Your Privacy Protected

Privacy Policy

How WeMed collects, uses, and protects your personal and health information in compliance with Australian telehealth and medical practice regulations.

Effective date: 1 July 2026

This policy is governed by the Privacy Act 1988 (Cth), the Australian Privacy Principles, the My Health Records Act 2012, and the Healthcare Identifiers Act 2010. Health information is treated as sensitive information under the APPs.

1. Introduction & Scope

WeMed Pty Ltd ("we", "us", "our") operates a telehealth and medical practice connecting patients with Australian-registered health practitioners. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal and health information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the My Health Records Act 2012, and the Healthcare Identifiers Act 2010.

This policy applies to all patients, prospective patients, website visitors, and doctors who interact with our telehealth platform, website, and related services. Health information is treated as "sensitive information" under the APPs and is afforded a higher level of protection.

3. Personal & Health Information We Collect

We collect personal information you provide when booking a consultation, registering as a patient, or communicating with us. This includes your full name, date of birth, email address, phone number, residential address, and Medicare/DVA number where applicable.

Health information we collect includes your medical history, reason for consultation, current medications, allergies, previous diagnoses, specialist referrals, pathology and imaging results, and records of consultations conducted via telehealth or face-to-face.

We also collect technical information when you use our platform, such as IP address, device details, browser type, and consultation metadata (date, time, duration, and type of consultation). Telehealth video consultations are not recorded or stored by us unless explicit consent is provided.

4. How We Collect Information

We collect information directly from you when you complete a booking form, register on our platform, attend a consultation, or correspond with our practitioners. We also collect information with your consent from your referring doctor, previous treating practitioners, pathology providers, and imaging services.

Some information is collected automatically through our website and platform infrastructure, including usage data and cookies, as described in the Cookies section below.

5. How We Use Your Information

We use your personal and health information for the primary purpose of providing medical care, including conducting telehealth and face-to-face consultations, forming diagnoses, prescribing medications, issuing referrals, and maintaining your clinical health record.

We also use your information for related secondary purposes where you would reasonably expect this, such as billing and Medicare claiming, appointment reminders, follow-up communications, practice administration, quality assurance, and meeting our legal and regulatory obligations under healthcare and telecommunications legislation.

6. Disclosure of Your Information

We only disclose your health information to authorised recipients for purposes directly related to your care. This may include your nominated general practitioner, referring and treating specialists, pathology and imaging providers, pharmacies, and other health practitioners involved in your treatment, with your consent or where permitted by law.

We may disclose limited personal information to Medicare, the Department of Veterans' Affairs, private health funds, and regulatory authorities where required by law. We do not sell, rent, or commercially trade your personal or health information to any third party.

7. Telehealth & Cross-Border Data

Our telehealth consultations are conducted over encrypted communications platforms. Video and audio data are transmitted in real time and are not recorded or retained by WeMed unless you provide explicit written consent and understand the purpose of the recording.

Some platform infrastructure and third-party service providers may store or process data outside Australia. Where this occurs, we take reasonable steps to ensure the overseas recipient handles your information in accordance with the APPs, and you consent to this cross-border disclosure by using our telehealth services. Under APP 8, we remain accountable for information handled overseas.

8. Data Security & Storage

We protect your personal and health information using industry-standard security measures, including encryption in transit (TLS), restricted access controls, secure authentication, and regular security reviews. Access to clinical records is limited to authorised practitioners and administrative staff who require access to perform their duties.

Your health records are stored within accredited practice management systems that comply with Australian healthcare data security standards. We maintain audit logs of access to sensitive health information in accordance with best-practice clinical governance.

9. Data Retention

We retain your health records for the period required by Australian medical record-keeping requirements and relevant state health legislation, which generally requires adult records to be retained for a minimum of seven years from the date of last entry, and records relating to children until the child reaches 25 years of age.

When records are no longer required, we destroy or de-identify the information in a secure manner in accordance with the APPs and relevant health record legislation.

10. Your Rights — Access & Correction

Under APP 12 and APP 13, you have the right to request access to the personal and health information we hold about you, and to request correction of information that is inaccurate, out of date, incomplete, or misleading.

To request access or correction, please contact us using the details below. We may charge a reasonable fee for providing access and will respond to your request within a reasonable period. In limited circumstances permitted by law, we may refuse access; if we do, we will provide reasons for the refusal.

12. Cookies & Website Analytics

Our website uses cookies and similar technologies to improve functionality, analyse traffic, and enhance your experience. You can control cookies through your browser settings. Disabling some cookies may affect website functionality.

We use analytics tools that collect de-identified usage data. This data is not linked to your identifiable health information.

13. Third-Party Service Providers

We engage trusted third-party service providers to support our operations, including accredited practice management systems, secure video conferencing, payment processing, and email communications. Each provider is bound by confidentiality and security obligations consistent with the APPs.

These providers may process data in cloud infrastructure located outside Australia. We take reasonable steps to ensure each provider handles your information in line with Australian privacy requirements.

14. Children & Dependents

Where we provide care to patients under 18 years of age, we collect information with the consent of a parent or legal guardian. Health information relating to minors is subject to the same retention and security requirements described above, with extended retention periods as required by law.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. The updated version will be published on this page with the revised effective date. We encourage you to review this page periodically.

16. Complaints & Contact

If you believe we have breached your privacy or mishandled your information, please contact us using the details below. We will investigate and respond to your complaint in a timely manner.

If you remain dissatisfied, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992. The OAIC oversees privacy compliance under the Privacy Act 1988 (Cth).

Contact Our Privacy Officer

For access, correction, consent withdrawal, or privacy enquiries, please contact our Privacy Officer.

Email

privacy@wemed.au

Phone

0494 618 595

Postal

17 Randle Street, Surry Hills, NSW 2010