Privacy Policy

1. Introduction

  • (a) The personal healthcare management mobile application (CDMpal App) and our website (www.cdmpal.com.au) is created, operated and controlled by CDMPRO Pty Ltd (ACN 666 351 444) (we, our or us).
  • (b) The CDMpal App is a mobile software application that allows users to: (i) securely receive, view, store, track and manage their health, medical and pharmaceutical related information and data; (ii) share health, medical and pharmaceutical related information and data with their treating medical practitioner or healthcare professional by integrating with third party software; (iii) manage their treatment and medication using calendar reminders tools; (iv) request allied health and medical  specialist appointments; and (v) record, store and track fitness, activity and wellbeing by integrating with fitness tracking devices and other wearable and non-wearable healthcare devices (collectively, the Services).
  • (c) We are committed to ensuring your Personal Information is protected. We manage your Personal Information in accordance with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth) (Privacy Act).
  • (d) By downloading, visiting, accessing or using the CDMpal App and Services, you agree to this Privacy Policy.
  • (e) This Privacy Policy outlines how we collect, store, process, use and disclose your Personal Information, and how you may access your Personal Information
    kept by us or how you may make a privacy complaint.
  • (f) For the purpose of this Privacy Policy, Account, CDMpal ID, Paired User and Medical Provider has the meaning in the CDMpal App Terms and Conditions
    and User, you or your means the individual who accesses or uses the CDMpal App and the Services, and whose details are listed in the Account. 

2. The Information We Collect

2.1. Personal Information

  • (a) Personal information has the same meaning that it has under the Privacy Act, namely, information means information or an opinion about an identified individual or an individual who is reasonably identifiable, whether the information or opinion is true or not and recorded in a material form or not.
  • (b) Sensitive Information has the same meaning that it has under the Privacy Act, namely information or opinions about your health, political affiliations, sexual preferences, religious beliefs, racial or ethnic origin, criminal history or other such private information. A reference to Personal Information in this Privacy Policy includes Sensitive Information except where otherwise indicated.
  • (c) We collect and use Personal Information and Non-Personal Information from you and your Paired Users who upload, publish and store information on, or via, the CDMpal App, and any other individual who interacts with us.
  • (d) We will only collect and hold Personal Information about you that is reasonably necessary to undertake our business activities and functions, to make the CDMpal App and the Services and our other products and services available to you, or as otherwise permitted by law.
  • (e) The type of Personal Information and Non-Personal Information that we collect and use depends on the type of dealings that you have with us. 

2.2. User

We collect, store and hold Personal Information about Users of the CDMpal App as well as information or data that does not contain Personal Information. For example, the type of Personal Information and non-Personal Information that we collect includes:

  • (a) contact details and account registration information (for example, your name, email address, phone number, date of birth, gender at birth and location, username and password);
  • (b) health, medical, wellbeing and pharmaceutical related information and data (including, but not limited to, your medical history (such as your height, weight, blood pressure, fluid intake and output, temperature, blood oxygen saturation, allergies, dietary and nutritional information), notes of your symptoms or diagnosis, specialist reports and test results, specialist and healthcare professional referrals, medical certificates, information about a healthcare services you have received or are scheduled to receive, healthcare plans, action plans, photographs, videos, prescriptions and other pharmaceutical purchases and usage, hospital admission and discharge letters, demographic information, power of attorneys and advanced care directives and any other health and medical records, or any other data or information that is or may be deemed to be Personal Information or Sensitive Information (collectively, User Data);
  • (c) data and information relating to your dealings, or enquiries you have made, with us, including information about: (i) the Services you have ordered or used; (ii) the third party products and services you have used or enquired about; and (iii) Paired Users that you have paired and connected with through the CDMpal App and otherwise interacted with on, or via, the CDMpal Appl (including User Data you have shared with Paired Users on, or via, the CDMpal App)
  • (d) payment and billing information; and
  • (e) other information that you provide to us or that we may collect in the course of our relationship with you.

2.3. Paired Users

We collect and hold Personal Information as well as information or data that does not contain Personal Information about Paired Users that access and use on, or via, the CDMpal App. For example, the type of Personal Information and non-Personal Information that we collect includes:

  • (a) information from other Users who you have paired with (such as the full name of the Paired User, the Paired User’s relationship to the User (for example, spouse, parent, sibling), age/date of birth and CDMpal ID);
  • (b) information of Medical Providers (for example, the Medical Providers’ MGTcare ID number, name of the medical practitioners, address, type of medical or allied health services and phone number)
  • (c) data and information relating to your dealings, or enquiries you have made, with us, including information about the Users that you have paired and connected with through the CDMpal App and otherwise interacted with on, or via, the CDMpal Appl (including User Data you have uploaded, published, downloaded or shared with a User on, or via, the CDMpal App); and
  • (d) other information that you provide to us or that we may collect in the course of our relationship with you.

2.4. Other information

  • (a) We may also collect some information that is not Personal Information because it does not identify you or anyone else. For example, we may collect anonymous answers to surveys or aggregated information about how you use the CDMpal App and Services and how you interact with Paired Users.
  • (b) If you are a candidate seeking employment with us, we will use your Personal Information to process your application and assess your suitability for any role. We may retain your information for future reference.

3. How We Collect Personal Information

3.1. Direct collection from you

  • (a) We will collect Personal Information and Non-Personal Information about you in a number of different ways. We may collect Personal Information and Non-Personal Information directly from you or in the course of our dealings with you. For example, when  you:
    • (i) access and use the CDMpal App and Services (including when you open an Account or create or update your Account on, or, via, the CDMpal App);
    • (ii) update, upload, download, publish, share or submit User Data on, or, via, the CDMpal App;
    • (iii) connect or pair with Paired Users through the CDMpal App, interact with or request User Data from your Paired Users;
    • (iv) visit the CDMpal App, our website or submit information, questions or queries through the CDMpal App or our website or complete any online forms or documents or when you enter or participate in, surveys and questionnaires; and
    • (v) otherwise contact, interact or communicate with us (such as by telephone, email or in person) with a query or request or lodge a complaint with us on, or via, the CDMpal App; and
    • (vi) when otherwise legally authorised or required to do so.
  • (b) By providing your Personal Information to us, you acknowledge that you are authorised to provide such information to us.

3.2. Collection from third parties

  • (a) We may also collect Personal Information and Non-Personal Information about you from third parties, including:
    • (i) when Paired Users update, upload, publish or submit User Data on, or, via, the CDMpal App;
    • (ii) when you provide your Personal Information to our Authorised Affiliates or other third parties;
    • (iii) if you use third party products or services that interact with the CDMpal App, Services or our other products and/or services (for example, third party payment processors, MGTcare software  platform, medical recording devices such as smartwatches, smartphones and medical instruments).
  • (b) If you provide us with Personal Information about another individual (as their authorised representative), we rely on you to:
    • (i) inform them that you are providing their Personal Information to us; and
    • (ii) advise them that they can contact us for further information.
  • (c) You must take reasonable steps to ensure the individual is aware of, and consents to, the matters outlined in this Privacy Policy, including that their Personal Information is being collected, the purposes for which that information is being collected, the intended recipients of that information, the individual’s right to access that information, and who we are and how to contact us.
  • (d) Upon our request, you must also assist us with any requests by the individual to access or update the Personal Information you have collected from them and provided to us.

3.3. Third party payment processor

We use a third party payment processor to process payments made to us. In connection with the processing of such payments, we do not collect, process, use, share, store or disclose any Personal Information or payment information (such as credit card and bank account details). Rather, all such information is provided directly to our third party processor, Apple Pay and Google Pay, whose use of your Personal Information is governed by their privacy policy, which may be viewed at https://support.apple.com/en au/HT203027 and https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt
=privacynotice&ldl=en.

4. How We Use Your Personal Information

4.1. Purposes of use and disclosure

  • (a) We do not sell your Personal Information. We only use, process and disclose your Personal Information for the purposes for which it is collected.
  • (b) We use, process and disclose your Personal Information and Non-Personal Information to provide or deliver the CDMpal App, the Services and our other products or services to you.
  • (c) We also use, process and disclose your Personal Information (excluding Sensitive Information) and Non-Personal Information to:
    • (i) assist with, or respond to, your queries or respond to, or investigate, complaints raised by you about the CDMpal App, the Services, our other products or services or your Paired Users;
    • (ii) conduct performance analytics activities (for example, we use your Personal Information (excluding Sensitive Information), in aggregated anonymised form, to improve CDMpal App, the Services, our other products or services and the quality of our data, to develop new products and services that meet your needs and understand and manage our risk better);
    • (iii) manage, administer, improve, test, develop and upgrade the CDMpal App and our other products and services , informing you about scheduled maintenance or outages and managing our relationship with you;
    • (iv) inform you about the CDMpal App, the Services, our other products or services or about offers, promotions, surveys, questionnaires about us, the CDMpal App, Services, or other matters which we believe are of interest to you;
    • (v) charge and bill you to access and use the CDMpal App;
    • (vi) verifying your identity;
    • (vii) for internal record keeping;
    • (viii) to comply with our legal and regulatory obligations;
    • (ix) for any purpose to which you have consented; and
    • (x) for any other purpose notified to you at the time of collection.
  • (d) In the event of a merger, acquisition or sale of the whole or part of our business or assets, we reserve the right to transfer your Personal Information as part of the transaction, without your consent or notice to you.

4.2. Disclosure to Authorised Affiliates

  • (a) In order to provide or deliver the CDMpal App, the Services and our other products or services to you, we may disclose your Personal Information (but excluding Sensitive Information) and Non-Personal Information to:
    • (i) our parent entity and related bodies corporate, service providers, third party contractors, agents, or suppliers; and
    • (ii) authorised external service providers who perform functions on our behalf, such as financial and credit card institutions, third party payment processors in order to process any payments, internet and technology services providers, app and website software developers, hosting companies (e.g AWS), and software security service providers, credit reporting agents, debt collection agents and market research,  (collectively, Authorised Affiliates).
  • (b) We may disclose your Personal Information and Non-Personal Information to the MGTcare software platform for purpose of sharing User Data with your Paired Users. You control of how, when and how much User Data you share with your Paired Users.
  • (c) Paired Users may provide us with Personal Information and Non-Personal Information collected from you. If you disclose Personal Information to a Paired User, we rely on you to provide the Paired User with consent for us to collect, store, use, process, alter and disclose your Personal Information. For example, a Pair User may upload, share or submit medical documents, clinical results or notes, task lists and medication reminders to the CDMpal App or your Paired User may use the in-app message system to share User Data with you.
  • (d) We may disclosure or share usage patterns, trends, and other statistical or behavioural data derived from use of the CDMpal App to our Authorised Affiliates who perform functions on our behalf. For example, we may disclose usage patterns, trends, and other statistical or behavioural data to our app and website software developers for the purpose of improving the performance of the CDMpal App and Services.
  • (e) We may also disclose your Personal Information and Non-Personal Information:
    • (i) to any other party with your consent and direction;
    • (ii) to law enforcement bodies or regulatory authorities to assist with their functions, or as otherwise required or authorised by law; or
    • (iii) where we consider necessary to comply with any applicable law, regulation, legal process, governmental request or industry code or standard.
  • (f) When we disclose your Personal Information or Non Personal Information to any of our Authorised Affiliates, we will ensure that they undertake to protect your privacy. These Authorised Affiliates are not permitted to use the information for any purpose other than the purpose for which they have been given access.

4.3. Overseas Disclosure

  • (a) All of our Authorised Affiliates are located in Australia (except for our app and website developers and third-party payment processors) and we do not disclose or transfer your Personal Information to overseas recipients in the course of providing access to, and use of, the CDMpal App and Services.
  • (b) If we subsequently decide to disclose your Personal Information to an overseas recipient, we will take such steps as reasonable in the circumstances to ensure that the overseas recipient treats your Personal Information securely and otherwise complies with the relevant Australian Privacy Principles.
  • (c) In the course of processing payments made to us, we commonly disclose payment information to our third-party payment processors who are located throughout the world.
  • (d) In the ordinary course of business, we may also disclose your Personal Information (excluding Sensitive Information) to our app and website developers based in Sri Lanka.
  • (e) By accessing or using the CDMpal App and Services or providing your Personal Information (excluding Sensitive Information) to us, you explicitly and freely consent to the disclosure of your Personal Information (excluding Sensitive Information) to our third-party payment processors and app and website developers.
  • (f) If you have any questions in relation to the transfer of your Personal Information, please contact us using the contact details set out in section 10 below.

4.4. Disclaimer

  • (a) We will not disclose your Personal Information to any third party (other than our Authorised Affiliates) without your written consent, unless:
    • (i) we are otherwise required by the relevant Privacy Laws;
    • (ii) we are permitted to under this Privacy Policy; or
    • (iii) such disclosure is, in our opinion, reasonably necessary to protect our rights or property, avoid injury to any person, or ensure the proper functioning of the CDMpal App.
  • (b) This Privacy Policy only covers the use and disclosure of information we collect from you. The use of your Personal Information by any third party is governed by their privacy policies and is not within our control.

5. Notifiable Data Breaches Scheme

In the event of any loss, or unauthorised access or disclosure of your Personal Information that is likely to result in serious harm to you, we will investigate and notify you and the Australian Information Commissioner as soon as practicable, in accordance with the notifiable data breach scheme contained in Part IIIC of the Privacy Act.

6. Marketing communications

6.1. Direct marketing

  • (a) We may use and disclose your Personal Information (excluding Sensitive Information) to send you information about the CDMpal App, the Services, our other products or services or information, and other information that may be of interest to you. 
  • (b) These communications may continue, even after you stop using the CDMpal App.

6.2. Communication channels

  • (a) We may send this information to you via the communication channels specified at the time you provide your consent. 
  • (b) These communication channels may include mail, email, SMS, telephone or by customizing online content and displaying notices or advertising on the CDMpal App.

6.3. Opting-out

You can opt out of receiving these communications by: 

  • (a) contacting us using the details below; or 
  • (b) using the unsubscribe function in the email or SMS.

7. Storage and Security

7.1. Protecting your Personal Information

  • (a) We take reasonable steps in the circumstances to keep your Personal Information and Non-Personal Information safe. We use a combination of technical, administrative, and physical controls to protect and maintain the security of your Personal Information and Non-Personal Information.
  • (b) Our officers, employees, agents and third-party contractors are expected to observe the confidentiality of your Personal Information and Non-Personal Information.
  • (c) Wherever possible, we procure that Authorised Affiliates who have access to your Personal Information and Non-Personal Information take reasonable steps to:
    • (i) protect and maintain the security of your Personal Information and Non-Personal Information; and
    • (ii) comply with the Australian Privacy Principles when accessing and using your Personal Information.
  • 7.2. No guarantee
  • (a) The transmission of information via the internet is not completely secure. While we do our best to protect your Personal Information and Non-Personal Information, we cannot guarantee the security of any Personal Information and Non-Personal Information transmitted through the CDMpal App.
  • (b) You provide your Personal Information and Non-Personal Information to us at your own risk, and we are not responsible for any unauthorised access to, and disclosure of, your Personal Information and Non-Personal Information.

7.3. Destruction of Personal Information

CDMPRO will deactivate your Account and your User Data will no longer be accessible by you through the CDMpal App. Your User Data will be retained for a period of 90 days from the effective date of termination, after which your User Data (including Personal Information) will be permanently de-identified (except we may retain your basic registration information in accordance with document retention and destruction laws).

8. Accessing and Correcting Your Personal Information

  • (a) We shall use our reasonable endeavours to keep your Personal Information accurate, up-to-date and complete. You have the right to access any Personal Information we hold about you, subject to some exceptions under the Privacy Act.
  • (b) You can access, or request that we correct, your Personal Information by writing to us using the details below. We may require proof of identity. If we do not allow you to access any part of your Personal Information, we will tell you why in writing.
  • (c) We will not charge you for requesting access to your Personal Information but may charge you for our reasonable costs in supplying you with access to this information.
  • (d) We will endeavour to respond to your request for access or correction within 30 days from your request.

9. Privacy Complaints

  • (a) If you have any issues about this Privacy Policy or the way we handle your Personal Information, please contact us using the details below and provide full details of your complaint and any supporting documentation.
  • (b) At all times, privacy complaints:
    • (i) will be treated seriously;
    • (ii) will be dealt with promptly;
    • (iii) will be dealt with in a confidential manner; and
    • (iv) will not affect your existing obligations or your commercial arrangements with us.
  • (c) Our Privacy Officer will endeavour to: 
    • (i) respond to you within 10 business days; and
    • (ii) investigate and attempt to resolve your concerns within 30 business days or any longer period necessary and notified to you by our Privacy Officer.
  • (d) If you are dissatisfied with the outcome of your complaint, you may refer the complaint to the Office of the Australian Information Commissioner.

10. How to Contact Us

We can be contacted by email at admin@cdmpal.com.au.

11. Changes to this Privacy Policy

  • (a) From time to time, it may be necessary for us to review and revise our Privacy Policy. We may notify you about changes to this Privacy Policy by posting an updated version on the CDMpal App.
  • (b) We encourage you to check the CDMpal App from time to time to ensure you are familiar with our latest Privacy Policy.