1. Who this policy covers
This Privacy Policy explains how Port Jackson Pty Ltd (ABN 79 604 392 145), trading as Posture 4 Health ("we", "us", "our"), collects, holds, uses, and discloses personal information through the Posture 4 Health application (the "Application"), in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy applies to:
- clinic staff (practitioners, receptionists, and administrators) who use the Application ("Staff Users"); and
- patients/clients whose information is entered into the Application by a clinic ("Patients").
Each clinic using the Application ("Clinic") is separately responsible, as the data controller, for its own collection of Patient information and for obtaining any consents required from its Patients — see section 8.
2. Information we collect
2.1 From Staff Users
- Name and email address (for login and account administration);
- Role/permission level within the Clinic;
- Login activity and basic usage data (e.g. last screen viewed, for convenience features such as resuming where you left off);
- Acceptance records for our Terms of Use & Software License Agreement (name/email, date, and version accepted).
2.2 From or about Patients (entered by Clinics)
- Name, age/date of birth, sex, height, and weight;
- Photographs taken for posture assessment (lateral and AP/front-view images), and landmark/measurement data derived from those photographs;
- Calculated posture metrics and scores (e.g. Postural Health Score, Vitality Score, and related breakdowns);
- Exercise prescriptions and clinical notes entered by Staff Users;
- Contact details (e.g. email address and/or mobile number) where a Clinic chooses to email or text a report, reminder, or other communication to the Patient.
2.3 Technical information
- Device/browser information needed for the Application to function (e.g. to request camera access for posture photos);
- Information stored locally on the device (browser local storage / IndexedDB) to allow the Application to work offline and resume sessions — this stays on the device and is not separately collected by us, except where it is synced to our servers as part of normal use (e.g. saving an assessment).
We do not use cookies, third-party advertising trackers, or analytics services that profile individual Patients or Staff Users.
3. How we collect information
We collect information:
- directly from Staff Users (e.g. when creating an account, or entering Patient details and taking photographs during an assessment);
- automatically, through the Application's normal operation (e.g. camera capture, calculated scores, login timestamps).
We do not collect personal information about Patients directly — this is provided to us by the Clinic via its Staff Users, in the course of the Clinic's own clinical practice.
4. How we use information
We use the information described above to:
- provide, operate, and maintain the Application, including generating posture assessments, scores, and reports;
- authenticate Staff Users and manage access permissions for each Clinic;
- enable Clinics to send reports, reminders, and related communications to their Patients by email or SMS, where requested;
- generate, with the assistance of a third-party AI text service, draft wording for reports and care-plan communications, using de-identified clinical measurements only (see section 5);
- maintain records of acceptance of our Terms of Use & Software License Agreement;
- provide customer support and respond to enquiries;
- maintain the security, integrity, and proper functioning of the Application (e.g. detecting and preventing unauthorised access);
- comply with our legal obligations.
We do not use Patient information for marketing, and we do not sell personal information to third parties.
5. Disclosure of information
We may disclose information to:
- the Clinic that the Patient or Staff User is associated with, and to other Staff Users at that Clinic who have appropriate access permissions (e.g. a practitioner viewing a Patient's history);
- service providers (sub-processors) who help us operate the Application — we require each to protect the information and to use it only to provide services to us. Our current sub-processors are:
- Supabase (database, authentication, and file storage) — Patient and account data is hosted in Australia (Sydney); see section 7;
- Netlify (application hosting and content delivery, USA/global) — delivers the Application's code to your browser; Patient data is not stored on or routed through Netlify, as your browser communicates directly with Supabase in Australia;
- Resend (transactional email, USA) — used to send emails such as a Patient report or an account email; receives the recipient's name and email address and the message or report content;
- ClickSend (SMS, Australia) — used to send text messages, such as reminders, where a Clinic enables this; receives the recipient's mobile number and message content;
- Stripe (payments, USA) — processes Clinic subscription and billing information; it does not receive Patient health information;
- Anthropic (AI text generation, USA) — used to draft report and care-plan wording. Only de-identified clinical measurements are sent; Patient identifiers (such as name, date of birth, and contact details) and Patient photographs are not sent to this service. Under Anthropic's commercial terms, data sent via its API is not used to train its models;
- government bodies, regulators, or law enforcement, where required or authorised by law;
- a successor entity, in the event of a sale, merger, or restructuring of our business, subject to that entity continuing to protect the information in accordance with this policy (or a policy of at least equivalent protection).
We do not disclose Patient information to other Clinics, or to Staff Users outside the Patient's own Clinic.
6. Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure, including:
- role-based access controls, so Staff Users can only access information relevant to their Clinic and role;
- encrypted transmission of data (HTTPS/TLS) between the Application and our servers;
- authentication via Supabase Auth, with the ability for Clinics to deactivate Staff User accounts;
- restricting administrative access to our infrastructure to authorised personnel.
No method of transmission or storage is completely secure. If we become aware of a data breach likely to result in serious harm, we will take steps required under the Privacy Act 1988 (Cth) Notifiable Data Breaches scheme, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.
7. Storage location and overseas disclosure
7.1 Patient and account information collected through the Application is stored using Supabase infrastructure, hosted in Australia (Sydney, ap-southeast-2). Backups of this information are also held in Australia.
7.2 Some of our service providers are located overseas, which means limited personal information may be disclosed outside Australia in the course of operating the Application (Australian Privacy Principle 8). Specifically:
- email content and recipient details are processed by Resend in the United States when an email (such as a Patient report) is sent;
- de-identified clinical measurements are processed by Anthropic in the United States when AI-assisted report or care-plan wording is generated — no Patient identifiers are sent;
- Clinic subscription and billing information is processed by Stripe in the United States (no Patient health information is sent);
- the Application's code is delivered via Netlify's global content delivery network, but Patient data is not stored on that network.
SMS messages are sent via ClickSend in Australia. We take reasonable steps to ensure these providers handle personal information in a manner consistent with the Australian Privacy Principles.
8. Clinics' responsibilities for Patient consent
Clinics are responsible for:
- ensuring they have a lawful basis (including, where required, the Patient's informed consent) to collect Patient personal and health information and enter it into the Application, including taking posture photographs;
- informing Patients that their information will be processed using the Application and, where appropriate, providing Patients with a copy of (or a link to) this Privacy Policy or the Clinic's own privacy policy;
- responding to Patient requests to access, correct, or delete their information held in the Application, in accordance with the APPs and any applicable health records law — we will assist Clinics to action such requests within the Application where technically possible.
9. Data retention and deletion
9.1 We retain information for as long as the relevant Clinic's account remains active, plus any additional period required by law (including health records retention requirements, which can be longer than general business records).
9.2 A Clinic may request deletion of a Patient's record via the Application (where this feature is available) or by contacting us. We will action such requests unless we are required by law to retain the information. Clinics should note that health records legislation in their state (e.g. the Health Records Act 2001 (Vic) or equivalent) may impose minimum retention periods for patient health records (commonly around 7 years from the last consultation, or until a minor patient turns 25) — Clinics are responsible for ensuring any deletion request is consistent with their own record-keeping obligations before requesting deletion via the Application.
9.3 On termination of a Clinic's licence to use the Application, we will retain the Clinic's data for 90 days to allow export, after which it may be deleted in accordance with our data retention practices, subject to section 9.1.
10. Access and correction
10.1 Staff Users can access and update their own account information within the Application (e.g. via Settings).
10.2 A Patient who wishes to access, correct, or delete their personal information should contact their Clinic in the first instance, as the Clinic controls that information. If the Clinic is unable to assist, the Patient (or the Clinic on their behalf) may contact us using the details in section 12.
11. Children's information
The Application may be used by Clinics to record posture assessments for minors, with the consent of a parent/guardian obtained by the Clinic in accordance with its own policies and applicable law. We do not knowingly collect personal information directly from children.
12. Complaints and contact
If you have a question, concern, or complaint about how we handle personal information, please contact us at contact@posture4health.com.
We will acknowledge your complaint and aim to respond within a reasonable time. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
13. Changes to this policy
We may update this Privacy Policy from time to time, for example to reflect changes in the Application, our service providers, or the law. The "Last updated" date at the top of this policy will be revised, and material changes will be notified to Staff Users (e.g. by email or in-app notice).
A link to the current version of this Privacy Policy is available within the Application (Settings → Account) and on request.