Privacy Policy
Last updated: July 22, 2026
1. About this Privacy Policy
This Privacy Policy explains how GETLEAN.COM.AU PTY LTD (ABN 17 677 036 387), trading as GetLean (GetLean, we, us or our), collects, holds, uses, discloses and otherwise handles personal information.
GetLean operates an online platform that provides technology, administration, payment processing, customer support, care coordination and non-diagnostic support services. Through the platform, individuals may be connected with independent Australian-registered healthcare practitioners, pharmacies, pathology providers and other service providers.
GetLean does not independently diagnose medical conditions, prescribe medication, dispense medication or make clinical treatment decisions. Those functions are performed by appropriately qualified independent healthcare providers acting in accordance with their own legal and professional obligations.
We are committed to handling personal information in accordance with applicable Australian laws, including, where applicable:
- the Privacy Act 1988 (Cth);
- the Australian Privacy Principles;
- the Health Records and Information Privacy Act 2002 (NSW);
- the NSW Health Privacy Principles;
- the Spam Act 2003 (Cth);
- the Do Not Call Register Act 2006 (Cth);
- the Commonwealth Notifiable Data Breaches scheme; and
- other applicable Commonwealth, state and territory privacy, health-record, healthcare and consumer-protection laws.
This Privacy Policy applies to information handled through:
- the GetLean website and online platform;
- account registration and intake processes;
- health and suitability questionnaires;
- email, telephone, SMS, video and online communications;
- photographs, documents and information uploaded through the platform;
- customer support and care-coordination activities;
- payments, subscriptions, cancellations and refunds;
- practitioner, pharmacy, pathology and delivery arrangements facilitated through the platform;
- cookies, analytics and website technologies;
- marketing and promotional communications; and
- other interactions with GetLean.
This Privacy Policy does not replace the separate privacy policies or professional record-keeping obligations of independent practitioners, pharmacies, pathology providers or other third-party healthcare providers.
2. Who is responsible for your information
GetLean may collect and hold information for platform, administrative, support, billing, safety, legal, risk-management and care-coordination purposes.
Independent providers may also collect, hold, use and disclose information in their own right. These providers may include:
- Australian-registered healthcare practitioners;
- medical practices and clinical service providers;
- nurses and care-coordination providers;
- pharmacies;
- pathology providers and laboratories;
- identity-verification providers;
- payment processors;
- software and cloud-service providers;
- communications providers;
- delivery and courier providers; and
- other providers involved in services requested by you.
GetLean and an independent provider may each hold different records relating to the same interaction. For example:
- GetLean may hold account, intake, platform, payment, administrative, communication and support records;
- a healthcare practitioner may hold a separate clinical record;
- a pharmacy may hold prescription, dispensing, counselling and supply records;
- a pathology provider may hold request, testing and reporting records; and
- a care-coordination provider may hold communication and support notes.
A request to access or correct information may need to be directed to the organisation that holds the relevant record. We will provide reasonable assistance to help identify the appropriate organisation.
3. Information we may collect
The information we collect depends on how you interact with GetLean, the services you request and the information reasonably required to provide or facilitate those services.
We do not collect information merely because it may be useful in the future. We seek to limit collection to information reasonably necessary for a lawful function or activity.
3.1 Identity and contact information
We may collect:
- your full name;
- date of birth;
- residential, postal and delivery addresses;
- email address;
- telephone number;
- account username;
- communication preferences;
- emergency or authorised-contact details where relevant;
- identity-verification information;
- copies or details of government-issued identification;
- account authentication information;
- login and security records; and
- information required to confirm that you are at least 18 years old and eligible to use the platform.
Account authentication information may include encrypted or hashed passwords, login tokens, multifactor-authentication information and security records. Whether GetLean receives or stores this information depends on the authentication system used.
3.2 Health and sensitive information
Where reasonably necessary for a requested service, we may collect sensitive health information, including:
- medical history;
- current and previous health conditions;
- symptoms;
- allergies and intolerances;
- current and previous medicines or treatments;
- family medical history where clinically relevant;
- height, weight, body measurements and related information;
- lifestyle, nutrition, physical-activity and wellbeing information;
- pregnancy, breastfeeding or reproductive-health information where relevant;
- mental-health information where relevant to safety or assessment;
- smoking, alcohol or substance-use information where relevant;
- clinical and suitability questionnaires;
- pathology requests and results;
- consultation and appointment information;
- practitioner communications made available to GetLean;
- clinical-suitability or service-status information;
- information about side effects, adverse events or safety concerns;
- photographs or images supplied for identity, assessment, monitoring, safety or support purposes;
- information supplied by your usual healthcare provider where authorised; and
- other health information reasonably required for practitioner assessment, patient safety, support, legal compliance or continuity of care.
Health information is sensitive information. We collect, use and disclose it only where permitted by law, including where consent has been obtained or another lawful basis applies.
Providing information through a questionnaire does not itself guarantee that a consultation, prescription, treatment, pharmacy supply or any particular outcome will be available.
3.3 Photographs, images and identification documents
We may ask you to provide photographs, images or documents where reasonably necessary for:
- identity and age verification;
- practitioner assessment;
- confirming information you have supplied;
- clinical monitoring where directed by a practitioner;
- investigating an adverse event or safety concern;
- investigating damaged or incorrectly supplied goods;
- preventing fraud or account misuse;
- responding to a complaint; or
- satisfying legal, professional or regulatory requirements.
We will not use photographs, identification documents or clinical images in advertising, testimonials, case studies, social-media content or other public promotional material without separate, specific and informed consent.
We do not use facial recognition or other automated biometric identification. Photographs and identity documents supplied through the platform are reviewed by people, not matched by automated biometric systems. If this changes, its use will be disclosed before collection, will occur only where reasonably necessary and lawful, and any consent required by law will be obtained first.
3.4 Government-related identifiers
Where reasonably necessary, we may collect government-related identifiers such as:
- driver-licence details;
- passport details;
- Medicare information;
- Individual Healthcare Identifiers; or
- other government-issued identifiers.
We do not adopt a government-related identifier as GetLean’s own customer or account identifier unless permitted by law.
We use and disclose government-related identifiers only where reasonably necessary and permitted or required by law.
3.5 Payment and transaction information
We may collect or receive:
- selected services or plans;
- billing details;
- transaction dates and amounts;
- payment status;
- subscription and renewal information;
- refund and credit information;
- chargeback and payment-dispute information;
- payment-provider customer or transaction identifiers; and
- limited payment-card information made available by a payment processor.
Full card details will generally be processed directly by an external payment provider and may not be stored by GetLean.
3.6 Communications and support information
We may collect:
- emails;
- SMS and online messages;
- customer-support requests;
- telephone call notes;
- recorded calls, where notice and any required consent have been provided;
- appointment and administrative communications;
- complaints and feedback;
- records of consent;
- records of marketing preferences;
- cancellation and refund requests;
- safety and incident reports; and
- information supplied during a complaint, fraud, safety or service investigation.
Calls are not currently recorded. Notes may be taken of telephone conversations. If call recording is introduced, appropriate notice will be provided and this Privacy Policy updated first.
3.7 Technical, website and device information
When you use our website, communications or platform, we may automatically collect:
- IP address;
- browser type;
- device type;
- operating system;
- language settings;
- approximate location derived from technical information;
- referring website or campaign;
- pages viewed;
- links selected;
- access dates and times;
- session activity;
- crash and performance information;
- cookie and similar identifiers;
- advertising identifiers, where used;
- email engagement information; and
- information about how you interact with the website or platform.
We may use this information for security, fraud prevention, website operation, troubleshooting, analytics, service improvement and permitted marketing activities.
3.8 Information about other people
You should not provide personal or health information about another person unless:
- you are authorised to do so;
- the information is relevant and reasonably necessary;
- providing it is lawful; and
- any required consent has been obtained.
Where you nominate an emergency contact, authorised representative or usual healthcare provider, we may collect that person’s name, contact details and relationship to you.
3.9 Information received from third parties
We may receive information from:
- healthcare practitioners and clinical providers;
- nurses and care coordinators;
- pharmacies;
- pathology providers and laboratories;
- identity-verification providers;
- payment processors;
- referral partners;
- customer-support and communications providers;
- a person authorised by you;
- your usual healthcare provider, with appropriate authority;
- fraud-prevention and cybersecurity providers;
- public records where lawful; and
- another lawful source.
Where reasonably practicable, we will take steps to make you aware of the collection and the circumstances in which it occurred.
4. How we collect information
We may collect information:
- directly from you;
- through website forms and account registration;
- through intake and health questionnaires;
- during telephone, email, SMS, video or online communications;
- through photographs, pathology results, identification documents or other uploads;
- from practitioners, pharmacies or pathology providers involved in a requested service;
- from payment and identity-verification providers;
- through cookies, pixels, analytics and similar technologies;
- through a referral or promotional partner;
- from an authorised representative; and
- from another source permitted by law.
Where reasonably practicable, we collect personal information directly from you.
5. Collection notices
This Privacy Policy provides general information about our handling of personal information.
We may also provide a more specific collection notice when or before collecting information. A collection notice may explain:
- the entity collecting the information;
- the purpose of collection;
- the types of recipients;
- whether providing the information is required or optional;
- consequences of not providing the information;
- relevant overseas disclosures;
- access and correction arrangements; and
- where this Privacy Policy can be found.
Where appropriate, specific collection notices should appear at account registration, health screening, photograph or identification upload, pathology upload, payment, marketing opt-in and referral-partner consent stages.
6. Unsolicited personal information
We may occasionally receive personal or health information that we did not request.
Where we receive unsolicited information, we will consider whether we could lawfully have collected it. Where we could not lawfully have collected it and retention is not otherwise required or authorised, we will take reasonable steps to securely destroy or de-identify it.
Unsolicited information forming part of a Commonwealth record or otherwise subject to a legal retention requirement may be handled as required by law.
7. Why we collect, use and disclose information
We may collect, hold, use and disclose information where reasonably necessary to:
- create, administer and secure an account;
- verify identity, age and eligibility to use the platform;
- operate, maintain and protect the platform;
- facilitate an online intake process;
- facilitate access to an independent practitioner;
- facilitate practitioner consultation and assessment;
- arrange communications between you and relevant providers;
- support administration and care coordination;
- facilitate pharmacy or pathology services where applicable;
- process payments, recurring billing, refunds and cancellations;
- provide customer support and non-diagnostic assistance;
- send account, appointment, billing, safety and service communications;
- manage consent and communication preferences;
- respond to enquiries, complaints and access or correction requests;
- investigate fraud, identity misuse, security threats or unlawful conduct;
- investigate service, supply or delivery issues;
- manage adverse events, product concerns and safety issues;
- comply with legal, professional, court, regulatory and law-enforcement requirements;
- maintain records required for governance, safety, audit and compliance;
- assess and improve services and customer experience;
- conduct internal analytics and reporting;
- conduct permitted direct marketing;
- establish, exercise or defend legal claims;
- undertake business-continuity and disaster-recovery activities;
- obtain professional advice;
- manage insurance and risk; and
- undertake a proposed or completed business restructure, financing, sale or transfer subject to applicable confidentiality and legal requirements.
We will not use or disclose health information for a materially unrelated purpose unless permitted by law and, where required, with consent.
8. Consent and health information
Where consent is required, it should be voluntary, informed, current and sufficiently specific.
By actively providing health or other sensitive information for a requested service, you consent to its collection, use and disclosure for the purposes explained at the time of collection and in this Privacy Policy, subject to applicable law.
Acceptance of this Privacy Policy does not, by itself:
- authorise public use of your photographs or health information;
- authorise the sale of health information;
- authorise disclosure of health information to advertising platforms;
- authorise disclosure of participation status to an unrelated referral or rewards partner;
- authorise materially unrelated secondary uses; or
- guarantee any clinical outcome.
Where a proposed use or disclosure is materially different from the original purpose, we will obtain any further consent required by law.
You may withdraw consent to future handling where consent is the relevant basis. Withdrawal:
- does not affect lawful handling that occurred before withdrawal;
- does not require deletion where retention remains required or authorised;
- may affect our ability, or a provider’s ability, to continue providing a service; and
- does not prevent handling otherwise permitted or required by law.
9. What happens if information is not provided
You may choose not to provide requested information.
However, if necessary information is not provided:
- we may be unable to create or verify an account;
- an independent practitioner may be unable to conduct an appropriate assessment;
- a pharmacy or pathology provider may be unable to provide a service;
- we may be unable to process payment or provide support;
- a service may be delayed, restricted or unavailable;
- safety or identity requirements may not be satisfied; or
- a provider may determine that it cannot safely proceed.
You should provide complete and accurate health information where it is requested for practitioner assessment or safety.
10. Sharing information with practitioners
We may disclose relevant information to Australian-registered healthcare practitioners or clinical providers where reasonably necessary to facilitate:
- consultation;
- clinical assessment;
- communication;
- follow-up;
- safety monitoring;
- continuity of care; and
- compliance with legal and professional duties.
Practitioners exercise independent professional judgment. They may collect additional information directly from you and maintain their own clinical records.
GetLean does not control a practitioner’s independent clinical decisions or all aspects of the practitioner’s record-keeping obligations.
11. Sharing information with pharmacies
Where pharmacy services are required following an independent practitioner’s decision, relevant information may be disclosed to an independent pharmacy for purposes such as:
- receiving and assessing a valid prescription;
- verifying identity and contact details;
- dispensing;
- labelling;
- counselling;
- supply;
- delivery;
- stock and safety management;
- responding to adverse events or product concerns; and
- satisfying legal and professional obligations.
A pharmacy may collect additional information directly from you and maintain its own dispensing and supply records.
12. Sharing information with pathology providers
Where pathology or testing is requested, information may be disclosed to:
- a pathology provider;
- a laboratory;
- the requesting practitioner;
- another relevant clinical provider; or
- a provider responsible for authorised follow-up.
Information may include:
- identity and contact details;
- request information;
- relevant clinical information;
- test results; and
- information required for follow-up or safety escalation.
Pathology providers and practitioners may maintain separate records and have independent privacy and professional obligations.
The absence of a communication from GetLean must not be interpreted as confirmation that a pathology result is normal or that no medical follow-up is required. Pathology review, communication and follow-up responsibilities should be explained separately in relevant clinical communications.
13. Other recipients
We may disclose information to:
- practitioners and clinical providers;
- nurses and care-coordination providers;
- pharmacies;
- pathology providers and laboratories;
- payment processors;
- identity-verification providers;
- hosting, cloud and software providers;
- customer-support and communications providers;
- video-consultation providers;
- cybersecurity, fraud-detection and technical-support providers;
- analytics providers;
- couriers and delivery providers;
- accountants, auditors, insurers and professional advisers;
- regulatory, health-complaints and law-enforcement bodies;
- courts and tribunals;
- a purchaser, financier or successor in connection with a proposed or completed business sale, restructure or transfer, subject to appropriate safeguards;
- a person authorised by you; and
- other parties where you consent or where disclosure is permitted or required by law.
We seek to limit disclosures to information reasonably necessary for the relevant purpose.
14. Couriers and delivery providers
Where delivery is arranged, GetLean, a pharmacy or another provider may disclose limited information necessary for delivery, such as:
- recipient name;
- delivery address;
- telephone number;
- delivery instructions; and
- tracking information.
Couriers ordinarily do not require access to medical histories, clinical records or detailed health information.
Where an independent pharmacy arranges delivery, the pharmacy may disclose delivery information directly to its courier.
15. Referral, rewards and promotional partners
We will not disclose information revealing or implying your participation in a health or weight-management service to an unrelated referral, rewards or promotional partner merely because you accepted this Privacy Policy or our Terms.
Where an optional referral or rewards arrangement involves disclosure of personal or potentially health-related information, we will use a separate consent process that identifies:
- the partner;
- the information to be disclosed;
- the purpose;
- whether participation is optional;
- whether the partner may use the information for marketing;
- relevant overseas handling; and
- how consent may be withdrawn.
Declining an optional referral or promotional disclosure will not prevent access to GetLean’s core platform unless that disclosure is genuinely necessary for the requested service and this is clearly explained.
16. Direct marketing
We may use contact information to send information about GetLean services where permitted by law.
We will not use or disclose sensitive health information for direct marketing unless permitted by law and any required consent has been obtained.
Marketing communications sent by email or SMS will:
- accurately identify the sender;
- include appropriate contact details;
- contain a functional unsubscribe method where required; and
- be managed in accordance with applicable marketing and communications laws.
You may opt out by:
- using the unsubscribe link in an email;
- replying “STOP” where that option is offered;
- updating available communication preferences; or
- contacting support@getlean.com.au.
We will action unsubscribe requests within the period required by law.
Opting out of marketing does not prevent necessary:
- account communications;
- billing notices;
- appointment information;
- practitioner or pharmacy communications;
- safety messages;
- legal notices; or
- service updates.
17. Advertising platforms and audience measurement
We may use advertising and analytics services to understand campaign performance and website use.
Depending on our configuration, these providers may receive limited information such as:
- cookie or device identifiers;
- IP address;
- website events;
- campaign source;
- page visits; or
- conversion events.
We do not intentionally provide advertising platforms with:
- detailed medical histories;
- questionnaire answers;
- pathology results;
- prescription details;
- treatment records;
- adverse-event information; or
- other sensitive health information for advertising or audience creation.
We will not use sensitive health information for personalised advertising, customer-list matching, retargeting or lookalike-audience creation unless the activity is lawful, transparently disclosed and supported by any consent required by law.
The advertising and measurement services we currently use include Meta (server-side conversion measurement), Google (analytics and tag management), Snap, TikTok and Microsoft Clarity. The information shared with these services is limited to the categories described above, such as cookie and device identifiers, IP address, campaign information, contact identifiers used for conversion matching where permitted, and conversion events.
18. Cookies and similar technologies
We may use:
- cookies;
- local storage;
- pixels;
- tags;
- software development kits;
- conversion tracking;
- analytics tools; and
- similar technologies.
These technologies may be used to:
- keep users signed in;
- remember preferences;
- secure the platform;
- prevent fraud;
- understand website use;
- measure performance;
- identify technical errors;
- improve services;
- measure advertising effectiveness; and
- deliver or limit marketing where permitted.
You may be able to manage cookies through browser settings or an available consent-management tool. Disabling certain cookies may affect website or platform functionality.
Where consent is legally required before using a non-essential technology, we will obtain that consent.
The cookie, analytics and advertising technologies we currently use include Google Analytics and Google Tag Manager, Meta conversion measurement, Snap, TikTok, Microsoft Clarity, and cookies set by our authentication provider (Clerk), payment provider (Stripe) and support-chat provider (Help Scout).
19. Overseas storage and access
Some service providers may store information outside Australia or permit personnel outside Australia to access information for technical, administrative or support purposes.
Overseas recipients may include providers of:
- cloud hosting;
- software platforms;
- communications;
- analytics;
- customer support;
- identity verification;
- payment processing;
- cybersecurity; or
- technical support.
Where required by Australian privacy law, we take reasonable steps to ensure an overseas recipient handles personal information consistently with applicable Australian privacy requirements, unless an exception applies.
Server location alone does not determine whether overseas handling occurs. Remote access, backups, subprocessors and technical support may also involve overseas handling.
Our platform and databases are hosted in Australia. Information may also be stored in or accessed from the United States by service providers we use for payments, communications, authentication, customer support, fulfilment coordination, analytics and advertising measurement.
20. Artificial intelligence and automated tools
GetLean will not intentionally enter identifiable patient health information into a general-purpose public artificial-intelligence system unless:
- the use has been assessed and approved;
- appropriate contractual, security and confidentiality protections apply;
- the use is lawful;
- the information is limited to what is reasonably necessary;
- any required consent or notice has been provided; and
- human oversight is maintained where the output may affect a person.
Where automated tools assist with administration, security, transcription, summarisation, support or workflow management, GetLean remains responsible for taking reasonable steps to ensure the use is appropriate, accurate, secure and consistent with this Privacy Policy.
GetLean does not represent that an automated system makes independent clinical prescribing or treatment decisions.
GetLean currently uses AI-assisted tools to support administrative, customer-support and internal workflow tasks. These tools operate under human oversight and subject to contractual, security and confidentiality protections. No automated system makes clinical, prescribing or treatment decisions.
21. Information quality
We take reasonable steps to ensure personal information is accurate, current, complete and relevant for the purpose for which it is used or disclosed.
You should promptly update changes to:
- contact details;
- delivery address;
- medical conditions;
- medicines;
- allergies;
- pregnancy or breastfeeding status;
- adverse events;
- other clinically significant information; and
- information that may affect identity, safety or service delivery.
GetLean does not independently verify every statement provided by a user.
22. Security
We take reasonable steps to protect personal information from:
- misuse;
- interference;
- loss;
- unauthorised access;
- unauthorised modification; and
- unauthorised disclosure.
Depending on the information and system involved, safeguards may include:
- access controls;
- authentication measures;
- multifactor authentication;
- encryption;
- role-based permissions;
- activity and audit logging;
- staff training;
- confidentiality obligations;
- secure hosting;
- supplier due diligence;
- backups;
- security monitoring;
- incident-response procedures; and
- secure destruction or de-identification.
This list describes safeguards that may be used. It is not a representation that every control applies to every system.
No electronic transmission or storage system is completely secure. This statement does not exclude or limit any obligation GetLean has under applicable privacy, health-record, data-security or data-breach laws.
You should protect your login credentials and notify us promptly if you suspect unauthorised account access.
23. Data breaches
We maintain procedures for assessing and responding to suspected privacy and security incidents.
Depending on the circumstances, we may:
- contain the incident;
- investigate what occurred;
- identify affected information and individuals;
- take remedial action;
- engage relevant service providers;
- notify regulators, healthcare providers, insurers or law-enforcement bodies; and
- notify affected individuals where required by law.
Where the Notifiable Data Breaches scheme applies, we will assess whether an eligible data breach has occurred and provide notifications required by law.
Not every security incident requires public or individual notification.
Suspected incidents involving GetLean should be reported promptly to support@getlean.com.au with the subject line Privacy or security incident.
24. Retention of information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and as required or authorised by law.
Retention periods may depend on:
- the category of information;
- whether it forms part of a health or clinical record;
- the age of the individual when a health service was provided;
- legal and professional record-keeping requirements;
- billing, accounting and tax requirements;
- safety and adverse-event obligations;
- complaint or dispute requirements;
- applicable limitation periods;
- fraud and security requirements;
- backup cycles; and
- whether an account remains active.
Where GetLean is legally classified as a private health-service provider in NSW in relation to particular records, applicable NSW retention requirements will be observed. Independent practitioners, pharmacies and pathology providers may be required to retain their records for different periods.
When information is no longer required, we will take reasonable steps to securely destroy or de-identify it, subject to technical, backup and legal constraints.
Where NSW law requires a record of the destruction or transfer of a health record, that record will be maintained.
25. Account closure and deletion requests
Closing an account does not necessarily require immediate deletion of all information.
Following account closure, information may continue to be retained where required or authorised for:
- health-record obligations;
- safety and continuity of care;
- billing, accounting, taxation or audit;
- complaints or disputes;
- fraud prevention;
- legal claims;
- regulatory obligations;
- adverse-event investigation; or
- secure backup processes.
You may request deletion or de-identification.
We will assess the request and explain, where appropriate, whether information:
- can be deleted;
- must be retained;
- has been de-identified;
- is held by an independent provider; or
- cannot reasonably be removed immediately from secure backups.
Australian privacy law does not provide an unlimited right to immediate deletion of every record.
26. Access to personal information
You may request access to personal information held by GetLean.
Requests should be sent to:
Privacy Officer
GETLEAN.COM.AU PTY LTD
Email: support@getlean.com.au
Subject: Privacy access request
We may need to verify your identity before providing access.
We will respond within a reasonable period and within any specific statutory timeframe that applies. Where the NSW health-information access regime applies, we will seek to determine the request within the required NSW timeframe.
Access may be refused or limited only where permitted by law, including where disclosure would:
- unreasonably affect another person’s privacy;
- create a serious threat to health or safety;
- reveal information connected with legal proceedings;
- prejudice an investigation;
- be unlawful;
- reveal commercially sensitive evaluative information in circumstances protected by law; or
- fall within another lawful exception.
Where access is refused, we will provide reasons and complaint options where required.
A request for a practitioner’s clinical record, pharmacy record or pathology record may need to be made directly to that provider.
27. Correction of information
You may ask us to correct personal information you believe is:
- inaccurate;
- out of date;
- incomplete;
- irrelevant; or
- misleading.
We may:
- correct the information;
- ask for supporting material;
- add a statement recording your requested correction; or
- explain why the requested change was not made.
Where required and appropriate, we may notify a relevant recipient of a correction.
A clinical opinion or professional note will not necessarily be altered merely because you disagree with it. Your comments or a statement of disagreement may be added where appropriate and permitted.
28. Anonymity and pseudonyms
You may browse general website content or make some general enquiries anonymously or using a pseudonym where lawful and practicable.
Identification will usually be necessary for:
- account security;
- payment;
- identity verification;
- practitioner assessment;
- pharmacy processes;
- pathology;
- delivery;
- safety;
- fraud prevention; and
- legal and professional requirements.
29. Children
GetLean services are intended for people aged 18 years and over.
We do not knowingly offer the platform to children.
If we become aware that information about a child has been collected contrary to eligibility requirements, we will assess the circumstances and take appropriate action. This may include:
- restricting or closing an account;
- securely deleting information where lawful;
- retaining information where legally required; or
- referring a matter through an appropriate healthcare or safety process.
30. Third-party websites and services
The website or platform may contain links to or integrations with third-party websites, portals, tools or services.
Those parties may collect information under their own privacy policies.
GetLean is not automatically responsible for every independent third party’s conduct merely because a link or integration is provided. This does not exclude responsibility GetLean may have for:
- its own collection, use or disclosure;
- misleading representations;
- its selection or management of a service provider; or
- obligations that cannot lawfully be excluded.
You should review the privacy information supplied by relevant third parties.
31. Business transfers
If GetLean is involved in a proposed or completed merger, acquisition, restructure, financing, asset sale, insolvency process or transfer of business, personal information may be disclosed to advisers, financiers, counterparties or successors where reasonably necessary.
Any disclosure will be subject to applicable legal requirements and, where appropriate, confidentiality and data-protection obligations.
A business transfer does not authorise a recipient to use sensitive information for unrelated purposes contrary to applicable law.
32. Legal disclosure and serious threats
We may collect, use or disclose information where required or authorised by law, including in response to:
- a valid court order;
- subpoena;
- statutory notice;
- regulatory request;
- professional reporting obligation;
- law-enforcement process; or
- another lawful requirement.
We may also handle information where permitted by law to lessen or prevent a serious threat to life, health or safety, or in connection with suspected unlawful activity or serious misconduct.
33. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in:
- law or regulation;
- technology;
- service providers;
- security requirements;
- data-handling practices; or
- our services.
The current version will be published with its effective date.
We will not rely solely on continued use of the platform as consent to a materially new use of sensitive information where fresh consent is required.
Where a material change affects existing sensitive information, we will provide additional notice or obtain consent where required by law.
34. Privacy complaints
You may make a privacy complaint by contacting:
Privacy Officer
GETLEAN.COM.AU PTY LTD
ABN 17 677 036 387
Email: support@getlean.com.au
Please include:
- your name and contact details;
- the nature of your concern;
- relevant dates;
- the information, account or service involved; and
- the outcome you are seeking.
We will:
- acknowledge the complaint within a reasonable period;
- investigate it fairly;
- request further information where necessary; and
- aim to provide a substantive response within 30 days.
A complex complaint may require additional time. If so, we will provide an update where reasonably practicable.
If you are not satisfied with our response, you may be entitled to contact:
Office of the Australian Information Commissioner
Website: oaic.gov.au
Telephone: 1300 363 992
Information and Privacy Commission NSW
Website: ipc.nsw.gov.au
Telephone: 1800 472 679
Depending on the subject of the complaint, you may also be able to contact a relevant healthcare complaints body, professional regulator or other authority.
A complaint about an independent practitioner, pharmacy or pathology provider may need to be directed to that provider. We will provide reasonable assistance in identifying the relevant contact.
35. Contact us
Questions, consent-withdrawal requests, access requests, correction requests, deletion requests and privacy complaints may be directed to:
Privacy Officer
GETLEAN.COM.AU PTY LTD
ABN 17 677 036 387
Trading name: GetLean
Website: getlean.com.au
Email: support@getlean.com.au