Privacy Policy
How Django Health Pty Ltd collects, holds, uses and discloses personal information and health information, under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. About this policy
Django Health Pty Ltd ("Django Health", "we", "us" or "our") is an Australian proprietary company based in Victoria. We are committed to protecting the privacy of the people whose information we handle, and we manage personal information in accordance with the Privacy Act 1988 (Cth) (the Privacy Act) and the Australian Privacy Principles (APPs) contained in that Act.
This policy explains what information we collect, why we collect it, how we hold it, who we disclose it to, and how you can access it, correct it or complain about how we have handled it. It applies to visitors to this website, to people who contact us, to representatives of the organisations we work with, and to participants in programmes we coordinate.
Where we coordinate a programme on behalf of another organisation, that organisation may also have its own privacy policy governing the information it holds. This policy covers information held by Django Health.
2. Information we collect
We only collect personal information that is reasonably necessary for our functions and activities. Depending on your relationship with us, this may include:
- your name, job title and the organisation you represent;
- contact details, including email address, postal address and telephone number where you provide one;
- the content of enquiries, correspondence and meeting notes;
- information needed to plan, schedule and coordinate a programme, such as availability, location, accessibility requirements and consent records;
- participation and attendance records for programmes we coordinate;
- billing and payment information for organisations that engage us;
- technical information about your visit to this website, as described in section 7.
You are not obliged to identify yourself when making a general enquiry, but if you do not provide the information we ask for, we may be unable to respond usefully or to deliver the service requested.
3. Sensitive and health information
Health information is a category of sensitive information under the Privacy Act and attracts additional protection. Because we coordinate health and wellbeing programmes, we may need to handle limited health information about participants — for example, accessibility needs, referral details, or information a participant provides so that appropriate arrangements can be made.
We collect sensitive information only where it is reasonably necessary for our activities and where you have consented to that collection, or where the collection is otherwise required or authorised by law. We collect the minimum amount required for the purpose.
Django Health does not provide clinical treatment. Clinical records created by treating practitioners and services remain with those practitioners and services and are governed by their own privacy obligations, not by this policy.
4. How we collect it
We collect personal information directly from you wherever it is reasonable and practicable to do so — when you email us, complete the enquiry form on this website, speak with us, or take part in a programme we coordinate.
Sometimes we collect information about you from another party, such as the organisation that has engaged us to run a programme, or a service provider making a referral. Where we do, we take reasonable steps to make sure you are aware of the matters set out in APP 5, including who we are, why the information was collected and how to reach us.
5. Why we use and disclose it
We use and disclose personal information for the purpose for which it was collected, for directly related purposes you would reasonably expect, or where you have consented, or where the use or disclosure is required or authorised by law. In practice, this means:
- responding to your enquiry and providing you with information you have asked for;
- planning, scheduling and coordinating a programme, including arranging appointments and referrals with the providers involved;
- preparing participation records and outcome reports for the organisation that engaged us;
- administering our engagement, including quoting, invoicing and record-keeping;
- improving the way we deliver and coordinate our services;
- meeting our legal, insurance and regulatory obligations.
Reports we prepare for an engaging organisation are provided in aggregate or de-identified form wherever the purpose of the report can be met that way.
We do not sell personal information, and we do not disclose personal information to third parties for their own direct marketing purposes.
6. Third parties and overseas disclosure
We may disclose personal information to:
- the health, allied health and community service providers involved in delivering a programme, where disclosure is necessary to arrange or deliver that service;
- the organisation that has engaged us, in accordance with section 5;
- our professional advisers, including accountants, insurers and lawyers;
- service providers who support our operations, such as email, document storage and website hosting providers, bound by confidentiality obligations;
- a person or body to whom we are required or authorised by law to disclose the information.
Some of the technology providers we rely on for email, file storage and website hosting may store data on servers located outside Australia. Before disclosing personal information to an overseas recipient, we take steps reasonable in the circumstances, as required by APP 8, to ensure the recipient does not breach the Australian Privacy Principles in relation to that information.
7. Cookies and this website
This website is a static site. It does not set advertising cookies, does not run third-party analytics or tracking scripts, and does not embed content from external services.
Our hosting provider records standard technical information as part of serving and securing the site, which may include your IP address, browser type, the pages requested and the date and time of the request. This information is used to operate and protect the website and is not used to build a profile of you.
The enquiry form on our contact page opens your own email application and sends the message from your email account. Anything you write in it reaches us as an ordinary email and is handled as described in this policy.
Most browsers let you refuse or delete cookies through their settings. Because this site does not rely on cookies, doing so will not affect how it works.
8. Security, quality and retention
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Those steps include restricting access to information to the people who need it, using access-controlled systems and accounts, and applying confidentiality obligations to the people who work with us.
We also take reasonable steps to ensure that the personal information we collect, use and disclose is accurate, up to date, complete and relevant. Please tell us if your details change or if anything we hold about you is wrong.
We retain personal information only for as long as it is needed for the purposes described in this policy, or for as long as we are required to keep it under Australian law — including record-keeping obligations under taxation, corporations and other legislation. When information is no longer needed and we are not required to retain it, we take reasonable steps to destroy it or to ensure it is de-identified.
If an eligible data breach occurs, we will respond in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner where required.
9. Access, correction and your rights
Under APP 12 and APP 13, you may:
- ask us to confirm what personal information we hold about you;
- request access to that information;
- ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading;
- ask us to explain how we handle your information;
- ask to deal with us anonymously or under a pseudonym, where that is lawful and practicable;
- withdraw a consent you have previously given, which may affect our ability to continue providing a service.
To make a request, email [email protected]. We will need to verify your identity before acting on it. We aim to respond within 30 days. Access is generally provided free of charge, though we may charge a reasonable fee for the cost of retrieving and supplying information in some cases. If we refuse access or correction, we will tell you why in writing and explain how to complain.
10. Complaints and contact
If you believe we have breached the Australian Privacy Principles or otherwise mishandled your personal information, please contact us first so we can try to put it right:
- Django Health Pty Ltd (ABN 91 701 311 480, ACN 701 311 480)
- Email: [email protected]
- Victoria (VIC) 3551, Australia
We will acknowledge your complaint, investigate it, and respond in writing with the outcome, ordinarily within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC), which is the independent regulator for privacy in Australia. The OAIC can be contacted at oaic.gov.au or on 1300 363 992.
We may update this policy from time to time. The current version is always published on this page with the date it was last updated.
A question about your information?
Privacy enquiries, access requests and complaints all go to the same address and are answered in writing.