Privacy Policy
Active Health Partners respects your privacy.
We collect, hold, use and disclose personal information for the purpose of providing our workplace health, safety and wellbeing Services, operating our digital platforms, responding to enquiries, managing client relationships and conducting our business activities.
Our Services are described on our website at www.activehealthpartners.com.au/overview (the Website).
We only collect personal information that is reasonably necessary for our functions and activities or where otherwise permitted or required by law.
We may disclose personal information to our employees, contractors, technology providers, cloud storage providers, professional advisers, insurers, auditors, accountants and other service providers who assist us to operate our business and deliver our Services.
Where Services are provided to an employer or other organisation, personal information may also be disclosed to that employer or organisation in accordance with the purpose of the Service.
We may use business contact information to communicate with clients and prospective clients about our Services where permitted by law. We do not use sensitive or health information collected through employer-sponsored workplace Services for direct marketing.
Our Privacy Policy contains further details regarding how you can access or correct information we hold about you, how you can make a privacy-related complaint, how that complaint will be dealt with and the extent to which your information may be disclosed to overseas recipients.
We may change our Privacy Policy from time to time by publishing changes to it on our Website. We encourage you to check our Website periodically to ensure that you are aware of our current Privacy Policy.
1. INTRODUCTION
Active Health Partners respects and upholds your rights under the Australian Privacy Principles contained in the Privacy Act 1988 (Cth).
This Privacy Policy explains what personal information we collect, how we collect and hold it, how we use it, who we disclose it to and how you can access or correct your personal information or make a privacy complaint.
This Privacy Policy applies to information collected through:
our Website;
the Hybrid Work Hub platform;
our workplace health, safety and wellbeing Services;
training, assessments, consulting and educational Services;
communications with clients, prospective clients, users and other individuals; and
our general business operations.
Where applicable, we will also take reasonable steps to provide protections aligned with the General Data Protection Regulation (GDPR) for individuals located in the European Union or other applicable overseas privacy laws.
2. DEFINITIONS
Cookies means a small text file that is stored on a user’s device for record-keeping, functionality, analytics or security purposes.
Client means an organisation or individual that engages Active Health Partners to provide Services.
De-identified Information means information that no longer identifies, or is reasonably capable of identifying, an individual.
Employer means an organisation that provides employees, contractors or other authorised users with access to our Services.
Hybrid Work Hub or HWH means Active Health Partners’ digital workplace health, safety and wellbeing platform.
Information means either Personal Information or Non-personal Information.
Non-personal Information means information that does not identify an individual or is not reasonably capable of identifying an individual.
Personal Information has the same meaning as under the Privacy Act and generally means information or an opinion about an identified individual or an individual who is reasonably identifiable.
Personal Information may include information such as name, address, email address, telephone number, employment-related details, payment information, photographs, assessment responses and other details provided to us when using our Services.
Sensitive Information has the same meaning as under the Privacy Act and includes health information and other categories of Personal Information that require additional protection.
Services means the workplace health, safety, wellbeing, training, education, consulting, assessment and digital platform services provided by Active Health Partners.
User means an individual authorised to access or use the Hybrid Work Hub or another Active Health Partners system.
3. WHY DOES ACTIVE HEALTH PARTNERS COLLECT YOUR PERSONAL INFORMATION?
Active Health Partners collects Personal Information to provide and administer its Services.
This includes information you provide when you:
register or access our Services;
use the Hybrid Work Hub;
complete training, questionnaires, checklists or assessments;
upload photographs or documents;
communicate with us;
interact with our Website;
complete transactions;
request support; or
contact us with an enquiry.
We may collect, hold, use and disclose your Personal Information to:
enable you to access and use our Services;
provide training, assessments, reports and recommendations;
provide Services to a Client or Employer;
generate individual and aggregated reports;
identify and categorise reported workplace issues or risk indicators;
communicate with you and provide support;
operate, maintain and secure our systems;
improve our Services and user experience;
manage client relationships, billing and business operations;
comply with legal, contractual, insurance and regulatory obligations;
investigate complaints, disputes or security incidents; and
conduct other activities with your consent or as permitted by law.
We only collect Personal Information where you consent, where it is reasonably necessary for our functions and activities or where collection is otherwise permitted or required by law.
4. SERVICES PROVIDED TO EMPLOYERS
Active Health Partners provides Services to organisations, including Employers, which may involve collecting Personal Information and Sensitive Information from employees, contractors or other authorised Users.
The Employer generally determines:
which individuals are asked or required to participate;
the workplace purpose for which the Service is used;
which Services or platform features are made available;
which representatives of the Employer receive reports or information; and
what workplace action is taken after reviewing the information.
Active Health Partners collects, holds, processes and discloses information as reasonably necessary to provide and administer the Services requested by the Employer.
Personal Information collected through these Services may be provided or made available to the Employer.
This may include:
individual responses;
uploaded photographs;
training and assessment completion information;
reports;
recommendations;
flagged or categorised responses; and
aggregated reporting.
Active Health Partners does not control how an Employer uses Personal Information after it has been provided to or accessed by the Employer.
The Employer is responsible for managing that information in accordance with its own privacy, employment, workplace health and safety and other legal obligations.
Individuals may contact either Active Health Partners or their Employer regarding information held or used by that party.
5. HOW DOES ACTIVE HEALTH PARTNERS COLLECT AND HOLD YOUR PERSONAL INFORMATION?
We generally collect Personal Information directly from you.
We may also collect Personal Information from:
your Employer or another Client;
an authorised representative;
publicly available sources;
enquiries and events;
our Website;
digital forms and questionnaires;
training and assessment Services;
third-party systems used to deliver our Services;
technology and service providers; or
other parties where authorised or permitted by law.
We may collect Personal Information through email, telephone, video conference, in-person communication or through the Hybrid Work Hub and other online systems.
Where practicable, we collect Personal Information directly from the individual concerned.
Where information is provided by an Employer or other Client, that organisation is responsible for ensuring that it is authorised to provide the information to us.
If we receive unsolicited Personal Information, we will determine whether the information could have been collected by us lawfully.
Where it could not have been collected, we will take reasonable steps to destroy or de-identify it, unless we are required or authorised by law to retain it.
6. WHAT PERSONAL INFORMATION DOES ACTIVE HEALTH PARTNERS COLLECT?
We collect information relating to our commercial clients and their representatives, as well as individuals who provide information as part of Services delivered to those clients, including employees and contractors.
This may include:
name;
email address;
telephone number;
job title and organisation;
work address;
employment-related information;
billing and transaction information;
communications and correspondence;
training participation and completion information;
workstation, furniture and equipment information;
information about work habits and working arrangements;
information about an individual’s immediate work environment;
uploaded photographs or documents;
technical support information;
device, browser and system information;
IP address and system logs;
assessment responses;
reports and recommendations; and
information generated through use of our Services.
We may also collect Sensitive Information, including health-related information, where it is reasonably necessary to deliver our Services and where consent has been provided or collection is otherwise permitted or required by law.
Sensitive Information may include information about:
physical discomfort;
injury;
functional limitations;
health or wellbeing;
workplace connectedness;
stress; and
potential psychosocial risk indicators.
7. WHAT DOES ACTIVE HEALTH PARTNERS DO WITH YOUR PERSONAL INFORMATION?
We use Personal Information to:
deliver and administer our Services;
provide access to the Hybrid Work Hub;
generate reports and recommendations;
provide information to a Client or Employer;
identify and categorise employee-reported issues or risk indicators;
provide training, support and technical assistance;
communicate with users and clients;
manage billing, contracts and business relationships;
operate, maintain and secure our systems;
investigate misuse, fraud or security incidents;
conduct quality assurance;
comply with legal and regulatory requirements;
manage complaints, disputes and legal claims; and
improve our Services and user experience.
Some reports, recommendations, categories or flags may be generated automatically using predetermined rules based on information submitted through the platform.
These outputs:
depend on the accuracy and completeness of the information provided;
may not be manually reviewed by an Active Health Partners practitioner or consultant;
do not independently verify a User’s work environment or circumstances;
do not constitute a medical diagnosis; and
do not constitute a formal workplace risk assessment.
We may analyse aggregated and De-identified Information to:
improve our Services;
improve platform functionality and user experience;
identify general workplace trends;
develop benchmarking insights;
undertake research and analysis;
develop reports and educational materials; and
support product and service improvement.
We will take reasonable steps to ensure that this information does not identify an individual or Client.
8. WHO WILL ACTIVE HEALTH PARTNERS DISCLOSE YOUR PERSONAL INFORMATION TO?
We may disclose Personal Information to:
the Client or Employer that arranged or authorised the Service;
our employees, directors, contractors and authorised personnel;
technology, cloud storage and hosting providers;
software and platform providers;
communications and technical support providers;
payment and invoicing providers;
data analytics and reporting providers;
consultants and subcontractors assisting us to provide the Services;
lawyers, auditors, insurers, accountants and other professional advisers;
regulators, courts, law enforcement bodies and government agencies where required or authorised by law;
parties involved in a proposed or actual business sale, restructure, investment or corporate transaction; and
other recipients with your consent.
Where we disclose information to service providers, we take reasonable steps to require those providers to use the information only for authorised purposes and to apply appropriate confidentiality and security measures.
Sensitive Information will only be disclosed:
for the primary purpose for which it was collected;
for a directly related purpose that you would reasonably expect;
with your consent; or
where permitted or required by law.
9. OPENNESS
You may request access to, or correction of, Personal Information we hold about you by contacting us.
We may ask you to:
make the request in writing;
provide sufficient information to identify the relevant records; and
verify your identity.
We will respond within a reasonable period.
We may refuse access where permitted by law, including where access would:
unreasonably affect another individual’s privacy;
pose a serious threat to a person’s life, health or safety;
prejudice an investigation;
relate to anticipated or existing legal proceedings;
reveal commercially sensitive evaluative information; or
otherwise fall within a lawful exception.
Where access or correction is refused, we will generally provide reasons and information about available complaint mechanisms, unless it would be unreasonable or unlawful to do so.
Where information has already been provided to an Employer or Client, you may also need to contact that organisation to request access to or correction of the information it holds.
10. MARKETING
We may contact commercial clients and prospective clients with information about our Services, resources, events and developments where permitted by law.
We may use business contact information for these purposes.
We do not use health information, wellbeing responses or other Sensitive Information collected through Employer-sponsored Services for direct marketing.
You may opt out of marketing communications at any time by:
using the unsubscribe function in the communication; or
contacting us using the details set out in this Privacy Policy.
We will take reasonable steps to action an opt-out request promptly.
11. NON-PERSONAL INFORMATION
We may collect Non-personal Information relating to Website and platform usage.
This may include:
device type;
browser type;
operating system;
pages accessed;
links selected;
date and time of access;
referring website;
general usage patterns; and
diagnostic and security information.
We may use this information in aggregated form to:
administer our Website and systems;
improve our Services;
understand usage patterns;
diagnose technical issues;
maintain security; and
improve the user experience.
12. QUESTIONS & COMPLAINTS
If you have any questions or complaints regarding this Privacy Policy or how we handle Personal Information, please contact:
Daniel Grynberg
Active Health Partners
South Eastern Sports & Spinal Clinic Pty Ltd
Email: daniel@activehealthpartners.com.au
Phone: (03) 9989 4646
Postal address: 74 Mackie Rd, Bentleigh East, VIC, 3165
A privacy complaint should include:
your contact details;
a description of the privacy concern;
relevant dates and circumstances; and
the outcome you are seeking.
We will:
acknowledge your complaint within a reasonable period;
assess and investigate the matter;
request further information where required;
provide a response within a reasonable period; and
explain any corrective or preventative action we propose to take.
We aim to provide a substantive response within 30 days, although complex matters may require additional time.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
Where the complaint principally concerns how an Employer has used information provided through our Services, you may also raise the complaint directly with that Employer.
13. SECURITY OF INFORMATION
We take reasonable technical, physical and organisational steps to protect Personal Information from:
misuse;
interference;
loss;
unauthorised access;
unauthorised modification; and
unauthorised disclosure.
These steps may include:
access controls and authentication;
encryption in transit or at rest;
restricted administrative access;
security monitoring;
backups;
confidentiality obligations;
provider due diligence;
incident response procedures; and
periodic reviews of systems and access permissions.
No data transmission, cloud service or storage system can be guaranteed to be completely secure or continuously available.
14. RETENTION & DESTRUCTION OF PERSONAL INFORMATION
We retain Personal Information only for as long as reasonably necessary to:
provide the relevant Services;
meet our contractual obligations;
comply with legal, regulatory, accounting, insurance or reporting requirements;
manage complaints, disputes or legal claims;
maintain appropriate security and business records; or
fulfil another lawful purpose for which the information is held.
Retention periods may differ depending on:
the type of information;
the Service provided;
Client instructions;
contractual arrangements;
applicable legal requirements; and
whether a complaint, incident or legal claim is anticipated or underway.
Where Personal Information is no longer required, we will take reasonable steps to securely destroy or de-identify it unless retention is required or authorised by law.
Information held through the Hybrid Work Hub may also be retained, returned, hosted or deleted in accordance with the applicable agreement between Active Health Partners and the relevant Client.
De-identified or aggregated information may be retained after identifiable information has been deleted.
15. LINKS
Our Website or Services may contain links to third-party websites or services.
We are not responsible for the privacy, security or information-handling practices of third-party websites or services that are not operated or controlled by us.
You should review the relevant privacy policy before providing Personal Information to a third party.
16. COOKIES
We use cookies and similar technologies to:
enable Website and platform functionality;
remember preferences;
understand Website usage;
diagnose technical faults;
maintain security;
improve Website content; and
measure the effectiveness of communications or campaigns.
You may be able to disable or manage cookies through your browser settings.
Disabling some cookies may affect the functionality of our Website or Services.
We may use third-party analytics or technology providers. Information collected by those providers may be handled in accordance with their own privacy policies and our contractual arrangements with them.
17. WEBSITE DATA
When you visit our Website, we may collect technical information such as:
IP address;
browser type;
device type;
operating system;
pages accessed;
links selected;
referring website;
date and time of access;
approximate location derived from technical information; and
time spent on the Website.
This information is used for administrative, analytical, security and service improvement purposes.
18. TRANSFER TO OTHER COUNTRIES
We may disclose, store, process or allow access to Personal Information through overseas technology, cloud, communications, analytics or support providers where reasonably necessary to deliver our Services.
The countries in which overseas recipients are likely to be located may include:
[insert confirmed countries].
Where required by law, we will take reasonable steps to ensure overseas recipients handle Personal Information in a manner consistent with the Australian Privacy Principles.
In some circumstances, Active Health Partners may remain accountable under the Privacy Act for the acts or practices of an overseas recipient.
You may contact us for further information about overseas disclosures relevant to a particular Service.
19. DATA BREACHES
We maintain procedures for responding to suspected or confirmed data breaches.
If a data breach occurs, we may:
take steps to contain the breach;
investigate what occurred;
assess the type of information involved;
assess the risk of harm;
take remedial action;
work with affected Clients and service providers; and
review our safeguards to reduce the risk of recurrence.
Where a data breach is likely to result in serious harm and notification is required under the Notifiable Data Breaches scheme or another applicable law, we will take reasonable steps to notify affected individuals and the relevant regulator.
Where information is held or processed in connection with Services provided to a Client, we may coordinate the data breach response with that Client.
20. MISCELLANEOUS
We may update this Privacy Policy from time to time to reflect:
changes to our Services;
changes to our technology or service providers;
changes to our information-handling practices; or
legal and regulatory developments.
The updated version will be published on our Website with a revised effective date.
Where a material change affects how previously collected Personal Information will be used or disclosed, we will take any additional steps required by law, which may include providing further notice or obtaining consent.
This Privacy Policy is intended to comply with applicable privacy laws.
Nothing in this Privacy Policy excludes, restricts or modifies any rights or remedies available under applicable privacy or consumer protection laws.
Effective date: 01/07/2026
Version: V3.0