Privacy

Privacy Policy.

How we collect, use, store, protect and disclose personal and health information.

Last updated: 27 July 2026

1. About this policy

Embark Potential Pty Ltd (ABN 27 682 258 939) (“Embark Potential”, “we”, “us” or “our”) is responsible for the personal information it holds.

This Privacy Policy explains how we collect, hold, use and disclose personal information, including health information. It applies to our website and online forms, referrals, screening, psychological assessments, professional services, communications, payments, feedback and complaints.

We handle personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles, and health information in accordance with the Health Records and Information Privacy Act 2002 (NSW), including the Health Privacy Principles, where applicable.

A separate collection notice may be provided when information is collected through a particular form or service. That notice should be read together with this policy.

2. Personal information we collect

Depending on your interaction with us, we may collect:

We do not intentionally use Meta, TikTok or other advertising tracking pixels. We use only cookies and technical information reasonably required to operate and protect the website. If our use of analytics or cookies changes materially, we will update this policy and introduce any required consent mechanism.

3. How we collect information

We usually collect personal information directly from you or your authorised representative through online forms, telephone or video calls, appointments, questionnaires, correspondence, uploaded documents and the delivery of our services.

We may also receive information from an authorised referrer, parent, guardian, nominee, support coordinator, health practitioner, school, service provider, government agency or another person involved in your care or support, where you have consented or the collection is otherwise authorised or required by law.

If you provide personal information about another person, you must be authorised to do so and, where practicable, make them aware of this Privacy Policy and any relevant collection notice.

If we receive unsolicited personal information, we will assess whether we could lawfully have collected it. If not, we will destroy or de-identify it as soon as practicable where lawful and reasonable.

Do not send clinical records or sensitive health information through an ordinary email. Clinical forms and documents should be submitted only through the secure method provided by Embark Potential.

4. Why we collect, use and disclose information

We collect, hold, use and disclose personal information where reasonably necessary to:

We will not use or disclose health information for an unrelated purpose unless you consent or the use or disclosure is otherwise permitted or required by law.

5. If you do not provide information

You may choose not to provide requested information. However, we may then be unable to assess suitability, respond fully to your request, provide a service safely, prepare an accurate report, process an invoice or meet our legal and professional obligations.

6. Data quality

We take reasonable steps to ensure that the personal information we collect, use and disclose is accurate, complete, current and relevant. Please tell us if your information changes or you believe a record is inaccurate.

7. Anonymity and pseudonyms

You may make a general enquiry anonymously or using a pseudonym where practicable. We will usually need to confirm identity to provide clinical services, manage records, issue reports, process payments or comply with legal and professional obligations.

8. Children, decision-making capacity and representatives

Where services involve a child or a person who may require decision-making support, we consider age, maturity, capacity, guardianship, parental responsibility and any other relevant legal authority. We seek consent from the person or an authorised representative as required and involve the person in decisions to the extent reasonably practicable.

We may require evidence of identity and authority before accepting instructions, providing access to records or disclosing information to a representative.

9. Who we may disclose information to

Where reasonably necessary and authorised, we may disclose personal information to:

With the person’s consent, relevant assessment outcomes or reports may be provided to the referrer. Embark Potential does not provide a financial benefit to a referrer or practice for referrals.

10. Systems, storage and service providers

Clinical system

Clinical forms, documents and records submitted through our secure online system are stored in Embark Potential’s Replit production environment configured for the Australian geographic region. Clinical files submitted through this system are not routed through ordinary email.

Email and appointments

We use Google Workspace for ordinary business email, calendar and appointment administration. Ordinary email is not used as the submission pathway for clinical files. Information contained in administrative emails or appointment records may be processed by Google and its subprocessors outside Australia.

Backups

Backups may be held on an encrypted local drive and in an access-controlled OneDrive account managed by Embark Potential. Microsoft and its subprocessors may process information outside Australia.

Invoices and payments

We use Xero to prepare and manage invoices. Payment is made by direct bank transfer. Embark Potential does not collect or store credit or debit card details through its website or clinical system.

Xero may store or process information in the United States, New Zealand, the United Kingdom, India, Singapore, Canada, South Africa and other countries in which its affiliates or subprocessors operate.

11. Overseas processing and disclosure

Although our primary clinical production environment is configured for Australia, Replit is a United States-based provider. Replit platform services and its subprocessors, as well as other providers supporting administration, communication, backup and invoicing, may process or access personal information outside Australia.

Depending on the provider and service used, these locations may include the United States, New Zealand, the United Kingdom, India, Singapore, Canada, South Africa and countries within the European Union.

Where an overseas disclosure occurs, we take reasonable steps required by law in relation to the recipient’s handling of personal information.

12. Security

We take reasonable technical and organisational steps appropriate to the sensitivity of the information we hold. Measures currently used include:

No electronic system can be guaranteed to be completely secure. Suspected data breaches will be assessed and handled in accordance with applicable law, including the Notifiable Data Breaches scheme.

13. Generative artificial intelligence

We do not enter identifiable patient or client information into generative artificial intelligence tools. Appropriately de-identified information may be used for limited professional or service-improvement purposes only where individuals are not reasonably identifiable. If this practice changes materially, we will first assess the privacy, legal, professional and security implications and update our notices and consent processes where required.

14. Research and service improvement

We may use aggregated or de-identified information for internal quality improvement, service planning or research where individuals are not reasonably identifiable and the use is lawful. Identifiable information will not be published for these purposes without appropriate consent or other lawful authority.

15. Professional outreach and direct marketing

We do not use patient or client health information for direct marketing and do not operate a consumer marketing mailing list.

We may use publicly available business contact details for professional outreach only where permitted by applicable privacy and marketing laws. Commercial electronic messages are sent only where the recipient has expressly consented or consent may lawfully be inferred, including from a conspicuously published business address where there is no statement that unsolicited messages are not wanted and the message is directly relevant to the recipient’s role or functions. Such messages identify Embark Potential, provide current contact details and include a clear unsubscribe method. We honour unsubscribe requests within five working days.

16. Retention and disposal

Clinical health records are generally retained:

Other personal information is retained only for as long as reasonably required for the purpose for which it was collected and to meet legal, professional, insurance, accounting and dispute-resolution requirements.

When information is no longer required and there is no lawful reason to retain it, we take reasonable steps to securely destroy or de-identify it. Backup copies may remain until they are securely overwritten or deleted through the applicable backup cycle.

17. Access and correction

You may request access to personal information we hold about you or ask us to correct information you believe is inaccurate, incomplete, out of date, irrelevant or misleading.

Requests can be made using the contact details below. We may need to verify your identity or authority. We aim to respond within 30 calendar days. Access may be refused or limited where permitted by law, in which case we will generally provide written reasons and available complaint options.

If we refuse to correct information, you may ask us to associate a statement with the record indicating that you consider the information inaccurate, incomplete, out of date, irrelevant or misleading.

18. Privacy complaints

You may make a privacy complaint using the contact details below. Please describe the issue and any outcome you are seeking. We will acknowledge and investigate the complaint and aim to provide a response within 30 calendar days. If more time is reasonably required, we will explain why and provide an updated timeframe.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC). Complaints concerning health information in NSW may also be made to the Health Care Complaints Commission or the Information and Privacy Commission NSW, depending on the nature of the complaint.

19. External websites

Our website may link to external websites. We are not responsible for the privacy practices or content of those websites. You should review their privacy information before providing personal information.

20. Changes to this policy

We may update this Privacy Policy when our services, systems or legal obligations change. The current version and its last-updated date will be published on this page.

21. Contact us

For privacy enquiries, access or correction requests, or complaints, contact:

Privacy Officer
Embark Potential Pty Ltd
234 Prospect Highway
Seven Hills NSW 2147
Email: admin@embarkpotential.com.au