Last updated: 15 August 2026
1. About this policy
Gleaming Dental Surgery ABN 28 145 430 968 (Gleaming Dental, we, us or our) respects your privacy and is committed to handling personal information responsibly. This policy explains how we collect, hold, use and disclose personal information, including health information, and how you may access or correct your information or make a privacy complaint.
We operate a dental practice at 6/53 Gladesville Road, Hunters Hill NSW 2110. We aim to comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Health Records and Information Privacy Act 2002 (NSW) and the NSW Health Privacy Principles, as applicable.
2. Information we may collect and hold
Depending on your dealings with us, we may collect and hold:
- identity and contact details, such as your name, date of birth, address, phone number and email address;
- emergency-contact, guardian, family and carer details;
- health information relevant to your dental care, including medical and dental history, medications, allergies, diagnoses, treatment plans, clinical notes, photographs, scans, radiographs, referrals and appointment history;
- Medicare, private health insurance, Department of Veterans’ Affairs or other government-related identifiers where required or authorised;
- billing, payment, quotation, consent and transaction information;
- communications, enquiries, feedback and complaints;
- website and technical information, such as IP address, browser/device information, cookies, security logs and interactions with our website; and
- employment or contractor information if you apply to work with us.
Health information is sensitive information. We generally collect it with your consent or where collection is otherwise permitted or required by law.
3. How we collect information
We usually collect information directly from you or your authorised representative when you book or attend an appointment, complete a form, contact us by phone, email or our website, consent to treatment, make a payment or otherwise communicate with us.
Where appropriate and permitted, we may also collect information from a parent, guardian or carer; another treating practitioner; a specialist, dental laboratory, imaging provider or pharmacy; a health insurer or government agency; or another person involved in your care. If you provide information about another person, please ensure you are authorised to do so.
You may deal with us anonymously or using a pseudonym where lawful and practicable. In many clinical situations, however, we need accurate identifying and health information to provide safe treatment, process claims and meet legal or professional obligations. If required information is not provided, we may be unable to provide some services.
4. Why we collect, use and disclose information
We may handle personal information to:
- assess, plan, provide and coordinate dental care;
- manage appointments, reminders, referrals, follow-up care and patient communications;
- maintain clinical and business records and meet professional, insurance and legal obligations;
- process accounts, payments, rebates, insurance and government claims;
- communicate with your authorised representatives and other healthcare providers involved in your care;
- operate, secure and improve our practice, website and services;
- respond to enquiries, access or correction requests and complaints; and
- comply with laws, court orders, public-health requirements and regulatory obligations.
We may communicate about appointments and care by telephone, email or SMS. We may also send news, service updates or marketing communications where you have consented or where otherwise permitted by law. We will not use health information for direct marketing without the consent required by law. You may withdraw marketing consent or unsubscribe at any time without affecting your care.
We generally use or disclose information for the purpose for which it was collected, a related purpose you would reasonably expect, with your consent, or where authorised or required by law.
5. When we may share information
Where relevant and permitted, we may disclose information to:
- dentists, specialists and other healthcare providers involved in your care;
- dental laboratories, imaging providers, pharmacies and suppliers involved in providing treatment;
- your parent, guardian, carer or authorised representative;
- private health insurers, Medicare, the Department of Veterans’ Affairs and other claim or funding bodies;
- payment processors, accountants, insurers, auditors, legal advisers and debt-recovery providers;
- email, communications, appointment, practice-management, records-storage and other service providers that support our operations; and
- courts, regulators, law-enforcement bodies or other parties where authorised or required by law.
We take reasonable steps to limit disclosures to what is necessary and to require service providers to protect the information they handle for us.
Key systems and service providers
We currently use NetDent, supplied by Network Logic Health Systems, for clinical records, billing and claims. NetDent integrates with HICAPS for private health insurance claims and payment processing.
We use Appointy and Google Calendar to manage online bookings, appointment schedules and related notifications. Depending on how a booking is made, this may involve a patient’s name, contact details, appointment date and time, selected service, booking notes and technical information. Appointy processes booking information on our behalf and may send appointment reminders or notifications. Appointment details may be synchronised with Google Calendar.
We use Microsoft OneDrive for authorised document storage, backup and collaboration. Microsoft may process service and diagnostic data in locations where it operates. Data residency for files stored in OneDrive for Business depends on the configuration and location of our Microsoft 365 tenant.
We use HICAPS, a member of the NAB Group, to process private health insurance claims and payments. This may involve disclosing patient identification, health-fund membership, treatment, claim and transaction information to HICAPS, relevant insurers, payment networks and their service providers. HICAPS advises that some providers may be located or accessible overseas and that it may not always be practicable to identify each country.
6. Website, forms, cookies and third-party services
When you use our website or submit an online form, we may collect the information you provide together with technical information needed to deliver and secure the service. Our website may use cookies and similar technologies for essential functions, security, preferences, performance and analytics. We use Google Analytics and Google Ads, which set cookies and receive technical information about your visit (such as IP address, device and browser details and the pages you view) so we can measure how the site is used and how our advertising performs.
The website may include services or content supplied by third parties, such as maps, forms, spam prevention, analytics or embedded media. Those providers may collect information in accordance with their own privacy policies. You can control many cookies through your browser settings, although disabling them may affect website functionality.
Please do not include urgent or highly sensitive clinical information in a website contact form. Contact the practice directly for clinical matters, and call 000 in an emergency.
7. Overseas processing
Some technology, booking, calendar, claims, payment or cloud service providers — including Appointy, Google, Microsoft and service providers used by HICAPS — may process information outside Australia. Appointy states that it processes personal information in countries including the United States, Singapore and India. Google and Microsoft operate global infrastructure. OneDrive for Business files for a Microsoft 365 tenant provisioned in Australia are generally stored at rest within the Australian data region, subject to the applicable product terms and tenant configuration. Google Workspace data-region options and the location of processing depend on the service, edition and account configuration.
NetDent’s supplier states that information is held securely by its service providers, while HICAPS states that the countries involved in networked storage may not always be practicable to identify.
Before disclosing personal information overseas, we take reasonable steps required by applicable privacy law to protect it. Provider infrastructure and locations may change. You may contact us for current information about likely overseas locations relevant to your information.
8. Security and retention
We take reasonable physical, administrative and technical steps to protect information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include access controls, authentication, staff confidentiality obligations, secure systems, backups, monitoring and secure disposal. No transmission or storage system is completely secure.
We retain health and business records for the periods required by law and professional obligations, or for as long as reasonably needed for the purposes described in this policy. When information is no longer required, we take reasonable steps to destroy it securely or de-identify it, subject to lawful retention requirements.
9. Access and correction
You may request access to personal or health information we hold about you and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Please make your request in writing using the contact details below and provide enough information for us to identify you and the records requested.
We will respond within a reasonable period and in accordance with applicable law. We may need to verify your identity. In limited circumstances we may refuse access or correction; if so, we will explain the reason and available complaint mechanisms where required. A reasonable fee may apply for providing access, but not for making a request.
10. Privacy concerns and complaints
If you have a privacy question or complaint, please contact us using the details below. Describe the issue and provide your contact details and any relevant documents. We will acknowledge and investigate the matter and aim to respond within a reasonable period.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au or the Information and Privacy Commission NSW at ipc.nsw.gov.au.
11. Data breaches
We maintain procedures for responding to suspected privacy and data-security incidents. Where a breach is likely to result in serious harm, we will assess and respond to it and notify affected individuals and the relevant regulator where required under the Notifiable Data Breaches scheme or other applicable law.
12. Contact us
Privacy Officer — Gleaming Dental
6/53 Gladesville Road
Hunters Hill NSW 2110
Phone: (02) 9817 5302
Email: admin@gleamingdental.com.au
13. Changes to this policy
We may update this policy when our practices, service providers or legal obligations change. The current version will show its last-updated date.
