Legal
Privacy Policy
Effective date: 17 August 2026
Mindkit Psychological Services Proprietary Limited, ABN 99 687 719 473, trading as Mindkit Psychology, operates Mindkit.
Mindkit Psychological Services Proprietary Limited, ABN 99 687 719 473, trading as Mindkit Psychology, operates Mindkit. We provide psychology, assessment, coaching and related support from Brunswick East, Melbourne, and by telehealth across Australia.
This policy explains how we collect, hold, use, disclose and protect personal information, including health information. It applies to clients and prospective clients; parents, guardians and support people; referrers and professional contacts; job applicants; website users; and others who deal with Mindkit.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Health information handled in Victoria is also subject to the Health Records Act 2001 (Vic) and the Victorian Health Privacy Principles. Other state or territory health privacy laws may apply.
What information do we collect?
What we collect depends on how you interact with Mindkit. We collect information reasonably necessary for our work, or otherwise permitted or required by law.
- Identity and contact information, including your name, date of birth, pronouns, address, email, phone number and emergency contacts
- Health and sensitive information relevant to your service, including psychological and medical history, disability, medications, mental health, developmental and family history, clinically relevant identity information, and risk or safety information.
- Clinical records, including intake forms, questionnaires, interview and therapy notes, assessment data, test results, observations, formulations, recommendations, correspondence and reports.
- Information from another person or organisation, such as a parent, partner, family member, school, referrer, treating practitioner, employer, insurer, support coordinator or funder, where authorised or permitted by law.
- Funding, referral and billing information, including relevant Medicare details, NDIS or other funding information, referral documents, invoices, receipts and payment status.
- Communications with Mindkit, including email, phone, SMS, contact forms, portal messages, complaints and feedback.
- Information for commissioned workplace, insurer or medico-legal work.
- Website and technical information, including IP address, device and browser information, security logs, cookies and analytics used on the live website.
- Recruitment and contractor information if you apply to work with Mindkit or provide services to the practice.
Mindkit does not ordinarily keep audio or video recordings of therapy, assessment or feedback sessions. Some appointments may use an approved AI-assisted transcription tool to draft notes. If we intend to keep a recording, we will tell you beforehand and obtain any required consent.
How do we collect information?
We usually collect information directly from you when you contact us, complete forms, book or attend an appointment, communicate with the practice, make a payment, provide documents or use our website.
We may collect information from another person or organisation when you authorise it, it is reasonably necessary to provide the service, or the law permits or requires it. Examples include a GP referral, information from a parent or support person, school information for a child assessment, records from another practitioner, or instructions from an insurer or solicitor.
Where reasonable and practicable, we collect health information directly from the person it concerns.
Why do we collect, use and disclose information?
We use personal and health information for the purpose for which it was collected, related purposes you would reasonably expect, with your consent, or as permitted or required by law.
- Providing psychology, neuropsychological and other assessment, coaching, support and related services.
- Understanding the referral question, planning and conducting the work, interpreting information, preparing reports and recommendations, and providing feedback.
- Managing bookings, reminders, waitlists, administration, billing, rebates, deposits, refunds and third-party funding.
- Communicating with you and, where authorised, people involved in your care or support.
- Clinical supervision, consultation and professional quality activities.
- Meeting legal, regulatory, insurance, professional and record-keeping obligations.
- Responding to complaints, privacy requests, incidents, subpoenas, court orders and other lawful requirements.
- Protecting clients, staff and others where disclosure is permitted or required by law.
- Operating, securing and maintaining our website and practice systems.
- Recruitment, contractor management and ordinary business administration.
- Sending practice updates or marketing where permitted by law. We do not use health information for direct marketing without specific consent.
When can information be shared without my consent?
Psychological information is confidential, but confidentiality has legal limits. Mindkit may use or disclose information without consent where permitted or required by law, including to respond to a serious threat to life, health or safety; comply with a court order or subpoena; meet mandatory reporting obligations; or respond to another legal requirement.
Where practicable and lawful, we will discuss the disclosure with you first. We disclose only what is reasonably necessary.
Who may we disclose information to?
Depending on the service and your circumstances, we may disclose information to:
- Mindkit clinicians, authorised administrative staff and contractors who need it for their role.
- Clinical supervisors or consultants involved in supervision or case consultation.
- Health practitioners, schools, support providers or others involved in your care, with your consent or as permitted by law.
- Medicare, NDIS plan managers, insurers, employers, rehabilitation providers, legal representatives or other funders where needed for an authorised claim, report or commissioned service.
- Technology and professional service providers supporting practice management, telehealth, secure communication, document storage, payments, accounting, IT, cybersecurity, assessment or approved clinical documentation.
- Courts, tribunals, regulators, insurers, law-enforcement bodies or government agencies where authorised or required by law.
We do not sell client information.
How do we use software and AI-assisted tools?
Mindkit uses approved AI-assisted tools for clinical documentation, report development, written resources and related administration.
Heidi Health may transcribe appointments and draft clinical notes. BastionGPT may assist with identifiable clinical information, including organising, summarising, drafting or checking notes, correspondence and reports. Claude Enterprise may help prepare client handouts, worksheets, information sheets and other practice material. Identifiable client information is not entered into Claude Enterprise for this work.
We do not enter identifiable client information into general consumer AI tools. AI-assisted material is treated as a draft. The clinician or staff member reviews the source and output, and decides what is kept in the clinical record or provided in a document.
AI may support material used when a clinician considers an Autism or ADHD assessment, neuropsychological conclusions, treatment planning, support or funding recommendations, or other clinical questions. The responsible clinician makes the final interpretation and decision, and can change or reject AI-generated material. Mindkit does not authorise identifiable client information to train general-purpose AI models.
See our AI Use Policy for more detail about these tools and controls.
Where is information stored and how is it protected?
Mindkit stores information electronically and, where necessary, on paper. Halaxy is our main practice-management and clinical-record system and states that Australian practice data is stored in Australia. Other approved systems may hold information needed for clinical documentation, assessment, secure storage, communication, payments or accounting.
We use safeguards suited to sensitive health information, including access controls, authentication, staff confidentiality, software updates and incident-response procedures. No electronic system is completely secure. We take reasonable steps to prevent misuse, interference, loss and unauthorised access, modification or disclosure, and to respond to privacy or security incidents.
Do not send extensive clinical records through a general website contact form. We will provide an appropriate transfer method when records are needed.
Is information disclosed overseas?
Some approved providers may process or disclose personal information outside Australia. Under current arrangements, the United States is a likely recipient location. Provider support, related companies or subprocessors may also involve the United Kingdom and Canada.
Locations can change with provider infrastructure or subprocessors. Mindkit keeps a service-provider register and reviews data-location and disclosure arrangements when systems change.
For overseas disclosures, we take the steps required by applicable privacy law. Victorian health information is also handled under the transborder requirements of the Health Records Act 2001 (Vic).
What information does the website collect?
The website uses technical information and essential cookies to operate and secure the site, including IP address, browser and device information, security logs and basic access information.
The rebuilt website is planned to use Google Analytics 4. If enabled at launch, it may collect device and browser details, approximate location, pages viewed and site interactions. Clinical records and information in Mindkit’s clinical systems are not sent to Google Analytics.
Any non-essential analytics or tracking on the live site will be described in the cookie notice, which will be updated if the tracking setup changes.
How long do we keep health records?
Mindkit keeps health records for at least the period required by law, professional standards and insurance requirements.
Victorian private health records generally must be kept for at least seven years after the person last received a health service. If they were under 18 at that time, the record generally must be kept until they turn 25.
Some records must be kept longer for legal, professional, insurance or clinical reasons. When information can lawfully be destroyed and is no longer required, it is securely destroyed or permanently de-identified.
Can I access or correct my information?
You can ask to access personal or health information Mindkit holds about you, or correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
Email hello@mindkit.com.au. We may verify your identity or, if you act for someone else, your authority. We respond as soon as reasonably practicable and within any legally required timeframe.
Access may be refused or limited where allowed by law, including if it would unreasonably affect another person’s privacy or create a serious threat to life or health. If we refuse access or correction, we will explain why where permitted and outline complaint options.
A fee may apply to some access requests where permitted. Victorian health-record access fees are capped by the Health Records Regulations and updated periodically. Correction requests are free.
Can I use a pseudonym or stay anonymous?
You may contact Mindkit without giving your full identity where lawful and practical, such as for an initial general enquiry.
Clinical services usually require enough identifying information to keep an accurate health record, manage safety, communicate with you, process funding or rebates, and meet professional and legal obligations.
How do we handle information about children and young people?
Mindkit provides some services to children and teenagers. We consider the young person’s age, capacity, privacy and safety, and the role of parents or legal guardians, when handling information.
As part of consent and intake, we explain who will receive information and how privacy works for the service.
What happens if there is a data breach?
Mindkit has procedures for suspected privacy and security incidents.
If a breach is likely to cause serious harm and the Notifiable Data Breaches scheme applies, we assess it, act to reduce harm, and notify affected people and the Office of the Australian Information Commissioner when required.
How can I make a privacy complaint?
For concerns about Mindkit’s handling of personal or health information, email feedback@mindkit.com.au with “Privacy” in the subject. Tell us what happened and the outcome you want. We will acknowledge, investigate and respond within a reasonable time.
If unresolved, you may complain to the Office of the Australian Information Commissioner. For Victorian health information, you may also complain to the Victorian Health Complaints Commissioner. Other states or territories may have different regulators.
How do we update this policy?
We review this policy when our information-handling practices change and through regular privacy governance.
The current version and effective date are published on the Mindkit website. Material changes to client health-information handling will also appear in relevant collection notices, consent forms or service information.
How can I contact Mindkit about privacy?
Mindkit Psychology
Mindkit Psychological Services Proprietary Limited
ABN 99 687 719 473
Brunswick East, Victoria
Email: hello@mindkit.com.au
Privacy complaints: feedback@mindkit.com.au
Phone: (03) 7003 2743