top of page

Privacy Policy

Effective date: 24 June 2026 | Version 1.0


This Privacy Policy explains how BioAxis Pty Ltd (BioAxis, we, us and our) collects, holds, uses, discloses
and protects personal information, including health information, in connection with BioAxis services.
This policy is intended to be made available free of charge on the BioAxis website at
https://bioaxis.com.au/privacy-policy and in another reasonable format on request.


1. Privacy Laws and Health Information Compliance


BioAxis operates in Australia and provides services to Australian patients. BioAxis handles personal
information in accordance with applicable Australian privacy and health information requirements,
including the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data
Breaches scheme, applicable state and territory health records or health privacy requirements where
relevant, and the Healthcare Identifiers Act 2010 (Cth) where healthcare identifiers are collected or
used.


Health information is sensitive information under Australian privacy law. For the purposes of healthcare
compliance terminology, references to protected health information in BioAxis operations should be
read as including health information, healthcare identifiers, prescription information, pharmacy
fulfilment information, and other personal information collected for the purpose of providing or
arranging a health service.


BioAxis maintains privacy practices, procedures and systems designed to ensure that personal
information and health information are handled lawfully, transparently and securely. These include:


- collecting health information only where it is reasonably necessary for BioAxis services and, where
required, with the patient's consent.

- limiting access to patient information to authorised personnel and service providers who need it for
the patient pathway

- using secure operational platforms, access controls and confidentiality requirements for staff and
contractors

- sharing patient information only with parties involved in the consultation, prescribing, dispensing,
fulfilment, payment, support, compliance or legal process

- using contractual and operational controls for service providers that handle personal information on
BioAxis' behalf

- maintaining procedures for access and correction requests, privacy complaints, data breach
assessment and regulatory notification where required

- reviewing privacy handling practices when systems, providers or patient pathways materially change


2. Information We Collect


BioAxis may collect and hold the following kinds of personal information:

- identity and contact information, including name, date of birth, residential address, delivery
address, email address and phone number
- eligibility and verification information, including Medicare number, Individual Healthcare Identifier
or other information required to confirm identity, Australian patient status or healthcare eligibility
- account, booking and support information, including login details, appointment information,
support communications and service preferences
- payment and transaction information, including payment status, receipts, refunds and limited
payment metadata received from payment processors
- technical information from website or platform use, such as device, browser, IP address, cookies,
analytics events and security logs


BioAxis may also collect and hold health information, including:

- health questionnaire responses, treatment goals, symptoms and reasons for consultation
- medical history, diagnosed conditions, allergies, injury history, cancer history, medication and
supplement use, prior peptide use, and fertility, pregnancy or breastfeeding information where
relevant
- uploaded bloodwork, imaging, pathology, medical reports or other clinical documents
- consultation outcomes, prescriptions, dispensing information, pharmacy fulfilment status, delivery
status, support notes and related operational records


3. How We Collect Information


BioAxis generally collects personal information directly from the patient when the patient:

- visits the BioAxis website or uses an online form
- creates an account or proceeds through an operational platform such as GetScripted
- selects a consultation or treatment pathway
- completes a health questionnaire or uploads documents
- books or attends a medical consultation
- makes a payment or requests a refund
- communicates with BioAxis by email, SMS, telephone, website chat, social media or other support
channels


BioAxis may also collect relevant information from consulting doctors, pharmacies or compounding
partners, Infinity Wellness Group, GetScripted, payment processors, booking platforms, communication
platforms, IT providers and other service providers involved in the patient pathway.
If BioAxis receives unsolicited personal information, BioAxis will assess whether it could have collected
that information under the APPs. If it could not have been collected, BioAxis will take reasonable steps
to destroy or de-identify it where lawful and reasonable to do so.


4. Why We Collect, Hold, Use and Disclose Information


BioAxis collects, holds, uses and discloses personal information and health information for purposes
including:

- identifying the patient and confirming that the patient is located in Australia
- creating and managing patient accounts and service records
- collecting information for doctor review and supporting the medical consultation process
- facilitating prescription and pharmacy fulfilment workflows where a practitioner determines that
treatment is clinically appropriate
- processing payments, receipts, refunds and transaction records
- sending service communications such as booking reminders, questionnaire reminders, payment
confirmations, order updates, dispatch updates and check-in messages
- responding to patient support requests, complaints, disputes and regulatory enquiries
-  maintaining clinical, operational, legal, insurance, accounting and business records
- improving BioAxis systems, services, patient experience, safety and compliance controls
- complying with laws, regulations, court or tribunal orders, professional obligations and regulator
requests


5. Consent and Patient Choice


By using BioAxis services, completing a health questionnaire, booking a consultation, uploading medical
information or proceeding with a treatment pathway, the patient consents to BioAxis collecting, using
and disclosing relevant personal information and health information for the purposes described in this
policy.


A patient may choose not to provide requested information. However, if information is required for
identity verification, clinical assessment, prescribing, pharmacy fulfilment, payment processing, legal
compliance or safe patient support, BioAxis or the relevant practitioner may not be able to provide or
continue the requested service.


6. Disclosure to Doctors, Pharmacies and Service Providers


BioAxis may disclose relevant personal information and health information to:

- the consulting doctor or other registered health practitioner involved in the patient's care pathway
- GetScripted or another operational platform used for intake, booking, scripting, patient records or
workflow management
- Infinity Wellness Group, pharmacy partners, compounding partners or dispensing/fulfilment
providers where a prescription or pharmacy workflow is required
- payment processors, banks and transaction service providers
- booking, email, SMS, customer support, CRM, website, analytics, hosting, cloud storage, security
and IT providers
- professional advisers, insurers, auditors, regulators, law enforcement, courts, tribunals or other
authorities where required or permitted by law


BioAxis only discloses information that is reasonably necessary for the relevant purpose. BioAxis does
not sell patient personal information or health information.


7. Government Identifiers and Healthcare Identifiers

BioAxis may collect Medicare numbers, Individual Healthcare Identifiers or other government-related
identifiers where this is reasonably necessary for identity verification, Australian patient eligibility,
healthcare administration, prescribing, pharmacy fulfilment or legal compliance.


BioAxis does not use Medicare numbers or healthcare identifiers for general marketing. BioAxis will not
adopt a government-related identifier as its own internal identifier unless permitted by law.


8. Payment Information


Payments may be processed through GetScripted or another third-party payment provider. BioAxis may
receive payment confirmation, transaction details, invoice information, refund information and related
account information.


BioAxis does not intentionally store full card numbers or card security codes. Card information is
handled by authorised payment providers in accordance with their own security and compliance
obligations.


9. Website Data, Cookies and Analytics


BioAxis may collect website and technical information through cookies, pixels, analytics tools, security
tools or similar technologies. This information may be used to operate the website, maintain security,
understand website use, improve services, measure marketing performance and support compliance.
Patients can usually adjust browser settings to refuse or limit cookies, but some website or platform
functions may not work correctly if cookies are disabled.


10. Marketing Communications


BioAxis may send service-related communications that are necessary for bookings, questionnaires,
payments, support, order updates, dispatch updates, safety follow-up or treatment pathway
administration.


BioAxis may also send marketing or educational communications where permitted by law or where the
patient has consented. Patients may unsubscribe from marketing communications using the unsubscribe
option provided or by contacting BioAxis. Service-related communications may still be sent where
necessary to administer the patient's service pathway.


11. Storage, Security and Access Controls


BioAxis takes reasonable steps to protect personal information and health information from misuse,
interference, loss, unauthorised access, unauthorised modification and unauthorised disclosure.
These steps may include:

-  using reputable operational, clinical, payment, hosting and communication systems
- role-based access controls and access limitation based on business need

- multi-factor authentication where available and appropriate
- password controls, system security settings and device security practices
- confidentiality obligations for staff, contractors and service providers
- secure transmission and storage practices available through the relevant platforms
- access logs, audit trails and monitoring where supported by the relevant platform
- staff guidance on privacy, health information handling and data breach escalation
- review of privacy and security risks when onboarding material service providers


No online system can be guaranteed to be completely secure. Patients should take reasonable care
when providing information online and should keep login details secure.


12. Overseas Disclosure


BioAxis operates in Australia for Australian patients. Some service providers used by BioAxis may store,
process or support information using infrastructure or personnel located outside Australia.


Where overseas disclosure or overseas processing is likely, BioAxis will take reasonable steps to use
reputable providers and to protect patient information in accordance with applicable Australian privacy
obligations.

 

Depending on the provider and system configuration, information may be processed in
Australia, the United States or other countries in which BioAxis' service providers maintain infrastructure
or support services. BioAxis will update this policy where it becomes aware that more specific country
information should be listed.


13. Retention, Destruction and De-identification


BioAxis retains personal information and health information for as long as reasonably required for the
purposes described in this policy, including patient support, clinical and pharmacy workflows, legal
compliance, professional obligations, accounting, insurance, dispute management, audit and business
record keeping.


Where BioAxis no longer needs personal information for a lawful purpose, and is not required or
permitted to retain it, BioAxis will take reasonable steps to destroy or de-identify the information.


14. Access and Correction


Patients may request access to personal information held by BioAxis and may request correction if they
believe information is inaccurate, out of date, incomplete, irrelevant or misleading.


BioAxis may need to verify the patient's identity before processing an access or correction request.
BioAxis will respond within a reasonable period and will generally aim to respond within 30 days. In
some cases, BioAxis may lawfully refuse access or correction, or may need to direct the patient to
another provider that holds the relevant record, such as the consulting doctor, pharmacy or operational
platform.

15. Anonymity and Pseudonymity


Patients may browse general information on the BioAxis website without identifying themselves where
the website allows it.


BioAxis cannot provide clinical intake, medical consultation, prescribing, pharmacy fulfilment, payment
or patient support services anonymously or pseudonymously where identification is required for safe
healthcare, legal compliance, prescribing, dispensing, delivery, billing or fraud prevention.


16. Data Breaches


BioAxis maintains processes to identify, assess, contain and respond to suspected privacy or security
incidents involving personal information or health information.


Where BioAxis determines that an eligible data breach has occurred under the Notifiable Data Breaches
scheme, BioAxis will notify affected individuals and the Office of the Australian Information
Commissioner where required by law.


17. Privacy Complaints


Patients may contact BioAxis if they have a privacy concern, access request, correction request or
complaint. BioAxis will review privacy complaints and will generally aim to respond within 30 days.
If a patient is not satisfied with BioAxis' response, they may contact the Office of the Australian
Information Commissioner at www.oaic.gov.au or by telephone on 1300 363 992. Depending on the
nature of the information and jurisdiction, another health privacy regulator may also be relevant.


18. Changes to This Policy


BioAxis may update this Privacy Policy from time to time to reflect changes to its services, systems,
providers, legal obligations or privacy practices. The updated version will be published on the BioAxis
website or otherwise made available to patients.

19. Contact


For privacy questions, access requests, correction requests or privacy complaints, patients may contact:
Privacy contact BioAxis Privacy Officer.


Email support@bioaxis.com.au
Website https://bioaxis.com.au/privacy-policy

Peptides Australia - BioAxis Telehealth clinic australia

PLEASE NOTE: BioAxis facilitates telehealth consultations with AHPRA-registered medical practitioners. All prescriptions are issued at the clinical discretion of the treating doctor and supplied in accordance with applicable Australian regulations. This website provides general information only and does not constitute medical advice.

Copyright © 2026 BioAxis Pty Ltd All rights reserved.

ABN: 49 697 681 833

bottom of page