Privacy Policy
Tealwood holdings Pty Ltd
ABN 27 709 893 170 | Last updated 13 August 2026
Your privacy matters to us. This policy explains how TMJ Centre Melbourne collects, holds, uses, discloses and protects personal and health information, and how you can access your information, request a correction or make a privacy complaint.
1. About this policy
Tealwood holdings Pty Ltd (TMJ Centre Melbourne, we, us or our) is a Victorian private health service provider. We are committed to handling personal and health information in an open, respectful and secure way.
This policy applies to information handled through our Melbourne CBD clinic, consultations provided at 509 Princes Highway, Narre Warren, telehealth services, website, online booking system, patient and referral forms, TMJ Symptom Quiz, email communications and other clinic activities. It applies to patients, parents and guardians, carers, referrers, website visitors, prospective patients, practitioners, contractors and other people who interact with us.
We handle information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Health Records Act 2001 (Vic), the Health Privacy Principles (HPPs), the Spam Act 2003 (Cth) and other applicable laws.
This policy is a general explanation of our information-handling practices. It does not replace a collection notice provided for a particular form or service, clinical consent, or our separate AI Scribe Privacy and Collection Notice.
2. Personal and health information we collect
The information we collect depends on how you interact with us. It may include:
- Identity and contact information, such as your name, preferred name, date of birth, address, email address, telephone number, pronouns where provided, emergency contact, and parent, guardian or authorised representative details.
- Health and clinical information, such as your medical and dental history, medications, allergies, current and past symptoms, pain history, sleep and breathing information, relevant lifestyle factors, previous treatment and information provided by other health practitioners.
- Assessment and treatment information, including clinical notes, diagnoses and working diagnoses, examination findings, jaw measurements, questionnaire and screening results, photographs, radiographs, scans, imaging reports, appliance records, treatment plans, consent records, prescriptions, referrals, reports and treatment outcomes.
- Sensitive information that is relevant to safe care, which may include mental health information, disability information and other information collected through screening tools such as PHQ-4, GAD-7, STOP-BANG, Epworth Sleepiness Scale and the Jaw Functional Limitation Scale.
- Audio recordings, transcripts and draft documents created through an AI scribe when the required consent has been obtained.
- Appointment and administrative information, including bookings, attendance, cancellations, reminders, communications, complaints, billing, invoices, payment status and health fund or insurer information where relevant.
- Website and technical information, such as IP address, approximate location, browser and device type, pages visited, referral source, campaign or UTM information, cookie or similar identifiers and interactions with website features.
- Information submitted through our online booking system, TMJ Symptom Quiz, Patient Referral form, Have a Question Before Booking form and other patient forms.
- Communication and marketing preferences, email subscription status and, where enabled, information about whether an email was opened or a link was selected.
- Information relating to practitioners, contractors, job applicants and business contacts where reasonably necessary for our operations.
3. How we collect information
We usually collect personal and health information directly from you. We may collect it:
- during telephone, in-person or telehealth consultations and other communications with us;
- when you make a booking, complete a patient form, submit a referral, use the TMJ Symptom Quiz, make an enquiry, subscribe to educational emails or provide feedback;
- from a parent, guardian, carer, support person or authorised representative;
- from a referring dentist, GP, specialist, allied health practitioner, radiology provider, laboratory, hospital or another health service involved in your care;
- from Cliniko, Arlo, ActiveCampaign and other service providers acting for us; and
- automatically through cookies, Google Analytics 4, Google Tag Manager, server logs and similar technology when you use our website.
Where it is reasonable and practicable, we will collect information from you rather than from someone else. If we receive unsolicited personal information, we will decide whether we could lawfully have collected it. If not, we will destroy or de-identify it where lawful and reasonable to do so.
4. Why we collect, use and disclose information
We collect, hold, use and disclose information where reasonably necessary to:
- assess, diagnose, treat and support patients, including coordinating care with other practitioners;
- confirm identity, maintain accurate clinical records and support patient safety;
- manage bookings, reminders, telehealth, enquiries, referrals, reports, billing, payments and clinic administration;
- arrange imaging, laboratory work, oral appliances and other services connected with care;
- communicate with patients, parents, guardians, authorised representatives and referring or treating practitioners;
- prepare clinical documentation using an AI scribe when separate consent has been obtained;
- meet professional, insurance, accreditation, accounting, taxation, record-keeping, legal and regulatory obligations;
- manage feedback, complaints, incidents, claims, audits, quality assurance and service improvement;
- operate, secure, measure and improve our website and digital services;
- send educational or promotional communications where you have consented or where otherwise permitted by law; and
- protect the rights, safety and property of patients, staff, practitioners and the public.
5. Consent, choice and anonymity
We collect health and other sensitive information with consent unless collection is required or permitted by law. Consent may be express or implied from the circumstances, but we obtain express consent where the nature of the activity requires it, including before using an AI scribe.
You may choose not to provide particular information. However, if we cannot obtain information needed to identify you, assess risk, provide safe care or meet legal requirements, we may be unable to provide some or all services.
You may make a general enquiry without identifying yourself where lawful and practicable. Clinical care, bookings, prescriptions, reports, billing and record access will usually require us to confirm your identity.
6. When we disclose information
We use and disclose information for the primary purpose for which it was collected, for a directly related purpose you would reasonably expect, with your consent, or where required or permitted by law. We limit disclosure to information reasonably necessary in the circumstances.
We may disclose information to:
- dentists, allied health practitioners, administrative staff and contractors working with or for TMJ Centre Melbourne who need the information to perform their role;
- referring and treating practitioners, radiology providers, pathology or other diagnostic services, laboratories, appliance manufacturers, pharmacists, hospitals and other health services involved in your care;
- a parent, guardian, carer, support person, interpreter or authorised representative where you have agreed or where disclosure is otherwise lawful and appropriate;
- technology and service providers that support practice management, bookings, telehealth, clinical documentation, secure storage, website hosting, analytics, email delivery, communications, IT support, payment processing and cybersecurity;
- professional advisers, auditors, accountants, insurers and legal representatives where reasonably necessary and subject to confidentiality obligations;
- courts, regulators, government bodies, law enforcement agencies or other parties where required or authorised by law; and
- another entity in connection with a lawful sale, restructure or transfer of the practice, subject to appropriate confidentiality and privacy safeguards.
We do not sell or rent patient information. We do not disclose health information for direct marketing without express consent.
7. Cliniko practice-management system
We use Cliniko, operated by Red Guava Pty Ltd, to manage appointments, patient details, forms, communications, billing and clinical records. Cliniko acts as a service provider to us. Patient information is primarily hosted in Australia, although Cliniko uses approved subprocessors, including providers in Australia and the United States, for infrastructure, support, email, SMS and related functions.
Cliniko’s current subprocessor information is available from Cliniko’s subprocessor list.
If you accept this privacy policy during online booking, that acceptance records that the policy was made available to you. It does not replace consent required for a specific treatment, marketing activity or AI-scribe use.
8. Arlo AI scribe
We may use Arlo, operated by Medifusion Pro Ltd in Ireland, to assist with preparing consultation notes, referral letters and patient summaries. Arlo integrates with Cliniko. It processes patient data only on our instructions and does not provide medical advice, diagnosis or treatment decisions. A clinician reviews and approves all content before it becomes part of the clinical record.
When Arlo is proposed:
- we explain its use and request express consent before recording begins;
- everyone participating in the consultation must agree;
- you may decline or withdraw consent without disadvantage to your care;
- audio is encrypted in transit and at rest and is deleted after it is processed into text;
- transcripts and generated documents are retained for a limited period, typically up to 30 days unless configured otherwise, while the approved clinical record is retained in Cliniko under our usual record-retention requirements;
- patient data is not used by Arlo for advertising or to train general AI models; and
- Australian regional processing is selected, although limited access or processing may occur in Ireland or through approved service providers for support, security or service delivery.
Further details are provided in our separate AI Scribe Privacy and Collection Notice before or when consent is requested.
Arlo’s own privacy information is available in the Arlo Privacy Policy.
9. Website forms, symptom quiz, analytics and cookies
Our website includes online bookings, the TMJ Symptom Quiz, the Patient Referral form and the Have a Question Before Booking form. Information submitted through these services may include health information. This policy should be read with any short collection notice displayed at the point the information is entered.
We use Google Analytics 4 to understand how visitors find and use the website, and Google Tag Manager to manage approved website tags. These services may collect technical information such as device and browser details, approximate location, referral source, pages viewed, interactions and cookie or similar identifiers. IP addresses may be processed to provide security or approximate-location functions in accordance with the provider’s settings.
We do not intentionally send names, email addresses, telephone numbers, clinical notes, form contents or individual symptom-quiz answers to Google Analytics. Website analytics is used to measure general website performance and events such as completion of a booking process.
You can manage cookies through your browser and through any cookie controls made available on our website. Blocking some cookies may affect website functionality. Google may process analytics information in the United States and other countries in which it or its service providers operate.
More information is available in the Google Privacy Policy.
10. Educational and promotional emails
We use ActiveCampaign to manage email subscriptions, educational sequences and promotional emails. ActiveCampaign may process your name, email address, subscription preferences, campaign source and information about email delivery, opens or link selections.
We send promotional emails where you have consented or where otherwise permitted by law. Each promotional email provides an unsubscribe option. Unsubscribing from marketing will not stop essential communications about appointments, care, safety, billing or services you have requested. We may retain a suppression record so that your opt-out is respected.
Health information, including symptom-quiz responses, will only be used to personalise promotional communications where this has been clearly explained and express consent has been obtained.
ActiveCampaign is based in the United States. Depending on the account region and the functions used, contact data may be primarily hosted in Australia but may be accessed or processed in the United States and other countries where ActiveCampaign and its approved subprocessors operate.
ActiveCampaign’s current processing locations and providers are described in its multi-regional hosting policy and subprocessor list.
11. Telehealth
For appropriate consultations, we may provide telehealth using an approved platform. Telehealth may involve the transmission of identity, contact, appointment and health information through the platform. We take reasonable steps to use secure services, but privacy can also depend on the participant’s device, internet connection and surroundings.
Telehealth consultations are not recorded unless we explain the proposed recording and obtain any consent required. If Arlo is used during telehealth, the AI-scribe requirements in section 8 apply.
12. Children and young people
We provide services to some patients under 18. We may collect information from the young person and from a parent, guardian, carer, referrer, school or other practitioner where relevant and lawful.
Consent, access and disclosure decisions are made according to the young person’s age, maturity, decision-making capacity, clinical circumstances, safety and applicable law. Where appropriate, we will involve the young person in decisions about their information and explain privacy matters in a way they can understand. A parent or guardian does not automatically have unrestricted access in every circumstance.
13. Overseas disclosure and processing
Some service providers and their subprocessors are located or operate outside Australia. The overseas countries most likely to receive or access information through our current systems include the United States and Ireland. Google, ActiveCampaign, Cliniko, Arlo and other approved providers may also use subprocessors in additional countries listed in their current privacy or subprocessor information.
Before disclosing personal information overseas, we take reasonable steps required by the APPs to ensure appropriate privacy safeguards apply, unless an exception is available. The privacy protections and legal rights in another country may differ from those in Australia.
14. How we store and protect information
We may hold information in electronic clinical and business systems, secure cloud services, email systems, encrypted devices and, where applicable, physical records. We take reasonable steps to protect information from misuse, interference, loss and unauthorised access, modification or disclosure.
Our safeguards may include:
- role-based access and limiting access to people who need the information for their work;
- passwords, multi-factor authentication and authentication safeguards;
- encryption in transit and at rest where supported by the service;
- secure backups, software updates, monitoring and incident-response procedures;
- staff and contractor confidentiality obligations and privacy training;
- locked or access-controlled storage for physical records; and
- password protection or secure transfer methods for sensitive clinical documents where appropriate, including sending passwords separately.
No electronic or physical system can be guaranteed to be completely secure. If you send sensitive information by ordinary email or another method outside our secure systems, there may be additional risks. Please contact us if you need help choosing a suitable way to send information.
15. Retention and deletion
We retain health information for the periods required by the Health Records Act 2001 (Vic) and other laws. In general, a Victorian private health service provider must not delete health information until more than seven years after the last occasion on which it provided a health service to the individual. If the information was collected while the individual was a child, it must also be retained until after the individual turns 25. The later date applies.
Other personal information is retained for as long as reasonably necessary for the purpose for which it was collected and for applicable legal, insurance, accounting, security and dispute-resolution requirements. When information is no longer required and deletion is lawful, we take reasonable steps to destroy it securely or permanently de-identify it.
Temporary Arlo audio, transcripts and draft documents are handled as described in section 8. Marketing information is retained while you remain subscribed and as needed to maintain an unsubscribe or suppression record.
16. Access, correction and transfer of records
You may ask whether we hold information about you, request access to your personal or health information, ask us to correct information you believe is inaccurate, incomplete, out of date or misleading, or ask us to provide relevant health information to another health service provider.
Contact our Privacy Officer using the details in section 20. We may need to verify your identity and clarify the information requested. We will respond within a reasonable period and provide access in an appropriate form where required. We do not charge a fee for making a request, but we may charge reasonable costs or a fee up to the prescribed Victorian maximum where permitted by law.
Access or correction may be refused or limited in circumstances permitted by law, including where access would create a serious threat, affect another person’s privacy, reveal confidential information or relate to legal proceedings. If we refuse a request, we will generally explain the reasons and available complaint options. Correcting a clinical record may involve adding an amendment or statement rather than deleting the original entry where record integrity and retention laws require it.
17. Privacy and data breaches
We maintain processes to identify, contain, assess and respond to suspected privacy or data breaches. If a breach is likely to result in serious harm and the Notifiable Data Breaches scheme applies, we will notify affected individuals and the Office of the Australian Information Commissioner as required. We may also report or seek guidance from the Victorian Health Complaints Commissioner or other authorities where appropriate.
18. Privacy enquiries and complaints
If you have a privacy question or complaint, please contact our Privacy Officer. It is helpful to describe what happened, the information involved, relevant dates and the outcome you are seeking. We will treat the matter respectfully, investigate it and aim to respond within 30 days.
If you are not satisfied with our response, you may contact the Victorian Health Complaints Commissioner for a complaint involving health information or a Victorian health service, or the Office of the Australian Information Commissioner for a complaint under the Privacy Act.
Victorian Health Complaints Commissioner: Make a complaint | 1300 582 113
Office of the Australian Information Commissioner: Privacy complaints | 1300 363 992
19. Changes to this policy
We review this policy regularly and when our services, technology providers or legal obligations change. The current version will be published on our website with its last updated date. Material changes may also be communicated through other appropriate channels.
20. Contact us
Privacy Officer
Tealwood holdings Pty Ltd
ABN 27 709 893 170
Suite 901, 227 Collins Street, Melbourne VIC 3000
Narre Warren consulting location: 509 Princes Highway, Narre Warren VIC 3805
Telephone: (03) 9417 4038
Email: info@tmjcentremelbourne.com.au
Website: www.tmjcentremelbourne.com.au