Privacy policy
Last updated: 13 September 2026
Helix Mens Health Pty Ltd — ACN 696 568 126 · ABN 61 696 568 126
Helix Mens Health is an Australian telehealth clinic. We collect health information about you, which is among the most sensitive information there is. This policy sets out what we collect, why, who sees it, where it lives, and what you can do about it.
We've tried to write it so you can actually read it. If anything here is unclear, email us at admin@helixmenshealth.com.au.
The law that applies to us
We're bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and by the Health Records Act 2001 (Vic) and the Health Privacy Principles.
Small businesses under $3 million in turnover are usually exempt from the Privacy Act. That exemption does not apply to us. Any organisation that provides a health service and holds health information is covered regardless of size, and we are covered from our first patient.
What we collect
Information you give us directly
- Your name, date of birth, email address, phone number, residential address and the state you live in
- Your delivery address, if it's different
- Your answers to our online assessment
- Your medical history questionnaire — past and current medical conditions, medications, allergies, family history, any previous use of testosterone or similar substances, fertility intentions, and lifestyle information including alcohol, smoking, sleep and exercise
- Your height, weight and waist measurement
- Messages you send us through the portal or by SMS, including requests to stop SMS updates
Information created about you during your care
- Your blood test results
- Consultation notes written by your treating doctor
- Your treatment plan, including the medication and dose prescribed
- A record of each prescription and where it was sent
- Records of medication shipped to you
- A record of what you agreed to, and when, including the date, time, IP address and device you agreed from
Information from others
- Blood results from our pathology partner
- Dispensing confirmations from our pharmacy partner
Payment information
Card payments are processed by our payment providers. We never see or store your full card number. We hold a record that a payment was made, for what, and when.
Technical information
When you use our website or portal, our systems record standard technical data — IP address, browser type, pages viewed, and the time of access. Some of this is kept in security and audit logs so we can tell who accessed what.
Why we collect it
Health information is legally "sensitive information", and we can only collect it with your consent. You give that consent when you complete our assessment and medical history questionnaire, and we record when you did.
We collect and use your information to:
- Assess whether treatment is clinically appropriate for you
- Provide your care and let your doctor make safe prescribing decisions
- Arrange your blood tests and your medication
- Monitor your treatment over time
- Communicate with you about your care and your account
- Take payment
- Meet our legal, regulatory and clinical governance obligations
- Improve how the service works — using de-identified information wherever we can
We do not sell your information. We do not disclose it to data brokers, insurers or employers.
Who we share it with
Your treating doctor. Your doctor is an AHPRA-registered medical practitioner engaged by Helix. They have access to the clinical information they need to treat you, and only for patients assigned to them.
Our pathology partner, so your blood tests can be collected and results returned. They receive your name, date of birth, contact details and the tests requested.
Our pharmacy partner, so your prescription can be dispensed and sent to you. They receive your name, date of birth, address and the prescription details.
Our administrative staff, who handle bookings, payments and forwarding prescriptions. Their access is limited to what their role requires.
Our service providers — the companies that host our systems, send our emails and SMS, process our payments and manage bookings. They handle your information only to provide those services to us, and are not permitted to use it for anything else.
Where the law requires it. We may disclose information if we're compelled to by law, a court order, or a regulator such as AHPRA. We'll tell you if that happens, unless we're prohibited from doing so.
In an emergency, where disclosure is necessary to prevent a serious threat to your life, health or safety, or someone else's.
If we ever sell or transfer the business, patient records may transfer with it. You'd be notified before that happened.
Where your information is stored
Your clinical records — your medical history, blood results, consultation notes, treatment plan and prescriptions — are stored in a database hosted in Sydney, Australia. They are not sent overseas.
Some of the services we use to run the business are provided by companies based outside Australia, and some of them process limited information outside Australia. Under the Privacy Act that is an overseas disclosure, so we're setting it out plainly:
| Service | What it handles | Where |
|---|---|---|
| Supabase | Database hosting — all clinical records | Data stored in Sydney, Australia. Company is US-based and staff may access systems for technical support. |
| Netlify | Website and patient portal hosting | United States |
| Resend | Transactional emails — appointment reminders, account notifications | United States |
| Mobile Message | Factual SMS updates, mobile number, message content, replies and delivery status | Australia, according to the provider’s published privacy policy |
| PayPal | Payment processing | United States |
| Cal.com | Appointment booking | United States |
We take reasonable steps to ensure these providers handle your information consistently with the Australian Privacy Principles. Your clinical records — results, notes and medical history — are not sent to any of them.
Automated decisions
Decisions about your treatment are made by a doctor, not by software.
Our systems highlight things for your doctor's attention — a blood result outside the reference range, an answer on your questionnaire that needs discussion. Those are prompts to a human clinician, not decisions. No part of your assessment, approval, dosing or ongoing care is decided automatically.
If that ever changes, we'll update this policy and tell you.
How long we keep it
We keep health records for at least seven years from your last consultation or treatment, as Victorian health records law requires. In some cases we keep them longer, where another law requires it or where we may need them to defend a legal claim.
We keep them even if you stop treatment or close your account. That isn't a choice we get to make — it's a legal retention obligation, and it exists to protect you as much as us.
Payment and tax records are kept for the period required by Australian tax law.
Closing your account
You can close your account yourself, from the Account page in the portal or the app, or by emailing us from the address on your account — we'll ring you to confirm it's you before we act. There's a full explanation at helixmenshealth.com.au/legal/account-deletion.
Your account closes seven days after you ask. In those seven days your membership is cancelled and no charge is taken, scheduled emails are stopped, and we ask the pharmacy to cancel any prescription of yours still with them — but nothing is destroyed, so you can change your mind. On the seventh day we destroy your login and every session, your saved card (at our payment provider, not just our record of it), every queued email, any website enquiry or newsletter sign-up you made before you had an account, advertising attribution, device fingerprints, and your delivery instructions.
We keep your health record — consultation notes, blood results, prescriptions, shipments, bookings, messages and documents — for at least seven years from your last consultation or treatment, as the section above says. If you were under 18 when a record was made, it is kept until you turn 25 or for seven years, whichever is longer. Where a record is the subject of a legal claim, a complaint or a request from a regulator or a court, it is kept until that is resolved. On the day your account closes we compute the exact date your record will be destroyed and email it to you.
Your name, date of birth, email, phone number and address stay on that record. A health record has to belong to a person, and it is how a result that comes back abnormal after you leave still reaches you. You will get no other email from us — no reminders, no receipts, no marketing — except a notice we are obliged to send, such as a recall, a late abnormal result, or a data-breach notification.
Payment and tax records are kept for the period Australian tax law requires, on their own clock. The consents you gave, and the security log recording that an account existed and who accessed it, are kept; nothing can delete from that log.
If you never had a consultation with us and never paid us anything, there is no health record to keep, and everything we hold about you is deleted on the seventh day.
Copies of deleted data may persist in our database backups for up to seven days after deletion. Backups are taken once a day, kept for seven days, used only to recover the whole database after a failure, and then overwritten.
How we protect it
- All access to your record requires authentication, and access is restricted by role. Your doctor sees their own patients. Administrative staff see what their job requires. Nobody has blanket access.
- Access controls are enforced at the database level, not only in the application.
- Access to patient records is logged, and those logs cannot be edited or deleted.
- Data is encrypted in transit and at rest.
- We review our access controls and test them.
No system is perfectly secure, and we won't pretend otherwise. If something goes wrong, see the next section.
If there's a data breach
If your information is lost, accessed without authorisation, or disclosed in a way that's likely to cause you serious harm, we're required by law to notify you and the Office of the Australian Information Commissioner. We'll tell you what happened, what information was involved, and what you should do.
We'll do this promptly. We won't wait for an investigation to conclude before telling you that your information is affected.
Seeing and correcting your information
You can ask for a copy of the health information we hold about you, and you can ask us to correct anything that's wrong.
Email admin@helixmenshealth.com.au. We'll confirm your identity, then respond within 30 days.
There's no charge for making a request. If it's large or complex we may charge a reasonable cost for producing it, and we'll tell you what that is before we do any work.
We can refuse access in limited circumstances set out in the legislation — for example where giving you access would pose a serious threat to someone's life or safety, or would unreasonably affect another person's privacy. If we refuse, we'll tell you why in writing, and how to challenge it.
If we correct something, we keep a record of the original. Clinical records are not rewritten — corrections are recorded alongside what was there before, which is standard practice and protects the integrity of your record.
SMS about your care
We may send factual SMS about existing care and account events. Messages identify Helix Mens Health and direct you to your signed-in account. SMS can appear on a lock screen and reveal your relationship with the clinic; we keep detailed clinical information in the portal.
Reply STOP to stop SMS. This does not cancel your care or stop necessary emails. Changing your profile or phone number does not restart SMS. We retain a minimal record of the stopped number so we can honour that request. A message already in transit may still arrive.
Our SMS provider is Mobile Message. Its [privacy policy](https://mobilemessage.com.au/privacy) describes its processing of messages and replies and states that its servers are in Australia. Contact admin@helixmenshealth.com.au about your communication preferences. Use urgent medical services when you need urgent care; SMS replies are not an emergency service.
Marketing
We send you emails about your care and your account. Those aren't marketing, and you can't opt out of them while you're a patient — they include things like blood test reminders and prescription notifications.
We may also send you general health information and updates about our service. You can opt out of those at any time, using the unsubscribe link or by emailing us.
We never use your health information — your results, your diagnosis, your treatment — to target advertising to you.
Can you deal with us anonymously?
Not for treatment. We're prescribing a Schedule 4 prescription medicine, and the law requires that your doctor knows who you are.
You can browse our website without telling us who you are, and you can ask us general questions about the service without creating an account.
Cookies, analytics and advertising
Essential cookies. Our patient portal uses cookies to keep you signed in and to keep your session secure. The portal doesn't work without them.
Analytics. We use Google Analytics on our public website to understand how people find and use it — which pages get visited, how long people stay, which devices they use. This tells us about traffic patterns, not about you as an individual, and it isn't linked to your patient record.
Advertising. We advertise on Meta platforms, and our public marketing pages carry a Meta advertising pixel that tells us whether an ad led to a visit.
You can block or delete cookies in your browser settings. Some parts of the portal won't work if you do. You can opt out of Google Analytics using Google's browser add-on, and you can adjust ad personalisation in your Meta account settings.
Complaints
If you think we've mishandled your information, email admin@helixmenshealth.com.au and tell us what happened. We'll acknowledge it within 5 business days and give you a response within 30 days. Most things get sorted faster that way.
Changes to this policy
We'll update this policy as the service changes. The version number and date at the top tell you which version you're reading.
If we make a change that materially affects how we handle your information, we'll tell you directly rather than quietly republishing the page.
Contact us
Privacy Officer Helix Mens Health Pty Ltd admin@helixmenshealth.com.au
Version 2.2