Elemnt Technologies Pty Ltd (ABN 33 672 926 082) operates Elemnt Health. In this policy, "Elemnt," "we," "us," and "our" mean Elemnt Technologies Pty Ltd.
This policy explains what personal information we collect, why we hold it, and what you can ask us to do with it. It covers our website at elemnt.health and the Elemnt Wellness application at wellness.elemnt.health. We refer to the two together as the Services.
We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and those obligations apply to us in full, whatever our size.
Who this policy covers
Different parts of this policy apply to different people. It uses the following terms for them throughout.
- Visitors browse our website, contact us, or ask to hear from us.
- Practitioners use the application in their practice. An account may be held by an individual practitioner or by the clinic or practice they work in, and each person using it has their own login.
- Client Data is information about a Practitioner’s own patients or clients, including pathology results, that a Practitioner uploads. Section 5 explains how it is handled and who is responsible for what.
- Patients are the people Client Data is about. They do not hold accounts with us. A Practitioner may share a report or dashboard with a patient through a link we host. Section 1 sets out what we collect when that happens.
The application is not for records about people under 18. Practitioners must not upload them, and our Terms of Use make that a condition of holding an account.
1. What we collect and hold
From Visitors
- Your name and email address, along with anything else you choose to tell us in a form or an email.
- Your practice or business name and your role, if you give them to us.
- Technical information about your visit: the pages you viewed, the date and time, how long you stayed, the site you arrived from, your browser and device, and an approximate location worked out from your IP address.
We do not need health information from Visitors, and we ask you not to send any through our website forms. If we receive health information we did not ask for and could not have collected, we destroy it or de-identify it, as the Privacy Act requires.
From Practitioners
- Account details, including your name, email address, and password. Passwords are stored only as a cryptographic hash, so we cannot read yours.
- Your practice details, your professional role, and your professional registration number where you hold one.
- Billing details. Card numbers are handled by our payment provider and never reach our systems.
- A record of how you use the application, including sign-ins, uploads, and the reports you generate.
- Any correspondence you have with our support team.
Client Data
- Pathology and blood test results a Practitioner uploads.
- The identifying details attached to those results, including name, date of birth, and sex. We hold these so that records display correctly for the Practitioner working with that person.
- Clinical context a Practitioner records against them, such as episodes, notes, and observations.
- The insights and reports the application derives from the above.
- Anything else contained in the documents themselves. A pathology report may carry further details, such as a Medicare or health insurance number. We store the document as it was given to us, and we do not extract those numbers, use them to identify anyone, or adopt one as our own reference for a person.
Client Data is health information, which the Privacy Act treats as sensitive information. We hold it to the higher standard that classification requires.
Practitioners decide what to upload. Where a document contains details you would rather we did not hold, redact them or upload only the results.
From Patients
When a Practitioner shares a report or dashboard, the link is hosted by us and protected by a password that the Practitioner sets and gives to the patient. If you open one, we record that it was opened, when, and basic technical details of the device and browser used. We do this to make the link work and to keep it secure. We do not create an account for you, contact you using these details, or use them for marketing.
2. How we collect it
Most of what we hold, you give us directly: by filling in a form, creating an account, uploading a result, or writing to us. Some of it is collected automatically as you use the Services, through cookies, log files, and similar technologies, which section 13 explains.
Where it is reasonable and practicable, we collect personal information from the person it is about. Client Data is the exception, because it reaches us from the Practitioner rather than from the patient. Section 5 sets out what that means for everyone involved.
3. Why we hold it
For Visitors, to answer your question, send you what you asked for, and keep in touch about our work if you have agreed to hear from us. Every marketing message includes a way to unsubscribe.
For Practitioners, to give you access to the application, take payment for anything you buy, support you when something goes wrong, and send you notices about your account or these terms.
For Client Data, to provide the application to the Practitioner who uploaded it, to produce the reports they ask for, and, once it has been de-identified, to improve our models and the Services on the terms set out in section 6. Apart from those uses and the limited disclosures described in section 7, we make no other use of it. We do not use Client Data for marketing, we do not disclose it to anyone for their own purposes, and we do not sell it.
4. Consent and sensitive information
We collect health information with consent, unless the law allows or requires us to collect it without. Where consent is needed, it has to be genuine, which means informed, specific, current, and freely given. Continuing to browse a website is not consent to collect health information, and we do not treat it as such.
Where we need your consent, we ask for it in plain terms, separately from anything else we ask you to agree to, and we keep a record of it. You can withdraw it at any time by contacting us. Withdrawing it may mean we can no longer provide part of the Services, and we will tell you if that is the case.
Practitioners are separately asked to accept our Terms of Use and this policy in the application, and that acceptance is recorded. That is an agreement to our terms, not a consent to collect health information, and we do not rely on it as one.
Practitioners are responsible for obtaining their patient’s consent before uploading Client Data. Under our Terms of Use, accepting those terms includes warranting that they have done so.
5. Who is responsible for Client Data
We hold Client Data on behalf of the Practitioner who uploaded it. They decide what to upload, what to make of the insights, and what to discuss with their patient. We handle it only to provide the Services to them, and we do not use it for our own purposes beyond what section 6 describes.
The clinical relationship sits between the Practitioner and their patient. We are not part of it. The application organises results, shows how they relate to one another, and gives clinical context. It does not diagnose, it does not give medical advice, and it does not replace a Practitioner’s judgement. Every conclusion remains theirs.
We are not a Practitioner’s system of record. Practitioners have their own record-keeping obligations, which in most Australian states run for at least seven years from the last occasion of service. Those obligations are theirs, not ours, and a Practitioner should keep their own records rather than rely on us to hold them.
If you are a patient and you want to see, correct, or remove your records, start with your Practitioner. They hold the relationship, the full context, and the obligations above. If you come to us instead, we will point you to them, and where the law requires us to act ourselves we will do so and let them know.
6. Improving the Services
We use information about how the Services are used to make them better, including improving the models behind the analysis the application performs. Where that work involves health information, we use it only after it has been de-identified.
De-identified, for us, means all of the following:
- Direct identifiers are removed before the information is used, including name, date of birth, contact details, and any Practitioner or patient identifier.
- What remains carries nothing that could reasonably identify a person, and it is not linked back to the account it came from.
- We do not attempt to re-identify anyone from it, and we do not permit anyone else to.
De-identification happens before the information is used for this purpose, not afterwards. We never train on names or other identifying attributes. We do not sell personal information, de-identified or otherwise, and we do not disclose Client Data to third parties for their own purposes.
A Practitioner may ask us to stop using data from their account for this purpose, and we will stop from the date they ask. Information that has already been de-identified cannot be traced back to any account, so it cannot be separated out or retrieved after the fact.
7. Who we share information with
We share personal information only where one of the following applies:
- With service providers who help us run the Services, covering hosting and infrastructure, email delivery, payment processing, and analytics. They may use it only to perform that service for us, and they are bound by contract to protect it.
- With our professional advisers, insurers, and auditors, where they need it to advise us.
- Where the law requires it, or where it is reasonably necessary to protect someone’s safety or to establish or defend a legal claim.
- If our business is sold or merges with another, in which case the acquirer is bound to handle it under a policy no less protective than this one. Selling the business is not the same as selling data, which we do not do.
8. Where your information is stored
Our databases are hosted in the United States, so the information we hold through the application, including Client Data, is stored there. Our analytics provider is also hosted in the United States. Some supporting services operate from Singapore and Japan. The email and office systems we use for correspondence and administration are provided by Google, which stores information across its international infrastructure.
Storing information overseas does not reduce our obligations to you. It remains under our control, and it is held for us by providers who may only handle it on our instructions, may not use it for their own purposes, and are contractually required to protect it. We remain accountable for how they handle it, and our obligations under Australian privacy law continue to apply wherever it sits.
9. How we protect it
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. In practice that includes encrypting information in transit and at rest, restricting access to the people who need it for their work, requiring authentication on every account, requiring a password on any report a Practitioner shares with a patient, logging access to the application, and reviewing our controls as the product changes.
No system is completely secure, and we cannot guarantee the security of information while it travels across the internet. If something does go wrong, section 12 explains what we will do.
If you believe you have found a security vulnerability in the Services, tell us at security@elemnt.health. We will not pursue anyone who reports a genuine issue in good faith and gives us a reasonable opportunity to address it before disclosing it publicly.
10. How long we keep it
We keep personal information only for as long as we need it, or for as long as the law requires, whichever is longer. In practice:
- Website enquiries are kept for 24 months. If you have asked to hear from us, we keep your contact details until you unsubscribe.
- Practitioner accounts, and the Client Data in them, are deleted within 90 days of the account closing, apart from the billing records below. Access ends when the account closes, so ask us for a copy of anything you need before you close it.
- Accounts that go inactive are closed after 5 years without a sign-in, and then deleted on the same basis as any other closed account. We notify you by email beforehand.
- Billing records are kept for 7 years, as tax and corporations law requires.
- Analytics and session records are kept for 30 days.
- De-identified information is kept indefinitely. Because nothing in it links back to a person or an account, it cannot be individually retrieved or deleted.
You can ask us to delete information we hold about you at any time. Where we are able to, we will. Where we cannot, because the law requires us to keep it, we will tell you why and for how long.
11. Accessing and correcting your information
You can ask us for a copy of the personal information we hold about you, and you can ask us to correct it if it is wrong or out of date. Write to us at privacy@elemnt.health and we will respond within 30 days.
We do not charge for making a request. There is rarely a reason for us to refuse one, but if we do, we will explain why in writing and tell you how to have that decision reviewed.
If your request concerns Client Data, please read section 5 first.
12. If something goes wrong
Complaints. If you believe we have mishandled your personal information, tell us at privacy@elemnt.health. We will acknowledge your complaint within 5 business days, look into it, and give you a written answer within 30 days. If our answer does not satisfy you, you can take the matter to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Data breaches. If a breach occurs that is likely to result in serious harm, we will notify the people affected and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires. Where a breach involves Client Data, we will notify the account holder and the Practitioner who uploaded it, so they can meet their own obligations to the patient.
13. Cookies and analytics
Our website and application use cookies and similar technologies to keep them working, remember your preferences, and understand how they are used. That analysis is done by an analytics provider hosted in the United States.
We also use session recordings to see how the application behaved when something went wrong. Recordings mask what people type, so passwords and entered values are not collected. They can, however, capture what is shown on screen, which may include a patient’s name where it appears in the interface. We do not use analytics to read or analyse Client Data, and recordings are deleted after 30 days.
If you would rather no patient name reached our analytics at all, you can record patients under a pseudonym or an internal reference and keep the identifying details in your own system. Tell us if you believe a recording captured something it should not have, and we will remove it.
Most browsers let you refuse or delete cookies. Doing so may stop parts of the Services from working as intended.
14. Other websites
The Services may link to websites we do not run, including the pathology providers we list so that a private blood test can be arranged. Anything you enter on those sites goes to them, not to us, and they handle it under their own privacy policies rather than this one. We are not responsible for how they handle it, and we encourage you to read their policies before giving them anything.
15. Changes to this policy
We update this policy as the Services change or the law does. The current version is always on this page, with the date it took effect shown at the top. If a change materially affects how we handle your information, we will tell account holders directly rather than rely on you noticing.
16. Contact us
For anything in this policy, including access requests and complaints, write to our Privacy Officer at privacy@elemnt.health.