Privacy Policy
Last updated: September 2026
1. About this policy
This Privacy Policy explains how Connected Wellness Pty Ltd (ABN 11 612 504 373), trading as me&my wellness ("we", "us", "our"), collects, uses, stores and shares your personal information, including your health information.
Your health is personal, and so is the information you share with us about it. We treat it with care and handle it in line with:
- the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs);
- the Health Records and Information Privacy Act 2002 (NSW) and its Health Privacy Principles, because we provide health services in New South Wales;
- the NDIS Code of Conduct and NDIS Practice Standards, when we support NDIS participants; and
- the Spam Act 2003 (Cth) for our emails and other electronic messages.
This policy applies to our clinical nutrition and lifestyle medicine consultations, NDIS services, supplement and product sales, corporate wellbeing programs, website, newsletters, webinars, workshops and podcasts.
2. The information we collect
Personal and contact information
Your name, date of birth, gender, address, email, phone number, emergency contact, and how you heard about us.
Health information
If you consult with us, we collect health information so we can provide safe, personalised care. This may include your medical and family history, current conditions and symptoms, medications and supplements, allergies and intolerances, pathology and other test results, body measurements, diet, sleep, activity and lifestyle habits, your health goals, and the details of your GP or other treating practitioners. Health information is "sensitive information" under privacy law. We only collect it with your consent and when it is reasonably necessary for the services we provide you.
NDIS information
If you are an NDIS participant, we may collect your NDIS number, relevant plan details and goals, how your plan is managed, and the contact details of your plan manager, support coordinator, nominee or guardian.
Orders and payments
If you buy supplements, products or services, we collect order, delivery and billing details. Card payments are processed by our payment providers, and we do not store your full card details.
Corporate programs
If you take part in a workshop, webinar or wellbeing program through your employer, we may collect your name, work email, attendance and any feedback or survey responses you choose to give.
Website, email and online activity
When you visit our website, open our emails or interact with our ads, we collect information such as your IP address, browser and device type, pages viewed, links clicked and referring site. This is collected through cookies and similar technologies (see section 10).
Recordings and content
If you appear as a guest on our podcast, attend a recorded webinar or take part in a workshop, we may collect your image, voice and contributions. We will always tell you before a session is recorded. For how we use AI transcription and note-taking in consultations, see section 9.
3. How we collect it
Most of the time we collect information directly from you: through our website forms and booking system, intake questionnaires, consultations (in person or by telehealth), email, phone and social media messages.
With your consent, or where the law allows, we may also collect information from:
- your GP, specialists, allied health practitioners or pathology providers;
- your NDIS plan manager, support coordinator, nominee or guardian; and
- your employer, if you join a corporate program (usually just your name and work contact details).
Dealing with us anonymously. You can make general enquiries, read our content or attend some public events without identifying yourself, or by using a pseudonym. We cannot provide clinical consultations, NDIS services or product orders anonymously, because we need to know who you are to care for you safely and to meet our legal obligations.
If we receive personal information we didn't ask for and don't need, we will destroy or de-identify it where it is lawful and reasonable to do so.
4. How we use your information
We use your personal information to:
- assess your needs and provide nutrition, lifestyle medicine and wellbeing services;
- recommend, supply and deliver supplements and products, including practitioner-only products;
- deliver NDIS supports, including service agreements, progress reports and invoicing;
- manage bookings, reminders, invoices and payments;
- communicate with you and with other practitioners involved in your care (with your consent);
- run and improve our programs, website and services;
- send you newsletters and information about our services, where you have agreed (see section 5); and
- meet our legal, professional, insurance and regulatory obligations.
Educational content. We create articles, podcasts, webinars and teaching resources. We will never identify you, or share details that could identify you, in this content without your written consent. Any client examples we use are de-identified.
5. Marketing and newsletters
We will only send you marketing emails or SMS messages if you have agreed to receive them or if the law otherwise allows it. Every message includes an easy way to unsubscribe, and you can also opt out by contacting us. We never use your health information for marketing without your express consent, and we never sell your personal information.
6. Who we share it with
We only share your information when it is needed for the purposes above, with your consent, or when the law requires or allows it. This may include:
- Your healthcare team: your GP, specialists or other practitioners, with your consent.
- Pathology providers: when we request tests on your behalf.
- Supplement suppliers and dispensaries: the details needed to fill a practitioner-only or dispensed product order.
- NDIS parties: your plan manager, support coordinator, the NDIA or the NDIS Quality and Safeguards Commission, as needed to deliver and claim for your supports or where the NDIS rules require it.
- Employers (corporate programs): only attendance numbers and de-identified or aggregated feedback. We do not share your individual health information with your employer unless you give us written consent.
- Service providers who help run our business: for example our website and customer relationship platform (HubSpot), accounting and invoicing (Xero), email and file storage (Google Workspace and/or Microsoft 365), video and telehealth (Zoom), recording and podcast production (Riverside), AI transcription and note-taking (Fireflies.ai), payment processors and couriers. These providers may only use your information to provide their services to us.
- Professional advisers and insurers: for example our accountant, lawyer or professional indemnity insurer, where needed.
- Where required or authorised by law: for example to lessen or prevent a serious threat to someone's life, health or safety, to respond to a court order or subpoena, or to report incidents under NDIS rules.
7. Overseas storage and disclosure
Some of the service providers we use store or process data outside Australia, including in the United States and other countries where they or their subcontractors operate. For example, our AI transcription provider, Fireflies.ai, stores and processes consultation recordings and transcripts in the United States. Before we use a provider, we take reasonable steps to make sure it protects personal information to a standard consistent with Australian privacy law, for example by reviewing its security and privacy commitments.
8. How we store and protect it
We store information electronically in secure, password-protected systems. We use technical and organisational safeguards to protect it, including:
- multi-factor authentication;
- encryption provided by our platforms;
- limiting access to people who need it; and
- confidentiality obligations for anyone who works with us.
Any paper records are kept securely and destroyed securely once they are no longer needed.
How long we keep it. In line with NSW law, we keep health records for at least seven years after your last consultation. If you were under 18 when we collected them, we keep them until you turn 25, whichever is later. NDIS records are kept for at least seven years. When information is no longer needed and we are not required to keep it, we securely destroy or de-identify it.
Data breaches. If a data breach is likely to cause serious harm to you, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.
9. Technology, AI and automated decisions
AI transcription and note-taking in consultations. With your consent, we use Fireflies.ai, an AI transcription and note-taking tool, during consultations, in person or by telehealth. It helps us keep accurate clinical notes so we can give you our full attention. Fireflies records the audio of your consultation and processes the health information you discuss to produce a transcript and summary. We will ask for your consent before using it. You can say no, or change your mind at any time, and this will not affect your care. Your practitioner reviews and finalises every note. The finalised note becomes part of your health record and is kept as described in section 8.
Fireflies stores data in the United States (see section 7) and encrypts it both in transit and at rest. Fireflies states that it does not use customer data to train AI models, and that its AI providers are contractually prohibited from storing or training on that data. You can read more in the Fireflies security overview.
Other uses of AI. We may also use AI-assisted tools for administrative work such as scheduling, drafting and summarising.
Automated decisions. We do not make decisions that significantly affect your rights or interests using computer programs alone. Every clinical assessment and recommendation is made by a qualified practitioner.
10. Cookies and analytics
Our website uses cookies and similar technologies to make the site work, remember your preferences, understand how visitors use the site, and measure and improve our marketing. These include HubSpot analytics and tracking cookies, and may include advertising tools from platforms such as Meta (Facebook and Instagram) and Google.
You can accept or decline non-essential cookies using our cookie banner, and you can block or delete cookies in your browser settings. Some parts of the site may not work properly without cookies.
11. Accessing and correcting your information
You can ask for access to the personal and health information we hold about you, or ask us to correct it if it is inaccurate, out of date, incomplete or misleading. Please contact our Privacy Officer (section 13). We will respond within 30 days.
It is free to make a request. We may charge a reasonable fee for the cost of providing copies, and we will tell you about any fee before we proceed. In limited situations the law allows us to refuse access, for example if giving access would pose a serious threat to someone's health or safety. If that happens, we will explain why in writing and tell you how to complain.
12. Children and people who need support
If a client is under 18, we usually collect information from, and seek consent from, a parent or guardian. A young person who is able to make their own decisions may consent on their own behalf. For NDIS participants and other clients who need support, we work with their nominee, guardian or chosen support person, while respecting the person's own choices as far as possible.
13. Questions and complaints
If you have a question about privacy or think we have mishandled your information, please contact our Privacy Officer:
Privacy Officer: Anthony Hartcher
Connected Wellness Pty Ltd, trading as me&my wellness
Email: info@meandmywellness.com.au
Phone: (02) 9909 6764
Post: 14 Chatham Street, Randwick NSW 2031
We will acknowledge your complaint within 7 days and aim to resolve it within 30 days. If you are not satisfied with our response, you can contact:
- Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au, 1300 363 992
- NSW Information and Privacy Commission (health information): www.ipc.nsw.gov.au, 1800 472 679
- NDIS Quality and Safeguards Commission (NDIS participants): www.ndiscommission.gov.au, 1800 035 544
14. Links to other websites
Our website, articles and emails may link to other websites, such as research sources, suppliers and social media platforms. We are not responsible for their privacy practices, so please read their privacy policies.
15. Changes to this policy
We review this policy regularly and will update it when our practices or the law change, including the Privacy Act reforms the Australian Government is currently proposing. The current version will always be available on this page, with the date it was last updated shown at the top.
