Privacy Policy
Privacy Policy (security of Personal Information)
Medecs Learning provides education, training, and clinical consultancy to the Healthcare & Social assistance sector in Australia. The services we provide inherently requires us to collect your Personal Information. We understand your Personal Information is sensitive and requires protection systems and secure management protocols. Your privacy is important to us so we hope by reading this policy you will feel informed and confident we are doing the best we can to manage the security of your Personal Information.
This policy explains how Medecs Australia Pty Ltd trading as Medecs Learning (Medecs, we, us or our) collects, holds, uses, discloses and protects personal information through its website and connected digital services.
It is intended to support compliance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme and, where applicable, the Spam Act 2003 (Cth), National Vocational Education and Training Regulator Act 2011 (Cth), Student Identifiers Act 2014 (Cth), National Disability Insurance Scheme Act 2013 (Cth) and associated standards and requirements.
This policy should be read with collection notices displayed on particular forms. A collection notice explains the circumstances and purpose of a specific collection and may provide more detailed information than this policy.
1.Scope.
This policy applies to personal information collected through:
- The Medecs Learning website and HubSpot-hosted pages and forms;
- The Complex Healthcare Request Form and other enquiry or referral forms;
- Online course enquiries, enrolments, and payments;
- HubSpot CRM, marketing emails and newsletters connected with the website;
- Microsoft 365 services used to respond to, manage, or securely share information collected online; and
- Vasto student management and learning management systems used in connection with training services.
2.What is Personal Information and why do we collect it?
Personal Information is information or an opinion that identifies an individual. Examples of the primary Personal Information we collect include names, addresses, birth dates, email addresses, phone numbers and at times financial information required for payment of our services.
We collect your Personal Information for the primary purpose of providing our education & training services to you. This includes:
- Registered Training Organisation (RTO 45695) National reporting requirements
- Primary and financial information to be able to deliver education & training services
- NDIS registered provider (0114 Community Nursing Care) National reporting requirements
- Providing information to our clients and marketing. You may unsubscribe from our mailing/marketing lists at any time.
3.Health & other sensitive Information.
Medecs provides clinical support and participant-specific training services. We may therefore collect sensitive information, including health, disability, and support information, where it is reasonably necessary for our functions, and the individual has consented, or another lawful basis applies.
The Complex Healthcare Request Form may collect:
- Participant name and date of birth;
- NDIS participant number, where applicable;
- Parent, guardian, or decision-maker name and contact details;
- Medical conditions and complex healthcare needs;
- The clinical skill areas required, including medication, enteral care, bowel care, diabetes, epilepsy, respiratory, wound, palliative and other supports;
- Participant-specific training requirements; and
- Additional information relevant to assessing and coordinating the request.
These details are identifiable health information.
As a Registered Training Organisation we are required to collect personal information at the point of enrolment in nationally accedited courses. The Personal Information we collect at the point of enrolment in nationally accredited courses include:
- Names and addresses,
- Birth date,
- Email address and phone numbers and
- Student USI numbers (national VET data requirement)
- Employment details if relevant (national VET data requirement)
- Language & cultural diversity (national VET data requirement)
- Education & prior qualifications (national VET data requirement)
- Study reason (national VET data requirement)
- Disability (national VET data requirement)
- At times credit/debit card information required for payment of our services.
4.Information about children and represented indivdiuals.
Medecs may collect information about children and adults who require decision-making support. Where appropriate, information must be provided or authorised by the individual, a parent, guardian, nominee, decision-maker, or other person with lawful authority. Medecs may request evidence or further confirmation of that authority.
A referring professional or organisation must only provide information they are authorised to disclose. Medecs will seek additional consent or authority before commencing services where required.
5.How do we collect Personal Information?
We may collect information directly from an individual, or from an authorised representative or stakeholder, through:
- Website forms, telephone, email, Microsoft Teams, and other approved communications;
- HubSpot CRM and marketing tools;
- Course enrolment, payment, learning, and assessment systems;
- Service requests, consent forms, clinical records, and documents;
- Families, guardians, support coordinators, service providers, schools, hospitals, and health professionals;
- Government, regulatory or funding bodies where authorised; and
- Cookies, analytics, advertising pixels, and similar technologies, subject to the controls described below.
If Medecs receives unsolicited personal information, we will determine whether it could lawfully have been collected. If not, and where lawful and reasonable, it will be destroyed or de-identified.
6.Why we collect, use and disclose information.
We collect, use, and disclose information for purposes including:
-
Responding to enquiries and assessing referrals and service requests.
-
Planning, coordinating, and delivering clinical support, care-plan services and participant-specific training and assessment;
- Communicating with participants, representatives, providers, health professionals, and other authorised stakeholders;
- Administering courses, enrolments, assessment, credentials, and regulatory reporting;
- Processing payments, managing accounts, and maintaining financial records;
- Managing consent, quality, safety, incidents, complaints, and legal obligations;
- Securing, maintaining and improving our website, systems, and services;
- Sending newsletters and marketing communications where permitted; and
- Other purposes notified at collection, consented to, or required or authorised by law.
7.Disclosure of Personal Information
We do not share your personal information with any parties unless required by law in the following legitimate circumstances:
- National and State VET data collection. As a Registered Training Organisation (RTO 45695), we are required by law to provide your Personal Information to the Commonwealth Government for national vocational education & training (VET) data collection and to the Tasmania State Government training authority for VET data collection and funding requirements. Further information about VET data reporting requirements is available from the National Regulator ASQA
- NDIS registered provider (0114 Community Nursing Care) National reporting requirements
- Third parties where you consent to the use or disclosure; and
- Where required or authorised by law
8.How we disclose your personal information
We are required by law (under the National Vocational Education and Training Regulator Act 2011 (Cth) (NVETR Act)) to disclose the personal information we collect to the National VET Data Collection kept by the National Centre for Vocational Education Research Ltd (NCVER).
9.Systems we use
Hubspot
HubSpot hosts the Medecs website and provides CRM, website forms, visitor analytics, marketing email, and newsletter functionality. Medecs’ HubSpot account is hosted in Sydney, Australia, using Amazon Web Services infrastructure. Limited processing or access may occur outside Australia through HubSpot affiliates, approved subprocessors, support, security, analytics, and service operations.
Microsoft 365
Medecs uses Microsoft 365 services including Outlook, Teams and SharePoint. Core customer data for applicable services is stored at rest within Microsoft’s Australian data-centre regions, subject to the particular service, tenant configuration, and Microsoft’s current data-residency commitments. Limited overseas access or processing may occur for support, security, diagnostics, or connected services.
Vasto
Medecs uses Vasto student and learning management systems. As our NCVER accredited VET data collection system. Vasto advises that customer data is stored within Australia using Amazon Web Services infrastructure and that it uses encrypted connections, monitoring, activity logging, threat detection, and periodic security testing.
Stripe
Medecs uses Stripe to process online payments. Payment card details entered into Stripe-controlled payment facilities are handled by Stripe under its privacy and security arrangements. Medecs may receive limited billing information, payment status, and transaction identifiers needed to manage payments, refunds, and financial records. Medecs does not ordinarily receive or store complete payment card details through its website.
10.Cookies, analytics and advertsiing technologies.
Our website uses cookies and similar technologies for website operation, security, user preferences, analytics, and advertising measurement. These may include:
- Essential and security cookies needed to operate forms, sessions, consent preferences, and website features;
- HubSpot cookies such as hstc, hubspotutk, hssc and hssrc, together with infrastructure, consent, security and enabled chat or feature cookies;
- Google Analytics to understand website visits, devices, navigation, and performance;
- Meta Pixel to measure advertising performance and support advertising audiences; and
- LinkedIn Insight Tag to measure website interactions and LinkedIn campaign performance.
Google, Meta, LinkedIn, and their service providers may process identifiers and website activity outside Australia. Their handling is governed by their own privacy arrangements as well as the controls Medecs applies to its website.
Visitors can use the website cookie preference tool to accept, reject, or manage non-essential analytics and advertising cookies. Essential cookies cannot always be disabled because they are necessary for website operation and security. Browser settings may also be used to control cookies, although disabling some cookies may affect website functionality.
Health-form tracking control
Advertising pixels and unnecessary analytics are disabled across the Complex Healthcare Request Form journey. Medecs does not permit health-related field values, uploaded clinical material or participant identifiers to be sent to advertising platforms.
11.Marketing communications.
Medecs may use HubSpot to send newsletters, educational material, service updates, and promotional communications where the recipient has consented or where otherwise permitted by law. Marketing consent is separate from consent to collect health information or provide a requested service.
Recipients can unsubscribe using the link in a marketing message or contact Medecs. We may still send necessary services, safety, transactional or administrative communications. We do not use sensitive health information for direct marketing without specific lawful authority.
12.Data hosting and overseas processing.
Medecs primarily uses systems with Australian hosting arrangements. However, technology providers, their affiliates, support teams, and approved subprocessors may access or process limited information overseas.
Depending on the service and functionality used, these locations may include the United States and other
countries identified in the provider’s current subprocessor information.
Where APP 8 applies, Medecs takes reasonable steps in the circumstances to ensure an overseas recipient handles personal information consistently with the APPs, unless an exception applies. Provider locations and subprocessors may change, and Medecs reviews material service-provider arrangements as part of its privacy and security governance.
13.Security
Medecs takes reasonable technical, organisational and physical steps to protect personal information from misuse, interference, loss and unauthorised access, modification, or disclosure. Measures may include:
- Role-based access and least-privilege permissions;
- Multifactor authentication and controlled privileged accounts;
- Approved company-owned laptops and desktop computers for authorised workforce access;
- Device management, security updates, endpoint protection, and encryption;
- Controlled SharePoint sites, shared mailboxes, and CRM access;
- Secure transmission, backups, monitoring, and incident-response arrangements;
- Staff confidentiality, privacy, and cybersecurity training; and
- Service provider review and access removal when no longer required.
No internet transmission or storage system is completely risk-free. Individuals should not send urgent clinical information through a general website form.
If there is an immediate threat to life or safety, call emergency services on 000.
14.Data quality, retention and disposal.
Medecs takes reasonable steps to ensure information is accurate, complete, current, and relevant for its intended use. Individuals and authorised representatives should tell us when information changes or requires correction.
Retention periods depend on the record type and applicable clinical, RTO, NDIS, corporate, taxation, insurance, contractual and legal requirements. Information is not retained indefinitely merely because it may be useful. When information is no longer required and no lawful reason for retention applies, Medecs takes reasonable steps to securely destroy or de-identify it.
15.Access and correction.
An individual may request access to personal information Medecs holds about them or ask for it to be corrected. An authorised representative may make a request where their authority is established.
Medecs may need to verify identity and authority before responding. Access may be refused or limited where permitted by law, including where disclosure would unreasonably affect another person’s privacy or create a serious health or safety risk. If access or correction is refused, Medecs will generally provide written reasons and available complaint options.
16.Privacy enquiries and complaints.
Privacy enquiries, access and correction requests, and complaints should be directed to:
|
Contact |
Director Governance |
|
Organisation |
Medecs Learning |
|
|
snoone@medecslearning.com |
|
Telephone |
(03) 6272 1843 |
|
Post |
PO Box 327, Glenorchy, Tasmania 7010, Australia |
A complaint should describe the concern and include enough information for Medecs to investigate. We will acknowledge the complaint, assess it fairly, keep the complainant informed, and provide a response within a reasonable period. Complex matters may require additional time.
If the complainant is dissatisfied with Medecs’ response, they may contact the Office of the Australian Information Commissioner at www.oaic.gov.au or 1300 363 992. Other health, disability, training, or consumer complaint bodies may also have jurisdiction depending on the subject matter.
17.Data Breaches
Medecs maintains arrangements for responding to suspected privacy and cybersecurity incidents. We will contain and assess a suspected breach, take remedial action, and document relevant decisions. Where an eligible data breach is likely to result in serious harm, Medecs will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
18.Anonymity and pseudonymity.
Individuals may interact anonymously or use a pseudonym where lawful and practicable, such as when browsing general website content or making a general enquiry. Medecs may require identity information where it is necessary to provide a service, protect safety, process an enrolment or payment, verify authority, meet regulatory requirements, or maintain accurate clinical and training records.
19.Changes to policy.
Medecs reviews this policy annually and earlier when there is a material change to law, technology, service delivery, or information-handling practices. The current version will be published on the Medecs Learning website. Material changes may also be communicated through appropriate channels.
20.Document control.
|
Version |
Effective date |
Approved by |
Summary |
|
2.0 |
1 July 2026 |
Directors |
Updated for HubSpot, health-information forms, cookies, analytics, advertising pixels, Stripe, and current digital systems. |