Movement 3 Clinical Exercise and Exercise Science
Operated by Tempus Group Pty Ltd as trustee for the Tempus Health Trust · ABN 97 404 050 519
Effective date: 19 June 2026 · Version: 1.0 · Next review: 1 June 2027
Movement 3 Clinical Exercise and Exercise Science (“Movement 3”, “M3”, “we”, “us”, “our”) is a clinical exercise physiology practice. We are operated by Tempus Group Pty Ltd as trustee for the Tempus Health Trust (ABN 97 404 050 519).
We collect information about your health in order to provide you with exercise physiology services. We understand that this is some of the most personal information you will ever share with anyone, and we take the responsibility seriously.
This policy explains, in plain language:
This policy applies to everyone whose personal information we handle — clients, prospective clients, people who contact us through our website or social media, referrers, carers and substitute decision-makers, contractors, and job applicants.
This policy is published free of charge at movement3.com.au/privacy. If you would like it in another format — printed, large print, or read aloud to you — please ask and we will provide it at no cost.
We are bound by the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs) set out in that Act.
Many small businesses in Australia are exempt from the Privacy Act because they turn over less than $3 million a year. That exemption does not apply to us. Any business that provides a health service and holds health information is covered by the Privacy Act regardless of its size. As a clinical exercise physiology practice, we are a health service provider, and we are fully bound.
Queensland does not have separate private-sector health records legislation. The Information Privacy Act 2009 (Qld) applies to Queensland government agencies and public hospitals, not to private practices like ours. Our obligations to you come from Commonwealth law.
We are also bound by, and this policy should be read alongside:
| Instrument | What it governs |
|---|---|
| My Health Records Act 2012 (Cth) | How we view, upload to and handle information in the My Health Record system |
| Healthcare Identifiers Act 2010 (Cth) | How we use Individual Healthcare Identifiers (IHIs) |
| Notifiable Data Breaches scheme (Part IIIC, Privacy Act) | What we must do if your information is compromised |
| ESSA Code of Professional Conduct and Ethical Practice | Our professional obligations on confidentiality, consent, record-keeping and the responsible use of technology and AI (clauses 2.9 and 3.2 in particular) |
| National Code of Conduct for Health Care Workers (Queensland) | The minimum standards of conduct required of us as an unregistered health profession in Queensland |
| Spam Act 2003 (Cth) and Do Not Call Register Act 2006 (Cth) | Our electronic marketing and telemarketing |
| Statutory tort for serious invasions of privacy (Schedule 2, Privacy Act) | Your right to sue for a serious invasion of privacy, in force since June 2025 |
| Child Protection Act 1999 (Qld) and related child safety laws | Our mandatory reporting obligations |
| Workers’ Compensation and Rehabilitation Act 2003 (Qld) | Information we must provide to insurers for workers’ compensation claims |
| National Disability Insurance Scheme Act 2013 (Cth) and the NDIS Code of Conduct | Our obligations to NDIS participants |
Personal information is any information or opinion about an identified individual, or an individual who is reasonably identifiable — whether or not it is true, and whether or not it is recorded in a material form.
Sensitive information is a special category of personal information that attracts a higher level of protection under the Privacy Act. It includes health information, racial or ethnic origin, religious beliefs, sexual orientation, and criminal record.
Health information includes information about your physical or mental health, any disability, your health services history, and information collected while providing a health service to you. Almost everything in your clinical file is health information.
In practice, this means: the great majority of what we hold about you is sensitive information. We generally cannot collect it without your consent, we cannot use it for a purpose other than the one we collected it for without your consent, and we must take active steps to protect it.
Your name and any previous names, date of birth, gender, address, phone numbers, email address, emergency contact details, occupation and employer, preferred language, and — where relevant to your care or to how we should communicate with you — your cultural background, Aboriginal or Torres Strait Islander status, and interpreter or accessibility needs.
Where relevant to your funding stream, we collect:
We handle these strictly in accordance with APP 9. We do not adopt a government identifier as our own way of identifying you in our systems — your file is identified by our own client number — and we only use or disclose these identifiers where the law permits or requires it, or where it is reasonably necessary to verify your identity or to claim a payment on your behalf.
We use VALD human measurement technology (including ForceDecks force plates and DynaMo dynamometry) to conduct objective physical testing. This generates data including force production, asymmetry between limbs, rate of force development, jump height, grip and isometric strength, balance and postural control measures, and comparisons of your results over time and against normative reference data.
This is health information about you.
With your specific consent, we may record:
Consent for clinical recording is separate from consent for marketing use. We will never use your image, video, voice, testimonial or case details in marketing, social media, on our website or in professional education without your separate, express, written consent, obtained specifically for that purpose. You can withdraw that consent at any time, and we will remove the material from anything we control going forward.
If you choose to connect a wearable device or fitness application — such as a Garmin, Apple Watch, Fitbit, Whoop, Strava account or Apple Health — to the programme delivery platform we use, we will receive data from it. This may include step counts, heart rate, heart rate variability, sleep data, workout history, GPS-derived activity data, and body composition measurements.
Connecting a device is entirely voluntary and is not a condition of receiving services from us. You control the connection and can disconnect it at any time through your own device or account settings. Data that stays on your device and is never shared through the platform is not collected by us.
Bank account or card details for direct debit and payment, billing address, invoice and payment history, outstanding balances, funding approvals and claim statuses, and correspondence about accounts.
We do not store full card or bank account numbers ourselves. Payment details are held by our payment processors under their own security standards:
You should be aware that under Ezidebit’s terms, if an amount owing is not paid after demand, Ezidebit may commence collections or enforcement action and may report a default to a credit reporting agency. This is Ezidebit’s process, not ours, and we would always contact you about an overdue account before it reached that point.
When you visit our website, complete an enquiry form, book online, subscribe to our email list, or interact with our social media:
Be aware that if you describe your health condition in a website enquiry form or a social media message, you are giving us health information through a channel that is not a clinical record system. We will move it into our clinical system promptly, but we would encourage you to keep initial enquiries general and save the detail for your consultation.
Sometimes your clinical record will necessarily contain information about other people — your family medical history, the details of a carer or substitute decision-maker, or an emergency contact. We collect only what is necessary and we treat that information with the same care as your own.
We collect professional contact details, qualifications, registration and insurance details from referrers, contractors and job applicants, and the information necessary to engage and pay contractors or assess applications.
This is our preference and our default. We collect information from you in your consultations, in intake and health screening forms, over the phone, by email or SMS, through our website and online booking, and through the client app we use for programme delivery.
We frequently collect information about you from third parties, because coordinated care requires it. These include:
Where we collect information about you from someone else, we will take reasonable steps to make sure you know we have done so, and why — unless you have already been told, or unless telling you would be inconsistent with the law or would pose a serious threat to someone’s life, health or safety.
If we receive personal information about you that we did not ask for and that we could not lawfully have collected ourselves, we will destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
You are not obliged to give us any particular piece of information. However, exercise physiology is a clinical service and some information is genuinely necessary for us to work safely. If you decline to provide it, we may not be able to assess you accurately, may not be able to design a safe programme, may not be able to claim on your behalf from Medicare, DVA, NDIS or an insurer, or in some cases may not be able to provide services at all. We will tell you clearly if that is the case, and why.
Under APP 2, you have the option of dealing with us anonymously or under a pseudonym where it is lawful and practicable.
In practice: you can make a general enquiry, ask about our services, ask a general question about exercise and health, or attend a public education session, without telling us who you are.
Once you become a client, this is no longer practicable. We cannot lawfully deliver a clinical health service, keep the records the law and our profession require, claim from a funder, or manage clinical risk without knowing who you are. We will tell you at the point where anonymity is no longer possible.
Our primary purpose in collecting your information is to provide you with exercise physiology and clinical exercise services safely and effectively, and to manage the practice that delivers them.
Clinical care
Administration and business
Improvement and marketing
We will only use or disclose your information for a purpose other than the one we collected it for where:
We do not use your health information for any purpose unrelated to your care without your express consent.
Consent may be express (you say or write it) or implied (reasonably inferred from your conduct and the circumstances). For consent to be valid it must be informed, voluntary, current and specific, and given by someone with capacity to give it.
You can withdraw your consent at any time, for any specific purpose, by telling us in writing. We will act on it promptly.
Withdrawing consent operates from the moment you withdraw it. It cannot undo disclosures we have already lawfully made, and it does not affect information we are required by law to retain (see section 18). Withdrawing consent for something central to your care — such as communicating with your referring GP under a Medicare Chronic Disease Management plan — may mean we cannot continue to provide that service, and we will explain this to you honestly rather than simply proceeding.
Where you do not have capacity to consent, we will deal with your substitute decision-maker — an attorney under an enduring power of attorney, a guardian appointed by QCAT, or a statutory health attorney under the Powers of Attorney Act 1998 (Qld) — and we will verify their authority.
For children and young people, we assess capacity individually rather than by age alone. A young person who demonstrates sufficient maturity and understanding to comprehend the nature and consequences of a decision may consent for themselves, and may be entitled to have their information kept confidential from their parents. Where a young person does not have that capacity, we deal with a parent or guardian.
We will explain to a young person, in terms they can understand, what we will and will not share with their parent or carer.
We do not sell, rent or trade your personal information. Ever. To anyone.
We disclose your information in the following circumstances.
With your consent, we share relevant clinical information with the practitioners involved in your care — your GP, specialists, physiotherapist, dietitian, psychologist, occupational therapist and others. This is a core part of how coordinated allied health care works, and we will have discussed it with you at intake.
If you are referred to us under a Medicare Chronic Disease Management plan (GP Management Plan or Team Care Arrangement), we are required to report back to your referring GP on your progress and outcomes. This is a condition of the referral.
| Funder | What we disclose, and why |
|---|---|
| Medicare / Services Australia | Your Medicare number, service dates, item numbers and provider details, to claim rebates on your behalf and to satisfy audit requirements |
| Department of Veterans’ Affairs | Your DVA file number, treatment cycle information, clinical reports (including end-of-cycle reports), and correspondence with your GP, as required by DVA’s treatment arrangements |
| NDIS — NDIA, plan managers, support coordinators, nominees | Service agreements, invoices, progress reports, assessments and reports supporting plan reviews. What we share with a plan manager (billing information) differs from what we share with a support coordinator (progress and functional outcomes), and we keep that distinction |
| WorkCover Queensland, self-insurers, and rehabilitation providers | Progress reports, functional capacity information, treatment plans and discharge reports. Under Queensland workers’ compensation law, an insurer may require documents relevant to a claim, and we may be obliged to provide them |
| CTP insurers | Reports and records relevant to a motor accident claim, where required by law or where you have authorised it |
| Private health funds | Membership number, service dates and item numbers, to process your claim |
Where a funder or insurer has a legal right to your records, that right may operate whether or not you consent. We will tell you when we receive such a request, unless we are prohibited from doing so.
We participate in the My Health Record system. With your consent, and in accordance with the My Health Records Act 2012 (Cth), we may:
You control your My Health Record. You can set access controls, restrict specific documents, remove documents, or cancel your record entirely at any time through myGov or by contacting the My Health Record helpline on 1800 723 471. You can also ask us not to view or upload to your record, and we will comply.
We maintain a separate My Health Record Security and Access Policy as required of registered healthcare provider organisations. It is available on request.
Unauthorised access to a My Health Record is a criminal offence. Access by our practice is logged and auditable, and you can view the access history of your own record.
We disclose your information to the technology providers that operate the systems we use to run the practice. Section 10 sets these out in full — what each one holds, and where.
Our accountant, bookkeeper, lawyers, professional indemnity insurer and, if it ever becomes necessary, a debt recovery agency. These parties are bound by confidentiality and, in most cases, by the Privacy Act themselves.
We will disclose your information without your consent where the law requires or authorises it, including:
We may disclose your information without your consent where we reasonably believe it is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety, and it is unreasonable or impracticable to obtain your consent. This is a high threshold and we do not apply it lightly. If we make such a disclosure, we record it in your file.
If the practice is sold, merged, or transferred, or if a new practitioner takes over your care, your records may be transferred as part of that transaction. We will notify you before this happens, and give you the opportunity to request that your records be transferred to a practitioner of your choosing instead, or to obtain a copy.
If we cease to practise, we will notify our active clients, arrange for your records to be transferred to another provider or held securely by a records custodian for the required retention period, and tell you how to obtain access.
We use cloud-based software to run the practice. Being specific about this matters: where your information is held, and who else can reach it, is part of what you are consenting to.
Every provider below is engaged under terms that require them to keep your information confidential and secure, to use it only to provide the service to us, and not to use it for their own purposes.
| System | What it is used for | What it holds about you | Where your data is stored |
|---|---|---|---|
| Halaxy | Practice management — our clinical record system | Your full clinical record: identity and contact details, health information, clinical notes, correspondence, referrals, appointments, invoices, payments, Medicare and DVA claiming | Australia (Amazon Web Services). Halaxy uses some overseas sub-processors for specific functions — including SMS delivery, payment processing and accounting integration, some of which are located in the United States |
| Heidi Health | AI clinical documentation (“AI scribe”) | Audio of your consultation, converted immediately to a transcript, which we then edit into a clinical note (see section 11) | Heidi provides data localisation for Australian customers. Heidi holds ISO 27001 and SOC 2 certification |
| VALD | Objective physical testing and performance data (ForceDecks, DynaMo) | Your name, date of birth, test results, force and movement measurements, and results over time | VALD is an Australian company (Brisbane). VALD’s privacy policy states that it may transfer information to Australia, the United States, the United Kingdom and the European Economic Area |
| Everfit | Exercise programme delivery and your client app | Your name, contact details, programme, exercise history, logged workouts, body measurements, in-app messages with us, and any wearable data you choose to connect | United States. Everfit Technologies, Inc. is a US company. Everfit uses sub-processors including Stripe (payments) and, for certain AI features, OpenAI |
| Google Workspace | Email, calendar, documents and file storage | Correspondence with you and about you, calendar entries, and administrative documents | United States and other Google data centres globally |
| ClickUp | Task and project management | Administrative tasks referencing clients — for example, “follow up [name] re GP report.” We keep clinical detail out of ClickUp | United States, and other AWS regions including Sydney, depending on account configuration |
| Go High Level (HighLevel) | Website, CRM, enquiry forms, email and SMS marketing | Enquiry and lead information, contact details, marketing communication history, and what you told us in a website form before becoming a client | United States. HighLevel LLC is a US company and states it may transfer information to affiliates and partners in other countries, including India |
| Ezidebit | Recurring direct debit and card processing for ongoing memberships | Your name and contact details, bank account or card details, your payment schedule, and your payment and dishonour history | Ezidebit Pty Ltd is an Australian company (ACN 096 902 813) operating under an Australian Financial Services Licence and bound by the Privacy Act. It is a subsidiary of Global Payments, Inc., and its privacy statement says personal information may be transferred to and stored in the United States or another country |
| Halaxy payments | Processing of one-off and ad-hoc payments — initial consultations, casual sessions, invoices | Card details and transaction history | Processed through Halaxy’s payment partners, including Stripe, Braintree and PayPal (United States) |
We are deliberate about which system holds what:
This separation is a deliberate risk control, not an accident of how the systems happen to be set up.
Software changes. If we add, remove or replace a system that holds your personal information, we will update this policy. If a change materially affects how your information is handled — particularly where it is stored — we will tell our active clients directly rather than relying on you to re-read this page.
We use AI in two limited ways. We think you are entitled to know exactly what they are.
We use Heidi Health, an AI clinical documentation tool, to help write our clinical notes. Here is precisely how it works.
What happens
What we can tell you about the safeguards
What this does not change
The clinical note is our work and our responsibility. The AI drafts; the exercise physiologist decides. Nothing is entered into your record that has not been read and approved by a qualified practitioner.
You can say no. Declining consent for AI documentation will not affect your care in any way. We will simply write the note ourselves.
The programme delivery platform we use, Everfit, includes AI features that may process workout and nutrition data through OpenAI. Where we use these features, they assist with programme construction. They do not make clinical decisions about your care.
No decision that affects your rights or interests is made by a computer program. Every clinical decision — whether exercise is safe for you, what your programme should be, whether to progress or modify it, when to discharge you, what to report to a funder — is made by a qualified Accredited Exercise Physiologist exercising professional judgement.
From 10 December 2026, the Privacy Act requires privacy policies to disclose where computer programs are used to make, or to do a substantial part of, decisions that significantly affect an individual’s rights or interests. We do not use automated decision-making of this kind. If that ever changes, we will update this policy and tell you before it takes effect.
This section reflects our obligations under clauses 2.9.6 and 2.9.7 of the ESSA Code of Professional Conduct and Ethical Practice, which require us to use technology and AI lawfully, with your consent, and with transparency about its impact.
Some of the software we use stores or processes your information outside Australia. This is disclosed to you here so that your use of our services is informed.
Your clinical record is held in Australia. Halaxy stores Australian customer data in Australia, and it is our clinical system of record.
However, information may be disclosed to or accessible from overseas recipients in the following countries:
Under APP 8, before we disclose personal information to an overseas recipient we must take reasonable steps to ensure that recipient does not breach the Australian Privacy Principles. We do this by contracting only with providers who commit to appropriate security and confidentiality standards, and by limiting what information reaches overseas systems in the first place (see section 10.2).
You should understand: once information is held overseas, Australian privacy law may be harder to enforce in practice, and the information may be subject to the laws of that country, including lawful access by foreign authorities. This is an unavoidable feature of using modern cloud software, and it is why we keep your clinical record onshore and are deliberate about what goes offshore.
If you have concerns about this, please raise them with us before commencing services and we will discuss what is and is not possible.
Under APP 10 we take reasonable steps to ensure the information we collect, use and disclose is accurate, up to date, complete and relevant.
We do this by confirming your details with you periodically, asking you to review your intake information, and updating your record when you tell us something has changed.
Please tell us when your details change — your address, phone number, medications, medical conditions, GP, or funding arrangements. Incorrect health information in a clinical record is a safety risk, not just an administrative annoyance.
Under APP 11 we take reasonable steps to protect your information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
Technical
Physical
Practices operating in shared spaces
We deliver services in a shared gym environment. We take specific care that your clinical information — on screens, on paper, or in conversation — is not accessible to gym staff, other members, or anyone not involved in your care.
Organisational
No system is completely secure. We cannot guarantee absolute security, and we will not pretend otherwise. What we can commit to is taking the steps a reasonable practice in our position should take, and telling you honestly if something goes wrong.
Your part in this: please use a strong, unique password for the client app, do not share your login, and tell us immediately if you think your account has been accessed by someone else. Be aware that email and SMS are not fully secure channels; if you would prefer we not send clinical information by email, tell us and we will use another method.
We maintain a data breach response plan. If we suspect a breach, we contain it, assess it, and remediate it.
Under the Notifiable Data Breaches scheme, if there is unauthorised access to, unauthorised disclosure of, or loss of your personal information, and it is likely to result in serious harm to you, we must:
Because we hold health information, the threshold for “serious harm” is lower than it would be for many businesses. We treat any potential exposure of clinical information as serious.
If a breach involves My Health Record information, we will also notify the System Operator as required by section 75 of the My Health Records Act 2012 (Cth).
If you are a client or have enquired with us, we may send you appointment reminders, service updates, health education content, newsletters and information about our programmes and events, by email and SMS.
You can opt out at any time by clicking unsubscribe, replying STOP to an SMS, or emailing us. Opting out of marketing does not stop appointment reminders, clinical communications, or account and billing notices, which are a necessary part of delivering your care. If you want to stop those too, tell us and we will discuss what that means for your care.
Under APP 7.6, you can also ask us to tell you the source of the contact information we hold about you, and we will tell you unless it is impracticable or unreasonable to do so.
Our website is built on the Go High Level platform and uses cookies and similar technologies to make the site work, remember your preferences, and understand how visitors use it. We may use analytics and advertising tools, including Google Analytics and Meta (Facebook and Instagram) tools, which may set their own cookies and collect information about your visit.
You can control cookies through your browser settings. Blocking cookies may affect how parts of the site work.
We may run advertising on Google, Meta and other platforms. This can include showing ads to people who have visited our website, and building audiences based on general characteristics. We do not upload health information to advertising platforms, and we do not target advertising based on any individual’s health condition.
If you contact us through Instagram, Facebook or another social platform, that message is held by the platform under its privacy policy, not ours. We have no control over how those companies handle it.
Please do not send us detailed health information through social media. If you do, we will move it into our clinical system and ask you to continue the conversation through a secure channel.
Our website may link to other sites. We are not responsible for the privacy practices or content of any site we do not operate.
We retain clinical records for a minimum of:
This reflects the standard applied across Australian health practice and the limitation periods that apply to potential claims. Some records are kept longer where a legal claim, insurance matter, investigation or complaint is on foot, or where a specific law requires it.
Financial and tax records are kept for at least five years as required by the Income Tax Assessment Act, and other records for as long as they are needed for the purpose for which they were collected.
Under APP 11.2, once we no longer need your information for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we destroy it or de-identify it.
Paper records are destroyed by secure shredding. Electronic records are securely deleted from our systems, and we take reasonable steps to ensure they are deleted from backups in accordance with our providers’ retention cycles.
Under APP 12 you have the right to access the personal information we hold about you. It is your information. You do not need to give a reason for wanting it.
Write to us at [email protected], or by post to the address in section 22. Tell us what you want — your whole file, a specific report, notes from a particular date range — and how you would like to receive it.
We will verify your identity before releasing anything. If someone is requesting on your behalf, we will require evidence of their authority.
We will respond within 30 days. We will give you access in the form you have asked for where it is reasonable and practicable — a copy of your file, a summary, an opportunity to view your record with a practitioner present to explain it, or access through an intermediary such as your GP.
We do not charge you for making a request. We may charge a reasonable fee for the cost of providing access — retrieval, copying, and postage — where a request is substantial. Any fee will be reasonable, will not be used to discourage you, and we will tell you what it is before we incur it. We will not charge for a straightforward request from a current client.
We may refuse access in the limited circumstances set out in APP 12.3, including where giving access would pose a serious threat to the life, health or safety of any person, would have an unreasonable impact on another person’s privacy, relates to existing or anticipated legal proceedings, or where the law requires us to refuse.
If we refuse, we will tell you in writing, explain why, and tell you how to complain. Where we can, we will offer a way to give you part of what you asked for — for example, releasing your record with third-party information redacted, or providing a summary.
Under APP 13, if information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you can ask us to correct it. We will also correct it on our own initiative if we become aware of a problem.
There is never a charge for a correction request.
We will respond within 30 days.
An important distinction in clinical records: a clinical note is a record of what was observed, reported and clinically reasoned at a particular point in time. We will readily correct factual errors — a wrong date of birth, a misspelled medication, an incorrect address, a mistaken diagnosis. Where you disagree with a clinical opinion recorded at the time, we cannot simply erase or rewrite history, because the integrity of the record matters for your safety.
In that situation, APP 13.4 gives you a right we will always honour: we will attach a statement of your disagreement to the record, in your words, so that anyone who reads the record in future reads your view alongside ours.
If we have already disclosed the incorrect information to someone else, we will notify them of the correction if you ask us to and it is practicable to do so.
We would rather hear from you than have you go elsewhere first. A complaint tells us something is wrong and gives us the chance to fix it.
Contact our Privacy Officer:
Please describe what happened, when, and what you would like us to do about it. Written complaints help us investigate properly, but we will accept a complaint verbally if that is easier for you.
| Step | Timeframe |
|---|---|
| We acknowledge your complaint | Within 5 business days |
| We investigate — reviewing records, systems and, where relevant, speaking to the people involved | |
| We give you a written response setting out our findings, our decision, and what we will do | Within 30 days |
| If we need longer, we tell you why and keep you updated |
Complaints are handled confidentially. Making a complaint will never affect the quality of the care you receive from us.
If you are not satisfied with our response, or you would prefer not to come to us first, you can go to:
Office of the Australian Information Commissioner (OAIC) — for privacy complaints Phone: 1300 363 992 Web: www.oaic.gov.au Post: GPO Box 5218, Sydney NSW 2001
Office of the Health Ombudsman (Queensland) — for complaints about health services and health practitioner conduct in Queensland, including unregistered health professions under the National Code of Conduct for Health Care Workers Phone: 133 646 Web: www.oho.qld.gov.au
Exercise & Sports Science Australia (ESSA) — for complaints about the professional conduct of an Accredited Exercise Physiologist Web: www.essa.org.au
NDIS Quality and Safeguards Commission — for complaints relating to NDIS supports Phone: 1800 035 544 Web: www.ndiscommission.gov.au
Workers’ Compensation Regulator (Queensland) — for complaints relating to a workers’ compensation matter Phone: 1300 362 128
My Health Record helpline — for complaints about My Health Record Phone: 1800 723 471
You may also have a right to bring a claim under the statutory tort for serious invasions of privacy, in force since June 2025.
Movement 3 Clinical Exercise and Exercise Science Tempus Group Pty Ltd as trustee for the Tempus Health Trust ABN 97 404 050 519
Privacy Officer: Rob Bonser, Accredited Exercise Physiologist
We review this policy at least annually, and whenever we change our systems or our practices, or when the law changes.
The current version is always available at movement3.com.au/privacy, with the effective date at the top.
Where a change materially affects how we handle your personal information, we will notify active clients directly rather than relying on you to check this page. Minor changes will be reflected here with an updated effective date.
| You have the right to | Where it comes from | How to use it |
|---|---|---|
| Know what we collect and why | APP 1, APP 5 | Read this policy; ask us anything |
| Deal with us anonymously for general enquiries | APP 2 | Just don’t tell us your name |
| Not have your sensitive information collected without consent | APP 3 | Decline; we’ll tell you the consequences |
| Access your own records | APP 12 | Email [email protected] |
| Have errors corrected | APP 13 | Email us — no charge, ever |
| Attach your own statement where we disagree | APP 13.4 | Email us your statement |
| Opt out of marketing | APP 7, Spam Act | Unsubscribe link, reply STOP, or email us |
| Know where your information goes overseas | APP 8 | Section 12 of this policy |
| Withdraw consent | Privacy Act; ESSA Code | Tell us in writing |
| Refuse AI documentation | Section 11 | Just say no — it won’t affect your care |
| Control your My Health Record | My Health Records Act 2012 | myGov, or 1800 723 471 |
| Be told if your data is breached | Notifiable Data Breaches scheme | We’ll contact you |
| Complain, and escalate | APP 1.4 | Section 21 of this policy |
AEP — Accredited Exercise Physiologist; a university-qualified allied health professional accredited by Exercise & Sports Science Australia.
APP — Australian Privacy Principle. The thirteen principles in Schedule 1 of the Privacy Act 1988 (Cth) that govern how we handle your information.
De-identified — information from which identifiers have been removed so that you are no longer reasonably identifiable.
Health information — information about your physical or mental health or disability, and information collected in the course of providing you with a health service.
IHI — Individual Healthcare Identifier; a unique 16-digit number assigned to you for use in the Australian healthcare system.
OAIC — Office of the Australian Information Commissioner; the national privacy regulator.
Personal information — information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Sensitive information — a category of personal information that includes health information and attracts higher protection under the Privacy Act.
Substitute decision-maker — a person legally authorised to make decisions on your behalf when you lack capacity, such as an attorney, guardian or statutory health attorney.

Clinical exercise physiology, injury rehabilitation and strength and conditioning in Bundaberg, QLD
Clinical Exercise Physiology
Exercise Physiology Coaching
Performance Testing
Consulting & Workshops
14 Heidke Street
0415 426 426
Copyright 2026. Mov3ment. All Rights Reserved.