Legal
Consumer Health Data Privacy Policy
Last Updated: 25/06/2025
(This Consumer Health Data Privacy Policy is intended for Australian residents and supplements the general SaluStory Privacy Policy. It provides additional details on how we handle health information collected through our services. In case of any inconsistencies, the provisions that offer the most protection to individuals' health data will apply.)
Introduction: This Consumer Health Data Privacy Policy ("Health Privacy Policy") explains how SALUSTORY PTY LTD ("SaluStory," "we," "us" or "our") collects, uses, stores, and protects health-related personal information. We abide by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) in handling all personal information, especially health information, which is regarded as "sensitive information" under the law. In this Policy, "health information" refers to information or an opinion about an individual's health, medical history, or disability, and information collected while providing a health service (including data about symptoms, diagnoses, medications, and child development health records). This policy applies to Australian users of the SaluStory app and services, and it should be read together with our general Privacy Policy. Terms used here have the same meaning as in our Privacy Policy, unless otherwise defined.
We do not use or disclose consumer health data except as described in this Policy, and we do not combine it with unrelated data for secondary uses without consent. We also do not subject health data to any overseas laws that would undermine your privacy rights, our handling remains governed by Australian law even when using overseas servers.
1. Health Information We Collect
SaluStory is designed to help caregivers log and track health details of children. As such, the health information we collect includes:
- Child Health Profiles: Basic identifying details about the child under care, such as name or nickname, date of birth (used to calculate age), sex or gender (used to define developmental milestones), and any known medical conditions or allergies you choose to note in their profile. This helps contextualise other health data (e.g., age for developmental milestones).
- Symptom Logs: Information on symptoms or health observations you record. For example, entries might include a description of a symptom (fever, cough, rash, etc.), its severity, date and time, and any contextual notes (e.g., "fever of 38.5C starting in the evening"). You might also log measurements like temperature readings, or attach photos related to a symptom (such as a photo of a rash) if the app allows.
- Medications and Treatments: Records of medications or remedies given to the child, including the name of the medication, dosage, date and time administered, and any effects or side effects observed. This category can also include treatments or interventions (for example, "used asthma inhaler," "applied ice pack to injury," or "physical therapy exercises").
- Health Events and History: Broader health-related events such as doctor's visits, immunisations (vaccines received, dates), hospital stays or emergencies, and results of any medical tests that you manually input (e.g., "clinic confirmed ear infection" or "COVID-19 test result positive on [date]"). You may also log diagnoses or health conditions if you receive an official diagnosis for the child (e.g., diagnosing asthma or eczema).
- Developmental and Wellness Data: Information on growth and development, which often overlaps with health. This might include height and weight tracking, developmental milestones (first steps, first words, etc.), dietary notes (e.g., new foods tried, appetite changes), sleep patterns, or mental and emotional well-being notes. While not medical in the strict sense, this data relates to the child's overall health profile.
- Caregiver's Notes: Any additional notes you enter that might combine health observations with your personal interpretations or plans (for example, "Plan to ask doctor about recurrent cough next visit"). These notes, while informal, are treated with the same level of privacy as formal health logs.
- Clinician Feedback (if applicable): If the app allows a clinician to input comments or feedback directly (for instance, a paediatrician reviewing the shared log and adding a note), that information would also be collected and stored. (Currently, SaluStory primarily has the caregiver entering data, and any clinician feedback would likely be given outside the app. We will update this policy if direct clinician input becomes a feature.)
- Derived Health Insights: The app might provide summary charts or analytics, for example, a graph of symptom frequency or correlations (like "symptom X often occurs at night" derived from timestamps). These derived data points are generated from the information you provide. While they are not new raw data collected from you, nor are they diagnostic conclusions, they constitute health-related information that we handle carefully.
- Account and Device Data (Limited to Context): In association with health data, we also collect your user account ID and timestamps, which are linked to each health entry (to allow you to review history). We may capture device information or location at the time of an entry only if you choose to include it (for example, you might note location in a log "on holiday in Brisbane" or allow location tagging for context, SaluStory does not automatically record GPS location for health entries). Device information (like model, OS) might indirectly be associated with health data if needed for debugging issues (e.g., if a data sync fails, logs might show device type), but we do not consider device identifiers as health data per se. They are handled under our general Privacy Policy.
No Collection of Government Identifiers or Financial Info in Health Data: We do not ask for Medicare numbers, health insurance details, or payment information as part of health logs. (Payment for subscriptions is handled through app stores or payment processors separately, not tied to health data in our system.) We also do not collect "biometric" identifiers (like fingerprints, unless your device's biometric is used just to unlock the app locally) or genetic information through the app. If in the future we enable storing genetic test results or similar, it would be entirely user-provided and we would update our practices accordingly.
Sensitive Information and Consent: Under the Privacy Act, health information is considered sensitive and requires consent for collection. By inputting health information into SaluStory, you are providing your consent for us to collect and handle that information for the purposes of providing our service. You may withdraw this consent at any time by deleting specific entries or your account (as described in Section 5 on Your Rights). We will not collect any health information from you without your permission, all health data in SaluStory is user-supplied (or supplied by someone authorised by the user, such as a clinician with access, if applicable).
2. Sources of Health Information
We obtain health data primarily directly from you, the user (caregiver). The sources include:
- User Input: Information you manually enter into the app, whether by typing, selecting options, or uploading content. This encompasses symptom logs, medications, etc., entered through the app's interfaces. You control what information is entered and when.
- Linked Parties at Your Direction: If SaluStory provides an option to have another party contribute data (for example, if you invite a secondary caregiver or a healthcare provider to view and add notes to the child's profile), then health information might also come from them. However, this occurs only with your authorisation (such as inviting them and granting access). All parties with access are expected to handle the data in line with this Policy. You can revoke access at any time if sharing features are in use.
- Device Sensors (Minimal): Generally, SaluStory does not automatically collect health metrics from device sensors (such as heart rate from a smartwatch) unless you actively connect such a device or app. Currently, there are no automated wearable integrations. If we introduce, say, integration with a thermometer or fitness tracker, we will clearly explain what data is pulled (e.g., temperature readings, step counts) and obtain your permission. Any such data would be treated as health information under this Policy.
- Cookies and Tracking Tech: Not directly applicable to health info, since our use of cookies (if any on our website) is for general site functionality. We do not track health conditions via cookies. Any web analytics would only see generic usage, not the content of your health logs, which are secure on our backend.
- Inferences by the App: SaluStory might infer certain information from data you provide, for instance, if you log certain symptoms frequently, the app might infer that the child has a recurring condition. These inferences are not medical conclusions and are used only to present information back to you (like highlighting trends). We do not use automated algorithms to make significant decisions about you or the child's health; any informational suggestions are non-diagnostic and for your reference only.
Importantly, we do not collect health information from any third-party data brokers or advertisers. All health data in SaluStory is confined to the context of your caregiving use of the app.
3. How We Use Health Information
We recognise that health data is highly sensitive. Our uses of health information are solely focused on providing and improving the SaluStory service for your benefit, and are consistent with the purposes for which you provided the data. These uses include:
- Providing Core Features: We use the health information to populate the app's features, for example, to create a timeline of the child's health events, to generate charts (like growth charts or symptom frequency graphs), and to enable search or filter functions (such as finding all entries related to "allergy"). Essentially, the data you input is organised and processed so that it can be useful to you in managing the child's care.
- Sharing with Clinicians (User-Directed): When you decide to share health information with a healthcare provider (such as through a PDF export or granting them read-access via the app if such feature exists), we use the data to generate the output for sharing. We will only disclose the specific health information you choose to share, and only to the people you designate. (Refer to Section 4 on disclosures.) This use is entirely under your control; SaluStory itself doesn't send your child's data to any doctor unless you explicitly initiate it.
- Alerts and Reminders: If you opt in to receive reminders (for example, a medication schedule or a follow-up reminder like "It's been 4 hours since the last dose, you can give the next dose now"), we will use the medication log data to trigger these notifications. Similarly, we might remind you of upcoming immunisations or check-ups based on the age data you entered. All such features are optional and can be configured in the app settings. The data remains on our secure system; we are just processing it to send you the reminder you asked for.
- Customisation and Tips: We may provide general wellness tips or app suggestions tailored to your usage. For instance, if we notice you log asthma-related symptoms frequently, the app might suggest "Would you like to track environmental factors like pollen count?". These suggestions are based on patterns in your usage but do not involve sharing your health data with any external advertisers or third parties. The logic and content of suggestions are developed in-house or with medical consultants, and any tailoring happens within the app. You can ignore or turn off these suggestions if you prefer.
- Support and Troubleshooting: If you reach out to us for support and it involves a health data issue (say, "I lost an entry" or "the data doesn't look right"), our support team may need to access relevant health data entries to assist you. Our team will only access what is necessary to resolve your issue, and they operate under strict confidentiality. For example, if you report that a particular symptom entry isn't displaying, we might look at that entry in the database to diagnose the problem. Support access is logged and monitored.
- Improving the Service (with De-Identification): We continually aim to improve SaluStory's features. Health data, in aggregated and de-identified form, may be analysed to understand user needs. For instance, if many users track a particular type of symptom, we might prioritise adding more features around that (like more detail fields or educational content). We might look at statistics like "X% of users log medication schedules" to ensure our UI supports that well. When doing broader analysis, we remove personal identifiers. Insights gleaned from health data are used internally for product development, ensuring we maintain user privacy.
- Compliance and Legal Uses: We use health information as needed to comply with applicable laws. For example, if a law requires us to retain records of consent for handling health data, we will use your account records to demonstrate that. If we are responding to a legal request (as discussed in the Privacy Policy), we will only use and disclose the minimum necessary health information to comply. Also, under the Privacy Act's APP 6 and the concept of "permitted health situations," in rare scenarios we might use or disclose health information without consent to lessen or prevent a serious threat to life, health or safety, or for certain research or public health purposes, but only if all conditions of the law are met. We emphasise that such uses are extremely rare and mostly theoretical; our default stance is to get your consent for any use beyond providing the app's service.
No Marketing Use: We do not use your health information to market or advertise to you. For example, we won't suddenly show ads for cough syrup just because you logged a cough, and we won't sell or provide your health details to companies for promotional purposes. We treat your health logs as strictly confidential.
Use Consistent with Consent: The Australian Privacy Principle 6 requires that we only use or disclose personal information (especially sensitive info like health data) for the primary purpose of collection or a directly related secondary purpose that you would reasonably expect, or else with your consent. In plain terms, this means we use your health data mainly to help you manage health, which is the reason you gave it to us. Any other use either happens with your knowledge (as described above) or with separate consent if needed. If we ever want to do something else, for instance, participate in a medical research project using anonymised app data, we will either ensure the data is fully de-identified (so it's no longer personal) or we will approach you for permission.
4. Disclosure of Health Information
We will not disclose your identifiable health information to third parties except in the limited circumstances described here:
- Disclosure at Your Request (Clinicians or Family): The primary instance of sharing health data is when you, the user, choose to share it. For example, you might use SaluStory to compile a health report on your child and then share that report with a paediatrician, or you might use an in-app feature to invite a co-parent or caregiver to view the child's records. In these cases, we disclose the information only to the people you designate and only the specific data you choose to share. Your consent is obtained implicitly by the action you take (such as clicking "Share" or "Invite" and confirming the recipients). We advise you to share only with trusted individuals and to revoke access when it's no longer needed. You can manage sharing settings within the app (if a sharing feature is available) or simply refrain from using sharing features.
- Service Providers with Data Access: As explained in the Privacy Policy, certain service providers process data on our behalf. The ones most relevant to health information include our cloud hosting provider (Bubble and AWS) and possibly an analytics or error tracking service. In such cases, these providers might technically handle or transmit health data as part of their service (e.g., the data is stored on AWS servers, or error logs might contain snippets of data if an operation failed at a certain point). These third parties are not allowed to use your health information for any purpose other than delivering the service to us. We ensure via contractual terms and due diligence that they implement strong privacy and security protections. Notably, if any service provider is located overseas (like AWS in the U.S.), we remain responsible under APP 8 for their compliance. We will not use providers in jurisdictions with inadequate privacy safeguards unless we have confidence in their compliance (for instance, AWS has strict security certifications).
- Within Our Company and Related Entities: Your health data may be accessed by limited authorised personnel within SaluStory (specifically, engineers or support staff when necessary, as noted in Section 3, and possibly executives for oversight). All personnel are bound by confidentiality and data access policies. We do not currently share data with any parent or affiliate companies (SaluStory is a standalone company). If in future we had affiliated entities (e.g., a research arm or a partner company) that needed access to data, we would treat them as we would any external third party, i.e., no access without your consent or unless required to provide you a service you signed up for.
- Legal and Safety Disclosures: We may disclose health information if required by Australian law or a court or tribunal order. For instance, if we receive a lawful subpoena or notice for information as part of a court case, we would have to comply. We would only provide the specific information demanded (which could include health data if that's what's requested) and nothing more. Additionally, the Privacy Act allows use or disclosure of health information without consent in certain emergency situations or to assist in locating a missing person, etc., under what are termed "permitted general situations" or "permitted health situations." One example: if we believed that not sharing certain information would likely result in a serious threat to someone's life, health or safety, and that sharing with a relevant person (like a doctor or emergency service) could help prevent that, we could do so. This is a high bar and would only be done in extreme, good-faith circumstances (such as if we received an SOS through the app indicating a user or child is in immediate danger). In practice, our app is not an emergency service, so such scenarios are highly unlikely.
- Data Breach Notifications: If there is ever a data breach involving health information that triggers notification requirements, we may have to disclose certain details to regulators (OAIC) and potentially to you and the public (as required by law). This is not a "sharing" of your data in the conventional sense, but rather part of compliance. We would endeavour to handle even breach disclosures in a way that minimises the exposure of personal details.
- Corporate Transactions: If SALUSTORY PTY LTD is involved in a merger, acquisition, or sale of business assets, user data (including health data) may be transferred to the new owner or entity as part of the transaction. The new entity would still be required to handle your information in accordance with this Policy (we would ensure the commitments carry forward). You will be notified if such a transfer occurs and be given the option to delete your data beforehand if you wish.
No Unauthorised Disclosure: We do not disclose health information to any third-party for their own use, for example, we don't give out lists of users with certain health conditions to researchers, advertisers, or insurance companies. If someone like a researcher approached us wanting aggregate health data, we would only consider providing de-identified data (and likely only with ethical considerations in mind). If there were any proposal to share identifiable health information for some new purpose, we would seek your consent or allow you to opt-in explicitly.
In summary, disclosures of health data are tightly controlled. In most cases, you are in charge of any sharing. For any sharing we initiate (like to service providers or by legal necessity), we stick to the principle of minimal disclosure, only what's required for the purpose, and ensure appropriate safeguards are in place.
5. Your Privacy Rights (Specific to Health Data)
All the rights outlined in our general Privacy Policy apply fully to the health information you entrust to SaluStory. We highlight them here in context:
- Access to Health Information: You have the right to access the health records you've kept in SaluStory. In practice, you can view most of this through the app interface (that's part of the service). But you can also request a full export of all health data associated with your account. We can provide this in a readable format (for example, a CSV or PDF compilation of logs). This can be useful if you want to keep a copy outside the app or provide it to a new healthcare provider. We will process access requests within a reasonable time (usually within 30 days). In rare cases where we refuse access (e.g., if granting access would unreasonably impact others' privacy, or if it's frivolous), we will give you written reasons as required by law. Generally, with personal health data, refusals are uncommon.
- Correction of Health Data: Accuracy is important for health records. If you find any error in your health logs or profile (for instance, you accidentally logged a 50ml medication dose instead of 5ml), you can usually correct it yourself in-app by editing or deleting the entry. If something is not editable and you want it changed, contact us and we will correct it for you. We may ask for some proof or clarification if needed (for example, if two caregivers disagree on a correction). We will not alter historical health records unless we are sure a mistake exists and have the right to do so (we won't falsify data). If we for some reason can't comply with a correction request, we'll explain why (e.g., if we believe the record is accurate or if we are legally required to keep it as-is) and we'll let you add a note to the record with your version.
- Deletion of Health Data: You may delete individual health entries at any time through the app. Deleted entries will be removed from our active database (though may persist in backups for a short period as described earlier). If you wish to delete all health data, that is effectively deleting your account (since the account is built around that data). You can request account deletion, and we will permanently erase personal and health information. The only exceptions are as noted: data we must keep for legal reasons (which usually wouldn't be health logs, but rather transaction records or communications) or for a public health or research purpose that qualifies under law (highly unlikely in our case without consent). If any such data is retained, we would de-identify it if possible. After deletion, if you ever decided to rejoin SaluStory, you would be starting fresh as we would not have retained your old health logs.
- Consent and Withdrawal: By using the app and inputting health information, you consent to our collection and handling of that data. You have the right to withdraw consent for any further collection or use. For instance, you might withdraw consent for us to use your data for improvement analytics (beyond your individual use), in practice, since we don't do much with your identifiable data beyond serving you, withdrawing consent usually means you'd stop using the app or ask us to delete your info. We don't have secondary uses that you would toggle on or off except maybe marketing communications, which we already handle via opt-in and opt-out. If you have any concerns, reach out and we can accommodate as much as possible (e.g., we could isolate your data from any aggregation processes if you object, etc.).
- Data Portability: While not a formal right under Australian law, we support the idea that you should be able to take your health data and use it elsewhere. The access and export right covers this. If there's a specific format or direct transfer you need (like sending records directly to a doctor's system), we'll assist if feasible.
- Complaint Process: If you believe we have not handled your health information in accordance with this Policy or the law (for example, if you suspect a privacy breach or an unauthorised use), you have the right to complain. We encourage you to contact us first so we can resolve the issue quickly. Our contact details are at the end of this policy. We take complaints seriously and will investigate and respond. Additionally, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you're not satisfied with our response. The OAIC has authority to investigate privacy concerns and we will cooperate fully with them.
- Opt-Out of Research or Analytics: As mentioned, any use of your health data for research or broad analytics is done in de-identified form. However, if you still wish to opt out of even de-identified data being used in analytics, let us know. Because de-identified data isn't linked to individuals easily, the best approach is to opt out before de-identification (we can exclude your data from the data sets we aggregate). We will maintain an internal flag if needed to exclude a particular user's data from any such uses. There's no impact on the normal service; you'll continue to get the same app functionality.
Exercising Your Rights: To make any request (access, correction, deletion, etc.), you can contact us via email. For security, we will verify your identity (since health data is sensitive, we must be sure the person requesting data or deletion is indeed you or an authorised representative). Verification might involve confirming some data points we have on file or sending a code to your registered email. We will respond to your requests within a reasonable timeframe, and certainly within any time limits set by law. Access and correction are usually free of charge. If a request is unusually onerous (e.g., voluminous printing), we might charge a nominal fee, but we will discuss it with you first.
We are committed to honouring your rights and ensuring you have control over your (and your child's) health information.
6. Data Security for Health Information
Health information is among the most sensitive data, so we apply stringent security measures to protect it (as detailed in the Privacy Policy's Data Security section). To reiterate key points with a health focus:
- Encryption: All health data is transmitted over secure, encrypted channels (HTTPS). When stored on our servers, it's encrypted at rest using industry-standard encryption provided by AWS. This means that even if someone were to somehow access the storage without authorisation, the data would not be easily readable.
- Access Controls and Confidentiality: Only you (via your account credentials) and those you choose to share with can view identifiable health information. Internally, our staff access to health data is very limited. Technical administrators might access the database for maintenance, but they do not casually browse user data, and strict policies prevent any improper use. Any access for support is logged. We train our team on privacy, emphasising the sensitivity of health data. Breach of these protocols by an employee would result in disciplinary action including possible termination and reporting if needed.
- Segmentation and Security Architecture: Within our system, personal and health data is segmented by user account. One user cannot access another's data (assuming no sharing link has been explicitly given). We regularly test to ensure there are no cross-account data leaks or vulnerabilities. The Bubble.io platform also has its own security isolations to prevent data from leaking between apps or customers.
- Backups: We perform regular backups to prevent data loss. These backups are encrypted and stored securely. Access to backup files is as restricted as live data. Backups are kept only for a defined period and then rotated out or destroyed. So your health data isn't stored indefinitely in multiple places, we control where it resides.
- Device Security: While we protect data on our side, users should also be mindful of security on their side. For example, if you use the app on a mobile device, we encourage you to use a passcode or biometric lock on the device. We also offer a logout or app PIN feature (if available) so that if someone gains access to your phone, they still cannot open SaluStory without a secondary code. Be cautious about storing exported reports or screenshots of the app on your device, as those fall outside our app's protections (once data is exported to a PDF or image by you, securing that file is up to you).
- No Unnecessary Data: We minimise the health data we collect to just what's useful for the app's purpose. By not collecting extraneous identifiers or linking health data to public identities, we reduce risk. For example, we don't attach your child's full surname or your address to health logs, so even in the unlikely event of some data exposure, it would be hard to tie a symptom entry to a particular individual without other context.
- Testing and Compliance: We periodically review our security measures, possibly with external security experts. We stay updated on best practices for health data security (for instance, guidelines by the OAIC or standards like ISO27001 even if not certified, as inspiration). Given that we operate under Australian law, we are not under HIPAA (a US law), but our security measures are in many ways similar to what HIPAA or other health data regulations would expect, encryption, access control, audit logs, etc., because these are universally good practices.
If you have any specific questions about SaluStory's data security or if you suspect any security issue, please reach out to us immediately. We will promptly investigate and inform users of any incidents in accordance with the Notifiable Data Breaches scheme. Our goal is to provide a secure environment so you can use SaluStory with peace of mind, focusing on caregiving rather than worrying about data privacy.
7. Compliance with Australian Privacy Principles
We want to underscore our compliance with certain key Australian Privacy Principles (APPs) particularly relevant to health data:
- APP 6, Use and Disclosure: As elaborated, we only use or disclose your health information for the purpose it was collected (providing our service to you), or for directly related purposes you'd expect, or otherwise with your consent. We do not use health data for unexpected secondary purposes. If, for example, a secondary purpose arises such as contributing to a public health study, we would only do so in a permitted way (de-identified data or with explicit consent). Your reasonable expectations are central, we believe everything described in Sections 3 and 4 above aligns with what a user would reasonably expect when using a health tracking app.
- APP 8, Cross-Border Disclosure: SaluStory's use of AWS servers in the United States constitutes a cross-border disclosure. In compliance with APP 8, we take reasonable steps to ensure the overseas recipient (our cloud infrastructure) does not breach the APPs in relation to your health information. We have agreements in place that mirror privacy protections, and we remain accountable. In practice, this means your data gets the same level of protection as it would under Australian-based storage. If AWS or Bubble were to violate those standards, under Australian law SALUSTORY PTY LTD would be held responsible to you. The bottom line is, using our app should not compromise your privacy rights just because the server is in another country. We ensure that.
- APP 11, Security of Personal Information: We adhere to APP 11 by implementing the measures described in Section 6 above. We continuously assess what steps are reasonable in our circumstances to protect health info from misuse, loss, or unauthorised access. Given the sensitivity, our threshold for "reasonable steps" is high, encryption, strict access control, etc., are all in place. Additionally, APP 11 requires that we destroy or de-identify personal information when it's no longer needed. As noted, when you delete data or we no longer need it, we remove it or de-identify it (except any legal archival requirements). We do not keep health records indefinitely "just in case" without purpose. We also avoid retaining any identifiers longer than necessary.
- APP 12 and 13, Access and Correction: These principles underlie the rights we described. We gladly comply with them, giving you access to your data and correcting it on request.
- APP 2, Anonymity and Pseudonymity: To the extent feasible, we allow pseudonymous use (you can, for example, sign up with just an email that doesn't have your full name, and use nicknames). However, complete anonymity might limit functionality or support. We balance APP 2 by at least giving you the choice not to divulge more info than necessary.
- APP 3, Collection of Sensitive Info: APP 3 says we must collect sensitive information (like health data) only with consent and when reasonably necessary for our functions. We absolutely do that, your provision of the data is consensual and it's clearly for the function of the app (caregiving tracking). We don't collect health info from third parties without consent.
- APP 5, Notification of Collection: Through this Policy and our Privacy Policy, we are being transparent about what we collect and why at the time of collection. Also, within the app, we will likely have brief prompts or tool-tips explaining why certain data is asked for, fulfilling the notification requirement.
- APP 9 and 10, Identifiers and Quality: We don't use government identifiers for your health data, and we strive to keep the data accurate and up-to-date (though ultimately you control the entries).
- APP 7, Direct Marketing: We do not use health info for direct marketing. We might send general wellness newsletters if you sign up, but that's not based on specific health data (and you can opt out). We certainly don't provide your info to others for marketing.
Staying compliant with the APPs is not just a legal formality for us, it's part of treating users with respect and care, especially when it comes to something as personal as health. If you have any questions about our privacy compliance or want to know more about how we manage privacy, please contact us.
8. Contact and Further Information
If you have any questions or concerns about this Consumer Health Data Privacy Policy or about how we handle health information, please reach out to us:
Email: privacy@salustory.com
We are here to help and will gladly clarify anything about your health data privacy. If you're not satisfied with our response, remember you can contact the Office of the Australian Information Commissioner (OAIC) via www.oaic.gov.au or phone 1300 363 992.
By using SaluStory, you trust us with your loved one's health information. We take that responsibility seriously and are committed to protecting your data while helping you care for your child.