Privacy Policy

Summary

Dental Embassy is committed to protecting your personal and health information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Notifiable Data Breaches (NDB) scheme.

As a health service provider, we collect and manage sensitive health information to provide safe and effective dental care. We also use website analytics and advertising tools to improve our website and communicate our services.



1. Our Commitment to Privacy

Dental Embassy handles personal and health information in accordance with:

  • The Privacy Act 1988 (Cth)
  • The Australian Privacy Principles (APPs)
  • The Notifiable Data Breaches scheme

2. What Information We Collect

We may collect:

Personal Information

  • Name
  • Date of birth
  • Address
  • Phone number and email
  • Emergency contact details

Sensitive Information (Health Information)

  • Medical and dental history
  • X-rays, scans and photographs
  • Diagnoses and treatment plans
  • Clinical notes

Administrative Information

  • Appointment history
  • Billing and payment details
  • Health fund and Medicare details
  • Referral information
  • Communication records

Website and Device Information

When you visit our website, we may collect:

  • IP address
  • Device type and browser information
  • Pages viewed and time spent on pages
  • Interactions with website content
  • General geographic location (approximate)

3. How We Collect Information

We collect information:

  • Directly from you (in person, phone, email, SMS, online forms)
  • Through our secure patient portal
  • Via online booking systems
  • From referring healthcare providers
  • From Medicare or health funds
  • Automatically through website cookies and tracking technologies

Where reasonable and practicable, we collect information directly from you.


4. Why We Collect and Use Information

We collect and use your information to:

  • Provide safe and appropriate dental care
  • Maintain accurate clinical records
  • Process payments and health fund claims
  • Communicate about appointments and treatment
  • Meet legal and accreditation obligations
  • Improve our website and patient experience
  • Measure the effectiveness of our advertising

We do not use your health information for advertising purposes.


5. Consent and Sensitive Information (APP 3)

Health information is sensitive information under Australian law. By registering as a patient, you consent to us collecting and using your health information for the purpose of providing dental treatment.

We will obtain consent where required for any secondary uses not directly related to your care.


6. Disclosure of Information (APP 6)

We may disclose your information:

  • To healthcare providers involved in your treatment
  • To dental laboratories and specialists
  • To Medicare and health funds
  • To third-party service providers assisting with practice operations
  • When required or authorised by law
  • To prevent a serious threat to life, health or safety

We do not sell your personal information.


7. Overseas Disclosure (APP 8)

Patient clinical records are stored within Australia using secure cloud-based systems.

However, some website analytics and advertising providers (such as Google and Microsoft) may process website interaction data on servers located outside Australia.

Where personal information is disclosed overseas, we take reasonable steps to ensure the recipient handles the information in accordance with Australian privacy obligations.


8. Cloud-Based Systems

We use secure cloud-based practice management software (including CareStack) hosted in Australia. Access is restricted to authorised staff involved in your care or administration.


9. Data Security (APP 11)

We take reasonable steps to protect your information, including:

  • Access controls and authentication systems
  • Encryption of data in transit
  • Secure Australian hosting for clinical records
  • Staff confidentiality obligations
  • Secure disposal of records
  • Ongoing monitoring and updates

No system can guarantee absolute security.


10. Data Retention

We retain health records:

  • At least 7 years from last treatment
  • For minors, until at least age 25

Records are securely destroyed or de-identified when no longer required.


11. Direct Marketing (APP 7)

With your consent, we may send appointment reminders, updates or information about our services via SMS or email.

You may opt out at any time.

We may also display advertising through online platforms. These platforms may use cookies to show ads based on previous website visits.


12. Website Analytics, Advertising and Tracking Technologies

Our website uses cookies and similar technologies to understand how visitors use our site and to measure advertising performance.

We use:

  • Google Analytics – to analyse website traffic and user behaviour
  • Google Ads – to measure advertising performance and display ads
  • Microsoft Clarity – to understand how users interact with our website (e.g., clicks, scrolling and navigation patterns)

These tools may collect information such as:

  • IP address
  • Browser and device information
  • Pages visited
  • Interaction behaviour (such as clicks and scrolling)

Microsoft Clarity may use session replay technology to analyse website usability. This is used for improving site functionality and user experience.

This data:

  • Is generally aggregated and de-identified for reporting
  • Is not linked to your clinical health records
  • Is not used to access or view your treatment information

You can control cookies through your browser settings. You can also opt out of personalised advertising via Google’s Ad Settings or similar tools.

If we implement a cookie consent banner, it will allow you to manage non-essential tracking technologies.


13. Access and Correction (APP 12 & 13)

You may request access to or correction of your personal information by contacting us in writing.

We aim to respond within 30 days.

A reasonable administrative fee may apply for copies of clinical records.


14. Anonymity and Pseudonymity (APP 2)

Where lawful and practicable, you may interact with us anonymously (for example, general website browsing).

However, we require identification for clinical treatment.


15. Data Breaches (NDB Scheme)

If a data breach is likely to result in serious harm, we will:

  • Assess and contain the breach
  • Notify affected individuals where required
  • Notify the Office of the Australian Information Commissioner (OAIC)

16. Complaints

If you have concerns about your privacy, please contact us first.

We aim to respond within 30 days.

If you are not satisfied, you may contact the Office of the Australian Information Commissioner (OAIC):

Website: https://www.oaic.gov.au/
Phone: 1300 363 992


17. Contact Us

Dental Embassy
Unit 2, 45 Hall Street
Lyneham ACT

Email: care.dentalembassy@gmail.com
Phone: 1300 000 230


18. Changes to This Policy

We may update this policy from time to time. The latest version will always be available on our website.