How we collect, use and protect personal information, and the rights available to you. We work in healthcare, where confidentiality is not optional, and we hold our own practices to that standard.
Lenia Health is committed to protecting the privacy of everyone who visits our website, contacts us, or works with us. This policy explains what information we collect, why we collect it, how we handle it, and the choices and rights available to you.
We work exclusively in healthcare, an industry where confidentiality is not optional. That standard applies to how we handle our own data practices as much as to the systems we build for our clients.
Lenia Health Pty Ltd ("Lenia Health", "we", "us", "our") is a healthcare technology company delivering integration, data, artificial intelligence and cloud solutions to healthcare organisations. We are the data controller responsible for the personal information described in this policy.
Our registered office is at 5a Hartnett Cl, Mulgrave VIC 3170, Australia. We operate teams in Australia and India and serve healthcare organisations globally.
This policy covers personal information we collect when you:
This policy does not cover how we handle data inside client environments during a delivery engagement. That is governed by the specific contract, data processing agreement and security schedule agreed with each client. See section 6.
We may receive limited information about you from publicly available professional sources such as company websites and professional networking platforms, from mutual business contacts who introduce us, or from event organisers where you have consented to your details being shared with participating organisations.
| Purpose | What this involves |
|---|---|
| Responding to enquiries | Reading your message, replying, arranging a call and discussing whether and how we can help |
| Delivering services | Performing work under contract, managing projects, providing support and reporting on progress |
| Managing relationships | Contract administration, invoicing, account management and supplier coordination |
| Improving our website | Understanding which pages are useful, diagnosing errors and improving structure and content |
| Security and integrity | Detecting and preventing fraud, spam, unauthorised access and misuse of our systems |
| Legal compliance | Meeting obligations under tax, corporate, employment and data protection law |
| Recruitment | Assessing applications, conducting interviews and communicating outcomes |
We do not sell personal information. We do not share it with advertisers. We do not use it for automated decision-making that produces legal or similarly significant effects.
Where data protection law requires us to identify a legal basis, we rely on the following:
In the course of delivering integration, data, AI and cloud services, we may work within environments that contain patient health information or other sensitive personal data. Our approach to this is deliberate and consistent.
We share personal information only where there is a clear reason to do so:
We operate in Australia and India and serve clients globally, so personal information may be transferred to and processed in countries other than the one in which it was collected.
Where we transfer personal information across borders, we put appropriate safeguards in place. These include standard contractual clauses approved by relevant authorities, assessments of the legal environment in the receiving country, and contractual restrictions on onward transfer. Where a client requires data to remain within a specific jurisdiction, we architect the solution accordingly and confirm this in the engagement contract.
Security is designed into how we operate rather than added afterwards. Our measures include:
No system can be guaranteed completely secure. If a breach occurs that is likely to result in serious harm, we will notify affected individuals and the relevant regulator within the timeframes required by applicable law.
| Type of information | Retention period |
|---|---|
| Website enquiries that do not progress | 24 months from last contact |
| Client relationship records | Duration of the relationship plus 7 years |
| Contracts and financial records | 7 years, as required by Australian tax and corporate law |
| Client environment access logs | As specified in the engagement contract, typically 12 to 24 months |
| Unsuccessful job applications | 12 months, unless you consent to a longer period |
| Website analytics | 26 months in aggregated form |
When information is no longer needed we delete it or irreversibly anonymise it.
Subject to the law that applies to you, you have the right to:
To exercise any of these rights, email contact@leniahealth.com. We respond within 30 days and will not charge a fee unless a request is manifestly unfounded or excessive. We may ask you to verify your identity before we act.
If your request concerns data held inside a client environment, we will direct it to the healthcare organisation that controls that data, as they are the appropriate party to respond.
We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We handle health information in accordance with the additional protections that apply to sensitive information. If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
We comply with the Digital Personal Data Protection Act 2023 and applicable rules regarding notice, consent, purpose limitation and the rights of Data Principals, including the right to nominate another individual to exercise rights on your behalf.
Where the General Data Protection Regulation or UK GDPR applies, you have the rights described in section 11 and may lodge a complaint with your national supervisory authority. Transfers of personal data outside the EEA or UK are made under standard contractual clauses or another approved transfer mechanism.
Where we handle protected health information on behalf of a covered entity or business associate, we do so under a business associate agreement consistent with HIPAA requirements. Residents of states with applicable privacy legislation may have additional rights of access, deletion and opt-out, which we honour on request.
Where local law provides rights or protections beyond those described here, we apply the higher standard.
We use a small number of cookies and similar technologies. Essential cookies are necessary for the site to function. Analytics cookies are used only with your consent and help us understand which content is useful. Full detail, including how to manage your preferences, is in our Cookie Policy.
Our website contains links to external sites we do not control. This policy does not apply to them. We encourage you to read the privacy policy of any site you visit.
Our website and services are directed at healthcare organisations and business professionals. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we will delete it.
We review this policy regularly and update it when our practices change or the law requires. The date at the top of this page shows when it was last revised. Material changes will be signalled prominently on our website. Where the change affects processing based on your consent, we will seek fresh consent.
For any question about this policy, to exercise your rights, or to raise a concern about how we have handled your information, contact us directly. We take privacy complaints seriously and will investigate and respond substantively.
Privacy enquiries and data requests