Level 1, 15 Rheola St, West Perth,

Privacy Policy

Preventus Privacy Policy

1. Purpose of this Policy

Praventus Pty Ltd, trading as Praventus Injury Management (Praventus, we, us or our), respects the privacy of the individuals whose information we handle.

This Privacy Policy explains how we collect, hold, use, disclose, protect, access and correct personal information, including sensitive and health information.

We are committed to handling personal information in accordance with:

  • the Privacy Act 1988 (Cth);
  • the Australian Privacy Principles;
  • the Notifiable Data Breaches scheme;
  • applicable workers’ compensation, workplace rehabilitation and health privacy requirements; and
  • other applicable Australian laws.

This Policy applies to information relating to workers, employees, claimants, candidates, clients, referrers, treating practitioners, service providers, website users and other individuals with whom we interact.

2. Our Services

Praventus provides services that may include:

  • Early Intervention Injury Management
  • Workplace Rehabilitation (WRP)
  • Return to Work Coordination
  • Functional Capacity Assessments
  • Workplace Assessments
  • Ergonomic Assessments
  • Manual Handling Assessments
  • Case Conferencing
  • Medical Liaison
  • Treating Practitioner Liaison
  • IME Coordination
  • Suitable Duties Development
  • Injury Management Consultancy
  • Employer Training
  • Injury Prevention Consultancy

The nature of these services means that we may need to collect and handle health information and other sensitive information.

3. Meaning of Personal and Sensitive Information

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or recorded in a material form.

Sensitive information is a category of personal information that includes information about an individual’s:

  • health;
  • disability or injury;
  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • professional or trade association membership;
  • trade union membership;
  • sexual orientation or practices;
  • criminal record; and
  • biometric or genetic information in certain circumstances.

Health information includes information or an opinion about:

  • an individual’s physical or mental health;
  • an injury, illness or disability;
  • health services provided or proposed to be provided;
  • medication, treatment, rehabilitation or work capacity;
  • expressed wishes regarding future health services; and
  • other personal information collected in connection with providing a health service.

4. Information We May Collect

Depending on the nature of our interaction with an individual, we may collect:

4.1 Identity and contact information

  • name;
  • date of birth;
  • address;
  • telephone number;

7. Collection of Sensitive and Health Information

We will only collect sensitive information, including health information, where:

  • the individual has consented and the information is reasonably necessary for our functions or activities;
  • collection is required or authorised by law;
  • collection is necessary to lessen or prevent a serious threat to life, health or safety and it is unreasonable or impracticable to obtain consent;
  • the information is required for the establishment, exercise or defence of a legal or equitable claim;
  • a permitted health situation or another exception under privacy law applies; or
  • collection is otherwise lawfully authorised.

Consent may be express or implied where permitted by law and appropriate in the circumstances. We may require express written consent where the information is particularly sensitive or where information is to be obtained from or provided to third parties.

8. Privacy Collection Notices and Consent

This Privacy Policy provides general information about our handling practices.

We may also provide a more specific privacy collection notice or consent form when collecting information. That notice may explain:

  • the particular information being collected;
  • the purpose of collection;
  • whether collection is required or optional;
  • the consequences if the information is not provided;
  • the people or organisations to whom it may be disclosed; and
  • any other information required by law.

A consent form or authority does not permit unrestricted use or disclosure of personal information. We will continue to limit our handling of information to what is reasonably necessary, authorised and lawful.

9. What Happens if Information Is Not Provided

An individual is generally not required to provide personal information to us unless required by law or under an applicable process.

However, if necessary information or authority is not provided, we may be unable to:

  • accept or properly assess a referral;
  • provide some or all of the Services;
  • communicate with treating practitioners or other stakeholders;
  • prepare a reliable report or recommendation;
  • coordinate rehabilitation or return-to-work activities; or
  • meet a legal, contractual or professional obligation.

Where appropriate, we will explain the likely consequences of not providing information.

10. Use and Disclosure of Personal Information

We generally use and disclose personal information for the primary purpose for which it was collected.

We may also use or disclose information for a related secondary purpose where:

  • the individual would reasonably expect the use or disclosure;
  • the individual has consented;
  • the use or disclosure is required or authorised by law;
  • it is reasonably necessary to lessen or prevent a serious threat to life, health or safety;
  • it is reasonably necessary for an enforcement-related activity conducted by an enforcement body;
  • it is necessary for a legal claim or confidential alternative dispute-resolution process;
  • a permitted health situation applies; or
  • another exception under privacy law applies.

Sensitive information will generally only be used or disclosed for a directly related secondary purpose, unless another legal basis applies.

11. Parties to Whom We May Disclose Information

Where reasonably necessary and lawful, we may disclose information to:

  • the individual to whom the information relates;
  • the referring or contracting client;
  • the individual’s employer or host employer;
  • insurers, claims agents and insurance brokers;
  • treating doctors and allied health practitioners;
  • hospitals, clinics and rehabilitation providers;
  • occupational physicians and independent medical examiners;
  • vocational, ergonomic, functional or workplace assessment providers;
  • legal representatives;
  • interpreters;
  • payroll, human resources, safety and management personnel;
  • government agencies, regulators, tribunals and courts;
  • professional registration or accreditation bodies;
  • auditors, accountants and professional advisers;
  • IT, communications, cloud storage and records-management providers;
  • payment, accounting and debt-recovery providers;
  • contractors and consultants assisting us to deliver the Services;
  • emergency services where necessary; and
  • another person authorised by the individual or permitted by law.

We seek to disclose only the information reasonably required for the relevant purpose.

The fact that an employer, insurer or another party funds the Services does not automatically entitle that party to unrestricted access to all health information. Information will be disclosed according to the applicable consent, legal authority, contractual arrangements and the purpose for which the Services are being provided.

12. Disclosure to Treating Practitioners

With appropriate authority or where otherwise permitted by law, we may communicate with treating practitioners to:

  • clarify diagnosis, prognosis, treatment or work capacity;
  • obtain or provide relevant workplace information;
  • discuss barriers to recovery or return to work;
  • coordinate treatment, rehabilitation or case conferencing;
  • request reports, certificates or recommendations; and
  • support safe and durable workplace participation.

We will not direct a treating practitioner’s clinical decision-making.

13. Government Agencies, Regulators and Legal Disclosure

We may disclose information where required or authorised by law, including in response to:

  • a court order, subpoena or warrant;
  • a requirement of a workers’ compensation or workplace safety authority;
  • a lawful request from a regulator or enforcement body;
  • a mandatory reporting obligation;
  • professional registration or accreditation requirements; or
  • legal proceedings or dispute-resolution processes.

Where legally permitted and appropriate, we may notify the affected individual before making a compulsory disclosure.

14. Overseas Disclosure

Some technology, cloud, communications or professional service providers used by Praventus may store or process information outside Australia.

The countries involved may vary depending on the service provider and system used.

Before disclosing personal information overseas, we will take reasonable steps required by applicable privacy law. These steps may include:

  • assessing the service provider’s privacy and security practices;
  • using contractual privacy and confidentiality protections;
  • limiting the information disclosed;
  • applying access controls and encryption where appropriate; and
  • obtaining consent where required.

An overseas recipient may be subject to privacy laws that differ from Australian law.

Where practicable, Praventus will maintain primary health and injury management records in systems hosted in Australia or in systems offering appropriate privacy and security safeguards.

15. Direct Marketing

Praventus may use business contact information to communicate with clients and professional contacts about relevant services, events, resources or business updates where permitted by law.

We will not use an individual’s health information for direct marketing without the individual’s consent where consent is required.

Marketing communications will include a reasonable means of opting out. An individual may also ask us at any time not to send further marketing communications.

Operational, clinical, contractual and service-related communications are not marketing communications and may continue where reasonably necessary.

16. Cookies and Website Analytics

Our website may use cookies and similar technologies to:

  • enable website functionality;
  • remember preferences;
  • maintain security;
  • analyse website performance and usage; and
  • improve the user experience.

A user may adjust browser settings to reject or delete cookies, although some website functions may not operate correctly as a result.

We will take reasonable steps to ensure website analytics and tracking tools are configured so they do not unnecessarily collect health or other sensitive information.

We do not authorise third-party advertising platforms to use information entered into health, injury, referral or contact forms for targeted advertising.

17. Artificial Intelligence and Automated Tools

Praventus may use approved digital or artificial-intelligence-assisted tools for limited administrative purposes, such as formatting, transcription, summarisation, workflow support or quality review.

Where such tools are used:

  • human oversight will be maintained;
  • outputs will not replace professional judgement;
  • access will be limited to authorised purposes;
  • reasonable privacy and security assessments will be undertaken;
  • sensitive information will not be entered into publicly available or unapproved systems; and
  • information will be de-identified where reasonably practicable.

We will not make a significant clinical, rehabilitation or employment recommendation solely through automated decision-making without appropriate human review.

18. Data Quality

We take reasonable steps to ensure that personal information we collect, use and disclose is accurate, current, complete and relevant for its purpose.

Individuals, clients and other information providers should promptly notify us if information changes or is believed to be incorrect.

Because health status, work capacity and workplace circumstances may change over time, reports and recommendations should be considered in light of the date on which they were prepared.

19. Storage and Security

We may hold personal information in electronic and physical form.

We take reasonable technical, organisational and physical measures to protect information against:

  • misuse;
  • interference;
  • loss;
  • unauthorised access;
  • unauthorised modification; and
  • unauthorised disclosure.

Measures may include:

  • access controls and user authentication;
  • role-based permissions;
  • password and multi-factor authentication requirements;
  • encryption where appropriate;
  • secure cloud and document-management systems;
  • device and network security;
  • secure backup processes;
  • confidentiality agreements;
  • employee privacy and cybersecurity training;
  • physical security;
  • incident-response procedures;
  • supplier due diligence; and
  • secure destruction processes.

No electronic transmission or storage system is completely secure. We cannot guarantee that unauthorised access or disclosure will never occur, but we will take reasonable steps required by law to protect the information we hold.

20. Employee and Contractor Access

Access to personal information is limited to employees, contractors and service providers who reasonably require it for their role.

Personnel with access to health and other sensitive information are expected to:

  • comply with privacy, confidentiality and information-security requirements;
  • access information only for authorised purposes;
  • avoid discussing information in inappropriate settings;
  • securely store and transmit information;
  • report suspected privacy or security incidents; and
  • complete relevant training.

21. Retention and Destruction

We retain personal information for as long as reasonably necessary to:

  • provide and document the Services;
  • meet contractual and professional requirements;
  • comply with statutory record-retention obligations;
  • manage complaints, claims and disputes;
  • maintain business and financial records; and
  • protect legitimate legal interests.

Retention periods may vary depending on:

  • the type of information;
  • the individual’s age;
  • the nature of the Services;
  • professional standards;
  • workers’ compensation and health-record requirements;
  • contractual requirements; and
  • applicable limitation periods.

When information is no longer required and we are not legally required to retain it, we will take reasonable steps to securely destroy it or permanently de-identify it.

22. Access to Personal Information

An individual may request access to personal information that we hold about them.

A request should:

  • be made in writing;
  • provide sufficient details to identify the information requested; and
  • include evidence of identity where reasonably required.

We will respond within a reasonable period.

We will generally provide access in the manner requested where reasonable and practicable. Access may be provided through inspection, a copy of records, a summary, or another suitable method.

We may refuse or limit access where permitted by law, including where access:

  • would pose a serious threat to life, health or safety;
  • would unreasonably affect another person’s privacy;
  • relates to legal proceedings or anticipated legal proceedings;
  • would reveal commercially sensitive decision-making;
  • would be unlawful;
  • is required or authorised to be denied by law;
  • would prejudice enforcement-related activities;
  • would reveal information generated in connection with a dispute-resolution process; or
  • is frivolous or vexatious.

Where access is refused, we will generally provide written reasons and information about available complaint mechanisms, unless it would be unreasonable or unlawful to do so.

We will not charge for making an access request. We may charge a reasonable amount for costs involved in providing access where permitted by law, but not for an individual’s own time spent making the request.

23. Correction of Personal Information

An individual may ask us to correct personal information they believe is inaccurate, out of date, incomplete, irrelevant or misleading.

We may also correct information on our own initiative where appropriate.

If we correct information that was previously disclosed to another organisation, we will take reasonable steps to notify that organisation where required by law and requested by the individual.

Where we decline to make a requested correction, we will generally:

  • explain the reasons in writing;
  • explain available complaint mechanisms; and
  • take reasonable steps to associate a statement with the record noting that the individual considers it inaccurate, out of date, incomplete, irrelevant or misleading.

A disagreement with a professional opinion does not necessarily mean that a record is inaccurate. However, an individual may request that their disagreement or additional information be noted on the record.

24. Requests Made by Representatives

An individual may authorise a representative to make a privacy request on their behalf.

Before dealing with the representative, we may require:

  • written authority;
  • proof of the representative’s identity;
  • proof of the individual’s identity; and
  • clarification of the scope and duration of the authority.

We may decline to deal with a representative where their authority is unclear, has expired or does not cover the requested information.

25. Anonymity and Pseudonyms

Where practicable, individuals may interact with us anonymously or using a pseudonym.

However, this may not be practicable where:

  • we are required or authorised by law to identify the individual;
  • identity is necessary to provide the Services safely or effectively;
  • information must be matched to an employment, insurance or workers’ compensation matter;
  • a report or professional opinion is required; or
  • identity verification is necessary to protect privacy or security.

26. Data Breaches

A data breach may occur where personal information is lost or subjected to unauthorised access, use, modification or disclosure.

Praventus maintains procedures for assessing and responding to suspected data breaches.

Where a breach occurs, we may:

  • contain the breach;
  • assess the nature and extent of the incident;
  • take remedial action;
  • investigate how it occurred;
  • assess the risk of harm;
  • notify affected individuals;
  • notify the Office of the Australian Information Commissioner;
  • notify another regulator, insurer, client or authority where required; and
  • implement measures to reduce the risk of recurrence.

Under the Notifiable Data Breaches scheme, we will notify affected individuals and the Australian Information Commissioner where we have reasonable grounds to believe an eligible data breach has occurred and notification is required by law.

Individuals who become aware of a suspected privacy or security incident involving Praventus information should contact us immediately.

27. Privacy Complaints

An individual who has a concern or complaint about our handling of personal information should contact our Privacy Officer using the details below.

A complaint should include:

  • the complainant’s name and contact details;
  • a description of the concern;
  • relevant dates, people and documents; and
  • the outcome sought.
  • We will:
  • acknowledge the complaint within a reasonable period;
  • investigate it fairly and appropriately;
  • request additional information where required;
  • provide a written response where appropriate; and
  • take reasonable remedial action if the complaint is substantiated.

We aim to respond substantively within 30 days, although complex matters may require additional time. If additional time is required, we will provide an update where practicable.

If an individual is dissatisfied with our response, they may complain to the Office of the Australian Information Commissioner. In some circumstances, another health complaints body, workers’ compensation authority or regulator may also have jurisdiction.

28. Third-Party Websites and Services

Our website or communications may contain links to external websites or services.

We are not responsible for the privacy, content or security practices of third parties that we do not control. Individuals should review the privacy policies of those third parties before providing information.

29. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in:

  • legislation or regulatory guidance;
  • our Services;
  • our information-handling practices;
  • technology and security risks; or
  • our organisational structure.

The current version will be made available on our website or on request.

Material changes will take effect from the date stated in the updated Policy. Where appropriate, we may separately notify affected clients or individuals.

30. Contacting Us

Questions, access or correction requests, privacy complaints and suspected data breaches may be directed to:

Privacy Officer
Praventus Pty Ltd
Trading as Praventus Injury Management

Address: Level 1, 15 Rheola St, West Perth WA 6005
Email:admin@praventus.com.au
Telephone: 0439 739 415
Website: www.praventus.com.au

31. Office of the Australian Information Commissioner

Information about privacy rights or making a complaint is available from the Office of the Australian Information Commissioner.

Website: www.oaic.gov.au
Telephone: 1300 363 992

Version date: July 2026

Scroll to Top