Privacy Policy
The Hand Therapy Co trading as Bowral Hand Therapy and Goulburn Hand Therapy
Last updated: September 2026
What is personal and health information?
Personal information includes things like your name, address, phone number, email address and date of birth.
Health information is more sensitive and includes details about your medical history, injuries, diagnoses, treatment plans, and test results. It can also include your Medicare number, referrals, photos and any notes taken by your therapist.
Why do we collect your information?
We collect your personal and health information so we can:
Provide you with safe and effective hand therapy
Book appointments and send you reminders
Write letters to doctors, surgeons, or other health professionals involved in your care
Process billing through Medicare, WorkCover, NDIS, or private health insurers
Monitor your progress and keep accurate clinical records
Make referrals if you ask us to
We only collect what is necessary for your care and support.
How do we collect information?
We collect information:
When you complete our online intake and consent forms via Cliniko
When you speak with our admin team or therapy team
During therapy sessions at our Bowral or Goulburn clinics
From referrers (like your GP or surgeon), with your consent
Sometimes, information may be collected indirectly (e.g. when your family member or support person provides it), but we'll always check that you're happy for us to keep it.
What systems do we use to store your information?
At The Hand Therapy Co, we use secure digital systems:
Cliniko - for your appointment bookings, clinical records, intake and consent forms, appointment reminders, and letters/emails to referrers (you can opt out of reminders anytime)
Xero - for billing and practice information
These systems are password protected, stored in secure cloud environments, and access is restricted to authorised to authorised team members.
Who might we share your information with?
We only share your information with:
Other health professionals involved in your care (e.g. your GP or specialist)
Your insurer, if you're using a third-party fund (e.g. WorkCover, NDIS, private health insurance)
Your referrer, when they request an update or report
Anyone you've given us permission to share with
We also use Cliniko and Gmail to communicate with doctors, surgeons, insurers, and other providers involved in your care. If you're under WorkCover, this may include forwarding reports and invoices to your case manager or insurance company.
Sending information via email can carry a risk, as emails may be intercepted after leaving our system before they reach the intended recipient. If you prefer that we don't use email to share your information, please let us know; we're happy to use another method.
We'll never sell your data or share it for marketing purposes without your consent.
Where is your information stored?
Our client data is stored in Australian-based cloud storage systems that comply with national privacy standards. These systems include:
Cliniko (clinical records, appointments, intake/consent forms, and reminders) – Cliniko is an Australian company and stores Australian account data on servers located in Australia
We regularly review our providers to make sure they maintain strong security and privacy measures.
How long do we keep your information?
By law, we must keep health records for:
7 years for adults
Until age 25 for clients under 18
After that, your records are securely destroyed unless required for legal or clinical purposes.
Your rights
You have the right to:
Access your information - just ask and we will explain how to do this
Correct any incorrect or out-of-date information
Request that we delete your personal data if it's no longer needed (we will always explain if we are legally required to keep it)
Object to how your data is used (e.g. for newsletters or case examples)
From 2025, privacy laws have expanded these rights to give you more control over your data.
How do we protect your information?
We take your privacy seriously. We:
Lock paper files and confidential notes when not in use
Restrict digital access to team members who need it
Use strong passwords and secure cloud systems
Regularly review who has access
Never leave confidential documents unattended in public areas
Provide privacy training to all staff
We also have a Data Breach Response Plan in place.
If something goes wrong, we will act quickly to notify you and take steps to protect your information.
Contact us
If you have any questions about how your information is used, or you'd like to access, correct or delete your information, please contact:
Privacy Officer – The Hand Therapy Co: Ceri Pulham
Email: ceri@handtherapyco.com.au
Phone: 02 4861 6113
If you're not satisfied with how we handle your concern, you can also contact the office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au
