Privacy Collection Notice and Privacy Policy
Next Level Physiotherapy and Strength Studio | September 2026
The short Privacy Collection Notice appears first, followed by the full Privacy Policy.
Privacy Collection Notice — for intake forms and waivers
Next Level Physiotherapy and Strength Studio is operated by Myers Health and Fitness Pty Ltd in Varsity Lakes, Queensland. For privacy questions, contact info@nextlevelstrengthstudio.com. Our full Privacy Policy appears below on this page: https://nextlevelstrengthstudio.com/privacy-policy.
We collect contact, appointment, billing, funding and sensitive health information needed to provide physiotherapy and related services, maintain records, prepare reports and referrals, manage bookings and claims, and meet legal and professional obligations. We generally obtain it from you and may also receive relevant information from a GP, other provider, parent, guardian, carer, authorised representative, insurer or funding body. Without necessary information, we may be unable to provide a particular service or process a claim.
Where relevant and permitted, we may share necessary information with your nominated or referring provider, authorised representative, Medicare, DVA, NDIS or WorkCover recipient, insurer, and the service providers that support our records, booking, website, email and technology. Some providers and their subprocessors may process information outside Australia. Our full policy explains security, retention, access, correction and complaints.
Our website assistant uses AI for general enquiries and emails us a conversation transcript. Please do not give it sensitive health details. Its separate, optional contact form lets you submit your name, phone number and a short message for staff to respond. An AI telephone receptionist, Ava, is planned and will identify itself when it answers. A separate clinical reporting tool may be introduced later; it is not yet approved for real client information, and we will provide further notice before using it. Clinicians remain responsible for clinical decisions and documents. Email info@nextlevelstrengthstudio.com if you have questions or wish to request that a particular AI use be avoided; we will explain what can be accommodated. Choosing not to use a website chat does not prevent you contacting the clinic directly.
We ask for consent where required and check the authority of parents, guardians and representatives where applicable. You can contact us to ask for access or correction, withdraw a consent for future use where relevant, or make a privacy complaint. Withdrawal cannot undo information already sent or remove a record we must lawfully keep. If our response to a complaint does not resolve it, you can contact the OAIC.
Acknowledgement for a form: “I have been given the Privacy Collection Notice and know where to read the full Privacy Policy.” This acknowledges receipt; it is not a blanket consent to treatment, future AI report drafting, marketing or disclosure of a particular report.
Privacy Policy
Last updated: 24 September 2026
1. About us
Myers Health and Fitness Pty Ltd trades as Next Level Physiotherapy and Strength Studio in Varsity Lakes, Queensland. We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what we collect, why we use it, who may receive it, how we protect it and your choices.
For privacy questions, requests or complaints, email info@nextlevelstrengthstudio.com. Our website is https://nextlevelstrengthstudio.com.
2. Information we collect
We collect information reasonably needed to provide and administer our services. Depending on your circumstances, this may include:
your name, date of birth, contact details, emergency contacts and details of a parent, guardian or authorised representative;
appointment, referral, account, payment, Medicare, private health insurance, DVA, NDIS and WorkCover details, including relevant numbers and claim information;
sensitive health information, such as your history, symptoms, diagnoses, assessment findings, treatment notes, exercise plans, progress, imaging and reports; and
correspondence with you and with people involved in your care or funding, where relevant.
When you use our website, booking system or digital services, we and our service providers may collect technical information such as IP address, browser and device details, pages viewed, cookies, advertising identifiers and service logs. If you type information into the website assistant, its conversation transcript may contain what you typed even if the assistant did not ask for personal or health details.
3. Where information comes from
We generally collect information directly from you through booking, intake forms, consultations, calls, email and website interactions. We may also receive relevant information from a GP or other referrer, treating practitioner, parent, guardian, carer, authorised representative, employer, insurer, NDIS participant or representative, Medicare, DVA or WorkCover Queensland, where appropriate. We seek to collect health information directly from you where reasonable and practicable.
If you do not provide information needed for a particular service, we may be unable to assess or treat you safely, manage an appointment, process a claim or prepare a requested report. We will explain the practical effect where possible.
4. Why we use information and who receives it
We use information to assess and treat clients; keep clinical records; prepare treatment plans, GP letters and reports; arrange appointments; contact you about care; process accounts, rebates and funding; respond to enquiries; manage the practice; and meet legal and professional obligations.
Where relevant and permitted, we may disclose necessary information to your nominated or referring GP and other providers, authorised representatives, Medicare, DVA, NDIS recipients or representatives, WorkCover Queensland, insurers, and organisations that provide our booking, clinical-record, payment, email, website and technology services. A report may be provided to a funder, insurer or other nominated recipient through an authorised channel. We check the recipient and the applicable authority before sending a clinical report. We may also disclose information where required or permitted by law. We do not sell client information.
The information shared and the basis for sharing it depend on the service, referral, funding arrangement, your authority and applicable law. You can ask us about a proposed report or recipient before it is sent.
5. Our digital and AI services
Website assistant. Our website assistant answers general questions about services, pricing, location and appointments. It uses our website server, OpenAI services and n8n Cloud to process conversations. It does not access clinical records or provide a diagnosis or individual treatment advice. Please do not put medical histories, claim numbers or other sensitive information into the chat. We receive a copy of website-assistant conversations by business email and retain those transcript emails for no more than 90 days under our configured process. The assistant does not prompt visitors to provide personal details in ordinary chat. If you choose to submit its separate contact form, you provide your name, phone number and a short message, which is emailed to our business account so a staff member can respond. Information needed for a clinical record may instead be recorded in Cliniko. The assistant should not be used for urgent clinical concerns.
Ava telephone receptionist — planned. We are preparing an AI receptionist called Ava, using Twilio, OpenAI Realtime, n8n Cloud and limited, authorised Cliniko access for appointment administration. Ava will identify itself as AI at the start of a call, provide general information and help with appointment enquiries. It will not diagnose or give individual treatment advice. Call audio will be processed in real time by external providers. Twilio call recording is off, and we do not intend to keep Ava conversation transcripts. Providers may still retain call metadata or technical records under their service settings. We will check the final setup and update this policy before Ava goes live. Callers will be able to request human help through the available transfer, callback or voicemail route.
Clinical report drafting — possible future use. We are developing a staff reporting portal, but it is not approved for use with real client information. If introduced, a clinician may use the OpenAI API to help draft NDIS reports, WorkCover reports or GP letters. Structured identifiers would be removed from the proposed AI request, and the clinician would inspect and approve the exact text sent. Clinical details could still identify a person from context, so we would not call the material anonymous. A physiotherapist would review, edit and approve any draft, add identifiers locally, and remain responsible for the final document and clinical decisions. We will give clients appropriate notice, assess the legal basis and applicable consent, and update this policy before using real client information in that portal. No consent to a future report-drafting use is sought merely by reading this policy.
We may consider other AI-assisted documentation or administrative functions later. We will assess each material change, provide an appropriate notice and seek consent where required before introducing it. AI supports staff; it does not replace a clinician's judgement.
6. Questions and requests about AI
You can ask how AI is used or email info@nextlevelstrengthstudio.com to request that a particular use of AI be avoided. We will explain what we can accommodate and any effect on the requested feature or service. You can choose not to use the website assistant and can contact us directly. Once Ava launches, you will be able to request human assistance. If clinical report drafting is introduced, its specific notice will explain the available choices before your information is used.
7. Service providers and overseas processing
Our service providers include Cliniko, Google Workspace/Drive/Gmail, Squarespace, OpenAI, n8n Cloud and DigitalOcean. Twilio will be used for Ava when launched. Our intended DigitalOcean production server is in Sydney. Other providers and their subprocessors may access, store or process information outside Australia, including in the United States and other locations according to their service arrangements. Australian hosting of our server does not mean all information remains in Australia. Before overseas disclosures of personal information, we assess applicable Australian Privacy Principle 8 obligations and reasonable safeguards. Specific overseas countries and provider arrangements may change; contact us if you want information about a particular service.
8. Security and retention
We take reasonable steps to protect information through staff access controls, authentication, encryption where configured, secure service providers and internal procedures. No electronic system or email delivery is completely secure. Approved clinical documents may be stored in our business Google Drive, and clinical records are held in Cliniko. Ordinary email can be misdirected, forwarded or accessed by someone other than the intended recipient; ask us whether a more secure delivery method is available for a particular report.
We keep clinical, financial and other records for the period required by applicable law and professional obligations or while reasonably needed for care, claims or lawful business purposes, then securely destroy or de-identify them when appropriate. Different providers may keep operational or security records under their own settings. Website-assistant transcript emails are subject to the 90-day maximum noted above. We do not state that every provider copy is deleted at the same moment as a copy in our own system.
The developing reporting portal is not approved for real client information. Before it is introduced, we will confirm and disclose its draft-deletion and provider-retention arrangements. The DigitalOcean VPS has no enabled VPS backups according to the business; other service providers may have their own backup and retention arrangements.
9. Website cookies and marketing
Our Squarespace website uses cookies and similar technology, including its Google Analytics 4 integration. We do not currently use a Meta advertising pixel. Google Analytics may receive technical information about visits and interactions, such as pages viewed, device information and identifiers. Our cookie banner lets you accept, decline or manage non-essential cookies, and the site is configured to restrict non-essential cookies. Some limited technical requests may still occur when you decline, and page views can reveal information about a visitor's interests or circumstances. We do not intentionally send website-chat message content to Google Analytics or advertising tools. You can change your choice through the site’s Cookie Preferences control and use browser controls, though some features may be affected.
We send promotional emails or texts only where we have an appropriate basis. People booking online can choose whether to join our mailing list. For people booked manually, we ask for verbal agreement before adding them and record that choice. Each promotional message provides a way to unsubscribe. Appointment and care messages are separate from marketing. We do not use sensitive health information for direct marketing without specific consent.
10. Children and representatives
For a child or young person, we consider whether they can understand the particular decision. Where appropriate, a parent or guardian makes decisions on their behalf. We check the authority of anyone requesting access, giving instructions or receiving information. A parent or guardian does not automatically receive every record where a young person can make their own privacy decision or where the law limits access. We also check the authority of representatives for adult clients.
11. Access, correction and complaints
Email info@nextlevelstrengthstudio.com to request access to or correction of information we hold, ask a privacy question, or make a complaint. We may ask you to verify your identity or authority. We will respond within a reasonable time, explain any lawful refusal and discuss any reasonable copying charge before providing copies. If you disagree with information we cannot change, ask us about attaching a statement to the record.
If you are unhappy with our response to a privacy complaint, or we have not responded within a reasonable period (generally 30 days), you can contact the Office of the Australian Information Commissioner at https://www.oaic.gov.au/privacy/privacy-complaints.
12. Data breaches and policy changes
We investigate suspected data breaches, take steps to contain harm and notify affected people and the OAIC when an eligible data breach requires notification. We review this policy when our systems or practices change. For material changes, we will provide an appropriate updated notice and seek consent where required before the new use begins.