Privacy Policy
Halo Journey Australia Pty Ltd
ABN 38 682 044 631
Last updated: 13 July 2026
1. INTRODUCTION
1.1 This Privacy Policy applies to all personal information collected by Halo Journey Australia Pty Ltd (ABN 38 682 044 631) ("Halo Journey", "we", "us", or "our") via:
(a) the website located at www.halojourney.com.au ("Website");
(b) the Zanda client portal ("Client Portal"); and
(c) any intake forms, health declaration forms, or other documents provided to us in connection with our services.
1.2 Halo Journey provides online counselling, mediation, life coaching, and online yoga services to individuals and families across Australia. In delivering these services, we collect personal information, including health information, from our clients. We are committed to handling all personal information in accordance with the Privacy Act 1988 (Cth) ("Privacy Act") and the 13 Australian Privacy Principles ("APPs").
1.3 As a provider of health services, Halo Journey is an APP entity for the purposes of the Privacy Act. Health information collected by us is classified as sensitive information and is subject to heightened protections under the APPs.
1.4 By using our Website, Client Portal, or services, or by providing personal information to us, you consent to the collection, use, storage, and disclosure of your personal information in accordance with this Privacy Policy.
1.5 We may update this Privacy Policy from time to time. The current version will always be available on our Website. We encourage you to review this policy periodically.
2. TYPES OF INFORMATION WE COLLECT
2.1 Personal Information Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or not, and whether it is recorded in a material form or not (Privacy Act 1988 (Cth), s 6). The personal information we collect may include:
(a) name, preferred name, pronouns, and date of birth;
(b) contact details including email address, phone number, and postal address;
(c) login credentials for the Client Portal;
(d) payment details and billing information;
(e) emergency contact details; and
(f) details of your GP or treating health practitioner.
2.2 Sensitive Information — Health Information Health information is a category of sensitive information under the Privacy Act and is subject to heightened protections. In the course of providing counselling, mediation, life coaching, and online yoga services, we may collect health information from clients. This may include:
(a) current and previously diagnosed mental health conditions;
(b) current medications, dosages, and prescribing practitioners;
(c) physical health conditions, chronic illnesses, and disabilities;
(d) physical injuries, surgeries, and medical procedures;
(e) trauma history (to the extent voluntarily disclosed);
(f) contraindicated conditions, movements, or therapeutic approaches;
(g) safety considerations including suicidal ideation, self-harm, or risk to others; and
(h) any other health information provided in a client health declaration form or during the course of service delivery.
2.3 Other Sensitive Information We may also collect other categories of sensitive information as defined under the Privacy Act, including racial or ethnic origin, religious or philosophical beliefs, or other information where it is relevant to the services you have requested. We will only collect such information with your consent or where otherwise permitted by law.
2.4 Website and Technical Information When you use our Website, we may also collect non-identifying technical information including:
(a) cookies and browsing data to improve your website experience; and
(b) analytics data such as pages visited, time on site, and device type.
This information does not, in most cases, identify you personally.
3. HOW WE COLLECT YOUR INFORMATION
3.1 We collect personal information and health information in the following ways:
(a) directly from you when you complete a client intake form or health declaration form;
(b) through the Zanda client portal when you register, book appointments, or communicate with us;
(c) when you contact us by email, phone, text, or through the Website;
(d) during the course of service delivery, including counselling, mediation, coaching, and yoga sessions; and
(e) from third parties, such as your GP or treating practitioner, where you have provided consent or where we are otherwise authorised to do so.
3.2 Where we collect personal information from a third party, we will take reasonable steps to make you aware of the information provided and the circumstances of its collection.
3.3 We collect health information only where it is reasonably necessary for the delivery of our services and with your express consent, except where otherwise permitted or required by law.
4. PURPOSE OF COLLECTION
4.1 General Personal Information We collect general personal information to:
(a) provide, manage, and improve our services;
(b) communicate with you about appointments, service updates, and administrative matters;
(c) process payments and maintain billing records;
(d) respond to enquiries and complaints; and
(e) comply with our legal and regulatory obligations.
4.2 Health Information We collect health information for the following primary purposes:
(a) to assess your suitability to participate in the services you have requested;
(b) to tailor service delivery to your individual needs, physical condition, and health circumstances;
(c) to manage our duty of care obligations to you and, where applicable, to others;
(d) to identify contraindicated conditions, movements, or therapeutic approaches that should be avoided or modified;
(e) to respond appropriately in the event of a health emergency or safety concern during service delivery; and
(f) to maintain accurate client records as required by applicable professional and legal standards.
4.3 Direct Marketing We may use your contact details to send you information about our services, updates, and relevant developments. We will only do this where you have consented or where it is otherwise permitted under the Privacy Act and the Spam Act 2003 (Cth). We will not use sensitive information, including health information, for direct marketing purposes. All marketing communications will include a simple mechanism to unsubscribe.
5. HEALTH INFORMATION COLLECTION NOTICE (APP 5)
5.1 At or before the time we collect health information from you (or as soon as practicable after), we will take reasonable steps to ensure you are aware of the following:
(a) Halo Journey Australia Pty Ltd (ABN 38 682 044 631) is collecting your health information;
(b) the health information is collected for the purposes set out in clause 4.2 of this policy;
(c) the collection is authorised by your consent, as provided in your intake form form;
(d) if you do not provide the requested health information, we may not be able to deliver services safely or at all;
(e) you may access or seek correction of your health information by contacting us using the details in clause 13; and
(f) you may make a complaint about our handling of your health information as set out in clause 11.
5.2 This notice is provided through our he client health declaration form completed prior to commencement of services, and through this Privacy Policy which is available on our Website and upon request.
6. DISCLOSURE OF PERSONAL INFORMATION
6.1 General Disclosure We may disclose your personal information to:
(a) our service providers who assist us in operating the Website, Client Portal, and delivering our services, including payment processors, cloud storage providers, analytics services, customer support platforms, and the Zanda client portal — each bound by confidentiality obligations and required to maintain standards consistent with the APPs;
(b) your nominated emergency contact, where we reasonably believe it is necessary in a health emergency; and
(c) other parties with your express consent.
6.2 Disclosure of Health Information We will only disclose your health information:
(a) for the primary purpose for which it was collected (service delivery and duty of care);
(b) for a secondary purpose directly related to the primary purpose, where you would reasonably expect such disclosure;
(c) with your express consent; or
(d) where we reasonably believe the disclosure is necessary to lessen or prevent a serious threat to the life, health, or safety of you or another person, and it is unreasonable or impracticable to obtain your consent — in accordance with APP 6.2(c) of the Privacy Act 1988 (Cth).
6.3 Mandatory Reporting and Emergency Disclosure Where Halo Journey's practitioners have mandatory reporting obligations under applicable law (including child safety legislation), or where there is a serious and imminent risk to the life or safety of any person, we may be required to disclose relevant information to emergency services, government authorities, or other appropriate parties without your consent. We will inform you of any such disclosure where it is lawful and practicable to do so.
6.4 No Sale of Personal Information We do not sell, rent, or trade your personal information or health information to third parties.
7. OVERSEAS DISCLOSURE
7.1 Some of our service providers, including cloud storage, analytics, and client portal services, may store or process data on servers located outside Australia. Where this occurs, we take reasonable steps to ensure those providers maintain data protection standards consistent with the APPs, including through contractual obligations.
7.2 By using our services, you acknowledge that your personal information may be transferred to and stored in countries outside Australia as part of our use of these service providers.
7.3 We will not otherwise disclose your personal information to overseas recipients unless you expressly request us to do so. Where you request such a transfer, the overseas recipient may not be subject to the APPs, and we will not be accountable for any mishandling of your information by that recipient.
8. STORAGE AND SECURITY
8.1 We store your personal information and health information in a manner that reasonably protects it from unauthorised access, misuse, modification, or disclosure, in accordance with APP 11. Our security measures include:
(a) encrypted storage of client records and health information;
(b) access controls restricting health information to authorised practitioners and staff;
(c) secure transmission of data via the Website and Client Portal; and
(d) regular review of our data security practices.
8.2 The Zanda client portal applies its own security measures to data stored within the platform. We take reasonable steps to ensure Zanda maintains standards consistent with the APPs.
8.3 In the event of an eligible data breach affecting your personal information, we will comply with our mandatory notification obligations under Part IIIC of the Privacy Act, including notifying the Office of the Australian Information Commissioner (OAIC) and affected individuals as required.
9. DATA RETENTION
9.1 We retain personal information and health information for as long as necessary to fulfil the purposes for which it was collected, and to comply with our legal and professional obligations. Our standard retention periods are:
(a) Health information (adult clients): 7 years from the date of last service, or as otherwise required by applicable professional standards;
(b) Health information (clients who were minors at the time of service): until the client turns 25 years of age, or 7 years from the date of last service, whichever is later;
(c) Financial and billing records: 7 years from the date of the transaction, in accordance with taxation and accounting obligations; and
(d) General personal information and inactive account data: 7 years from the date of last activity or contact.
9.2 When personal information is no longer required, we will take reasonable steps to destroy, deidentify, or anonymise it in accordance with APP 11.
10. ACCESS AND CORRECTION
10.1 Under APP 12, you have the right to request access to the personal information and health information we hold about you. Under APP 13, you have the right to request correction of information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
10.2 To make an access or correction request, please contact us in writing using the details in clause 13. We will respond to your request within a reasonable time and, in any event, within 30 days.
10.3 We may decline an access or correction request in limited circumstances permitted by the APPs, including where providing access would pose a serious threat to the life or health of any person, or where the request is frivolous or vexatious. Where we decline a request, we will provide written reasons.
10.4 Right to Request Deletion You may request deletion of your personal information. We will respond to deletion requests within 7 business days. We will verify your identity, confirm any legal obligations that may affect the request (including mandatory retention periods), and provide written confirmation once deletion is complete. Note that we may be required to retain certain information for the periods set out in clause 9 regardless of a deletion request.
11. COMPLAINTS
11.1 If you have a complaint about the way we have handled your personal information or health information, please contact us in writing using the details in clause 13.
11.2 All complaints will be considered by the Business Manager and/or the Director(s) of Halo Journey Australia Pty Ltd. We may seek further information from you to clarify your concerns. We will acknowledge receipt of your complaint within 5 business days and aim to resolve it within 30 days.
11.3 If we agree that your complaint is well founded, we will, in consultation with you, take appropriate steps to rectify the matter.
11.4 If you remain dissatisfied with the outcome, you may refer the matter to the Office of the Australian Information Commissioner (OAIC): • Website: www.oaic.gov.au • Phone: 1300 363 992 • Post: GPO Box 5218, Sydney NSW 2001
12. GDPR
Our Website does not specifically target individuals located in the European Union, and we do not monitor the behaviour of individuals in the European Union. Accordingly, the European Union General Data Protection Regulation (GDPR) does not apply to our operations. If you are located in the European Union and have concerns about how your information is handled, please contact us using the details in clause 13.
13. CONTACT US
For all privacy enquiries, access and correction requests, deletion requests, or complaints, please contact us at: Halo Journey Australia Pty Ltd Email: info@halojourney.com.au Phone: +61 414 975 728 or +61 485 042 221
14. AUTOMATED DECISION-MAKING
Halo Journey Australia Pty Ltd uses some AI-assisted tools for operational and administrative purposes generally, however, no such tools are used in client intake, matching, session delivery, or administration that make or inform decisions affecting clients. These tools are used only for general administrative and design assistance, including but not limited to helping with wording or formatting of documents and preparing training materials.