The Skin Centre Privacy Policy
At The Skin Centre, your privacy matters to us. As a dermatology practice, we handle some of your most sensitive information, including your health records, and we take that responsibility seriously.
This Privacy Policy explains how we collect, use, store and share your personal information, and the rights you have over it. It applies to everyone who interacts with us, whether you are a patient, a visitor to this website, or someone who contacts us by phone, email or social media.
The Skin Centre (The Skin Centre GC Pty Ltd ACN 649 339 800) is bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We review this policy regularly to keep it accurate and current. If you have any questions about how we handle your information, you can contact us using the details at the end of this policy.
Quick Reference Guide
What you need to know about your privacy at The Skin Centre:
- We collect your health information to provide you with medical care.
- Your information is kept secure and only shared with people involved in your care.
- You can access and correct your health records at any time.
- We will tell you if there is a data breach that might seriously harm you.
- You can complain if you are unhappy with how we handle your information.
Your key rights:
- Access your medical records.
- Correct wrong information.
- Deal with us anonymously (where possible).
- Opt out of marketing communications.
- Make a privacy complaint.
1. Introduction
1.1 This Privacy Policy provides information to you on how your personal information (which includes your sensitive information, including your health information) is collected and used within our practice, The Skin Centre (The Skin Centre GC Pty Ltd ACN 649 339 800) and practitioners who operate from The Skin Centre, and the circumstances in which we may share it with third parties.
2. Why and How Your Consent is Necessary
2.1 When you register as a patient, you provide consent for us (including the medical practitioners who operate from The Skin Centre, our employees, agents, contractors and other representatives) to access and use your personal information so the practitioners operating from our practice can provide you with the best possible healthcare. Only persons who need to see your personal information will access it. If we need to use your information for any other purposes, we will seek additional consent from you to do so.
3. Why Do We Collect, Use, Hold and Share Your Personal Information?
3.1 Our practice will need to collect your personal information to facilitate the provision of healthcare services to you by the independent medical practitioners operating from our practice. Our main purpose for collecting, using, holding and sharing your personal information is to facilitate the management of your health by those independent medical practitioners, as well as any clinical and cosmetic professionals managing your health. We also use it for directly related business activities, such as financial claims and payments, practice audits and accreditation, staff training and business processes.
4. What Personal Information Do We Collect?
4.1 The information we will collect about you includes your:
- names, date of birth, addresses, contact details including emergency contact and next of kin;
- demographic information, including gender, cultural background and religious beliefs;
- medical information including medical history, medications, allergies, adverse events, immunisations, social history, family history, risk factors, photographs of your condition (including before and after photographs), histology reports and other medical reports and correspondence;
- Medicare number (where available) for identification and claiming purposes;
- healthcare identifiers;
- payment and/or financial information;
- concession card details; and
- health fund details.
5. Dealing With Us Anonymously
5.1 You have the right to deal with us anonymously or under a pseudonym unless it is impracticable for us to do so or unless we are required or authorised by law to only deal with identified individuals.
5.2 Please be aware that Medicare rebates are only available where a Medicare card (and/or associated information) is available. As such your practitioner may require you to pay for your consults in full without this rebate if you choose to deal with us anonymously or under a pseudonym.
6. How Do We Collect Your Personal Information?
6.1 Our practice may collect your personal information in several different ways:
- You may provide us with your personal information directly (for example, when you make an appointment with a medical practitioner operating from our practice, our practice staff will collect your personal and demographic information via your registration).
- The medical practitioners providing medical services may also collect further personal information from you which may be disclosed to us. Information can also be collected through My Health Record, for example via a Shared Health Summary, Event Summary or through a Discharge Summary provided by a hospital or other healthcare service provider.
- We may also collect your personal information when you contact us via our website, send us an email or SMS, telephone us, make an online appointment or communicate with us using social media.
- In some circumstances personal information may also be collected from other sources. Often this is because it is not practical or reasonable to collect it from you directly. This may include information from your guardian or responsible person; other involved healthcare providers, such as specialists, allied health professionals, hospitals, community health services and pathology and diagnostic imaging services; and/or your health fund, Medicare or the Department of Veterans’ Affairs (as necessary).
6.2 If a clinician deems it in your best interest to discuss your clinical information with you, we will arrange for this to occur either in person, via telephone or via videoconference.
7. When, Why and With Whom Do We Use and Share Your Personal Information?
7.1 We collect, use and disclose your personal information to facilitate the provision of medical services to patients of the practitioners operating from our practice and to provide our services to you.
7.2 We may also share your personal information:
- with other healthcare providers;
- when it is required or authorised by law (for example, court subpoenas, or where we are obliged to make a mandatory notification to a regulatory body);
- when it is necessary to lessen or prevent a serious threat to a patient’s life, health or safety or public health or safety, or where it is otherwise impractical to obtain your consent;
- to assist in locating a missing person;
- to establish, exercise or defend a claim;
- for the purposes of confidential dispute resolution processes;
- during the course of providing nursing support services;
- for the purposes of uploading that information to your My Health Record, such as through the shared health summary or event summary; and/or
- with third parties who work with our practice for business purposes, such as accreditation agencies or information technology providers. These third parties are required to comply with the Australian Privacy Principles (APPs) and this policy.
7.3 Only people who need to access your information will be able to do so. Other than in the course of facilitating the provision of medical services or as otherwise described in this policy, our practice will not share personal information with any third party without your consent.
7.4 Information Stored Overseas
We use some services that may store certain information overseas. Here is what goes where:
| Service | Location | What information | Privacy protection |
| Microsoft 365 | Various countries including USA | Business emails, some administrative data | Contractually bound to handle data consistently with the Australian Privacy Principles; ISO 27001 certified |
| Canva | USA | De-identified images for marketing materials only (where express consent provided) | Contractually bound to handle data consistently with applicable privacy laws |
| Dropbox | USA | Administrative documents (no patient files) | SOC 2 certified; encryption in transit and at rest |
| WordPress | USA | Website analytics (anonymous only) | Bound by applicable data protection terms |
| Mailchimp | USA | Email addresses for consented marketing only | Bound by applicable data protection terms; EU-US Data Privacy Framework participant |
7.5 We only send information overseas when:
- you have consented to it;
- it is necessary for your medical care;
- we are required by law; or
- it is necessary to prevent serious harm.
7.6 Where possible, we remove identifying information before sending data overseas.
7.7 Marketing communications. We will not use your personal information for marketing without your clear consent.
7.8 If you consent to marketing, we may send you:
- information about new treatments or services;
- skin health education materials; and
- practice news and updates.
7.9 How to opt out. You can stop marketing communications at any time by:
- clicking “unsubscribe” in any email;
- calling us on 07 5597 7170; or
- emailing reception@skincentre.com.au.
7.10 Important: opting out of marketing will not stop essential communications about your care, such as appointment confirmations or test results.
8. What Happens if There is a Data Breach?
8.1 A data breach occurs when your personal information is accessed, used or disclosed without permission, or is lost in circumstances where unauthorised access is likely.
8.2 If we experience a data breach that is likely to result in serious harm to you, we are required by law to:
- notify you as soon as practicable after we become aware of the breach;
- notify the Office of the Australian Information Commissioner (OAIC); and
- provide you with information about what happened and the steps you can take.
8.3 “Serious harm” includes identity theft, financial loss, threats to physical safety, loss of business opportunities, humiliation or damage to reputation.
8.4 We will tell you:
- what information was involved;
- what we are doing about it;
- what you should do to protect yourself; and
- how to contact us for more information.
9. How Do We Store and Protect Your Information?
9.1 Your personal information may be stored at our practice in various forms.
9.2 Our practice stores information as electronic records (including via cloud-based services), visual records (including photos) and archived paper records.
9.3 Our practice stores all personal information securely through the use of passwords, encrypted back-ups, confidentiality agreements for staff and secure cabinets.
9.4 All records will be retained until the later of seven (7) years from your last contact with the practice, or until you reach the age of twenty-five (25).
9.5 We take steps to destroy or de-identify information that we no longer require.
9.6 Our server security policy is designed to protect the servers from unauthorised access, data breaches and other security threats. Our practice uses the following security measures to ensure the personal information which it holds is secured:
- antivirus software is installed on all servers and updated regularly;
- firewalls are configured to block unauthorised traffic;
- servers are placed on their own subnet;
- access to servers is restricted to authorised users;
- physical access to the servers is limited, with servers located in a locked building and security cameras installed around the building;
- servers are patched regularly to fix security vulnerabilities; and
- backups are created regularly every hour onsite with daily offsite backups.
10. How to Access or Correct Your Information
10.1 You have the right to see your medical records. To request your records:
- Email: reception@skincentre.com.au
- Phone: 07 5597 7170
- In person: ask at reception
What happens next:
- We will confirm your identity (for your protection).
- We will acknowledge your request within 3 business days.
- We will provide your records within 30 days.
- We may charge reasonable costs for copying and postage.
10.2 Correcting wrong information. If information about you is wrong or out of date:
- tell us in person, over the phone or in writing (email is fine); and
- we will fix it free of charge.
10.3 We might not be able to give you access if:
- it would seriously threaten someone’s life or health;
- it would unreasonably impact someone else’s privacy;
- the request is frivolous or vexatious; or
- it would prejudice legal proceedings.
11. How to Make a Privacy Complaint
11.1 We take privacy seriously. If you think we have mishandled your information, please tell us by:
- Email: reception@skincentre.com.au (mark “Privacy Complaint”)
- Post: Practice Manager, Suite 3.07, Pindara Specialist Suites, 29 Carrara Road, Benowa QLD 4217
- Phone: 07 5597 7170
What to include:
- your name and contact details;
- what happened;
- when it happened; and
- what you would like us to do about it.
What happens next:
- We will acknowledge your complaint within 3 business days.
- We will investigate and respond within 30 business days.
- If you are not happy with our response, you can contact the OAIC.
Office of the Australian Information Commissioner (OAIC):
- Phone: 1300 363 992
- Website: oaic.gov.au
Note: the OAIC usually expects you to complain to us first.
12. Privacy and Our Website
12.1 If you “like” or comment on our social media pages, we will have your social media name.
12.2 Our website uses cookies. A “cookie” is a small file stored on your computer’s browser, which assists in managing customised settings of the website and delivering content. We collect certain information such as your device type, browser type, IP address and the pages you have accessed on our website and on third-party websites. You are not identifiable from such information. You can use the settings in your browser to control how your browser deals with cookies. However, in doing so, you may be unable to access certain pages or content on our website.
12.3 Our website may contain links to third-party websites. We are not responsible for the content or privacy practices of websites that are linked from our website.
13. Privacy Statement Review
13.1 This Privacy Policy will be reviewed annually to ensure it is in accordance with any changes that may occur.
14. What These Terms Mean
| Term | What it means |
| Australian Privacy Principles (APPs) | The 13 rules all Australian organisations must follow when handling personal information. |
| De-identified information | Information where names and other identifying details have been removed so you cannot be identified. |
| Health information | Information about your health, disability, medical history, or health services provided to you. |
| Personal information | Information that can identify you, such as your name, address, phone number, or medical records. |
| Serious harm | Harm that could include identity theft, financial loss, threats to safety, or serious damage to reputation. |
Contact Information
Phone: 07 5597 7170
Email: reception@skincentre.com.au
Address: Suite 3.07, Pindara Specialist Suites, 29 Carrara Road, Benowa QLD 4217
Last Updated: 17 June 2026

