Privacy Policy

 

The Bub Club Pty Ltd
(ACN 693 533 121)


Contents

1.       Your privacy rights                                                                                                   

2.       Personal information we collect from you                                                                  

3.       Personal information we receive from other sources                                                 

4.       How we use personal information                                                                               

5.       Marketing and your choices                                                                                          

6.       Who we disclose personal information to                                                                    

7.       Overseas disclosure                                                                                                       

8.       Security, retention and destruction                                                                              

9.       Cookies and similar technologies                                                                                 

10.     Children and young people                                                                                           

11.     Third-party websites and services                                                                                

12.     Data breaches                                                                                                                

13.     If you are outside Australia                                                                                          

14.     Changes to this Privacy Policy                                                                                      

15.     How to contact us and make a complaint                                                                    

Schedule 1    | Quick reference – how we handle your information                       



Our commitment to your privacy

The Bub Club Pty Ltd (ACN 693 533 121) (The Bub Club, we, us or our) provides this Privacy Policy to explain what personal information we collect, why we collect it, who we share it with, how we protect it, and the choices and rights you have. It applies to the App, our website, our courses and programs, our community events and classes and every other way you interact with us.

We handle personal information in accordance with the Privacy Act 1988 (Cth) (the Privacy Act), the 13 Australian Privacy Principles (the APPs) and all other laws that apply to us.

This Privacy Policy forms part of, and should be read with, our User Agreement (terms and conditions) and, if you are a Provider, our Provider Terms of Service. available at https://www.thebubclub.com.au/ and in the App.

Our privacy promises

1.    We will never sell, rent or trade your personal information.

2.    We will never publish your email address or other identifying details without your consent.

3.    We will never use identifiable images of you or your child in advertising without your separate, express consent.

4.    We collect sensitive health information only with your consent, and only where it is reasonably necessary for the services you have asked us to provide.

Contents of this Privacy Policy

1.            Scope of this Privacy Policy and the laws that apply to us

What this Privacy Policy covers

1.1          This Privacy Policy applies to all personal information (including sensitive information and health information) that we collect, hold, use, disclose, store, transfer or otherwise handle, by any means and in any form, whether:

(a)           collected through the App, our website, a booking or checkout flow, a form, a waiver, an email, a telephone call, a message, a social media channel, a survey, or in person at a course, Session, community event or class;

(b)          held in electronic form (including in cloud storage, databases, backups and message logs) or in hard-copy form;

(c)           collected from you directly, from a Provider, from another User, from a public register, from a service provider or verifier acting on our behalf, or from any other lawful source; and

(d)          collected before, on or after the date of this Privacy Policy.

1.2          It applies to every category of individual we deal with, including: Users (parents and parents-to-be) and their partners, support persons, babies and children; Providers (including midwives and pelvic floor physiotherapists) and their personnel; attendees at our courses, community events and classes; visitors to our website and the App; our contractors, suppliers, venue operators and brand partners; and applicants and enquirers.

The laws we comply with

1.3          We comply with, and this Privacy Policy is to be read consistently with, each of the following (as amended or replaced from time to time):

(a)           the Privacy Act 1988 (Cth) (the Privacy Act), including all 13 Australian Privacy Principles set out in Schedule 1 to that Act (the APPs) and any applicable registered APP code;

(b)          Part IIIC of the Privacy Act (the Notifiable Data Breaches scheme);

(c)           the Health Practitioner Regulation National Law as applied in Queensland by the Health Practitioner Regulation National Law Act 2009 (Qld) and in each other State and Territory (the National Law), including its provisions concerning mandatory notifications, notifiable conduct and the advertising of regulated health services;

(d)          the Health Ombudsman Act 2013 (Qld), under which health service complaints in Queensland are made to the Office of the Health Ombudsman;

(e)           the Child Protection Act 1999 (Qld) (including the mandatory reporting obligations that apply to registered nurses and midwives), the Working with Children (Risk Management and Screening) Act 2000 (Qld) and the corresponding child protection and screening legislation of each other State and Territory in which we or a Provider operate;

(f)            the Domestic and Family Violence Protection Act 2012 (Qld), including its information-sharing provisions, and corresponding legislation in other jurisdictions;

(g)          the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth), in relation to our electronic and telephone marketing;

(h)          the Australian Consumer Law in Schedule 2 to the Competition and Consumer Act 2010 (Cth);

(i)            to the extent they apply to us or to any information we handle, the My Health Records Act 2012 (Cth) and the Healthcare Identifiers Act 2010 (Cth); and

(j)            all other Commonwealth, State and Territory laws that apply to our handling of personal information, health information and records.

State and Territory health records legislation

1.4          Our services are available to individuals across Australia. In addition to the Privacy Act, health privacy legislation applies to private sector health service providers in certain jurisdictions. Where and to the extent it applies to information we hold about you, we comply with:

(a)           the Health Records and Information Privacy Act 2002 (NSW) and the Health Privacy Principles under it;

(b)          the Health Records Act 2001 (Vic) and the Health Privacy Principles under it;

(c)           the Health Records (Privacy and Access) Act 1997 (ACT); and

(d)          any equivalent health records or health privacy legislation of any other State or Territory in which we operate or in which you are located.

1.5          In Queensland, health privacy for the private sector is governed by the Privacy Act rather than by separate State health records legislation. The Information Privacy Act 2009 (Qld) applies to Queensland public sector agencies and does not generally apply to us; however, if we are engaged as a contracted service provider to a Queensland agency, we will comply with the obligations that engagement imposes.

Our position where the law is unclear

1.6          We do not rely on any argument that our obligations are reduced because our services are educational rather than clinical, or because of our size or turnover. Specifically, and to remove any doubt:

(a)           we are not a “small business operator” exempt from the APPs. We collect and hold health information and provide a health service within the meaning of the Privacy Act, and accordingly section 6D(4)(b) of the Privacy Act applies to us. We therefore comply with the Privacy Act and the APPs in full, irrespective of our annual turnover, and we do not claim any small business, employee records or related-body-corporate exemption in respect of the information covered by this Privacy Policy;

(b)          we treat all information about your pregnancy, birth, post-natal recovery, physical and mental health, and about your baby or child’s health, as sensitive information and health information, and we apply the higher standard of protection the Privacy Act requires for that information, whether or not a particular activity we provide would strictly constitute a “health service”;

(c)           where two or more laws or standards apply to the same information and impose different requirements, we apply the requirement that gives you the greater protection; and

(d)          nothing in this Privacy Policy limits, excludes or modifies any right you have, or any obligation we have, under the Privacy Act, the APPs, any State or Territory health privacy legislation, the Australian Consumer Law or any other law. If any part of this Privacy Policy is inconsistent with such a law, that law prevails and this Privacy Policy is to be read as modified to the minimum extent necessary to give effect to it.

What these terms mean

1.7          Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether or not it is recorded in a material form.

1.8          Sensitive information means personal information of the kinds listed in the Privacy Act, including health information, genetic information, biometric information, and information about racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs, membership of a professional or trade association or trade union, sexual orientation or practices, and criminal record.

1.9          Health information means information or an opinion about the health (including an illness, disability or injury) of an individual at any time, an individual’s expressed wishes about the future provision of health services to them, a health service provided or to be provided to an individual, other personal information collected to provide or in providing a health service, and genetic information about an individual in a form that is or could be predictive of their health or that of a genetic relative.

1.10       Other capitalised terms used in this Privacy Policy (including App, User, Provider, Session, Program, Course, Event and Membership) have the meanings given to them in our User Agreement or, for Providers, our Provider Terms of Service.

Providers have their own obligations

1.11       Providers listed on the App are independent health practitioners. In addition to the obligations we impose on them under our Provider Terms of Service, each Provider is separately and personally bound by the Privacy Act, by their professional standards and codes (including those of the Nursing and Midwifery Board of Australia and the Physiotherapy Board of Australia) and by their own reporting obligations under the National Law and child protection legislation. We do not assume those obligations, and nothing in this Privacy Policy transfers them to us or relieves a Provider of them. This Privacy Policy does not govern a Provider’s handling of information in their own practice records, which is governed by their own privacy policy and legal obligations.

Consent

1.12       Where we rely on your consent (including to collect sensitive information or health information, to use your image, or to send you marketing), your consent must be voluntary, informed, current, specific and given by a person with capacity. You may withdraw your consent at any time as described in clause 2. Withdrawing consent does not affect the lawfulness of anything done before it was withdrawn, and where withdrawal means we can no longer provide a service to you, we will tell you.

1.13       If you are unable to provide consent yourself, consent may be given by a person authorised at law to give it on your behalf, and we may collect and handle personal information about your baby or child with the consent of a parent or guardian.

2.            Your privacy rights

You have the right to know what personal information we hold about you, to access it, to ask us to correct it, to ask us to delete it, to withdraw a consent you have given, and to complain if you think we have mishandled it. Exercising these rights will never cause you to receive a lesser standard of service from us.

Access and correction

2.1          You may request access to, or correction of, the personal information we hold about you at any time by contacting our Privacy Officer using the details at the end of this Privacy Policy. Many details can also be viewed and updated directly in your App account.

2.2          We will respond to a request within a reasonable period (usually 30 days). We do not charge for making a request, although we may charge a reasonable fee for giving access where a cost is incurred in retrieving information.

2.3          There are limited circumstances in which we may refuse a request, including where giving access would: be unlawful; have an unreasonable impact on another person’s privacy (for example, information that identifies a Provider, another User or your co-parent); prejudice an investigation of unlawful activity, fraud or a safety concern; relate to existing or anticipated legal proceedings; or where the request is frivolous or vexatious. If we refuse, we will tell you why in writing and explain how you may complain.

2.4          If we correct information we have previously disclosed to another person or organisation, we will, if you ask us to, take reasonable steps to notify them of the correction. If we do not agree with your view about the accuracy, completeness, currency, relevance or non-misleading nature of information we hold, we will not be obliged to change it, but we will, at your request, take reasonable steps to associate with the record a statement that you consider the information to be inaccurate, out of date, incomplete, irrelevant or misleading, in a way that will be apparent to any user of the information.

2.5          You may make a request through an authorised representative, legal adviser or agent, provided we are reasonably satisfied as to their authority and your identity. We will not charge you for making a request, for correcting information, or for making a privacy complaint.

Deletion and withdrawal of consent

2.6          You may ask us to delete your account and the personal information we hold about you, and you may withdraw any consent you have given (including consent to receive marketing or to the use of your image) at any time.

2.7          We may not be able to delete all of your information immediately. We are required by law, or permitted for the establishment or defence of a legal claim, to retain certain records – including health-related records, transaction and tax records, safety and complaint records, and records relating to a Provider’s professional obligations. Where we cannot delete information, we will restrict its use to those purposes and tell you why.

Anonymity

2.8          Where it is lawful and practicable, you may deal with us anonymously or by pseudonym for example, when browsing public content or making a general enquiry. We cannot provide accounts, courses, memberships, bookings or Sessions anonymously, because we need to verify identity for safety, payment and professional-obligation reasons.

3.            Personal information we collect from you

We aim to collect only the personal information we need. What we collect depends on how you interact with us: as a User, as a Provider, or as a visitor to our website, events or classes. The categories are:

All individuals

(a)           Contact information: your name, email address, postal or residential address, and telephone or mobile number.

(b)          Account information: your username, password (held in encrypted form), profile photograph, account status, date of birth and communication preferences.

(c)           Payment information: your billing address and payment method details. Card numbers are collected and processed directly by our payment processor and we do not see or store complete card numbers.

(d)          Transaction information: details of your purchases, bookings, memberships, cancellations, refunds and credits.

(e)           Communications: the content of messages you send through the App (including messages between Users and Providers), support enquiries, survey responses, reviews and feedback. Messages between Users and Providers will often contain health information. Where they do, we treat the message content as health information and apply the higher protections described in this Privacy Policy, including where our personnel access messages for support, moderation, safety or complaint handling purposes.

(f)            Usage and device information: information about your use of the App and website, including pages and content viewed, features used, session logs, crash and diagnostic data, device identifiers, browser and operating system details, and IP address.

(g)          Location information: approximate location (for example, to show you events and classes near you). We do not collect precise location unless you enable it.

(h)          Fraud prevention information: information used to detect and prevent fraud, misuse and unauthorised access.

Users: health and family information

The following categories are sensitive information under the Privacy Act. We collect them only with your consent and only where reasonably necessary to provide the services you have asked for:

(i)            Pregnancy and health information:  your stage of pregnancy, expected due date, birth preferences and experience, post-natal recovery, feeding, pelvic floor and physical health information, mental health and wellbeing information you choose to share, and any other health information you provide in bookings, forms, waivers, Sessions or Community Features.

(j)            Information about your baby or child: your baby’s or child’s name, date of birth, developmental stage and any health information you choose to share. This information may only be provided by a parent or guardian.

(k)           Waivers and consents: the waivers, disclaimers and consents you accept before participating in a course, Session, event or class, and any medical clearance information you provide.

Providers: professional information

(l)            Registration and credentials: your Ahpra registration and endorsement details, qualifications, scope of practice and professional history.

(m)         Insurance and membership: certificates of currency for professional indemnity and public liability insurance, and any professional association or union membership details.

(n)          Screening and eligibility: working with children check / Blue Card and other screening clearance details, police check information where required, and right-to-work information.

(o)          Payment and tax information: your bank account details, ABN and GST registration status, and payout records.

(p)          Performance information: your availability, response times, attendance, cancellations and no-shows, User reviews, ratings and complaints, and audit and compliance records.

Photography and recordings at events and classes

3.2          We may photograph or record our courses, community events and classes for our records and for marketing. We will give notice at the venue or in the booking conditions and you may ask us not to use identifiable images of you or your child. We will not use identifiable images in advertising without your consent.

Recording of Sessions

3.3          We may record Sessions (including any Session delivered by video or telephone), and Providers may be permitted to record them, if you and the Provider have each given express consent before the recording begins. Any recording of a Session is health information and is collected, held, used and disclosed only in accordance with this Privacy Policy. You may withdraw your consent to a recording at any time and may ask us to delete a recording, subject to clause 2.7.

If you choose not to provide information

3.4          You do not have to give us the personal information we ask for. However, if you do not, we may not be able to provide you with a course, Session, membership, event place or other service, or to list you as a Provider.

4.            Personal information we receive from other sources

(a)           From Providers: information about the Sessions and services delivered to you, including attendance, notes about the education provided and any safety or escalation concern raised.

(b)          From Users: reviews, ratings, feedback and complaints about a Provider.

(c)           From public registers and verifiers: confirmation of a Provider’s registration and endorsement from the Ahpra register, from insurers, and from third-party verification and screening services.

(d)          From your payment provider: confirmation of payment, chargeback and refund information.

(e)           From other individuals at your direction: information provided by your partner, support person or another family member where you have asked or authorised them to do so. We do not collect sensitive information (including health information) about another adult, whether from you or from anyone else, unless that person has given their own consent.

(f)            From our service providers: analytics, marketing, hosting and support providers acting on our behalf.

4.2          If you give us information about another person (including your partner, support person or child), you confirm that you are authorised to do so and that the information may be handled as described in this Privacy Policy. If the information is sensitive information (including health information) about another adult, we collect it only with that person's own consent, and you must not include it in a booking, form, waiver, message or post unless they have agreed. Health information about your baby or child may be provided by a parent or guardian in accordance with clause 1.13.

5.            How we use personal information

We use personal information for the following purposes:

(a)           To provide our services: to create and administer your account, deliver courses, content, Community Features, events, classes and memberships, and to facilitate bookings, Sessions and payments between Users and Providers.

(b)          To connect you with Providers: to share with your chosen Provider the information reasonably necessary for that Provider to deliver your booking safely and effectively.

(c)           To process payments: to charge Fees, collect Session Fees, deduct the platform fee, remit payments to Providers and process refunds, credits and chargebacks.

(d)          To verify Providers: to verify registration, endorsement, insurance and screening credentials, to issue and maintain credential badges and to re-verify them periodically.

(e)           For safety, quality and compliance: to monitor quality and safety, moderate Community Features, investigate complaints and incidents, conduct audits, respond to escalations and safety concerns, enforce our terms and policies, and meet our own legal and professional obligations.

(f)            For security and fraud prevention: to verify identity, secure our systems, and detect, prevent and investigate fraud, misuse and unauthorised access.

(g)          To improve our services: to analyse how our services are used, develop new content, programs and features, and conduct research using de-identified or aggregated information.

(h)          To communicate with you: to send service messages, booking confirmations, reminders, updates to our terms, and responses to your enquiries.

(i)            For marketing: to tell you about our courses, memberships, events, classes and brand partner offers, in accordance with the marketing section below.

(j)            With your consent: to use your feedback, story, image or recording in our content and marketing where you have agreed.

(k)           To comply with the law: to meet our obligations under the Privacy Act, health and professional regulation, consumer law, taxation and record-keeping requirements, and to respond to lawful requests.

Health information

5.2          We use health information only

(a)           for the purpose for which you provided it;

(b)          for a directly related secondary purpose you would reasonably expect;

(c)           with your consent; or

(d)          where otherwise permitted or required by law (including to lessen or prevent a serious threat to life, health or safety).

Automated decision-making

5.3          We do not use automated decision-making or profiling in any way that has a legal or similarly significant effect on you without human involvement. We may use artificial intelligence tools to help operate and improve our services and where we do, we do so in accordance with this Privacy Policy, and Providers are prohibited under the Provider Terms of Service from entering your information into unapproved artificial intelligence tools.

6.            Unsolicited information, data quality and identifiers

Unsolicited personal information

6.1          If we receive personal information about you that we did not solicit, we will determine within a reasonable period whether we could lawfully have collected it under this Privacy Policy. If we could not, and the information is not contained in a Commonwealth record and we are not otherwise required by law or a court or tribunal order to retain it, we will destroy it or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

Accuracy and quality of information

6.2          We take reasonable steps to ensure that the personal information we collect is accurate, up to date and complete, and that the personal information we use or disclose is accurate, up to date, complete and relevant having regard to the purpose of the use or disclosure. Please keep your account details current and tell us if anything changes, particularly your contact details and any health information relevant to a course, Session, event or class you have booked.

Government related identifiers

6.3          We do not adopt a government related identifier (such as a Medicare number, Individual Healthcare Identifier, tax file number or driver licence number) as our own identifier for you, and we do not use or disclose a government related identifier except where permitted by the Privacy Act – for example, where it is reasonably necessary to verify your identity, to fulfil an obligation to a government agency, or where required or authorised by law. Where we collect a Provider’s Australian Business Number, tax file number or registration number, we use it only for the payment, taxation and verification purposes described in this Privacy Policy.

7.            Marketing and your choices

7.1          With your consent, or where otherwise permitted by law, we may send you marketing communications about our courses, memberships, events, classes and brand partner offers by email, push notification, in-app message or SMS. Every marketing message includes a simple means of opting out, and you can also update your preferences in the App or by contacting us.

7.2          We do not use or disclose sensitive information (including health information) for direct marketing without your express consent, and we do not sell your information to advertisers.

7.3          Our direct marketing complies with APP 7, the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth). This means that:

(a)           every commercial electronic message we send identifies us and includes a functional unsubscribe facility that we will action within five Business Days;

(b)          we send marketing messages only where you have consented or where your consent can properly be inferred from our existing relationship with you and you would reasonably expect to receive them;

(c)           we do not make marketing telephone calls to numbers on the Do Not Call Register except where an exemption applies; and

(d)          on request, we will tell you the source of the information we used to contact you.

7.4          We do not disclose your personal information to any other organisation for that organisation’s own direct marketing purposes without your consent, and we never provide health information for that purpose.

7.5          We may use re-marketing and audience tools (for example, Google Ads, Meta and TikTok) to show our advertising to people who have visited our website or App. Where we do, we use only non-health information, the relevant platform handles data under its own privacy policy and you can manage your preferences through that platform’s advertising settings.

7.6          We recognise that, because of the nature of our services, even information that is not on its face health information may indicate that you are pregnant, planning a pregnancy or a parent. For that reason, we do not share with any advertising, audience or re-marketing platform: your health information; the content of your bookings, forms, waivers, Sessions or messages; or in-app activity data that would reveal your stage of pregnancy, the health content you have viewed, or the Sessions, Providers, courses or Programs you have viewed or booked. Any re-marketing we undertake is limited to general website or App visitation and is subject to the platform settings described in clause 7.5.

8.            Who we disclose personal information to

We disclose personal information only as described below, and we require our service providers to protect it on terms consistent with this Privacy Policy:

(a)           Providers: we disclose to your chosen Provider only the information reasonably necessary to deliver your booking. Providers are independent practitioners with their own obligations under the Privacy Act and their professional standards and are contractually required to keep your information confidential, use it only to deliver your Session and not to retain or export User lists or contact details.

(b)          Other Users: limited Provider profile information (name, qualifications, photograph, availability, badges and ratings) is displayed in the App. Anything you post in group Community Features is visible to other participants in those features.

(c)           Service providers: payment processors, cloud hosting and IT providers, verification and screening services, analytics providers, customer support, communications and marketing platforms and our professional advisers (including accountants, auditors, insurers and lawyers).

(d)          Venues and event partners: where necessary to administer attendance, access and safety at an event, course or class.

(e)           Brand partners: in de-identified or aggregated form only, unless you have given express consent to the disclosure of identifiable information.

(f)            Regulators and authorities: Ahpra and other health regulators, child protection and police authorities, courts and tribunals, the Australian Taxation Office, and other bodies where required or authorised by law – including in response to a subpoena, mandatory reporting obligation or notifiable conduct obligation, or to lessen or prevent a serious threat to life, health or safety.

(g)          In a business transaction: a purchaser or prospective purchaser of our business or assets, or a related body corporate, on confidential terms.

Functions our service providers perform

8.2          The organisations to which we disclose personal information may carry out or provide, among other things:

(a)           customer enquiry and support services;

(b)          booking, scheduling and communication systems; payment processing, billing, collections and chargeback handling;

(c)           mailing and messaging systems; identity, credential and screening verification;

(d)          information technology, hosting, security, backup and disaster recovery services;

(e)           brand partners in de-identified or aggregated form only (see clause 8.6), unless you have given express consent to the disclosure of identifiable information.

(f)            marketing and market research services; website and App usage analysis; insurance broking, underwriting and claims handling; and

(g)          accounting, audit and legal services.

8.3          Before disclosing personal information to a service provider, we take reasonable steps to ensure it is bound by confidentiality and privacy obligations consistent with this Privacy Policy and the Privacy Act, and to require that it use the information only for the purposes for which we provided it.

Other disclosures

8.4          We may also disclose personal information to: your authorised representatives or legal advisers, where you ask us to; our professional advisers, including our accountants, auditors, insurers and lawyers; organisations involved in a transfer or sale of all or part of our assets or business, or in managing our business risk and funding functions; and the police or other appropriate persons or authorities where a communication or circumstance suggests possible unlawful activity, a serious threat to the life, health or safety of any person, or a risk of harm to a child.

8.5          We do not sell, rent or otherwise disclose personal information to third parties for monetary or other valuable consideration.

De-identified Information

8.6          Information is de-identified only where it is no longer about an identifiable individual or an individual who is reasonably identifiable, having regard to the other information available to the recipient. Before disclosing de-identified information, we assess the risk that it could be re-identified, including where it relates to a small group of people or contains dates, locations or other details that could be matched with other data. We do not attempt to re-identify de-identified information, and we contractually prohibit brand partners and other recipients from attempting to re-identify it or from combining it with other information for that purpose.

9.            Overseas disclosure

9.1          Some of our service providers may store or process information outside Australia. Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it in a way consistent with the APPs, including through contractual protections.

9.2          We do not disclose health information overseas except where reasonably necessary for the operation of our services (for example, secure cloud hosting or support), and in those cases we take reasonable steps to ensure the recipient handles it in accordance with the APPs.

9.3          Where State or Territory health privacy legislation (including the Health Records and Information Privacy Act 2002 (NSW) and the Health Records Act 2001 (Vic)) applies to a transfer of your health information outside the relevant jurisdiction, we transfer the information only where:

(a)           we reasonably believe the recipient is subject to a law, binding scheme or contract that upholds principles for the fair handling of the information substantially similar to those that apply to us;

(b)          you have consented to the transfer; or

(c)           the transfer is reasonably necessary for the provision of the services you have asked for, and we have taken reasonable steps to ensure the information will not be handled inconsistently with those principles.

10.         Security, retention and destruction

10.1       We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Our measures include encryption in transit, access controls and role-based permissions, secure cloud infrastructure, firewalls and malware protection, confidentiality obligations on our personnel and Providers, and secure handling of any hard-copy records.

10.2       No system can be guaranteed completely secure. You must keep your login credentials confidential and must not allow another person to use your account.

10.3       Personal information may be stored both electronically – on our systems, with our hosting and cloud providers, and in backups – and, where necessary, in hard-copy form. Our electronic information is protected by measures including firewalls, anti-malware and email filtering, encryption, multi-factor authentication where available, role-based access controls and audit logging. Hard-copy information is held securely and access to it is restricted. We train our personnel on their privacy and confidentiality obligations, we restrict access to personal information to those who need it to perform their role, and we require our Providers, contractors and service providers to maintain equivalent standards.

10.4       Where we no longer need personal information for any purpose for which it may be used or disclosed under this Privacy Policy, and we are not required by law or by a court or tribunal order to retain it, we take reasonable steps to destroy it or to de-identify it.

10.5       We retain personal information only for as long as it is needed for the purposes described in this Privacy Policy, or as required by law. For health information, we retain records for at least 7 years from the date of the last service or interaction to which the record relates or, where the record relates to a person who was under 18 at that time, until that person turns 25, whichever is later. Taxation, corporate and other records are retained for the periods required by law. When information is no longer required, we take reasonable steps to destroy it or to de-identify it permanently.

11.         Cookies and similar technologies

11.1       We use cookies and similar technologies in the App and on our website to keep you signed in, remember your preferences, manage bookings and checkout, keep your session secure, and measure and improve performance.

11.2       Some cookies are essential to how our services work; others are analytics or advertising cookies. Third parties (including analytics and social media platforms) may set cookies through our website, and use them under their own privacy policies.

11.3       You can accept, decline or delete cookies through your browser or device settings, and manage app tracking through your device’s privacy settings. If you decline non-essential cookies you can still use our services, though some features may not work as intended.

About cookies

11.4       A cookie is a small text file or packet of information placed on your device by a web or application server so that it can identify and interact with your device more effectively. A session cookie is held temporarily and disappears when you close your browser or application; a persistent cookie remains on your device and may be used on later visits. Cookies cannot run programs, and a cookie can only be read by a server in the domain that issued it. Where a cookie collects or stores personal information, we extend the same protections to that information as to personal information collected by any other means.

Why we use cookies

11.5       We use cookies and similar technologies to: remember your preferences and settings; manage account creation and sign-in, so that you are not required to sign in on every page; keep your session secure and detect misuse; facilitate bookings, checkout and payment; show you relevant notifications and content; remember information you have chosen to submit to us; and measure and improve the performance of the App and website.

Third-party cookies and analytics

11.6       Third parties may set cookies or use similar technologies through our website and App. These may include analytics providers (such as Google Analytics, advertising and audience platforms (such as Google Ads and Meta), and social media plugins and buttons. Those parties handle the information they collect under their own privacy policies, and we do not control their technologies. Where we use analytics, we configure it to limit the collection of identifying information wherever reasonably practicable.

12.         Children and young people

12.1       Our services are intended for adults. You must be at least 18 years old to create an account. Information about a baby or child is collected only from a parent or guardian, is treated as sensitive information, and is used only to provide the services you have asked for. We do not knowingly permit a child to create an account or to be marketed to.

12.2       If you believe a child has provided us with personal information without parental consent, please contact us and we will take reasonable steps to delete it.

13.         Third-party websites and services

13.1       The App and our website may link to, or make available, third-party websites, products and services (including brand partner offers, payment services, insurance and dispute resolution services). Those third parties handle personal information under their own privacy policies, which you should review. We are not responsible for the content or privacy practices of any third party.

14.         Data breaches

14.1       We maintain a data breach response plan. We comply with the Notifiable Data Breaches scheme under the Privacy Act: if a data breach occurs that is likely to result in serious harm to any individual, we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, and we will tell you what happened, what information was involved and what steps you should take.

14.2       Providers are required to notify us immediately of any actual or suspected loss, misuse or unauthorised access to or disclosure of User information.

15.         If you are outside Australia

15.1       Our services are directed to people in Australia. If you access our services from overseas, you do so on the basis that your information will be handled in accordance with this Privacy Policy and Australian law.

15.2       We do not have an establishment in the European Union or United Kingdom and do not target our services there. However, if and to the extent the General Data Protection Regulation or the UK GDPR applies to information we hold about you, we will handle that information consistently with it – including your rights of access, rectification, erasure, restriction, portability and objection, and your right to complain to your local supervisory authority.

15.3       Where the General Data Protection Regulation or the UK GDPR applies to information we hold about you, you have the rights to: be informed about our processing; access your personal data; have inaccurate data rectified; have data erased in certain circumstances; restrict processing; data portability; object to processing (including for direct marketing); and not be subject to a decision based solely on automated processing that produces legal effects concerning you. To exercise a right, contact our Privacy Officer using the details at the end of this Privacy Policy.

16.         Changes to this Privacy Policy

16.1       We may update this Privacy Policy from time to time. The current version is always available in the App and on our website, and shows the date it was last updated. If we make a material change we will notify you through the App, by email or by push notification before it takes effect. Where a change requires your consent, we will ask for it.

17.         How to contact us and make a complaint

17.1       Privacy Officer: Tiffanie West, The Bub Club Pty Ltd, 54 Moana Park Avenue, Broadbeach Waters QLD 4218 Email: tiff@thebubclub.com.au

17.2       If you have a question, wish to exercise a privacy right, or are concerned that we have mishandled your personal information, please contact our Privacy Officer. We will acknowledge your complaint promptly, investigate it, and aim to give you a written response within 30 days.

17.3       If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at www.oaic.gov.au, by telephone on 1300 363 992, or by writing to GPO Box 5218, Sydney NSW 2001.

17.4       If your concern relates to the conduct of a health practitioner (including a midwife or physiotherapist listed on the App), you may also make a complaint or notification to:

(a)           the Office of the Health Ombudsman (Queensland) at www.oho.qld.gov.au or by telephone on 133 646, which is the entry point for health service complaints in Queensland;

(b)          the Australian Health Practitioner Regulation Agency at www.ahpra.gov.au or by telephone on 1300 419 495; or

(c)           the health complaints entity in your own State or Territory.

17.5       If your concern relates to health information and a State or Territory health privacy law applies to it, you may also complain to the relevant State or Territory privacy or health information regulator, including the Information and Privacy Commission New South Wales, the Office of the Health Complaints Commissioner (Victoria) or the ACT Human Rights Commission, as applicable.

17.6       We keep a record of privacy complaints and their outcomes, and we use them to review and improve our practices, procedures and systems as required by APP 1.

* * * *

Last updated: 30 July 2026

Schedule 1       | How this Privacy Policy addresses each Australian Privacy Principle

(a)           APP 1 – Open and transparent management of personal information: this Privacy Policy is published in the App and on our website, is available free of charge, sets out the matters required by APP 1.4, and is supported by our internal practices, procedures and systems, including our data breach response plan, privacy training, access controls and complaint-handling process (clauses 1, 10, 13 and 16).

(b)          APP 2 – Anonymity and pseudonymity: we permit dealings with us anonymously or by pseudonym where lawful and practicable, and explain when we cannot (clause 2).

(c)           APP 3 – Collection of solicited personal information: we collect only information reasonably necessary for our functions and activities, and collect sensitive information (including health information) only with consent and where reasonably necessary, by lawful and fair means (clauses 1, 3 and 5).

(d)          APP 4 – Dealing with unsolicited personal information: we assess unsolicited information and destroy or de-identify it where we could not lawfully have collected it (clause 6).

(e)           APP 5 – Notification of the collection of personal information: this Privacy Policy, together with the collection notices in our forms, booking flows and waivers, provides the notification required at or before the time of collection (clauses 1, 3 and 4).

(f)            APP 6 – Use or disclosure of personal information: we use and disclose information only for the primary purpose of collection, for a directly related secondary purpose you would reasonably expect, with your consent, or as otherwise permitted or required by law (clauses 5 and 8).

(g)          APP 7 – Direct marketing: we market only in accordance with APP 7, the Spam Act and the Do Not Call Register Act, always provide a simple opt-out, and never use sensitive information for direct marketing without express consent (clause 7).

(h)          APP 8 – Cross-border disclosure of personal information: we take reasonable steps to ensure overseas recipients handle information consistently with the APPs, and we acknowledge our accountability under section 16C (clause 9).

(i)            APP 9 – Adoption, use or disclosure of government related identifiers: we do not adopt government related identifiers as our own, and use or disclose them only as permitted (clause 6).

(j)            APP 10 – Quality of personal information: we take reasonable steps to ensure information is accurate, up to date, complete and relevant (clause 6).

(k)           APP 11 – Security of personal information: we take reasonable steps to protect information from misuse, interference, loss and unauthorised access, modification or disclosure, and to destroy or de-identify it when no longer needed (clause 10).

(l)            APP 12 – Access to personal information: we give access on request, within a reasonable period, subject only to the limited grounds of refusal permitted by the Privacy Act, with written reasons and a complaint pathway if we refuse (clause 2).

(m)         APP 13 – Correction of personal information: we correct information on request or on our own initiative, notify third parties of corrections where asked, and associate a statement of your contrary view where we do not agree (clause 2).

(n)          Part IIIC – Notifiable Data Breaches scheme: we maintain a data breach response plan and will notify affected individuals and the Office of the Australian Information Commissioner of any eligible data breach as soon as practicable (clause 13).

Schedule 2                Quick reference: how we handle your information

1.             What we collect: your contact and account details, payment and transaction records, your messages, usage and device information, and – with your consent – health and pregnancy information about you and your baby. For Providers: registration, insurance, screening, payment and performance information.

2.             Why: to deliver courses, content, community, memberships, events and Sessions; to process payments; to verify Providers; to keep people safe; to improve our services; and to meet our legal obligations.

3.             Who we share it with: your chosen Provider (only what they need), our service providers, venues where necessary, regulators where required by law, and brand partners only in de-identified form or with your consent. Never sold.

4.             Your choices: access, correct or delete your information, withdraw consent, opt out of marketing, decline non-essential cookies, and ask us not to use identifiable images of you or your child.

5.             Health information: collected only with your consent, used only for the purpose you gave it (or a directly related purpose you would expect), and never used for marketing without your express consent.

6.             Complaints: contact our Privacy Officer first; you can also complain to the OAIC.