Skip to main content

Privacy Policy 

Effective Date: 14 August 2026 

Who We Are 

AP Psychology & Consulting Services Pty Ltd (“AP Psychology”, “we”, “our” or “us”) is committed to protecting the privacy, confidentiality and security of the information entrusted to us. 

We provide psychological health and safety consulting services, organisational development services, learning and development programs, workplace mental health initiatives, and digital products including the TM Thrive platform and mobile application. 

As an ISO/IEC 27001 certified organisation, we maintain a comprehensive information security management system designed to protect information from unauthorised access, disclosure, alteration, loss or misuse. This Privacy Policy explains how we collect, use, disclose, store and protect personal information. 

 

Our Privacy Obligations 

We comply with applicable privacy and information management legislation, including: 

  • Privacy Act 1988 (Cth) 
  • Australian Privacy Principles (APPs) 
  • Health Records Act 2001 (Vic) 
  • Health Privacy Principles (HPPs) 
  • Notifiable Data Breaches Scheme requirements 
  • Professional obligations applicable to registered psychologists and health service providers 

 

What Information We Collect 

The information we collect depends on the services you use and your relationship with us. 

Business and Contact Information 

This may include: 

  • Name 
  • Organisation 
  • Position title 
  • Work email address 
  • Phone number 
  • Postal address 
  • Communication preferences 

Client and Service Information 

Where required to deliver professional services, we may collect information relevant to: 

  • Program participation 
  • Workshop attendance 
  • Consulting engagements 
  • Training activities 
  • Workplace wellbeing initiatives 
  • Customer support requests 

Website and Platform Information 

When you use our website, TM Thrive platform or mobile application, we may collect: 

  • Account registration details 
  • Work email address 
  • Organisation affiliation 
  • User activity logs 
  • Device information 
  • Browser information 
  • Session information 
  • Security and authentication data 
  • Website analytics information 

 

TM Thrive Platform and Mobile Application 

TM Thrive has been designed to support psychologically healthy and safe workplaces while maintaining strong privacy and security controls.  

What TM Thrive Collects 

TM Thrive may collect information necessary to: 

  • Create and manage user accounts 
  • Provide access to learning content 
  • Support psychosocial risk assessments 
  • Administer organisational programs 
  • Deliver customer support 
  • Improve platform functionality 
  • Maintain platform security 

What TM Thrive Does Not Intend to Collect 

TM Thrive is not designed to collect: 

  • Clinical treatment records 
  • Psychological counselling notes 
  • Medical records 
  • Medicare information 
  • Personal healthcare histories 

unless specifically required as part of a separate professional service engagement and with appropriate privacy controls. 

Aggregated and De-Identified Reporting 

Where practical and appropriate, information is aggregated and de-identified before being provided in organisational reports. 

Our objective is to support organisational psychosocial risk management while protecting individual privacy and confidentiality.  

 

How We Collect Information 

We may collect information: 

  • Directly from you 
  • Through forms and registrations 
  • Through communications with us 
  • Through program participation 
  • Through use of TM Thrive 
  • Through our website 
  • Through customer support interactions 
  • Through third-party providers acting on our behalf 
  • Through your employer where they are administering a program or service 

 

How We Use Personal Information 

We use personal information to: 

  • Deliver our services 
  • Administer programs and projects 
  • Provide TM Thrive functionality 
  • Verify user accounts 
  • Respond to enquiries and requests 
  • Provide technical support 
  • Process registrations 
  • Manage contractual obligations 
  • Improve products and services 
  • Conduct research and evaluation activities 
  • Meet legal and regulatory obligations 
  • Protect the security and integrity of our systems 

We may also use information to provide updates, newsletters, event invitations and service-related communications where permitted by law. 

Individuals may opt out of marketing communications at any time. 

 

Disclosure of Personal Information 

We only disclose personal information where reasonably necessary. 

This may include: 

  • Technology and cloud service providers 
  • Learning delivery providers 
  • Payment processors 
  • Professional advisers 
  • Contractors and consultants 
  • Government agencies where legally required 
  • Regulatory authorities 
  • Auditors and certification bodies 

We do not sell personal information. 

We do not permit third parties to use personal information for their own marketing purposes without consent. 

 

Overseas Disclosure 

We primarily seek to utilise Australian-based systems and storage locations where appropriate. 

Some technology providers used to deliver our services may process information outside Australia. Where personal information is disclosed overseas, we take reasonable steps to ensure that information receives protections consistent with Australian privacy requirements. 

 

Cookies and Website Analytics 

Our websites and platforms may use: 

  • Cookies 
  • Analytics technologies 
  • Session management technologies 
  • Performance monitoring tools 
  • Security monitoring services 

These technologies help us: 

  • Improve website functionality 
  • Detect security threats 
  • Understand website usage 
  • Improve user experience 
  • Maintain platform performance 

Most web browsers allow users to manage or disable cookies through browser settings. 

 

Information Security 

Protecting information is a core organisational priority. 

AP Psychology & Consulting Services maintains an ISO/IEC 27001 certified information security management system and implements a range of security controls including: 

  • Role-based access controls 
  • Multi-factor authentication where appropriate 
  • Encryption of data in transit 
  • Encryption of data at rest 
  • Security monitoring 
  • Risk management processes 
  • Vulnerability management 
  • Secure software development practices 
  • Incident response procedures 
  • Business continuity and disaster recovery planning 

We continually review and improve our security controls to meet evolving threats and business requirements.  

 

Data Retention and Destruction 

We only retain personal information for as long as necessary to: 

  • Deliver services 
  • Meet contractual obligations 
  • Comply with legal requirements 
  • Fulfil regulatory obligations 
  • Support legitimate business operations 

When information is no longer required, it is securely destroyed, deleted, anonymised or de-identified in accordance with our information security controls, retention schedules and ISO/IEC 27001 requirements. 

In some circumstances, de-identified and aggregated information may be retained for research, evaluation, quality improvement and reporting purposes where lawful and appropriate. 

 

Access and Correction 

You may request access to personal information we hold about you. 

You may also request correction of information that is inaccurate, incomplete or outdated. 

Requests should be submitted using the contact details provided below. 

We may require reasonable proof of identity before providing access. 

 

Complaints and Concerns 

If you have concerns about how we handle personal information, please contact us. 

We take privacy complaints seriously and will investigate and respond within a reasonable timeframe. 

If you are not satisfied with our response, you may contact: 

Office of the Australian Information Commissioner (OAIC) 

or 

Health Complaints Commissioner (Victoria) 

where applicable. 

 

Data Breach Management 

AP Psychology & Consulting Services maintains documented incident management and data breach response procedures. 

Where an eligible data breach occurs, we will respond in accordance with applicable legal obligations, including the Notifiable Data Breaches Scheme under the Privacy Act 1988. 

This may include notification to affected individuals, clients and regulators where required. 

 

Changes to This Policy 

We may update this Privacy Policy from time to time to reflect: 

  • Legislative changes 
  • Regulatory guidance 
  • Technology changes 
  • Service improvements 
  • Business requirements 

The most current version will always be available on our website. 

 

Contact Us 

AP Psychology & Consulting Services Pty Ltd 

Email: info@psychology-consulting.com 

If you have questions about this Privacy Policy or how we handle personal information, please contact us and we will be happy to assist.