Legal

Privacy Policy

Your health information is some of the most sensitive information about you. Here's exactly what we collect, why, where it's stored, and what control you have over it.

Last updated: 14 September 2026

1. Who this policy covers

This policy applies to Force and Function Pty Ltd (ABN 52 696 427 577), trading as Force & Function ("we", "us", "our"), and to everyone whose information we handle — clients, prospective clients, carers, referrers and website visitors.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). The Privacy Act's small business exemption does not apply to us: any organisation that provides a health service and holds health information is covered regardless of its size. We treat that as a standard to meet properly, not a technicality.

2. What we collect

Personal information: your name, date of birth, address, phone number, email address, emergency contact, and where relevant your carer, guardian or nominee.

Health information (classified as sensitive information under the Privacy Act): your medical history, injuries, diagnoses, symptoms, medications, referrals, assessment results, exercise programs, session notes, progress measures and correspondence with other practitioners.

Funding and billing information: your Medicare number, DVA card details, NDIS participant number and plan details, plan manager details, WorkCover claim number, private health fund details, and payment records. We do not store full card numbers — payments are processed by our payment provider.

Website information: anything you type into our contact form, and standard technical information such as your IP address when you visit the site (see section 8).

3. How we collect it

  • Directly from you — at booking, in your initial consultation, in sessions, and by phone, email or our contact form.
  • From your referrer — your GP, specialist, surgeon, support coordinator or plan manager.
  • From funding bodies — Services Australia (Medicare), DVA, the NDIA or your WorkCover insurer.
  • From a carer, family member or guardian where you have authorised this, or where you are unable to provide it yourself.

Wherever it's reasonable and practicable, we collect information directly from you. If we receive information about you from someone else and you didn't know, we'll tell you.

4. Consent for health information

We collect health information with your consent, which you give when you engage us for services and complete our intake process. Consent is not a one-off: you can withdraw it at any time, decline to answer any question, or ask us not to record something specific.

If you choose not to give us certain information, we'll tell you what that means practically. Sometimes it simply limits what we can advise; sometimes it means we can't safely prescribe exercise at all.

5. Why we use it

  • To assess you, prescribe and progress your exercise program, and deliver your care safely.
  • To keep accurate clinical records, as we are professionally required to do.
  • To bill you, or to claim from Medicare, DVA, the NDIS or your insurer on your behalf.
  • To communicate with you about appointments, your program and your account.
  • To report to your referrer or treating team, where you've consented.
  • To meet our legal, professional and insurance obligations.

We do not sell your information. We do not use your health information for marketing, and we do not send marketing emails unless you have specifically asked to receive them.

6. Who we share it with

We disclose your information only where you have consented, or where the Privacy Act permits or requires it:

  • Your treating team — your GP, referrer, specialist or other allied health practitioners, with your consent.
  • Funding bodies — Services Australia (Medicare), DVA, the NDIA, your plan manager or support coordinator, or your WorkCover insurer, for claiming and reporting.
  • Our service providers — the software and infrastructure we use to run the practice (see section 7).
  • Where required by law — for example a court order, subpoena, or a mandatory reporting obligation.
  • To lessen a serious threat — where we reasonably believe it's necessary to lessen or prevent a serious threat to your life, health or safety, or that of another person.

7. Where your information is stored

We think you should know exactly which systems hold your information and where they are.

Service What it holds Where
SploseClinical records, bookings, billingAustralia
Google WorkspaceOur email correspondenceOverseas, incl. United States
CloudflareWebsite delivery; processes contact form submissions in transitOverseas, incl. United States
ResendDelivers contact form messages to our inboxOverseas, incl. United States
GitHub PagesHosts this website (no client data)Overseas, incl. United States

Your clinical records stay in Australia. Splose, our practice management system, stores Australian clients' data in Australian data centres.

Overseas disclosure (APP 8). The website and email services listed above are operated by providers based outside Australia, primarily in the United States, and your information may be stored or processed overseas by them. Before disclosing information to an overseas recipient we take reasonable steps to ensure it's handled consistently with the APPs, including relying on providers with recognised security certifications and contractual privacy commitments. By sending us information through our contact form or by email, you consent to it being handled this way.

8. Our website

Cookies and tracking. This website does not use analytics, advertising or tracking cookies. We don't profile visitors and we don't run advertising pixels.

Contact form. What you type into our contact form is transmitted through Cloudflare and delivered to our inbox by Resend. It isn't stored on the website itself. Please don't include detailed health information in the form — it's for general enquiries, and a phone call or your initial consultation is the appropriate place for clinical detail.

Online booking. Our booking page embeds a booking calendar operated by Splose. Anything you enter into that calendar is collected by Splose under its own privacy policy as well as this one, and it may set its own cookies.

Fonts. Our pages load typefaces from Google Fonts, which means your IP address is transmitted to Google when the page loads.

Other sites. Where we link to external sites, we're not responsible for their privacy practices.

9. Keeping it secure

We take reasonable steps to protect your information from misuse, interference, loss and unauthorised access, including encrypted storage and transmission, access controls and multi-factor authentication on our systems, keeping devices locked and up to date, and limiting access to what's needed to deliver your care. No system can be guaranteed completely secure, but we take this seriously.

10. How long we keep it

We keep clinical records for at least 7 years from the date of your last appointment. Where the client was under 18, we keep records until they turn 25, or 7 years from the last entry, whichever is later. These are minimum professional standards, and records may be kept longer where there's a legal reason to.

When information is no longer needed and we're not required to retain it, we destroy or de-identify it securely.

11. Accessing and correcting your information

You have the right to ask for a copy of the personal and health information we hold about you, and to ask us to correct anything that's wrong, out of date or incomplete.

To make a request, email Admin@forceandfunction.au or call 0435 537 959. We may ask you to verify your identity. We'll respond within 30 days.

Access is normally free, though we may charge a reasonable fee for the cost of retrieving and copying a large record. We can't charge you simply for making the request.

There are limited circumstances where we may refuse access — for example where giving access would pose a serious threat to someone's life, health or safety, or unreasonably affect another person's privacy. If we refuse, we'll explain why in writing and tell you how to complain. Where clinically appropriate, we may offer to provide the information through your GP instead.

12. Data breaches

We're covered by the Notifiable Data Breaches scheme. If a data breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner as soon as practicable, and tell you what's happened and what you should do.

13. Complaints

If you're concerned about how we've handled your information, contact us first at Admin@forceandfunction.au. We'll acknowledge your complaint promptly and aim to resolve it within 30 days.

If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner — phone 1300 363 992 or visit oaic.gov.au. NDIS participants may also contact the NDIS Quality and Safeguards Commission on 1800 035 544, and Queensland health service complaints can be made to the Office of the Health Ombudsman on 133 OHO (13 46 46).

14. Changes to this policy

We may update this policy as our practice or our legal obligations change. The current version is always published on this page with the date it was last updated.

15. Contact us

Force and Function Pty Ltd — Privacy Officer
Email: Admin@forceandfunction.au
Phone: 0435 537 959
Southport QLD — servicing the Gold Coast and South-East Queensland