Praktika Privacy Policy
We are committed to protecting the privacy of personal information which We handle. We recognise that privacy principles protect personal information as a matter of individual right. We recognise the essential right of individuals to have their information handled in ways which they would reasonably expect — protected on the one hand, and made accessible to them on the other.
Collection of personal information
In broad terms this means that We:
- store and handle only information which We need for our specified primary purpose, i.e. provision of services to practices and their patients;
- ensure that the clients know how We handle, store and provide access to that information;
- use and disclose it only for the primary or a directly related purpose, or for another purpose with the practice's or person's consent (unless otherwise authorised by law);
- store it securely, protecting it from unauthorised access; and
- retain it for the period authorised by the Health Records Act 2001 or according to the practice's specific requests;
- provide practices and their staff with secure access to the information they store in Praktika.
- provide practices, staff and patients with information about how to access and correct their personal information, and how to make a complaint (see clauses 18 and 19).
Collection of information via Praktika online software
Use and disclosure of personal information
- for the purpose that We have collected the information, i.e. securely storing it and providing secure access to it by the authorised Praktika users;
- purposes connected with the operation, administration, development or enhancement of Praktika online software and the services it is used to provide;
- any other purposes required or authorised by law.
Transfer of information outside of Australia
Practice responsibilities
Security of personal information
We have implemented technology and security policies, rules and measures to protect the personal information that We have under our control. However, you should be aware that there are risks in transmitting information across the Internet. So, while We strive to protect such information, We cannot ensure or warrant the security of any information transmitted online, and practices do so at their own risk. Once any personal information comes into Our possession, We will take reasonable steps to protect that information from misuse and loss and from unauthorised access, modification and disclosure. We may remove personal information from its system where it is no longer required (except where archiving is required and in order to fulfil our obligations under the Health Records Act 2001). See also clause 20 for what happens in the event of a data breach.
We take additional steps to protect the security of the information we store and transmit, such as strong 256-bit SSL encryption.
The level of access to this information, i.e. rights to read, write or modify it, for users belonging to your practice is regulated and authorised by you. We only make sure that there is no unauthorised access to the information that is stored on our servers. Cross-account access to the information is categorically not allowed.
All the information is stored on our dedicated web servers that are located in high-level of security data centres.