Privacy Policy

ANNEX HEALTH PRIVACY POLICY

Effective date: November 11, 2025
Version: 1

1. Purpose

Annex Health respects the privacy of its clients and other individuals whose personal information it handles.

This Privacy Policy explains how Annex Health collects, holds, uses and discloses personal information, including health information. It also explains how individuals may access or correct their information and make a privacy complaint.

2. About Annex Health

Annex Health is operated by Freya Clayhills, an Accredited Exercise Physiologist and sole trader.

Annex Health
ABN 65 974 149 706
Suite 108, 1 Erskineville Road
Newtown NSW 2042
Australia
Email: annexhealth@outlook.com
Telephone: 0422 438 142
Website: https://www.annexhealth.com.au/

Annex Health provides face-to-face services in Sydney and telehealth services throughout Australia.

3. Privacy laws

Annex Health is a health service provider and handles health information. Its privacy obligations may include obligations under:

  • the Privacy Act 1988 (Cth) and Australian Privacy Principles;

  • the Health Records and Information Privacy Act 2002 (NSW) and Health Privacy Principles;

  • applicable health records, surveillance, professional and mandatory reporting laws; and

  • professional standards and requirements applying to Accredited Exercise Physiologists.

Where different privacy laws apply, Annex Health will seek to comply with the requirements applicable to the relevant information and service.

4. Personal information collected

“Personal information” means information or an opinion about an identified individual or an individual who is reasonably identifiable.

“Health information” is sensitive information concerning an individual’s health, disability, health services or other matters recognised as health information under applicable privacy legislation.

Annex Health may collect:

4.1 Identity and contact information

  • name;

  • date of birth;

  • address;

  • email address and telephone number;

  • emergency contact details;

  • identity verification information; and

  • parent, guardian, nominee or authorised representative details.

4.2 Health and clinical information

  • diagnosed conditions and conditions under investigation;

  • medical and family history;

  • previous surgery, hospitalisation, injury and significant illness;

  • medication and supplement information;

  • allergies and adverse reactions;

  • symptoms and symptom patterns;

  • disability and functional information;

  • sleep, stress, mood, nutrition and lifestyle information;

  • exercise, movement and physical activity information;

  • work and occupational information;

  • goals and preferences;

  • exercise, movement and physical capacity assessment results;

  • strength, cardiovascular fitness and functional testing results;

  • body composition and DEXA results;

  • pathology or blood results supplied by the client;

  • wearable device information;

  • consultation records and clinical notes;

  • exercise prescriptions and program information;

  • questionnaires and outcome measures;

  • medical clearances, referrals and reports; and

  • communications with the client and authorised members of the client’s treating team.

4.3 Administrative and technical information

Annex Health may also collect:

  • appointment and booking information;

  • invoices, payment status and transaction information;

  • correspondence, feedback and complaints;

  • website enquiry information;

  • IP address, browser, device and website usage information;

  • cookie and analytics information; and

  • consent records and communication preferences.

Annex Health does not ordinarily retain complete payment card details. Payment information may be processed by an external payment provider.

5. How information is collected

Annex Health may collect information:

  • directly from a client through forms, questionnaires, consultations, assessments, email, telephone or telehealth;

  • from a parent, guardian, substitute decision-maker or authorised representative;

  • from a referring or treating health practitioner where authorised or otherwise permitted by law;

  • from wearable devices or platforms connected or made available by the client;

  • from reports and records supplied by a client;

  • from DEXA, pathology, imaging or other testing providers;

  • through the Annex Health website, booking systems and practice-management systems;

  • through exercise delivery and communication platforms; and

  • through audio recording, transcription or Ai-assisted systems, but only where the necessary notice and consent have been provided.

Where reasonable and practicable, Annex Health will collect personal information directly from the individual concerned.

6. Why Annex Health collects and uses information

Annex Health may collect, use and disclose personal information to:

  • assess whether its services are appropriate for a client;

  • provide exercise physiology services;

  • assess movement, exercise tolerance and physical capacity;

  • prepare and monitor exercise programs;

  • monitor symptoms, activity, sleep and recovery patterns;

  • communicate with the client and authorised healthcare providers;

  • seek medical clearance or coordinate care;

  • manage appointments, payments and administration;

  • maintain clinical and business records;

  • manage health, safety, risk and emergencies;

  • comply with legal, regulatory, insurance and professional obligations;

  • respond to complaints, disputes or legal claims;

  • improve service quality and program delivery;

  • send service communications and, with any consent required by law, marketing communications;

  • produce aggregated or de-identified service statistics;

  • conduct consented recording, transcription or Ai-assisted processing; and

  • undertake research only where the relevant legal, ethical and consent requirements have been met.

7. Consequences of not providing information

Clients are not required to provide all information requested. However, if relevant information is withheld, Annex Health may be unable to:

  • determine whether its services are appropriate or safe;

  • provide an accurate or appropriately tailored program;

  • coordinate care with other practitioners;

  • process an appointment or payment; or

  • continue providing services.

8. Wearable and connected-health information

With the client’s agreement, Annex Health may review information from platforms or devices such as Apple Health, WHOOP, Oura, Fitbit and Garmin.

Depending on the device and permissions selected, this may include activity, exercise, heart rate, sleep, recovery and related information.

Clients are responsible for:

  • checking the permissions granted to the relevant platform;

  • reviewing the platform provider’s privacy policy;

  • maintaining the security of their accounts and devices; and

  • disconnecting access if they no longer wish to provide data.

Wearable information may be incomplete, delayed or inaccurate. It is used as supplementary information and is not treated as a substitute for clinical assessment or medical investigation.

9. Ai-assisted systems and transcription

Subject to the client’s separate consent where required, Annex Health may use Ai-assisted tools for:

  • transcribing consultations;

  • preparing draft consultation notes;

  • summarising information;

  • assisting with reports;

  • organising client information;

  • identifying patterns in symptom, activity or wearable information; and

  • preparing exercise or program documentation.

Ai outputs may contain errors or omit relevant context. Ai does not independently diagnose clients or make final clinical decisions. Relevant outputs are reviewed by Freya Clayhills before being relied on for clinical purposes.

Annex Health will not intentionally use identifiable client information to train a public or general-purpose Ai model. Annex Health will seek to use providers offering appropriate confidentiality, security and data-handling controls.

A client may decline optional recording, transcription or Ai processing without losing access to the underlying service, although Annex Health may use non-Ai administrative and clinical systems required to deliver and document care.

10. Disclosure of information

Annex Health may disclose relevant personal information to:

  • the client’s GP, specialist or other treating practitioner, with authority or where otherwise permitted by law;

  • hospitals, ambulance services or emergency contacts where necessary to address a serious health or safety risk;

  • DEXA clinics, pathology providers, dietitians and other external service providers;

  • practice-management, booking, telehealth, exercise prescription, email, payment, cloud storage, transcription and technology providers;

  • professional advisers, insurers, auditors and contractors bound by confidentiality obligations;

  • government agencies, regulators, courts or law-enforcement bodies where required or authorised by law;

  • a purchaser or successor in connection with a proposed sale or transfer of the business, subject to appropriate confidentiality and privacy safeguards; and

  • other persons where the client has consented.

Annex Health does not sell identifiable client health information.

11. Current and anticipated service providers

Providers may include:

  • HealthBank — practice management, forms, questionnaires and health records;

  • Physitrack — exercise prescription and program delivery;

  • Acuity Scheduling — online booking;

  • Squarespace — website hosting and website functions;

  • Microsoft Outlook — email;

  • Fireflies.ai — consultation recording, transcription or summarisation, where separately consented;

  • Payment Provider — payment processing via direct bank transfer;

  • wearable platforms selected by the client; and

  • external clinical and testing providers involved in the client’s care.

Providers may change from time to time. Annex Health will take reasonable steps to select reputable providers and configure systems consistently with its privacy obligations.

12. Overseas disclosure and cloud processing

Some technology providers may store, access or process information outside Australia. Relevant countries may include Fireflies & Squarespace = United States, Physitrack = Physitrack acknowledges that Australian client data may be transferred overseas. The specific countries applicable to your account and its subprocessors require confirmation, Healthbank = HealthBank's published privacy policy states that it does not ordinarily disclose personal information to overseas recipients, except in specified circumstances. However, its clinical data hosting and support locations require direct confirmation.

Before disclosing personal information overseas, Annex Health will take reasonable steps required by applicable law. However, overseas recipients may be subject to different privacy laws and government-access regimes.

Where express consent is relied upon for a particular overseas disclosure, Annex Health will provide sufficient information for that consent to be informed.

13. Direct marketing

Annex Health may send information about services, programs or resources where:

  • the recipient has consented;

  • the communication is otherwise permitted by law; and

  • a functional unsubscribe facility is provided where required.

Clinical and appointment communications are not direct marketing. A person may unsubscribe from marketing without affecting essential service communications.

14. De-identified and aggregated information

Annex Health may create information that has been aggregated or de-identified so that individuals are not reasonably identifiable.

Subject to applicable law and the relevant client consent, Annex Health may use such information for:

  • internal service evaluation;

  • quality improvement;

  • program development;

  • outcome reporting;

  • professional education;

  • marketing statistics; or

  • approved pilot or research activities.

Annex Health will assess re-identification risk having regard to the dataset, small participant groups, rare conditions and the information proposed for publication.

Research use is governed by additional consent and, where applicable, ethics review and research governance requirements.

15. Photographs, recordings and testimonials

Annex Health will obtain separate permission before publishing an identifiable client:

  • photograph;

  • audio or video recording;

  • testimonial;

  • case study; or

  • clinical story.

Consent to clinical services does not constitute consent to promotional use.

16. Security

Annex Health takes reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include:

  • password protection and multi-factor authentication;

  • access controls;

  • reputable cloud and clinical platforms;

  • secure device configuration;

  • staff and contractor confidentiality requirements;

  • backups and software updates;

  • secure disposal practices; and

  • data-breach response procedures.

No electronic transmission or storage system can be guaranteed to be completely secure.

Clients should avoid sending highly sensitive information through unsecured communication channels where a secure alternative is available.

17. Data retention and destruction

Annex Health retains clinical and business records for the period required by law, professional standards, insurance requirements and legitimate business needs.

As a general risk-management measure, adult health records may be retained for at least seven years after the last service. Records concerning a child may need to be retained until the individual reaches 25 years of age or for another period required by applicable law.

When information is no longer required, Annex Health will take reasonable steps to destroy it securely or permanently de-identify it, unless retention is required or permitted by law.

18. Access and correction

An individual may request access to personal information held about them or ask for it to be corrected.

Requests should be sent to annexhealth@outlook.com. Annex Health may:

  • verify the requester’s identity;

  • ask that the request be made in writing;

  • charge a reasonable administrative fee where permitted; and

  • refuse access in circumstances permitted by law.

If a request is refused, Annex Health will generally provide written reasons and available complaint options.

19. Data breaches

Annex Health maintains procedures for responding to suspected privacy and data-security incidents.

Where an incident is likely to result in serious harm, Annex Health will assess whether notification is required under the Notifiable Data Breaches scheme or other applicable law and will make notifications where required.

20. Complaints

Privacy complaints may be submitted to:

Privacy Officer
Annex Health
Suite 108, 1 Erskineville Road
Newtown NSW 2042
Australia
Email: annexhealth@outlook.com
Telephone: 0422 438 142

The complaint should describe the issue and the outcome sought. Annex Health will acknowledge and investigate the complaint within a reasonable period.

If the complaint is not resolved, the individual may contact:

  • the Office of the Australian Information Commissioner; or

  • the NSW Privacy Commissioner, where the NSW health privacy legislation applies.

21. Changes to this policy

Annex Health may amend this Privacy Policy from time to time. The current version will be published on its website with its effective date.