Legal · Privacy · Australia
Privacy Policy
Novada Tech runs the non-clinical operation for private healthcare practices in Australia and the United States. We answer calls and enquiries, make and change bookings, run recall lists and maintain records, and we do that work inside the systems our clients already run. That means we come into contact with health information about their patients, which Australian privacy law treats as sensitive information and protects more strictly than ordinary personal information.
This policy explains what we collect, why we collect it, who we disclose it to, how long we keep it and what you can do about it. It is written for two different readers: someone using this website, and someone whose information we handle because their clinic engaged us. Section 02 explains which one you are.
- Last updated
- 15 September 2026
- Applies to
- this website and our desk services
- Governing law
- Privacy Act 1988 (Cth)
About this policy
This policy sets out how Novada Tech handles personal information, including health information. It applies to this website, to enquiries and bookings made through it, and to Novada Practice Operations, the service we provide to private practices in Australia and the United States, covering both patient access and the practice workforce.
It describes our practices. It is not legal advice, and it does not replace the privacy policy of the clinic that holds your record. Where we handle information on behalf of a client, that client's own policy and consent arrangements govern the record itself, and this policy explains our part in it.
This policy is not a collection notice. Where the Privacy Act 1988 (Cth) requires us to tell you specific things at the moment we collect your information, we do that separately, at that moment.
Who we are, and the two roles we play
Novada Tech is an Australian owned and operated business. Our coordinators are in Australia. We do not subcontract the desk work to anybody else.
If your practice is in the United States, read that paragraph again. It means your patient information is accessed from outside the United States. That is lawful, and it is your call to make, not ours. Section 10 sets out exactly what it involves so you can assess it properly.
- Legal entity and ABN: Novada Tech Pty Ltd (ABN 90 665 134 921)
- Registered and postal address: Suite 23, 220 Collins Street, Melbourne VIC 3000
- Privacy contact: support@novadatech.com.au
Role one: information we hold in our own right
This covers people who visit this website, people who make an enquiry or a booking with us, our business clients and the people who work for them, our suppliers, and our own workers and job applicants. We decide how that information is handled, and this policy governs it.
Role two: information we handle for a client
This is the larger part of what we do, and it works differently. We work inside the client's own systems, using access the client grants us, under the client's instructions and the terms of our service agreement. For clinics that means practice management software such as Cliniko, Jane, SimplePractice, Nookal, Dentrix, Open Dental, Dental4Windows or ezyVet. Nothing migrates to a Novada system. The client keeps the system of record.
For a practice in the United States, that role has a name under HIPAA. The practice is the covered entity. We are its business associate, because we handle protected health information to carry out a function on its behalf. Before we are given access to anything, we sign a business associate agreement, which is required by 45 CFR 164.502(e) and 164.504(e) and forms part of the services agreement. That agreement, not this policy, is what binds us to the practice.
We do not describe ourselves as HIPAA certified, and neither should anyone else. No body certifies compliance with HIPAA, so the phrase means nothing. What exists is the agreement we sign and the safeguards we keep to under it.
That role has two halves and they are not the same kind of information. Patient Access means working in your practice management software, where the information is largely health information about your patients. Practice Workforce means recruitment, onboarding, compliance records and payroll, where the information is about your staff and your job applicants and is not health information at all. The distinction matters: where a Business Associate Agreement applies it covers protected health information, and staff and candidate information is handled under the services agreement instead.
In that role the clinic is generally the organisation with the primary relationship to the patient, and the organisation that holds the record. We handle that information as a service provider, for the client's purposes, and not for our own.
If you are a patient
Your record belongs to your clinic, not to Novada. Requests to see it, correct it or complain about it should go to them first, because they hold it and they can act on it. If you contact us instead, we will pass your request on to them promptly and tell you we have done so.
What we do not do
Novada does not provide clinical services of any kind. No triage, no clinical advice, no assessment, no diagnosis and no treatment decision. Anything clinical is escalated to the client's own team under an escalation protocol agreed with that client in writing. That boundary is a term of our service agreements.
We do not access the My Health Record system, and we do not collect, use or handle Individual Healthcare Identifiers. If that ever changes we will update this policy before the change takes effect, because the Healthcare Identifiers Act 2010 (Cth) and the My Health Records Act 2012 (Cth) would then also apply to us.
The laws that apply to us
The primary law is the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles in Schedule 1 to that Act, which cover open and transparent management (APP 1), anonymity (APP 2), collection (APPs 3 to 5), use and disclosure (APP 6), direct marketing (APP 7), cross border disclosure (APP 8), identifiers and quality (APPs 9 and 10), security (APP 11) and access and correction (APPs 12 and 13).
The small business exemption, and why we do not use it
Section 6D of the Privacy Act 1988 (Cth) exempts many businesses with an annual turnover of $3 million or less. Two things about that exemption matter here.
- It does not apply to health service providers. Section 6D(4)(b) removes the exemption from an entity that provides a health service to another individual and holds health information other than in an employee record. Turnover is irrelevant. Our clinic clients are covered by the Privacy Act whatever their size.
- The definition of a health service is broad. Section 6FB defines a health service to include an activity performed in relation to an individual that is intended to assess, record, maintain or improve that individual's health. The line between a clinical service and an administrative service performed on a health record is not always obvious.
For those reasons we do not rely on the small business exemption. We handle health information to the standard the Australian Privacy Principles set, regardless of whether a court would find the exemption available to us, and our service agreements require the same thing.
Removing the small business exemption generally is a proposed second tranche reform that the Australian Government has agreed to in principle. As at the date of this policy it has not been legislated and no commencement date has been set, so the exemption remains part of the Act.
Amendments in force
The Privacy and Other Legislation Amendment Act 2024 (Cth) received assent on 10 December 2024 and commenced most of its provisions on that day. Three consequences are relevant to this policy:
- APP 11.3 now states expressly that the reasonable steps required to secure personal information include technical and organisational measures.
- A statutory cause of action for serious invasions of privacy, in Schedule 2 to the Privacy Act, commenced on 10 June 2025. It allows an individual to sue for intrusion upon seclusion or misuse of information, and it applies more widely than the Australian Privacy Principles do.
- New transparency obligations about automated decision making, in APPs 1.7 to 1.9, commence on 10 December 2026. See section 17.
State and territory health records law
State and territory health privacy legislation can apply in addition to the Commonwealth Act, not instead of it, so a single record can be covered by both. The laws most likely to be relevant to our clients are:
- Health Records and Information Privacy Act 2002 (NSW), which sets fifteen Health Privacy Principles and applies to private sector persons in New South Wales who are health service providers or who collect, hold or use health information.
- Health Records Act 2001 (Vic), which sets eleven Health Privacy Principles and applies to organisations that handle health information in Victoria.
- Health Records (Privacy and Access) Act 1997 (ACT), which covers health records in the Australian Capital Territory.
United States law, where a client is American
Where we handle protected health information for a practice in the United States, we do it as that practice's business associate under the Health Insurance Portability and Accountability Act of 1996 and the rules made under it, as amended by the HITECH Act of 2009 and the Omnibus Rule of 2013. Three parts apply to us directly:
- The Privacy Rule, 45 CFR Part 164 Subpart E. We may use or disclose protected health information only as the business associate agreement permits or as law requires, and we apply the minimum necessary standard.
- The Security Rule, 45 CFR Part 164 Subpart C, which since the HITECH Act applies to business associates directly and not only through the contract. It requires administrative, physical and technical safeguards for electronic protected health information.
- The Breach Notification Rule, 45 CFR Part 164 Subpart D. Our obligation runs to the practice, on the timing set out in section 14.
HIPAA sets a floor, not a ceiling. It does not displace a state law that protects the individual more, so your own state's health privacy law can apply on top of it. Where your state law, your accreditation body or a payer contract imposes a requirement on your business associates, tell us and we will work to it, or we will tell you plainly that we cannot.
We are not a covered entity, we do not bill any health plan, and we do not hold protected health information in our own right. Everything we touch belongs to the practice.
Marketing law
Electronic and telephone marketing is separately governed by the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth). See section 11.
The information we collect
a. Website visitors
When you open a page on novadatech.com.au, the tools in section 08 collect your IP address and the approximate location it suggests, your device type, browser and operating system, the pages you view and how long you spend on them, the page or advertisement that sent you, and cookie and advertising identifiers.
b. Enquiries and bookings
If you contact us or book a review, we collect your name, email address, phone number, business name and role, the type of practice you run, the appointment time you choose, anything you write to us and the answers to any questions the booking form asks. We also record which page of this website produced the booking, so we know which enquiry came from where.
c. Clients, suppliers and their people
For the businesses we work with, we collect contact details and roles, the system access arrangements the client sets up, and contract and billing information.
d. Information we handle for a client, inside the client's systems
For Patient Access, working inside a clinic's practice management software, this can include: patient names and contact details; the reason given for an appointment; the practitioner, service and appointment date and time; referral details and health fund or scheme details where the clinic's system captures them; cancellation, no-show, recall and reactivation status; and the notes we record in the clinic's system about each contact. Much of this is health information.
For Practice Workforce, working inside the practice's own systems, this can include: the names and contact details of your staff and of people who apply to you; the right to work and identity documents you require; professional registration, qualification and credential details and their expiry dates; induction, training and policy acknowledgement records; position, hours, leave and pay details; bank account details and the tax and superannuation or withholding information payroll needs to run; and, where your role requires one, the outcome of a background or criminal record check.
Two of those are sensitive information
Criminal record information is sensitive information under the Privacy Act 1988 (Cth), and so is health information about a member of your staff if it ever reaches us, for example on a medical certificate. We collect either only where you have asked us to administer a process that requires it, we keep it inside your own systems, and we do not use it for anything else.
The employee records exemption in section 7B(3) of the Privacy Act 1988 (Cth) concerns an organisation's handling of records about its OWN current and former employees. We are not your employees ' employer. We do not treat the staff records we handle for you as exempt employee records, and we apply the Australian Privacy Principles to them.
e. Telephone calls
We answer calls for our clients, so we receive whatever the caller tells us and record the outcome in the client's system.
We do not record telephone calls. If a client chooses to record calls on their own service, that recording is the client's own arrangement. The client is responsible for it, including for meeting the notification and consent obligations that apply under the Telecommunications (Interception and Access) Act 1979 (Cth) and the surveillance and listening devices legislation of the relevant State or Territory.
f. Our own people
We collect the information we need to recruit, employ or engage our coordinators and to meet our obligations as an employer.
Health information and other sensitive information
Section 6FA of the Privacy Act 1988 (Cth) defines health information broadly. It includes information or an opinion about an individual's health or disability, information about a health service provided or to be provided to them, and other personal information collected in the course of providing a health service. An appointment record that names a patient and the practitioner they are seeing is health information.
Health information is sensitive information under section 6(1) of that Act, and sensitive information carries a higher bar. Under APP 3.3, an organisation must not collect sensitive information unless the individual consents and the collection is reasonably necessary for one or more of the organisation's functions or activities, unless an exception in the Act applies. Under APP 7.4, sensitive information may only be used or disclosed for direct marketing with the individual's consent.
How that works in practice for us
- Where we collect or record health information, we do so on behalf of and at the direction of the client, inside the client's system, for the purpose the client engaged us for. The consent framework covering that record is the client's, obtained under the client's own privacy arrangements.
- We use it only for that purpose, and for directly related purposes the individual would reasonably expect, consistent with APP 6.
- We do not sell personal information or health information, and we do not use health information we handle for a client for our own marketing or business development.
- We do not configure the analytics and advertising tools described in section 08 to receive health information, and health information from a client's system is not sent to them.
The clinical boundary
Nothing we do is a clinical act. We do not triage, assess, diagnose, advise or treat. If a call raises anything clinical, it goes to the client's own team under the escalation protocol agreed with that client.
How we collect it
Under APP 3.6, an organisation must collect personal information about an individual only from that individual, unless the individual consents to collection from someone else or it is unreasonable or impracticable to collect it directly. We collect information:
- Directly from you, when you call us, email us, use the booking widget on this website, or speak to one of our coordinators.
- Automatically from your device, through the cookies, tags and pixels described in section 08.
- From our client, or from the client's system, where we are working on that client's behalf under access the client has granted us.
- From a third party at a client's direction, for example a referrer or another provider, where the client's own arrangements allow it.
Where we collect a patient's information, we are collecting it for the client, into the client's record, and the client is responsible for the collection notice that goes with it.
How we use it, and who we disclose it to
We use personal information to:
- answer calls, messages and enquiries for our clients and for ourselves;
- make, reschedule and cancel bookings in a client's system, run recall and reactivation lists, recover cancellations and follow up no-shows;
- advertise a role, screen applicants, arrange interviews and run the onboarding and induction steps a client asks us to run;
- maintain registration, credential, training and policy records for a client's staff, and give notice of an expiry before it becomes a problem;
- process payroll on a client's cycle, against the hours and entitlements that apply to its staff, with the client remaining the employer throughout;
- produce the monthly report we give each client, covering enquiries, response times, booking outcomes and reasons lost;
- respond to your enquiry, prepare for a review call and follow up with you;
- operate, secure, measure and improve this website;
- invoice, keep our own business records and meet our legal and tax obligations; and
- handle complaints, disputes and insurance matters.
Who we disclose it to
- The client, for anything we handle on their behalf. This is the main disclosure, and in most cases the information never leaves the client's own system.
- Our coordinators and staff, limited to the people assigned to that client, under written confidentiality obligations.
- Technology suppliers that run this website, our customer relationship management and booking platform, and the analytics and advertising tools in sections 08 and 09. Beyond those, we work inside the systems our clients already run. The only system we supply is a telephone number that a client forwards their front desk line to, so that calls reach our coordinators. If an engagement ever requires an additional tool, we tell the client before it is introduced.
- Professional advisers, such as our accountants and lawyers, where they need it.
- Anyone we are required or authorised by law to disclose to, including a court, tribunal or regulator, or where disclosure is necessary to lessen or prevent a serious threat to life, health or safety.
We do not sell personal information, and we do not disclose it to third parties for their own independent marketing purposes.
Cookies, analytics and advertising tracking
This website loads four tracking tools, and only these four:
- Google Tag Manager, a container that loads the Google tags below.
- Google Analytics, which measures how the website is used, managed through that container.
- Google Ads conversion tracking, which tells us which advertisement produced an enquiry or a booking, also managed through that container.
- The Meta pixel, which measures the performance of advertising on Facebook and Instagram and can be used to build advertising audiences.
Between them these tools collect the website visitor information listed in section 04, set cookies and similar identifiers in your browser, and share that information with Google and Meta, who process it on their own infrastructure. See section 10 for where that infrastructure is.
These tools load when a page opens, and this website does not currently present a cookie consent banner. If you do not want this collection, you can:
- block or delete cookies, or use private browsing, through your browser settings;
- install the Google Analytics opt-out browser add-on from tools.google.com/dlpage/gaoptout;
- adjust the advertising settings in your Google account and your Meta account; or
- use a browser or extension that blocks tracking scripts.
Blocking cookies and scripts may stop parts of this website working, including the booking widget. The privacy policies of the two providers are at policies.google.com/privacy and facebook.com/privacy/policy.
The Office of the Australian Information Commissioner published guidance on tracking pixels and privacy obligations in November 2024. It makes clear that responsibility for a pixel sits with the organisation that deploys it, not with the provider whose code is being used. We treat that responsibility as ours.
Third party tools embedded in this website
The booking widget
Our booking calendar is embedded from link.novadatech.com, which is our customer relationship management and booking platform. The calendar is an iframe served from that domain, so anything you enter into it goes to that platform and then into our customer records. The widget sets its own cookies and receives the campaign parameters we attach to the embed address, which is how we know which page produced a booking.
The booking embed also writes a short value to your browser's session storage recording which page you booked from, so the confirmation page can greet you correctly. It is cleared when you close the tab.
Links to other sites
This website links to sites we do not run. We are not responsible for their content or their privacy practices, and this policy does not apply to them.
Sending information overseas
APP 8 and section 16C of the Privacy Act 1988 (Cth) govern disclosure of personal information to an overseas recipient. Before we disclose, we must take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, and if the recipient then mishandles the information we can be held accountable for that act as though we had done it ourselves. Reasonable steps is an obligation to act carefully, not a guarantee about what an overseas company will do.
The overseas processing that applies to us is:
- Google and Meta. The website tracking described in section 08 sends information to Google and to Meta, who process and store it on infrastructure outside Australia, including in the United States.
- Our customer relationship management and booking platform. Enquiries and bookings made through this website are stored in that platform. Enquiry and booking records submitted through this website are held in our customer relationship management and booking platform, which stores that data in Australia.
The desk service itself is delivered from Australia. Our coordinators are in Australia, and patient records stay in the client's own system. We do not copy a client's records into a system of ours, and we do not send health information to the tracking tools in section 08.
If your practice is in the United States
The same fact reads the other way round for you. Your patients' protected health information is accessed from Australia. Our coordinators sign in to your system from there. Nothing is copied out of it, but it is read, and it is worked on, from outside the United States.
HIPAA does not prohibit this. It contains no data residency requirement and no restriction on where a business associate sits. What it does require is that you know, and that your own risk analysis under 45 CFR 164.308(a)(1) accounts for it. Some state laws, some accreditation standards and some payer contracts do restrict offshore access to patient information, and those are yours to check, not ours to assume. We would rather you found this in a policy than in an audit.
If offshore access is not acceptable to you, tell us before you sign anything. We will say so plainly rather than work around it.
Marketing, email and SMS
Our own marketing
We may send you information about our services if you gave us your details or you would reasonably expect to hear from us, and every message carries a way to stop. Under APP 7.4, sensitive information, including health information, may only be used for direct marketing with consent. To opt out of our marketing, use the unsubscribe link in any email, reply STOP to any SMS, or email support@novadatech.com.au.
Commercial electronic messages are governed by the Spam Act 2003 (Cth), which requires consent, accurate identification of the sender with contact details that stay current for at least thirty days, and a functional unsubscribe facility that works for at least thirty days after the message is sent. Opt-outs must be actioned within five working days, and we action them sooner where we can. Telemarketing calls are governed by the Do Not Call Register Act 2006 (Cth). Under APP 7.8, APP 7 does not apply to the extent that those Acts apply.
Recalls, reminders and reactivation messages sent for a clinic
When we run a recall list, a reactivation campaign, an appointment reminder or a no-show follow-up, we do it as the clinic, not as Novada. Those are the clinic's messages, sent from the clinic's system, to the clinic's patients, under the clinic's own consent records and instructions, and opt-outs are recorded in the clinic's system.
If you want a clinic's messages to stop
Reply as the message tells you, or contact the clinic directly, because the consent record lives with them. You can also tell us at support@novadatech.com.au and we will pass it on to the clinic and record it in their system.
How we protect information
APP 11 requires us to take reasonable steps to protect personal information from misuse, interference and loss and from unauthorised access, modification or disclosure. Since 10 December 2024, APP 11.3 states expressly that those reasonable steps include technical and organisational measures.
The measures we rely on are:
- working inside the client's own system, using credentials the client issues and permissions the client sets, so the record stays in the client's system of record rather than being copied into ours;
- limiting access to the coordinators assigned to that client;
- written confidentiality obligations on everyone who works for us, and coordinators employed by us in Australia rather than subcontracted;
- access controls and authentication on the systems we use, and encryption in transit on this website; and
- returning or revoking system access at the end of an engagement.
What we are not claiming
We hold no security certification or accreditation, and this policy does not claim one. We do not describe our controls as bank grade, military grade or fully compliant, because those phrases mean nothing and promise everything. No system connected to the internet can be made completely secure, and we cannot guarantee absolute security.
How long we keep information
APP 11.2 requires us to take reasonable steps to destroy or de-identify personal information once we no longer need it for any purpose for which it may be used or disclosed, and we are not required by law or a court order to keep it.
- Our own record of the work. We keep our own operational log of what we did and when: what came in, what we did about it, who did it, what we escalated and to whom, and what we reported to the client. That log is our record, not a copy of theirs, and it is what our monthly reports and any audit response are built from. We keep the log for as long as we need it to answer for the work, and no longer than our limitation period obligations require.
- Records inside a client's system. These are kept by the client, under the client's own retention obligations, which can be long. For example, section 25 of the Health Records and Information Privacy Act 2002 (NSW) generally requires a health service provider to keep health information for seven years from the last occasion a health service was provided to an adult, and where it was collected while the individual was under eighteen, until that person turns twenty-five. Health Privacy Principle 4 under the Health Records Act 2001 (Vic) sets a comparable standard.
- Website enquiries and bookings. Records of enquiries and bookings made through this website are held in our customer relationship management and booking platform and are automatically deleted once they are more than 12 months old.
- Copies of a client's patient records. We do not keep them. That work is carried out inside the client's own systems and those records stay there, under the client's own retention rules. Where our own log necessarily names a patient, for example to record that a call was returned or a booking was made, we hold that entry as part of our record of the work we did. It is not a copy of the client's file, and we do not assemble one.
- Business associate documentation, for United States practices. 45 CFR 164.530(j) requires the policies, procedures and records that document our handling of protected health information to be kept for six years from the date they were created or last in effect, whichever is later. That is documentation about the work. It is not a copy of your patients' records, which we do not keep at all.
- Business records. Contracts, invoices and accounting records are kept for as long as our tax, corporate and limitation period obligations require.
Data breaches
The Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth) applies to us. An eligible data breach occurs where there is unauthorised access to, unauthorised disclosure of, or loss of personal information, that is likely to result in serious harm to one or more individuals, and the harm has not been prevented by remedial action.
Our pathway is:
- contain the breach and assess it. Where we suspect an eligible data breach, we take all reasonable steps to complete that assessment within thirty days of becoming aware of the grounds for suspicion, and faster wherever we can, because the risk of harm grows with time;
- where we have reasonable grounds to believe an eligible data breach has occurred, notify the Office of the Australian Information Commissioner and the affected individuals as soon as practicable, with what happened, the kinds of information involved and what those individuals should do; and
- where the breach concerns information we handle for a client, notify that client without delay so they can meet their own obligations, and agree with them who notifies the individuals so nobody is told twice and nobody is missed.
The sensitivity of the information affected is one of the factors in whether serious harm is likely. Health information is among the most sensitive kinds of personal information there is, and we treat any incident involving it accordingly.
Where the practice is in the United States
The Breach Notification Rule puts the obligation on us in a different shape. As a business associate we notify the practice, not the individuals and not the regulator. Under 45 CFR 164.410 that notice must go without unreasonable delay and in no case later than sixty days after we discover the breach, and it must identify each individual whose protected health information we believe was involved, so far as we can.
Sixty days is the outer limit the rule allows, not our intention. We will tell you as soon as we know, because you cannot start your own clock until we have started ours. The notifications to affected individuals, to the Secretary of Health and Human Services and, above five hundred individuals in a state or jurisdiction, to the media, are the practice's to make as the covered entity. We will give you what you need to make them.
Accessing and correcting your information
Under APP 12 you may ask for access to the personal information we hold about you, and under APP 13 you may ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. We respond within a reasonable period, which the Office of the Australian Information Commissioner considers should generally not exceed thirty days.
There is no charge for making an access request, and no charge for a correction. We may charge for the reasonable cost of giving access, and any such charge will not be excessive. We may need to verify your identity first, and if we refuse a request we will tell you why in writing and how to complain.
Which organisation to ask
If the information is in a patient record held in a clinic's system, ask that clinic. They hold the record and they can act on it. Equivalent access and correction rights exist under Health Privacy Principles 6 and 7 of the Health Records and Information Privacy Act 2002 (NSW) and under Part 5 and Health Privacy Principle 6 of the Health Records Act 2001 (Vic).
If the information is something Novada holds in its own right, such as an enquiry you made through this website, email support@novadatech.com.au and tell us what you are looking for.
Dealing with us anonymously
APP 2 gives you the option of dealing with us anonymously or under a pseudonym where that is lawful and practicable. You can read this website without telling us who you are, subject to the tracking described in section 08, and you can ask us a general question by phone without giving your name.
We cannot make or change a booking in a clinic's system anonymously, because the clinic's record has to identify the patient it belongs to.
Automated decision making
From 10 December 2026, APPs 1.7 to 1.9 of the Privacy Act 1988 (Cth), inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth), require an organisation to state in its privacy policy whether it uses a computer program to make, or to do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, where personal information about that individual is used in the operation of the program. If it does, the policy must set out the kinds of personal information and the kinds of decisions involved. The obligation is a transparency measure.
We do not use automated decision making. Our coordinators work inside our clients' own systems, and where an automated feature exists in one of those systems it is configured and controlled by the client rather than by us. If we ever introduce a system of our own that makes, or substantially contributes to, a decision significantly affecting an individual, we will update this policy before it is used.
Complaints
Step one: tell us
If you think we have mishandled your personal information, contact us first. Email support@novadatech.com.au with the subject line Privacy complaint. We will acknowledge your complaint, investigate it and give you a written response, and we aim to do that within thirty days. Complaints are handled by Ade Eni, Privacy Officer.
Step two: escalate
If you are not satisfied with our response, or we do not respond, you can take it further. These offices generally expect you to have complained to the organisation first and given it about thirty days to respond.
- Office of the Australian Information Commissioner for complaints under the Privacy Act 1988 (Cth). oaic.gov.au · 1300 363 992 · online complaint form at webform.oaic.gov.au · GPO Box 5288, Sydney NSW 2001.
- Privacy Commissioner, Information and Privacy Commission NSW for health information complaints under the Health Records and Information Privacy Act 2002 (NSW). 1800 472 679 · ipcinfo@ipc.nsw.gov.au · ipc.nsw.gov.au.
- Health Complaints Commissioner, Victoria for health information complaints under the Health Records Act 2001 (Vic). 1300 582 113 · hcc.vic.gov.au.
If your complaint is about a record held by your clinic rather than by us, raise it with them first. They hold the record.
Changes to this policy
We review this policy from time to time and will update it when our practices, our services or the law change. The current version is always published on this page with the date it took effect, shown at the top and repeated below. Where a change is significant, we will say so on this page.
This version took effect on 15 September 2026. It replaces all earlier versions.
How to contact us
For anything in this policy, including access, correction and complaints:
- Privacy Officer
- Ade Eni, Privacy Officer
- Postal address
- Suite 23, 220 Collins Street, Melbourne VIC 3000
- Entity and ABN
- Novada Tech Pty Ltd (ABN 90 665 134 921)
- Effective
- 15 September 2026
If your practice is in the United States
Where the complaint concerns protected health information we handled as a business associate, the regulator is the Office for Civil Rights at the United States Department of Health and Human Services, which enforces the HIPAA rules. hhs.gov/ocr/complaints. A complaint there must generally be filed within one hundred and eighty days of when you knew the act complained of occurred, so do not let it sit. Your own state attorney general may also have power to act under HIPAA and under state health privacy law.
You can read the Australian Privacy Principles and the Commissioner's guidance at oaic.gov.au, and the legislation named throughout this policy at legislation.gov.au and on the relevant State legislation registers.
Nothing clinical, ever