SKYLINE MEDICAL SOCIETY PTY LTD

ABN: 58 670 966 426 • AHPRA Registered
•Effective Date: June 2026

Privacy Policy

About Us

Skyline Medical Society PTY LTD is an AHPRA-registered integrated healthcare organisation providing mobile dental prosthetics, medical patient care, logistics, digital health services, and aviation-enabled outreach (Skyline Med Flights) across New South Wales and Victoria, Australia. Our Privacy Officer is responsible for ensuring compliance with this policy and can be contacted at the details above.

2. What Personal Information We Collect

2.1 Patient and Client Information
• Full name, date of birth and contact details (phone, email, address)
• Health information including dental and medical history, diagnoses, treatment plans and clinical notes
• Medicare number, DVA number, NDIS participant number, private health fund details
• Referral information from GPs, dentists, specialists or aged care facilities
• Payment and billing information (processed securely — we do not store card numbers)
• Appointment booking history and correspondence with our team

2.2 Website and Online Booking Visitors
• Name and contact details submitted via our website or booking platform
• IP address, browser type and usage data collected via cookies and analytics tools
• Enquiry and message content submitted through contact forms 2.3 Aged Care Facility Contacts
• Facility name, manager name, title, email and phone number
• Resident referral information (with appropriate consent or facility authority)
• Meeting notes and correspondence related to service agreements

2.4 Job Applicants and Interns
• Resume, cover letter, qualifications and references
• Contact details and identity information
• Interview notes and assessment outcomes

3. How We Collect Your Information

We collect personal information in the following ways:
• Directly from you — when you book an appointment, complete intake forms, contact us by phone or email, or engage with our services
• From aged care facilities and healthcare providers — when referring residents or patients to our services
• From government agencies — including Medicare, DVA and NDIS portals for billing and eligibility purposes
• Automatically — via our website and booking platform using cookies, analytics and server logs
• From third parties — including professional referrers, insurance providers and health fund administrators

4. Why We Collect and Use Your Information

We collect and use personal information to:
• Provide safe, effective and personalised dental and medical care to patients and residents
• Process appointments, treatment plans, billing and health fund claims
• Meet our AHPRA registration and health records obligations
• Communicate appointment reminders, follow-up care instructions and service updates
• Improve our services, train our staff and conduct quality assurance activities
• Respond to enquiries, complaints and feedback
• Comply with legal, regulatory and insurance obligations
• Conduct legitimate business operations including marketing, hiring and administration
[We will never use your health information for marketing purposes without your explicit consent.]

5. When We Disclose Your Information

We may disclose your personal information to:
• Other treating healthcare professionals involved in your care (e.g. referring GPs, specialists, aged care nursing staff) — with your knowledge and consent where practicable
• Medicare Australia, DVA, NDIS, private health funds and government voucher administrators for billing and claims
• Aged care facilities where you reside or receive our services
• Our clinical and administrative staff on a need-to-know basis
• IT service providers, booking platform operators and cloud storage providers — subject to confidentiality agreements
• Legal and regulatory authorities — where required by law, court order or regulatory obligation
• Professional indemnity insurers and legal advisors
[We do not sell, rent or trade your personal information to any third party for commercial purposes]

6. Health Records and Sensitive Information

Health information is classified as sensitive information under the Privacy Act. We treat it with the highest level of care and protection. We collect, use and disclose health information only:
• For the primary purpose for which it was collected (i.e. your direct care)
• For a directly related secondary purpose that you would reasonably expect
• With your express consent
• Where required or authorised by law
All clinical records are retained in accordance with applicable State and Territory health records legislation and AHPRA guidelines. Patient records are typically retained for a minimum of 7 years from the date of last service (or until a patient turns 25 years old if they were a minor at the time of treatment).

7. How We Protect Your Information

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. Our security measures include:
• Secure, password-protected electronic records systems with role-based access controls
• Encrypted data transmission via HTTPS for all website and booking platform activity
• Secure physical storage for any paper-based records, with restricted access
• Staff training on privacy obligations and confidentiality
• Regular review of our data storage and access practices
In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme.

8. Your Privacy Rights

8.1  Access to Your Information You have the right to request access to the personal information we hold about you. To make an access request, contact our Privacy Officer at [email protected]. We will respond within 30 days. In some cases, a reasonable administrative fee may apply.

8.2 Correction of Your Information If you believe any personal information we hold about you is inaccurate, incomplete or out of date, you may request that we correct it. We will take reasonable steps to correct information or, if we disagree with your correction request, we will note your concerns on the record.

8.3 Complaints If you believe we have breached your privacy rights, you may lodge a complaint with our Privacy Officer. We will investigate and respond within 30 days. If you are not satisfied with our response, you may escalate your complaint to: • The Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au | 1300 363 992 • The Health Complaints Commissioner in your state or territory

8.4 Withdrawal of Consent Where we rely on your consent to process your information, you may withdraw consent at any time. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal. Note that withdrawing consent for certain processing may affect our ability to provide services to you.

8.5 Opt-Out of Marketing You may opt out of receiving marketing communications from us at any time by: • Clicking the unsubscribe link in any marketing email • Emailing [email protected] with the subject line 'Unsubscribe' • Calling 0456 488 999

9. Cookies and Online Tracking

Our website (skylinemedsociety.com) uses cookies and similar tracking technologies to improve your browsing experience and analyse site traffic. Types of cookies used include:
• Essential cookies — required for the website and booking platform to function
• Analytics cookies — to understand how visitors use our site (e.g. Google Analytics)
• Preference cookies — to remember your settings and choices
You may disable cookies through your browser settings. Disabling certain cookies may affect your ability to use some features of our website or booking platform.

10. Third-Party Links and Platforms

Our website and communications may contain links to third-party websites, booking platforms, social media pages and payment processors. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you interact with.
Our online booking platform is operated by a third-party provider. Personal information submitted through the booking platform is subject to both this Privacy Policy and the platform provider's own privacy terms.

11. Overseas Disclosure

We primarily store and process your personal information in Australia. In limited circumstances, we may use cloud services or platforms that store data on overseas servers. Where we disclose information to overseas recipients, we take reasonable steps to ensure those recipients comply with the Australian Privacy Principles or equivalent standards.

12. Children's Privacy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations or services. The current version will always be available at www.skylinemedsociety.com/privacy-policy. Material changes will be communicated via our website or email notification.

14. Contact Our Privacy Officer

For any privacy-related enquiries, access requests, corrections or complaints, please contact: Organisation Skyline Medical Society PTY LTD ABN 58 670 966 426 Privacy Officer Mr Mutini Nhliziyo DT, DP — Founder & Managing Director Email [email protected] Phone 0456 488 999 Website www.skylinemedsociety.com Address Melbourne, Victoria, Australia

Compliance

Skyline Medical Society PTY LTD · ABN 58 670 966 426 · AHPRA Registered · Effective June 2026 · Version 1.0 This document has been prepared in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Health Records Act 2001 (Vic), Health Records and Information Privacy Act 2002 (NSW), and AHPRA's practitioner obligations.