Privacy Policy
Last updated: 22 July 2026
This Privacy Policy explains how MEDEVO Pty Ltd (once incorporated) ("MEDEVO", "we", "us") collects, uses, holds and discloses your personal and health information when you use our telehealth facilitation service. We handle your information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Health information is "sensitive information" and is given a higher level of protection.
1. Who we are
MEDEVO operates a telehealth facilitation service that connects patients in Queensland with independent, AHPRA-registered medical practitioners and licensed pharmacies, to support access to medicinal cannabis where clinically appropriate. We provide technology and administration only — we do not prescribe, dispense, or take title to any medicine.
2. What we collect
- Account & identity: name, date of birth, contact details, proof of identity.
- Eligibility & health information: your questionnaire responses, medical history and details you provide for a consultation.
- Consultation & messaging: secure messages and records associated with your consultation (the independent doctor is responsible for the clinical record they create).
- Billing & transaction: payment details handled via a disclosed-agent arrangement; the doctor sets consultation fees.
- Technical: usage, device and audit-log data for security and service improvement.
3. How and why we use it
We collect and use your information for the primary purpose of facilitating your consultation, prescription, dispensing and delivery — and for related secondary purposes such as administration, billing, security, compliance, and meeting our legal and regulatory obligations. We will not use your health information for direct marketing of medicinal cannabis products (which would also breach advertising rules).
4. Who we share it with
- Independent doctors engaged on the platform, to facilitate your consultation.
- Licensed partner pharmacies, to enable dispensing and delivery.
- Couriers, for delivery (limited contact details only).
- Service providers (hosting, payments, messaging) under appropriate data-processing arrangements.
- Regulators (such as the TGA, AHPRA, Queensland Health, the OAIC) where required or authorised by law.
5. Security
We take reasonable steps to protect your information: encryption in transit and at rest, role-based access, multi-factor authentication, audit logging, and alignment with recognised baseline security controls. Each party involved (doctor, pharmacy, platform) is responsible for its own compliance with the APPs, including breach notification under the Notifiable Data Breaches scheme.
6. Access, correction & complaints
You may request access to, or correction of, your personal and health information. If you believe we have mishandled your information, you can complain to us first; if unresolved, you may complain to the Office of the Australian Information Commissioner (OAIC).
7. Contact
For privacy enquiries, contact MEDEVO at: [privacy contact — to be confirmed]. Once confirmed, this will be a dedicated privacy contact for access and correction requests.