AccessOncology Pty Ltd Privacy Policy
- Introduction
AccessOncology Pty Ltd (we, us, our) respects your privacy and we are committed to protecting personal information. This Privacy Policy outlines how we collect, use, handle and disclose personal information that we collect through our websites, “ScienceToLife”, “CPD4MedProfessional”, related platforms, applications and processes. Personal information we collect will be treated strictly in accordance with the Privacy Act 1988 (Cth) (Privacy Act), the Australian Privacy Principles (APPs) and this Privacy Policy.
From time to time we may also use computer programs and other automated tools as part of our websites. Where those tools use personal information to make decisions that could significantly affect you, this is explained in section 16 below in accordance with.
- How we collect personal information and types of personal information we collect
We collect and store personal information that is reasonably necessary for, or directly related to, the functions and activities of our website, CPD System and associated services. This may include your name, postal address, contact numbers, billing and payment information, your professional qualifications, your continuing professional development (CPD) information and deidentified patient information (which may include sensitive information such as health information).
Where a third-party payment gateway is used your handled in accordance with the payment provider’s security standards.
We collect this information in numerous ways, including:
(a) when you register on and visit our CPD System, including when you submit information through our online forms;
(b) when you send us an inquiry, email or contact us;
(c) when administering any part of our services;
(d) customer satisfaction or feedback enquiries; and
(e) from publicly available or other sources, such as our business partners.
Where you do not wish to provide us with your personal information, we may not be able to provide you with requested goods or services.
- Our purpose for handling your personal information
As a general rule, personal information should only be processed for purposes that are relevant, reasonable in the circumstances, and reasonably necessary for the functions and activities of the business.
We collect, hold, use and disclose personal information to:
(a) offer and provide you with our products and services, including the CPD System which tracks and manages your CPD information and deidentified patient information;
(b) manage and administer the CPD System and other services we provide you, including account keeping procedures;
(c) communicate with you regarding our products and services;
(d) comply with our legal and regulatory obligations; and
(e) otherwise to manage our business.
Our CPD System stores personal information for 7 years to comply with the CPD requirements of the Medical Board of Australia.
For CPD4MedProfessional we may disclose your personal information to third parties who provide us with technical and support services or our professional advisers, where permitted under the Privacy Act. This may include sending personal information outside of Australia, such as to Stream Interactive Limited in New Zealand. We do not otherwise disclose your personal information to third parties unless required by law or instructed by you to supply the relevant College with the CPD hours completed by you in any given year.
- Direct Marketing
We may use your personal information to let you know about products and services that we think may be of interest to you. However, you may opt out of receiving marketing information at any time by using the contact details provided in section 13 of this Privacy Policy.
We will not disclose your personal information to third parties for marketing purposes without your consent.
- Access to and Correction of Personal Information
Subject to the Privacy Act, you have the right to access and correct the personal information that we hold about you at any time. You may also request that we delete your personal information.
To make a request, please contact us using the details provided in section 13 of this Privacy Policy. We will respond to all requests for access to, or correction of, personal information within a reasonable time.
We may seek to recover from you reasonable costs incurred for providing you with access to any of the personal information about you held by us.
We are not obliged to correct any of your personal information if we do not agree that it requires correction and may refuse to do so. If we refuse a correction request, we will provide you with a written notice stating our reasons for refusing.
- Collection of Deidentified Patient Information
The deidentified patient information we collect may include but is not limited to medical diagnoses, treatment history and other related information. We ensure that all patient information collected is deidentified in accordance with the Privacy Act and APPs (Australian Privacy Principles), so that individuals cannot be identified from the information.
Generally, deidentification involves removing personal identifiers (such as name, address, date of birth, contact details and individual healthcare identifiers) and taking reasonable steps to reduce the risk that individuals can be re-identified, including through aggregation or suppression of rare or unique data combinations.
- Purpose of Collection of Deidentified Patient Information
The purpose of collecting deidentified patient information is to provide products and services (including the CPD System). Deidentified information may also be used and/or aggregated deidentified patient information and data may be provided to third parties for the purposes of:
(a) enabling insight into treatment patterns;
(b) improving healthcare and clinical practices and patient outcomes;
(c) enabling the development of research, studies, statistical analyses, modelling and reports;
(d) enhancing medical knowledge through publication of journals, articles and/or other materials.
It is not possible to identify individuals from the aggregated deidentified patient information or data.
Deidentified or aggregated datasets should not be used to attempt re-identification of individuals, and recipients should be contractually or otherwise restricted to research, educational or analytical purposes consistent with this Privacy Policy.
- Use and Disclosure of Deidentified Patient Information
We use and may allow third parties to use deidentified patient information solely for the purpose for which it was collected as provided in section 7 of this Privacy Policy.
Any sharing of deidentified patient information should be undertaken in a way that is intended to minimise the risk of re-identification, in accordance with Office of the Australian Information Commissioner (OAIC) guidance on de-identification and health privacy.
- Deidentification of Patient Information
We take reasonable steps to ensure that the patient information we collect is deidentified in accordance with the Privacy Act and APPs. This means that the information is stripped of any identifying information, such as names, addresses, or other personal information, so that individuals cannot be identified from the information.
You must take all reasonable steps to ensure that any patient personal information submitted to our CPD System has been appropriately deidentified and is used solely for purposes of complying with your CPD obligation, developing patient treatment patterns or pathways and/or improving healthcare outcomes. Where required by the Privacy Act and APPs, you must obtain a patient’s consent prior to entering their personal information or sensitive information (such as their health information) into the CPD System.
In some circumstances, health information and other sensitive information may remain personal information even after certain identifiers are removed. Information that could reasonably allow a patient to be identified, including combinations of dates, locations, uncommon diagnoses or other unique characteristics, should not be entered unless lawfully permitted and appropriately managed.
- Protection of personal information and security measures
We take reasonable steps to protect the personal information we hold from misuse, interference, loss, unauthorised access, modification or disclosure. We maintain appropriate security measures, including firewalls and secure servers, and procedures to protect your personal information.
Security controls and relevant vendor arrangements, including any overseas hosting or support arrangements, are reviewed periodically having regard to the nature and sensitivity of the information handled.
- Overseas transfers of personal information
We will hold personal information electronically on our CPD System, in cloud storage, and in some cases, on third party servers, which may be located overseas (such as New Zealand).
By providing your personal information to us:
(a) you consent to the storage of your personal information on overseas servers;
(b) you consent to us disclosing your personal information to any overseas recipients for purposes necessary or useful in the course of operating our business; and
(c) you agree that APP 8.1 will not apply to such disclosures.
Overseas recipients may include hosting and infrastructure providers, technical support providers and analytics or email delivery services used in connection with the CPD System and related services. Some of these providers may be located in New Zealand and other countries. Individuals may contact the Privacy Officer using the details in section 13 for more information about the categories of overseas recipients used.
Independently of consent, reasonable steps such as due diligence and contractual protections are taken to seek to ensure that overseas recipients protect personal information in a manner consistent with the APPs.
- Compliance with Australian Privacy Laws
We comply with the APPs and the Privacy Act. This includes our obligations to:
• manage personal information in an open and transparent way;
• collect personal information only for lawful purposes that are reasonably necessary;
• ensure that personal information we hold is accurate, up-to-date, and complete;
• use and disclose personal information only for the purposes for which it was collected or as required by law;
• protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure;
• provide individuals with access to their personal information and the ability to correct or delete it;
• have a clearly expressed and up-to-date privacy policy that explains our privacy practices.[cite:8]
- Contact Us
If you have any questions, concerns or complaints about this Privacy Policy or how personal information is handled, or wish to make a request to access, correct or delete personal information, please contact the Privacy Officer at: Team@ScienceToLife.com.au.
If you are dissatisfied with the handling of your complaint, you may contact the Office of the Australian Information Commissioner:
Office of the Australian Information Commissioner
GPO Box 5218
Sydney NSW 2001
Telephone: 1300 363 992
Email: enquiries@oaic.gov.au[cite:8]
- Cookies
A cookie is a small text file stored in a computer’s memory or on a hard disk for a pre-defined period of time. Cookies may be used to identify specific machines in order to collect aggregate information on how visitors are experiencing the website. This information helps adapt the website to suit user requirements. While cookies allow a computer to be identified, they do not by themselves identify a specific individual.
Cookies and similar technologies may also be used for analytics, performance monitoring, session management, authentication, security and remembering user preferences. Most web browsers allow cookies to be disabled or managed through browser settings, although doing so may affect website functionality.
- Changes to this Privacy Policy
We reserve the right to change the terms of this Privacy Policy from time to time, without notice. An up-to-date copy of this Privacy Policy will be made available on the website. Users are encouraged to review this Privacy Policy periodically to ensure awareness of any changes.
- Automated decision-making and use of computer programs
Computer programs and other automated tools may be used within the CPD System to assist with activities such as analytics, dashboard reporting, tracking CPD completion, applying CPD rules and, in future, recommending educational content that may be relevant to a user’s practice.
These tools may use personal information such as registration details, CPD history, professional role, specialty information and activity data generated through use of the CPD System.
Where a computer program is arranged to make, or do a thing that is substantially and directly related to making, a decision using personal information and that decision could reasonably be expected to significantly affect an individual’s rights or interests, further information will be made available in this Privacy Policy and through associated privacy notices in accordance with applicable APP requirements commencing on 10 December 2026.
Individuals may contact the Privacy Officer using the details in section 13 if they would like more information about the use of automated tools, analytics or future recommendation features within the CPD System.
The last update to this document was July 2026.