Mindset Health Pty Ltd (ABN: 11 617 368 957) (“we”) are committed to protecting and respecting your privacy. This Privacy Policy (“Policy”) (together with our Terms and any other documents referred to on it) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us and how you can get access to this information. If in doubt, the primary governing law of this policy is that of the state of Victoria, Australia. This Policy applies to people living outside of Australia, Australian residents have a separate policy below this policy that applies.
Mindset Health provides you (the “User”) with access to the online and mobile services associated with Nerva, including but not limited to, try.nervaibs.com and all associated subdomains (the “Website”), and the Nerva mobile application (the “App”), collectively the “System”.
We process your data in order to provide a program of personalised tools for helping you change your smoking habits (and to support the delivery of that program).
We require consent from all users before processing their data. This consent can be withdrawn at any time.
Personal Information or personal data or personal identifiable information (PII) means information relating to an identified or identifiable natural person who can be directly or indirectly identified by reference to an identifier.
We collect and use information like your name, email address, gender, country, city, state and age bracket to personalise the course and communicate with you. You're able to opt out of any external communications (i.e., email and push notifications) at any time.
We collect information about your IBS symptoms (including, but not limited to, self-reported symptoms or difficulties associated with diarrhoea, pain, constipation, wind, bloating, nausea, anxiety and stress) in order to personalise our program.
We may also collect general information about your mental and physical wellbeing in order to evaluate progress against your self-defined goals.
We may collection information about the devices you use to access the System, including (but not limited to) IP address, mobile device UDID and IMEI numbers, operating system, browser type, and screen size. This information is used to provide you with customer support, for system administration, to tailor your experience of the System, to report aggregate information internally, and to assist communication (e.g., push notifications).
We may store cookies (small text files managed by your web browser) on your computer in order to improve your experience with the System. Example uses of these cookies include: recognising you when you return to the System, maintaining data you've entered across multiple sessions, and storing information about your personal preferences.
You may refuse to accept cookies by changing the settings on your device to prevent cookies from being set. However, if you select this setting you may be unable to access certain parts of the System. Unless you have adjusted your browser setting so that it will refuse cookies, our system may issue cookies when you visit the System.
Non-Personal Information means any information that does not reveal Your specific identity either directly or indirectly.
We may include your data in aggregated data sets shared with our research partners. In these sets, your data is not personally identifiable, and would be used for supporting generalised statements (e.g., "women ages 30-40 working improved their IBS symptoms by more than men"). If you'd like to opt out, please email hello@mindsethealth.com.
Information collected automatically through Mindset Health (or third-party services employed in Mindset Health), which can include: behavioural data (e.g. number of sessions you complete, what techniques you practice or how many times you practice the techniques), the IP addresses or domain names of the computers utilised by the Users who use Mindset Health, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilised to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilised by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.
Mindset Health understands that your identifiable health information is private and personal and is dedicated to maintaining its confidentiality and integrity. As such, we will never sell or rent it, and we have policies, procedures, and other safeguards to help protect it from improper use and disclosure.
The following categories describe the ways in which we use your identifiable health information and the rare instances that require us to disclose it to persons and entities outside of Mindset Health. We have not listed every use or disclosure within the categories below, but all permitted uses and disclosures will fall within one of the following categories. In addition, there are some uses and disclosures that may require your specific authorisation.
Mindset Health does not disclose Personal Information to third parties for any purpose materially different from the purpose(s) for which it was originally collected.
We may disclose information relating to your use of the System when requested by you. This disclosure at your request may require written authorisation by you.
We do not store credit card or customer details with any 3rd parties except trusted suppliers who help us deliver the services associated with the System and we are committed to ensuring that all suppliers meet our security and data protection standards.
We may use and disclose your identifiable health information in connection with providing services, for our internal operations, which include administration, eligibility, planning, analytics and various activities that assess and improve the quality and cost effectiveness of the service that we deliver to you. Examples are using information about you to improve quality of the service, satisfaction surveys, de-identifying health information, customer services and internal training. To the extent you receive access to our Website and App through your employer or your health plan, our services may include supporting, and sharing information with, your employer’s wellness program, your health plan or third-party administrator or other similar programs. Possible information to be shared may include participation data (i.e. the fact that you used Nerva), milestone data (e.g. number of sessions you complete or how many times you practice the techniques) to allow you to earn incentives and rewards (if those are offered as part of your wellness program), as well as data from your self-reported IBS-related symptoms.
We may receive a confirmation when you open an email from us, or click on a link in an email, if your computer supports this type of program. We use this confirmation to help us make emails more interesting and helpful. When you receive an email from us, you can opt out of receiving further emails by following the included instructions to unsubscribe. However, by opting out of further email communications after you sign up, you may limit program reminders and other valuable program content and components.
We allow chat support messages within the Nerva app and Website to support your interaction with, or completion of tasks relating to your use of the System. We may use your personal information and health information assist in these conversations. You can opt out by emailing us at hello@mindsethealth.com.
We may use and disclose your identifiable health information to contact you as a reminder to interact with, or complete tasks relating to your use of the System. You may make changes to the format and frequency of these reminders, or cancel these reminders and/or notifications by logging into your Nerva account in the App, and/or by accessing the native notification settings on your mobile device when using the App.
There are some services provided in our organisation through third party services providers. Examples of third party services providers include accounting services, server hosting and email delivery providers, business associates, vendors and other business partners and reputable companies in the industry who subcontract to us or to those of your employer as our corporate customers, where permitted by law. We may disclose your identifiable health information to our third party services providers so that they can perform the job that is required of them. To protect your identifiable health information, we require appropriate contracts or written agreements be in place that safeguard your identifiable health information.
With your explicit permission, we may share your identifiable health information with third party medical professionals nominated by you.
We may use and disclose your identifiable health information when necessary to prevent a serious threat to your health and safety or the health and safety of the public or another person. Any disclosure, however, would only be to someone able to help prevent the threat.
Certain laws permit or require certain uses and disclosures of identifiable health information for example, for public health activities, health oversight activities and law enforcement. In these instances, Mindset Health will only use or disclose your identifiable health information to the extent the law requires.
We may use de-identifying health information for internal and external research and publicity purposes. This may include publishing aggregate information about our users (for example, that women ages 30-40 with IBS improved their symptoms by 70%) in the context of providing public health information and conducting academic research. In certain instances, we may only provide such information with special waivers and permissions from you. You can opt out by emailing us at hello@mindsethealth.com.
Some of the third-party services that we use to monitor and analyse web traffic to keep track of user behaviour include:
In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets. If Mindset Health or substantially all of its assets are acquired by a third party, personal data held by it about its customers will be one of the transferred assets. Mindset Health will ensure that information transferred to third parties will only be used in a way that is compliant with our privacy principles, and will remain liable in cases of onward transfers to third parties.
We store all your personal information on secure servers. In some cases, to ensure a fast user experience, we may store some data on your device.
Where you have chosen a password that enables you to access certain parts of our App, you are responsible for keeping this password confidential. We ask you not to share the password with anyone.
We do not store any credit or debit card information. Payments are processed via a third party payment provider that is fully compliant with Level 1 Payment Card Industry (PCI) data security standards. Any payment transactions are encrypted using SSL technology.
Once we have received your information from the app or website, we will use strict procedures and security features to try to prevent unauthorised access. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy. We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so. Information you provide to us is stored in encrypted form on secure servers located in the US, which are owned and operated by Google Cloud Platform (GCP). GCP are industry leaders in the provision of hosting services and take security very seriously - you can find out more about their security policies and processes in their Security Whitepapers.
We may process some of your data with third parties to use their software platforms who have servers outside the US, UK or EEA to send communication emails to our users, but always in accordance with data protection law and subject to strict safeguards.
Users of the System have certain specific rights with regard to their information.
A user of the System has the right to view all personal information that Mindset Health has collected about them, as well as the disclosure of this data. In order to receive this data, please contact the Security, Privacy, and Compliance Officer. The first copy of this information is provided free of charge, and in a portable / common electronic form (e.g., CSV file).
A user of the System has the right to ensure that the data we have stored is accurate. In most cases, the system allows you to directly modify your own information. However, if there is incorrect data within our system that you are not able to change, please contact the Security, Privacy, and Compliance Officer and we will work directly with you to update this information.
Subject to any exemptions provided by law, a user of the System has the right to request deletion of all data within the system. To request your data be deleted, please contact the Security, Privacy, and Compliance Officer. In most cases, this request will be completed within 30 days. If circumstances require a delay to this deletion, Mindset Health will notify you directly explaining the reason for the delay. Note also that in some cases, there may be a legal requirement to hold on to your data. Again, Mindset Health will notify you directly if this is the case.
A user of the System has the right to withdraw their consent at any time by contacting the Security, Privacy, and Compliance Officer. Please note that without consent to process your data, we will be unable to deliver the Nerva program.
In addition to the right to request disclosures of your data specified in the "right to access" above, we will notify you as required by law if there has been a breach of the security of your identifiable health information.
If you believe that any of your rights with respect to your or others’ identifiable health information have been violated by us, our employees or agents, please communicate with the Mindset Health Security, Privacy, and Compliance Officer.
We reserve the right to revise this Policy without notification. Any changes or updates will be effective immediately upon posting to https://www.mindsethealth.com/legal/nerva-privacy-policy. Your continued use of the System constitutes your agreement to abide by the Privacy Policy as changed. Under certain circumstances (for example, if we expand the ways in which we use your personal information beyond the uses stated in our Privacy Policy at the time of collection), we may also elect to notify you of changes or updates to our Privacy Policy by additional means, such as by sending you an email.
Questions relating to revisions to this Policy may be addressed to the Security, Privacy, and Compliance Officer.
Mindset Health's Security, Privacy, and Compliance Officer (and Data Controller) can be reached at:
Alexander Naoumidis
Level 2, 620 Church Street, Cremorne VIC 3121
If we are subject to the Health Insurance Portability and Accountability Act (“HIPAA”), you may also contact the Secretary of the U.S. Department of Health and Human Services. Under no circumstances will we take any retaliation against you for filing a complaint.
This Policy is effective as of October 26, 2024.
--------------------------------------------------------------------------------
Last Updated: 26/10/2024
Mindset Health Pty Ltd (ABN 11 617 368 957) (Mindset, us or we) understands the importance of protecting the privacy of an individual’s personal information.
This Privacy Policy applies to people located in Australia and describes how we aim to protect the privacy of your personal information, your rights in relation to your personal information that we manage and the way we collect, hold, use and disclose your personal information.
In handling your personal information, we will comply with the Privacy Act 1988 (Cth) (Privacy Act) and with the Australian Privacy Principles in the Privacy Act and applicable health records legislation. This policy may be updated from time to time.
Personal information is information or an opinion about an identified, or reasonably identifiable, individual. During the provision of our services and products, we may collect your personal information.
Generally, we collect the following kinds of personal information:
Generally, we collect your personal information directly from you, through your use of our services and products, including our app and our website, when you complete an online form, or where you interact with us by way of telephone, email, or post, for example:
There may be occasions when we collect your personal information from other sources such as from:
Generally, we will only collect your personal information from sources other than you if it is unreasonable or impracticable to collect your personal information from you.
We collect, hold, use and disclose personal information where it is reasonably necessary for the purposes of:
We may also use your personal information for purposes related to the above purposes and for which you would reasonably expect us to do so in the circumstances, or where you have consented, or the use is otherwise in accordance with law.
Where personal information is used or disclosed, we take steps reasonable in the circumstances to ensure it is relevant to the purpose for which it is to be used or disclosed.
You are under no obligation to provide your personal information to us. However, without certain information from you, we may not be able to provide our services and/or products to you.
We disclose your personal information for the purpose for which we collect it. That is, generally, we will only disclose your personal information for a purpose set out in the ‘How we use your personal information’ section. This may include disclosing your personal information to:
We may disclose personal information to overseas recipients in order to provide our services and/or products and for administrative or other business management purposes.
It is impracticable to list all countries in which recipients may be located. However, we are likely to disclose personal information to our parent company in the United States of America and to other related bodies corporate.
Overseas recipients may have different privacy and data protection standards. However, before disclosing any personal information to an overseas recipient, we take steps reasonable in the circumstances to ensure the overseas recipient complies with the Australian Privacy Principles or is bound by a substantially similar privacy scheme unless you consent to the overseas disclosure or it is otherwise required or permitted by law. If you have any queries or objections to such disclosures, please contact our Privacy Officer on the details set in the ‘Contact us’ section below.
We may use and disclose your personal information for direct marketing in order to inform you of products and services that may be of interest to you. In the event you do not wish to receive such communications, you can opt-out by contacting us via the contact details set out in the ‘Contact us’ section below or through any opt-out mechanism contained in a marketing communication to you.
We may use your personal information for marketing and advertising, including for interest-based advertising. We engage our advertising partners, including third party advertising companies and social media companies, to advertise our services and products.
We and our service providers may use cookies and other similar technologies to automatically log information about you, your computer or mobile device, and your interaction over time with our services and products, such as:
Cookies are text files that websites store on your device or in the browser for the purpose of helping you navigate between pages efficiently, remembering your preferences, enabling functionality, and helping us understand user activity and patterns.
Opt-out of push notifications. If you opt in to receive push notifications within the app, we may send push notifications or alerts to your mobile device from time to time. You can deactivate push notifications and alerts at any time by changing your device settings, changing the push notification settings within the application, or deleting the app.
Opt-out of interest-based advertising. You may limit online tracking by:
Note that because these opt out mechanisms are specific to the device or browser on which they are exercised, you will need to opt out on every browser and device that you use.
Do Not Track. Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. We currently do not respond to "Do Not Track" or similar signals. To find out more about "Do Not Track," please visit http://www.allaboutdnt.com.
We may engage in clinical research and trials that use only aggregated and de-identified data we have collected. If you would not like your personal information used in our studies, please contact us via the contact details set out in the ‘Contact us’ section below.
We take steps reasonable in the circumstances to ensure that the personal information we hold is protected from misuse, interference and loss and from unauthorised access, modification or disclosure.
We hold personal information in electronic form on secure servers, including by means of firewalls, encryptions, logins and password protection, accessible only by authorised users.
We also hold personal information in hard copy form, accessible only by authorised users with an office access pass.
We will destroy or de-identify personal information on request, unless we are otherwise required or authorised by law to retain the information. We may delete or de-identify personal information in circumstances where it is no longer required.
Our services and products are not intended for use by children without the consent of their parents or guardians. If we learn that we have collected personal information through our services or products from an individual under 15 without the consent of the child’s parent or guardian as required by law, we will delete or destroy it.
We take steps reasonable in the circumstances to ensure personal information we hold is accurate, up-to-date, complete, relevant and not misleading. Under the Privacy Act and applicable health records legislation, you have a right to access and seek correction of your personal information that we collect and hold.
If at any time you would like to access or correct the personal information that we hold about you, or you would like more information on our approach to privacy, please contact our Privacy Officer on the details set out in the ‘Contact us’ section below.
We will grant access to the extent required or authorised by the Privacy Act and applicable health records legislation and take steps reasonable in the circumstances to correct personal information where necessary and appropriate.
To obtain access to your personal information:
If we refuse your request to access or correct your personal information, we will provide you with written reasons for the refusal and details of complaint mechanisms. We will also take steps reasonable in the circumstance to provide you with access in a manner that meets your needs and our needs.
We will endeavour to respond to your request to access or correct your personal information within 30 days from your request.
For further information or enquiries regarding your personal information, or if you would like to opt-out of receiving any promotional or marketing communications, please contact our Privacy Officer at: privacy@mindsethealth.com.
Please direct all privacy complaints to our Privacy Officer. At all times, privacy complaints:
Our Privacy Officer will commence an investigation into your complaint. You will be informed of the outcome of your complaint following completion of the investigation. If you are dissatisfied with the outcome of your complaint, you may refer the complaint to the Office of the Australian Information Commissioner.
We reserve the right to modify this Privacy Policy at any time. If we make material changes to this Privacy Policy, we will notify you by updating the date of this Privacy Policy. We may also provide notification of changes in another way that we believe is reasonably likely to reach you, such as via e-mail (if you have an account where we have your contact information) or another manner.