1. Who we are
Ivy Dental is a dental practice with clinics across Brisbane, Queensland. We provide general, cosmetic, and emergency dental care.
When this policy says “we”, “us”, or “Ivy Dental”, it means the practice and its clinical and administrative team. “You” means a patient or website visitor.
2. What we collect
The personal information we may collect includes:
- Your name, date of birth, and contact details, including phone, email, and address.
- Health history and medical information relevant to your dental care.
- Dental records, including clinical notes, X-rays, photographs, and treatment plans.
- Medicare card details and Child Dental Benefits Schedule eligibility.
- Private health fund membership details.
- Payment and billing information.
- Website usage data, such as pages visited, browser type, and device information.
We only collect information that is reasonably necessary for the purposes described in this policy.
3. How we collect it
We may collect personal information:
- Directly from you when you complete patient forms, book appointments, attend consultations, or contact us by phone or email.
- From your health fund provider to process claims and verify eligibility.
- From Medicare to verify CDBS eligibility and process bulk-billed services.
- From a referring practitioner when another dentist or health professional refers you.
- Through our website if you choose to allow optional analytics, and when you follow a link from our website to an external booking service.
Where possible, we collect personal information directly from you. We will explain what information is needed and why at the time of collection.
4. Why we collect it
We use personal information to:
- Provide dental care and treatment.
- Maintain accurate clinical records as required by health records legislation.
- Process payments and health fund claims.
- Communicate about appointments, treatment plans, and recalls.
- Process Medicare claims, including claims under the Child Dental Benefits Schedule.
- Comply with legal and regulatory obligations, including obligations under Queensland health records legislation.
- Improve the website and understand how visitors use it.
We will not use personal information for purposes unrelated to your dental care without your consent.
5. How we store it
We take reasonable steps to protect personal information from misuse, loss, unauthorised access, modification, and disclosure.
- Digital records are stored in access-controlled practice management systems. Hosting and subprocessors are governed by the provider's contractual and privacy terms.
- Physical records, where applicable, are kept in locked storage with restricted access.
- Access to patient records is limited to authorised clinical and administrative staff.
- Systems are updated and maintained to current security standards.
We retain health records for the minimum periods required by Queensland legislation. Records are securely destroyed after the required retention period.
7. Cookies and analytics
Optional analytics are off unless you select Accept in the website notice. Declining before acceptance keeps the optional third-party analytics scripts unloaded. If you withdraw after accepting, code already loaded may remain until you close the page, but Ivy Dental stops sending optional analytics events. Your choice is stored in this browser. Booking, calling, and the core website continue to work when analytics are declined.
If you accept, we use Plausible Analytics to understand website use and improve pages and appointment pathways. Depending on your device, the information sent may include the page address and title, referring site, date and time, browser and device details, IP or network information, approximate location, campaign information, and interactions such as booking-link, call-link, FAQ, and scroll events.
We configure our analytics events not to intentionally include names, email addresses, phone numbers, form responses, or clinical-record content. A page address or interaction can nevertheless indicate an inferred interest in a dental service. We do not send clinical-record content through website analytics.
Plausible processes analytics information under its own terms and privacy practices. Its service providers and systems may process or store information outside Australia, where privacy protections may differ from Australian law. You can read the Plausible data policy.
When you choose an online-booking link, we open Dentally and add limited referral parameters to that link: the website source, source page, relevant clinic, campaign or placement, and a random click identifier. This handoff occurs even if optional analytics are declined so the booking destination and basic referral context remain intact. We do not intentionally place your name, contact details, free-text information, or clinical-record content in those parameters. Dentally may receive and process the parameters together with information you provide during booking under the privacy information shown by its booking service.
You can change your decision at any time on this device. Opening the preferences below immediately pauses optional analytics until you make a new choice. Changing your choice cannot retrieve information already sent before the change.
8. Your rights
Under the Australian Privacy Principles, you can:
- Request access to personal information and health records held by Ivy Dental.
- Request correction of information that is inaccurate, incomplete, or out of date.
- Ask how personal information has been used or disclosed.
- Make a complaint if you believe your privacy has been breached.
Contact us to request access or correction. We will respond to access requests within 30 days. An administrative fee may apply in some cases when archived records must be retrieved.
If you are not satisfied with how we handle a privacy complaint, you can contact the Office of the Australian Information Commissioner.
9. Contact
Contact Ivy Dental if you have a question about this policy, want to access or correct your records, wish to make a complaint, or suspect unauthorised access to information held by us.
Use the email address or phone number below and explain that your enquiry relates to privacy or health records.
10. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or legal requirements. The revised policy will be posted on this page with an updated date.
We encourage you to review this page periodically. Continued use of our services after changes are posted constitutes acknowledgement of those changes.
11. Data breach response
Ivy Dental has a data breach response plan in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
If an eligible data breach occurs, we will notify affected individuals and the Office of the Australian Information Commissioner as required under the Privacy Act. The notice will explain the nature of the breach, the type of information involved, and recommended steps.
We will take reasonable steps to contain a suspected breach, assess the risk of serious harm, investigate what occurred, and undertake remediation.
Contact Ivy Dental promptly if you suspect unauthorised access to personal information held by us.