Privacy Policy
Last updated: August 2026. Next scheduled review: August 2027.
This Privacy Policy applies in addition to the terms and conditions of our Site.
This is the Privacy Policy of Nourished Gut Clinic, Karly Raven (ABN: 24 897 643 041), director: Karly Raven. If you have any questions or need further information, please email us at hello@karlyraven.com.
We are committed to protecting your privacy, whether you are a contact, client, supplier, contractor or employee of ours.
This document describes how we collect and manage your personal and sensitive information when you interact with our business. We take this responsibility very seriously. Much of what you share with us is health information, which is some of the most personal information you have. If you have any questions or concerns about how your information is being handled, please do not hesitate to contact us.
We comply with the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth) (Privacy Act). As a health service provider, we are bound by the Privacy Act regardless of our size or turnover.
This policy should be read together with our AI Use Policy below, which explains in detail how artificial intelligence is used in our practice.
GDPR
We are an Australian telehealth practice, and we understand that visitors and clients from the EU and UK may access this site, so we also aim to comply with the General Data Protection Regulation (GDPR) where it applies. If you are located in the EU or UK, you may have additional rights including the right to access, correct, erase, restrict or port your data, and the right to object to processing. Contact us using the details below to exercise any of these rights.
Personal information
If you engage with us via this website, or choose to become our client, we may collect the following kinds of personal information from you:
- Your name, email address and phone number
- Your address and the country you live in
- Your date of birth
- Your emergency contact and, where relevant, the details of your GP or other treating practitioners
- Your opinion about future topics, products or services that may interest you
- Information that allows us to tailor our content to your needs when you sign up for a webinar, masterclass or promotional event
- Payment and billing information, processed through our payment providers
- Your IP address and information about your browsing history, to help us improve the usability and appeal of our website (see the section on Cookies below)
- If you are an employee, contractor or student practitioner, or propose working with us in that capacity, information about your qualifications, registrations, skills and work experience
- If you are a supplier or prospective supplier, information about your business, services, products and prices
Collection and use of personal information
Ethical collection
Where practicable we will only collect personal information about you directly from you, or from sources managed by you. However, in some circumstances we may obtain personal information from a third party, such as a referring practitioner or pathology provider. If information is obtained contrary to this Privacy Policy and the Privacy Act, we will destroy or de-identify it within a reasonable period.
We may collect your personal information by various means, including when:
- You contact us with a question, comment or enquiry
- You subscribe to our newsletter or opt in to receive a free resource
- You complete an application form or book a Digestive Strategy Session
- You book a consultation, join a program, or purchase a product or service from us
- You attend a webinar, masterclass, workshop or event we are hosting or presenting at
- You correspond with us on a social media platform such as Instagram, Facebook or LinkedIn
- You listen to and interact with our podcast content
- You share general information relating to your health, your business or your personal life
- You provide us with a testimonial or review
- Our website automatically collects information about you and your activity on our site, including analytics and cookies
- A third party supplies information to us, such as when you are referred to us by another practitioner or a mutual acquaintance
We may collect and use your personal information to:
- Respond to your enquiries
- Assess whether our services are appropriate for you
- Provide you with our products, programs or services at your request
- Communicate with you about your care, including protocols, resources and appointment reminders
- Process payments and manage our accounts
- Monitor or improve the use of, and satisfaction with, our website, products and services
- Share the latest news and developments relevant to our work
- Let you know about our expertise, and products or services that may be of interest to you
We may, from time to time, send you newsletters, invitations and updates about our services. We will only do so if you have asked to receive such communications through a double opt-in process. You can opt out at any time by replying to the message you received, or by clicking the unsubscribe link at the bottom of any marketing email from us.
We will only collect your information:
- With your full awareness and consent, such as when you email us, tick a checkbox or fill in a form
- If we need it to provide you with information or services that you have requested
- If we are legally required to collect it
- If collecting the information is necessary to preserve life or keep someone safe from harm
- For necessary administrative processes if you become our client
- If we believe we can demonstrate a legitimate interest in using your data for marketing purposes, although we will always give you a choice to opt out
If you do not provide us with information when requested, we may not be able to carry out your instructions, provide safe clinical care, or achieve the purpose for which the information was sought.
Sensitive information
We understand that some information is particularly sensitive, and that you are trusting us with it. Health information is classified as sensitive information under the Privacy Act and is given a higher level of protection.
The sensitive information we collect from you may include:
- Information relating to your health concerns, symptoms and digestive history
- Any past or present diagnoses, investigations, procedures and treatments
- Medications, supplements and prescriptions, past and current
- Pathology, breath test, stool and microbiome test results
- Family medical history
- Dietary intake, lifestyle, sleep, stress and menstrual or hormonal history
- Where relevant to your care, information about your mental health and wellbeing
We will only collect sensitive information by methods that are reasonably secure, such as:
- Through your intake form in Practice Better when you book an appointment
- During your telehealth consultation
- Through secure upload of test results and documents to your Practice Better client portal
- When you send us information by email, although please note that we cannot guarantee email is sufficiently secure. If information is extremely sensitive, please ask us about more secure ways to share it
The reasons we collect your sensitive information are:
- So that we can provide you with the services you have requested
- So that we can assess your case accurately and recommend appropriate treatment
- To ensure the care we provide is safe, individualised and clinically appropriate
We will not use your sensitive information for a purpose other than the one it was collected for without your consent, unless we are permitted or required to do so by law.
Secure storage of sensitive information
We are committed to storing and handling your sensitive information securely.
- Client records are stored in Practice Better, a purpose-built practice management platform with encryption and access controls.
- Sensitive information is stored on password protected devices with multi-factor authentication and current cybersecurity protections.
- Only the practitioner responsible for your care and authorised team members have access to your sensitive information, and only on a need-to-know basis.
- Some information may be stored securely online or in the cloud. You can find out more about our providers in the Security section below.
- Physical documents, where they exist, are stored securely and are not left accessible.
Collecting information from minors
All information collected from children under the age of 18 is classified as sensitive information.
We may collect information about a child under 18 in the following circumstances:
- In the presence of their parent or guardian
- With their parent or guardian's full and informed consent
Where a young person is assessed as having the maturity to consent to their own healthcare, we will discuss privacy and confidentiality with them directly.
This information is collected for the sole purpose of providing services and is handled with heightened security. Parents and guardians can request access to, correction of, or deletion of their child's data at any time, subject to the child's own privacy rights and our legal obligations.
Retention and destruction of information
We retain personal and health information only for as long as necessary to fulfil our obligations to you, or as required by law.
- Adult client records are retained for a minimum of 7 years from the date of the last entry.
- Records of clients who were under 18 at the time of treatment are retained until they turn 25.
These periods reflect the retention requirements that apply to private health service providers in several Australian states and are applied by us as best practice nationally.
Archived data is reviewed periodically, and any information no longer required is securely destroyed. Physical records are shredded and digital records are permanently deleted from our systems, including backups.
Disclosure of information
We may disclose your information in the following circumstances:
- To provide you with the services you have requested
- To send you products you have purchased
- Where disclosure is necessary to carry out your instructions, such as requesting pathology or functional tests, ordering practitioner-only supplements, or corresponding with another practitioner on your behalf
- Where we use support services to assist us in our business
- To engage in professional supervision, peer review or case discussion, where all information shared is de-identified to preserve your confidentiality
- To refer you to another practitioner or service provider at your request
Who disclosures are made to
You consent to us sharing relevant information on a strictly need-to-know basis with:
- People you authorise us to correspond with, as reasonably required to carry out your instructions
- Your GP, specialist or other treating practitioners, with your consent
- Pathology and functional testing laboratories, where you have consented to testing
- Compounding pharmacies and practitioner-only dispensaries, where a prescription or order is required
- Our employees and subcontractors
- Third party providers who assist with accounting, administration, archiving, auditing, business consulting, email marketing, legal or financial advice, professional supervision, website maintenance and technology services
Legal disclosure
We will also disclose your information if required by law in response to a subpoena, discovery request or court order, in compliance with mandatory reporting obligations, or in circumstances permitted by the Privacy Act. This includes where we have reasonable grounds to suspect unlawful activity or misconduct of a serious nature relating to our work with you. We may also make a disclosure to an appropriate authority if we have serious concerns about your health, safety or wellbeing, or the safety of another person.
Disclosure overseas
We use all reasonable means to protect the confidentiality of your information while it is in our possession or control. We will not knowingly share your information with any third party other than the service providers who assist us with necessary business activities or with the services we provide to you. Where we do share your information with third party service providers, we only do so if we are satisfied that the provider has a suitably protective privacy policy of its own, or has signed a confidentiality agreement with us.
Some of our service providers store or process data on servers located outside Australia, including in the United States, and may not be subject to Australian privacy laws. By providing your information to us, you consent to this disclosure. Further detail is set out in the Security section below.
An invitation to discuss
If you have any concerns about the disclosure of your information, please get in touch. We are always happy to talk it through with you personally and to look at alternatives that would make you more comfortable.
Security
We take reasonable physical, technical and administrative safeguards to protect your personal and sensitive information from misuse, interference, loss, and unauthorised access, modification and disclosure.
We manage risks to your information by:
- Storing files securely with encryption and access controls
- Using strong passwords and multi-factor authentication
- Ensuring that only key personnel have access to sensitive information
- Releasing information to service providers on a strictly need-to-know basis
- Reviewing our security practices and provider arrangements regularly
Third party storage
Your information may also be stored with a third party provider, where it will be managed under that provider's security policy. The following providers may be involved during our work together:
- Practice Better (client records, intake forms, telehealth, secure messaging): practicebetter.io/privacy
- Heidi Health (AI clinical documentation, used with your consent): heidihealth.com
- Kajabi (website, programs, courses, email marketing, checkout): kajabi.com
- Stripe (payment processing): stripe.com/privacy
- PayPal (payment processing): paypal.com
- Xero (accounting and invoicing): xero.com/au/security
- Google Workspace (email and file storage): workspace.google.com/security
- Meta (Instagram and Facebook advertising and analytics): facebook.com/business/m/privacy-and-data
- Google Analytics (website analytics): support.google.com/analytics
Waiver
If you are communicating with us by electronic means such as email, contact forms, social media or video call, we may not have full control over the transmission or storage of any personal information disclosed, although we employ best practice cybersecurity standards at all times. You agree that by participating in these forms of communication you understand and accept that there is an inherent risk of disclosure or loss of your personal information, for which we cannot be held responsible. If you are concerned about sharing particularly sensitive information, please ask us about more secure options.
Combining information
From time to time we may combine information you provide with information gathered from your website, Instagram, Facebook or LinkedIn.
Artificial intelligence
We use AI-powered tools to improve our efficiency, streamline operations and support the services we provide. These tools may assist with clinical notetaking, content drafting, scheduling, administration and research support.
We are committed to ensuring all AI-related data processing aligns with the Australian Privacy Principles, and that your information is handled securely and transparently. We take steps to minimise the data shared with AI tools, including:
- Asking for your consent before an AI clinical scribe is used in your consultation, and respecting your decision if you decline
- De-identifying personal details, such as using initials rather than names, for anything outside your own clinical documentation
- Limiting AI processing to non-sensitive information unless we have your explicit consent
- Never entering identifiable health information into publicly available generative AI tools
The AI tools we use are selected based on their privacy and security policies. Below is an overview of the tools we may use and their purpose:
- Heidi Health: clinical notetaking and transcription for session documentation, used with your consent, to improve accuracy and record-keeping
- General generative AI tools, such as ChatGPT, Claude and Copilot: drafting, summarising, brainstorming and improving written communications and content, using de-identified or non-sensitive information only
AI does not make clinical decisions in our practice. Every AI-supported clinical note, protocol and summary is reviewed and approved by your practitioner before it is saved or sent. Our full AI Use Policy below sets out how this works in detail.
Cookies and analytics
Cookies are small text files commonly used by websites to improve a user's experience, collect statistics or marketing information, and provide access to secure areas. Our website uses cookies and tracking technologies to enhance user experience, analyse site performance and provide personalised content.
You can configure your browser settings not to accept cookies, but this may interfere with the functioning of this website.
Google Analytics
We use Google Analytics to collect information about your use of our website so that we can understand how it is being used and improve its functionality. You can find out more about the information Google collects and how it is used at support.google.com/analytics/answer/6004245.
Google also provides a browser add-on you can use to opt out and prevent your data being used by Google Analytics, available at tools.google.com/dlpage/gaoptout.
Tracking pixels
We use third party tracking pixels from Meta to analyse user interactions and improve our marketing. These pixels may collect information such as your browsing activity, IP address, and interaction with our ads. You can opt out of targeted advertising by adjusting your browser and ad preference settings.
Automated decision making
We use automated processes to assist with personalised marketing, booking availability, access to purchased content and localised pricing. These processes help us provide an efficient and relevant experience.
We do not use automated decision-making to make, or substantially contribute to making, decisions about your diagnosis, your treatment, your suitability for our programs or your clinical care. Those decisions are always made by a human practitioner.
If you believe an automated decision has affected you unfairly, you may request a review by contacting hello@karlyraven.com.
Access to and correction of your information
You can contact hello@karlyraven.com to access, correct or update your personal information at any time. Please expect an acknowledgement within 7 days. Unless we are subject to a confidentiality obligation or another restriction that permits us to refuse access under the Privacy Act, and we believe there is a valid reason for doing so, we will endeavour to make your information available to you within 30 days.
If you request a copy of your clinical records, we may provide a summary or arrange a consultation to talk it through with you, so that the information is given to you in a way that is clear and clinically useful.
Complaints
If a breach of this Privacy Policy occurs, or if you wish to raise a concern about how your information has been handled, please contact us by email at hello@karlyraven.com, outlining your concerns. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may seek a review by contacting:
- The Office of the Australian Information Commissioner, using the information available at oaic.gov.au/privacy/privacy-complaints
- The health complaints body or health ombudsman in your state or territory
Notification of change
When we update our Privacy Policy, we will post a copy of the revised policy on our website. It is your responsibility to check whether any changes have been made since your last visit. Where changes are significant, we will let you know directly.
Notification of a data breach
If we have reason to suspect that a serious data breach has occurred and that it may result in serious harm to you, we will immediately assess the situation and take appropriate remedial action. Our assessment will be completed within 30 days.
If we still believe you are at risk of serious harm, we will notify the Office of the Australian Information Commissioner and either notify you directly or, if that is not possible, publish a notification of the breach on this website. This is consistent with our obligations under the Notifiable Data Breaches scheme.
This Privacy Policy was last updated: August 2026. Next scheduled review: August 2027.
AI Use Policy
Last updated: August 2026. Next scheduled review: August 2027.
Nourished Gut Clinic, Karly Raven (ABN: 24 897 643 041)
At Nourished Gut Clinic (we, us or our) we are committed to being transparent about how we use Artificial Intelligence (AI) in our clinical practice and business operations. Where AI is used, we use it ethically, carefully, and in accordance with Australian law and best practice.
We are a telehealth naturopathic practice. That means the information we hold is health information, which Australian privacy law treats as sensitive information and protects more strictly than ordinary personal information. Our use of AI is built around that reality.
This policy should be read together with our Privacy Policy above, which explains how we collect, hold, use and disclose your personal and health information more broadly.
Our position in one sentence
AI supports the administrative and drafting work behind your care. It does not make clinical decisions, and it never replaces the judgement of your practitioner.
How we use AI
We may use trusted AI powered tools and platforms in our day-to-day operations for purposes including, but not limited to:
Clinical documentation and note-taking. With your consent, we may use an AI clinical scribe to transcribe your consultation and help draft your consultation notes, treatment protocol or appointment summary. This allows your practitioner to be present with you rather than typing throughout your session. Every note and protocol is reviewed, corrected and approved by your practitioner before it is saved to your file or sent to you.
Written content and marketing. Drafting, editing and formatting blog posts, emails, newsletters, podcast show notes, social media captions, website copy and practitioner resources.
Administration and internal workflows. Scheduling support, document formatting, template creation, form processing, internal systems and general administrative tasks.
Research and clinical literature support. Summarising and organising published research to support our clinical reasoning and practitioner education. AI is used to help us find and digest evidence. It is not used as a source of clinical truth. All clinical recommendations are grounded in the published literature and in your practitioner's professional judgement.
We do not and will not use AI to make autonomous decisions about you, your health, your treatment or your care without human review and oversight.
AI and your health information
Health information is sensitive information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We apply the following protections.
Consent comes first. We will tell you before an AI clinical scribe is used in your consultation, and we will ask for your consent. Consent is genuinely optional. If you would prefer we did not use an AI scribe, simply tell us. Your practitioner will take notes manually and your care will not be affected in any way.
You can change your mind. You may withdraw your consent to AI-assisted note-taking at any time, for any consultation or for all future consultations. Just let us know before or during your appointment.
We de-identify wherever possible. Where AI is used for anything beyond your own clinical documentation, such as case discussion, practitioner mentoring, teaching materials, research or content, your information is de-identified first. Names, dates of birth, contact details and any other identifying details are removed. We will not share identifiable information about you or your case without your explicit written consent.
We do not put identifiable health information into public AI tools. Consistent with guidance from the Office of the Australian Information Commissioner (OAIC), we do not enter identifiable personal or health information into publicly available generative AI tools.
We choose our tools carefully. Where AI is used with health information, we select platforms that are built for healthcare use, that apply appropriate security and access controls, and that do not use your data to train their models. We review these arrangements as part of our ongoing vendor assessment.
Recordings. Where a consultation is recorded or transcribed for documentation purposes, the recording and transcript are handled as part of your clinical record, stored securely, and retained or deleted in line with our Privacy Policy and our legal retention obligations.
Overseas storage. Some AI and practice management tools we use may store or process information on servers located outside Australia. Where this occurs, we take reasonable steps to ensure the provider handles your information consistently with the Australian Privacy Principles. Further detail is set out in our Privacy Policy.
Human oversight
Every AI-supported output that relates to your care is reviewed by a qualified practitioner before it is used, saved or sent.
Specifically:
- Consultation notes, protocols and summaries are checked line by line for clinical accuracy before they reach your file or your inbox.
- Testing interpretation, prescribing, dosing, dietary staging and treatment decisions are made by your practitioner, not by an AI tool.
- Any AI-supported content that discusses health information is reviewed for clinical accuracy before publication.
We remain fully responsible for all final content, clinical documentation and decisions in our practice, regardless of whether AI was involved in producing a draft.
Automated decision-making
We do not use AI or computer programs to make, or to substantially contribute to making, decisions that could significantly affect your rights or interests. This includes decisions about your diagnosis, your treatment, your suitability for a program, or your access to our services. Those decisions are made by a human practitioner.
If this ever changes, we will update this policy and our Privacy Policy to explain what information is used and what kinds of decisions are involved, in line with the transparency requirements taking effect under the Privacy Act 1988 (Cth) from 10 December 2026.
Accuracy and reliability
AI is useful for drafting and organising, and it also gets things wrong. It can misinterpret speech, invent detail that sounds plausible, and misrepresent research.
We manage this by:
- reviewing every AI-supported output before it is used;
- checking clinical claims against the primary published literature, not against AI summaries;
- correcting transcription errors before notes are finalised; and
- training our team on the limitations of the tools we use.
If you ever notice something in your notes, protocol or summary that does not match your consultation, please tell us and we will correct it.
Transparency
We aim to be open about our use of AI wherever it is relevant to you.
- We will tell you when an AI scribe is being used in your consultation and ask for your consent.
- We will identify any AI system you may interact with directly, such as a chatbot.
- If you would like to know whether AI was used in producing a particular document, email or piece of content relating to you, please ask us and we will tell you.
Who this policy applies to
This policy applies to all practitioners, employees, contractors and any other individuals or entities using AI systems provided or authorised by us. It covers all current and emerging AI technologies used in our operations, including:
- generative AI tools, for example content drafting and document creation;
- AI clinical scribes and transcription tools;
- machine learning models, for example data analysis and automation;
- AI features built into software we use; and
- AI used in customer service, for example chatbots.
"AI" refers to technologies that perform tasks typically requiring human intelligence, such as generating text, analysing data or making recommendations.
This policy applies only to AI tools we directly use or control. It does not apply to AI used by third party service providers unless expressly stated. Where we engage third parties who use AI, we take reasonable steps to ensure their privacy and security standards are appropriate.
Fairness
We are committed to using AI fairly and without discrimination. We take reasonable steps to identify and reduce potential bias in the AI systems and data we use, and we remain alert to the fact that health-related AI tools can carry bias from the data they were trained on. Clinical judgement, applied to you as an individual, always takes precedence over a generalised output.
Prohibited uses
We will not use AI for:
- making clinical diagnoses or treatment decisions without practitioner review;
- entering identifiable client health information into public or unsecured AI tools;
- unlawful activity;
- discrimination based on protected attributes, for example race, gender, age, disability or religion;
- generating or spreading false or misleading health information, or any content intended to deceive;
- fabricating research, statistics, testimonials or clinical outcomes;
- infringing intellectual property rights;
- creating deepfakes or manipulating media in harmful ways;
- creating or using biometric surveillance systems, such as facial recognition, without lawful authority or consent; or
- automated decision-making with significant legal or personal effects without appropriate human oversight, where prohibited by law.
Your choices
You can:
- decline the use of an AI scribe in your consultations, at any time, without affecting your care;
- ask us how AI was used in relation to your information;
- request access to, or correction of, the information we hold about you; and
- make a complaint if you believe your information has been mishandled.
Requests and complaints can be made using the contact details below. We will respond within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
Monitoring and review
We monitor how AI systems are used in our practice to ensure compliance with this policy. We review this policy at least annually, and whenever there is a material change to the technology we use or to the law.
Contact us
For any questions about this policy or our use of AI, please contact:
Privacy contact: Karly Raven
Email: hello@karlyraven.com
This AI Use Policy was last updated: August 2026. Next scheduled review: August 2027.