Skip to main content
Golden RatioClinics
Privacy Policy

How we look after your health information

Your health information is the most sensitive category of personal information Australian law recognises. This policy tells you, in plain English, what we collect, why, where it sits, who can see it, and how to ask us to change or delete it.

Effective 13 May 2026 · Version 1.0

The short version

  • We only collect the personal and health information we need to provide your care.
  • We never sell your information. We do not use it for advertising.
  • Your health record is held in an Australian-hosted, encrypted clinical database.
  • You can ask us for a copy of your record, or to correct it, at any time — at no cost.
  • We notify you and the OAIC if a notifiable data breach affects your information.

1. Who this policy belongs to

Golden Ratio Clinics is a telehealth medical practice operated by Golden Ratio Clinics Pty Ltd (ACN 697 157 565), an Australian private company. In this policy, "we", "us" and "our" mean Golden Ratio Clinics Pty Ltd.

We are bound by the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles. As a health service provider we are also bound by the My Health Records Act 2012 (Cth), the Healthcare Identifiers Act 2010 (Cth), and the medical records obligations set by the Australian Health Practitioner Regulation Agency (Ahpra).

2. What we collect

We try to collect only the information that is genuinely necessary to deliver your care. In practice that falls into four categories.

2.1 Identity information

Full legal name, date of birth, residential address, Medicare card number (for identity verification under the Australian Privacy Principles), and where relevant your Individual Healthcare Identifier (IHI).

2.2 Contact information

Telephone number, email address, and a preferred method of contact. We use these to send appointment confirmations, secure clinical messages, and routine practice administration.

2.3 Health information

The full clinical record from each consultation: history taken by the nurse and doctor, any clinical assessments and plans, relevant test results you provide, correspondence to or from other practitioners, and a copy of any prescription written for you by a Golden Ratio doctor. Health information is classed as sensitive information under the Privacy Act and is given the strongest protections available.

2.4 Payment and account information

Records of fees charged and paid. Card details are not stored on our servers — payments are processed through a PCI-DSS compliant third-party gateway that returns only a transaction token to us.

2.5 Technical information

When you visit goldenratio.clinic we log standard server information (IP address, browser type, page visited, timestamp) for security and uptime monitoring. We do not run advertising trackers and do not sell this data.

3. Why we collect it

We collect personal and health information for the primary purpose of:

  • verifying your identity and Australian residency;
  • providing the clinical service you have booked — the pre-screen, the consultation, and any follow-up;
  • making the clinical record required of us under the Medical Board of Australia's record-keeping standards;
  • billing you and handling refunds under Australian Consumer Law;
  • meeting our reporting obligations to bodies such as the TGA where the law requires it.

We may also use information for secondary purposes that you would reasonably expect — for example, sending you a routine appointment reminder, or contacting you about practice changes that affect your care. We do not use your information for direct marketing of any kind without your express consent, and you can withdraw any such consent at any time.

4. Who can see your information

Inside the practice, access to your clinical record is limited to the clinicians and clinical-support staff directly involved in your care, on a least-privilege basis. Every staff member with access is bound by a confidentiality obligation that survives the end of their engagement with us.

Outside the practice, we disclose your information only in the following circumstances:

  • With your consent. For example, sending a clinical summary to your GP or a referral to a specialist you have nominated.
  • To dispense a prescription. Your prescription is sent securely to the pharmacy you nominate, including its mandatory clinical context.
  • To trusted service providers operating under written agreements that bind them to the APPs — clinical software providers, secure messaging providers, payment processors, and our independent auditors. These providers cannot use your information for their own purposes.
  • Where the law requires or authorises it — for example, a mandatory report to the TGA, a subpoena, a coronial inquiry, or where a child or another person is at serious risk of harm.

We do not disclose your information overseas without your consent, except where a sub-processor (such as a cloud security service) holds limited technical data outside Australia under arrangements that comply with APP 8.

5. Where your information sits, and how it is protected

Your clinical record is held in an Australian-hosted, encrypted database operated by Supabase, with data residency configured to an Australian region. Backups are encrypted at rest with AES-256 and in transit with TLS 1.3.

We use the technical and organisational safeguards expected of an Australian medical practice, including:

  • row-level security on the clinical database;
  • multi-factor authentication for every staff account;
  • a written information-security policy and breach-response plan;
  • logging and review of administrative access to clinical records;
  • routine internal audit and periodic external penetration testing.

Clinical records are retained for seven years from the date of the last consultation for an adult, or until the patient turns twenty-five for a minor — the timeframes required by the Medical Board of Australia. After that, records are securely destroyed or de-identified unless we are required by law to retain them longer.

6. My Health Record

If you have a My Health Record and have not opted out, your Golden Ratio doctor may, with your consent, upload a shared health summary or prescription record so other treating clinicians can see continuity of care.

You can manage your My Health Record settings at any time at www.myhealthrecord.gov.au — including suspending or cancelling the record, restricting what we can upload, or removing documents already uploaded.

7. Your rights over your information

You can ask us, at no cost, to:

  • give you a copy of the information we hold about you (APP 12);
  • correct anything in your record that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13);
  • tell you who we have given a copy of your information to in the last twelve months;
  • stop us using your information for any secondary purpose to which you object;
  • close your account and direct us to delete or de-identify information that we are not required by law to retain.

We will respond within thirty days. If we cannot fulfil a request — for example, where we are legally required to keep the information — we will tell you why in writing.

8. Cookies and website analytics

We use a small number of strictly necessary cookies to keep you signed in to the patient portal and to remember your preferences. We do not use third-party advertising cookies, do not run pixels for ad networks, and do not sell or share visit data with any third party for marketing purposes.

We use Vercel's privacy-friendly analytics on the marketing site (no individual user tracking, no cross-site identifiers, IPs hashed at edge). You can block analytics in your browser with no loss of site functionality.

9. Data breaches

We are subject to the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. If a data breach occurs that is likely to result in serious harm to any individual whose information we hold, we will notify the affected individuals and the Office of the Australian Information Commissioner as soon as practicable, and tell you what you can do to protect yourself.

10. Contacting our Privacy Officer

Privacy questions, access requests, and corrections go to our Privacy Officer:

Privacy Officer

Golden Ratio Clinics Pty Ltd

contact@goldenratio.clinic

08-800-42-420

If you are not satisfied with how we have handled a privacy issue, you can raise the matter with the Office of the Australian Information Commissioner:

Make a complaint to the OAIC · phone 1300 363 992.

11. Changes to this policy

We review this policy at least once a year and whenever our practices materially change. We will tell you about a material change either through a notice on this page or — for changes that affect how we use your information — through a direct message to your registered email. The version number and effective date at the top of this page are the authoritative record of the current version.