Privacy
Privacy Policy.
How we collect, use, store, protect and disclose personal and health information.
Last updated: 27 July 2026
1. About this policy
Embark Potential Pty Ltd (ABN 27 682 258 939) (“Embark Potential”, “we”, “us” or “our”) is responsible for the personal information it holds.
This Privacy Policy explains how we collect, hold, use and disclose personal information, including health information. It applies to our website and online forms, referrals, screening, psychological assessments, professional services, communications, payments, feedback and complaints.
We handle personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles, and health information in accordance with the Health Records and Information Privacy Act 2002 (NSW), including the Health Privacy Principles, where applicable.
A separate collection notice may be provided when information is collected through a particular form or service. That notice should be read together with this policy.
2. Personal information we collect
Depending on your interaction with us, we may collect:
- Identity and contact information: name, date of birth, address, email address, telephone number, preferred contact method and emergency or representative contact details.
- Health and clinical information: referral information, presenting concerns, medical and developmental history, diagnoses, medications, assessment responses and results, clinical observations, reports, correspondence, risk and safety information, and relevant family, education, employment, disability, NDIS or service information.
- Service and administrative information: appointments, consent and authority records, communications, invoices, payment status, complaints and feedback.
- Professional contact information: a referrer’s or other professional’s name, role, organisation, business contact details and relationship to the person receiving services.
- Website and technical information: information required to operate and secure the website, such as IP address, browser and device information, timestamps, security logs and essential cookie data.
We do not intentionally use Meta, TikTok or other advertising tracking pixels. We use only cookies and technical information reasonably required to operate and protect the website. If our use of analytics or cookies changes materially, we will update this policy and introduce any required consent mechanism.
3. How we collect information
We usually collect personal information directly from you or your authorised representative through online forms, telephone or video calls, appointments, questionnaires, correspondence, uploaded documents and the delivery of our services.
We may also receive information from an authorised referrer, parent, guardian, nominee, support coordinator, health practitioner, school, service provider, government agency or another person involved in your care or support, where you have consented or the collection is otherwise authorised or required by law.
If you provide personal information about another person, you must be authorised to do so and, where practicable, make them aware of this Privacy Policy and any relevant collection notice.
If we receive unsolicited personal information, we will assess whether we could lawfully have collected it. If not, we will destroy or de-identify it as soon as practicable where lawful and reasonable.
Do not send clinical records or sensitive health information through an ordinary email. Clinical forms and documents should be submitted only through the secure method provided by Embark Potential.
4. Why we collect, use and disclose information
We collect, hold, use and disclose personal information where reasonably necessary to:
- respond to enquiries and referrals;
- conduct free initial screening and assess whether a service or pathway is suitable;
- provide psychological assessments, reports, consultations and other agreed services;
- communicate with you, your authorised representative, referrer and relevant professionals or services;
- schedule appointments, coordinate service delivery and manage follow-up;
- prepare invoices, record payments and manage our accounts;
- maintain accurate clinical, administrative and professional records;
- manage quality, safety, risk, feedback and complaints;
- meet legal, regulatory, insurance and professional obligations; and
- protect the safety or rights of individuals where authorised or required by law.
We will not use or disclose health information for an unrelated purpose unless you consent or the use or disclosure is otherwise permitted or required by law.
5. If you do not provide information
You may choose not to provide requested information. However, we may then be unable to assess suitability, respond fully to your request, provide a service safely, prepare an accurate report, process an invoice or meet our legal and professional obligations.
6. Data quality
We take reasonable steps to ensure that the personal information we collect, use and disclose is accurate, complete, current and relevant. Please tell us if your information changes or you believe a record is inaccurate.
7. Anonymity and pseudonyms
You may make a general enquiry anonymously or using a pseudonym where practicable. We will usually need to confirm identity to provide clinical services, manage records, issue reports, process payments or comply with legal and professional obligations.
8. Children, decision-making capacity and representatives
Where services involve a child or a person who may require decision-making support, we consider age, maturity, capacity, guardianship, parental responsibility and any other relevant legal authority. We seek consent from the person or an authorised representative as required and involve the person in decisions to the extent reasonably practicable.
We may require evidence of identity and authority before accepting instructions, providing access to records or disclosing information to a representative.
9. Who we may disclose information to
Where reasonably necessary and authorised, we may disclose personal information to:
- the person receiving the service and their authorised representative;
- referrers, general practitioners, psychologists, allied health practitioners and other relevant professionals;
- schools, service providers, support coordinators, the NDIS or government bodies involved in the person’s care, funding or support;
- contractors and technology providers that support our website, secure information systems, communications, storage, backup, invoicing and business operations;
- professional advisers, insurers, regulators, courts, tribunals, law enforcement or other bodies where authorised or required by law; and
- another person or organisation where you have consented.
With the person’s consent, relevant assessment outcomes or reports may be provided to the referrer. Embark Potential does not provide a financial benefit to a referrer or practice for referrals.
10. Systems, storage and service providers
Clinical system
Clinical forms, documents and records submitted through our secure online system are stored in Embark Potential’s Replit production environment configured for the Australian geographic region. Clinical files submitted through this system are not routed through ordinary email.
Email and appointments
We use Google Workspace for ordinary business email, calendar and appointment administration. Ordinary email is not used as the submission pathway for clinical files. Information contained in administrative emails or appointment records may be processed by Google and its subprocessors outside Australia.
Backups
Backups may be held on an encrypted local drive and in an access-controlled OneDrive account managed by Embark Potential. Microsoft and its subprocessors may process information outside Australia.
Invoices and payments
We use Xero to prepare and manage invoices. Payment is made by direct bank transfer. Embark Potential does not collect or store credit or debit card details through its website or clinical system.
Xero may store or process information in the United States, New Zealand, the United Kingdom, India, Singapore, Canada, South Africa and other countries in which its affiliates or subprocessors operate.
11. Overseas processing and disclosure
Although our primary clinical production environment is configured for Australia, Replit is a United States-based provider. Replit platform services and its subprocessors, as well as other providers supporting administration, communication, backup and invoicing, may process or access personal information outside Australia.
Depending on the provider and service used, these locations may include the United States, New Zealand, the United Kingdom, India, Singapore, Canada, South Africa and countries within the European Union.
Where an overseas disclosure occurs, we take reasonable steps required by law in relation to the recipient’s handling of personal information.
12. Security
We take reasonable technical and organisational steps appropriate to the sensitivity of the information we hold. Measures currently used include:
- restricted access to systems and accounts;
- encrypted transmission through secure online submission pathways;
- an encrypted local backup drive and an access-controlled OneDrive account managed by Embark Potential;
- device and software security updates;
- separation of clinical submission pathways from ordinary email; and
- secure disposal or deletion when information is no longer required.
No electronic system can be guaranteed to be completely secure. Suspected data breaches will be assessed and handled in accordance with applicable law, including the Notifiable Data Breaches scheme.
13. Generative artificial intelligence
We do not enter identifiable patient or client information into generative artificial intelligence tools. Appropriately de-identified information may be used for limited professional or service-improvement purposes only where individuals are not reasonably identifiable. If this practice changes materially, we will first assess the privacy, legal, professional and security implications and update our notices and consent processes where required.
14. Research and service improvement
We may use aggregated or de-identified information for internal quality improvement, service planning or research where individuals are not reasonably identifiable and the use is lawful. Identifiable information will not be published for these purposes without appropriate consent or other lawful authority.
15. Professional outreach and direct marketing
We do not use patient or client health information for direct marketing and do not operate a consumer marketing mailing list.
We may use publicly available business contact details for professional outreach only where permitted by applicable privacy and marketing laws. Commercial electronic messages are sent only where the recipient has expressly consented or consent may lawfully be inferred, including from a conspicuously published business address where there is no statement that unsolicited messages are not wanted and the message is directly relevant to the recipient’s role or functions. Such messages identify Embark Potential, provide current contact details and include a clear unsubscribe method. We honour unsubscribe requests within five working days.
16. Retention and disposal
Clinical health records are generally retained:
- for an adult, for at least seven years from the date of the last health service recorded; and
- for a person who was under 18 when the record was made, until the person reaches 25 years of age.
Other personal information is retained only for as long as reasonably required for the purpose for which it was collected and to meet legal, professional, insurance, accounting and dispute-resolution requirements.
When information is no longer required and there is no lawful reason to retain it, we take reasonable steps to securely destroy or de-identify it. Backup copies may remain until they are securely overwritten or deleted through the applicable backup cycle.
17. Access and correction
You may request access to personal information we hold about you or ask us to correct information you believe is inaccurate, incomplete, out of date, irrelevant or misleading.
Requests can be made using the contact details below. We may need to verify your identity or authority. We aim to respond within 30 calendar days. Access may be refused or limited where permitted by law, in which case we will generally provide written reasons and available complaint options.
If we refuse to correct information, you may ask us to associate a statement with the record indicating that you consider the information inaccurate, incomplete, out of date, irrelevant or misleading.
18. Privacy complaints
You may make a privacy complaint using the contact details below. Please describe the issue and any outcome you are seeking. We will acknowledge and investigate the complaint and aim to provide a response within 30 calendar days. If more time is reasonably required, we will explain why and provide an updated timeframe.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC). Complaints concerning health information in NSW may also be made to the Health Care Complaints Commission or the Information and Privacy Commission NSW, depending on the nature of the complaint.
19. External websites
Our website may link to external websites. We are not responsible for the privacy practices or content of those websites. You should review their privacy information before providing personal information.
20. Changes to this policy
We may update this Privacy Policy when our services, systems or legal obligations change. The current version and its last-updated date will be published on this page.
21. Contact us
For privacy enquiries, access or correction requests, or complaints, contact:
Privacy Officer
Embark Potential Pty Ltd
234 Prospect Highway
Seven Hills NSW 2147
Email: admin@embarkpotential.com.au