Privacy Policy
How Cognovo Pty Ltd collects, uses, discloses, stores and protects personal information, including health information, under the Privacy Act 1988 (Cth).
Effective date: [17th August 2026] · Version: 1.0 · Last reviewed: [17th August 2026]
This policy applies to Cognovo Pty Ltd (ABN [76 698 095 475]) and to this website. Where we handle information on behalf of a client under a contract, that client's own privacy policy and any applicable state or territory health privacy law may also apply. See section 4.
1. About this policy
Cognovo Pty Ltd (Cognovo, we, us, our) is an Australian mental health informatics company providing software development and service evaluation services. We take the privacy of personal information seriously. It is central to the work we do.
This policy explains how we handle personal information, as that term is defined in the Privacy Act 1988 (Cth) (the Privacy Act), in accordance with the Australian Privacy Principles (APPs) in Schedule 1 to that Act.
Because our work involves health information, we treat ourselves as bound by the Privacy Act and the APPs regardless of our annual turnover, and we apply the Act's heightened protections for sensitive information (which includes health information) across our operations.
This policy covers information we collect through this website, through our business dealings, and in the course of delivering services. Section 4 deals specifically with data we handle on behalf of client organisations.
2. Information we collect
2.1 Business and website contacts
For people who contact us, work with us, or engage our services, we may collect:
- name, job title and the organisation you work for;
- contact details, including email address, phone number and postal address;
- the content of your enquiry and our correspondence with you;
- records of meetings, proposals, contracts and project documentation;
- billing and payment details for client organisations;
- technical information collected automatically when you visit this website (see section 10).
2.2 Research and evaluation participants
When we conduct a service evaluation, we may collect information from staff, service providers and, where the evaluation design requires it and proper approvals are in place, people who use mental health services. This can include survey responses, interview or focus group transcripts, demographic details, and outcome measure data.
Participation in evaluation activities is voluntary. Before collecting information directly from participants we provide a specific participant information statement explaining the purpose, what will be collected, how it will be used and stored, and how to withdraw. Where an evaluation constitutes research involving human participants, we seek approval from an appropriate Human Research Ethics Committee.
2.3 Sensitive information
Sensitive information, including health information and information about racial or ethnic origin, sexual orientation, religious beliefs or criminal record, attracts additional protection under the Privacy Act. We collect sensitive information only where:
- it is reasonably necessary for a function or activity we carry out; and
- you have consented, or another exception under the Privacy Act applies (for example, where collection is required or authorised by law, or is carried out under the guidelines issued under section 95A of the Act for health research).
2.4 Job applicants
If you apply to work with us we collect the information in your application: contact details, work history, qualifications, referee comments, and the results of any checks we tell you about in advance. We use it only to assess your application and, if you are successful, to engage you.
3. How we collect it
Wherever it is reasonable and practicable, we collect personal information directly from you, for example when you:
- complete the enquiry form on this website, email us or call us;
- engage us, or work for an organisation that engages us;
- take part in an evaluation interview, workshop or survey;
- subscribe to updates, or attend an event or presentation we deliver;
- apply for a role with us.
We may also collect information from third parties, including:
- a client organisation that provides data to us under a contract (see section 4);
- your employer or a colleague who refers you to us;
- referees you nominate, or publicly available sources such as an organisation's website.
If we receive personal information about you that we did not ask for and could not lawfully have collected, we will destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
4. Client data and health information
Much of the information we handle belongs to our clients. When a health service, community organisation or government body engages us to build software or evaluate a programme, we may be given access to records that include health information about people receiving care.
In these engagements:
- The client remains responsible for the data. We act as a service provider handling that information on their behalf and under their instructions, subject to our contract with them.
- We minimise what we hold. We ask for de-identified or aggregated data wherever the task allows, and only seek identifiable information where it is genuinely necessary, for example to link records across time.
- We use it only for the engagement. Client data is used solely to deliver the agreed services. We do not use it for our own purposes, sell it, or use it to train third-party artificial intelligence systems.
- Additional laws may apply. Depending on the client and the jurisdiction, state and territory health records and public sector privacy legislation may also govern the information, for example the Health Records Act 2001 (Vic), the Health Records and Information Privacy Act 2002 (NSW), or equivalent legislation elsewhere. We comply with the obligations that apply to each engagement.
- Access requests go to the client. If you are a consumer of a service that has engaged us and you want to access or correct your records, please contact that service directly. They hold the record and control access to it. We will support them in responding.
- Return or destruction. At the end of an engagement we return or securely destroy client data in line with the contract, except where we are required to retain a copy by law.
Software we build for a client typically runs under that client's own privacy policy and information governance arrangements. Where Cognovo hosts or supports a system, the specific arrangements are set out in the contract and in any system-specific privacy notice.
5. How we use your information
We use personal information for the purpose it was collected for, for related purposes you would reasonably expect, and where the law requires or permits. In practice this means:
- responding to enquiries and providing information you have asked for;
- delivering, managing and improving our services;
- preparing proposals, tenders, contracts and invoices;
- conducting evaluations and producing findings and reports;
- maintaining our business records and meeting accounting, insurance and legal obligations;
- sending updates about our work where you have asked to receive them (see section 13);
- assessing job applications;
- protecting the security and integrity of our systems.
Evaluation findings are reported in aggregate or de-identified form. We do not identify individual participants in reports or publications without their express consent.
6. Disclosure to others
We may disclose personal information to:
- the client organisation that engaged us, in accordance with our contract;
- our employees, contractors and professional advisers who need it to do their work;
- service providers who support our operations, including cloud hosting, email, document storage, video conferencing, survey tools, accounting software and IT support, under agreements requiring them to protect it;
- a Human Research Ethics Committee or funder, where required for oversight of an evaluation;
- a person or body to whom we are required or authorised to disclose by law, including in response to a court order or a request from a law enforcement or regulatory agency;
- a party involved in the sale or restructure of our business, subject to confidentiality obligations.
We do not sell personal information, and we do not disclose it to third parties for their own marketing purposes.
In rare circumstances we may disclose information where we reasonably believe it is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, as permitted by the Privacy Act.
7. Overseas disclosure
Our preference is to keep data in Australia, and we require Australian data residency for identifiable health information handled under client engagements unless the client has specifically agreed otherwise in writing.
Some of the general business tools we use may store or process information overseas, for example in [the United States and the European Union]. Where we disclose personal information to an overseas recipient we take reasonable steps to ensure the recipient does not breach the APPs, as required by APP 8, including through contractual protections.
8. Storage, security and retention
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Our measures include:
- encryption of data in transit (TLS) and at rest;
- role-based access control, and access granted only on a need-to-know basis;
- multi-factor authentication on business systems;
- secure, reputable cloud infrastructure with audited security controls;
- secure file transfer for client data, since we do not accept identifiable health information by ordinary email;
- logging and monitoring of access to systems holding sensitive information;
- confidentiality obligations and privacy training for our personnel;
- secure destruction of physical and electronic records at end of life.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your information has been compromised, please contact us immediately using the details in section 16.
We keep personal information only for as long as we need it for the purposes set out in this policy, or for as long as the law requires. For example, business and financial records are generally retained for seven years. When information is no longer needed we destroy it securely or de-identify it.
9. Data breaches
We maintain a data breach response plan. If we suspect a breach we contain it, assess the risk, and take steps to prevent recurrence.
Where a breach is likely to result in serious harm to any individual whose information is involved, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. Where the information belongs to a client, we will notify that client promptly and support their response.
10. This website, cookies and analytics
You can browse this website without telling us who you are. When you visit, our hosting provider automatically records standard technical information in server logs: your IP address, browser type and version, the pages you request, the date and time of the request, and the page that referred you. This is used for security, troubleshooting and understanding overall usage.
Cookies
This website does not set advertising or cross-site tracking cookies. [If we add website analytics, this section will describe the tool used, what it collects, and how to opt out.] You can control or delete cookies through your browser settings at any time; doing so will not prevent you from using this site.
Contacting us
This website does not collect enquiries through a form. To contact us you email us directly, and we hold that correspondence in our business email system so we can respond and keep a record of the enquiry. Ordinary email is not a secure channel, so we ask that you do not include personal health information or details identifying a consumer or patient. If secure exchange of such information is needed, we will establish an appropriate channel.
Third-party resources and links
This website loads a web font from Google Fonts, which means your browser makes a request to Google's servers. Our site also links to external organisations. We are not responsible for the privacy practices of other sites, and we encourage you to read their privacy policies.
11. Access and correction
Under APP 12 and APP 13 you may ask for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.
Please make your request in writing to the contact in section 16, with enough detail for us to identify the information and to verify who you are. We will respond within 30 days. We do not charge for making a request; if significant work is required to give access we may charge a reasonable cost-based fee, which we will tell you about beforehand.
There are limited grounds on which we may refuse access or correction. For example, where giving access would have an unreasonable impact on another person's privacy, or where we are required by law to refuse. If we refuse we will tell you in writing, give our reasons, and explain how to complain.
If we hold the information as a service provider to a client, please direct your request to that organisation. See section 4.
12. Anonymity and pseudonymity
Under APP 2 you have the option of dealing with us anonymously or under a pseudonym, where that is lawful and practicable. In many cases, for example a general question about our services, we do not need to know who you are. Where we cannot deal with you anonymously, such as when we are entering a contract, we will tell you.
13. Direct marketing
We may occasionally send information about our services, publications or events to business contacts. Every message includes a way to unsubscribe, and we act on opt-out requests promptly. We do not use sensitive information for direct marketing without consent, and we do not provide contact details to other organisations for their marketing. To opt out at any time, email privacy@cognovo.com.au.
14. Making a complaint
If you think we have breached the APPs or mishandled your personal information, please tell us. We would like the chance to put it right.
- Contact us first. Write to our Privacy Officer using the details in section 16, setting out what happened. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If we need longer we will explain why and keep you informed.
-
If you are not satisfied with our response, you can refer
the matter to the Office of the Australian Information Commissioner:
Website: www.oaic.gov.au · Phone: 1300 363 992 · Post: GPO Box 5218, Sydney NSW 2001
Depending on the jurisdiction and the type of information, a state or territory privacy or health complaints body may also be able to consider your complaint.
15. Changes to this policy
We review this policy regularly and may update it to reflect changes in our practices or the law. The current version is always available at cognovo.com.au/privacy.html and shows its effective date at the top. Material changes will be notified on this website, and directly to clients where a change affects an engagement.
16. Contact us
To ask a question, request access or correction, or make a complaint, contact our Privacy Officer:
- Privacy OfficerCognovo Pty Ltd
- Emailprivacy@cognovo.com.au
A note on urgent help. Cognovo is not a clinical service and cannot provide mental health treatment or crisis support. In an emergency call 000. For support at any hour, contact Lifeline on 13 11 14 or Beyond Blue on 1300 22 4636.