Clarke Allied Health Pty Ltd (ABN 35 640 855 750), trading as Holistic Me, The Innovative
Dietitian and Holistic Me Supports. 210 Main Road, Blackwood SA 5051.
Last updated: 9 August 2026
We provide dietetic and allied health services, including as a registered NDIS provider. We
hold health information, so the Privacy Act 1988 (Cth) and the Australian Privacy Principles
apply to us regardless of our size. The small business exemption does not apply to health
service providers.
Identity and contact details: your name, date of birth, address, phone number and email
address.
Health and clinical information: your health history, dietary and nutritional needs,
disability-related information, clinical notes, assessments, plans and reports, and
correspondence with other practitioners involved in your care.
Funding and scheme information: your NDIS number and plan details, plan management
arrangements, aged care funding arrangements where relevant, and billing and payment
records.
Representative and support information: details of a parent, guardian, plan nominee,
support coordinator, advocate or other person authorised to act for you, and the nature of
their authority.
Information about other people you tell us about, such as a family member or carer, where
it is relevant to your care.
Website information, described in its own section below.
Wherever reasonably practicable we collect information directly from you: in an
appointment, over the phone, by email, or through our online intake and consent forms.
We also collect information about you from other people, where you have consented or the
law permits. This commonly includes the person or organisation who referred you (your
GP, another health practitioner, a hospital or a support coordinator); your plan manager or
the NDIA in relation to funding and claiming; in aged care, the head provider you receive
services through; and your family member, guardian or representative where they are
involved in your care.
If we receive information about you that we did not ask for and do not need, we destroy or
de-identify it where the law allows.
We collect information to provide, coordinate and improve your care, to communicate with
you and the people involved in your support, to bill and claim correctly, and to meet our
legal and regulatory obligations.
We disclose your information for the purpose it was collected, or for another purpose with
your consent, or where an exception applies. Those exceptions include where disclosure is
required or authorised by law, where it is necessary to lessen or prevent a serious threat to
someone’s life, health or safety, for mandatory reporting or a reportable incident, or to a
court or tribunal. We explain these limits when we talk with you about consent, because
they are situations where we cannot promise confidentiality.
We do not use your NDIS number, Medicare number or any other government identifier as
our own client reference.
We do not send marketing. No newsletters, no promotional emails or text messages, and we
have never used health or disability information to target a message to anyone.
We do not run advertising. We do not buy ads, we do not use advertising pixels, and we do
not build or share advertising audiences from anyone who visits our site or uses our
services. If you have asked for appointment reminders and set that up with us, those are
reminders about care you have already arranged, not marketing. Our blog and website
articles are general information, not messages sent to you based on your personal
information.
If this ever changes, we would ask your consent first, and any message would carry a simple
way to opt out at no cost to you.
When you visit our website we use Google Analytics, which records standard technical
information such as your IP address, the type of device and browser you use, which pages
you visit and how long you spend on them. It is the only analytics tool on our site. We use it
to understand how the site is used, not to identify you, and we do not combine it with your
clinical records.
We can also see whether a phone enquiry reached us through the website or directly. That
tells us how people are finding us. It does not tell us anything about you beyond the fact that
the call came from the site.
If you contact us through an enquiry form or a service agreement form on the site, we
collect what you enter so that we can respond to you and set up your services.
Cookies are small files stored on your device that help a website work and help measure
how it is used. Our site uses Google Analytics cookies. You can control or block cookies
through your browser settings, though some parts of the site may not work as well if you
do.
Our blog is written by our dietitians and is general information only. It is not advice for any
individual, and it makes no claim to treat, cure or diagnose anything. We are confirming
whether the blog is published through a third-party platform and, if so, whether that
platform records anything about visitors. We will name it here once we know. We would
rather publish this honest position than leave the page silent, and if you would like to know
where that is up to before we update it, please ask.
We take practical steps to protect your information, and we are required by law to take
reasonable ones.
Our business systems are accessed through work accounts. Multi-factor authentication is
enforced on them, and we are finalising enrolment across all accounts. Access is on a need-
to-know basis, so staff see what they need for your care and not more. Information is
encrypted in transit, and our providers hold recognised security certifications. Staff are
trained in privacy and in what to do if something goes wrong, and we keep a register of any
breach or near miss so we can spot patterns.
We also have rules about screens and paper: not leaving your information visible in a
shared space, on a home visit or on a video call, and not keeping your information on
personal devices.
No system is completely risk-free, and we will not pretend otherwise. If something does go
wrong, the section further down explains what we do.
Some of the systems we use are based overseas, most commonly in the United States. This
means your information may be stored or processed there.
Systems that may hold information about you include: Google Workspace (documents,
email and calendars); ClickUp (client records, tasks and documents); Halaxy (clinical
records and appointments, an Australian company); JotForm (intake and consent forms);
Deputy (rostering, which may include an address where a support worker collects you);
DocuSign (where an agreement is signed electronically); Discord (used only for day-to-day
scheduling, using a first name and last initial, never clinical information); 3CX (our phone
system); and Xero and Dext (billing and receipts). Make and Zapier pass information
between these systems without storing it.
Before using any system that holds your information, we review the provider’s data-
handling terms and require protections consistent with Australian privacy law. We remain
accountable for your information even when an overseas provider is processing it.
We use approved, business-tier AI tools to help with work such as preparing plans, drafting
documents and summarising information. The tools we currently use are Claude
(Anthropic), ChatGPT (OpenAI) and ClickUp Brain (within ClickUp). We want to be
straightforward about what this means:
These tools may be used with your name and health information, not only with de-identified
information, when we are preparing something specifically for you.
A practitioner always checks anything an AI tool helps produce, and remains responsible for
it. No decision about your care is made by AI alone.
Under our business accounts, these providers do not use our data to train their general AI
models. Information is processed overseas, as described above.
Our staff do not type or paste any of the following into Claude or ChatGPT: NDIS numbers,
dates of birth, Medicare numbers or other healthcare identifiers, tax file numbers, bank or
card details, full residential addresses, and identity document numbers. We want to be
accurate about one thing rather than make it sound simpler than it is: ClickUp Brain works
inside our own ClickUp system, which is where your records are kept, so it can reach
information already stored there, including details of that kind. Its provider does not retain
what it processes and does not use it to train anything.
You have a choice about this, and it will not affect your services, your care or what you pay.
New clients are asked directly in their service agreement. Clients who joined us earlier are
being written to by the end of September 2026, so that everyone has the same choice. Until
you tell us otherwise, we continue to use these tools to prepare your own documents, as
described above. If you would like to make or change your choice now, without waiting for
our letter, contact us and we will action it straight away and confirm it back to you.
From 10 December 2026, Australian privacy law requires organisations to explain in their
privacy policy where a computer program is used in making decisions that significantly
affect people. We are assessing our AI use against that requirement now, and we will set out
here, before that date, the kinds of information involved and the kinds of decisions affected.
We would rather tell you early than wait.
We work with children, including children under nine through early childhood supports.
Their privacy is treated with the same care as an adult’s, with some additional
considerations:
A parent or guardian usually exercises privacy rights for a young child, including giving
consent and asking to see records.
As a child grows, we assess their capacity to make a particular decision for themselves
rather than relying on age alone. A young person who understands what is being asked may
make that decision themselves, and may ask us to keep some information private from a
parent.
We explain what we are doing in a way the child can understand, and we seek their
agreement, even where a parent is the person legally giving consent.
Where there is a parenting order, guardianship order or child protection order affecting
who may make decisions or receive information, please tell us and give us a copy so we
handle it correctly.
Where authority is genuinely in dispute between adults, we may pause non-urgent work
until it is resolved, and we will explain why. This protects the child.
Our obligations as mandatory reporters are not affected by any of the above. If we hold a
reasonable suspicion that a child is at risk, we must report it, and consent is not required for
that.
Choice and control over your own information is part of good care, not an administrative
extra. You can:
Choose how AI is used with your information, or opt out entirely.
Decline to be recorded. We ask every time before recording anything, and you can say no.
Deal with us anonymously or under a pseudonym where that is lawful and practical. It is
often not practical for clinical care, and we will tell you plainly when it is not.
Tell us who you do and do not want your information shared with, including a family
member, and we will follow that except where the law requires otherwise.
Ask to see or correct your information.
Withdraw a consent at any time. This applies from when you tell us; it does not undo
something already done, or records we must keep.
Object to something we are doing with your information and have it properly considered. If
we disagree, we will explain why and tell you how to take it further.
You can ask for access to the personal information we hold about you, or to have it
corrected. We respond within 30 days and usually at no cost. If we cannot give access or
make a change, we explain why in writing, and you can ask us to attach a statement noting
your view. Where we correct something already shared with someone else, we tell them too
where it is relevant.
We keep records only as long as we need them or the law requires. As a general position,
adult health records are kept for at least seven years from your last appointment, and a
child’s records until they turn 25. Some records must be kept longer under NDIS or aged
crae requirements. When information is no longer needed we securely destroy or de-
identify it.
If we become aware of a data breach likely to cause you serious harm, we assess it
promptly, notify the Office of the Australian Information Commissioner where required, and
tell you directly wherever practicable, with the steps you can take to protect yourself.
If you are unhappy with how we have handled your information, please tell us first. We take
complaints seriously and it will not affect your care. Contact us on (08) 7092 8680 or
hello@holisticme.com.au.
You can also complain to an external body at any time. You do not have to wait for us to
finish, and you can have an advocate or support person help you.
Office of the Australian Information Commissioner (privacy): 1300 363 992, Monday to
Thursday 10am to 4pm, or oaic.gov.au/privacy/privacy-complaints. The OAIC will usually
ask that you raise it with us first.
NDIS Quality and Safeguards Commission (NDIS supports and provider conduct): 1800 035
544, or ndiscommission.gov.au. TTY 1800 555 677. National Relay Service 1800 555 727.
Aged Care Quality and Safety Commission (aged care): 1800 951 822.
Phone (08) 7092 8680. Email hello@holisticme.com.au. Post 210 Main Road, Blackwood
SA 5051.
If you would like this information in Easy Read or another accessible format, please ask and
we will provide it.