Legal information
Privacy Policy
How North of Why collects, uses, stores and shares personal and health information.
Last updated: September 2026
North of Why respects your privacy. This policy explains how we collect, use, store and share personal and health information.
North of Why is the registered business name of Trisha Evers, ABN 23 724 194 652. We handle information under the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Health Records Act 2001 (Vic) and relevant professional obligations.
What information do we collect?
What we collect depends on the service you are seeking and may include:
- Your name, date of birth and contact details.
- Appointment, referral, Medicare, insurance and payment information.
- Information about your health, wellbeing, history and circumstances relevant to the service.
- Clinical records, including notes, assessments, correspondence and reports.
- Information from a GP, another health practitioner or another person involved in your care.
- Professional information relevant to consultation, training or other services.
For parenting or family support, this may include relevant information about a child or family member. We collect only what is reasonably necessary to provide the requested service and meet legal and professional responsibilities.
How do we collect it?
We usually collect information directly from you by phone, email, forms and during appointments. With your consent, or where law permits, we may receive it from your GP, another health practitioner, a family member, referrer, insurer or funder.
At launch, the website has no online enquiry form, analytics or advertising trackers and does not collect clinical information. The website host may collect technical data, such as an IP address, browser type and pages visited, to operate and secure the site.
Why do we collect and use it?
We may use your information to:
- Respond to enquiries and assess whether the service is suitable for your needs.
- Provide and manage services, records, communications and appointments.
- Process accounts, Medicare claims and payments.
- Coordinate with other professionals or services, with your consent.
- Meet legal, ethical, insurance and professional requirements and maintain the safety and quality of services.
You may choose not to provide requested information. However, this may mean that we cannot provide a safe, appropriate or effective service.
When may we share it?
Personal and health information is confidential. We ordinarily share it only with your consent.
Limited information may be shared with providers that support the practice, including practice-management, telehealth, secure messaging, website hosting, information technology, payment, accounting and communication providers. Trish also participates in professional supervision and consultation; information used for this purpose is limited and de-identified wherever reasonably possible.
Without consent, information may be disclosed when the disclosure:
- Is required or authorised by law, including a court order, subpoena or mandatory reporting obligation.
- Is reasonably necessary to lessen or prevent a serious threat to a person’s life, health or safety.
- Is otherwise permitted under privacy or health-records law.
Where possible and appropriate, we will discuss the disclosure with you.
Is information handled outside Australia?
We use providers for email, website hosting, practice management, telehealth and secure messaging, and may add payment and accounting providers. Some information may be stored, disclosed or accessed outside Australia, including in the United States. We identify other countries where practicable and take reasonable steps to ensure providers handle personal information consistently with Australian privacy requirements.
How do we store and protect it?
Information may be held in secure electronic systems and, where needed, physical files. Reasonable safeguards include access controls, password protection, multi-factor authentication where available and secure disposal. Access is limited to people who need the information for an authorised role.
If a data breach occurs, we will promptly contain and assess it and notify affected people and relevant authorities where required.
How long do we keep it?
Health records are generally kept for at least seven years after the last health service. If your information was first collected while you were under 18, it is kept until you are at least 25 or for at least seven years after your last health service, whichever is later. Records may be kept longer where law or professional obligations require or permit.
When information is no longer needed and no law requires its retention, it is securely destroyed or permanently de-identified.
How can you access or correct it?
You may request access to your information or correction of inaccurate, incomplete or out-of-date information using the details below. We may ask you to verify your identity.
We will respond as soon as reasonably practicable and within legal timeframes. Access or correction may be limited or refused where law permits; if so, we will provide reasons and complaint options where required.
What if you have a privacy concern?
Please contact us if you have a question or concern about how your information has been handled. We will treat it respectfully and confidentially and aim to respond within 30 days.
If you are not satisfied with the response, you may contact:
- Office of the Australian Information Commissioner on 1300 363 992.
- Health Complaints Commissioner Victoria on 1300 582 113.
Contact
Privacy contact: Dr Trish Evers
Email: contact@northofwhy.com
Telephone: 0451 442 687
Postal address: PO Box 626 Berwick VIC 3806