Assessments and Answers Psychology

Privacy Policy

INTRODUCTION

At Assessments and Answers Psychology Pty Ltd your privacy and treatment of personal information are of paramount importance. This Privacy Policy explains what personal information we collect, why we collect personal information, and how we collect, use, disclose, store and protect your personal information when you visit our website at https://assessmentsandanswerspsychology.com/ (Website), use our psychological assessment services, or continue to use our services. As a healthcare provider, we are committed to maintaining the highest standards of privacy protection for sensitive health information, in accordance with Australian privacy laws.

Our Privacy Policy also explains how to contact us to correct, update or delete any personal information provided to us, or make a complaint if you have concerns. We are compliant with the Privacy Act 1988 (Privacy Act) and the Australian Privacy Principles (APPs).

We maintain secure records of all user consents and withdrawals to ensure compliance with data protection regulations and to respect your privacy choices. These records are kept for the duration of our relationship with you and for a reasonable period thereafter as required by applicable laws.

Unless otherwise indicated by the context words importing the singular include the plural and vice versa.

CHANGES THAT WE MAKE TO OUR PRIVACY POLICY

We will notify you about any changes to our Privacy Policy by updating the “Last Updated” date of this Privacy Policy and posting the updated version on our Website. You are encouraged to periodically review this Privacy Policy to stay informed of updates. We will seek your explicit consent for any changes in our Privacy Policy that affect how we process your personal information, particularly regarding sensitive health information or changes to our information sharing practices. If you do not agree with the changes, you may choose to stop using our services, though we will continue to protect any information previously collected in accordance with the privacy policy under which it was collected.

COLLECTION OF YOUR PERSONAL INFORMATION BY THIRD PARTIES

This Privacy Policy does not apply to any third-party services or websites which we connect to, and which may also collect and use information about you. We are not responsible for the privacy practices of any third party, including but not limited to payment processors, or other healthcare practitioners who may be involved in your care. We encourage you to review the privacy policies of all third-party services you interact with through our platform.

WHICH ENTITIES DOES THIS PRIVACY POLICY COVER?

This Privacy Policy applies to us with respect to content on our Website, our psychological assessment services, and information you provide to us about yourself through any of our service delivery channels.

WHAT IS PERSONAL INFORMATION?

Personal information is defined as information, whether true or not, about an individual who can be identified:

a. From that information; or

b. From that information and other information to which the organisation has or is likely to have access. This includes both general personal information such as your name and contact details, as well as sensitive personal information such as health records, medical history, and information about your physical and mental health.

WHEN AND HOW DO WE COLLECT YOUR PERSONAL INFORMATION?

We collect most personal information directly from you when you consent to use our services or receive communications from us, or information we receive from third parties such as your treating general practitioner, specialist medical practitioners, paediatrician or psychiatrist. Your consent may be express (for example, you agree to the use of your information by completing our online intake forms when you become a client) or implied by an action you take or do not take (such as because you have agreed to terms and conditions that contain information about the use or disclosure of your information).

You provide us your information when you use our psychological assessment services, complete our online intake questionnaires, communicate with our team, or you use our Website generally or you deal with us in any capacity related to your healthcare journey.

WHAT PERSONAL INFORMATION DO WE COLLECT?

Personal Information

We may collect and process various types of personal information, including sensitive personal information. Sensitive personal information includes information such as racial or ethnic origin, political opinions, religious beliefs, health information, or biometric information (Sensitive Information). When we collect Sensitive Information, we implement additional safeguards to protect this information, including enhanced security measures, stricter access controls, and specialised handling procedures in compliance with applicable laws and regulations.

We may provide Sensitive Information relating to your health to other medical service providers, such as your general practitioner or specialist medical practitioners, and we may disclose your Sensitive Information to third party service providers whom we engage to support our clinical operations and service delivery. We will only supply this information with your consent, or in circumstances where it is required for the delivery of health services, such as referral to another health service provider, where it is necessary to prevent or lessen a serious threat to a patient’s life, health or safety, or other reason as permitted by law.

We collect personal information necessary for providing psychological assessment services. This includes:

Demographic and Contact Information

Your child’s and parents’/guardians’ full name, date of birth, gender, pronouns, residential address, postal address, telephone numbers, email address, emergency contact details, and next of kin information as required for our service delivery and emergency contact purposes.

Government and Healthcare Identifiers

Medicare number (if applicable for rebates), and any relevant pension concession card details that may affect your healthcare entitlements.

Health and Medical Information

We collect extensive Sensitive Information including your child’s perinatal and developmental history, family history of mental health diagnoses or suspected presentations, physical health summary, developmental and behavioural challenges, any previous assessments completed, and any previous interventions and response to intervention.

Clinical Assessment Data

We collect information from our assessments, which may include video recordings with your informed consent. These recordings are used for assessment clarity and report writing and are deleted upon completion of the assessment and report. We also use AI clinical note-taking software services such as NovoNote and Heidi Health to assist with gathering relevant client information.

AI-Assissted Healthcare Services

Our service utilises BastionGPT, a secure AI-powered healthcare assistant designed exclusively for trained healthcare professionals, to assist with clinical documentation, information retrieval, and administrative tasks related to your psychological assessment services. BastionGPT operates under strict ethical guidelines consistent with medical professional standards and complies with relevant healthcare data protection laws including APPs.

When using BastionGPT, we may process your personal and health information through this secure AI system to:

  • Assist with clinical documentation and report preparation
  • Support information retrieval and analysis during assessments
  • Enhance the accuracy and efficiency of our clinical record-keeping
  • Facilitate administrative tasks related to your care

BastionGPT processes only the minimum necessary information required to fulfill the requested healthcare task. All data processed through BastionGPT is encrypted both in transit and at rest, and the system does not retain, store, or use your data beyond the duration of the active session unless explicitly required for your ongoing care. Your information is never used for secondary purposes such as AI training, marketing, or any other purpose unrelated to your healthcare.

Third-Party Medical Information

We collect information from third parties with your consent, including paediatricians, psychiatrists, general practitioners, and allied health providers (for example psychologists, occupational therapists, speech therapists, physiotherapists). This may include reason for referral, diagnoses, previous assessments, medications, and NDIS goals and supports.

Additional Information Collected

Additionally, we may collect credit card and other payment information for billing purposes, identifying information about yourself and any authorised representatives, device information when you visit our website including your device ID, browser type and version, device type, geo-location information, computer and connection information, statistics on page views, traffic to and from our website, IP address and standard web log information, details of the services we have provided to you or that you have enquired about, including any additional information necessary to deliver those services and respond to your enquiries, any additional information relating to you that you provide to us directly through our website, or use of our services, information you provide about yourself when you communicate with us or others when you use our services, information you provide to us through surveys or feedback forms, and any other personal information that is directly related to and necessary for facilitating your dealings with us, as explicitly stated at the time of collection.

Collection Methods

Our practice employs digital collection methods designed to ensure accuracy, security, and efficiency in gathering the comprehensive information required for psychological assessments. We collect personal information through:

  • Digital intake and consent forms administered through our secure practice management system (Zanda)
  • Direct psychological assessments conducted in home, school or clinic environments
  • Electronic communication channels including secure email correspondence for receiving test results, medical reports, and parent/teacher-shared photographs or documents that support clinical assessment and care coordination
  • Information sharing arrangements with authorised family members, support persons, or carers, implemented only with your explicit written consent and documented through our secure digital consent management system
  • Third-party healthcare provider communications including referral documents, specialist reports, and clinical correspondence from your general practitioner, specialist medical practitioners, allied health providers, and other healthcare professionals involved in your child’s care

We may collect these types of personal information either directly from you, or from third parties or from third party applications you control and give us access to. We may collect this information when you register for our services through our website, communicate with us through correspondence, secure messaging, email, or when you share information with us from other healthcare providers or medical applications, interact with our Website, services, content and communications, or engage with our psychological assessment services.

You can choose not to provide us with your personal information. However, please note that if you do not provide this information, you may not be able to take full advantage of some of the features of our services. It is important to note that the provision of personal information is voluntary. You have the right to withdraw your consent at any time, in which case you should contact us using the contact details provided in this policy. However, withdrawal of consent may impact our ability to provide certain services, particularly those requiring comprehensive medical information for safe and effective care delivery.

WHY DO WE COLLECT YOUR PERSONAL INFORMATION?

We may collect your personal information when required by law, but generally we collect personal information from you (or about you) to allow us to provide you with our comprehensive psychological assessment services, to improve understanding of presenting challenges and influencing factors, to determine a clinical profile and provide personalised recommendations, to assist with care planning, to send administrative information including appointment confirmations, to respond to inquiries and offer comprehensive patient support, to respond to legal requests and prevent harm to patients or others, to communicate more effectively with you about our services and your child’s care, and to ensure your experience with us is positive, safe, and therapeutically beneficial.

Personal information collected or received by us will only be used for the stated purpose for which it was provided, or for purposes that are directly related to the primary purpose of collection and would be reasonably expected by you in the circumstances.

WHEN DO WE DISCLOSE YOUR PERSONAL INFORMATION?

We may collect, hold, use and disclose your personal information for the following purposes: to enable you to access and use our psychological assessment services, to operate, protect, improve and optimise our services, business operations and our patients’ experience, such as to perform clinical quality assessments, to send you service, support and administrative messages, reminders, technical notices, updates, security alerts, and information requested by you, and to comply with our legal obligations, resolve any disputes that we may have with any of our users, and enforce our agreements with third parties.

We may also disclose your personal information to a trusted third party who also holds other information about you. This third party may combine that information in order to enable it and us to develop anonymised consumer insights so that we can better understand your preferences and interests, personalise your experience and enhance the products and services that you receive.

We may disclose personal information for the purposes described in this privacy policy to:

  • Our employees and related bodies corporate
  • Third party suppliers and service providers (including providers for the operation of our websites and/or our business or in connection with providing our products and services to you)
  • Secure AI healthcare systems (such as BastionGPT) for clinical documentation and information processing, operating under strict privacy and security protocols with no data retention beyond active sessions
  • Professional advisers, dealers and agents
  • Payment systems operators (e.g., merchants receiving card payments)
  • Our existing or potential agents, business partners or partners
  • Anyone to whom our assets or businesses (or any part of them) are transferred
  • Specific third parties authorised by you to receive information held by us
  • Other persons, including government agencies, regulatory bodies and law enforcement agencies, or as required, authorised or permitted by law

We maintain strict consent protocols for all information sharing, recognising the sensitive nature of health information and the importance of maintaining patient confidentiality while ensuring comprehensive care coordination.

Third-Party Information Sources and Healthcare Provider Relationships

Our practice receives information from various third-party sources essential for providing psychological assessment services. We maintain consent protocols for all third-party information sharing, recognising the importance of care coordination while protecting patient privacy.

We receive clinical information from specialist medical practitioners who provide diagnostic reports, treatment recommendations, and other relevant information. General practitioners provide medical histories, current treatment plans, and clinical summaries that inform our psychological assessments.

We may receive information from or provide information to other healthcare practitioners involved in your child’s care, including allied health professionals, specialist consultants, and other medical practitioners, ensuring that all communications are properly documented and consent is established and maintained.

With appropriate authorisation, we may receive information from or provide information to legal representatives, insurance providers, or other authorised parties assisting with healthcare-related matters, ensuring that all communications comply with privacy requirements and are properly documented.

OVERSEAS DISCLOSURE AND DATA TRANSFER

We may transfer information we receive about you, including all personal information, to our hosting service providers and data centres, which may be located overseas, subject to compliance with the APPs, specifically APP 8 – Cross-border Disclosure of Personal Information. Our primary service providers including Zanda and Novopsych may utilise cloud infrastructure that involves data storage or processing in overseas jurisdictions.

You acknowledge that such transfers may occur, and that any information that we transfer may be subject to laws, regulations, and privacy frameworks of the countries where our service providers operate their infrastructure. We take reasonable steps to ensure that overseas recipients of your personal information are subject to privacy and security standards that are substantially similar to the APPs, through contractual arrangements, service provider certifications, and regular compliance assessments.

Where we disclose personal information to overseas recipients, we will take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to that information, unless you have consented to the disclosure or an exception under the Privacy Act applies. We maintain records of all overseas disclosures and the safeguards in place to protect your information during international transfers.

HOW DO WE STORE AND PROTECT YOUR PERSONAL INFORMATION?

Technical Security Measures

In compliance with the requirements under APP 11, we have implemented technical security measures including multi-factor authentication for all system access across our organisation, encryption of sensitive information both in transit and at rest using industry-standard protocols, secure server infrastructure provided through certified cloud service providers with appropriate Australian data sovereignty protections, and regular security monitoring and threat assessment protocols.

Our practice management system (Zanda) employs enterprise-grade security features including role-based access controls that limit information access based on clinical need and staff role requirements, audit logging of all information access and modifications with detailed tracking of user activities, automated backup systems with encryption to ensure data integrity and recovery capabilities, and secure remote access protocols for cloud-based operations that maintain security standards regardless of access location.

All clinical information is stored within secure, encrypted databases hosted by our certified practice management system providers. Our systems are designed to ensure that no patient information is stored on mobile devices, portable storage devices, or unsecured local systems.

Our AI-assisted healthcare services (such as BastionGPT) employ additional security measures including:

  • End-to-end encryption for all data transmission to and from the AI system
  • No data retention or storage beyond the active session duration
  • Restricted access limited to authorised healthcare professionals only
  • Comprehensive audit logging of all AI system interactions for accountability and compliance
  • Regular security reviews and updates to maintain compliance with evolving healthcare data protection standards
  • Strict prohibition on using client data for AI training, marketing, or any secondary purposes

Organisational Security Measures

We have established comprehensive organisational security protocols including structured access privilege systems that limit information access based on clinical need and role requirements, with our contract psychologists having access to clinical information, and any future administrative/operations manager having access to basic client information. We have account deactivation procedures when staff members leave the organisation, regular staff training on privacy and security obligations through employment contracts and ongoing professional development, and documented incident response procedures for potential security breaches that ensure rapid response and appropriate notification protocols.

Our security framework includes regular assessment of our technology platforms and service providers to ensure ongoing compliance with medical practice security standards and privacy requirements.

Information Handling Protocols

All patient communications received via email are imported into our secure practice management systems and deleted from external email accounts to minimise exposure risks and ensure all patient information is maintained within our secure clinical record systems.

Our telehealth consultation platforms (Zoom via Zanda, and Microsoft Teams) operate under strict privacy agreements with end-to-end encryption, ensuring that consultation content is never stored on intermediate servers and remains accessible only to authorised participants.

We have taken the necessary measures to ensure the personal information we hold is not compromised. In accordance with and as permitted by applicable law and regulations we will retain your information as long necessary to serve you, to maintain your clinical record, or as otherwise required to operate our services safely and effectively.

However, we cannot be held liable for events outside our control, including security breaches of third-party systems, internet infrastructure failures, or other circumstances beyond our reasonable control. We will take reasonable steps to maintain the integrity and security of any personal information we have stored, including taking reasonable steps to prevent interference and loss, misuse, unauthorised access, modification or disclosure of such personal information.

Note that no information transmitted over the Internet can be guaranteed to be completely secure. While we will endeavour to protect your personal information as best as possible, we cannot guarantee the security of any information that you transmit to us or receive from us. The transmission and exchange of information is carried out at your own risk.

It is important that you protect your privacy by ensuring that no one obtains your personal information, and you must contact us directly if your details change. Should your information be erroneously provided to us or no longer remain valid within the constraints of this Privacy Policy we will securely destroy or de-identify it as soon as practicable, as long as it is lawful to do so.

We have obligations to notify you if you are affected by a data breach. We will take all reasonable precautions to take remedial action to prevent such an event. However, as we cannot guarantee that remedial action will be sufficient to prevent all instances of a breach, we will take steps to notify you of an eligible data breach as soon as practicable, and provide recommendations as to what steps you should take to mitigate any serious issues.

YOUR RIGHTS ABOUT YOUR PERSONAL INFORMATION

You may exercise certain rights regarding your personal information which we process. In particular, you have the right to withdraw consent where you have previously given your consent to the processing of your personal information, object to the processing of your personal information if the processing is carried out on a legal basis other than consent, learn if your personal information is being processed by us, obtain disclosure regarding certain aspects of the processing and obtain a copy of the personal information undergoing processing, verify the accuracy of your personal information and ask for it to be updated or corrected, restrict the processing of your personal information under certain circumstances, and obtain the erasure of your personal information from us under certain circumstances.

You have the right to be informed about AI processing of your personal information and to understand how our AI service providers assist in your healthcare delivery. You may request information about AI system interactions with your data and can withdraw consent for AI-assisted processing while continuing to receive our standard healthcare services.

Access to Your Information

You have the right to request access to the personal information we hold about you. We will provide you with access to your personal information within a reasonable period, generally 30 days of receiving your request, unless there are exceptional circumstances that require additional time for processing. We provide access to information in a format that is readily understandable and, where possible, in the format you have requested.

We may refuse to give you access to personal information in certain circumstances permitted under the Privacy Act, including where giving access would pose a serious threat to the life, health or safety of any individual, or to public health or public safety, where giving access would have an unreasonable impact on the privacy of other individuals, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings, where giving access would reveal our intentions in relation to negotiations with you in such a way as to prejudice those negotiations, where giving access would be unlawful, where denying access is required or authorised by or under an Australian law or a court/tribunal order, or where we have a reasonable belief that there is an ongoing or potential unlawful activity or serious misconduct that could be impacted detrimentally by granting access.

If we refuse to give you access, we will provide you with reasons for our refusal, unless doing so would be unreasonable in the circumstances. We will also take reasonable steps to give you access in a way that meets your needs without giving rise to the reasons of our refusal. Further, we will provide details of how you may make a complaint about our decision.

Correction of Your Information

You have the right to request correction of personal information we hold about you if you believe it is inaccurate, out of date, incomplete, irrelevant, or misleading. Our team aims to update information within a reasonable timeframe of receiving your correction request, and we will confirm with you in writing once the corrections have been made. If we refuse to correct your personal information, we will provide you with written reasons for our refusal and information about how you can make a complaint about our decision.

Deletion of Your Information

You can request deletion of your personal information by contacting us at admin@assessmentsandanswerspsychology.com.au. However, we maintain medical records for at least 7 years after the last client contact, and for minors, records must be kept until the child turns 25 years old. When personal information is deleted, we archive your patient profile while maintaining the clinical record for the required retention period. There may be circumstances where we cannot comply with deletion requests, such as where retention is required by law or where the information is necessary for legal proceedings.

CONSENT FOR AI-ASSISTED HEALTHCARE SERVICES

We obtain informed consent before processing your personal and health information through our AI service providers (such as BastionGPT). During your initial consultation and intake process, we will:

  • Explain how our AI service provider assists in your healthcare delivery
  • Describe the security measures and privacy protections in place
  • Inform you of your rights regarding AI-assisted processing of your information
  • Provide you with the opportunity to consent to or decline AI-assisted services
  • Maintain detailed records of your consent decisions regarding AI system usage

You may withdraw your consent for AI-assisted processing at any time by contacting us at admin@assessmentsandanswerspsychology.com.au. Withdrawal of consent for AI processing will not affect your ability to receive our psychological assessment services, though it may impact the efficiency of certain administrative and documentation processes.

HOW LONG DO WE KEEP YOUR PERSONAL INFORMATION

Information Retention Periods

As a healthcare provider operating in Queensland and providing services across Australia, we maintain personal information in accordance with healthcare record retention requirements and professional obligations under Australian healthcare regulations.

Standard Retention Period

We retain all clinical records and personal information for a minimum of seven years after the date of the last clinical entry or service provision. For patients who were minors at the time of treatment, we retain records until the patient attains or would have attained the age of 25 years, or for a minimum of seven years after the date of the last entry, whichever period is longer.

Consent and Communication Records

Records of consent for information sharing, communication with healthcare providers, and other privacy-related decisions are maintained as part of the clinical record and are subject to the same retention periods.

We are committed to regularly reviewing and updating our information retention periods to ensure compliance with legal requirements and best practices in information protection. Personal Information shall be processed and stored for as long as required by the purpose they have been collected for. We ensure that personal information is minimised to what is necessary during the retention period and securely deleted or anonymised when no longer needed. Personal Information collected for purposes related to the performance of a contract between us and you shall be retained until such contract has been fully performed. Personal information collected for the purposes of our legitimate interests shall be retained as long as needed to fulfil such purposes.

We will retain personal information for a longer period if we are required to do so by law or by an order from a legal authority. Exceptions to our standard retention periods may apply in cases of ongoing legal disputes, investigations, or other legitimate business needs that require extended retention. In such cases, we will retain the relevant information only for as long as necessary to fulfil these specific purposes.

Once the retention period expires, personal information shall be securely deleted through our information management systems. The right of access, the right to erasure, the right to rectification and the right to information portability cannot be enforced after expiration of the retention period.

AUTOMATED DECISION MAKING AND TECHNOLOGY-ASSISTED SERVICES

We inform you of the following automated systems that may be utilised in your care:

Practice Management Automation

Our practice management systems include automated features for appointment scheduling, payment processing, and communication delivery. These systems operate under predefined parameters and do not make decisions that would negatively impact your care or access to services. All automated processes are subject to human oversight and can be reviewed or modified by our clinical and administrative staff.

Communication and Reminder Systems

We utilise automated systems for sending appointment reminders and administrative communications. These systems are designed to support your healthcare journey and ensure you receive timely information about your care. You may opt out of non-essential automated communications while continuing to receive clinically important notifications.

No Automated Clinical Decision Making

We do not utilise automated systems for clinical decision making, diagnosis, treatment recommendations, or clinical assessments. All clinical decisions, treatment plans, and healthcare recommendations are made by qualified medical practitioners using professional clinical judgement and evidence-based medicine principles.

You have the right to request human review of any automated processes and to understand how these systems operate in relation to your care. We will provide additional information about our automated systems upon request and ensure that you maintain control over automated communications and processes that affect your healthcare experience.

COMPLAINT PROCEDURES

If you have concerns about how we handle your personal information, you may lodge a complaint with us by contacting admin@assessmentsandanswerspsychology.com.au or calling (07) 3556 7971. We will investigate all complaints promptly and provide a formal response within a reasonable timeframe considering the circumstances, typically within 30 days of receiving your complaint.

Our complaint handling process includes acknowledgment of your complaint within 7 days, investigation of the matter by appropriate personnel, consultation with relevant staff and service providers where necessary, and provision of a written response outlining our findings and any corrective actions taken within a reasonable time.

If you are not satisfied with our response, you may contact the OAIC at enquiries@oaic.gov.au or 1300 363 992. You may also have rights to seek review through other regulatory bodies or legal proceedings as appropriate to your circumstances.

WEBSITE AND DIGITAL PLATFORM PRIVACY

Our Website includes contact forms collecting names, email addresses, and messages from prospective patients. This information is used solely for responding to enquiries and is subject to the same security and privacy protections as all other personal information collected by our practice.

We integrate online booking functionality with our practice management system, allowing patients to schedule appointments through secure web interfaces. All booking information is directly integrated into our clinical record system and protected under our comprehensive privacy framework.

Our website utilises analytics tools to improve user experience and understand website usage patterns. We implement appropriate consent management systems and provide clear information about the types of data collected, their purposes, and options for managing your preferences regarding website analytics and tracking.

We utilise secure digital communication for appointment confirmations, cancellations, and reminders via SMS and email. These communications are generated through our practice management system and are subject to our standard privacy protections and security measures.

CONTACT INFORMATION
ENQUIRIES, REQUESTS & COMPLAINTS

Privacy Officer and Contact Information
Privacy Officer: Alexandra Catt
Email: admin@assessmentsandanswerspsychology.com.au
Phone: (07) 3556 7971

Practice Information:
Practice Name: Assessments And Answers Psychology Pty Ltd
ABN: 37 671 096 736
ACN: 671 096 736

For all privacy-related enquiries, access requests, correction requests, complaints, or concerns about how we handle your personal information, please contact our Privacy Officer using the details above. We are committed to responding to all privacy-related communications promptly and professionally.

If you think your personal information, held by us, may have been compromised in any way or you have any other Privacy related complaints or issues, you should also raise the matter with the Privacy Officer.

If we do not resolve your enquiry, concern or complaint to your satisfaction or you require further please contact the Privacy Commissioner Australia, whose contact details are below.

Office of the Australian Information Commissioner
Telephone: 1300 363 992
Email: enquiries@oaic.gov.au Office
Address: Level 3, 175 Pitt Street, Sydney NSW 2000
Postal Address: GPO Box 5218, Sydney NSW 2001
Website: www.oaic.gov.au 
DATE OF CURRENT VERSION: 22/09/2025

 

Scroll to Top