Privacy Policy

Facial Harmony Skin & Dental

Version 1.2  |  Last updated 17 September 2026

Facial Harmony Skin & Dental respects the privacy of every patient, website visitor and person who contacts us. This policy explains the personal and health information we collect and hold, why we use it, when we disclose it, and how you can access or correct it or make a complaint.

We handle information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Health Records Act 2001 (Vic) and other laws that apply to our services. A collection notice on a form or at the point of collection may provide more specific information about a particular use of your information.

This policy applies to information handled through our dental, skin and cosmetic aesthetic services, our clinic, our website at facialharmony.au, online forms and booking services, patient communications, website accounts and related business activities.

Who we are and how to contact us

Facial Harmony Skin & Dental provides dental, skin and cosmetic aesthetic services from 3/1A Carrington Road, Box Hill VIC 3128. In this policy, Facial Harmony Skin & Dental is referred to as we, us or our.

Questions, access or correction requests, and privacy complaints may be directed to:

Privacy Officer: Dr NaMoo Park or delegated representative
Email: info@facialharmony.au
Phone: 03 8899 6497
Address: 3/1A Carrington Road, Box Hill VIC 3128

You may make a general enquiry anonymously or using a pseudonym where this is lawful and practicable. We usually need your correct identity and relevant health information before we can safely provide healthcare, maintain an accurate clinical record, process claims or meet legal obligations.

Information we collect and hold

The information we collect depends on how you interact with us. It may include:

  • identity and contact details, including your name, preferred name, date of birth, address, telephone number and email address
  • information about a parent, guardian, carer, authorised representative or emergency contact
  • health fund, Medicare, Child Dental Benefits Schedule, Department of Veterans Affairs and other claiming information where applicable
  • medical, dental and treatment history, allergies, medicines, symptoms, diagnoses and other health information relevant to safe care
  • clinical records, consent records, treatment plans, referrals, prescriptions, X-rays, scans, test results and clinical photographs
  • appointment details, correspondence, messages, preferences and feedback
  • billing, transaction and account information; we do not intentionally retain full payment card details
  • website account, enquiry, booking, form, purchase or subscription information
  • technical and usage information such as IP address, browser and device information, cookie identifiers, pages viewed and website interactions
  • security camera footage from common areas of the clinic
  • information needed to respond to a complaint, legal matter, insurance matter or regulatory request.

Health information is sensitive information. We collect it with your consent where consent is required, or where another legal basis permits or requires collection. We do not ask for information unrelated to our functions or services.

How we collect information

We usually collect information directly from you when you:

  • complete a patient, consent, medical history, website or enquiry form
  • book, attend or receive a consultation or treatment
  • communicate with us by telephone, email, text message, website, social media or in person
  • create a website account, make a purchase or subscribe to communications
  • use our website or interact with cookies, analytics and similar technologies.

Where permitted, we may also collect relevant information from a parent, guardian or authorised representative; your referring or treating practitioners; hospitals, pharmacies, laboratories or imaging providers; health funds, Medicare, government claiming services, insurers or payment providers; our practice systems and service providers; and lawful public sources or authorities.

If we receive personal information that we did not request, we will decide whether we could lawfully have collected it. If not, and if we are not required to retain it, we will securely destroy or de-identify it where lawful and reasonable.

If you provide information about another person, you should have authority to do so and should tell that person where it is reasonable to do so.

Why we use information

We collect, hold, use and disclose information to:

  • assess your health, suitability and treatment needs and provide safe and appropriate care
  • prepare treatment plans, obtain informed consent, monitor progress and maintain a complete clinical record
  • coordinate care with your treating team and other healthcare providers
  • manage appointments, recalls, referrals, enquiries and patient communications
  • process accounts, payments, refunds, health fund claims and applicable government claims
  • manage our website, online accounts, forms, bookings and security
  • respond to feedback, complaints, incidents, legal claims and regulatory requirements
  • maintain quality, train our team, conduct internal audits and improve services, using de-identified information where reasonably practicable
  • protect patients, staff, visitors and property and prevent or investigate suspected unlawful activity
  • meet professional, insurance, tax, record-keeping, public health and other legal obligations.

If you do not provide information that is reasonably necessary for your care or a requested service, we may need further information, may be unable to process a booking or claim, or may be unable to provide some services safely.

We do not generally use automated systems to make clinical decisions that significantly affect a patient. Clinical decisions are made by appropriately qualified practitioners.

When we disclose information

We disclose information only where it is reasonably necessary for the purpose for which it was collected, for a related purpose you would reasonably expect, with consent, or where permitted or required by law. Recipients may include:

  • practitioners and authorised team members involved in your care
  • GPs, dentists, specialists, hospitals, pharmacies, pathology or imaging providers, and other healthcare providers
  • dental laboratories and suppliers that prepare patient-specific products or support treatment
  • practice management, booking, clinical imaging, communications, IT, cloud storage, cybersecurity and website service providers
  • payment processors, HICAPS, health funds, Medicare, the Department of Veterans Affairs and other claiming or funding bodies where applicable
  • professional advisers, insurers, auditors, accreditation bodies, regulators, law enforcement bodies, courts or tribunals where lawful and necessary
  • a purchaser or successor operator if the practice is sold, transferred or closed, subject to applicable notice and health-record requirements.

Where practicable, we share only the information needed for the relevant purpose and use secure clinical or business communication channels. We do not sell patient information.

We may use or disclose information without consent where a law permits or requires it, including to lessen or prevent a serious threat to life, health or safety, respond to certain suspected unlawful activity, or establish or defend a legal claim.

Clinical photographs and imaging

Clinical photographs, X-rays and scans taken as part of a consultation or treatment are health records. We use them for assessment, diagnosis, treatment planning, informed discussion, monitoring progress, communication with other providers where appropriate and maintenance of your clinical record.

They are stored in authorised clinical or imaging systems, accessible only to people who need access for their role, and retained with the health record. They are not used for advertising, social media, testimonials, public education or other promotional purposes without separate explicit written consent.

Consent to promotional or educational use is optional and separate from consent to care. You may withdraw that optional consent for future use. Withdrawal does not require us to delete an image that forms part of your clinical record and may not reverse a lawful use that occurred before withdrawal.

Marketing communications

We may send information about services, practice news or offers where you have asked to receive it or where otherwise permitted by law. Marketing permission is separate from consent to treatment, and declining marketing does not affect your care.

We do not use health information for direct marketing unless you have expressly consented. You can opt out using the unsubscribe option in a message or by contacting us. We may retain a suppression record so we can respect your request. Appointment reminders, recalls, treatment communications and important service notices are not marketing and may continue where relevant to your care or account.

Website cookies analytics and online services

Our website may collect technical information through cookies, tags, pixels, logs and similar technologies. This may include your IP address, device and browser type, approximate location, pages viewed, referring page, session information and interactions with website features.

We may use these technologies to operate essential website, account, security, form and booking functions; remember preferences; improve performance; understand website use; measure campaigns; and show or measure relevant advertising where permitted.

The website uses Google Tag Manager to manage website tags. Active tags may include analytics or advertising services. Non-essential technologies may be controlled through our cookie settings where available, and you can restrict cookies through your browser. Blocking some cookies may affect website functions.

If you submit a website form, create an account, make a purchase, post a comment or upload content through a feature we provide, we collect the information and technical metadata submitted with that activity.

Our website may link to or embed booking tools, maps, video, social media, payment services and other third-party content. Those providers may collect information under their own privacy and cookie policies. We are not responsible for the privacy practices of an external website merely because we link to it.

Cloud services and overseas disclosures

We use service providers to operate our practice, communicate with patients, store records and run our website. Principal systems include Zavy360 for dental practice management, Timely for skin practice management and booking, Clinical Imaging Australia and Microsoft OneDrive for clinical photography, Google and Microsoft services for communications and collaboration, HICAPS and payment or claiming providers, and website hosting, security, analytics and tag services.

Some providers use related companies, support teams or subcontractors outside Australia. Based on our current arrangements, overseas recipients are likely to be located in New Zealand and the United States. Provider support or subcontractor arrangements may involve additional countries identified in their current privacy or subprocessor information.

Before disclosing personal information overseas, we take reasonable steps required by applicable privacy law to ensure the recipient handles it consistently with the Australian Privacy Principles, unless an exception applies. We also take reasonable steps to safeguard health information transferred outside Victoria.

Hosting, support and subcontractor arrangements can change. We review this section when our systems or provider arrangements change.

How we protect information

We take reasonable technical, physical and organisational steps to protect information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures include role-based access, password controls, multi-factor authentication for key systems, secure configuration, encryption where appropriate, staff confidentiality, secure disposal and vendor review. Access is limited to people who need the information for their role.

Security cameras

Security cameras operate in common areas of the clinic, including reception and waiting areas, for safety and security. Cameras are not installed in treatment rooms or other areas where a person would reasonably expect privacy. Footage is normally retained for 30 days unless required for an incident, investigation, insurance matter or legal obligation.

Data breaches

No storage or transmission method is completely secure. If a suspected data breach occurs, we will contain and assess it and take remedial action. Where the Notifiable Data Breaches scheme applies and an eligible data breach is identified, we will notify affected individuals and the Office of the Australian Information Commissioner as required.

How long we retain information

We retain information for as long as it is needed for the purpose for which it was collected and for applicable clinical, legal, insurance and business requirements.

  • Health records are generally kept for at least seven years after the last occasion on which we provided a health service to the individual.
  • If the individual was under 18 when we last provided a health service, the record is generally kept until the individual reaches 25 years of age.
  • Clinical photographs, X-rays and scans forming part of the health record are retained for the same applicable period.
  • Security camera footage is normally kept for 30 days unless required for a specific incident or legal purpose.
  • Financial, complaint, insurance, website and business records are retained for the period reasonably required by law and our legitimate operational needs.

When information is no longer required and lawful retention periods have ended, we take reasonable steps to securely destroy or permanently de-identify it. A deletion request does not override a legal or professional obligation to retain a health or business record.

Accessing or correcting your information

You may request access to personal or health information we hold about you and ask us to correct information that is inaccurate, incomplete, out of date, irrelevant or misleading. You may also ask us to make your health information available to another health service provider.

Contact our Privacy Officer and describe the information or correction requested. We may ask you to verify your identity and, where a request is made for another person, provide evidence of authority. There is no charge to lodge a request. We may charge a reasonable fee permitted by law for providing access, and we will explain any fee before proceeding.

We will respond within the period required by law. Access may be refused or limited in circumstances permitted by law. If we refuse access or correction, we will ordinarily give written reasons and explain available complaint options.

Clinical records must preserve an accurate history. We do not generally erase or overwrite an earlier entry. Where a correction is appropriate, we may add corrected information, retain an audit trail or attach a statement to the record.

Making a privacy complaint

If you are concerned about how we handled your information, contact our Privacy Officer using the details above. Explain what happened and the outcome you are seeking. We will acknowledge and investigate the complaint, keep you informed where appropriate and aim to provide a written response within 30 days.

If you are not satisfied with our response, you may contact:

Health Complaints Commissioner Victoria for complaints about a Victorian health service or the handling of health information. Website: hcc.vic.gov.au | Phone: 1300 582 113

Office of the Australian Information Commissioner for complaints under the Privacy Act or Australian Privacy Principles. Website: oaic.gov.au | Phone: 1300 363 992

Changes to this policy

We review this policy regularly and may update it when our services, systems, provider arrangements or legal obligations change. The current version will be available on our website and from the clinic on request. The date at the beginning shows when it was last updated. If a change materially affects how we handle information already collected, we will take reasonable steps to notify affected individuals where appropriate.