

PRIVACY POLICY
1. About this policy
Focused Mental Education Pty Ltd (ABN 56 678 167 765) respects your privacy. This policy explains what personal information we collect about you, why we collect it, who we share it with, how we keep it safe, and what you can do if you want to see it, correct it or complain about how we have handled it.
In this policy, "we", "us" and "our" mean Focused Mental Education Pty Ltd. "You" means anyone whose personal information we hold, including course participants, counselling and NDIS clients, enquirers, organisational clients and visitors to our website.
The law that applies to us
We are bound by the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles set out in it.
Many small businesses in Australia are exempt from the Privacy Act because their annual turnover is under three million dollars. That exemption does not apply to us. Because we provide health services, including counselling, mental health support and NDIS supports, and because we hold health information about the people we support, the Privacy Act applies to us regardless of our size or turnover.
As we operate in New South Wales, the Health Records and Information Privacy Act 2002 (NSW) also applies to the health information we hold.
We are also a registered NDIS provider, and we handle participant information in line with our obligations under the NDIS Practice Standards and the NDIS Code of Conduct.
2. What information we collect
The information we collect depends on how you deal with us. We only collect what we genuinely need.
Contact and enquiry information
When you contact us through the website, by email, by phone or in person, we typically collect:
-
your name
-
your email address and phone number
-
the organisation you work for, if you are enquiring on its behalf
-
the content of your enquiry and any messages you exchange with us
Training and course information
If you attend one of our courses, including Mental Health First Aid courses, we collect:
-
your full name, preferred email address and preferred mobile number, which are required to register you with Mental Health First Aid Australia
-
the course you attended, the dates, and your attendance
-
any accessibility or dietary requirements you tell us about, so we can run the session properly
-
feedback you choose to give us about the training
Health information and other sensitive information
If you engage us for counselling, psychosocial support, hypnotherapy or NDIS supports, we collect health information about you. This may include your history, presenting concerns, treatment or support notes, progress, risk information, referral details, and correspondence with other practitioners involved in your care.
Health information is treated as sensitive information under the Privacy Act. We collect it only with your consent, or where the law allows or requires us to, and we only use it for the purpose you gave it to us for.
We may also collect other sensitive information where it is directly relevant to the support we provide, for example Aboriginal or Torres Strait Islander status where you are attending a culturally specific course and choose to tell us.
NDIS participant information
If you are an NDIS participant, or you support one, we may also collect NDIS number, plan dates, funded support categories, plan management arrangements, goals relevant to the supports we deliver, and the contact details of your support coordinator, plan manager, nominee or guardian.
Website and technical information
Our website is built on the Wix platform. When you visit it, some information is collected automatically:
-
your IP address, which may indicate your approximate location
-
your device type, browser and operating system
-
the pages you viewed, how long you stayed, and the site you came from
-
cookies and similar technologies, as described in section 7
We use Google Analytics to understand how people find and use the site. This is statistical and we do not use it to identify you personally.
Billing and payment information
We do not sell anything through our website and we do not run an online shop, so no payment details are collected through the site.
We issue invoices using Xero, which holds your name, contact details and billing history for that purpose.
Where you pay by card in person, we use a Square terminal. Square processes the transaction and handles the card data. We never see or store your full card number, and card details are not kept in our own records. Payments made by bank transfer are recorded against your invoice in Xero.
3. How we collect it
Wherever it is reasonable and practical, we collect personal information directly from you: in conversation, by phone or email, through a form on our website, through a booking, or on a course registration or intake form.
Sometimes we collect information about you from someone else, for example:
-
an employer or organisation that has booked training for its staff
-
a support coordinator, plan manager, nominee, guardian or family member acting with your authority
-
a referring health practitioner or agency
-
the National Disability Insurance Agency, where relevant to your supports
If we collect information about you from someone else, we will take reasonable steps to let you know, unless you would already expect it or the law says otherwise.
4. Why we collect it and how we use it
We use personal information to:
-
respond to your enquiry and provide you with a quote
-
deliver the training, counselling, consultancy or NDIS supports you have engaged us for
-
register you with Mental Health First Aid Australia and arrange your certificate
-
schedule sessions and manage bookings
-
keep clinical and support records as our professional and legal obligations require
-
invoice you, or invoice your plan manager or the NDIA, and keep our accounts
-
improve our services, including by reviewing feedback
-
meet our obligations as a registered NDIS provider and under other laws
We do not sell your personal information. We do not trade or rent it to anyone.
5. Who we share it with
We disclose personal information only where it is necessary, and only to:
-
Mental Health First Aid Australia, to register course participants and issue accreditation, where you have attended an MHFA course
-
other instructors we engage to deliver or cover a course you are attending
-
your plan manager, support coordinator, nominee, guardian or the NDIA, where you have authorised it or where it is necessary to deliver and be paid for your supports
-
other health practitioners involved in your care, with your consent
-
the organisation that booked your training, limited to attendance and completion, not to anything personal you disclose during a session
-
our service providers, being our website platform (Wix), our email and document systems (Microsoft 365), our accounting software (Xero) and our card payment provider (Square)
-
our professional advisers, such as our accountant, lawyer or insurer, where needed
-
a regulator, court or other body where the law requires or authorises disclosure
Where there is a serious risk
If we reasonably believe it is necessary to lessen or prevent a serious threat to your life, health or safety, or to the life, health or safety of another person, we may disclose information without your consent. This is permitted under the Privacy Act. In practice this is rare, and where we can do so safely we will tell you first.
Where your information is stored
Some of the services we rely on store information in Australia, and some store it overseas.
Our email, documents and file storage run on Microsoft 365. Our account is configured to store that data in Australia, which covers Exchange Online, SharePoint, OneDrive and Teams. This means your correspondence with us and the records we keep about you are held onshore.
Our website platform (Wix), our accounting software (Xero) and our card payment provider (Square) may store or access information outside Australia, including in the United States, the European Union and other countries where their infrastructure operates. Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.
6. Direct marketing
We may occasionally contact you about courses, workshops or services that are relevant to you, using the contact details you have given us. Every marketing email we send includes an unsubscribe link, and you can ask us at any time to stop by emailing info@fme.com.au or calling us.
We do not use sensitive information, including health information, for marketing.
7. Cookies and website analytics
Cookies are small files placed on your device when you visit a website. Our site uses them to keep the site working properly, to remember your preferences, and to understand how the site is used.
We use Google Analytics, which sets cookies to measure visits and page views. You can opt out of Google Analytics across all websites by installing the Google Analytics Opt-out Browser Add-on, and you can block or delete cookies in your browser settings. Blocking some cookies may affect how the site works.
Some pages on our website include embedded YouTube videos. YouTube, which is owned by Google, may set cookies when you play a video. These cookies are only enabled if you accept them through our cookie settings.
When you first visit our site you are asked to accept or decline non-essential cookies, and analytics cookies are not set until you accept. You can change your choice at any time through the cookie settings link on the site.
8. How we keep information safe
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Those steps include:
-
storing records in access controlled systems rather than on paper wherever possible
-
multi factor authentication on our email and business systems
-
limiting access to client records to the people who need it to do their work
-
confidentiality obligations for anyone who works with or for us
-
secure disposal of records once we are no longer required to keep them
No system is completely secure. If something does go wrong, we will act quickly to contain it.
9. How long we keep it
We keep personal information only for as long as we need it, or for as long as the law requires, whichever is longer.
For health information, New South Wales law sets minimum retention periods. Where the person was an adult at their last service with us, we must keep the record for at least seven years from that last service. Where the person was under eighteen, we must keep the record until they turn twenty five.
Financial and tax records, including invoices held in Xero, are generally kept for five years as required by the Australian Taxation Office. NDIS records are kept in line with our obligations as a registered provider. Enquiries that do not lead to any service are kept only as long as they are useful and are then deleted.
10. Data breaches
If personal information we hold is lost or accessed without authorisation, and it is likely to cause you serious harm, the Notifiable Data Breaches scheme requires us to notify you and the Office of the Australian Information Commissioner. We have a process for assessing any suspected breach promptly and will keep you informed if you are affected.
11. Accessing and correcting your information
You can ask to see the personal information we hold about you, and you can ask us to correct it if it is wrong, out of date, incomplete or misleading. Email info@fme.com.au or call us on (02) 8044 3365.
We will ask you to verify your identity before we release anything. We will respond within thirty days. There is no charge for making a request, though we may charge a reasonable amount for the cost of copying or providing access to a large record, and we will tell you before we do.
There are limited situations where we may refuse access, for example where giving access would pose a serious threat to someone's life, health or safety, or would unreasonably affect another person's privacy. If we refuse, we will tell you why in writing and explain how to complain.
12. Complaints
If you think we have mishandled your personal information, please tell us first. We would rather hear about it and put it right.
Email info@fme.com.au or call (02) 8044 3365. We will acknowledge your complaint within five business days and aim to resolve it within thirty days. We will tell you the outcome in writing.
If you are not satisfied with our response, you can take it further:
-
Office of the Australian Information Commissioner, at oaic.gov.au or 1300 363 992
-
Information and Privacy Commission New South Wales, at ipc.nsw.gov.au or 1800 472 679, for health information held in New South Wales
-
NDIS Quality and Safeguards Commission, at ndiscommission.gov.au or 1800 035 544, if your complaint relates to NDIS supports
13. Anonymity
You can deal with us anonymously or under a pseudonym where it is lawful and practical, for example when making a general enquiry about course availability or pricing. We cannot deliver counselling, NDIS supports or accredited training anonymously, because we are required to keep records and to register participants by name.
14. Changes to this policy
We review this policy from time to time and will publish any updated version on our website with a new effective date. If we make a significant change to how we handle your information, we will take reasonable steps to tell you.
15. How to contact us
Privacy enquiries, access requests and complaints can be directed to:
Focused Mental Education Pty Ltd
PO Box 7370
Mount Annan NSW 2567
Email: info@fme.com.au
Phone: (02) 8044 3365
ABN 56 678 167 765
Effective date: Monday 21st September 2026
Last reviewed: Monday 21st September 2026
