Privacy Policy

Your information, protected

How The Big Pink Physio collects, uses, stores, discloses and protects your personal and health information — and the rights you have over it.

Last updated: [DD Month 2026] · Version 1.0

The Big Pink Physio ("we", "us", "our", "the practice") is committed to protecting your privacy. We are a health service provider, and we take particular care with the sensitive health information you trust us with. This policy explains how we handle your personal information in accordance with Australian privacy law.

1. Who we are

The Big Pink Physio is a physiotherapy practice operating in Sydney, New South Wales, run by an APA Titled Sports & Exercise Physiotherapist registered with the Physiotherapy Board of Australia (AHPRA).

  • Trading name: The Big Pink Physio [/ registered entity name]
  • ABN: [ABN]
  • Address: Fixio Physiotherapy, Suite 29, Building A, The Meriton Lighthouse, 888 Pittwater Road, Dee Why NSW 2099
  • Email: mace@thebigpinkphysio.com.au
  • Phone: 0400 882 643
  • Privacy Officer: [Name / role] — contactable at the email above

2. Laws that apply

We handle your information in accordance with:

  • the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs);
  • the NSW Health Records and Information Privacy Act 2002 (HRIP Act) and the 15 Health Privacy Principles (HPPs), which apply to health service providers in New South Wales; and
  • the Notifiable Data Breaches (NDB) scheme under the Privacy Act.

As a health service provider, the Privacy Act applies to us regardless of our annual turnover.

3. What personal information we collect

The information we collect depends on your interaction with us. It may include:

  • Identity & contact details — name, title, pronouns, date of birth, address, phone, email, and emergency-contact details.
  • Health information (sensitive information) — your medical and physiotherapy history, symptoms, examination findings, diagnoses, treatment and progress notes, imaging and test results, medications, and information relevant to pelvic, sexual, bladder, bowel and gender-affirming care.
  • Administrative & payment information — Medicare number, private health-fund details, DVA details, referral information, and payment records (we do not store full card numbers).
  • Communications — emails, messages, booking details and enquiry information.
  • Website data — see section 12.

4. How we collect it

Wherever practicable, we collect personal information directly from you — through intake forms, consultations, phone, email, or our online booking system. Sometimes we collect information from others with your consent or where the law allows, such as your GP or referring practitioner, other treating health professionals, your private health fund, Medicare, or DVA.

5. Why we collect and use it

We collect, hold and use your information to:

  • assess, plan, provide and manage your physiotherapy care;
  • communicate with you about appointments, results and treatment;
  • liaise with other health professionals involved in your care;
  • process payments, claims and rebates (Medicare, private health, DVA);
  • meet our professional, legal and record-keeping obligations; and
  • manage and improve our services.

We will only use your information for the purpose it was collected, a directly related purpose you would reasonably expect, or where you have consented or the law requires or permits it.

Health information is one of the most sensitive categories of personal information and attracts additional protection under the law. We generally collect it only with your consent, and only where it is reasonably necessary for your care. By providing your health information and receiving treatment from us, you consent to us handling it as described in this policy. You can withdraw or vary your consent at any time by contacting us, though this may affect our ability to provide care.

7. Who we disclose it to

We do not sell your information. We may disclose it to:

  • other health professionals involved in your care (with your consent) — for example your GP, specialists, surgeons or other allied-health providers;
  • Medicare, DVA, or your private health fund for claims and rebates;
  • our service providers who help us operate — such as our practice-management and booking software, secure hosting, IT support, and accounting — who are bound to protect your information;
  • a person responsible for you (for example a carer) where appropriate; and
  • others where required or authorised by law, or to lessen or prevent a serious threat to health or safety.

8. Overseas disclosure

We aim to keep your information in Australia. However, some of our third-party software providers (for example cloud-based practice-management, booking or email services) may store or process data on servers located outside Australia. Where this occurs, we take reasonable steps to ensure those providers protect your information in a manner consistent with the APPs. [List countries / providers here once your software stack is confirmed — e.g. practice-management provider data-hosting location.]

9. Storage & security

We take reasonable steps to protect your information from misuse, interference, loss, and unauthorised access, modification or disclosure. These steps include secure electronic records with access controls and passwords, encryption in transit where available, secure storage of any physical records, staff confidentiality obligations, and reputable software providers with their own security safeguards.

10. How long we keep it

We retain your health records for the minimum periods required by law. In general, adult health records are kept for at least 7 years from the date of last contact. For patients who were under 18, records are kept until the person reaches 25 years of age. When records are no longer required, we destroy or de-identify them securely. [Confirm retention periods against current NSW requirements and your professional indemnity insurer's guidance.]

11. Access & correction

You have the right to request access to the personal and health information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete or misleading. To make a request, contact our Privacy Officer using the details in section 17. We will respond within a reasonable time and may need to verify your identity. In limited circumstances we may decline access as permitted by law — for example where providing access would pose a serious threat to someone's life, health or safety — and if so we will explain why in writing and set out how you can respond.

12. Website, cookies & analytics

When you visit this website, our hosting and analytics tools may automatically collect limited technical information such as your IP address, browser and device type, pages viewed, and the date and time of your visit. This is used to keep the site secure and to understand and improve how it is used. We do not use this information to identify you personally.

Our website may use cookies — small files stored on your device — to help the site function and to gather anonymous usage statistics. You can disable cookies in your browser settings, though some features may not work as intended. [Specify which analytics tool you use — e.g. Google Analytics — and update this section if you add advertising or tracking pixels.]

13. Online booking

Appointments may be booked through our third-party booking and practice-management provider. Information you enter into the booking system is collected and stored by that provider on our behalf and handled in accordance with this policy and the provider's own privacy and security controls. [Name the provider — e.g. Cliniko — and link to its privacy/security information once booking is live.]

14. Data breaches

We have procedures to respond to suspected data breaches. If a breach of your personal information is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme, and take steps to contain and remedy the breach.

15. Complaints

If you believe we have mishandled your personal information or breached your privacy, please tell us first so we can put it right. Contact our Privacy Officer using the details in section 17. We will acknowledge your complaint promptly, investigate, and respond in writing — usually within 30 days.

If you are not satisfied with our response, you can contact:

  • Office of the Australian Information Commissioner (OAIC) — 1300 363 992 · oaic.gov.au
  • Information and Privacy Commission NSW (IPC) — 1800 472 679 · ipc.nsw.gov.au
  • Health Care Complaints Commission NSW (HCCC) — 1800 043 159 · hccc.nsw.gov.au

16. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or the law. The current version is always available on this page, with the "last updated" date shown at the top.

17. Contact us

For any privacy question, request, or complaint, contact our Privacy Officer:

  • The Big Pink Physio — Privacy Officer
  • Email: mace@thebigpinkphysio.com.au
  • Phone: 0400 882 643
  • Post: Fixio Physiotherapy, Suite 29, Building A, The Meriton Lighthouse, 888 Pittwater Road, Dee Why NSW 2099

This policy is provided as a template and general information only, not legal advice. Before publishing, please have it reviewed against your final business details, software stack, and current NSW record-keeping requirements — ideally by a lawyer or your professional-indemnity insurer.