Privacy Policy

Effective Date: April 2025

At Downscale, we're committed to protecting your personal and health information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Privacy Policy explains how we collect, use, store, and share your information as a clinical healthcare provider in Australia.

1. Who We Are

Downscale is an Australian telehealth weight loss clinic offering evidence-based care, including medical assessments, pathology reviews, nutritional guidance, and treatment support for individuals aged 12 and up. Our care is provided by qualified Nurse Practitioners and allied health professionals.

2. What We Collect

We collect personal and sensitive health information that may include:

  • Name, address, contact details, date of birth
  • Medicare and private health fund details
  • Medical history, medications, allergies
  • Pathology results and progress notes
  • Lifestyle factors relevant to your treatment
  • Appointment and payment records
  • Communication preferences and consent forms

We collect this information directly from you or with your consent from third parties such as GPs or pathology providers.

3. Clinical Records & Software – Halaxy

We securely store all clinical records using Halaxy, a healthcare platform that complies with Australian privacy legislation, including:

  • Australian Privacy Principles
  • ISO 27001 certification
  • AES-256 encryption
  • Medicare e-Claiming and e-Script functionality

We use secure Australian-based servers to host all data, and only authorised practitioners at Downscale can access your records. All systems comply with Australian privacy regulations and healthcare data protection standards.

4. Why We Collect Your Information

We collect personal information to:

  • Provide safe, personalised medical care
  • Assess your eligibility for treatment
  • Prescribe and send medications via e-script
  • Coordinate referrals and pathology
  • Issue certificates (e.g., medical or work leave)
  • Claim Medicare rebates
  • Communicate with you about your care (e.g., SMS, email)
  • Improve our services (de-identified data only)

5. Consent Before Treatment

Before starting any clinical care, we will ask you to sign a Consent Form, which includes:

  • Agreement to our clinical care model
  • Permission to store and access your health records
  • Consent to communicate with you via phone, SMS, or email
  • Acknowledgment of risks, benefits, and rights

This is a Medicare requirement and ensures informed, safe care. You can withdraw consent at any time.

6. Sharing of Information

We only share your information:

  • With your consent
  • With other treating professionals (e.g. your GP)
  • To send prescriptions or pathology forms
  • When legally required (e.g. court subpoena, public health risk)
  • To process payments (handled via Stripe, which is PCI-compliant)
  • In an emergency, with your nominated contact or emergency services

We never sell or trade your information.

7. Storage, Security & Access

Your records are:

  • Stored securely via Halaxy (encrypted, Australian servers)
  • Protected by multi-factor authentication and strict access controls
  • Never transferred overseas without your written consent

You may request to access or correct your information by contacting us below. We will respond within 30 days as per Australian law.

8. Marketing & Cookies

We may use cookies or analytics tools (e.g., Google Analytics) to improve our website. These do not identify you personally and you can opt-out via your browser settings.

We do not use your clinical data for any marketing purposes unless you've explicitly opted in.

9. Your Rights

You have the right to:

  • Access your health records
  • Correct inaccurate or outdated details
  • Withdraw your consent
  • Make a privacy complaint

To do so, contact our Privacy Officer via the email below.

10. Complaints

If you have concerns about your privacy, contact:

Privacy Officer – Downscale
📧 office@downscale.com.au

We take complaints seriously and aim to resolve them within 30 days.

If unresolved, you can contact:
Office of the Australian Information Commissioner (OAIC)
📞 1300 363 992 | 🌐 www.oaic.gov.au

11. Contact Us

If you have questions about this Privacy Policy or your personal data, please contact:

📧 office@downscale.com.au
📍 Black Health Intelligence Pty Limited (trading as Downscale)
🖥️ www.downscale.com.au