Privacy Policy

Last updated: 22 September 2026

Ardant is operated by MBCAM Pty Ltd (ABN 20 673 942 142) and Margeaux Bartholomew-Carle (ABN 27 609 616 412), trading as Ardant. In this policy, Ardant, we, us or our means those entities as applicable. Ardant provides occupational therapy services and operates a platform that connects clients with independent occupational therapists across Australia.

We respect your privacy and are committed to handling personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), applicable State and Territory health-records laws, and other laws and professional obligations that apply to our services.

This Privacy Policy explains how we collect, hold, use and disclose personal information. It applies to our websites, referral and booking forms, the Ardant mobile application and administration portal, our communications with you, and the occupational therapy and related administrative services we provide.

1. The information we collect

The information we collect depends on how you interact with Ardant.

Clients, participants and people referred to us

We may collect:

  • identity and demographic information, such as your name, preferred name, pronouns, gender and date of birth;
  • contact information, such as your email address, telephone number, residential address, suburb, State, postcode and time zone;
  • health and disability information, including diagnosed conditions, injuries, support needs, requested occupational therapy services, session preferences, clinical notes, assessments, reports, risks, alerts, cultural requirements, social circumstances and information relevant to providing safe care;
  • appointment and service information, including appointment dates and locations, service type, duration, travel and non-face-to-face work;
  • funding, billing and claiming information, including NDIS participant and plan-management details, Medicare details, DVA details, My Aged Care information, private billing details, plan manager or care provider details, invoice contact details, services used and amounts billed or paid;
  • details of nominated contacts, such as a parent, guardian, carer, support coordinator, plan manager, care manager, general practitioner or other health professional; and
  • documents and correspondence you or an authorised person provides to us.

Health information is sensitive information under the Privacy Act and receives a higher level of protection.

Referrers, representatives and other contacts

If you refer a person to Ardant or are involved in their care or funding, we may collect your name, role or relationship to the client, organisation, contact details, correspondence and information about your authority to act for the client.

If you provide information about another person, you must be authorised to do so and, where practicable, make them aware of this Privacy Policy and the information you have provided.

Occupational therapists, applicants and other service providers

We may collect:

  • identity and contact details, date of birth and address;
  • professional information, including AHPRA registration, qualifications, areas of practice, experience, languages, service areas and availability;
  • business and payment information, including ABN, bank details, Medicare provider number and invoicing or payroll information;
  • evidence of identity, insurance, police checks, Working with Children Checks, Working with Vulnerable People Checks and other required credentials;
  • information about employment status, practice-management systems, professional interests and service preferences; and
  • account, authentication, security and application-use information.

Website, app and technical information

When you use our websites, forms, portal or app, we and our technology providers may collect technical information such as:

  • IP address, browser and device type, operating system, date and time of access, pages viewed, referring page and approximate location derived from an IP address;
  • cookies and similar technologies used for security, essential functionality, preferences and website analytics;
  • account sign-in and security events, app version, error and diagnostic information; and
  • information you choose to provide through device features, such as a receipt photo or PDF selected from your camera, photo library or files.

The Ardant app may keep limited appointment and practitioner information on an authorised device to support app operation and limited offline access. Sign-in credentials and app-lock information are protected using the device’s secure storage where available.

If you enable face or fingerprint unlock, authentication is performed by your device. Ardant receives only the result of the authentication attempt and does not receive or store your face image, fingerprint or biometric template.

If an authorised practitioner chooses to open a client’s address in Apple Maps or Google Maps, that address is sent to the selected mapping provider under that provider’s privacy terms. Address suggestions entered in an Ardant online form may also be processed by Google Places.

2. How we collect personal information

We may collect personal information:

  • directly from you through a referral, booking, application, registration or contact form;
  • when you use our app, portal, website or services, attend an appointment, contact us, upload a document or communicate with an Ardant team member or occupational therapist;
  • from a parent, guardian, carer, support coordinator, referrer or other person authorised to act for you;
  • from an occupational therapist or another health or service provider involved in your care;
  • from funding and government bodies, plan managers, aged-care providers, insurers and payment or claiming services;
  • from our practice-management, booking and clinical-record systems, including Halaxy; and
  • from professional registers and verification sources, such as AHPRA, where appropriate.

3. Why we collect, use and disclose information

We collect, use and disclose personal information where reasonably necessary to:

  • receive, assess and manage referrals;
  • identify an appropriate occupational therapist based on matters such as location, requested services, client age group, delivery method, practitioner skills and availability;
  • contact clients, representatives, referrers and practitioners;
  • arrange and deliver occupational therapy and coordinate care;
  • maintain accurate clinical and service records;
  • schedule and manage appointments, session logs, receipts, expenses, travel and practitioner payments;
  • prepare invoices, process payments and administer claims or funding with Medicare, DVA, the NDIA, plan managers, aged-care providers, insurers and other relevant payers;
  • manage bookkeeping, accounting, taxation, practitioner payments and financial reporting, including through Xero;
  • recruit, onboard, credential and manage occupational therapists and other service providers;
  • create and secure user accounts, authenticate users, provide support and operate our websites, app and administration systems;
  • investigate incidents, respond to complaints, manage safety and quality, and meet legal, regulatory, insurance, audit and professional obligations;
  • prevent fraud, misuse and unauthorised access; and
  • analyse and improve our services using aggregated, de-identified or limited technical information where practicable.

We may use tools to assist our team to organise referrals and identify potentially suitable practitioners. Material referral and care decisions are reviewed by people. We do not currently rely on a solely automated decision that has a significant effect on a client.

We will not use health information for direct marketing without consent. If you choose to receive other marketing communications from us, you can opt out at any time by using the unsubscribe option or contacting us.

4. Consent and when information is required

We generally collect sensitive information, including health information, with your consent or the consent of an authorised representative. In limited circumstances, the law may allow or require collection without consent, including where necessary to lessen or prevent a serious threat to life, health or safety.

You do not have to provide all information we request. However, if required identity, contact, health, funding or safety information is not provided, we may be unable to assess a referral, match an appropriate therapist, provide safe services, bill the relevant payer or meet our legal obligations.

Where lawful and practicable, you may deal with us anonymously or using a pseudonym for a general enquiry. It is usually not practicable to provide clinical services, manage funding or create a secure practitioner account without confirming identity.

5. Who we may disclose information to

We may disclose personal information only where reasonably necessary for the purposes described in this policy, with consent, or as required or authorised by law. Recipients may include:

  • Ardant personnel and authorised office or administration staff;
  • the independent occupational therapist assigned to a client and, where necessary, other authorised health or service providers involved in the client’s care;
  • a client’s nominated parent, guardian, representative, carer, support coordinator, plan manager, care manager, referrer or other authorised contact;
  • government agencies and funding or claiming bodies, including Services Australia, Medicare, DVA, the NDIA and relevant aged-care or State insurance bodies;
  • plan managers, aged-care providers, insurers, payment providers and other organisations responsible for approving or paying for services;
  • technology and professional service providers that help us operate, including practice-management, booking, clinical-record, cloud hosting, database, storage, authentication, email, SMS, mapping, analytics, security, accounting, legal, audit and insurance providers;
  • regulators, courts, law-enforcement agencies and other parties where disclosure is required or authorised by law or is necessary to manage a serious threat to health or safety; and
  • a purchaser, successor or adviser in connection with a proposed or completed business transaction, subject to appropriate confidentiality and legal requirements.

Our main technology providers include Halaxy, Supabase, Vercel, Cloudflare, Microsoft, Xero, Google and the device-platform services provided by Apple or Google. The providers used for a particular person depend on the form, service, device and funding pathway involved.

We do not sell identifiable client or patient information.

6. Overseas processing and disclosure

Ardant’s primary clinical, referral and practice-management records are configured to be stored in Australia, including through our Australian-hosted Supabase environment and Halaxy’s Australian data hosting.

Some providers that support our websites and ancillary services are based overseas or use overseas personnel or infrastructure. As a result, limited personal information or technical information may be processed outside Australia, including in the United States, and in other countries where a provider or its subprocessors operate. For example:

  • Vercel may process website-hosting and request information in the United States and other jurisdictions;
  • Cloudflare provides authoritative DNS for our domain from servers worldwide, including in the United States. Our DNS records are unproxied, so website and application requests do not pass through Cloudflare;
  • Microsoft provides our business email through Microsoft 365 and may process message content and related information in Australia and other countries where Microsoft operates;
  • Google and optional Apple or Google mapping services may process addresses and technical information overseas;
  • Xero may process accounting and related personal information in Australia, New Zealand, the United States and other countries where Xero group companies and subprocessors operate; and
  • Halaxy may use overseas subprocessors for optional communications, analytics, payment or integration functions.

The exact country can depend on the service, configuration and network route. Before disclosing personal information overseas, we take reasonable steps appropriate to the circumstances, such as assessing the provider, limiting the information provided, using contractual and security protections, and configuring Australian data hosting where available.

7. Storage and security

We may hold personal information electronically in our clinical and practice-management systems, secure cloud services, business systems and authorised devices, and in hard copy where required.

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include role-based access, least-privilege database controls, multi-factor authentication, encryption in transit and at rest where supported, private file storage, secure device storage, access logging, staff confidentiality requirements, backups and security monitoring.

Only authorised users should access information through the Ardant app and administration portal. Practitioners are restricted to information needed for their work, and administrative access is restricted according to role.

No electronic system or transmission over the internet can be guaranteed to be completely secure. If you believe information has been accessed or disclosed without authorisation, contact us promptly using the details below.

8. Retention and deletion

We retain personal information for as long as reasonably necessary to provide services, meet clinical and professional obligations, resolve disputes and comply with legal, funding, insurance, taxation and record-keeping requirements.

Clinical and health records are generally retained for at least seven years from the date of the last service or entry. For a person who was under 18 when a record was made, records are generally retained until that person turns 25. We may retain records for longer where required by applicable law, a funding arrangement, professional standards, legal proceedings or another lawful reason.

Financial and business records are retained for the periods required by law. Enquiries, unsuccessful applications and other administrative information are retained only for as long as reasonably necessary for the purpose for which they were collected, unless a longer period is required or authorised.

When information is no longer required, we take reasonable steps to securely destroy it or de-identify it. Deletion from backups may occur through the provider’s normal secure backup-rotation process.

9. Accessing or correcting your information

You may ask to access personal information we hold about you or request that inaccurate, out-of-date, incomplete, irrelevant or misleading information be corrected.

Please email access@ardant.com.au with the subject line Privacy request. Tell us what information you are seeking or what you believe should be corrected. We may need to verify your identity and authority before acting on a request, particularly where health information is involved.

We will respond within a reasonable period, generally within 30 days. We do not usually charge for making a request. If a reasonable charge is permitted for providing access, we will tell you before incurring it.

In some circumstances, the law permits or requires us to refuse access or correction. If that occurs, we will generally give you written reasons and explain available complaint options, unless it would be unreasonable or unlawful to do so.

10. Privacy complaints

If you believe we have mishandled personal information or breached this policy, please contact:

Privacy Officer
Ardant
Email: access@ardant.com.au
Subject: Privacy complaint

Please describe what happened, when it happened, the information involved and the outcome you are seeking. We will acknowledge and investigate the complaint and aim to provide a response within 30 days. If we need more time, we will let you know.

If you are not satisfied with our response, or we do not respond within a reasonable period, you may lodge a complaint with the Office of the Australian Information Commissioner:

Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au/privacy/privacy-complaints
Telephone: 1300 363 992

Depending on where you live and the nature of the matter, you may also have the right to complain to a State or Territory health-privacy or health-complaints regulator.

11. Third-party websites and services

Our websites and app may contain links to external websites, booking services, mapping services, social media pages or other third-party services. Those services have their own privacy practices and policies. We encourage you to review them before providing personal information.

12. Changes to this policy

We may update this Privacy Policy when our services, technology providers or legal obligations change. The current version will be published on our website and identified by the “Last updated” date. Material changes will be communicated where reasonably practicable.

13. Contact us

For questions about this policy or Ardant’s privacy practices, or to request a copy of this policy in another format, contact:

Privacy Officer
Ardant
Email: access@ardant.com.au