Privacy Policy | Updated: 1 July 2026
1. About this policy
Cognevity Pty Ltd ('Cognevity', 'we', 'us') provides cognitive health services for adults. This policy explains how we handle your personal information, including your health information.
Because we provide a health service and hold health information, we're bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles in full.
2. What we collect
Contact details — your name, email address, address and phone number.
Booking details — what you tell us when you book a call with us.
Health information — your medical history, current health, lifestyle and environment, cognitive health concerns, cognitive assessment results, and any other medical data you choose to share.
Session notes — notes made during and after our coaching sessions.
Healthcare provider details — where we're coordinating with your doctor or specialist.
Payment details — to process your fees.
Website usage information — collected through cookies when you visit our website.
Newsletter details — your email address, if you subscribe to our updates.
Health information is sensitive information under the Privacy Act. We collect it only with your consent, which you give when you complete our intake assessment and sign our Coaching Services Agreement.
You can deal with us anonymously, or under a pseudonym, for general enquiries. For coaching itself we need to know who you are — we can't deliver the service or meet our health record obligations otherwise.
3. How we collect and hold it
We collect information directly from you through intake assessments; coaching sessions; email; website booking and contact forms.
Cookies & analytics Our website uses cookies, including Google Analytics, to understand visitor behaviour. Cookies don’t give us access to information stored on your device. You can reject cookies through your browser settings, though this may affect site functionality.
Session documentation We use Heidi, an AI-assisted note-taking tool, to create a transcript of our sessions and summarise it into your session notes. Heidi stores data in Australia. Transcripts are deleted once your notes are ready.
Storage Your session notes are emailed to you or stored in Google Drive, with access restricted to you and us. Your Coaching Services Agreement is signed through Adobe Sign. These services store data overseas (see Section 5). We hold no paper records.
Retention We keep your health information for 7 years from your last session, as required by the Health Records and Information Privacy Act 2002 (NSW). After that, we securely destroy or de‑identify it.
Security We take reasonable steps to protect your information from misuse, loss, and unauthorised access. No system is completely secure, and sending information over the internet carries some risk.
4. Why we collect and use it
We use your personal information to:
Deliver and personalise your coaching, including your action plan and progress monitoring.
Coordinate with your healthcare providers, where you've agreed to this.
Communicate with you about scheduling and administration.
Process your payments.
Meet our legal obligations.
If you subscribe, we send newsletters and updates. You can unsubscribe at any time. Coaching clients are not automatically subscribed. We never use health information for marketing and never sell personal information.
5. Who we share it with, including overseas
We share your personal information only as set out below, or with your consent.
Service providers we use
Heidi (Australia) — creates transcripts of our sessions and summarises them into your notes. Transcripts are deleted once your notes are complete.
Google (global) — stores your session notes in Google Drive, delivers our email, and provides website analytics. These services are hosted in Google’s data centres outside Australia.
Squarespace & Acuity Scheduling (United States) — host our website, manage bookings and enquiries, and send our newsletter.
Adobe Sign (United States) — manages the signing and storage of your Coaching Services Agreement.
Zoom (United States) — delivers your sessions. We don’t record sessions, and Zoom does not store session data.
Apollo Health (United States) — for Apollo Health members who request a ReCODE Report, your lab data is handled under Apollo Health’s own privacy policy.
Where information is disclosed overseas, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles. Overseas recipients may not be subject to the same privacy protections as in Australia.
We may also disclose information where required by law (e.g., court orders, warrants, law enforcement). We are legally required to report child abuse, abuse of a vulnerable adult, or a risk of serious harm.
If our practice is sold or merged, your information may transfer to the new owner under this policy. We will notify you if this occurs.
6. Accessing and correcting your information
You can ask us for a copy of the personal information we hold about you, or ask us to correct it, at any time. Email rachel@cognevity.com.au and we'll respond within 30 days. If we can't give you access or make a correction, we'll explain why in writing.
Please tell us if your contact details or health information change, so we can keep our records accurate and up to date.
7. If you have a concern
If you're concerned about how we've handled your personal information, please email rachel@cognevity.com.au. We'll acknowledge your concern within 7 days, look into it, and respond in writing within 30 days.
If you're not satisfied with our response, you can raise the matter with the Office of the Australian Information Commissioner at oaic.gov.au.
8. Data breaches
If a data breach happens that's likely to cause you serious harm, we'll notify you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
9. Changes and contact
We may update this policy from time to time. The current version is always on our website, with the date it was last updated.
For any question about this policy, contact us.