2+ million treatments delivered
Simple Online Healthcare Pty Ltd, trading as ‘Simple Online Doctor’, is committed to protecting your privacy.
Simple Online Healthcare Pty Ltd, trading as ‘Simple Online Doctor’ (“we”/ “us” / “our”), is registered in Australia with the company number 610 046 663.
This Privacy Policy outlines how we collect, use, store, and disclose your personal information in compliance with the Privacy Act 1988 (Cth) (Privacy Act), including the Australian Privacy Principles (APPs) and any relevant privacy code registered under the Privacy Act. It applies to all personal information you provide to us through our website, online medical consultations, and related services. We aim to manage your information openly and transparently so you can feel confident that your privacy is protected.
We only collect information that is reasonably necessary to provide our telehealth services. The types of personal information we may collect include:
We collect personal information directly from you in several ways, including:
We will generally collect personal information directly from you. If we ever need to collect information from someone else (for example, obtaining a specialist report or past medical record with your consent), we will only do so with your consent or as required by law.
Simple Online Doctor collects and uses your personal information only for legitimate purposes connected with our healthcare services. These purposes include:
We will only use or disclose your personal information for the purposes explained in this policy, for purposes that you would reasonably expect, or if required/permitted by law. If we ever need to use your information for a new purpose not covered here, we will seek your consent first (unless an exception under privacy law applies).
We do not sell your personal information. However, in the course of providing our services, we may disclose some of your personal information to third parties for the purposes outlined above. These third parties may include:
In all cases of third-party sharing, we only disclose what is necessary for that service or requirement. Wherever feasible, we will inform you about the disclosure or obtain your consent (for instance, when referring you to another provider). All third parties we engage are required to handle your personal information in accordance with privacy law and our guidelines. If any service provider is located overseas or stores data overseas, we will inform you and take steps to ensure your information receives equivalent protection (in line with APP 8 on cross-border disclosure). (At present, our primary data storage and processing occur in Australia.)
We take reasonable steps to protect the personal information we hold from misuse, interference, loss, and unauthorized access, modification, or disclosure (in compliance with APP 11 – Security of personal information).
Personal information is stored in secure electronic systems with encryption. Our website and online platforms use HTTPS (SSL/TLS encryption) to protect data transmitted between your device and our servers.
We restrict access to personal records to authorized personnel only. Only staff members and our registered doctors who need to see your information (for example, the doctor treating you or the support staff processing your booking) are permitted to access it. Each employee or contractor is bound by strict confidentiality obligations.
Our internal systems are protected by strong passwords and, where possible, multi-factor authentication to prevent unauthorized logins. Users of our service should also maintain the confidentiality of their own account password and notify us immediately of any unauthorized use.
We use reputable cloud hosting with adequate security protocols or secure physical servers located in controlled facilities. Regular backups are performed to prevent data loss, and those backups are secured as well. Physical documents (if any) are kept in locked cabinets with limited access.
We regularly update and patch our software to address security vulnerabilities. Security audits and monitoring are conducted to detect and respond to any unusual activity. Our team is trained on privacy obligations and security procedures to ensure your information is handled safely.
Despite our best efforts, no method of electronic storage or transmission over the internet is 100% secure. However, we continuously review and enhance our security practices to mitigate risks. If we ever experience a data breach that is likely to result in serious harm, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches scheme under Australian law.
We will retain your personal information only for as long as it is needed to fulfill the purposes for which it was collected or as required by law or professional standards.
We will keep your health information for as long as necessary to continue providing you services and to comply with legal obligations. For example, we may retain adult patient records for at least 7 years from the date of the last service and, in the case of a minor, until the child turns 25. We retain records to ensure continuity of care and for medico-legal purposes.
Contact information and other personal details will be kept while your account is active or as long as needed for our business operations. If you cease using our services, we may keep certain information for our records (for example, invoices or consents) to comply with taxation, auditing, and regulatory requirements.
We do not store full credit card numbers on our systems (these are handled by the payment gateway). Any payment transaction records we keep (e.g., receipts or transaction IDs) are retained according to financial record-keeping laws (often 7 years).
When personal information is no longer required for the purpose it was collected (and we are not legally required to retain it), we will take reasonable steps to destroy it or permanently de-identify it. For instance, if you close your account and request deletion of your identity documents on file, and we have no further legal need to keep them, we will securely delete those documents.
Please note that due to healthcare regulations, we cannot always accommodate immediate deletion of medical records upon request, especially if those records are needed to provide you (or future practitioners) with a complete medical history or if we must retain them by law. However, once the mandatory retention period ends, we will securely dispose of the information.
We will also respect any withdrawal of consent to use information for optional purposes (like marketing) by updating our records and practices accordingly.
You have the right to access the personal information we hold about you and to request corrections if you believe it is inaccurate, out-of-date, or incomplete. We are committed to responding to such requests in accordance with APPs 12 and 13.
You may request access to your information (including health records) at any time by contacting us using the details in the Contact section below. We will need to verify your identity before granting access. We will promptly provide you with your information, usually within 30 days. In some cases, we may provide access by giving you a summary of the information or facilitating an electronic record download. There is generally no fee for requesting access; however, if your request is complex and incurs significant staff time or resources, we might charge a reasonable cost-recovery fee (we will let you know in advance if a fee applies).
If you think any personal information we hold about you is incorrect or incomplete, please let us know. You can request that we correct or update your details. We will take reasonable steps to amend your records accordingly. If, for some reason, we cannot accommodate a correction (for example, if we disagree that the information is incorrect), we will let you know why and, at your request, note on your record that you sought a correction.
We always strive to maintain accurate, up-to-date information. For some changes (like updating your contact details), you may be able to log into your account and make the edits directly. For other changes (like amending a medical note), please contact us, and we will assist.
We take your privacy seriously, and we welcome questions or feedback about our privacy practices. If you have any concerns or believe your privacy has been compromised, please let us know so we can address the issue.
For any privacy-related inquiries or complaints, you can contact us at:
Email: [email protected]
Address:
119 Racecourse Road
Ascot
4007
Queensland
Australia
Phone: (07) 4839 7994
Please provide details about your question or complaint so we can respond effectively. We will acknowledge your query or complaint within a reasonable time (usually within 5 business days) and let you know the next steps. For complaints, we will investigate the matter and aim to provide you with a written response outlining the outcome and any actions we will take to resolve your concern.
If a privacy complaint is made, we will work with you to resolve it. This may involve clarifying the issue with you, investigating internally, and updating our procedures if necessary. We aim to resolve all complaints promptly and fairly, typically within 30 days. If we need more time (for example, if the matter is complex), we will keep you informed of the progress.
If you are not satisfied with our response, or if you prefer not to raise the matter with us, you have the right to contact the Office of the Australian Information Commissioner (OAIC). You can lodge a complaint with the OAIC after you have attempted to resolve it with us:
Office of the Australian Information Commissioner
By post: GPO Box 5218, Sydney NSW 2001, Australia
Website: https://www.oaic.gov.au
Phone: 1300 363 992
We value your trust and will do everything we can to address your concerns and improve our practices. Your feedback on privacy matters is welcome and helps us ensure we meet our obligations.
Our privacy practices are designed to comply with the Australian Privacy Act 1988 and the 13 Australian Privacy Principles. In summary:
By using our services, you consent to the collection and handling of your personal information as described in this policy. We encourage you to read this policy carefully and contact us if you have any questions.
Last updated: 07 April 2005 - This policy will be reviewed periodically and updated as necessary to ensure compliance with Australian privacy laws and our commitment to protecting your information. Any changes will be posted on this page and if significant, we may notify you through email or via our website.