Legal

Privacy Policy

Our commitment to privacy and confidentiality. Current as of 1 January, 2026.

About this Policy

Cygnet Clinic Pty Ltd, ABN: 21 633 929 889 ("we", "us", or "our"), is committed to safeguarding your privacy and upholding your right to control how your personal information is collected, used, and disclosed. As an APP Entity under the Privacy Act 1988 (Cth) ("the Act"), this Privacy Policy aligns with the Australian Privacy Principles (APPs) and outlines how we collect, store, use, and disclose personal and sensitive information. This Policy applies to our website, www.cygnetclinic.com.au (the "Site"), and to the clinical and related services we provide.

Collection of Information

In order to provide services, we may collect: • Personal Information, including name, email address, phone number, and billing details. • Sensitive Information, including health records, referrals, medical history, medication details, and related clinical documentation—with your informed consent. • Some clinicians at Cygnet Clinic may offer the option of using secure medical AI scribing technology to support documentation, and this will always be discussed transparently with clients before use. Any such system is required to comply with all Australian health-service privacy and security requirements. • IP addresses, for no other purpose than compliance with data security. No such information is used by the clinic for any other purpose.

Use and Disclosure of Information

We collect and use personal and sensitive information primarily to deliver and manage our services, including: • Scheduling appointments and maintaining client records • Processing payments and managing billing systems • Corresponding with referring medical professionals (with your consent) We may also share your information with third-party providers essential to our service delivery, such as administrative contractors or IT service providers. Information may also be used for secondary purposes permitted under the Privacy Act, including legal compliance, professional consultations, and internal service evaluations. We do not sell or trade personal information to third parties under any circumstances. With your consent, health information may be disclosed to your GP, specialists, or other healthcare providers where required for the continuation of care, or in emergencies where there is a serious risk to life or health.

Peer Supervision

Under the national health regulator, we are obliged to have peer supervision. Clients' identifying information (such as a name or place of work) has always been substituted by a pseudonym and other such measures to maintain confidentiality. The latest update in December 2025 to AHPRA's Code of Conduct requires a clinician to request consent to discuss your case in peer supervision whilst still maintaining our long-practice of de-identification. Your clinician will now be required to ask your permission to present a case in peer supervision.

Access and Accuracy

You may request access to or correction of the personal information we hold about you at any time. Requests should be directed to us via the contact details listed below. We will respond to access requests within a reasonable timeframe. An administrative fee may be charged if the request involves retrieval from archives or off-site storage. Requests may be declined where permitted by law, such as when information relates to legal proceedings. In such cases, reasons will be provided in writing.

Storage and Security

We implement appropriate technical, physical, and administrative safeguards to protect your personal information from loss, misuse, unauthorised access, or disclosure. These measures include password protection, secure servers, encryption, and SSL protection for our Site. While we take every reasonable precaution, no method of electronic transmission or storage can be completely secure. You transmit data to us at your own risk. Information may be stored electronically, using secure third-party Australian-based data centres, or physically at our clinic or in authorised secure storage facilities.

Data Breach Notification

In the event of a suspected data breach, we will conduct a prompt assessment in accordance with the Notifiable Data Breaches (NDB) Scheme. If the breach is deemed eligible, we will notify affected individuals as soon as practicable. If the breach pertains to the My Health Records Act, we may be required to notify the System Operator under section 73A of that Act.

Cookies & Analytics

To enhance your experience on our Site, we and our service providers may use cookies, web beacons, and similar technologies to monitor user activity and gather site usage statistics. This data may include IP address, browser type, pages viewed, and session duration. If linked to identifiable information, it will be managed in accordance with this Privacy Policy.

Complaints and Enquiries

For any questions, concerns, or complaints regarding your privacy or this policy, please contact us: 1) Use our Feedback Form 2) Email directors@cygnetclinic.com.au 3) Via Mail: Managing Director, Cygnet Clinic, 33/6 Keane Street, Midland, WA 6056 4) Phone: 08 9467 6373 If you are unsatisfied with our response, you may contact the Office of the Australian Information Commissioner by calling 1300 363 992.