Introduction
This Privacy Policy explains how we, Power Diary (ABN 14 147 141 188) protect the privacy of personal information. Power Diary provides internet-based software typically used to manage health practices and other appointment-based businesses. We are firmly committed to protecting the privacy and confidentiality of personal information and maintain robust physical, electronic and procedural safeguards to protect personal information in our care.
We’ve tried to make this Privacy Policy as easy to read as possible. After all, it’s your information and you deserve to know what we do to protect it, and all the rights you have. If there is anything you’re not sure of though, please contact our Data Protection Officer by emailing [email protected], and we’d be happy to answer any questions.
Definitions
We use a bunch of different terms in this policy. To make sure it’s clear what we are talking about, here are some definitions:
- Personal Data
Personal Data means data about a living individual that allows them to be identified from that data. It may be provided directly by a user, or provided indirectly by a user about their client (for example a health practitioner entering data about their patient). Personal information does not include “aggregate” information, which is data we collect about a group or category of products, services or people, from which individual identities have been removed. - Usage Data
Usage Data is data collected automatically either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit). - Cookies
Cookies are small pieces of data stored on a User’s device. - Data Processor
Data Processor means the person or entity that processes data on behalf of a data controller. According to GDPR and for the purposes of this policy, Power Diary is considered to be the data processor. - Data Controller
Data Controller means a person or entity who determines the purposes for which and the manner in which any personal data are, or are to be, processed. As part of using Power Diary you are likely to store personal data about your clients (or patients) in your Power Diary account. According to GDPR and for the purpose of this Privacy Policy, you, our customer and user, are considered to be the Data Controller of the data given to us to set up and manage a Power Diary account. - Sub Processors (or Service Providers)
Sub Processor (or Service Provider) means a person or entity who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process data more effectively. - User
The User (also referred to as our Customer) is the individual using our Service either directly or indirectly. The User is also referred to as the Data Subject and is any individual who can be identified via the Personal Data.
How we collect your data
Personal Data
While using our Service, we may ask users to provide us with certain personally identifiable information that can be used to contact or identify an individual (“Personal Data”). Personally identifiable information may include, but is not limited to: name, email address, telephone numbers, address, credit card details, cookies and information about that individual’s activities when directly linked to that person such as information about his or her use of the Power Diary website or services. Personal information can also include demographic information such as date of birth, gender, geographic area and preferences when such information is linked to other personal information that identifies an individual.
Where possible, we allow you to interact with us anonymously or by using a pseudonym. However, for most of our functions and activities, we will generally need your name and contact information and enough information about the matter to help you use the service effectively. If you choose not to provide your personal data, some functions and features on our websites and software may not be available and we may not be unable to provide you with all our services.
We don’t recommend it, but you can opt-out of receiving emails about new features and similar announcements by clicking on the ‘opt-out’ link or instructions in the email. Users cannot opt-out of receiving transactional emails or notifications relating to their account status, security announcements or other communication that might be essential to the operation of their account.
Of course, users that cease to use Power Diary, and all business with us is concluded (for example they have closed their practice and their Power Diary account), can opt-out of all communications from us.
Our users also enter personal data about their clients. This data can include sensitive information such as health records, and may include, but is not limited to: name, email address, telephone numbers, address, credit card details, insurance details, personal preferences, condition and treatment details. This data may also relate to minors and other vulnerable individuals who may be clients of Power Diary customers.
Usage Data
We may also collect information on how the Service is accessed and used (“Usage Data”). This Usage Data may include information such as users’ computer Internet Protocol address (IP address), browser type, browser version, the pages of our Service that they visit, the time and date of their visit, the time spent on those pages, unique device identifiers and other diagnostic data.
Tracking & Cookies Data
We use cookies and similar tracking technologies to track the activity on our Service and hold certain information.
Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to a user’s browser from a website and stored on their device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyse our Service.
Users can instruct their browser to refuse all cookies or to indicate when a cookie is being sent. However, if they do not accept cookies, they may not be able to use some or all of our Service.
Examples of Cookies and Pixels we use: session cookies (we use these cookies to operate our Service), pixels to understand the user journey and ensure we are not serving ads inappropriately (eg Facebook pixels), and preference cookies (we use these cookies to remember users’ preferences and various settings). Please refer to our Cookie Notice for more inforation.
How we use your data
We treat all information we collect directly or indirectly as strictly confidential. We do not rent, lease nor make available its customer lists or any other information contained in customer accounts (including client details), to third parties. We will not reveal, disclose, sell, distribute, rent, license, share or pass onto any third party (other than those who are contracted or supply services to us including spam filter operators) any personal information that may have been provided to us directly, or stored in a customer’s account unless we have express consent to do so, other than in the circumstances set out in this policy.
Service Provision
First and foremost we use the personal data we collect and hold to operate our web site and deliver our services. We use personal information to provide customers with: online appointment booking services, client management utilities, telehealth functionality, billing and credit control, and more.
Communication
We may use personal data to contact users with information about new features or announcements, to update users on the status of their account, to issue invoices, receipts, payment reminders, to provide training information, operational communications (like security updates), to send marketing communications, to seek feedback, or communicate other information that may be relevant.
Customer Support
We use personal data to provide assistance with the resolution of any technical support issues and to assist users with using our service.
Analysis and Development
We may also use data to improve the Power Diary service or product, analyse trends, and for monitoring the usage of the service, to detect, prevent and address technical issues.
Human Resources Data
We collect and process your personal data for the purposes of managing employment candidate applications and recruitment-related activities, as well as for organizational planning purposes.
We may use your personal data in relation to the evaluation and selection of applicants for recruitment purposes including scheduling and conducting interviews, tests, evaluations, and assessing results for candidate selection.
Legal Basis for processing under GDPR and UK GDPR
We will process your personal information lawfully, fairly and in a transparent manner. Power Diary’s legal basis for collecting and using the personal information described in this Privacy Policy depends on the Personal Data we collect and the specific context in which we collect it.
Power Diary may process your Personal Data because:
- You have given us permission to do so (consent);
- The processing is in our legitimate interests and it’s not overridden by your rights;
- To comply with the law.
When we process personal data for purposes that are in our legitimate interests, we have carried out a Legitimate Interest Assessment to confirm what these interests are, to consider what effect the processing has on individuals, and to check if our interests in processing could be outweighed by individuals’ interests.
Location of Your Data
Unless otherwise stated in this Privacy Policy, your data will not be stored outside of Australia, Canada, the UK or the USA.
How your data might be shared
Power Diary will not disclose any personal data uploaded to our servers to anyone else without permission, except for the following reasons;
Legal or Moral Requirement
In rare circumstances, where permitted or required by law, requested and needed for a client’s emergency treatment in exceptional circumstances, or for the prevention of immediate risk of loss of life or serious harm; to various regulatory bodies and law enforcement officials and agencies to protect against fraud and for related security purposes, we will share the personal data necessary.
Infrastructure Sub-Processors
In order to provide our services to customers and their clients, Power Diary employs various third party companies and individuals to assist with providing the service. Where necessary, we share a limited amount of personal data with our third-party service providers and sub processors. In all cases, we provide only the minimum amount of personal data that is needed to perform the service and take reasonable steps to ensure these parties have appropriate data protection safeguards in place.
A list of our sub-processors is as follows;
Entity Name | Corporate Location | Activities |
---|---|---|
Amazon Web Services, Inc (AWS) | United States | Web hosting |
NewRelic | United States | Application performance monitoring |
Message Media | Australia | Sending and receiving text messages |
Helpscout | United States | Support tickets, live chat |
Google, LLC | United States | Analytics |
Stripe | Ireland | User payments |
Send Grid | United States | Email sending |
Mailchimp | United States | Email sending |
Atlassian | Australia | Issue tracking, feature requests |
FirstPromoter* | Romania | Referral program |
Twilio | United States | Parts of telehealth video calls |
SecurePay | Australia | Payments |
Formagrid, Inc | United States | CRM system |
*If a user signs up via a link from an affiliate partner, their email and monthly subscription payments will be known to the referrer, but no other data will be shared.
Integration Sub-Processors
There are also sub-processors involved when certain integrations are used. These services are optional and only used if enabled by the data controller. Power Diary takes care to select integration partners who, at the time of the integration, have good data management policies in place and will only share the data necessary for the integration to work effectively. However, the responsibility lies with the user to determine the suitability of integrating and sharing data with these vendors.
The sub-processors involved in Power Diary integrations include;
Entity Name | Corporate Location | Activities |
---|---|---|
Medicare Australia | Australia | Insurance payments |
Xero | New Zealand | Invoices and payment |
Physitrack | United Kingdom | Client exercise prescriptions |
Tyro | Australia | Client payments |
Google LLC | United States | Calendar syndication |
Mailchimp | United States | Client communication |
Stripe | United States | Client payments |
Corporate Transactions
In the unlikely event that Power Diary is involved in a merger, acquisition or asset sale, Personal Data may be shared during negotiations and ultimately transferred as part of the completed transaction. However all data remains subject to the promises made in this Privacy Policy unless, of course, the customer agrees to be subject to new Privacy Policy terms.
International Data Transfers
Power Diary operates internationally and we may share, transfer and process data in countries other than the country you live in. These countries may have different laws but rest assured that when we share personal data to a third party, we take all reasonable steps to ensure that personal data remains protected in the manner you would expect. For individuals in the European Economic Area (EEA), your data may be transferred outside of the EEA but it will only be transferred to countries that provide adequate protection, or to a third party where we have reviewed their data protection processes and policies for adherence to the GDPR Standard Contractual Clauses.
Keeping your data secure
Power Diary will take reasonable steps to protect the personal information we hold from any misuse, interference, loss, and unauthorised access, modification or disclosure.
Security Precautions
Power Diary has an extensive range of security measures in place to protect personal information from unauthorised access, use, or loss. Our servers are maintained in a controlled and secured environment and access is restricted to only those who need it in order to provide the service.
Your Role
Our users also have an important role to play in keeping data secure. You are responsible for maintaining the confidentiality of your account details and password. Your passwords protect your personal information and you are responsible for any activities that occur in your account or in respect of your use of this service. Please let us know immediately if you suspect that the security of your password or account has been compromised in any manner.
Protecting Your Clients
You are responsible for making sure that your clients’ / patients’ privacy and associated rights are respected. As your Data Processor, we will take care to protect the privacy of your clients and will process their Personal Data in accordance with the terms of our agreement with you, and under your lawful instruction. Power Diary may provide options for you to integrate with various third-party systems however we do not control how, nor take responsibility for, the manner in which other systems manage personal data. You must assess for yourself the suitability of utilising third-party services in your context.
Links to Other Sites
Our service may contain links to other sites that are not operated by Power Diary. If you click on a third party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Exemptions
Note that this policy refers to customer and user data and where applicable, the employee records exemption in the Privacy Act and any other applicable exemptions in the Privacy Act or other legislation will apply.
How we retain your data
We will retain Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will also retain and use Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
We will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.
Your rights to your data
We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data. If you are a resident of the European Economic Area (EEA), you have certain data protection rights, and we extend these rights to all users.
In certain circumstances, you have the following data protection rights:
- The right to access, update or to delete the information we have on you.
- The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete.
- The right to object. You have the right to object to our processing of your Personal Data.
- The right of restriction. You have the right to request that we restrict the processing of your personal information.
- The right to data portability. You have the right to be provided with a copy of your Personal Data in a structured, machine-readable and commonly used format.
- The right to withdraw consent. You also have the right to withdraw your consent at any time where Power Diary relied on your consent to process your personal information.
If you wish to be informed about what Personal Data we hold about you and if you want it to be removed from our systems, please email [email protected]. Please note that we may ask you to verify your identity before responding to such requests. (If you are a patient or client of a business that uses Power Diary you will need to contact that business directly to discuss and evoke your protection rights.)
If you live in the EEA, you have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).
Changes to this policy
From time to time, we may review and update this Privacy Policy. Revised versions will be updated on this website and be effective once posted.
How to contact us
We welcome your feedback. If you have any questions or concerns about our Privacy Policy or our privacy practices, if you would like to make a request for information, or if you believe that we have not complied with this policy, the Privacy Act, or other privacy obligations, please contact us at:
Attention: Data Protection Officer
Email: [email protected]
Telephone: If you would prefer to speak by telephone, please email us with your
contact details and concerns, and we will respond in a timely manner
Power Diary treats your privacy seriously and any complaints will be assessed by an appropriate person with the aim of resolving any issue in an efficient and timely manner.
If you are not happy with our handling of your privacy concerns, you can also contact your local data protection authority. Depending on your location, you can use the following links;
- Australia: Office of the Australian Information Commissioner (OAIC)
- United Kingdom: Information Commissioner’s Office (ICO)
- United States: State Consumer Protection Offices (select based on your state)
These organisations are independent from Power Diary and can investigate privacy complaints.
Appendix 1: For individuals based in California
This section provides additional specific information for consumers based in California as required by the California Consumer Privacy Act of 2018 (“CCPA”).
Collection and Use of Personal Information
In the last 12 months, we may have collected the following categories of personal information:
- Identifiers, such as your name, mailing address, email address, zip code, telephone number, or other similar identifiers.
- California Customer Records (Cal. Civ. Code § 1798.80(e)), such as username and password, company name, job title, business email address, and department.
- Internet/Network Information, such as your browsing history, log and analytics data, information about the device(s) used to access the Services and information regarding your interaction with our websites or Services and other usage data.
- Geolocation Data, such as information about your location (at country and city level) collected from your IP address.
- Sensory Information, the content, audio and video recordings of conference calls between you and us that we record where permitted by you and/or the law.
- Profession/Employment Information that you include in your CV, cover letter and send to us when applying for a position.
- Other Personal Information, such as personal information you provide to us in relation to a survey, comment, question, request, article download or inquiry and any other information you upload to our Application.
We collect personal information directly from you, from your browser or device when you visit our websites, from third parties that you permit to share your information or from third parties that share public information about you and as stated above.
See the sections above, “How we use your data,” to understand how we use the personal information collected from California consumers.
Recipients of Personal Information
We share personal information with third parties for business purposes. The categories of third parties to whom we disclose your personal information may include: (i) our service providers and advisors, (ii) marketing and strategic partners; (iii) ad networks and advertising partners; (iv) analytics providers; and (v) social networks.
Please see the “How your data might be shared” section of the Privacy Policy above for more information.
California Privacy Rights
As a California resident, you may be able to exercise the following rights in relation to the personal information about you that we have collected (subject to certain limitations at law):
- The Right to Know any or all of the following information relating to your personal information we have collected and disclosed in the last 12 months, upon verification of your identity:
- The specific pieces of personal information we have collected about you;
- The categories of personal information we have collected about you;
- The categories of sources of the personal information;
- The categories of personal information that we have disclosed to third parties for a business purpose, and the categories of recipients to whom this information was disclosed;
- The categories of personal information we have sold and the categories of third parties to whom the information was sold; and
- The business or commercial purposes for collecting or selling the personal information.
- The Right to Request Deletion of personal information we have collected from you, subject to certain exceptions.
- The Right to Opt-Out of Personal Information sales to third parties now or in the future. However, we do not sell your personal information.
You also have the right to be free of discrimination for exercising these rights.
Please note that if the exercise of these rights limits our ability to process personal information (such as a deletion request), we may no longer be able to provide you with our products and services or engage with you in the same manner.
How to Exercise Your California Consumer Rights
To exercise your right to know and/or your right to deletion, please submit a request by emailing us at: [email protected].
We will need to verify your identity before processing your request.
In order to verify your identity, we will generally require sufficient information from you so that we can match it to the information we maintain about you in our systems. Sometimes we may need additional personal information from you to be able to identify you. We will notify you.
We may decline a request to exercise the right to know and/or right to deletion, particularly where we are unable to verify your identity or locate your information in our systems or as permitted by law.
You may choose to designate an authorized agent to make a request under the CCPA on your behalf. No information will be disclosed until the authorized agent’s authority has been reviewed and verified. Once a request has been submitted by an authorized agent, we may require additional information (i.e. written authorization from you) to confirm the authorized agent’s authority.
If you are an employee/former employee of a Power Diary customer that uses our application and services, please direct your requests and/or questions directly to your employer/former employer.
If you are a third party (auditor, business associate etc.), who was given access to the Power Diary application by a Power Diary customer, please direct your requests and/or questions directly to the customer that gave you access.
Last updated: 22nd November 2021