Privacy Policy

Last updated: 3 October 2026

1. About this policy

In this policy, "we", "us" and "our" mean The Personalised VA.

We respect your privacy. Whether or not the Privacy Act 1988 (Cth) applies to a particular activity, we voluntarily handle personal information in line with the Australian Privacy Principles as a minimum standard. This policy explains what personal information we collect, how we use and share it, how we keep it secure, and how you can access it or make a complaint.

It applies to:

•         visitors to www.thepersonalisedva.com.au (the "Site");

•         people who complete our enquiry questionnaire, contact us or subscribe to our emails;

•         the businesses we work for, and the people we deal with there; and

•         the clients of the businesses we work for, whose information we handle on those businesses' behalf (see section 4).

Please read it together with our Website Terms of Use and our Terms of Service.

2. What we collect and how

When What we collect
You visit the Site IP address, browser and device type, pages visited, the site you came from, and cookie and pixel data (see section 9)
You complete our enquiry questionnaire Name, email, phone number, business name and details, and your answers, which we use to contact you and arrange a discovery call
You email or phone us Your contact details and anything you tell us
You subscribe to our emails or download a free resource Name, email address, and which emails you open or click
You become a client Contact and billing details, business details including ABN, your Service Agreement, invoices and payment records, and our correspondence with you
We work in your systems Information about your clients, handled on your behalf (see section 4)

We collect most information directly from you. We may also receive information from someone who refers you to us. We do not collect payment card details from our own clients, who pay our invoices by direct deposit.

You can contact us without giving your name, but we will need your contact details to reply or to work with you.

3. How we use your information

We use personal information to:

•         reply to enquiries and hold discovery calls;

•         prepare proposals and Service Agreements;

•         provide, manage and invoice our services;

•         send the free resources and emails you have asked for;

•         understand how people use the Site and improve it;

•         advertise our services, including to people who have visited the Site (see section 9); and

•         meet our legal, tax and insurance obligations.

We do not sell or rent personal information to anyone.

4. Information we handle for the businesses we support

When we provide administration or bookkeeping support to a business, such as a psychology or allied health practice, we may see or handle personal information about that business's clients. This can include names, contact details, dates of birth, Medicare, DVA and health fund details, payment card details held in the practice's own software, appointment and billing records, call and message records, and referral documents. Some of this is health information, which the Privacy Act treats as sensitive information.

The business we are working for holds these records and is responsible for them under its own privacy policy. We:

•         handle it only to provide services to that business, and only on its instructions;

•         work inside the business's own systems (such as its practice management software, email and accounting software) wherever possible, rather than copying information into our own, and include only the client details a task needs in our own emails, which are stored by Proton Mail in Switzerland (see section 7);

•         do not read, write, transcribe or summarise session notes, clinical notes or clinical reports;

•         do not use it for our own purposes, including marketing;

•         set up automated messages to the business's clients only with wording the business has provided or approved;

•         do not ask for or send full payment card numbers by email or text;

•         share it only with people the business directs us to deal with (such as GPs, Medicare, DVA, NDIS plan managers and health funds), or where the law requires or authorises it; and

•         return or securely delete it when our work for that business ends.

Our work is ordinarily done by Moira. If an approved replacement VA provides cover, for example while Moira is unwell or on leave, they are engaged and paid by us, bound by a written confidentiality, privacy and security agreement, and use their own login. They only access a business's client information with that business's written approval, and their access is removed when the cover ends. We remain responsible for how they handle the information.

If a client of a business we support tells us something that suggests a serious risk to their own or someone else's life, health or safety, we pass it to their practitioner straight away, following the business's risk procedure. We do not assess risk or decide what is disclosed.

If you are a client of a business we support and want to access or correct your information, or have a concern about how it is handled, please contact that business directly. If you contact us, we will pass your request on to them.

5. Who we share information with

We share personal information only:

•         with the service providers listed in section 6, who help us run our business;

•         with our accountant, registered tax or BAS agent, insurer or legal adviser, where reasonably needed;

•         with an approved replacement VA providing services on our behalf (see section 4);

•         with anyone you or the business we work for asks us to share it with; or

•         where the law requires or allows it, such as under a court order or to lessen a serious threat to someone's life, health or safety.

6. Tools and service providers we use

Purpose Provider Where data may be stored
Website hosting and email newsletter Squarespace (including Squarespace Email Campaigns) United States
Enquiry questionnaire Fillout United States
Business email Proton Mail Switzerland
Phone calls and texts with the clients of practices we support VoIPline Australia
Task management Trello United States
Time tracking Clockify United States
Our own bookkeeping and invoicing Excel & Adobe PDF Viewer Local storage
Website analytics Google Analytics United States
Advertising Meta pixel (Facebook and Instagram) United States
Notes from onboarding phone calls with practitioners (with their permission) Zoom AI Companion Australia, with some data possibly stored in the United States
Notes from onboarding phone calls with practitioners (with their permission) Otter.ai United States
Screen recordings showing practitioners how to find or do things in their systems (no client information shown) Loom United States

We choose reputable providers with recognised security standards, and each handles information under its own privacy policy. Information about the clients of businesses we support is kept in those businesses' own systems, such as Halaxy, wherever possible. Emails we send or receive about those clients are stored by Proton Mail. Our task management and time tracking tools hold only client ID numbers from the business's own software, never names, initials, contact details or health information.

7. Overseas storage

Some of the providers in section 6 store data outside Australia, including in the United States and Switzerland. We take reasonable steps to choose providers with privacy and security protections consistent with the Australian Privacy Principles. Overseas providers may be subject to the laws of their own countries. For the clients of businesses we support, this means emails we send or receive about them are stored in Switzerland by Proton Mail. Their other information stays in those businesses' own systems (see section 4).

8. Security and retention

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, change or disclosure. These include multi-factor authentication, passwords kept in a secure password manager and never sent by email or text, devices that are password protected, kept up to date and locked when unattended, a separate named login or delegated access for each person, wherever the system allows it, in each client's systems, and access limited to what each task needs.

No method of storing or sending information online is completely secure, so we cannot guarantee the security of information sent to us. If we have a data breach that is likely to cause serious harm, we will tell the people affected and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme. If the breach involves information we handle for a business we support, we will tell that business promptly after becoming aware of it.

We keep personal information only as long as we need it. We keep our own business and financial records for 5 years, as required by tax law, and then securely delete them. If you make an enquiry but do not become a client, we keep your details only as long as needed to respond and follow up, then securely delete them. Information we handle for a business we support is returned or securely deleted when our work for that business ends, unless the law requires us to keep it.

9. Cookies, analytics and advertising

Cookies are small files stored by your browser. Pixels are small pieces of code that tell a platform when you visit a page. We and our providers use them to keep the Site working and, through Google Analytics, to understand how visitors use it. We also use the Meta pixel, which lets us show our ads on Facebook and Instagram to people who have visited the Site and measure how those ads perform.

You can block or delete cookies in your browser settings, though parts of the Site may not work as well. You can also manage ad preferences in your Facebook and Instagram account settings.

10. Email marketing

We only send marketing emails to people who have signed up or otherwise agreed to receive them, in line with the Spam Act 2003 (Cth). Every marketing email identifies us and includes an unsubscribe link, and we act on unsubscribe requests within 5 business days. We may still send you emails about services you have engaged us for.

11. Accessing and correcting your information

You can ask for a copy of the personal information we hold about you, or ask us to correct it, by emailing personalisedva@proton.me. We will respond within 30 days. There is no charge to make a request. We may ask you to confirm your identity, and in limited cases allowed by the Privacy Act we may refuse access, in which case we will tell you why.

For information we hold on behalf of a business we support, please see section 4.

12. Children

The Site and our services are for businesses and are not directed at people under 18. We do not knowingly collect personal information from people under 18 through the Site. Information about young people who are clients of a business we support is handled under section 4.

13. Complaints

If you have a concern about how we have handled your personal information, please email us at personalisedva@proton.me with the details. We will respond in writing, usually within 10 business days, and aim to resolve your complaint within 20 business days. It may take longer if the nature of the complaint reasonably requires it.

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5218, Sydney NSW 2001.

14. Changes to this policy

We may update this policy from time to time. The current version is always on the Site, with the date it was last updated. If we make a significant change that affects our current clients, we will let them know by email.

15. Contact us

The Personalised VA

Founder: Moira (ABN 49 268 734 717)

PO Box 5171, Erina NSW 2250

personalisedva@proton.me