy@nureo.com.au or by deleting your account through the Platform's account settings. We will delete your information where we are not legally required to retain it. Some information may be retained for legal compliance purposes as described in clause 11.

12.4 Anonymity and Pseudonymity (APP 2)

Where practicable, you may interact with the Platform without identifying yourself or by using a pseudonym. However, you must be identifiable to use features that require payment or Practitioner engagement.

12.5 Withdrawal of Consent

You may withdraw your consent to the collection of health information at any time by contacting us. Please note that withdrawing consent may limit your ability to use certain features of the Platform that depend on health data, and will not affect the lawfulness of processing carried out before withdrawal.

12.6 Exporting Your Data

You may request an export of your personal data in a machine-readable format by contacting privacy@nureo.com.au. We will endeavour to provide this export within 30 days.

13. Notifiable Data Breaches

The Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth) requires Nureo to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals of any eligible data breach — that is, a data breach that is likely to result in serious harm to any individual whose information is involved.

If we determine that an eligible data breach has occurred, we will:

Notify the OAIC as soon as practicable.

Notify affected individuals whose personal information was involved in the breach.

Provide information about the nature of the breach, the types of information involved, and the steps we recommend to protect yourself.

Take immediate steps to contain the breach and prevent further harm.

Given the sensitive nature of health information held on the Platform, we treat all potential data breaches with the highest priority and have incident response procedures in place to ensure rapid detection, assessment, and response.

14. Cookies and Tracking Technologies

The Nureo mobile application does not use browser cookies. However, we may use similar technologies including device identifiers, session tokens, and analytics SDKs embedded within the app.

These technologies are used to:

Maintain your authenticated session within the app.

Analyse app usage and performance (using de-identified or aggregated data).

Deliver relevant in-app content.

Detect and prevent fraud or security incidents.

You may be able to manage certain tracking permissions through your device's operating system settings (for example, limiting ad tracking on iOS or Android). Note that some of these settings may affect app functionality.

15. Children's Privacy

The Platform is intended for users 18 years of age and older. We do not knowingly collect personal information from children under 13 years of age. If we become aware that we have collected personal information from a child under 13 without parental consent, we will take immediate steps to delete that information and deactivate the associated account.

Users between 13 and 17 years of age may only use the Platform with the verifiable consent and supervision of a parent or legal guardian. If you are a parent or guardian and believe your child has provided personal information without your consent, please contact us immediately at privacy@nureo.com.au.

16. Third-Party Links and Services

The Platform may contain links to third-party websites, apps, and services, including Practitioner booking confirmations linking to external calendars or telehealth platforms. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through the Platform.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email (to the address registered on your Account) and/or by prominent in-app notification, at least 14 days before the changes take effect.

Your continued use of the Platform after the effective date of any amendment constitutes your acceptance of the updated Privacy Policy. If you do not agree to the changes, you should stop using the Platform and, if necessary, close your Account.

Previous versions of this Privacy Policy will be made available on request.

18. Privacy Complaints

18.1 Contact Us First

If you believe that we have breached the Australian Privacy Principles or this Privacy Policy, we encourage you to contact our Privacy Officer first so that we can attempt to resolve your concern promptly:

Email: privacy@nureo.com.au

Subject line: 'Privacy Complaint'

We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If we require more time, we will notify you of the expected timeframe and reason for the extension.

18.2 Office of the Australian Information Commissioner (OAIC)

If you are not satisfied with our response to your complaint, or if we fail to respond within a reasonable time, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

Website: www.oaic.gov.au

Phone: 1300 363 992

Email: enquiries@oaic.gov.au

The OAIC has the power to investigate complaints about alleged breaches of the Privacy Act and may make determinations, including ordering remedial action or the payment of compensation.

19. Contact Us

For any privacy-related queries, access requests, correction requests, or complaints, please contact our Privacy Officer:

Privacy Officer — Nureo Pty Ltd

Email: privacy@nureo.com.au

General support: support@nureo.com.au

Website: www.nureo.com.au

Registered address: 25 South Street, West Wodonga VIC 3690

ABN: 84 696 935 154

We endeavour to respond to all privacy enquiries within 5 business days.

Appendix A: Summary of Australian Privacy Principles Compliance

The following table summarises how Nureo complies with each of the 13 Australian Privacy Principles:

APP 1 — Open and transparent management: This Privacy Policy, published on our Platform and website, transparently describes our privacy practices. We appoint a Privacy Officer to manage compliance.

APP 2 — Anonymity and pseudonymity: Where practicable, users may use a pseudonym. Identification is required for payment and Practitioner booking features only.

APP 3 — Collection of solicited personal information: We collect only information reasonably necessary for our functions. Health information is collected with express consent only.

APP 4 — Dealing with unsolicited information: Where we receive personal information we did not solicit and could not have collected under APP 3, we destroy or de-identify it promptly.

APP 5 — Notification of collection: This Privacy Policy (and in-app notifications where appropriate) notifies you of what information we collect and why, before or at the time of collection.

APP 6 — Use and disclosure: Personal information is used only for the primary purpose of collection, related secondary purposes, or with consent. Health information is not used for advertising.

APP 7 — Direct marketing: Marketing communications are sent only with consent or as permitted by the Spam Act 2003. Opt-out is available on all marketing messages.

APP 8 — Cross-border disclosure: Overseas disclosures are only made where recipients are contractually bound to APP-equivalent standards or where you have consented.

APP 9 — Government-related identifiers: We do not adopt, use, or disclose government-related identifiers (e.g. Tax File Numbers) as our own identifiers.

APP 10 — Quality of personal information: We take reasonable steps to ensure information is accurate, up-to-date, and complete. Users can update their information through account settings.

APP 11 — Security: We implement encryption, access controls, and incident response procedures to protect personal information, particularly sensitive health information.

APP 12 — Access: Users can request access to their personal information within 30 days. Access may be declined in limited lawful circumstances.

APP 13 — Correction: Users can request correction of inaccurate information. We will correct within 30 days or attach a statement if we disagree.