Effective 4 August 2026Version 1.2

How we handle your information.

This policy explains how Éthos Melbourne (Éthos, we, us and our) collects, holds, uses and discloses personal information across our Brighton clinic, website and connected services.

At a glance
  • We collect only the information we reasonably need to answer enquiries, arrange and provide services, process payments and meet our legal obligations.
  • Health information receives additional protection and is not used for direct marketing without your express consent.
  • We do not sell your personal information.
  • You can ask us to access or correct information we hold about you, or make a privacy complaint.

1. Who we are and when this policy applies

This policy applies to Éthos Melbourne at 246 Bay Street, Brighton VIC 3186 and to personal information we handle when you browse our website, contact us, make a booking or purchase, visit our clinic, receive a service, communicate with our team or otherwise deal with us.

As a private health service provider, we handle personal and health information under the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Health Records Act 2001 (Vic) and the Victorian Health Privacy Principles.

2. The information we collect

The information we collect depends on how you interact with us. It may include:

  • Identity and contact details, such as your name, date of birth, address, email address, phone number and emergency or authorised-contact details.
  • Booking and transaction details, including appointment type, date and time, gift-card or package information, payment status, invoices, refunds and related communications. Payment providers process complete card details; we generally receive only the transaction result and limited payment details.
  • Health and treatment information, such as your health history, symptoms, scalp and hair concerns, medications, allergies, test results, referrals, treatment plans, progress notes, consent records and images taken for assessment or treatment with your knowledge.
  • Communications and preferences, including enquiries, feedback, complaints, appointment communications, accessibility needs and marketing choices.
  • Website and device information, such as IP address, browser and device type, pages requested, timestamps, referral information, security events and campaign identifiers contained in a link you use.

We do not ask for more health information than we reasonably need for our functions or services. If we ask for information that is optional, we will make that clear where practical.

3. How we collect information

We usually collect information directly from you through consultations and consent processes, our booking service, phone, email, payment processes and conversations with our team. Where health information is needed for your consultation, we will tell you how to provide it.

With your consent, authority or where permitted by law, we may also collect information from a parent, guardian or authorised representative; a referring or treating health professional; a diagnostic laboratory or other health service provider; and our booking, payment or communications providers.

You may browse our public website without telling us your name. You may also ask a general question anonymously or using a pseudonym where this is lawful and practical. We usually need accurate identifying information to safely provide clinical services, maintain health records and process bookings or payments.

4. Why we collect and use it

We collect, hold and use personal information where reasonably necessary to:

  • answer enquiries and provide requested follow-up;
  • assess suitability, plan and provide safe services, and maintain accurate treatment records;
  • manage appointments, reminders, waitlists, payments, gift cards, packages, refunds and accounts;
  • communicate with you, your authorised representative and, where appropriate, members of your treating team;
  • manage quality, safety, complaints, insurance and our legal or professional obligations;
  • protect our website, clinic, team and clients from fraud, misuse, security threats and unlawful activity; and
  • operate and improve our services using information that is aggregated or de-identified where practical.

If we cannot collect information that is necessary for a service, we may not be able to respond, complete a booking or safely provide that service. We will explain this where it may not be obvious.

5. Privacy Collection Notice — phone and email enquiries

Please keep ordinary email non-medical.

Do not email symptoms, diagnoses, medical history, medications, test results, treatment records or images. If your question relates to treatment or a clinical concern, call us first so we can explain the appropriate way to provide information. Our phone and email services are not monitored for urgent care. In an emergency, call 000.

When you call or email, we may collect your name and contact details, the content of your enquiry and practical notes needed to respond or arrange follow-up. A phone call may also provide caller-ID information depending on your device settings. We use this information to answer your enquiry and manage the requested follow-up.

Our Google Workspace service delivers and stores direct email enquiries in our access-controlled business inbox. Selecting the phone or email link on our website opens your device's telephone or email service; the website itself does not receive your phone number, email address or message through those links. Our website host still processes the ordinary technical request data described in section 9 when you visit the page.

We ordinarily keep a general phone or email enquiry for no more than 24 months after the last action on it, then delete or de-identify it, unless it becomes part of a client or patient record or we are required to keep it longer. If health information reaches us unexpectedly, we assess whether we are permitted and need to retain it; otherwise we delete or de-identify it where lawful and practical.

6. Health information and consent

Health information is sensitive information. We generally collect it with your consent and only where it is reasonably necessary to assess, arrange or provide a health service, maintain the related record, or meet a legal or professional obligation. Limited exceptions may apply where collection, use or disclosure is required or authorised by law or is necessary to address a serious threat to life, health or safety.

Where a client is under 18, we consider the young person’s capacity, the service being provided and the authority of a parent, guardian or representative. We collect and share only what is appropriate in the circumstances.

7. Marketing, photographs and testimonials

We may send service updates or offers where you have asked to receive them or where otherwise permitted by law. You can opt out at any time using the unsubscribe method in the message or by contacting us. We may retain a minimal suppression record so we can respect your choice.

We will not use health information for direct marketing without your express consent. We will also seek separate, specific permission before using an identifiable treatment image, testimonial or story in public marketing. Refusing or withdrawing marketing consent does not affect your access to our services.

8. When we disclose information

We may disclose information only where reasonably necessary for the purpose for which it was collected, for a directly related purpose you would reasonably expect, with your consent, or where required or authorised by law. Recipients may include:

  • authorised Éthos team members and practitioners who need it to perform their role;
  • your authorised representative and health professionals, diagnostic laboratories or other providers involved in your care;
  • service providers supporting our booking, website, email, payment, technology, records, professional advice, insurance and secure administration;
  • payment networks, banks and fraud-prevention providers for transactions; and
  • regulators, courts, law-enforcement bodies or other parties where disclosure is required or authorised by law.

Our current public website and transaction flow use the following core providers:

VercelWebsite hosting, delivery, security and processing of ordinary technical request data.
Google WorkspaceBusiness email delivery and storage, including direct email enquiries.
Acuity Scheduling / SquarespaceAppointments, client contact details, reminders, gift cards, packages and related communications.
StripeSecure package and gift-related payment processing, transaction management and fraud prevention.
PostHogPrivacy-limited website analytics used to understand visits, content engagement and booking or purchase handoffs.
Google FontsDelivery of website typefaces; Google may receive technical data including IP address, browser, device and the page requested.

When you choose an external booking, payment, map, press or social-media link, that service may collect information under its own privacy terms. We encourage you to review those terms before providing information.

9. Website technology, cookies and attribution

Our website host processes technical request data needed to deliver and secure the site. Embedded payment and scheduling services may use cookies or similar technology that is necessary for security, fraud prevention and the requested transaction.

We use PostHog product analytics to understand how our public website performs and which content helps visitors find a relevant service. This may record page views, approximate sessions, browser and device characteristics, performance measurements, referring source, campaign identifiers, section and scroll reach, interactions with links or buttons, and handoffs to booking, payment or other external services.

Our PostHog configuration does not use session recording, identify you by name, or intentionally collect contact details, health information, form values or payment details. We disable IP-address capture within PostHog and remove unsafe URL parameters and sensitive event properties before events are sent. PostHog may use a first-party cookie or browser storage identifier to distinguish an otherwise anonymous browser and calculate sessions. Where your browser sends a recognised Do Not Track signal, our analytics configuration is set not to capture these events.

If you arrive through a campaign link, the website may preserve limited referral or campaign identifiers in links to our pages and booking service so the source context is not lost. We do not currently deploy advertising pixels or use this website analytics data to build named patient profiles. If we introduce advertising technology, session recording, identification or materially different analytics, we will update our notices and provide choices or seek consent where required before using it.

10. Overseas and interstate processing

We operate in Victoria, but some technology providers and their subprocessors use infrastructure or support teams outside Victoria and Australia. Depending on the service and account configuration, information is likely to be processed in the United States, including website analytics processed through PostHog's US cloud, and, for some Stripe-related processing, India. It may also be processed in other countries where Google, Vercel, Squarespace, Stripe, PostHog or their authorised subprocessors operate.

Because global cloud and content-delivery networks change, it is not always practicable to name every processing location. Where required, we take reasonable steps through provider selection, contracts, security settings and access controls to protect information handled outside Australia. You may contact us for current information about the providers relevant to your information.

11. How we protect information

We take reasonable physical, technical and organisational steps to protect information from misuse, interference, loss and unauthorised access, modification or disclosure. These steps include access controls, secure accounts and authentication, encrypted connections, limiting access to people who need it, provider review, staff confidentiality and secure deletion or de-identification practices.

No digital or physical system is completely secure. Please do not send health information through ordinary email. Call us first and we will tell you how to provide information needed for a consultation.

12. How long we keep information

We retain information only for as long as it is needed for the purpose for which it was collected and any applicable legal, professional, insurance or dispute-resolution requirement.

  • Health records: as a Victorian private health service provider, we do not delete health information until at least seven years after the last occasion on which we provided a health service, or, if the information was collected while the person was under 18, until that person reaches 25—whichever period ends later.
  • General phone and email enquiries: ordinarily no more than 24 months after the last action, unless the enquiry becomes part of a client or patient record or must be retained longer.
  • Financial and transaction records: generally at least five years, and longer where they form part of a health record or another law requires it.
  • Technical and security information: for the shortest period reasonably needed to operate, investigate and protect the service, subject to provider settings and legal requirements.

When information is no longer required, we take reasonable steps to securely destroy or permanently de-identify it, subject to lawful backup and record-retention cycles.

13. Accessing or correcting your information

You may ask to access personal or health information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Contact our Privacy Officer using the details below and tell us what information you are seeking or want corrected.

We may need to verify your identity and authority before acting. We respond within the period required by applicable law and will explain any permitted refusal in writing, including available complaint options. We do not charge for a correction request. A limited, legally permitted fee may apply to some access requests; if so, we will explain it first.

14. Data breaches

If we suspect a data breach, we work to contain it, assess the likely impact, reduce harm and prevent recurrence. Where the Notifiable Data Breaches scheme or another law applies, we will notify the Office of the Australian Information Commissioner and affected individuals when required.

15. Questions and privacy complaints

Contact our Privacy Officer if you have a question, want to make a request or believe we have mishandled your information:

Privacy Officer · Éthos Melbourne
246 Bay Street, Brighton VIC 3186
info@ethosmelbourne.com.au
03 9593 6633

Please describe the issue and the outcome you are seeking. We will acknowledge the complaint, investigate it fairly, may ask for further information, and provide our response and reasons. We aim to resolve privacy complaints within 30 days; if we need longer, we will tell you why and provide an updated timeframe.

If you are not satisfied, you may contact the Office of the Australian Information Commissioner. For a complaint about health information in Victoria, you may also contact the Victorian Health Complaints Commissioner.

16. Changes to this policy

We may update this policy when our services, providers or legal obligations change. We will publish the current version here with its effective date and, where appropriate, give additional notice of a material change.