Ordime Pty Ltd respects the privacy of the businesses, users and individuals whose information is processed through the Ordime platform.
This Privacy Policy explains how Ordime Pty Ltd collects, holds, uses, processes, discloses, protects and otherwise handles personal information in connection with the Ordime website, platform, applications and related services.
Ordime is operated by:
Ordime Pty Ltd
ABN 95 700 576 978
Victoria 3550
Australia
Privacy enquiries: legal@ordime.com.au
Ordime is a software-as-a-service platform used by businesses to manage their operations, including appointments, clients, treatment records, communications, invoicing, payments, staff and other business activities.
An important distinction exists between:
information Ordime collects and manages for its own business and platform operations; and
information that Ordime Customers collect and maintain about their own Clients using the Ordime platform.
This distinction is explained throughout this Policy.
1. Scope of this Privacy Policy
This Privacy Policy applies to personal information handled by Ordime in connection with:
the Ordime website;
the Ordime platform;
Ordime Accounts;
Customer Workspaces;
online booking functionality;
subscription and billing services;
support services;
email and SMS functionality;
integrations;
communications from Ordime; and
other related Ordime services.
Ordime seeks to handle personal information consistently with applicable Australian privacy laws, including the Privacy Act 1988 (Cth) and Australian Privacy Principles where applicable.
Where health information is subject to state or territory health privacy legislation, including the Health Records Act 2001 (Vic), applicable requirements may also apply.
Nothing in this Privacy Policy limits any right or obligation that cannot lawfully be excluded.
2. Definitions
In this Privacy Policy:
Account means an individual user account used to access Ordime.
Authorised User means an individual authorised by a Customer to access a Customer Workspace.
Client means a customer, patient, prospective customer, recipient of services or other individual whose information is entered into or maintained within Ordime by a Customer.
Customer means the business, organisation, sole trader or other entity that creates, owns or subscribes to an Ordime Workspace.
Customer Data means information entered into, uploaded to, created within or otherwise processed through Ordime by or on behalf of a Customer.
Customer-controlled Client Data means Customer Data relating to a Customer's Clients, including appointment, treatment, health, contact, billing and other Client records.
Health Information means information relating to an individual's health, medical history, treatment, health services or other information regarded as health information under applicable Australian law.
Personal Information means information or an opinion about an identified individual or an individual who is reasonably identifiable.
Sensitive Information includes categories of information receiving additional protection under applicable privacy legislation, including Health Information.
Workspace means the separate Ordime environment established for a particular Customer.
Ordime, we, us or our means Ordime Pty Ltd.
Part A — The relationship between Ordime, Customers and Clients
3. Ordime is a SaaS platform
Ordime provides software infrastructure that Customers use to operate and manage their businesses.
Our Customers decide how they use the platform and what Client information they collect through it.
For example, a Customer may choose to use Ordime to maintain:
Client contact details;
appointment history;
treatment records;
medical information;
consultation forms;
consent records;
treatment photographs;
invoices;
communications; and
other Client information.
Ordime does not establish the underlying professional, commercial, clinical or service relationship between a Customer and its Client.
The relationship between a Client and the business providing services to that Client remains a relationship between the Customer and the Client.
4. Customer responsibility for Client Data
Customers are responsible for determining, subject to applicable law:
what Client information they collect;
why they collect it;
whether collection is necessary;
whether consent is required;
how the information is used;
which members of their business may access it;
how long they are required to retain it;
whether information should be corrected;
whether information should be disclosed;
whether information may lawfully be deleted; and
how they respond to privacy, health-record and other requests from their Clients.
Customers are responsible for their own compliance with applicable:
privacy legislation;
health-record legislation;
professional obligations;
clinical recordkeeping obligations;
consent requirements;
consumer laws; and
industry requirements.
Customers should maintain their own privacy policies, collection notices, consent processes and other documentation where required.
Ordime's Privacy Policy does not replace the Customer's privacy obligations to its Clients.
5. Ordime's role in relation to Customer-controlled Client Data
Ordime stores and processes Customer-controlled Client Data principally for the purpose of providing the Ordime Service to the relevant Customer.
Ordime does not ordinarily decide:
whether a Client should be given access to their records;
whether Client information should be corrected;
whether Client information should be deleted;
whether treatment or health records should be released;
whether consent should be withdrawn or amended;
whether information should continue to be retained by the Customer; or
whether information should be disclosed to another person.
Those decisions ordinarily remain with the Customer that collected and maintains the information.
Ordime will not independently release, alter or delete Customer-controlled Client Data merely because a Client asks Ordime to do so.
Ordime may take action concerning Customer-controlled Client Data where:
instructed or authorised by the relevant Customer;
necessary to provide or secure the Ordime Service;
necessary to investigate misuse, fraud or a security incident;
required or authorised by applicable law;
required by a court or tribunal order; or
otherwise permitted under our agreement with the Customer and applicable law.
Part B — Information processed through Ordime
6. Information Ordime collects about Account holders
When an individual creates or uses an Ordime Account, we may collect and process information including:
full name;
email address;
telephone number;
profile information;
profile photograph or avatar;
business name;
position or role;
Workspace membership;
user permissions;
login information;
password information in securely protected form;
multi-factor authentication information;
account recovery information;
authentication events;
IP addresses;
session information;
security events;
device and browser information;
communication preferences; and
information supplied directly to Ordime.
We may also retain information showing actions performed by an Authorised User for security, auditing and recordkeeping purposes.
7. Customer business information
When a Customer creates and operates a Workspace, information processed through Ordime may include:
business name;
trading name;
ABN;
business addresses;
telephone numbers;
email addresses;
operating locations;
business hours;
business settings;
GST and taxation settings;
staff information;
staff positions;
staff permissions;
roster information;
services;
products;
pricing;
suppliers;
inventory information;
assets;
business policies;
subscription information;
payment configuration; and
other information required to operate the Customer's business through Ordime.
Some business information may also constitute Personal Information, particularly where a Customer is a sole trader or information identifies an individual staff member.
8. Client information
Customers may use Ordime to collect and maintain information about their Clients.
Depending on the Customer and its use of Ordime, Customer-controlled Client Data may include:
name;
residential or postal address;
email address;
mobile or telephone number;
date of birth;
emergency contact information;
appointment history;
future appointments;
cancellations;
no-show information;
booking preferences;
service history;
purchases;
products;
gift cards;
loyalty or rewards information;
invoices;
payments;
deposits;
refunds;
credits;
Client notes;
communications;
consultation information;
forms;
consent records;
photographs;
documents;
uploaded files;
treatment records;
Health Information; and
other information entered by the Customer.
The Customer determines what Client information is appropriate and necessary for its business.
9. Health and Sensitive Information
Ordime is designed for use by businesses that may include medical aesthetics clinics, skin clinics, allied health providers and other businesses that maintain health or treatment information.
Customers may therefore use Ordime to store Health Information and other Sensitive Information.
This may include:
medical history;
medical conditions;
allergies;
medications;
contraindications;
previous procedures;
previous treatments;
treatment plans;
treatment settings and parameters;
clinical observations;
practitioner notes;
consultation records;
informed consent records;
treatment outcomes;
adverse reactions;
treatment photographs;
before-and-after photographs; and
other information relating to health or treatment services.
Customers are responsible for ensuring that they are entitled to collect and use such information and for obtaining any consent required by applicable law.
Ordime processes this information for purposes connected with providing, maintaining, securing and supporting the Service.
Ordime does not use identifiable Client Health Information for Ordime's own advertising or direct-marketing activities.
10. Information relating to minors
Customers may maintain Client records relating to persons under 18 years of age.
Ordime requires Customers using the platform for minors to obtain appropriate consent from an adult parent, legal guardian or other adult with lawful authority before collecting or maintaining the minor's information through Ordime.
Customers are responsible for:
confirming the identity or authority of the adult providing consent;
obtaining appropriate consent;
recording consent where necessary;
determining which information may lawfully be collected;
controlling access to the minor's information;
complying with applicable professional obligations; and
complying with applicable privacy and health-record laws.
This section concerns Client records.
Separate age requirements apply to individuals creating or using Ordime Accounts under the Ordime Terms of Service.
11. Online booking information
When a Client interacts with an online booking page operated by a Customer through Ordime, information may be collected including:
Client name;
email address;
telephone number;
selected service;
selected location;
selected staff member;
appointment date and time;
appointment notes;
booking status;
deposit information;
cancellation information; and
other information requested by the Customer.
This information is collected for the Customer with whom the Client is making the booking.
The Customer remains responsible for determining what information it requires from its Clients.
12. Payment and transaction information
Ordime may process information concerning:
subscription payments made by Customers to Ordime; and
payments made by Clients directly to Customers through payment functionality integrated with Ordime.
Information may include:
transaction identifiers;
Stripe identifiers;
invoice information;
amounts;
currency;
payment status;
subscription status;
refunds;
credits;
deposits; and
payment-method metadata.
Ordime uses Stripe for payment processing and related payment infrastructure.
Where payment-card interfaces are provided by Stripe, card information may be submitted directly to Stripe rather than being received or stored directly by Ordime.
Where Clients make payments to an Ordime Customer, those funds are paid to the relevant Customer through its connected payment account.
Ordime does not ordinarily receive or hold those Client funds.
13. Email and SMS information
Ordime allows Customers to communicate with Clients by email and SMS.
Information processed for these communications may include:
recipient name;
email address;
mobile telephone number;
message content;
message template;
communication type;
timestamps;
delivery status;
bounce or failure information;
unsubscribe status; and
other delivery metadata.
Ordime currently uses:
Postmark for email delivery; and
ClickSend for SMS delivery.
Information necessary to deliver communications may therefore be transmitted to these providers and their authorised subprocessors.
Customers remain responsible for determining whether they are permitted to send particular communications to their Clients.
14. Support information
If you contact Ordime directly for support, we may collect:
your name;
email address;
telephone number;
Account details;
business details;
Workspace information;
details of your support enquiry;
screenshots;
attachments;
diagnostic information;
correspondence; and
information necessary to investigate the issue.
Customers should avoid providing Client Health Information or other Sensitive Information to Ordime support unless reasonably necessary to investigate an issue.
15. Technical and security information
When Ordime is used, our systems may automatically process information such as:
IP address;
date and time of requests;
browser information;
operating system;
device information;
Account identifiers;
session identifiers;
login events;
failed login attempts;
authentication events;
security events;
pages or functions accessed;
API activity;
application errors;
infrastructure logs; and
diagnostic information.
We use this information for purposes including security, authentication, troubleshooting, auditing, abuse prevention and maintaining the reliability of the Service.
Part C — How information is collected and used
16. How Ordime receives information
Ordime may receive Personal Information:
directly from you;
when an Account is created;
when a Customer creates a Workspace;
when a Customer adds an Authorised User;
when a Customer enters information about a Client;
when a Client makes an online booking;
when a Client completes a form provided by a Customer;
when a payment is processed;
when email or SMS functionality is used;
when you contact Ordime support;
automatically through use of the platform;
from an integrated third-party provider;
from another authorised user of the relevant Workspace; or
where otherwise permitted by law.
Because Ordime is a SaaS platform, a significant proportion of Client information processed by Ordime is collected by or on behalf of the Customer rather than directly by Ordime for Ordime's own purposes.
17. How Ordime uses information
Ordime may process Personal Information where reasonably necessary to:
provide the Service;
operate Customer Workspaces;
create and administer Accounts;
authenticate users;
maintain security;
manage user permissions;
provide online booking functionality;
store Customer Data;
process Subscription billing;
facilitate integrated payments;
send requested email and SMS communications;
maintain audit records;
provide customer support;
diagnose technical issues;
investigate security incidents;
prevent fraud and misuse;
maintain infrastructure;
perform backups and disaster recovery;
enforce the Terms of Service;
comply with legal obligations;
manage Ordime's business;
improve reliability and performance;
communicate with Ordime Customers and users; and
perform other functions reasonably necessary to provide the Service.
Where Ordime processes Customer-controlled Client Data, processing is principally undertaken to provide services to the relevant Customer.
18. Customer-directed processing
Many actions performed by Ordime are initiated by a Customer or an Authorised User.
For example, a Customer may instruct Ordime's systems to:
create a Client record;
create an appointment;
send an appointment confirmation;
send an SMS reminder;
generate an invoice;
record a treatment;
upload a photograph;
issue a refund through an integrated payment provider;
produce a report; or
export information.
Ordime processes information as necessary to carry out those platform functions.
The fact that Ordime technically performs or facilitates an action does not mean that Ordime determines whether the Customer was entitled to perform that action.
19. Communications from Ordime
Ordime may communicate directly with Customers and Authorised Users.
Operational communications
These may include:
account verification;
password notifications;
security alerts;
multi-factor authentication;
Subscription information;
billing communications;
support communications;
maintenance notices;
service announcements;
important product changes;
changes to our Terms or policies; and
other communications required to operate the Service.
Users may not be able to opt out of essential operational communications while maintaining an active Ordime Account.
Marketing communications
Ordime may also send:
product announcements;
new-feature information;
promotional offers;
ambassador information;
educational content; and
other marketing relating to Ordime.
Where required by law, marketing communications will contain an appropriate unsubscribe mechanism.
Opting out of marketing will not prevent essential account, security, billing or service communications.
20. Product improvement and analytics
Ordime may analyse how the Service is used to improve:
reliability;
performance;
security;
user experience;
functionality;
capacity planning; and
future product development.
Where reasonably practicable, aggregated or de-identified information will be used for broader product analysis.
At the date of this Privacy Policy, Ordime does not use Google Analytics, Meta Pixel, Microsoft Clarity or similar third-party behavioural marketing analytics services on its website.
21. Aggregated and de-identified information
Ordime may create aggregated or de-identified information from information processed through the Service.
Where information has been properly de-identified so that an individual is no longer reasonably identifiable, Ordime may use that information for purposes including:
product development;
statistical analysis;
benchmarking;
capacity planning;
service improvement;
security;
performance analysis;
internal business planning; and
understanding general industry trends.
Ordime will not describe information as de-identified merely because obvious identifiers have been removed where an individual remains reasonably identifiable.
Ordime does not use identifiable Client Health Information to train general-purpose artificial-intelligence models.
22. Automated decision-making
Ordime does not currently use Personal Information to make solely or substantially automated decisions that have a significant legal or similarly significant effect on an individual.
Ordinary platform automation such as appointment reminders, notifications, scheduling functionality and reporting does not involve Ordime independently deciding an individual's legal, medical or professional rights.
If Ordime introduces materially significant automated decision-making in the future, we will update our privacy disclosures as required.
Part D — Disclosure and third-party providers
23. Ordime does not sell Personal Information
Ordime does not sell Personal Information.
Ordime does not sell Customer Client databases, treatment information or Health Information to advertisers, data brokers or third parties.
We disclose or make information available to third parties only where reasonably necessary to provide or secure the Service, comply with law or otherwise as described in this Privacy Policy.
24. Service providers
Ordime relies on third-party service providers to operate the platform.
These may include providers of:
application hosting;
database hosting;
object storage;
content delivery;
cybersecurity;
payment processing;
email delivery;
SMS delivery;
telecommunications;
technical infrastructure;
professional advice; and
other supporting services.
Information is disclosed to or processed by these providers only to the extent reasonably necessary for the relevant service.
Our principal providers currently include the following.
Railway
Railway provides application and database infrastructure.
Ordime's primary production application and database are hosted in Singapore.
Cloudflare
Cloudflare provides internet infrastructure, security functionality and object-storage services.
Ordime uses Cloudflare R2 to store files and objects uploaded to or generated through the Service.
The location at which R2 information is stored or processed depends on Cloudflare's infrastructure and the configuration of the relevant storage bucket.
Stripe
Stripe provides Subscription billing and payment infrastructure.
Stripe may process account, payment and transaction information necessary to provide these services.
Postmark
Postmark provides email-delivery infrastructure.
Information required to deliver emails may be transmitted through Postmark and its supporting infrastructure.
ClickSend
ClickSend provides SMS and related communications services.
Information required to deliver messages may be transmitted through ClickSend, telecommunications carriers and associated infrastructure.
Ordime may add, replace or change providers as the Service develops.
Where a change materially alters our privacy practices, this Privacy Policy will be updated as appropriate.
25. Overseas storage and processing
Ordime is an Australian company, but information processed through the Service may be stored, transmitted or processed outside Australia.
In particular:
Ordime's primary Railway application and database infrastructure is hosted in Singapore;
Railway's operations and supporting infrastructure may involve processing in the United States;
communications providers and their subprocessors may process information in Australia and overseas;
payment providers may operate global infrastructure; and
Cloudflare operates global infrastructure.
Depending on the particular provider and service used, Personal Information may be processed in countries including:
Australia;
Singapore;
United States of America;
countries within the European Union;
Philippines; and
other countries in which our infrastructure, telecommunications, payment or communications providers operate.
The precise locations may change as providers change their infrastructure or subprocessors.
Where applicable Australian privacy legislation imposes obligations relating to overseas disclosures, Ordime will take reasonable steps appropriate to the circumstances regarding overseas handling of Personal Information.
Customers acknowledge that using a cloud-based SaaS platform may involve processing through infrastructure located outside Australia.
26. International communications
If a Customer sends an SMS, email or other communication to a person outside Australia, information may be transmitted through telecommunications networks and providers operating in the recipient's country.
Customers are responsible for determining whether they are authorised to send those communications.
27. Third-party integrations
Ordime may provide integrations with third-party services.
Where a Customer chooses to activate an integration, information may be exchanged with the third-party provider to the extent necessary to provide the integration.
The Customer is responsible for deciding whether to enable the integration.
Once information is disclosed to a third-party service operating independently of Ordime, that provider's own privacy terms and practices may apply.
Customers should review the privacy practices of third-party services before connecting them to Ordime.
28. Legal disclosures
Ordime may use or disclose information where reasonably necessary or legally required to:
comply with Australian law;
comply with a court or tribunal order;
comply with a valid regulatory requirement;
respond to lawful law-enforcement requests;
investigate suspected unlawful activity;
prevent or investigate fraud;
investigate a security incident;
prevent a serious threat to safety;
protect Ordime's legal rights;
enforce contractual rights; or
establish, exercise or defend legal claims.
Where appropriate, Ordime will seek to limit any disclosure to information reasonably necessary for the relevant purpose.
Part E — Cookies and communications
29. Cookies and similar technologies
Ordime uses cookies and similar browser technologies where necessary to operate its website and platform.
These may be used for purposes including:
authentication;
maintaining user sessions;
security;
fraud prevention;
protecting Accounts;
remembering essential settings; and
providing platform functionality.
At the date of this Policy, Ordime does not use third-party behavioural advertising or marketing analytics tools such as Google Analytics, Meta Pixel or Microsoft Clarity.
If this changes materially, our privacy disclosures and, where required, consent mechanisms will be updated.
Disabling essential cookies may prevent the Service from operating correctly.
30. Communications sent by Customers
Customers may use Ordime to send email and SMS communications to their own Clients.
The Customer is responsible for determining:
whether the communication should be sent;
who it should be sent to;
whether appropriate consent exists;
whether the communication constitutes marketing;
whether required sender identification is present;
whether an unsubscribe facility is required; and
whether the communication otherwise complies with applicable law.
Ordime provides the software functionality but does not independently determine whether a Customer is legally entitled to send a particular message.
Ordime may restrict messaging functionality where reasonably necessary to investigate spam, abuse, fraud, security risks or misuse of our communications infrastructure.
Part F — Security and platform access
31. Security
Ordime takes reasonable technical and organisational measures designed to protect information against:
misuse;
interference;
loss;
unauthorised access;
unauthorised modification; and
unauthorised disclosure.
Measures may include:
encrypted communications;
secure cloud infrastructure;
authentication controls;
password hashing;
multi-factor authentication;
role-based access controls;
session controls;
security monitoring;
audit logs;
backups;
restricted administrative access; and
incident-response processes.
No internet-based system can be guaranteed to be completely secure.
Customers are also responsible for security measures under their control, including:
password security;
staff access;
device security;
user permissions;
connected third-party accounts; and
promptly removing access for former employees or contractors.
32. Access by Ordime personnel
Authorised Ordime personnel may access a Customer's Workspace or Customer Data where reasonably necessary to:
provide support;
investigate a reported issue;
diagnose a technical fault;
maintain platform functionality;
investigate suspected misuse;
investigate a security incident;
administer billing;
perform authorised recovery activities;
protect Ordime systems or users;
comply with legal requirements; or
otherwise operate the Service.
Such access is limited to authorised personnel or contractors with a legitimate need to access the relevant information.
Ordime personnel are required to handle Customer Data confidentially and appropriately.
Administrative or technical access by Ordime does not mean Ordime assumes responsibility for deciding how the Customer should manage its Client records.
33. Data breaches
Ordime maintains processes for investigating and responding to suspected data breaches.
Depending on the circumstances, our response may include:
containing the incident;
investigating what occurred;
determining what information was affected;
securing affected systems;
engaging relevant service providers;
assessing potential harm;
informing affected Customers; and
determining whether notification to individuals or regulators is legally required.
Where applicable legislation requires notification, Ordime will comply with applicable notification obligations.
Where a breach involves Customer-controlled Client Data, Ordime may cooperate with the relevant Customer so that each party can comply with its own obligations.
Part G — Access, correction and Client requests
34. Information managed directly by Ordime
Individuals may contact Ordime regarding Personal Information that Ordime collects and manages for its own business purposes.
This may include:
Ordime Account information;
contact details supplied directly to Ordime;
Ordime Subscription information;
billing information relating to Ordime's own charges;
support correspondence;
communications directly with Ordime;
Ordime marketing preferences; and
other information collected directly by Ordime for its own operations.
Where an individual has a legal right to access or correct such information, requests may be made to:
legal@ordime.com.au
Ordime may take reasonable steps to verify the identity and authority of the person making the request.
Access may be restricted or refused where permitted or required by law.
35. Customer-controlled Client Data
Client records maintained within a Customer's Workspace are Customer-controlled Client Data.
This may include:
Client contact details;
appointment records;
booking history;
consultation information;
Health Information;
treatment records;
medical history;
consent forms;
photographs;
invoices;
communications; and
other information maintained by the Customer.
For these records, the Customer ordinarily determines how the information is managed.
If you are a Client of a business using Ordime and wish to:
obtain your Client records;
access your appointment history;
obtain treatment records;
access medical or Health Information;
obtain copies of photographs;
correct information;
request deletion;
withdraw or amend consent;
change marketing preferences;
obtain copies of forms;
query how your information has been used; or
exercise another privacy or health-record right relating to the Customer's records,
you should contact the business with which you have the relationship directly.
Ordime does not ordinarily make decisions regarding access to, correction of, deletion of or disclosure of Customer-controlled Client Data.
36. Requests made directly to Ordime concerning Customer-controlled Client Data
If a Client contacts Ordime requesting access to, alteration of, deletion of or disclosure of Customer-controlled Client Data, Ordime will ordinarily direct the Client to the relevant Customer.
Ordime may also refer the request to the Customer where appropriate.
Ordime will not independently disclose, modify or delete Customer-controlled Client Data solely because a Client has requested that Ordime do so.
This protects the Customer's ability to:
verify the identity of the Client;
determine whether the request is lawful;
comply with professional recordkeeping obligations;
comply with mandatory retention periods;
protect information concerning other individuals;
assess consent issues; and
otherwise fulfil its legal responsibilities.
Ordime may respond directly or take action where:
the relevant Customer instructs or authorises Ordime to do so;
Ordime itself has a direct legal obligation to respond;
disclosure or action is required or authorised by applicable law;
a valid court or tribunal order applies; or
another lawful authority requires the action.
Nothing in this section excludes a privacy or health-record right that an individual may have directly against Ordime under applicable law.
37. Verification before disclosure
Ordime will not knowingly disclose Personal Information to a person merely because they claim to be the person to whom the information relates.
Where Ordime is required or authorised to provide Personal Information directly, reasonable steps may be taken to verify:
identity;
authority;
entitlement to the information; and
the scope of the request.
Where Customer-controlled Client Data is involved, verification will ordinarily be performed by the relevant Customer.
Part H — Data retention and cancellation
38. Customer responsibility for exporting data
Customers are responsible for exporting information they need to retain before their Ordime Subscription or Workspace access ends.
Once cancellation becomes effective:
normal Workspace access ceases;
Customer users lose access to the Workspace; and
the Customer can no longer ordinarily retrieve its records through the platform.
Where a Customer later wishes to regain Workspace access and the Workspace remains technically recoverable, the Customer may be required to establish a new paid Subscription.
Re-subscribing does not guarantee that information remains recoverable.
This requirement relates to Workspace access and does not restrict any statutory privacy right that cannot lawfully be excluded.
39. Personal and operational information following cancellation
After a Workspace is cancelled, ordinary Client, appointment, treatment and other personal operational information may be retained for up to 90 days.
This limited retention period may support:
technical recovery;
accidental cancellation recovery;
security investigations;
support;
dispute management; and
legitimate operational requirements.
After approximately 90 days, such information will ordinarily be:
deleted; or
anonymised or de-identified so that individuals are no longer reasonably identifiable,
unless continued retention is required or authorised by law.
Customers are responsible for exporting Client records they are legally or professionally required to retain before cancelling their Workspace.
40. Financial and compliance records
Ordime may retain financial, billing, invoicing, transaction, tax, audit and compliance-related records for up to five years, or longer where applicable law requires.
These records may include:
invoices;
transaction history;
payment records;
subscription records;
tax information;
audit information; and
related financial records.
Financial records may themselves contain Personal Information.
Where continued identification of an individual is reasonably necessary for a legitimate or legally required recordkeeping purpose, that information may remain identifiable for the applicable retention period.
41. Final Workspace purge
Subject to applicable legal obligations, Ordime intends to purge the remaining Workspace no later than five years following cancellation.
Information may be retained beyond the ordinary period where necessary or required because of:
applicable law;
a court or tribunal order;
an active legal dispute;
an investigation;
fraud;
security requirements; or
another lawful retention requirement.
When continued retention is no longer required or authorised, Personal Information will be deleted or de-identified as appropriate.
42. Backups
Information deleted from Ordime's active systems may temporarily remain within encrypted or protected backup systems until the relevant backup is rotated, overwritten or expires.
Where it is not reasonably practicable to delete an individual record from a backup immediately, the information will remain beyond ordinary active use until the backup is replaced or expires.
Information retained only within backups will not ordinarily be restored or used except where reasonably necessary for:
disaster recovery;
security;
system restoration; or
another legitimate operational requirement.
43. Historical records concerning Authorised Users
Removing an Authorised User from a Workspace does not necessarily remove that person's name from historical business records.
Information may remain where reasonably necessary to identify who:
created an appointment;
issued an invoice;
altered a record;
performed a treatment;
completed a form;
processed a transaction;
made a system change; or
performed another auditable action.
Such information may be retained where reasonably necessary for audit, security, business-record, professional or legal purposes.
Part I — Privacy complaints
44. Privacy enquiries and complaints relating to Ordime
If you believe Ordime has mishandled Personal Information for which Ordime is responsible, you may contact:
Privacy Officer
Ordime Pty Ltd
Email: legal@ordime.com.au
Please provide sufficient information for us to understand the issue.
Ordime may request additional information or verification of identity where appropriate.
We will investigate legitimate privacy complaints and respond within a reasonable period.
45. Complaints concerning an Ordime Customer
If your concern relates to how an Ordime Customer collected, used, disclosed, retained or otherwise handled your Client information, you should ordinarily contact that Customer directly.
For example, questions concerning:
why a clinic collected particular medical information;
why a salon retained an appointment record;
whether treatment information is accurate;
why a business sent a marketing communication;
whether consent was valid;
whether a record should be deleted; or
whether a Customer should provide you with a copy of your treatment records
should ordinarily be addressed to the relevant business.
Ordime provides the platform on which that information is stored but does not ordinarily determine the Customer's privacy practices.
46. External complaints
Depending on the circumstances and applicable legislation, an individual may have the right to complain to an external privacy or health-information regulator.
These may include the:
Office of the Australian Information Commissioner (OAIC)
and, for matters within its jurisdiction:
Victorian Health Complaints Commissioner
Other state or territory regulators may also have jurisdiction depending on the nature and location of the relevant organisation and information.
We encourage individuals to first contact the organisation responsible for the relevant information so that it has an opportunity to investigate and resolve the matter.
Part J — Other privacy matters
47. Business transfers
If Ordime is involved in a:
merger;
acquisition;
corporate restructure;
financing;
sale of business;
sale of assets; or
similar transaction,
information may be disclosed to professional advisers, prospective purchasers, investors or successor organisations where reasonably necessary for the transaction.
Where appropriate, reasonable confidentiality protections will be used.
Any successor organisation receiving Personal Information remains subject to applicable privacy obligations.
48. Third-party websites
The Ordime website or platform may contain links to services operated by third parties.
This Privacy Policy does not govern the privacy practices of independently operated websites or services.
Customers and users should review the privacy policies of those services before providing Personal Information to them.
49. Changes to this Privacy Policy
Ordime may update this Privacy Policy from time to time.
Changes may be made to reflect:
new Ordime functionality;
new integrations;
changes to infrastructure;
changes to service providers;
changes in data-handling practices;
legal or regulatory developments;
security requirements; or
changes to our business.
The updated Privacy Policy will be published with a revised Last updated date.
Where a change materially affects how Personal Information is handled, Ordime may provide additional notice through the platform, website or email where appropriate.
50. Relationship with the Terms of Service
This Privacy Policy should be read together with the Ordime Terms of Service.
The Terms of Service govern the contractual relationship between Ordime and its Customers.
This Privacy Policy describes how Personal Information is handled through Ordime.
Nothing in either document excludes or restricts rights or obligations that cannot lawfully be excluded.
51. Contact Ordime
Questions concerning this Privacy Policy or Ordime's own privacy practices may be directed to:
Ordime Pty Ltd
ABN 95 700 576 978
Victoria 3550
Australia
Email: legal@ordime.com.au