PRIVACY POLICY FOR MINDWAY EAP
Effective Date: 11 November 2024
At Mindway Group PTY LTD, trading as Mindway EAP (ABN: 29682230075) ("Mindway EAP," "we," "us," or "our"), we are committed to protecting your privacy and handling your personal information responsibly. This policy outlines how we collect, use, store, and protect your personal data when you use the Mindway EAP services ("App").

1. Key Definitions
  • Mobile Application: The Mindway EAP App, designed for mobile devices (iOS, Android, etc.).
  • Personal Data: Any information about you that identifies you, including data you provide or data collected automatically.
  • User: Any person who downloads, activates, or uses the App.
  • Cookies: Small files used to enhance the functionality and performance of the App.
  • We/Us/Our: Mindway Group PTY LTD, trading as Mindway EAP, Australia, Victoria.

2. Applicability
This Privacy Policy applies to all personal data collected through the App. By downloading, installing, or using the App, you acknowledge and agree to the terms of this Privacy Policy.

3. Data We Collect
We collect the following types of data:
3.1. Device Data:
  • Information such as device ID, IP address, operating system, and network details.
3.2. Voluntary Data:
  • Information you provide directly, such as your name, email address, notes, journal entries, and other details submitted during signup/app usage.
3.3. Employer Data Sharing on Signup:
  • During the signup process, we share your name and email address with your employer to manage access to Mindway EAP services. This occurs regardless of whether you later choose to use counseling services. No additional personal data is shared with your employer. Some employers may opt to give departmental breakdowns of your organisation, which is requested on your signup.
3.4. First-Time Client Form:
  • Data submitted via the First-Time Client Form is shared only with your assigned counselor and remains strictly confidential.
3.5. Cookies:
  • Used to enhance user experience, track app performance, and improve functionality.

4. Purpose of Collecting Data
We collect and process your data to:
  • Enhance your experience with the App and analyze its usage.
  • Provide technical and customer support.
  • Communicate with you regarding your account or App updates.
  • Securely store notes, journal entries, and other personal data.
4.1. Confidentiality Exception:
  • Aggregated and anonymized data, such as general trends (e.g., "percentage of employees citing 'work stress'") or usage statistics, may be shared with employers. No identifiable personal information is included in such reports.

5. Data Security
We implement reasonable technical and organizational measures to protect your data from unauthorized access, loss, misuse, or alteration. These include:
  • Encryption of sensitive data during transmission and storage.
  • Regular updates and security patches to our systems.
  • Access controls to restrict data to authorized personnel only.
While we strive to protect your data, no system is completely secure. You share information with us at your own risk.

6. Data Retention
We retain personal data only for as long as necessary for the purposes outlined in this policy or as required by law. Retention periods include:
  • Counseling Session Data: Retained for 7 years from the date of the last interaction.
  • User Account Data: Retained while your account is active and deleted within 30 days after account deletion unless legally required to retain it.
You may request data deletion by contacting support@mindwayeap.com.au.

7. Confidentiality of EAP Services
We take the confidentiality of our Employee Assistance Program services seriously. No identifiable personal information from your counseling sessions will be shared with your employer.
7.1. Data Not Shared with Employers:
  • Your name or email when counseling sessions are conducted.
  • Individual app usage data
  • Specific personal details from counselling sessions.
7.2. Limited Exceptions:
  • Aggregated or anonymized data trends, such as session reasons, mood days, and other data collected in app may be shared with employers without revealing personal information.
  • Billing-related information, such as the date of a counseling session, may be disclosed in compliance with legal or contractual obligations.
  • Your name and email are shared with your employer during the signup process, but this is not linked to counselling usage.
  • We may use this aggregated and anonymised data to give further breakdowns of company departments (if collected and applicable), which provides the employer with insights into specific areas of the business in relation to employee wellbeing.

8. User Rights
You have the following rights regarding your data:
  • Access: You can request information about how we process your data.
  • Correction: You can request corrections to inaccurate or incomplete data.
  • Deletion: You can delete your account directly in the App or request deletion by contacting support@mindwayeap.com.au.

9. Data Storage
Your data is stored on secure servers. Data transfers are conducted securely, and we ensure compliance with relevant cross-border data protection laws.

10. Minors
The App is intended for users over 18 years old. If you are under 18, you must discontinue use of the App immediately.

11. Data Breaches
In the event of a data breach:
  • We will promptly assess the impact and notify affected individuals if there is a risk of serious harm.
  • We will report the breach to the Office of the Australian Information Commissioner (OAIC), as required under the Notifiable Data Breaches (NDB) Scheme.

12. Policy Updates
This policy is effective as of 11 November 2024. Updates may be made periodically to reflect changes in laws, regulations, or our practices. The latest version will always be accessible via the App or our website.

13. Contact Us
If you have any questions, concerns, or requests regarding this policy, please contact us at:
Email: support@mindwayeap.com.au

Disclaimer: While we employ security measures, no data transmission over the internet can be guaranteed to be completely secure. By using the App, you acknowledge this inherent risk.