Healthcare Ethics Australia
Privacy · Australia · Privacy Act 1988 and the APPs
What we do with your information
Privacy Policy
for this website and our online courses for practitioners in Australia
In short
The short version
We collect your name, your email address and a record of which courses you bought and completed. We use it to sell you a course, give you access, issue your certificate and meet our tax obligations. Stripe handles payments and we never see your card number.
The part that matters most to the people who read this page: we never tell Ahpra or a National Board that you are a customer. If you bought the course yourself, nobody else is told either.
The short version is not the agreement. Where it and the numbered text differ, the numbered text is what applies.
Privacy policy
Who we are
This policy explains what we do with personal information about you when you use this website, ask us a question, or buy and take one of our courses. It is written to the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Healthcare Ethics Australia is the organisation that operates this website and the courses on it. We are based at 119 Marylebone Road, London NW1 5PU, United Kingdom, and we are responsible for the personal information described in this policy. You can reach us at any time at [email protected].
We are based outside Australia but we offer courses to practitioners in Australia, so we handle your personal information in line with the Australian Privacy Principles. Where the Privacy Act gives you a right, you have it whether we are in Australia or not.
Many of the people who use this site are responding to a notification, a complaint or an investigation. We have written this policy with that in mind, and one section deals with it directly.
The information we collect
We collect only what we need:
- Your name and email address, when you buy a course, create an account or contact us.
- Your profession or registration type, where you tell us, so that we can point you to the right courses.
- Your course records - which courses you bought, when, whether you completed them and on what date.
- Anything you choose to write to us, including in an enquiry.
We do not ask you for details of your notification, your complaint or your case, and you do not need to give them to us in order to buy or take a course. If you write them to us anyway, we treat them as described below.
We do not collect government identifiers such as your registration number, and we do not collect health information about you.
Why we use it
We use your information to sell you a course, to give you access to it, to issue your certificate, to answer your questions, to keep our records, and to meet our tax and legal obligations. We do not use it for anything else without telling you.
We will only send you marketing if you have asked for it, and every message carries an unsubscribe link that works.
Feedback you give us may be used in anonymised form, as our Terms and Conditions describe; nothing that could identify you or your case is published without your express written consent.
We do not sell personal information, and we do not disclose it for another organisation's marketing.
Payments
Payments are processed by Stripe. Your card details are given to Stripe and handled under Stripe's own privacy policy. We never see or hold your full card number. We receive only confirmation that a payment succeeded, the amount, the last four digits of the card and the card type. Stripe handles your card details as a separate organisation under its own privacy policy. Where you pay by bank transfer, we see what your bank shows on the transfer and nothing more.
Your regulatory situation stays with you
This matters more than anything else in this policy, so we will be plain about it.
We never report to Ahpra, to any National Board, to a NSW Council, to the HCCC or to the OHO that you have bought or taken a course. We do not maintain a register that any of them can search. No regulator has an account with us, and none has ever asked us for one. That is true however you came to us.
Your certificate is yours. You decide whether to put it in front of anyone. If you never mention us to your Board, your Board does not hear about us from us.
If you bought the course yourself
Then it is entirely confidential. No employer, no indemnity insurer, no professional association and no organisation of any kind is told that you are a customer.
If your organisation gave you the seat
If an employer, agency, insurer, university or association bought a seat and assigned it to you, that organisation can see which courses you completed and on what date, and the certificates issued. That is the whole of it. They do not see your answers, your time spent, how many attempts you made, or anything about a notification, complaint or investigation concerning you - we do not hold that information in the first place.
You are told before you start, not afterwards. Before you begin a course on an organisation seat you are shown a single statement saying your completion will be visible to the organisation that provided it, and you have to accept it. Nobody is enrolled on that basis without seeing it.
And you always have the alternative. If you would rather your organisation knew nothing about it, do not use the seat - buy the course yourself, in your own name, at the standard price. It is then covered by the paragraph above and your organisation is told nothing.
If you bought through a member discount code
You bought in your own name and it is your purchase. We do not tell the organisation that issued the code who used it, which courses they took, or whether they completed them.
The only exception
We would disclose that you are a customer only where Australian law requires it, or a court or tribunal orders it. If that happened and we were permitted to tell you, we would.
Who we share it with
We share personal information only with the service providers we need to run the business: our website and learning platform host, our payment processor, our email provider, and our accountants. Each is given only what it needs to do its job, and each is bound to use it only for that purpose.
Where an organisation has bought and assigned you a seat, that organisation sees the limited completion information described under Your regulatory situation stays with you, and nothing else.
We disclose personal information where the law requires it, or where it is necessary to establish, exercise or defend a legal claim.
If our business were ever sold or transferred, customer records could move with it. You would be told before that happened, and the buyer would be bound by this policy.
Where your information is held
Your information is held outside Australia. We are based in the United Kingdom, so your name, your email address and your course records are handled there. Some of our service providers - our website and learning platform host, our payment processor and our email provider - hold information in the United Kingdom, the European Union or the United States.
We tell you this plainly because the Australian Privacy Principles require it, and because you are entitled to know before you hand anything over. Where we disclose your personal information to an overseas recipient we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.
If you would like to know where a particular part of your information is held, ask us and we will tell you.
How long we keep it
We keep your account and course records while your account is open, and for seven years after your last purchase, because Australian tax law requires us to keep records of sales.
Enquiries that do not lead to a purchase are deleted within twelve months. Where you have agreed to receive marketing, we keep that consent until you withdraw it, and we keep a record of the withdrawal so that we do not contact you again. Anything you asked us to delete is deleted, except where we are required to keep it.
Cookies
This site sets only the cookies it needs in order to work. They keep you logged in, remember what is in your basket, and keep the site secure. The shop does not function without them, and they are not used to build a profile of you.
We do not use analytics cookies, advertising cookies or profiling cookies. We do not track you across other websites, we do not run advertising that follows you, and we do not share anything about your visit with an advertising network.
Your rights: access and correction
Under the Australian Privacy Principles you may:
- Ask for a copy of the personal information we hold about you.
- Ask us to correct it if it is wrong, out of date, incomplete or misleading.
- Ask us to delete it, which we will do unless we are required to keep it.
- Deal with us anonymously or under a pseudonym where it is lawful and practicable - for a general enquiry, it is.
Ask at [email protected]. We respond within 30 days and we do not charge for access. If we refuse a request we will tell you why in writing.
How we protect it, and what happens if something goes wrong
The site runs over HTTPS. Access to customer records is limited to the people who need it. We do not hold card numbers. Email and the contact form are not fully secure channels, so please do not send us details of your notification, complaint or case — we do not need them.
If a data breach occurred that was likely to cause you serious harm, we would notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
How to complain
If you think we have mishandled your personal information, tell us first at [email protected]. We will acknowledge your complaint within 5 working days and respond substantively within 30 days.
If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner at oaic.gov.au, or by phone on 1300 363 992.
Changes to this policy, and how it fits with our terms
We may update this policy. The date at the top of this page shows when it last changed. Where a change is material we will say so on this page rather than change it quietly.
This policy sits alongside our Terms and Conditions. Where the two conflict on a question about personal information, this policy applies.
How to contact us
Email [email protected], with “Privacy” in the subject line. That address reaches us for anything in this policy - a copy of your information, a correction, a deletion, or a complaint.
We reply to every enquiry within 30 days, and usually much sooner.
In one paragraph
We collect your name, your email address and a record of the courses you bought and completed. We use it to sell you a course, give you access to it and issue your certificate. Stripe handles payments and we never see your card number. We never tell Ahpra or a National Board that you are a customer. If you bought the course yourself, nobody else is told either; if your organisation assigned you a seat, it sees your completions and dates and nothing more, and you are told that before you start. You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it, at [email protected].
Definitions
Key terms on this page
Plain definitions of the words this page uses. Each one restates a section above rather than adding to it.
- Personal information. Information or an opinion about you, where you are identified or could reasonably be identified from it. On this site that means your name, your email address and the record of which courses you bought and completed.
- Australian Privacy Principles. The thirteen principles in Schedule 1 of the Privacy Act 1988 (Cth) that govern how personal information is collected, used, disclosed and secured. This policy is written to them. The principles are published by the OAIC.
- Overseas disclosure. Giving personal information to a recipient outside Australia. We are based in London, so the disclosure is stated plainly in this policy rather than left to be inferred, and we take reasonable steps to see that it is handled consistently with the Australian Privacy Principles.
- Notifiable data breach. A breach of personal information likely to result in serious harm, which must be reported both to the people affected and to the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.
- Notification. In Australian health regulation, the word for a complaint or concern raised with Ahpra about a registered practitioner. Ahpra publishes guidance for practitioners who have had a concern raised about them. We never tell Ahpra or a National Board that you are a customer.
- Course licence. Seats bought by an organisation in a block and assigned to named people. Where a seat was assigned to you, the administrator sees your assignment, completion and date, and nothing else.
Questions about your information
Frequently asked questions
Short answers to what people actually ask. Each one restates a section above rather than adding to it.
Do you tell Ahpra or my National Board that I bought a course?
No. We never report to Ahpra, to any National Board, to a NSW Council, to the HCCC or to the OHO that you have bought or taken a course. We keep no register any of them can search, and no regulator has an account with us.
What information do you actually collect?
Your name and email address, your profession if you tell us, a record of which courses you bought and completed and on what dates, and anything you choose to write to us. That is all.
We do not ask for details of your notification or complaint, we do not collect your registration number, and we do not collect health information about you.
Where is my information held?
Outside Australia. We are based in the United Kingdom, so your name, email address and course records are handled there. Some service providers hold information in the United Kingdom, the European Union or the United States.
Do you sell my information?
No. We do not sell personal information and we do not disclose it for another organisation’s marketing. Marketing from us only happens if you asked for it, and every message carries an unsubscribe link that works.
How long do you keep it?
Account and course records while your account is open, and for seven years after your last purchase, because Australian tax law requires records of sales to be kept. Enquiries that do not lead to a purchase are deleted within twelve months.
Can I get a copy of what you hold, or have it deleted?
Yes. Ask at [email protected]. We respond within 30 days, we do not charge for access, and if we refuse a request we tell you why in writing.
My organisation gave me the seat. What can they see?
Which courses you completed, the dates, and the certificates. Nothing else — not your answers, not your time spent, not how many attempts you made. You are told this before the course opens, and you can buy the course yourself instead.
Elsewhere on this site
Related pages
The other documents that govern a purchase, and the courses these terms apply to.
Courses by National Board:
Who reviewed this page
Written and last reviewed by Dr Shehzad Iqbal, MBBS, MRCS, MRCGP, Postgraduate Certificate in Healthcare Law and Ethics, University of Dundee. Last reviewed 22 August 2026. Questions about this page: [email protected].
Certificates are issued by Healthcare Ethics Courses.