1. Who we are
Telehealth Psychology Australia Pty Ltd (THPA) is a telehealth-only psychology practice serving children and adults across Australia.
- Legal entity: Telehealth Psychology Australia Pty Ltd
- ACN: 695 737 154
- ABN: 83 695 737 154
- Registered address: Level 18, 324 Queen Street, Brisbane QLD 4000 (a virtual office; THPA is telehealth only)
- Email: directors@thpa.au
- Website: thpa.au
Our psychologists are Registered Psychologists with the Psychology Board of Australia through AHPRA. You can verify any THPA psychologist’s registration at ahpra.gov.au.
2. What personal and health information we collect
To provide psychological services, we collect personal information and sensitive health information. The information we hold may include the following.
Personal information
- Your name, date of birth, gender, and contact details (address, phone, email)
- Emergency contact details
- Medicare number and Individual Reference Number (IRN)
- NDIS participant number and plan details
- WorkCover claim number and insurer details
- Referring doctor and other health professional details
- Cultural and linguistic background
- Employment and relationship status
Health information
- Presenting concerns and reasons for seeking treatment
- Medical history, diagnoses, and current medications
- Mental health history, including previous treatment and hospitalisations
- Results of psychological assessments and outcome measures (for example the K10, PHQ-9, GAD-7, and DASS-21)
- Clinical observations, formulations, and treatment plans
- Progress notes from each session
- Risk assessments and safety plans
- Reports prepared for your GP, NDIS, WorkCover, or other authorised parties
Technical information (telehealth): when you attend a session, the video platform may collect limited technical data such as connection quality, session duration, and device type. Sessions are conducted over Halaxy Telehealth, with video provided by Amazon Chime hosted on AWS in Sydney, using AES-256 encryption. Sessions are not recorded.
Optional note-taking: if you provide separate, specific consent, we may use Halaxy AI Scribe to assist with session notes. It is Australian-hosted, no audio is kept, and it is not used to train AI models. You can decline this without affecting your care.
3. How we collect it
We collect your personal and health information:
- Directly from you, through intake forms, during sessions, and through correspondence
- From your referring doctor, via referral letters and Mental Health Treatment Plans
- From other health professionals, with your consent, when coordinating your care
- From NDIS plan managers or support coordinators, for NDIS-funded services
- From WorkCover insurers or claims agents, for WorkCover-funded services
- Through our practice management system, Halaxy, when you complete online forms, book appointments, or use the client portal
We collect information only by lawful and fair means, and we will tell you the purpose of collection at or before the time we collect it.
4. Why we collect it and how we use it
We collect and use your information to:
- Provide you with psychological assessment and treatment
- Communicate with your GP and other health professionals, with your consent
- Process Medicare claims on your behalf, with your consent, where you have a valid Mental Health Treatment Plan from your GP
- Invoice NDIS plan managers or WorkCover insurers
- Contact you about appointments, reminders, and administrative matters
- Maintain clinical records as required by law and professional standards
- Comply with legal obligations, including mandatory reporting
- Manage complaints and incidents
- Conduct peer supervision and quality assurance, de-identified where possible
We do not collect more information than is reasonably necessary for these purposes.
We do not use your personal or health information for direct marketing. We do not sell, rent, or trade your information to any third party. We may send appointment reminders and administrative communications related to your care, and you can opt out of non-essential communications at any time.
5. Disclosure of your information
We will not share your personal or health information with anyone without your written consent, except where required or authorised by law.
With your written consent, we may share relevant information with:
- Your GP or referring doctor
- Other treating health professionals (for example a psychiatrist or specialist)
- NDIS plan managers, support coordinators, or the NDIA
- WorkCover insurers, claims agents, or rehabilitation providers
- Schools, employers, or other organisations you nominate
- Family members or carers you nominate
Without your consent, we may disclose information only where required or authorised by law, including:
- To lessen or prevent a serious threat to life, health, or safety (Privacy Act s.16A)
- Mandatory notifications to AHPRA under ss.141 to 143 of the Health Practitioner Regulation National Law
- Reports to Queensland Child Safety Services where child abuse or neglect is suspected
- When required by a court order, subpoena, or other legal process
- To emergency services (000) during a crisis in a telehealth session
- For law enforcement purposes as authorised under the Privacy Act
Service providers we use to handle your information:
- Halaxy is our primary practice management and billing system. Your clinical records are stored in Halaxy on AWS servers located in Sydney, Australia.
- Stripe may process card payments. Only payment data is shared with Stripe. Clinical information is never sent to Stripe, and your clinical records stay in Australia. Stripe involves an overseas disclosure of payment data only (see section 9).
6. Data security
All clinical records and personal information are stored in Halaxy, an Australian-built practice management system, with security features including:
- Data hosted on Amazon Web Services (AWS) servers in Sydney, within Australia
- AES-256 encryption for data at rest and in transit
- Multi-factor authentication for all practitioner accounts
- Role-based access controls
- Automatic session timeouts
- Audit logs of all data access
Our practitioners are required to use devices with full-disk encryption, keep operating systems patched, enable auto-lock, and enable remote wipe. Client data is not stored on local devices; all clinical records are kept in Halaxy.
As a telehealth-only practice, THPA does not maintain physical paper records. All documentation is created and stored electronically.
Data breaches: if a data breach is likely to result in serious harm, we will contain the breach, assess it, and, where the threshold is met, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable under the Notifiable Data Breaches scheme (Part IIIC, Privacy Act 1988). We keep a record of the breach and our response. Because mental health records are sensitive, we treat any breach involving clinical information seriously and assess it against the notification threshold without delay.
7. Access and correction
You have the right to request access to the personal and health information we hold about you (APP 12), and to request correction of information that is inaccurate, out of date, incomplete, irrelevant, or misleading (APP 13).
To request access or correction, email directors@thpa.au or ask your psychologist. We will respond within 30 days. We may charge a reasonable fee for providing access, for example for time spent preparing copies.
In limited circumstances we may refuse access, for example where providing access would pose a serious threat to the life, health, or safety of any person, where the information relates to existing or anticipated legal proceedings, where access would be unlawful, or where the request is frivolous or vexatious. If we refuse access or a correction, we will give you written reasons and tell you how to complain to the OAIC.
Clinical opinions, diagnoses, and clinical notes reflect your psychologist’s professional assessment at the time and are generally not amended on request. You may ask that a note be added to your record reflecting your perspective.
8. Retention
We retain your records in accordance with legislation and professional standards:
- Adult client records: a minimum of 7 years from the date of last appointment
- Clients seen as minors: until the person turns 25 years of age, or 7 years from last appointment, whichever is later
- Financial records: a minimum of 5 years from the date of preparation (ATO requirement)
At the end of the retention period, records are securely destroyed and recorded in our Secure Record Destruction Register.
9. Cross-border disclosure
We store your clinical records and personal information within Australia (AWS Sydney servers). The only overseas disclosure is payment data processed through Stripe. Clinical information is never sent to Stripe. Where any overseas disclosure occurs, we take reasonable steps to ensure the recipient is bound by privacy obligations consistent with the Australian Privacy Principles. If our arrangements change in the future, we will update this policy.
10. Website analytics and cookies
We are finalising our approach to website analytics and cookies. If we use analytics or cookies, this section will describe what is collected, why, and how you can manage your preferences. We do not link website analytics data to your clinical records.
11. Complaints
If you believe we have breached your privacy or mishandled your personal information, you can:
- Contact THPA directly at directors@thpa.au. We will acknowledge your complaint within 2 business days and investigate within 30 days.
- Contact the Office of the Australian Information Commissioner (OAIC): phone 1300 363 992, web www.oaic.gov.au.
For NDIS-related concerns, you can also contact the NDIS Quality and Safeguards Commission on 1800 035 544.
12. How to contact us
If you have any questions about this policy or how we handle your information:
- Email: directors@thpa.au
- Website: thpa.au
- Post: Telehealth Psychology Australia Pty Ltd, Level 18, 324 Queen Street, Brisbane QLD 4000 (a virtual office; THPA is telehealth only)
13. Changes to this policy
We may update this Privacy Policy from time to time. The current version is always available on our website (thpa.au), and a copy can be provided on request. We will notify existing clients of material changes.
This policy is reviewed annually. Effective date: April 2026. Last updated: 26 June 2026.