1. About this policy
Moveify is operated by Ryan Douglas Heath, trading as Moveify Health Solutions (ABN 52 263 141 529). This policy explains how we collect, use, store, and disclose your personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It applies to Moveify's clinical exercise physiology services and the Moveify app/platform, and to everyone who uses them, including patients and clinicians.
2. Information we collect
- Account & contact information: name, email, date of birth, phone, address, and emergency contact details.
- Identifiers & funding information: Medicare number/IRN; DVA, NDIS, or ReturnToWorkSA participant/claim numbers; private health insurer details; and your GP or referrer's details — where relevant to your care or claiming.
- Health & clinical data (sensitive information): medical conditions, medications, injury/surgery/falls history, pre-exercise screening responses, assessment and functional-testing results, exercise program details, exercise completion records (sets/reps/weight), RPE and pain scores, daily wellness check-ins (mood, pain, energy, sleep), and clinical notes.
- Consultation audio & AI-generated notes: where you consent, audio of your consultation is briefly recorded solely to generate a written clinical note — see section 6.
- Payment & billing information: the bank account or card details you provide for direct debit, and your transaction history. Card and bank details are handled by our payment providers (section 7); we do not store full card numbers.
- Usage data: audit logs recording logins, data access, and program modifications, for security and compliance.
Health and clinical data is sensitive information under the Privacy Act and receives the highest level of protection.
3. How we collect information
- Directly from you — at intake (the Consent & Pre-Exercise Questionnaire), when you create your account, log exercise completions, complete wellness check-ins, or update your profile.
- From your clinician — when they create your record, assign programs, or update clinical details.
- From session recordings — where you have consented (section 6).
- From third parties you authorise — e.g. your GP or referrer, or your funding scheme.
- Automatically — audit logs generated as you use the platform.
4. Why we collect your information
- To deliver clinical exercise prescription and rehabilitation, and to monitor and adjust your program.
- To generate and maintain your clinical documentation (including the AI-assisted note in section 6).
- To coordinate your care with your GP and other healthcare providers (with your consent).
- To bill and claim for your care, including from funded schemes where applicable.
- To let you track your exercise and wellness over time.
- To authenticate your identity and secure your account, send transactional emails, and maintain audit trails for security, compliance, and dispute resolution.
5. Sensitive health information and consent
Under APP 3 we obtain your explicit consent before collecting sensitive health information. Consent is captured at intake (the Consent & Pre-Exercise Questionnaire) and at account setup, with separate, optional consents for GP communication, app data collection, and session recording. You may withdraw any consent at any time by contacting us (section 15); withdrawing some consents may affect our ability to provide parts of the service.
6. Session recording and AI clinical documentation
With your consent, your treating clinician may record the audio of your consultation only to produce a written clinical note. The process is:
- Audio is recorded during the consultation and transmitted securely (encrypted in transit).
- It is transcribed using AWS Transcribe, and a structured clinical note is drafted using AWS Bedrock.
- All processing occurs in AWS's Sydney, Australia region — your audio and its transcript never leave Australia.
- Your clinician reviews and approves the note before it is saved.
- The audio is permanently deleted immediately after transcription. It is never stored.
This processing is covered by a contractual data-protection agreement with AWS (a Business Associate Addendum). You can decline session recording without affecting your treatment.
7. Third-party service providers
We use the following providers to operate our services:
- Google Cloud Platform (Cloud SQL): primary database hosting in Sydney, Australia (
australia-southeast1). All health data is stored here.
- Amazon Web Services (Sydney): powers our AI features — the session-recording note pipeline (section 6) and the optional AI Exercise Assistant used by clinicians. All AWS AI processing occurs in Australia (
ap-southeast-2). No health data is sent overseas.
- Stripe: processes direct debit and card payments for clinical service fees. Stripe handles your name, contact, and bank/card details; it does not receive any health data.
- Tyro: processes in-clinic EFTPOS and HICAPS card payments. Tyro is an Australian provider.
- Vercel: hosts our front-end application (HTML/CSS/JavaScript). No personal or health data is stored on or transmitted through Vercel.
- Gmail API: sends transactional emails (account setup, password resets). Only email addresses are processed — never health data.
We do not sell, rent, or trade your personal information.
8. Cross-border disclosure
In accordance with APP 8, all of your health and clinical data — including the AI session-note and AI Exercise Assistant processing — is stored and processed exclusively in Australia (Google Cloud and AWS, Sydney). No health data is disclosed or transferred overseas.
Limited non-health data involves overseas processing:
- Vercel hosts our front-end from infrastructure that includes the United States, but no personal or health data passes through it.
- Gmail API processes email addresses only for transactional emails.
- Stripe may process your payment and contact details (not health data) in the United States under its Data Processing Agreement, which includes Standard Contractual Clauses for cross-border transfers.
9. Who we share your information with
Access and disclosure are limited to:
- Your treating clinician(s) and our system administrator (for technical support, security, and compliance).
- Your GP and other healthcare providers — with your consent, to coordinate your care and support Medicare Chronic Disease Management claims.
- Funded schemes — Medicare/Services Australia, the Department of Veterans' Affairs, the NDIA/NDIS, ReturnToWorkSA, and private health insurers — only as needed to bill or claim for your care, and only the scheme(s) relevant to you.
- Our service providers (section 7), under contract.
- As required or authorised by law.
We do not sell, rent, or trade your personal information.
10. Data security
We take reasonable steps to protect your information from misuse, loss, and unauthorised access, modification, or disclosure:
- Encryption in transit (TLS/HTTPS) and at rest.
- Consultation audio encrypted in transit and deleted immediately after transcription (never stored).
- Password hashing (bcrypt); JWT authentication with role-based access control.
- Rate limiting on authentication; security headers (CSP, X-Frame-Options).
- Audit logging of key operations; automated daily database backups (7-day retention).
- No public signup — accounts are created only via clinician invitation.
11. Data retention
In accordance with APP 11, we retain your clinical records for 7 years after your last service, or until you reach 25 years of age, whichever is longer, as required for clinical record-keeping. After that period your data is securely destroyed. If your account is deleted earlier, your clinical records are still retained for that period. Consultation audio is not retained — it is deleted immediately after transcription (section 6).
12. Your rights
Under the APPs you may:
- Access (APP 12) — request a copy of the information we hold about you.
- Correct (APP 13) — request correction of inaccurate, out-of-date, incomplete, or misleading information.
- Withdraw consent — including for GP communication or session recording, without necessarily ending your treatment.
- Complain — see section 13.
Contact ryan@moveifyhealth.com; we respond within 30 days.
13. Complaints
If you believe your privacy has been breached, contact ryan@moveifyhealth.com — we investigate and respond within 30 days. If unsatisfied, you may complain to the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au · 1300 363 992 · GPO Box 5218, Sydney NSW 2001.
14. Changes to this policy
We may update this policy from time to time. The "last updated" date shows the latest revision; we notify affected users by email of material changes.
15. Contact
Ryan Douglas Heath, trading as Moveify Health Solutions · ABN 52 263 141 529 · ryan@moveifyhealth.com.