Privacy policy
Entity: Prickly Health Pty Ltd (ACN: 686 380 156, ABN: 26 686 380 156) ("Prickly", "we", "us", or "our")
Jurisdiction: Victoria, Australia (Operating as a National Service)
At Prickly, we provide clinician-led screening for sexually transmitted infections (STIs). Because we handle highly sensitive health information, we are committed to protecting your privacy to the highest legal, ethical, and clinical standards.
This Privacy Policy outlines how we collect, use, disclose, and protect your personal and health information in accordance with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and applicable state and territory health records legislation (including the Victorian Health Records Act 2001 and the New South Wales Health Records and Information Privacy Act 2002).
Section 1: Scope and types of information we collect
To provide safe, accurate, and compliant clinical care, we must collect both Personal Information and Sensitive Information (specifically, Health Information) as defined under Section 6 of the Privacy Act 1988 (Cth).
- Identity & demographics: Legal name, preferred name, date of birth, biological sex, gender identity, and pronouns. We collect preferred names and pronouns to ensure we communicate with you respectfully.
- Contact information: Email address and mobile phone number.
- Government & healthcare identifiers: Medicare number, Individual Healthcare Identifier (IHI), or overseas student/visitor health cover (OSHC/OVHC) details.
- Identity documentation: Where your identity cannot be adequately verified against national digital health systems (such as the IHI service), we may ask you to securely upload photographic identification (such as a driver licence or passport). These documents are uploaded over an encrypted channel directly into your clinical record in Halaxy, are held on servers located within Australia, and are never requested or accepted by ordinary email.
- Clinical data (including sexual health & medical histories): Answers to our digital sexual health questionnaire, clinical and medical histories relevant to your care, and pathology test results.
- Financial data: Payment details processed securely at the time of requesting a screening. All credit card transactions are handled via a secure, PCI DSS-compliant third-party gateway integrated with Halaxy. Prickly does not store, capture, or have access to your full credit card number or raw financial credentials.
- GP details: The contact details of your regular General Practitioner (only collected if you explicitly consent to sharing your results).
Section 2: Methods of collection, user responsibility, and APP 2 (anonymity)
We collect information directly from you when you complete our digital intake and consent forms. We also collect clinical results directly from our partner pathology laboratory following the processing of your samples.
User responsibility for data accuracy: When submitting clinical questionnaires or registering an account, you represent and warrant that all information provided is truthful, accurate, and completely up to date. You acknowledge that our clinicians rely entirely on the honesty and completeness of the data you submit to make safe clinical determinations.
Anonymity and pseudonymity (APP 2): Under APP 2, individuals have the option of not identifying themselves or using a pseudonym. However, due to the medical and regulatory nature of pathology testing in Australia, it is not practicable – and, for Medicare-rebated pathology, not lawfully possible – for Prickly to provide screening services anonymously or under a pseudonym. Our partner laboratory and clinicians require verified legal identities to issue valid Medicare-compliant pathology requests, accurately match clinical records, and process diagnostic results safely.
Unsolicited personal information (APP 4): If you provide us with personal or health information that we have not requested (such as sending unsolicited medical records or files via email), we will determine within a reasonable period if we could have lawfully collected that information under Australian law. If not, and where permitted by law, we will securely destroy or permanently de-identify that information immediately to protect your privacy.
Section 3: Use of information and clinical governance
Your information is strictly used for the primary purpose of providing healthcare services and managing your clinical pathway.
- Clinical governance and autonomy: Prickly utilises digital questionnaires to securely gather your health history solely for the purpose of pathology screening requests. We do not use fully automated decision-making (ADM) or AI systems to issue referrals or interpret clinical data. Every pathology request generated through our platform – and the subsequent review of every lab result – is manually assessed, verified, and actioned by an Ahpra-registered Australian clinician. In delivering this care, our clinicians exercise complete professional and clinical independence to determine if asynchronous care is appropriate and safe for your specific circumstances.
- Synchronous prescribing policy: In strict adherence to Medical Board of Australia telehealth guidelines, Prickly does not prescribe medication or formulate treatment plans asynchronously via text, chat, or questionnaire. If your screening results indicate that clinical treatment or prescription intervention is required, all prescribing and subsequent clinical management is conducted exclusively via a real-time, synchronous telehealth consultation (video or telephone) with an Ahpra-registered practitioner.
Section 4: Digital architecture, storage, and cross-border transfers (APP 8)
We minimise data vulnerability by ensuring your permanent clinical files are never stored on independent, unprotected, or non-clinical databases.
- Primary clinical storage (Halaxy): All clinical data, questionnaire responses, payment history, and medical records are hosted directly within Halaxy, an industry-leading, highly secure clinical practice management platform. All Halaxy data is stored on secure servers located physically within Australia, meeting national health privacy standards, and is encrypted both in transit and at rest using industry-standard encryption.
- Administrative processing (Google Workspace) & transient collection: We use Google Workspace exclusively for administrative and logistical operations (such as generating hardcopy PDF pathology referral forms and handling inbound administrative emails). Incoming laboratory results do not pass through Google Workspace – they are transmitted directly from our partner laboratory into our clinical platform via a secure clinical messaging network. Google Workspace is used under Google's enterprise data protection agreements, and we apply our own access controls and handling procedures to meet our obligations under the Australian Privacy Principles.
- Operational purge protocol: To maximise your privacy, any pathology referral data or clinical information passing transiently through our Google Workspace is completely purged from our active administrative systems as soon as it is no longer required for immediate clinical or logistical operations.
- Cross-border data transfer (APP 8): While your primary clinical records remain permanently in Australia, some supporting systems process limited data overseas: Google Workspace stores administrative data in secure data centres located within the European Union (EU); our website and security infrastructure (Cloudflare) processes visitor traffic on its global network, including in the United States; and card payments are handled by our PCI DSS-compliant payment gateway, which may process transaction data outside Australia. We take reasonable steps to ensure these providers handle your information consistently with the Australian Privacy Principles: each operates under enforceable contractual data protection safeguards, and data held in the EU is additionally protected by the General Data Protection Regulation (GDPR), a privacy regime that protects personal information in a way substantially similar to the APPs. Your express consent to this handling is also captured by tick box when you accept our Terms & Conditions at the time of requesting a screen.
Section 5: Disclosure to third parties, MHR, and mandatory reporting
We only share your information with the medical professionals and Prickly personnel actively involved in delivering your care, or where strictly required under Australian statutory obligations.
- Fulfilment staff: A Prickly team member packs and dispatches your collection equipment and sees your name, delivery address, and the contents of your mailer box, including the pathology request form. They hold a current Nationally Coordinated Criminal History Check (police check), have signed a confidentiality and privacy agreement, are trained in the Australian Privacy Principles, and have no access to your questionnaire answers, clinical notes, or results.
- Delivery and logistics partner: Your name, address, email address, and phone number are shared with Australia Post to facilitate the delivery of your specimen collection equipment and the return of your laboratory samples. Australia Post is an independent postal service provider and is independently bound by the Privacy Act 1988 (Cth) and relevant regulations.
- Pathology partner: Necessary demographic and clinical data is transferred to our partner pathology laboratory (4Cyte Pathology) via an industry-standard hardcopy referral form to allow your samples to be processed. This independent pathology laboratory is entirely separate from Prickly Health and is independently bound by the Privacy Act 1988 (Cth) and relevant regulations.
- Prescription home delivery: If your synchronous telehealth consultation results in a prescription and you explicitly request home delivery of your medication, we will securely transfer necessary demographic and clinical data to Chemist2U, an independent pharmacy delivery service whose partner pharmacies dispense and deliver your medication at your explicit direction. Chemist2U and the dispensing pharmacy are entirely separate from Prickly Health and are independently bound by the Privacy Act 1988 (Cth) and relevant regulations. You may instead have your electronic prescription dispensed at any pharmacy of your choice.
- My Health Record (MHR): Prickly does not directly upload any of your consultation notes or referral data to the federal My Health Record (MHR) system. Please note that our partner pathology laboratory defaults to uploading your test results to MHR as part of their standard practice. However, to put this choice in your hands, we provide a prominent option within our initial clinical questionnaire to opt out of having your results uploaded to MHR by the lab; we pass that instruction to the laboratory, which applies it as an independent entity.
- Your regular GP: We will not disclose your screening details or results to your regular GP unless you provide explicit, written consent.
- Authorised representatives & emergencies: We will only collect information from, or disclose information to, a third party acting on your behalf (such as a legal guardian, next of kin, or medical power of attorney) if they provide verified legal authorisation to do so, or where legally permitted under emergency health provisions to prevent a serious threat to life, health, or safety.
- Mandatory notifiable diseases: Under Australian public health laws, laboratories and clinicians are legally required to report positive cases of specific notifiable STIs (such as chlamydia and gonorrhoea) to state or territory health departments. These notifications are handled securely and are frequently partially de-identified. For self-test interventions requiring subsequent clinical referral (such as HIV), mandatory reporting is handled by the downstream practitioner ordering your formal confirmatory diagnostic testing.
- Legal compulsion: We may disclose your personal information if compelled by law, such as in response to a valid court subpoena, warrant, or statutory order.
Section 6: Communications, secure delivery, and Spam Act compliance
We handle clinical communications with maximum discretion to protect your privacy from onlookers.
- Results delivery: You will receive an email notification when your results are ready.
- Negative results: The email will explicitly state that your results are negative, so you are not left reading meaning into a neutral notification. A negative result reflects the samples tested; standard window periods still apply.
- Positive or indeterminate results: The email will contain neutral language stating only that a "result requires follow-up" and will provide directions on next steps. Specific diagnoses are intentionally omitted from the email body to prevent accidental privacy breaches if your device notifications are visible to third parties.
- Secure document delivery: For security, detailed treatment summary letters, clinical referrals, or practitioner-to-GP communications regarding positive results are never sent via standard email. They are shared exclusively via secure, two-factor authenticated (2FA) document download links generated by Halaxy.
- Routine clinical reminders: Because regular screening is an important part of sexual health management, Halaxy will automatically generate a single email reminder three months after your request to prompt you to consider whether your next screen is due. Three months is the shortest re-screening interval recommended by the Australian STI Management Guidelines – advised for higher-risk groups, with approximately annual screening suggested for many other sexually active adults; the right interval for you depends on your risk profile and your doctor’s advice. This is a single, factual clinical reminder generated as part of your care under the Spam Act 2003 (Cth), and is not classified as direct marketing.
- No direct marketing: Prickly will never use your sensitive health information for direct marketing, nor will we send you promotional materials.
Section 7: Data retention and statutory obligations
Under Australian medical record retention laws and state-based health records legislation, health service providers are legally obligated to retain clinical files for strict statutory periods. We cannot delete permanent clinical records from Halaxy upon patient request prior to the expiration of these periods:
- Adult records: Records for individuals aged 18 years or older must be retained for a minimum of 7 years from the date of the last clinical interaction.
- Minor records: For patients who access our service under the age of 18, records must be retained until the patient reaches 25 years of age, or for 7 years from the date of the last clinical interaction – whichever time period is longer.
Once the applicable retention period has expired, records that are no longer required are securely destroyed or permanently de-identified in accordance with APP 11.2.
Section 8: Age restrictions, identity verification, fraud mitigation, and account security
Prickly strictly provides services to individuals aged 16 years and over.
- Identity integrity & fraud: Providing false identification, acting as an unauthorised proxy, or utilising another individual's identity or healthcare identifiers compromises the integrity of the national health record system, creates severe cross-contamination risks for innocent third-party records, and constitutes a critical clinical hazard. Prickly reserves the right to immediately terminate services, cancel all pending pathology requests, and permanently isolate or flag the clinical file if we discover or have reasonable grounds to suspect that identity fraud has occurred. Where electronic verification is inconclusive, or where we have reasonable grounds to suspect identity fraud or a proxy registration, we may require you to securely upload photographic identity documentation before your request proceeds. If you decline, we cannot safely provide the Service.
- Authorised vs unauthorised proxies: You may only complete a questionnaire or submit personal information on behalf of another person if you are a legally recognised guardian or hold a verified medical power of attorney. Submitting health histories for a partner, family member, or friend without explicit, documented legal authority is strictly prohibited.
- Account security and shared devices: If you create a secure account or access portal through our platform, you are entirely responsible for maintaining the confidentiality of your login credentials. You must not share your access links, two-factor authentication tokens, or passwords with anyone. Because sexual health data is uniquely sensitive, we strongly advise against saving login credentials on shared family devices or public computers. Except as required by law, we are not responsible for unauthorised access to your account arising from a failure to keep your own login credentials, access links, or authentication tokens secure.
Section 9: Website analytics and data minimisation
When you interact with our website, we prioritise your privacy through strict data minimisation principles. We do not use third-party advertising pixels or tracking tools that link your digital journey to your clinical identity.
- No tracking cookies: We set no cookies for tracking, analytics, or advertising. Our hosting infrastructure (Cloudflare) may set strictly necessary security cookies to protect the site from malicious traffic; these identify no personal or clinical information. Our website does use your browser's local and session storage for small functional purposes only – such as rotating the homepage photography between visits and carrying your eligibility-check answers into our booking flow. This information stays on your device, is never used for tracking, and is not transmitted to our servers. When you open the eligibility check, your browser asks our hosting infrastructure (Cloudflare) which country your connection appears to be from, so the check can remind you to answer for where you are right now; that answer is used once, on your device, and is neither stored nor sent to us.
- General performance analytics: We may track standard, aggregated, de-identified technical metrics (e.g., page views, session duration, device types) via privacy-focused cloud analytics infrastructure to manage website traffic and optimise server performance. No personal or clinical information is shared with or processed by third-party advertising networks.
- Communication tracking: Through Halaxy, we securely monitor the delivery status of our emails to ensure you have successfully received vital clinical communications.
Section 10: Access, correction, and data quality (APP 12 & 13)
You have a legal right to request access to your personal and health information, or to request corrections if you believe the data we hold is inaccurate, incomplete, or out of date under APP 12 and 13.
- How to request: Please contact our designated Privacy Officer at hello@prickly.com.au.
- Verification: We will require you to verify your identity using standard identity documentation before releasing or correcting any information.
- How records are provided: You are entitled to direct access to your own records, and we will provide them to you on request in accordance with APP 12. To support continuous, safe care, we can also – if you prefer – securely transfer your complete records directly to your nominated healthcare practitioner; this is offered as an option, never imposed as a condition of access.
- Fees: We do not charge administrative fees for processing access or correction requests.
Section 11: Complaints and data breaches (APP 1 & NDB scheme)
If you believe we have breached the Australian Privacy Principles, the Privacy Act 1988 (Cth), or mishandled your health records, you have the right to lodge a formal complaint.
- Internal resolution: Please direct your complaint in writing to hello@prickly.com.au. We commit to investigating and responding to your complaint within 30 days.
- Notifiable data breaches (NDB) scheme: Prickly complies fully with the federal NDB scheme under Part IIIC of the Privacy Act 1988 (Cth). In the unlikely event of a data breach that is likely to result in serious harm, we are legally committed to promptly containing the breach, assessing the risk, and notifying both you and the Office of the Australian Information Commissioner (OAIC), outlining the steps we have taken to secure your data and the actions you should take.
- External escalation: If you are unsatisfied with our internal response, you may escalate your complaint to the federal regulator:
Office of the Australian Information Commissioner (OAIC)
GPO Box 5288, Sydney NSW 2001
www.oaic.gov.au (opens in new tab)
Section 12: Changes to this policy
We may update this Privacy Policy periodically to reflect changes in our clinical operations, digital infrastructure, or Australian privacy legislation. The updated policy will be published on our website, and the "Last updated" date at the top of this document will be amended accordingly.