Privacy Policy
This Privacy Policy explains how Back in My Body Therapies (“we”, “our”, “us”) collects, uses and protects your personal information. We are committed to respecting your privacy and complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using our website or services, you consent to the information practices outlined in this policy.
Types of Personal Information We Collect
We may collect:
your name, contact details, date of birth and emergency contact information
health and wellbeing information, including disability, sexual health, and psychosocial information relevant to therapy
Medicare, NDIS, NIISQ or other funding/referral details relevant to your service
payment and billing information
information provided in forms, referrals, emails, phone calls, telehealth sessions or in-person appointments
session recordings or AI-generated transcriptions/notes, where you have consented to their use
usage data relating to our website or booking platforms
any other information you choose to provide, or that is provided by a third party with your consent (such as a referring GP, support coordinator, or family member).
How We Collect Personal Information
We collect personal information through:
direct interactions during sessions, telehealth, forms, or phone/email contact
referrals from GPs, health professionals, agencies, or authorised representatives (e.g. NDIS support coordinators)
our website, online booking and practice management platforms, and payment processors
surveys, feedback or administrative records.
How We Use Personal Information
We use your personal information to:
deliver occupational therapy and sexuality services, including clinical assessment, treatment planning and reporting
contact you and manage appointments
keep accurate clinical and administrative records
process invoicing, billing, Medicare Better Access claims, and NDIS/NIISQ funding claims
communicate with other professionals or supports directly involved in your care, with your consent
meet legal, regulatory and professional (AHPRA, Medicare, NDIS Commission) obligations
improve our website, services and client resources.
Our Practice Management System (Splose)
We use Splose as our practice management platform to store client records, session notes, appointment and billing information. For Australian clients, Splose stores data within Australia on secure AWS infrastructure, encrypted using AES-256 at rest and TLS 1.2+ in transit. Splose is built to support compliance with the Australian Privacy Principles. Access within Splose is restricted to authorised practice staff - Lauren Cummings.
AI-Assisted Documentation
We may use AI-assisted transcription or note-writing tools (Splose's built-in AI features) to support clinical documentation. Where AI tools are used:
we will seek your consent before using AI to process information from your session, and you may withdraw that consent at any time
AI-generated notes are reviewed by your practitioner for accuracy before being relied upon
our AI providers operate under contractual data protection terms (including, where applicable, zero data retention and no use of your data for model training)
you may request that AI-assisted tools not be used in your sessions.
Disclosure of Personal Information
We do not sell or rent your personal information. We may disclose it to:
Splose and other IT, booking, or payment-processing providers who support our practice
other health professionals or supports directly involved in your care, with your consent
Medicare, NDIS Quality and Safeguards Commission, NIISQ, or other regulatory/funding bodies as required
regulatory authorities, insurers or legal representatives where required by law
emergency services where there is an immediate risk of harm to you or others.
Where any service we use stores information overseas (for example, some payment or analytics providers), we take reasonable steps to ensure that recipient handles your information consistently with the APPs before disclosure occurs.
Sensitive Information
We recognise that health, disability, and sexual wellbeing information is sensitive. We only collect it with your consent, and only use or disclose it for the purpose it was collected, or as otherwise authorised or required by law. You are never obligated to disclose more than is clinically necessary.
Data Breach Response
We maintain a data breach response process. If we become aware of an eligible data breach that is likely to result in serious harm, we will assess it promptly, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable, and take reasonable steps to contain and remediate the breach.
Your Rights and Choices
You have the right to:
request access to the personal information we hold about you
ask for corrections or updates if information is inaccurate or incomplete
restrict or withdraw consent for sharing (unless legally required)
withdraw consent for AI-assisted documentation specifically, at any time
opt out of non-essential communications at any time
make a complaint if you believe your privacy has been breached, including to the OAIC if a matter is not resolved with us directly.
Requests should be made in writing to the contact details below. A reasonable administration fee may apply for extensive access requests.
Storage and Security
We take reasonable technical and organisational steps to protect your personal information from misuse, loss or unauthorised access — including secure electronic systems, encryption, restricted access permissions, confidentiality obligations on privacy practices. While we take these steps seriously, no electronic transmission (including email and telehealth) is completely risk-free.
Website and Cookies
Our website may use cookies and analytics tools (such as Google Analytics) to understand usage and improve user experience. Where required, we will seek your active consent (via a cookie preference banner) before non-essential cookies are set, and you can manage or withdraw this consent through your browser or our cookie settings at any time. Disabling cookies may affect some website functionality.
Changes to This Policy
We may update this Privacy Policy to reflect changes in legislation, technology, or our services. The current version will always be available on our website.
For any questions or notices, please contact us at:
Back in My Body Therapies ABN 12 097 312 642
Email: Lauren@backinmybodytherapies.com.au
Last update: September 2026

