Privacy Policy

Bowen Physiotherapy 39 Powell St, Bowen QLD 4805 Phone: (07) 4786 2640 Email: info@bowenphysio.com.au Website: www.bowenphysio.com.au

Last updated: June 2026


Our Commitment to Your Privacy

Bowen Physiotherapy is committed to protecting your privacy and handling your personal information in an open and transparent way. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the Information Privacy Act 2009 (Qld), and the NDIS Practice Standards where applicable.

This policy explains how we collect, use, store, and disclose your personal and health information, and your rights in relation to that information.


What Information We Collect

We collect information necessary to provide physiotherapy services to you. This may include:

  • Your name, date of birth, address, phone number, and email address
  • Medicare number, DVA file number, or WorkCover claim details where applicable
  • NDIS participant number and plan details where applicable
  • Health information including medical history, current medications, diagnosis, and treatment notes
  • Referral information from your general practitioner or specialist
  • Billing and payment information
  • Emergency contact details
  • For minors: parent or guardian contact details and consent

How We Collect Your Information

We collect your information:

  • Directly from you when you complete intake forms, book an appointment, or communicate with us
  • From your parent or guardian where you are a minor
  • From your treating practitioners, GP, or specialists with your consent
  • Through our online booking system (Nookal)
  • Through our AI receptionist service (Booked Solid) when you contact us by phone or message
  • Through our website contact form

How We Use Your Information

We use your personal and health information to:

  • Provide physiotherapy assessment and treatment
  • Communicate with you about your appointments and care
  • Process billing and payments
  • Submit claims to Medicare, DVA, WorkCover QLD, NDIS, and private health insurers on your behalf
  • Comply with our legal and professional obligations
  • Maintain accurate clinical records
  • Meet our obligations under the NDIS Practice Standards where you are an NDIS participant

We will not use your information for marketing purposes without your explicit consent.


Consent and Withdrawal of Consent

By engaging our services, you consent to the collection, use, and disclosure of your personal and health information as described in this policy.

You have the right to withdraw your consent at any time. Withdrawing consent may affect our ability to provide certain services. To withdraw consent, please contact us using the details at the end of this policy.

Where we use specific tools such as Heidi Health (AI clinical documentation) or Physitrack (exercise and Telehealth platform), we will obtain your explicit consent before using those tools with your information. You may decline or withdraw consent for these specific tools without affecting your core physiotherapy care.


Privacy of Children and Young People

Where a patient is under 18 years of age, we will collect consent from a parent or legal guardian before collecting health information. We handle information about minors with additional care and will not disclose it without parental or guardian consent, except where required by law or in an emergency situation.

Clinical records for minors are retained until the patient turns 25 years of age or for 7 years from the date of last entry, whichever is later, in accordance with Queensland Health records legislation.

As a minor approaches and reaches adulthood, they may exercise their own privacy rights independently of their parent or guardian.


Artificial Intelligence (AI) Systems We Use

Bowen Physiotherapy uses the following AI-assisted tools to support our clinical and administrative operations. We are committed to transparency about how these systems interact with your information.

Booked Solid — AI Receptionist

We use Booked Solid as an AI-powered receptionist to handle appointment scheduling, reminders, and general patient communications. Booked Solid handles non-clinical scheduling information only — it is not used to collect or process sensitive health information.

Important information about Booked Solid:

  • Booked Solid is a UK-registered company operating under a formal Data Processing Agreement that recognises Australian Privacy Principle obligations
  • Patient data is stored in the UK or EU — this transfer is covered under Australian Privacy Principle 8.2, which permits overseas transfers where comparable privacy protections apply. UK/EU GDPR provides comparable protections to Australian privacy law
  • Voice recordings of phone calls are retained for 30 days for quality purposes, then permanently deleted
  • All data is encrypted in transit (TLS 1.2) and at rest (256-bit encryption)
  • Booked Solid conducts annual third-party penetration testing and monthly vulnerability scans

For more information, visit bookedsolid.co.uk/privacy and bookedsolid.co.uk/dpa.

Heidi Health — AI Clinical Documentation

We use Heidi Health to assist with clinical documentation including real-time transcription, clinical note generation, patient handouts, condition research, and clinical reports and correspondence.

Important information about Heidi Health:

  • Heidi Health complies with the Australian Privacy Principles and is certified to ISO27001 and SOC2 security standards
  • Patient data for Australian users is stored on Australian servers
  • Audio recordings of consultations are not retained — transcription occurs in real time and the audio is discarded
  • Heidi Health does not use patient data to train AI models without consent

Your practitioner will inform you before using Heidi Health and will obtain your explicit consent. You may decline AI transcription at any time — this will not affect your care. For more information, visit Heidi Health’s Privacy Policy.

Microsoft 365 — Email and Correspondence

We use Microsoft 365 (including Outlook) to manage patient correspondence and internal communications. Our Microsoft 365 tenant is confirmed to store data in Australian data centres, including Exchange Online, OneDrive, SharePoint, and Microsoft Teams.

SendGrid/SureMail — Email Delivery

We use SendGrid (via SureMail) to deliver transactional emails to patients including appointment confirmations and general correspondence. SendGrid processes recipient email addresses and message content only.

Nookal — Practice Management and Online Bookings

We use Nookal as our practice management and online booking system. Nookal stores appointment, billing, and patient contact information securely. Nookal holds SOC 2 Type 2 certification and complies with HIPAA and GDPR standards.


Clinical and Patient Engagement Systems

Physitrack — Exercise Prescription, Telehealth and Outcomes

We use Physitrack to deliver exercise programs, educational resources, outcome measure tracking, and Telehealth consultations. Physitrack handles patient contact details and health information including exercise programs and outcomes data.

Important information about Physitrack:

  • Primary patient data is stored on Australian AWS servers, with encrypted backups in Ireland
  • Physitrack is certified to ISO27001 and ISO27018 (Data Protection in Cloud) standards
  • Physitrack complies with the Australian Privacy Act 1988
  • Your explicit consent is required before your health data is shared with Physitrack

Your practitioner will obtain your explicit consent before enrolling you in Physitrack. You may decline use of Physitrack at any time without affecting your core care. For more information, visit Physitrack’s Privacy Policy.


Payment and Claims Systems

TYRO — Payment Processing

We use TYRO to process in-clinic patient payments including EFTPOS transactions and private health fund rebates via HICAPS. TYRO processes payment card details and transaction information but does not store full card numbers. For more information, visit tyro.com/privacy-policy.

HICAPS — Health Insurance Claims

We use HICAPS (integrated with TYRO) to process private health insurance claims at the point of care. HICAPS transmits your health fund membership details and treatment information to your private health insurer to calculate and process your rebate.

NDIS Portal and PRODA — NDIS Claims

Where you are an NDIS participant, we use the NDIS Provider Portal (accessed via PRODA — Provider Digital Access) to submit service claims on your behalf. This involves transmitting your NDIS participant number, service dates, and claim amounts to the National Disability Insurance Agency (NDIA). PRODA is operated by Services Australia.

Stripe — Online Payments

Patients who choose to pay online may do so via Stripe, a secure payment processing platform. Stripe processes your payment card details directly — Bowen Physiotherapy does not store your card information. Stripe is PCI-DSS compliant. For more information, visit stripe.com/au/privacy.

Xero — Accounting and Invoicing

We use Xero to manage our accounting, invoicing, and payment records. Patient invoice and payment data is synchronised with Xero. This includes your name, contact details, and financial transaction information. For more information, visit xero.com/au/legal/privacy.


Who We Share Your Information With

We may share your information with:

  • Referring practitioners and treating health professionals involved in your care, with your consent
  • Medicare, DVA, WorkCover QLD, and NDIS for the purpose of processing claims
  • Private health insurers where you are claiming a rebate
  • Physitrack — for exercise prescription, outcomes tracking, education and Telehealth, with your explicit consent
  • TYRO and HICAPS — for processing in-clinic payments and health fund claims
  • NDIS Portal/PRODA — for submitting NDIS claims to the NDIA on your behalf
  • Stripe — for processing online payments where you opt to pay online
  • Xero — for accounting, invoicing and payment records
  • Nookal — our practice management and online booking system
  • Booked Solid — our AI receptionist, for scheduling and non-clinical communications only (data stored in UK/EU)
  • Heidi Health — our AI clinical documentation tool, with your explicit consent
  • Microsoft 365 — for storage of patient correspondence and emails (Australian data centres)
  • SendGrid/SureMail — for delivery of emails to patients
  • Other parties where required or permitted by law, such as in response to a subpoena or court order

We do not sell your personal information to third parties.


Overseas Disclosure of Personal Information

Some of the third-party systems we use store or process data outside Australia. Where this occurs, we take reasonable steps to ensure those parties are subject to privacy obligations comparable to the Australian Privacy Principles, in accordance with APP 8.

  • Booked Solid stores data in the UK and EU, which are subject to UK GDPR and EU GDPR — frameworks that provide comparable protections to Australian privacy law
  • Physitrack stores primary data in Australia with encrypted backups in Ireland
  • All other key systems are confirmed to store data in Australia

Notifiable Data Breaches

Bowen Physiotherapy is subject to the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth). If we become aware of a data breach that is likely to result in serious harm to any individual whose information is involved, we will:

  • Assess the breach as quickly as possible
  • Notify affected individuals as soon as practicable
  • Notify the Office of the Australian Information Commissioner (OAIC)
  • Take immediate steps to contain the breach and prevent further harm

Our third-party service providers are also required to notify us of any data breaches involving your information in accordance with their contractual obligations to us.


Storage and Security of Your Information

Your information is stored securely across our practice management and clinical systems. We take reasonable steps to protect your information from misuse, interference, loss, and unauthorised access, modification, or disclosure.

Clinical records are retained in accordance with Queensland Health records legislation. Adult patient records are generally kept for a minimum of 7 years from the date of last entry, or until the patient turns 25 years of age (whichever is later) for records relating to minors.

When information is no longer required and retention obligations have been met, we will take reasonable steps to destroy or de-identify it securely.


My Health Record

If you have a My Health Record, we may upload clinical documents such as shared health summaries or event summaries to your record where clinically appropriate and where you have not restricted access. You can control access to your My Health Record through the My Health Record system operated by the Australian Digital Health Agency. For more information, visit myhealthrecord.gov.au.


Accessing and Correcting Your Information

You have the right to access the personal information we hold about you and to request corrections if it is inaccurate, incomplete, or out of date.

To request access or correction, please contact us:

  • Phone: (07) 4786 2640
  • Email: info@bowenphysio.com.au
  • Post: 39 Powell St, Bowen QLD 4805

We will respond to your request within 30 days. In some circumstances we may be unable to provide access — for example, where doing so would impact the privacy of another individual or where an exception under the Privacy Act applies. We will explain our reasons in writing if this is the case.


Website and Cookies

Our website (www.bowenphysio.com.au) may collect non-identifying information such as browser type, pages visited, and time spent on the site through standard web analytics tools. This information is used to improve our website and is not linked to your personal identity.

Our website may use cookies. You can disable cookies through your browser settings, though this may affect website functionality.


NDIS Participants — Additional Rights

If you are an NDIS participant, you have additional rights under the NDIS Practice Standards and the NDIS Act 2013. In addition to the complaints process below, NDIS participants may raise privacy concerns with the NDIS Quality and Safeguards Commission:

The NDIS Commission’s own privacy policy is available at ndiscommission.gov.au/privacy.


Complaints

If you believe we have not handled your personal information in accordance with this policy or the Australian Privacy Principles, we encourage you to contact us first so we can attempt to resolve your concern:

  • Email: info@bowenphysio.com.au
  • Phone: (07) 4786 2640

We will investigate your complaint and respond within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):


Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or the systems we use. The current version will always be available on our website. Where changes are material, we will take reasonable steps to notify patients.


This policy was last reviewed in June 2026. It has been prepared to meet obligations under the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Information Privacy Act 2009 (Qld), and the NDIS Practice Standards.