Privacy
Privacy Policy
How Compassionally™ Occupational Therapy collects, uses, holds and protects personal information.
Who we are and this policy's scope
Compassionally™ is the trading name of Simon Gao Pty Ltd ATF The Gao & Yu Family Trust, ABN 36 922 354 450. Simon Gao is the practice's privacy contact.
This policy applies to personal information handled in connection with enquiries, occupational therapy services, service coordination, billing, complaints and operation of the Compassionally™ website.
For privacy questions or an accessible copy of this policy, email simon@compassionally.com.au or call or text 0410 386 689.
Information we collect and hold
Compassionally™ collects only information that is reasonably needed for identification, contact, service delivery, safety, billing or funding requirements. Depending on the service and circumstances, this may include:
- identity, contact and demographic information;
- health, disability, functional, psychosocial and safety information;
- NDIS, Medicare, private-health, workers compensation, insurer, referral and payer information where relevant;
- referrals, third-party reports, assessments, measures, clinical notes, consent records and reports;
- appointments, service agreements, invoices, receipts and payment-status records, but not retained payment-card or bank credentials;
- complaint, enquiry and related communication records;
- information from or about family members, guardians, carers, representatives, referrers and treating providers where relevant and authorised; and
- communication, language, accessibility or cultural information a person chooses to provide where it is relevant to responsive service delivery.
Photographs, audio or video are collected only where necessary and with specific consent. Google Meet client sessions are not routinely audio or video recorded.
How we collect information
Information may be collected directly from the person or from an authorised representative through email, phone, SMS, intake and consent forms, service agreements, in-person or telehealth appointments, clinical interviews, observation, standardised assessments or measures, and document review.
With consent, representative authority or another applicable basis, relevant information may also be collected from family members, guardians, carers, support workers, support coordinators, treating practitioners, referrers, funders, insurers and other relevant stakeholders.
Children and young people are involved according to their age, understanding, decision-making capacity and clinical circumstances. Parent, guardian, nominee or representative authority is verified as appropriate. Family or carer involvement does not automatically remove the person's privacy interests.
Why we use and disclose information
Information may be used where reasonably necessary to respond to an enquiry, consider service fit, deliver occupational therapy, assess occupational performance, support clinical reasoning and safety, plan and review intervention, coordinate services, prepare reports, meet funding and billing requirements, maintain continuity and keep professional records.
Relevant information may be disclosed, on a minimum-necessary basis, to:
- the person and an authorised representative;
- referrers, treating practitioners, family members, carers or support providers where authorised and relevant;
- plan managers, support coordinators, insurers, workers compensation stakeholders or lawyers where required for an authorised and defined service or billing arrangement;
- an accountant, limited to information necessary for accounting and taxation rather than clinical information;
- technology and communication providers that support the practice; and
- emergency services, regulators, courts or other bodies where a disclosure is permitted or required, including when reasonably necessary to respond to immediate danger or an urgent safety concern.
Information is not automatically sent to every referrer or family member, and recipients do not receive unrestricted access to the clinical record.
How information is held and protected
Zanda is the primary practice-management and clinical-record system. Google Workspace supports business email, Calendar, Drive and Meet. Clinically relevant information held temporarily in email, Calendar, Drive or another working location is recorded or transferred to Zanda where appropriate.
Compassionally™ uses access controls, multi-factor authentication, device security, restricted sharing and minimum-necessary information practices.
The practice is mostly paperless. If paper is used temporarily, it is entered into or uploaded to Zanda and securely destroyed after the record has been checked for completeness.
Access, correction and privacy complaints
You may ask to access or correct personal information held about you by contacting Simon. Enough information may be requested to verify identity, authority and the records involved. Requests are considered in accordance with applicable privacy obligations, and a written explanation will be provided if access or correction cannot be given in the form requested.
To raise a privacy concern, email simon@compassionally.com.au or call or text 0410 386 689. Concerns will be considered respectfully and fairly. More information is available on the Complaints and feedback page.
If you are not satisfied with the response, you may read the Office of the Australian Information Commissioner's privacy complaint process. The OAIC explains when a person must first complain to the organisation before lodging with the OAIC.
Overseas storage, processing and access
Compassionally™ uses Zanda, Google Workspace, Netlify and GoDaddy. Depending on the provider, service and configuration, personal information or technical service data may be stored or processed outside Australia, or accessed by authorised support personnel or subprocessors outside Australia.
Published provider information identifies service locations including Australia, the United States, the United Kingdom and other countries. Arrangements may change. Compassionally™ considers provider privacy and security information and limits information handling to what is reasonably necessary. Contact Simon for more information about providers relevant to your information.
Website, email and telephone enquiries
This website does not contain a live enquiry form or file upload. Compassionally™ does not use website analytics, advertising trackers or session replay, and does not deliberately set cookies. Netlify may process technical request data, such as IP address, browser or device information and requested resources, to provide and secure the hosting service.
Email and telephone links open the visitor's chosen application. Ordinary email and SMS carry privacy risks, so please send only the information needed at first contact. Arrangements for sharing detailed or sensitive documents can be discussed after contact.
AI-assisted documentation and automated decisions
Google Meet transcription and Gemini meeting notes may be manually activated for a defined clinical reason after signed intake consent and separate confirmation from the person. Generated material is accessible to Simon, is reviewed and corrected where relevant, and may be retained as part of the client record. These tools do not diagnose, score, make recommendations or make automated clinical decisions. Simon remains responsible for clinical reasoning and decisions.
Identifiable client information is not entered into unapproved general-purpose AI services.
Data breaches
Suspected privacy incidents are contained and assessed. Affected people and the OAIC are notified where required under the Notifiable Data Breaches scheme, and the incident is reviewed to reduce the risk of recurrence.
Retention and secure disposal
Compassionally™ retains personal and clinical information for as long as it is required for the purposes for which it was collected and for applicable legal, professional, funding, insurance, taxation, contractual and dispute-management obligations. When information is no longer required, reasonable steps are taken to securely destroy it or de-identify it.
Changes to this policy
This policy may be updated when the practice, providers or applicable obligations change. The current version will be published on this page.
Last updated: 14 July 2026.