Privacy and information policy

Version 2.0 · Effective 11/09/2026 · Next review 11/09/2027

This policy explains how Wellworx handles personal and health information, your choices, and how to request access or raise a concern. Reading it does not itself provide consent to optional AI, recording or information sharing.

1. Who is responsible

This policy covers personal information handled by Wellworx Pty Ltd, trading as Wellworx Physio (ABN 51 671 354 368), and Jovi Villanueva, trading as Wellworx Workplace Solutions (ABN 22 795 544 254). The business providing your service is identified in your service agreement or invoice. Sharing between these businesses is also subject to the rules below.

Jovi Villanueva is the privacy contact for both services. Phone 0431 092 829; Physio: [email protected]; Workplace Solutions: [email protected]. You can ask for a paper copy or help understanding this policy.

This covers enquiries, physiotherapy, workplace services, billing and complaints. Where Jovi works for another provider, we explain which organisation holds each record and how to contact it. This policy does not replace that organisation's policy. Applicable duties include the Australian Privacy Principles and NSW Health Privacy Principles. Funding-specific requirements depend on the actual service and arrangement.

2. Information we collect and why

  • Contact and identity details, appointment arrangements, support and communication needs, and relevant representative details.
  • Health history, assessments, treatment and exercise plans, referrals, progress, clinical correspondence, and images or recordings where specifically agreed.
  • Funding, claim, invoice and payment details needed to explain costs, bill the agreed payer and process claims.
  • For workplace services: agreed job demands, attendance, training or assessment findings, and relevant worker information. Individual health information remains distinct from an employer's operational records.
  • Your feedback, complaints, access requests and the actions taken in response.

We collect what is reasonably needed to provide and coordinate services, keep clinical records, communicate with you, administer payment, manage concerns and meet legal duties. We normally collect from you. Where collection from a referrer, supporter, employer or other source is appropriate, we check the purpose and authority and explain it to you. We tell you about required information and what could happen if it is not provided. General enquiries may be anonymous where practical; identified care and funding claims usually need identifying details.

3. Choice, representatives and communication

The website form offers optional AI assistance for that enquiry and related draft replies. Without a verifiable opt-in, it remains available for handling without AI. This enquiry choice does not authorise clinical AI or recording.

Consent to treatment, optional AI use, recording, clinical photography and public use of images are separate choices. We explain the particular purpose, information, recipients and options before asking for consent. A carer, family member or employer is not automatically authorised to consent or receive records. We check the person's authority for the decision being made.

You may change an optional choice by contacting Jovi. We record the change and agree how future work will be handled. It does not undo earlier lawful processing or remove records that must be kept. Tell us your preferred safe contact method and whether anyone else may receive information. Email and SMS can be misdirected or accessed by others; we discuss a suitable alternative for sensitive material.

4. When information may be shared

We share necessary information for the purpose for which it was collected, a directly related purpose you would reasonably expect where the law allows, your specific consent, or another identified legal permission or requirement. We document the basis where needed. A serious-threat exception is not a general permission to share; its legal conditions must be met.

  • Your GP or other treating practitioners for relevant care coordination.
  • The agreed payer, care provider, insurer, Medicare, DVA, NDIS or health fund for the particular service, claim or reporting purpose.
  • An authorised representative after checking the scope of their authority.
  • Service providers supporting the functions described below, subject to appropriate privacy assessment.
  • Regulators, courts or other recipients where the law requires or permits it, and professional advisers or insurers where an appropriate basis exists.

For OCC services we explain what the employer commissioned, what information the employer will receive, and the named recipients. Paying for a service does not give an employer unrestricted access to a worker's clinical notes, diagnosis, recordings or identifiable feedback. Wellworx does not rely on a client employer's employee-records exemption as a blanket exemption for its own handling.

5. Digital services and overseas processing

Our current tools include local clinical files and databases, email and calendar services, online enquiries, cloud backups, administrative alerts and AI-assisted work. Information handled by a cloud provider can be processed or accessed outside Australia. The following explains the known uses; some account-specific storage, retention and processing locations have not yet been confirmed. No Australia-only or zero-retention assurance is made.

ServiceInformation and purposeLocation or current limit
Local clinical systemClinical files, forms, reports and billing on the practice Mac.Australia; FileVault was on when checked on 11/09/2026.
Google Gmail and CalendarEnquiries, correspondence, attachments and appointment details. Google Analytics is also present on the public websites.Google describes global processing. Actual account region and analytics configuration remain to be verified.
Apple iCloud and Voice MemosClinical backups and recordings/sync where enabled.International processing is possible. The account's Advanced Data Protection setting has not been verified.
FormspreePublic website enquiry fields and messages, then delivery to the practice inbox.AWS hosting in the United States. Please keep detailed health information out of the general enquiry form.
Anthropic Claude; OpenAI where selectedInformation supplied for clinical or administrative drafts, and relevant connected-service content.United States and other provider processing locations. The product, account controls and locations for a particular optional use must be explained before that use.
Telegram administrative alertsAdministrative notifications. New website-enquiry and patient-email alerts exclude names, contact details and message content; other operational uses require their own information-sharing assessment.Cloud messages are stored by Telegram. Australian storage or end-to-end protection for bot alerts has not been established.
Website and workflow infrastructureCloudflare hosts the public sites. Selected workflow/CRM information can also enter repository and remote-server synchronisation.International processing may occur. A complete account-specific location list has not yet been confirmed; no Australia-only promise is made.

Before overseas processing, we assess the applicable Australian and NSW transfer requirements, provider terms, necessary information and available safeguards. A privacy-policy acknowledgement is not a waiver of these duties. A request to limit a tool must be checked against every relevant automated route, including incoming-email handling.

6. AI-assisted work

Model-improvement settings for the checked Claude and ChatGPT/Codex accounts were off on 11/09/2026. This does not remove provider retention, legal or safety exceptions, or replace the consent and overseas-processing checks for a particular use.

AI is used to help organise information, classify incoming correspondence and prepare drafts of notes, assessments, plans and letters. These drafts may include suggested clinical reasoning. Jovi remains responsible for clinical decisions and must review the content before relying on it or issuing a final clinical document. Draft generation and storage can happen before this review.

Information supplied to an AI service can identify you. Removing a name alone does not necessarily make a clinical history anonymous. Our documentation workflows can include a patient name, transcript, condition and earlier notes. We must assess and limit what is sent for the particular task.

Provider retention and use of content depend on the product, account controls and terms, including legal or safety exceptions. We do not promise zero retention or that information can never be used for model improvement. The specific provider and arrangements must be explained before optional processing. You can request manual clinical documentation and correspondence; the choice must be recorded and applied before optional processing. The clinical-note, GP-letter, AHTR-report and clinical-report tools, and the patient-email classifier, require a verifiable recorded AI choice; otherwise they return to manual handling.

7. Recordings and clinical images

If a consultation is recorded, the purpose, participants, processing services and retention are explained first and separate express agreement is obtained from the relevant participants. You can ask for recording to pause or stop. Clinician dictation after a visit may also contain your health information and is handled as such.

The voice-note workflow transcribes on the Mac, can send the transcript and clinical context to a cloud AI service, and archives source audio after a draft is applied. It does not establish immediate deletion after verification. Clinical images and recordings are not approved for publicity by agreeing to clinical use.

We assess whether recordings and working material form part of the health record and apply the appropriate retention requirements. We do not promise automatic deletion after transcription. Any shorter retention for temporary material needs a documented lawful basis and a checked deletion process covering relevant copies and backups.

8. Storage, access and retention

We are responsible for reasonable safeguards against loss, misuse and unauthorised access. These include limiting access to authorised people and services, device and account protection, suitable transfer methods and backups. Access must be limited to the work a person or service is authorised to perform. Jovi owns the access review and breach response. Paper records require secure handling under the same confidentiality rules. This policy does not claim that every account has the same security or storage settings.

Health information collected when a person was an adult is retained for at least seven years after the last health service. Information collected when the person was under 18 is retained until at least age 25. Other legal, funding or preservation duties may require longer retention. We record and review any hold for a complaint or legal matter rather than automatically keeping every such file forever.

When information may lawfully be disposed of and is no longer needed, we arrange secure disposal and record the required details. Copies, working files and backups are considered in the retention plan. A rolling seven-day backup cycle is a recovery arrangement, not permission to delete the underlying health record.

9. Access, correction and complaints

Contact Jovi to request access or a correction. We check identity and any representative's authority without collecting unnecessary information. Our service target is a response within 30 calendar days. NSW private health-provider requests must be handled within the applicable 45-calendar-day response period. A refusal or partial refusal must have a lawful basis and written reasons and review options. We discuss reasonable access charges in advance; making a correction request, correcting information or attaching a statement of disagreement is free. If a correction is refused, you may ask to attach a statement of disagreement.

You may complain by phone, email or in person. The complaints policy sets out the process. You can seek advice from the IPC NSW on 1800 472 679 or the OAIC on 1300 363 992. The OAIC generally expects a complaint to the organisation first and about 30 days to respond. HCCC can assist with NSW health-service complaints, including where approaching the provider is inappropriate or uncomfortable. External bodies apply their own requirements and time limits.

10. Breaches and policy review

If a suspected breach occurs, Jovi coordinates containment, preservation of evidence, assessment and corrective action. We assess a suspected eligible breach promptly and take all reasonable steps to complete that assessment within 30 days. Where the Commonwealth notification threshold is met, we notify the OAIC and affected people as soon as practicable. Other applicable reporting and provider-contract duties are assessed separately.

The NSW public-sector mandatory notification scheme is not treated as an automatic extra reporting duty for every private health provider. My Health Record reporting is considered separately if that system is involved. This policy is reviewed annually and when a material service, technology or legal change occurs. This version takes effect on 11/09/2026 and is due for review by 11/09/2027, or sooner after a material change.

More information