Privacy Policy
Effective Date: 1 March 2026
Your Privacy and Velora Edge Group Pty Ltd (ABN 24 693 639 879) trading as Velora HealthConnect (collectively and individually referred to as "Velora HealthConnect", "we", "us" or "our").
Who We Are and How You Can Contact Us
We are Velora HealthConnect and we are based in NSW, Australia. We are committed to protecting your privacy and respecting and upholding your rights when you use this Site. This Privacy Policy applies to the products and/or services we provide on our Site www.velorahealthconnect.com.au ("Site") and our social media channels (if applicable), and explains how we collect, hold, use and disclose data and comply with the requirements of the Privacy Act 1988 (Cth) and constitutes part of our Website Terms & Conditions. This Privacy Policy does not cover information that you submit on other websites, even if we communicate with you on those sites. For example, if you post something on Instagram, Facebook, Pinterest, X, or YouTube, that information is governed by the privacy policies on those websites and is not governed by this Privacy Policy.
You can contact us for privacy related questions by emailing us or completing this form.
We will only use your personal information (including, if applicable, sensitive information) (personal data/data) in compliance with Australian Privacy Laws (Privacy Act 1988 (Cth)), Australian Privacy Principles and to the extent applicable, with the EU General Data Protection Regulation (GDPR) and any replacement legislation or regulation or guidelines and standards governing the use, storage or transmission of data.
Our Role in Your Privacy
If you are a customer, subscriber or just a visitor on our Site, this Privacy Policy will apply to you.
Our Responsibilities
As we are the providers of the products and services on this Site, we determine how and why your data is processed. We do not sell or rent your details to any third parties. We are committed to protecting your privacy and we want you to know exactly what information is collected and how we use it.
Your Responsibilities
Please read this Privacy Policy and our Website Terms & Conditions. If you provide us with any data relating to a third party, you confirm that you have the right to authorise us to process that data on your behalf in accordance with this Privacy Policy.
When and How We Collect Data
From the moment you visit our Site, we are collecting data, sometimes you might provide this data by completing a form or setting up an account, otherwise we might collect the data automatically. We may also collect data when:
- You register as a client with our clinic
- You provide us with your medical history, current health issues and concerns
- You provide us with information about your medical history, medications, allergies or other relevant clinical details during intake or consultation, including via secure online forms
- You purchase an online course, webinar, program or service
- You interact with us on social media
- You complete any sign-up forms, landing pages or send us a direct message via social media or an email to any of our nominated emails
- You participate in any request for additional data such as customer surveys
- You voluntarily submit your data to us for any reason
- You accept our cookies and tracking technologies, which may include services from third parties that provide analytics, traffic management, content delivery and load balancing (e.g. CDNs)
- You interact with any mobile applications operated by us
Types of Data We May Collect
To provide our services, operate our website and meet our legal obligations, we may collect different types of personal information from you. The type and amount of information we collect will depend on how you interact with us, the services you purchase and the permissions you give us. This may include:
- Personal Information we collect include (but are not limited to) your name, date of birth, address, email address, phone numbers, driver's licence details, Medicare information, billing and shipping information.
- Health Information about you with your consent, (including when you provide it to us) or otherwise in accordance with the Privacy Act, including (but not limited to) your medical history, Medicare number, Individual Healthcare Identifier (IHI) number, height, weight, symptoms, future health goals, medical records, medical prescriptions and other health information or sensitive information you provide or that we consider necessary to provide our services to you.
- Data about the products or services you purchase
- Data about your experience with our Site and our products and services
- We may collect and store photos, taken before, during and after your treatment, for treatment planning, clinical documentation or marketing purposes (with your express consent). All images are securely stored.
- Data relating to your circumstances and such other information that is relevant to the products or services we provide to you
- Technical Data that identifies you (your IP address, login, browser type, time zone, browser plugins, geolocation, what operating system and version) — we do not link this with any personal data
- Usage Data on how you use our Site (URL clicks, products and services views, how long you are on our pages and other actions)
We may also collect technical data via third-party services, such as content delivery networks or font services, to improve the performance and functionality of our Site. These services may collect information like IP addresses to ensure proper delivery and functionality.
Use and Disclosure of Your Data
Under data laws, we are only allowed to use your data for specific reasons and where we have the legal basis to do so. We will use your data for the purposes it was collected and related purposes which include:
- Operating our Site
- Providing you with products, information and services
- Customer support
- Tracking your purchase history
- Detecting and preventing fraud
- Improving our Site
- Making your experience on our Site more efficient and enjoyable
- Market research
- Provide you with information about events, other products or services or opportunities that may be of interest
- Marketing (with your consent)
- Monitoring your compliance with our Website Terms and Conditions
We may also use and disclose your personal data for secondary purposes, such as:
- Quality assurance
- Research and education
- Administrative and billing purposes
- As required by law subject to our obligations
- With your consent
- Within our business
- To send you marketing material (with your consent)
- Share with third parties to enable us to provide our products and/or services
Sensitive Information
Collection of Sensitive Information
We may collect sensitive information about our clients with their consent and only for the purposes directly related to treatment. The types of sensitive information we may collect include personal details, medical history, current health conditions, test results and any other information required for provision of care.
We collect sensitive information through telehealth consultations, phone calls, online forms and other secure electronic means.
Use of Sensitive Information
We use sensitive information solely for the purpose of providing services to our clients. This includes but is not limited to treatment planning, documenting services and ensuring continuity of care.
- Sensitive information may also be used for administrative purposes such as appointment scheduling, billing and quality improvement activities.
- We may use de-identified information for research and statistical purposes, ensuring that clients' identities are protected.
Disclosure of Sensitive Information
- We only disclose sensitive information to other healthcare professionals and organisations involved in the provision of healthcare to our clients. Such disclosures are made on a need-to-know basis and with the client's consent, except in cases where the law requires or permits the disclosure without consent.
- We may disclose sensitive information to government agencies, regulatory bodies and insurers when required by law or for insurance claims and compliance purposes.
- We do not disclose sensitive information to third parties for marketing or commercial purposes.
Data Security and Storage
We take all reasonable steps to ensure that sensitive information is stored securely and protected from unauthorised access, loss, misuse or disclosure. Measures include:
- Secure systems and password protection
- Multi-factor authentication on key systems
- Encrypted connections (HTTPS) for our website
- Role-based access controls so staff only see what they need
- Secure, approved software for document storage and communications
- Regular review of our information handling practices
Electronic records are stored in a secure and encrypted manner. We regularly review and update our security measures to maintain the integrity and confidentiality of sensitive information.
Meta Insights
In our efforts to continuously improve your experience on our platform, we utilise Meta Insights and Meta Analytics to understand how you interact with our content on our Facebook page. This technology helps us to measure and analyse user engagement and effectiveness of our services, ensuring we can enhance our offerings to better meet your needs. For details on how Meta collects and uses your data, we encourage you to review Meta's Privacy Policy. Should you prefer to not have personalised ads on Facebook based on the data collected, you have the right to modify your ad preferences. This can be done by accessing your Facebook settings and navigating to "Ad Preferences", where you can adjust your settings according to your preferences.
Choosing Not to Provide Personal Data
You can choose not to provide us with any personal data. However, if you do this, we will not be able to provide you with any products or services, however, you can continue to use our Site and browse the pages of our Site.
Marketing
We will always let you know before we collect any data from you what the intended use is and if we intend to use it for marketing and if third parties are involved we will obtain your consent (which you can withdraw at any time). You can change your mind about marketing material by opting out by:
- Completing the contact us form on our contact page; or
- Unsubscribing within the email if you have previously subscribed to our newsletter.
Your Rights
You can exercise your rights at any time by contacting us via the contact us page on our Site.
Accessing Information We Hold About You
We will provide you with the information within 30 days of your request, unless doing so would adversely affect the rights and freedoms of others (e.g. another person's confidentiality or intellectual property rights). We will tell you if we can't comply with your request and why.
Inaccurate Information
You can contact us to ask us to correct any information we hold about you that you believe is inaccurate.
Objections to Using Data for Profiling or Automated Decisions
We may use your personal information to help us understand what products, services, or information may be most relevant to you (for example, tailoring our communications based on your interactions with us). These activities are primarily administrative and marketing-related and do not involve automated decision-making that produces legal or similarly significant effects.
In limited circumstances, we may use automated tools to support operational or compliance-related processes. Where such tools are used, we take reasonable steps to ensure transparency and oversight. You may contact us if you would like further information about how these processes operate or how your information is used.
The Right to Be Forgotten
You have the right to request for your data to be erased. This means we have to delete all information that we hold about you, except to the extent of any information we are required to hold due to our legal obligations.
Making a Complaint
If you have any complaints regarding how your data is handled, please contact us. If you are not satisfied with our response to your complaint, you may seek a review by contacting the Office of the Australian Information Commissioner (OAIC) via their website www.oaic.gov.au.
Under Australian privacy laws, individuals may have rights to take legal action for serious invasions of privacy, including the misuse of private information or unreasonable intrusion into their private affairs.
If you believe your personal information has been intentionally or recklessly mishandled in a way that constitutes a serious invasion of privacy, you may be entitled to seek remedies, including compensation, in addition to making a complaint to the OAIC or other relevant authority.
Security of the Data We Collect
We realise that our customers trust us to protect their data and whilst we cannot guarantee the security of any information you transmit to us, or receive from us, we take that task seriously and maintain reasonable and appropriate physical, electronic and procedural safeguards to help protect your data. This includes the following:
- Firewalls
- Password access to accounts
- Storing electronic data with reputable third party storage providers who have appropriate security protections
- Limit access to personal information to individuals who need to know
- Using payment providers who are PCI DSS compliant
- We do not store your payment details
Data Breach Response and Notification
Despite the security measures we have in place, no system is completely secure. In the event of a data breach that is likely to result in serious harm to individuals whose personal information is affected, we will comply with our obligations under the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). This includes:
- Promptly assessing the suspected data breach
- Taking reasonable steps to contain and remediate the breach
- Notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required by law. Notifications will include information about the nature of the breach, the type of information involved, and steps affected individuals can take to reduce potential harm.
Where We Store Data
We use service providers based in Australia. We may share your data with overseas organisations in countries or under privacy frameworks approved by the Australian Government. These countries are deemed to have privacy protections similar to Australia's. Where applicable, we take steps to ensure that your data remains protected in line with Australian privacy laws.
How Long We Store Data For
We will retain your data for as long as it is reasonably necessary for the purposes for which it was collected and as required by Australian law. The specific retention period will depend on your interactions with us. If you have made a purchase, we will keep a record of your purchase for the period necessary to fulfill our invoicing and tax obligations as mandated by Australian tax laws. Once we no longer require your information for the stated purposes, we will securely delete it or anonymise any data that is no longer necessary, in accordance with applicable Australian privacy regulations.
Third Parties Who Access Your Data
We share data with third parties in the following circumstances:
- Other companies in our group of companies, as necessary to operate our Site
- Our suppliers and service providers working for us e.g. payment processors such as Stripe
- Our professional and legal advisors
- Your personal and sensitive information (to the extent applicable) may also be disclosed to government bodies, such as Medicare, for the purposes of claiming and verifying healthcare benefits and entitlements
- Third parties engaged in fraud prevention and detection
- Law enforcement or other government authorities
Third parties who enable us to provide our products and services may include:
- Payment processors such as Stripe, PayPal, Xero, Shopify who may process your payment for any products and services bought from us
- Social media and analytics such as Facebook, Instagram and Google Adwords for purpose of custom audience generation and the development of targeting criteria
- Other third parties such as Mailchimp, Klaviyo, Timely, Active Campaign, for processing and holding data that enables us to ensure you are kept informed of all course information, logins and marketing material, offers, promotions, newsletters, blogs and video training
- Third-party platforms (e.g. aesthetic booking software or clinical documentation systems) to manage appointment history and clinical records. These platforms comply with Australian privacy standards.
Where we have your consent to do so or otherwise where we are legally permitted to do so.
Use of Artificial Intelligence (AI)
We may use secure, third-party AI-powered software to assist with non-clinical tasks such as consultation transcription, administrative record-keeping and clinical note drafting. These tools are used to support efficiency and service quality.
All data processed through AI systems is handled in accordance with our Privacy Policy and applicable privacy laws. No AI tools are used to provide medical diagnoses or make treatment decisions.
Where required by law, patient consent will be obtained prior to the use of such technologies in their care.
Payment Security
All of our real-time credit card authorisations are handled by secure third party gateway providers and these are secured by the highest level of security. The following measures are taken to protect your data:
- Payments are fully automated with an immediate response.
- Your complete credit card number cannot be viewed by us or any outside party.
- All transaction data is encrypted for storage within our third party gateway suppliers bank-grade data centre, further protecting your credit card data.
- Our third party gateway provider is an authorised third party processor for all the major Australian banks.
- Our third party gateway provider will at no time touch your funds, all monies are directly transferred from your credit card to the merchant account held by us.
We use third-party gateway providers that are widely respected for providing secure and reliable online payment solutions. While we attempt to protect the information in our possession, no security system is perfect, and we cannot promise that information about you will remain secure in all circumstances.
The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard for all organisations that handle branded credit cards from major card schemes. PCI DSS is a standard mandated by the card brands like Visa, Mastercard, American Express and Discover and is managed by the PCI Security Standards Council. PCI-DSS requirements help ensure the secure handling of credit card information through our Site and the service providers.
Age of Consent
By using this site, you warrant that you are at least 18 years old. Our Site should not be used by anyone under the age of 18 years and we do not knowingly collect data from anyone under the age of 18 years.
Cookies and How to Block Them
Our Site uses cookies and similar technologies to provide certain functionality to our Site. "Cookies" are data files that are placed on your device or computer and often include an anonymous unique identifier. Cookies can also be used to analyse traffic and for advertising and marketing purposes. They do not harm your systems and the HELP function in your browser will tell you how to restrict or block the cookies.
You can turn off cookies by activating the setting in your browser that allows you to do this. You can also delete cookies through your browser settings. For more information about cookies, and how to disable cookies, visit www.allaboutcookies.org. If you use browser settings to block all cookies, you may not be able to access all or parts of our Site.
Web Beacons
We may use web beacons (or clear gifs) on our website and in our emails. When we send emails, we can track behaviour such as who opened the emails, who clicked the links and collect information such as your IP address, your browser or email type, we then put this information together to improve the performance of our email campaigns and provide you with better and/or services specific to your needs. You will always have the ability to opt out of any emails we send just click the link in the email that says "unsubscribe".
Governing Law
This Privacy Policy and your use of this Site is governed in all respects by the laws of Australia.
Updates to Our Privacy Policy
Please make sure to check in on our Privacy Policy periodically, as we may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons. We will always ensure that the current date of the Privacy Policy also known as the "Effective Date" is prominently displayed at the very top of this Privacy Policy, so you know it's the latest version.
Privacy Policy Complaints and Enquiries
If you have any queries or complaints about our Privacy Policy please contact us at: