Our Privacy Commitment
Last Updated: 31 May 2025
ABN: 67285505178
1. INTRODUCTION AND SCOPE
This Privacy Policy explains how MediScan ID (ABN: 67285505178) handles your personal information in accordance with the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs). This policy applies to all information collected through our service.
2. TYPES OF INFORMATION COLLECTED
2.1 Personal Information Information that identifies you or could identify you:
- Full name and contact details
- Date of birth and demographic information
- Emergency contact information
- Account and subscription details
- Payment information (processed via Stripe)
2.2 Sensitive Information (Health Information) Medical and health-related information including:
- Medical conditions and diagnoses
- Symptoms and management instructions
- Medication details and dosages
- Allergies and adverse reactions
- Any other health information you choose to provide
2.3 Technical Information
- Limited technical data necessary for service provision
- We do NOT collect: IP addresses, device identifiers, browsing data, or access logs
3. COLLECTION METHODS
3.1 Direct Collection
- Information you provide through account registration
- Profile updates and modifications
- Customer service communications
- Payment processing (via Stripe)
3.2 Third Party Collection
- Payment processing data from Stripe
- We do not collect information from other third parties
4. PURPOSE OF COLLECTION AND USE
4.1 Primary Purposes
- Providing emergency medical information access via NFC wristband
- Managing your subscription and account
- Processing payments and billing
- Customer support and service communications
4.2 Secondary Purposes
- Service improvement and development (with de-identified data only)
- Legal compliance and dispute resolution
- Fraud prevention and security
5. DISCLOSURE AND SHARING
5.1 Emergency Access Disclosure CRITICAL UNDERSTANDING: Your complete medical profile is accessible to anyone who scans your NFC wristband. This is the primary purpose and inherent function of our service.
5.2 Third Party Disclosure We do NOT share your information with third parties except:
- Stripe for secure payment processing
- When legally required by court order or law enforcement
- With your explicit written consent
- To contractors under strict confidentiality (rare occasions only)
5.3 Overseas Disclosure
- Your medical data remains on Australian servers only
- Stripe may process payments through international systems
- No other overseas disclosure without your explicit consent
6. DATA SECURITY AND PROTECTION
6.1 Security Measures
- Australian server storage with industry-standard security
- Encrypted data transmission and storage
- Access controls and authentication systems
- Regular security assessments and updates
6.2 Security Limitations YOU ACKNOWLEDGE: No digital system is completely secure. While we implement reasonable security measures, you accept the inherent risks of online data storage.
6.3 Data Breach Response
- We maintain incident response procedures
- Eligible data breaches will be reported to you and the Australian Information Commissioner as required by law
- We will take reasonable steps to minimize harm from any breach
7. DATA RETENTION AND DELETION
7.1 Retention Periods
- Active subscriptions: Data retained while account remains active
- Cancelled subscriptions: Data deleted within a reasonable timeframe
- Payment records: Retained as required by law (typically 7 years)
- Backup systems: Some data may persist temporarily in backups
7.2 Deletion Process
- Account deletion removes data from active systems
- Complete purging from all systems and backups occurs within our standard retention timeframe
- Some basic records may be retained for legal or fraud prevention purposes
8. YOUR PRIVACY RIGHTS
8.1 Access Rights
- Access your personal information through your account portal
- Request copies of information we hold about you
- We will respond to access requests within 30 days
8.2 Correction Rights
- Update information directly through your account
- Request corrections to inaccurate information
- We will correct verified inaccuracies promptly
8.3 Complaint Rights
- Lodge privacy complaints with our Privacy Officer
- We will investigate and respond within 30 days
- Unresolved complaints may be escalated to the Australian Information Commissioner
9. SPECIAL CONSIDERATIONS
9.1 Health Information Sensitivity We recognize health information requires special protection under Australian privacy law. However, the nature of our emergency access service means this information becomes publicly accessible via NFC scanning.
9.2 Children and Minors
- No specific age restrictions apply
- Parents/guardians responsible for minors’ information
- Special care taken with children’s health information
9.3 Marketing and Communications
- We may send service-related communications (essential)
- Marketing communications only with consent
- Easy unsubscribe options provided
10. PRIVACY OFFICER CONTACT
Privacy Officer
MediScan ID
ABN: 67285505178
Email: profiles@mediscanid.com
Response time: Within 3 business days
Australian Information Commissioner
Website: oaic.gov.au
Phone: 1300 363 992
11. POLICY UPDATES
- This policy may be updated to reflect changes in law or practice
- Material changes will be communicated prominently
- Continued use after changes constitutes acceptance
- Previous versions available upon request