Terms of Use, Privacy & Complaints Policy

Privacy Policy

Movement 3 Clinical Exercise and Exercise Science
Operated by Tempus Group Pty Ltd as trustee for the Tempus Health Trust · ABN 97 404 050 519
Effective date: 19 June 2026  ·  Version: 1.0  ·  Next review: 1 June 2027

1About this policy

Movement 3 Clinical Exercise and Exercise Science (“Movement 3”, “M3”, “we”, “us”, “our”) is a clinical exercise physiology practice. We are operated by Tempus Group Pty Ltd as trustee for the Tempus Health Trust (ABN 97 404 050 519).

We collect information about your health in order to provide you with exercise physiology services. We understand that this is some of the most personal information you will ever share with anyone, and we take the responsibility seriously.

This policy explains, in plain language:

  • what information we collect about you, and why
  • how we collect it, and who we collect it from
  • who we share it with, and in what circumstances
  • the specific software and technology we use to hold and process it, including where in the world your information is stored
  • how we use artificial intelligence in our practice
  • how we keep your information secure, and how long we keep it
  • your rights to access and correct your information
  • how to make a privacy complaint, and where to escalate it if you are not satisfied

This policy applies to everyone whose personal information we handle — clients, prospective clients, people who contact us through our website or social media, referrers, carers and substitute decision-makers, contractors, and job applicants.

1.1Availability

This policy is published free of charge at movement3.com.au/privacy. If you would like it in another format — printed, large print, or read aloud to you — please ask and we will provide it at no cost.


2The law that applies to us

We are bound by the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs) set out in that Act.

Many small businesses in Australia are exempt from the Privacy Act because they turn over less than $3 million a year. That exemption does not apply to us. Any business that provides a health service and holds health information is covered by the Privacy Act regardless of its size. As a clinical exercise physiology practice, we are a health service provider, and we are fully bound.

Queensland does not have separate private-sector health records legislation. The Information Privacy Act 2009 (Qld) applies to Queensland government agencies and public hospitals, not to private practices like ours. Our obligations to you come from Commonwealth law.

We are also bound by, and this policy should be read alongside:

Instrument What it governs
My Health Records Act 2012 (Cth) How we view, upload to and handle information in the My Health Record system
Healthcare Identifiers Act 2010 (Cth) How we use Individual Healthcare Identifiers (IHIs)
Notifiable Data Breaches scheme (Part IIIC, Privacy Act) What we must do if your information is compromised
ESSA Code of Professional Conduct and Ethical Practice Our professional obligations on confidentiality, consent, record-keeping and the responsible use of technology and AI (clauses 2.9 and 3.2 in particular)
National Code of Conduct for Health Care Workers (Queensland) The minimum standards of conduct required of us as an unregistered health profession in Queensland
Spam Act 2003 (Cth) and Do Not Call Register Act 2006 (Cth) Our electronic marketing and telemarketing
Statutory tort for serious invasions of privacy (Schedule 2, Privacy Act) Your right to sue for a serious invasion of privacy, in force since June 2025
Child Protection Act 1999 (Qld) and related child safety laws Our mandatory reporting obligations
Workers’ Compensation and Rehabilitation Act 2003 (Qld) Information we must provide to insurers for workers’ compensation claims
National Disability Insurance Scheme Act 2013 (Cth) and the NDIS Code of Conduct Our obligations to NDIS participants

3What we mean by “personal”, “sensitive” and “health” information

Personal information is any information or opinion about an identified individual, or an individual who is reasonably identifiable — whether or not it is true, and whether or not it is recorded in a material form.

Sensitive information is a special category of personal information that attracts a higher level of protection under the Privacy Act. It includes health information, racial or ethnic origin, religious beliefs, sexual orientation, and criminal record.

Health information includes information about your physical or mental health, any disability, your health services history, and information collected while providing a health service to you. Almost everything in your clinical file is health information.

In practice, this means: the great majority of what we hold about you is sensitive information. We generally cannot collect it without your consent, we cannot use it for a purpose other than the one we collected it for without your consent, and we must take active steps to protect it.


4What information we collect

4.1Identity and contact information

Your name and any previous names, date of birth, gender, address, phone numbers, email address, emergency contact details, occupation and employer, preferred language, and — where relevant to your care or to how we should communicate with you — your cultural background, Aboriginal or Torres Strait Islander status, and interpreter or accessibility needs.

4.2Government-related identifiers

Where relevant to your funding stream, we collect:

  • Medicare number and Individual Reference Number
  • Individual Healthcare Identifier (IHI)
  • Department of Veterans’ Affairs (DVA) file number and card type
  • NDIS participant number
  • WorkCover Queensland or other workers’ compensation claim number
  • Compulsory Third Party (CTP) motor accident claim number
  • Private health fund membership number
  • Centrelink Customer Reference Number, where required for a funding application

We handle these strictly in accordance with APP 9. We do not adopt a government identifier as our own way of identifying you in our systems — your file is identified by our own client number — and we only use or disclose these identifiers where the law permits or requires it, or where it is reasonably necessary to verify your identity or to claim a payment on your behalf.

4.3Health information

  • Your presenting concerns, symptoms, and reasons for seeking exercise physiology services
  • Medical history, diagnoses, comorbidities, past surgeries and injuries
  • Current medications, allergies and adverse reactions
  • Results of clinical assessments and screening we conduct
  • Reports, imaging results, pathology results and correspondence provided by your GP, specialists, or other health practitioners
  • Referral documents, GP Management Plans, Team Care Arrangements, DVA referrals, NDIS plans and reports, and insurer or rehabilitation provider documentation
  • Your exercise capacity, functional status, pain levels, and response to exercise
  • Progress notes for every session, and clinical reasoning about your programme
  • Discharge summaries and outcome measures
  • Where clinically relevant: smoking, alcohol and dietary history, sleep, stress, mental health status and psychosocial factors affecting your rehabilitation

4.4Objective testing and performance data

We use VALD human measurement technology (including ForceDecks force plates and DynaMo dynamometry) to conduct objective physical testing. This generates data including force production, asymmetry between limbs, rate of force development, jump height, grip and isometric strength, balance and postural control measures, and comparisons of your results over time and against normative reference data.

This is health information about you.

4.5Photographs, video and audio

With your specific consent, we may record:

  • Video of movement and technique for assessment, clinical reasoning, programme design, and to show you your own progress
  • Photographs for postural or functional assessment
  • Exercise demonstration video created specifically for your programme
  • Audio of your consultation, where you consent to us using our AI clinical documentation tool (see section 11)

Consent for clinical recording is separate from consent for marketing use. We will never use your image, video, voice, testimonial or case details in marketing, social media, on our website or in professional education without your separate, express, written consent, obtained specifically for that purpose. You can withdraw that consent at any time, and we will remove the material from anything we control going forward.

4.6Wearable and third-party fitness data

If you choose to connect a wearable device or fitness application — such as a Garmin, Apple Watch, Fitbit, Whoop, Strava account or Apple Health — to the programme delivery platform we use, we will receive data from it. This may include step counts, heart rate, heart rate variability, sleep data, workout history, GPS-derived activity data, and body composition measurements.

Connecting a device is entirely voluntary and is not a condition of receiving services from us. You control the connection and can disconnect it at any time through your own device or account settings. Data that stays on your device and is never shared through the platform is not collected by us.

4.7Payment and financial information

Bank account or card details for direct debit and payment, billing address, invoice and payment history, outstanding balances, funding approvals and claim statuses, and correspondence about accounts.

We do not store full card or bank account numbers ourselves. Payment details are held by our payment processors under their own security standards:

  • Ongoing memberships are processed by Ezidebit on a recurring direct debit or card schedule. When you sign a payment agreement, your bank account or card details, name and contact details are provided directly to Ezidebit and held by them. We see the status of your payments and a masked reference, not your full account details.
  • Other direct payments — initial consultations, one-off appointments, casual sessions and ad-hoc invoices — are processed through Halaxy, our practice management system.

You should be aware that under Ezidebit’s terms, if an amount owing is not paid after demand, Ezidebit may commence collections or enforcement action and may report a default to a credit reporting agency. This is Ezidebit’s process, not ours, and we would always contact you about an overdue account before it reached that point.

4.8Website, marketing and technical information

When you visit our website, complete an enquiry form, book online, subscribe to our email list, or interact with our social media:

  • Information you give us in forms — name, email, phone, and whatever you tell us about your situation
  • Your IP address, browser type, device type, operating system, and approximate location derived from your IP address
  • Pages you visited, how you arrived at our site, how long you stayed, and what you clicked
  • Whether you opened or clicked our emails and SMS messages
  • Information from cookies and similar tracking technologies (see section 17)

Be aware that if you describe your health condition in a website enquiry form or a social media message, you are giving us health information through a channel that is not a clinical record system. We will move it into our clinical system promptly, but we would encourage you to keep initial enquiries general and save the detail for your consultation.

4.9Information about people other than you

Sometimes your clinical record will necessarily contain information about other people — your family medical history, the details of a carer or substitute decision-maker, or an emergency contact. We collect only what is necessary and we treat that information with the same care as your own.

4.10Contractors, applicants and referrers

We collect professional contact details, qualifications, registration and insurance details from referrers, contractors and job applicants, and the information necessary to engage and pay contractors or assess applications.


5How we collect your information

5.1Directly from you

This is our preference and our default. We collect information from you in your consultations, in intake and health screening forms, over the phone, by email or SMS, through our website and online booking, and through the client app we use for programme delivery.

5.2From other people, with your knowledge

We frequently collect information about you from third parties, because coordinated care requires it. These include:

  • Your GP and any medical specialists, including referrals, GP Management Plans, Team Care Arrangements, letters and test results
  • Other allied health practitioners involved in your care — physiotherapists, dietitians, psychologists, occupational therapists, podiatrists
  • Hospitals and diagnostic services
  • The Department of Veterans’ Affairs and DVA-contracted providers
  • The National Disability Insurance Agency, your plan manager, support coordinator, or nominee
  • WorkCover Queensland, self-insurers, CTP insurers, and rehabilitation providers or case managers
  • Your private health fund
  • Your family members, carers or substitute decision-maker, where you have authorised this or where you do not have capacity to consent
  • Your employer, in a workers’ compensation or return-to-work context, limited to what is necessary for that purpose

Where we collect information about you from someone else, we will take reasonable steps to make sure you know we have done so, and why — unless you have already been told, or unless telling you would be inconsistent with the law or would pose a serious threat to someone’s life, health or safety.

5.3Unsolicited information

If we receive personal information about you that we did not ask for and that we could not lawfully have collected ourselves, we will destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

5.4If you do not give us the information we ask for

You are not obliged to give us any particular piece of information. However, exercise physiology is a clinical service and some information is genuinely necessary for us to work safely. If you decline to provide it, we may not be able to assess you accurately, may not be able to design a safe programme, may not be able to claim on your behalf from Medicare, DVA, NDIS or an insurer, or in some cases may not be able to provide services at all. We will tell you clearly if that is the case, and why.


6Dealing with us anonymously or under a pseudonym

Under APP 2, you have the option of dealing with us anonymously or under a pseudonym where it is lawful and practicable.

In practice: you can make a general enquiry, ask about our services, ask a general question about exercise and health, or attend a public education session, without telling us who you are.

Once you become a client, this is no longer practicable. We cannot lawfully deliver a clinical health service, keep the records the law and our profession require, claim from a funder, or manage clinical risk without knowing who you are. We will tell you at the point where anonymity is no longer possible.


7Why we collect, hold, use and disclose your information

7.1Our primary purpose

Our primary purpose in collecting your information is to provide you with exercise physiology and clinical exercise services safely and effectively, and to manage the practice that delivers them.

7.2Specifically, we use your information to

Clinical care

  • Screen you for risk and determine whether exercise physiology is appropriate and safe for you
  • Conduct assessments and objective testing, and interpret the results
  • Design, prescribe, deliver and progress your individual exercise programme
  • Monitor your response, adjust your programme, and measure your outcomes
  • Document your care to the standard required by law and by the ESSA Code of Professional Conduct and Ethical Practice
  • Communicate and coordinate with the other practitioners involved in your care
  • Manage clinical incidents, adverse events and risk

Administration and business

  • Make, confirm, remind you of, and reschedule appointments
  • Invoice you, process payments, and manage accounts
  • Claim on your behalf from Medicare, DVA, the NDIS, WorkCover Queensland, CTP insurers or your private health fund
  • Verify your eligibility and funding
  • Respond to your enquiries, feedback and complaints
  • Manage our own tasks, projects and workflow
  • Maintain our professional indemnity insurance and, where necessary, defend or respond to a claim
  • Meet our obligations to our accountant, auditor and the Australian Taxation Office
  • Comply with the law, and respond to lawful requests from courts, tribunals, regulators and government agencies

Improvement and marketing

  • Improve the quality and safety of our services, including through clinical audit and peer review
  • Undertake de-identified analysis of outcomes across our client base
  • Train, supervise and mentor exercise physiologists and students, using de-identified material unless you consent otherwise
  • Send you service information, health education and marketing, subject to section 16 and your right to opt out

7.3Secondary purposes

We will only use or disclose your information for a purpose other than the one we collected it for where:

  • you have consented; or
  • the secondary purpose is directly related to the primary purpose and you would reasonably expect it (for example, disclosing your progress to the GP who referred you, or to our billing systems); or
  • the use or disclosure is required or authorised by law; or
  • it is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety; or
  • another “permitted health situation” or “permitted general situation” under the Privacy Act applies.

We do not use your health information for any purpose unrelated to your care without your express consent.


8Consent

8.1How consent works

Consent may be express (you say or write it) or implied (reasonably inferred from your conduct and the circumstances). For consent to be valid it must be informed, voluntary, current and specific, and given by someone with capacity to give it.

  • We rely on your express written consent at intake for the collection and use of your health information, for communicating with your GP and other providers, and for our AI documentation tool.
  • We rely on implied consent for routine, expected things — such as using your contact details to send you an appointment reminder, or discussing your programme with you.
  • We rely on separate express written consent for anything outside the ordinary course of your care: marketing use of your image or story, research, or disclosure to a third party who is not part of your care team.

8.2Withdrawing consent

You can withdraw your consent at any time, for any specific purpose, by telling us in writing. We will act on it promptly.

Withdrawing consent operates from the moment you withdraw it. It cannot undo disclosures we have already lawfully made, and it does not affect information we are required by law to retain (see section 18). Withdrawing consent for something central to your care — such as communicating with your referring GP under a Medicare Chronic Disease Management plan — may mean we cannot continue to provide that service, and we will explain this to you honestly rather than simply proceeding.

8.3Capacity, young people and substitute decision-makers

Where you do not have capacity to consent, we will deal with your substitute decision-maker — an attorney under an enduring power of attorney, a guardian appointed by QCAT, or a statutory health attorney under the Powers of Attorney Act 1998 (Qld) — and we will verify their authority.

For children and young people, we assess capacity individually rather than by age alone. A young person who demonstrates sufficient maturity and understanding to comprehend the nature and consequences of a decision may consent for themselves, and may be entitled to have their information kept confidential from their parents. Where a young person does not have that capacity, we deal with a parent or guardian.

We will explain to a young person, in terms they can understand, what we will and will not share with their parent or carer.


9Who we disclose your information to

We do not sell, rent or trade your personal information. Ever. To anyone.

We disclose your information in the following circumstances.

9.1Your treating team

With your consent, we share relevant clinical information with the practitioners involved in your care — your GP, specialists, physiotherapist, dietitian, psychologist, occupational therapist and others. This is a core part of how coordinated allied health care works, and we will have discussed it with you at intake.

If you are referred to us under a Medicare Chronic Disease Management plan (GP Management Plan or Team Care Arrangement), we are required to report back to your referring GP on your progress and outcomes. This is a condition of the referral.

9.2Funders and third-party payers

Funder What we disclose, and why
Medicare / Services Australia Your Medicare number, service dates, item numbers and provider details, to claim rebates on your behalf and to satisfy audit requirements
Department of Veterans’ Affairs Your DVA file number, treatment cycle information, clinical reports (including end-of-cycle reports), and correspondence with your GP, as required by DVA’s treatment arrangements
NDIS — NDIA, plan managers, support coordinators, nominees Service agreements, invoices, progress reports, assessments and reports supporting plan reviews. What we share with a plan manager (billing information) differs from what we share with a support coordinator (progress and functional outcomes), and we keep that distinction
WorkCover Queensland, self-insurers, and rehabilitation providers Progress reports, functional capacity information, treatment plans and discharge reports. Under Queensland workers’ compensation law, an insurer may require documents relevant to a claim, and we may be obliged to provide them
CTP insurers Reports and records relevant to a motor accident claim, where required by law or where you have authorised it
Private health funds Membership number, service dates and item numbers, to process your claim

Where a funder or insurer has a legal right to your records, that right may operate whether or not you consent. We will tell you when we receive such a request, unless we are prohibited from doing so.

9.3My Health Record

We participate in the My Health Record system. With your consent, and in accordance with the My Health Records Act 2012 (Cth), we may:

  • View information in your My Health Record where it is relevant to providing you with care
  • Upload clinical documents, such as event summaries or shared health summaries, to your record

You control your My Health Record. You can set access controls, restrict specific documents, remove documents, or cancel your record entirely at any time through myGov or by contacting the My Health Record helpline on 1800 723 471. You can also ask us not to view or upload to your record, and we will comply.

We maintain a separate My Health Record Security and Access Policy as required of registered healthcare provider organisations. It is available on request.

Unauthorised access to a My Health Record is a criminal offence. Access by our practice is logged and auditable, and you can view the access history of your own record.

9.4Our software and service providers

We disclose your information to the technology providers that operate the systems we use to run the practice. Section 10 sets these out in full — what each one holds, and where.

9.5Professional advisers and insurers

Our accountant, bookkeeper, lawyers, professional indemnity insurer and, if it ever becomes necessary, a debt recovery agency. These parties are bound by confidentiality and, in most cases, by the Privacy Act themselves.

9.6Regulators, courts and mandatory disclosure

We will disclose your information without your consent where the law requires or authorises it, including:

  • In response to a subpoena, summons, warrant, court order or notice to produce
  • To the Office of the Health Ombudsman (Queensland) or Exercise & Sports Science Australia in connection with a complaint or investigation about our conduct
  • To the NDIS Quality and Safeguards Commission
  • Under mandatory reporting obligations, including reasonable suspicion of child abuse or neglect under the Child Protection Act 1999 (Qld), and reporting to the Queensland Police Service where the law requires
  • To a coroner
  • To Services Australia or DVA for compliance audit
  • To public health authorities where required by public health law

9.7Preventing serious threats

We may disclose your information without your consent where we reasonably believe it is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety, and it is unreasonable or impracticable to obtain your consent. This is a high threshold and we do not apply it lightly. If we make such a disclosure, we record it in your file.

9.8Sale or transfer of the practice

If the practice is sold, merged, or transferred, or if a new practitioner takes over your care, your records may be transferred as part of that transaction. We will notify you before this happens, and give you the opportunity to request that your records be transferred to a practitioner of your choosing instead, or to obtain a copy.

9.9If we cease practising

If we cease to practise, we will notify our active clients, arrange for your records to be transferred to another provider or held securely by a records custodian for the required retention period, and tell you how to obtain access.


10The software and technology we use

We use cloud-based software to run the practice. Being specific about this matters: where your information is held, and who else can reach it, is part of what you are consenting to.

Every provider below is engaged under terms that require them to keep your information confidential and secure, to use it only to provide the service to us, and not to use it for their own purposes.

10.1Our systems

System What it is used for What it holds about you Where your data is stored
Halaxy Practice management — our clinical record system Your full clinical record: identity and contact details, health information, clinical notes, correspondence, referrals, appointments, invoices, payments, Medicare and DVA claiming Australia (Amazon Web Services). Halaxy uses some overseas sub-processors for specific functions — including SMS delivery, payment processing and accounting integration, some of which are located in the United States
Heidi Health AI clinical documentation (“AI scribe”) Audio of your consultation, converted immediately to a transcript, which we then edit into a clinical note (see section 11) Heidi provides data localisation for Australian customers. Heidi holds ISO 27001 and SOC 2 certification
VALD Objective physical testing and performance data (ForceDecks, DynaMo) Your name, date of birth, test results, force and movement measurements, and results over time VALD is an Australian company (Brisbane). VALD’s privacy policy states that it may transfer information to Australia, the United States, the United Kingdom and the European Economic Area
Everfit Exercise programme delivery and your client app Your name, contact details, programme, exercise history, logged workouts, body measurements, in-app messages with us, and any wearable data you choose to connect United States. Everfit Technologies, Inc. is a US company. Everfit uses sub-processors including Stripe (payments) and, for certain AI features, OpenAI
Google Workspace Email, calendar, documents and file storage Correspondence with you and about you, calendar entries, and administrative documents United States and other Google data centres globally
ClickUp Task and project management Administrative tasks referencing clients — for example, “follow up [name] re GP report.” We keep clinical detail out of ClickUp United States, and other AWS regions including Sydney, depending on account configuration
Go High Level (HighLevel) Website, CRM, enquiry forms, email and SMS marketing Enquiry and lead information, contact details, marketing communication history, and what you told us in a website form before becoming a client United States. HighLevel LLC is a US company and states it may transfer information to affiliates and partners in other countries, including India
Ezidebit Recurring direct debit and card processing for ongoing memberships Your name and contact details, bank account or card details, your payment schedule, and your payment and dishonour history Ezidebit Pty Ltd is an Australian company (ACN 096 902 813) operating under an Australian Financial Services Licence and bound by the Privacy Act. It is a subsidiary of Global Payments, Inc., and its privacy statement says personal information may be transferred to and stored in the United States or another country
Halaxy payments Processing of one-off and ad-hoc payments — initial consultations, casual sessions, invoices Card details and transaction history Processed through Halaxy’s payment partners, including Stripe, Braintree and PayPal (United States)

10.2How we limit what goes where

We are deliberate about which system holds what:

  • Your clinical record lives in Halaxy. It is the source of truth and it is stored in Australia.
  • We do not store clinical records, treatment notes or identifiable clinical documentation in ClickUp, or in general-purpose file storage in Google Drive. Where an administrative task must reference a client, we use a name or an identifier and keep the clinical detail in Halaxy.
  • We do not put clinical detail into marketing systems. Go High Level holds enquiry and marketing information. Once you become a client, your clinical information goes into Halaxy, not into the CRM.
  • Everfit holds your programme, not your diagnosis. We keep clinical reasoning and diagnostic detail in Halaxy.
  • Payment systems never receive health information. Ezidebit and Halaxy’s payment partners receive your name, contact details, payment details and what you owe. They do not receive your diagnosis, your clinical notes, or any information about why you are seeing us.

This separation is a deliberate risk control, not an accident of how the systems happen to be set up.

10.3A note on this list

Software changes. If we add, remove or replace a system that holds your personal information, we will update this policy. If a change materially affects how your information is handled — particularly where it is stored — we will tell our active clients directly rather than relying on you to re-read this page.


11Artificial intelligence in our practice

We use AI in two limited ways. We think you are entitled to know exactly what they are.

11.1AI clinical documentation (Heidi Health)

We use Heidi Health, an AI clinical documentation tool, to help write our clinical notes. Here is precisely how it works.

What happens

  1. We ask for your consent before every consultation where we intend to use it. Consent is recorded.
  2. If you consent, the tool listens to the consultation and produces a live transcript.
  3. The transcript is used to draft a structured clinical note.
  4. The exercise physiologist reads, edits, corrects and approves the note before it is saved.
  5. The approved note is entered into your clinical record in Halaxy.

What we can tell you about the safeguards

  • Audio is not stored. Heidi states that consultations are transcribed in real time and the audio is not retained.
  • Your data is not used to train Heidi’s AI models. Heidi states this explicitly.
  • Heidi provides data localisation for Australian customers and holds ISO 27001 and SOC 2 certification.
  • Transcript retention is configurable and we set it to the minimum period we need for clinical audit.

What this does not change

The clinical note is our work and our responsibility. The AI drafts; the exercise physiologist decides. Nothing is entered into your record that has not been read and approved by a qualified practitioner.

You can say no. Declining consent for AI documentation will not affect your care in any way. We will simply write the note ourselves.

11.2AI features in Everfit

The programme delivery platform we use, Everfit, includes AI features that may process workout and nutrition data through OpenAI. Where we use these features, they assist with programme construction. They do not make clinical decisions about your care.

11.3We do not use AI to make decisions about you

No decision that affects your rights or interests is made by a computer program. Every clinical decision — whether exercise is safe for you, what your programme should be, whether to progress or modify it, when to discharge you, what to report to a funder — is made by a qualified Accredited Exercise Physiologist exercising professional judgement.

From 10 December 2026, the Privacy Act requires privacy policies to disclose where computer programs are used to make, or to do a substantial part of, decisions that significantly affect an individual’s rights or interests. We do not use automated decision-making of this kind. If that ever changes, we will update this policy and tell you before it takes effect.

This section reflects our obligations under clauses 2.9.6 and 2.9.7 of the ESSA Code of Professional Conduct and Ethical Practice, which require us to use technology and AI lawfully, with your consent, and with transparency about its impact.


12Overseas disclosure

Some of the software we use stores or processes your information outside Australia. This is disclosed to you here so that your use of our services is informed.

Your clinical record is held in Australia. Halaxy stores Australian customer data in Australia, and it is our clinical system of record.

However, information may be disclosed to or accessible from overseas recipients in the following countries:

  • United States of America — Everfit, Google Workspace, ClickUp, Go High Level, Ezidebit (as a subsidiary of Global Payments, Inc.), and Halaxy’s payment and accounting sub-processors including Stripe, Braintree, PayPal and Xero
  • India — Go High Level states it may transfer information to partners in India
  • United Kingdom and countries in the European Economic Area — VALD states it may transfer information to these locations
  • Singapore and Ireland — possible ClickUp AWS regions

Under APP 8, before we disclose personal information to an overseas recipient we must take reasonable steps to ensure that recipient does not breach the Australian Privacy Principles. We do this by contracting only with providers who commit to appropriate security and confidentiality standards, and by limiting what information reaches overseas systems in the first place (see section 10.2).

You should understand: once information is held overseas, Australian privacy law may be harder to enforce in practice, and the information may be subject to the laws of that country, including lawful access by foreign authorities. This is an unavoidable feature of using modern cloud software, and it is why we keep your clinical record onshore and are deliberate about what goes offshore.

If you have concerns about this, please raise them with us before commencing services and we will discuss what is and is not possible.


13Data quality

Under APP 10 we take reasonable steps to ensure the information we collect, use and disclose is accurate, up to date, complete and relevant.

We do this by confirming your details with you periodically, asking you to review your intake information, and updating your record when you tell us something has changed.

Please tell us when your details change — your address, phone number, medications, medical conditions, GP, or funding arrangements. Incorrect health information in a clinical record is a safety risk, not just an administrative annoyance.


14How we protect your information

Under APP 11 we take reasonable steps to protect your information from misuse, interference and loss, and from unauthorised access, modification or disclosure.

Technical

  • Multi-factor authentication on every system that holds client information
  • Strong, unique passwords managed through a password manager; no shared logins
  • Encryption in transit (TLS/SSL) and at rest across our clinical and administrative systems
  • Full-disk encryption and automatic screen lock on every device used for practice work
  • Automatic session timeout on clinical systems
  • Regular software and operating system updates and patching
  • Reputable endpoint security software
  • Access to client information limited to those who need it to do their job

Physical

  • Devices are never left unattended in public or in a vehicle
  • Any paper records are kept in a locked cabinet and are securely destroyed once digitised
  • Screens are positioned so that client information is not visible to others in shared gym or clinic environments
  • Care taken with verbal discussions in shared or open training spaces, so that conversations about your health are not overheard

Practices operating in shared spaces

We deliver services in a shared gym environment. We take specific care that your clinical information — on screens, on paper, or in conversation — is not accessible to gym staff, other members, or anyone not involved in your care.

Organisational

  • Written confidentiality obligations in every contractor and employment agreement
  • Privacy and data-handling induction for anyone who joins the practice, and refresher training annually
  • Due diligence on new software providers before they touch client information
  • Regular review of who has access to what, and prompt removal of access when someone leaves
  • A documented data breach response plan

No system is completely secure. We cannot guarantee absolute security, and we will not pretend otherwise. What we can commit to is taking the steps a reasonable practice in our position should take, and telling you honestly if something goes wrong.

Your part in this: please use a strong, unique password for the client app, do not share your login, and tell us immediately if you think your account has been accessed by someone else. Be aware that email and SMS are not fully secure channels; if you would prefer we not send clinical information by email, tell us and we will use another method.


15Data breaches

We maintain a data breach response plan. If we suspect a breach, we contain it, assess it, and remediate it.

Under the Notifiable Data Breaches scheme, if there is unauthorised access to, unauthorised disclosure of, or loss of your personal information, and it is likely to result in serious harm to you, we must:

  • Complete our assessment within 30 days of becoming aware of the suspected breach
  • Notify you as soon as practicable, telling you what happened, what information was involved, and what you should do
  • Notify the Office of the Australian Information Commissioner

Because we hold health information, the threshold for “serious harm” is lower than it would be for many businesses. We treat any potential exposure of clinical information as serious.

If a breach involves My Health Record information, we will also notify the System Operator as required by section 75 of the My Health Records Act 2012 (Cth).


16Direct marketing

16.1What we send

If you are a client or have enquired with us, we may send you appointment reminders, service updates, health education content, newsletters and information about our programmes and events, by email and SMS.

16.2The rules we follow

  • We do not use your health information for marketing without your express consent. Marketing is based on your contact details and your status as a client or enquirer, not on your diagnosis. We do not segment marketing lists by health condition.
  • Every marketing message includes a working unsubscribe link. We action unsubscribes promptly, as required by the Spam Act 2003 (Cth).
  • We do not sell or supply your details to any other organisation for their marketing.
  • We honour the Do Not Call Register for telemarketing.

16.3Opting out

You can opt out at any time by clicking unsubscribe, replying STOP to an SMS, or emailing us. Opting out of marketing does not stop appointment reminders, clinical communications, or account and billing notices, which are a necessary part of delivering your care. If you want to stop those too, tell us and we will discuss what that means for your care.

Under APP 7.6, you can also ask us to tell you the source of the contact information we hold about you, and we will tell you unless it is impracticable or unreasonable to do so.


17Our website, cookies and social media

17.1Cookies and analytics

Our website is built on the Go High Level platform and uses cookies and similar technologies to make the site work, remember your preferences, and understand how visitors use it. We may use analytics and advertising tools, including Google Analytics and Meta (Facebook and Instagram) tools, which may set their own cookies and collect information about your visit.

You can control cookies through your browser settings. Blocking cookies may affect how parts of the site work.

17.2Advertising

We may run advertising on Google, Meta and other platforms. This can include showing ads to people who have visited our website, and building audiences based on general characteristics. We do not upload health information to advertising platforms, and we do not target advertising based on any individual’s health condition.

17.3Social media

If you contact us through Instagram, Facebook or another social platform, that message is held by the platform under its privacy policy, not ours. We have no control over how those companies handle it.

Please do not send us detailed health information through social media. If you do, we will move it into our clinical system and ask you to continue the conversation through a secure channel.

17.4Third-party links

Our website may link to other sites. We are not responsible for the privacy practices or content of any site we do not operate.


18How long we keep your information, and how we destroy it

18.1Retention

We retain clinical records for a minimum of:

  • Adults: seven (7) years from the date of the last service we provided to you
  • People under 18 at the time of service: until you turn 25, or seven years after the last service, whichever is later

This reflects the standard applied across Australian health practice and the limitation periods that apply to potential claims. Some records are kept longer where a legal claim, insurance matter, investigation or complaint is on foot, or where a specific law requires it.

Financial and tax records are kept for at least five years as required by the Income Tax Assessment Act, and other records for as long as they are needed for the purpose for which they were collected.

18.2Destruction and de-identification

Under APP 11.2, once we no longer need your information for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we destroy it or de-identify it.

Paper records are destroyed by secure shredding. Electronic records are securely deleted from our systems, and we take reasonable steps to ensure they are deleted from backups in accordance with our providers’ retention cycles.


19Accessing your information

19.1Your right of access

Under APP 12 you have the right to access the personal information we hold about you. It is your information. You do not need to give a reason for wanting it.

19.2How to request access

Write to us at [email protected], or by post to the address in section 22. Tell us what you want — your whole file, a specific report, notes from a particular date range — and how you would like to receive it.

We will verify your identity before releasing anything. If someone is requesting on your behalf, we will require evidence of their authority.

19.3Timeframe and format

We will respond within 30 days. We will give you access in the form you have asked for where it is reasonable and practicable — a copy of your file, a summary, an opportunity to view your record with a practitioner present to explain it, or access through an intermediary such as your GP.

19.4Fees

We do not charge you for making a request. We may charge a reasonable fee for the cost of providing access — retrieval, copying, and postage — where a request is substantial. Any fee will be reasonable, will not be used to discourage you, and we will tell you what it is before we incur it. We will not charge for a straightforward request from a current client.

19.5When we may refuse

We may refuse access in the limited circumstances set out in APP 12.3, including where giving access would pose a serious threat to the life, health or safety of any person, would have an unreasonable impact on another person’s privacy, relates to existing or anticipated legal proceedings, or where the law requires us to refuse.

If we refuse, we will tell you in writing, explain why, and tell you how to complain. Where we can, we will offer a way to give you part of what you asked for — for example, releasing your record with third-party information redacted, or providing a summary.


20Correcting your information

Under APP 13, if information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you can ask us to correct it. We will also correct it on our own initiative if we become aware of a problem.

There is never a charge for a correction request.

We will respond within 30 days.

An important distinction in clinical records: a clinical note is a record of what was observed, reported and clinically reasoned at a particular point in time. We will readily correct factual errors — a wrong date of birth, a misspelled medication, an incorrect address, a mistaken diagnosis. Where you disagree with a clinical opinion recorded at the time, we cannot simply erase or rewrite history, because the integrity of the record matters for your safety.

In that situation, APP 13.4 gives you a right we will always honour: we will attach a statement of your disagreement to the record, in your words, so that anyone who reads the record in future reads your view alongside ours.

If we have already disclosed the incorrect information to someone else, we will notify them of the correction if you ask us to and it is practicable to do so.


21Making a privacy complaint

We would rather hear from you than have you go elsewhere first. A complaint tells us something is wrong and gives us the chance to fix it.

21.1Complain to us

Contact our Privacy Officer:

  • Email: [email protected]
  • Phone: 0415 426 426
  • Post: Privacy Officer, Movement 3 Clinical Exercise and Exercise Science, 14 Heidke Street, Avoca QLD 4670

Please describe what happened, when, and what you would like us to do about it. Written complaints help us investigate properly, but we will accept a complaint verbally if that is easier for you.

21.2What happens next

Step Timeframe
We acknowledge your complaint Within 5 business days
We investigate — reviewing records, systems and, where relevant, speaking to the people involved
We give you a written response setting out our findings, our decision, and what we will do Within 30 days
If we need longer, we tell you why and keep you updated

Complaints are handled confidentially. Making a complaint will never affect the quality of the care you receive from us.

21.3External escalation

If you are not satisfied with our response, or you would prefer not to come to us first, you can go to:

Office of the Australian Information Commissioner (OAIC) — for privacy complaints Phone: 1300 363 992 Web: www.oaic.gov.au Post: GPO Box 5218, Sydney NSW 2001

Office of the Health Ombudsman (Queensland) — for complaints about health services and health practitioner conduct in Queensland, including unregistered health professions under the National Code of Conduct for Health Care Workers Phone: 133 646 Web: www.oho.qld.gov.au

Exercise & Sports Science Australia (ESSA) — for complaints about the professional conduct of an Accredited Exercise Physiologist Web: www.essa.org.au

NDIS Quality and Safeguards Commission — for complaints relating to NDIS supports Phone: 1800 035 544 Web: www.ndiscommission.gov.au

Workers’ Compensation Regulator (Queensland) — for complaints relating to a workers’ compensation matter Phone: 1300 362 128

My Health Record helpline — for complaints about My Health Record Phone: 1800 723 471

You may also have a right to bring a claim under the statutory tort for serious invasions of privacy, in force since June 2025.


22How to contact us

Movement 3 Clinical Exercise and Exercise Science Tempus Group Pty Ltd as trustee for the Tempus Health Trust ABN 97 404 050 519

Privacy Officer: Rob Bonser, Accredited Exercise Physiologist

  • Email: [email protected]
  • Phone: 0415 426 426
  • Address: 14 Heidke Street, Avoca QLD 4670
  • Web: www.movement3.com.au
  • Hours: Monday to Friday, 9:00am – 5:00pm (outside hours by appointment)

23Changes to this policy

We review this policy at least annually, and whenever we change our systems or our practices, or when the law changes.

The current version is always available at movement3.com.au/privacy, with the effective date at the top.

Where a change materially affects how we handle your personal information, we will notify active clients directly rather than relying on you to check this page. Minor changes will be reflected here with an updated effective date.


Appendix AYour rights at a glance

You have the right to Where it comes from How to use it
Know what we collect and why APP 1, APP 5 Read this policy; ask us anything
Deal with us anonymously for general enquiries APP 2 Just don’t tell us your name
Not have your sensitive information collected without consent APP 3 Decline; we’ll tell you the consequences
Access your own records APP 12 Email [email protected]
Have errors corrected APP 13 Email us — no charge, ever
Attach your own statement where we disagree APP 13.4 Email us your statement
Opt out of marketing APP 7, Spam Act Unsubscribe link, reply STOP, or email us
Know where your information goes overseas APP 8 Section 12 of this policy
Withdraw consent Privacy Act; ESSA Code Tell us in writing
Refuse AI documentation Section 11 Just say no — it won’t affect your care
Control your My Health Record My Health Records Act 2012 myGov, or 1800 723 471
Be told if your data is breached Notifiable Data Breaches scheme We’ll contact you
Complain, and escalate APP 1.4 Section 21 of this policy

Appendix BGlossary

AEP — Accredited Exercise Physiologist; a university-qualified allied health professional accredited by Exercise & Sports Science Australia.

APP — Australian Privacy Principle. The thirteen principles in Schedule 1 of the Privacy Act 1988 (Cth) that govern how we handle your information.

De-identified — information from which identifiers have been removed so that you are no longer reasonably identifiable.

Health information — information about your physical or mental health or disability, and information collected in the course of providing you with a health service.

IHI — Individual Healthcare Identifier; a unique 16-digit number assigned to you for use in the Australian healthcare system.

OAIC — Office of the Australian Information Commissioner; the national privacy regulator.

Personal information — information or an opinion about an identified individual, or an individual who is reasonably identifiable.

Sensitive information — a category of personal information that includes health information and attracts higher protection under the Privacy Act.

Substitute decision-maker — a person legally authorised to make decisions on your behalf when you lack capacity, such as an attorney, guardian or statutory health attorney.

NOT SURE WHERE TO START?

Book a FREE 15 minute call

We'll listen to what you need, ask a few questions, and point you in the direction of the right service.

Clinical exercise physiology, injury rehabilitation and strength and conditioning in Bundaberg, QLD

Services
  • Clinical Exercise Physiology

  • Exercise Physiology Coaching

  • Performance Testing

  • Consulting & Workshops

Contact

Copyright 2026. Mov3ment. All Rights Reserved.