TECH4GOOD Pty Ltd (ABN 87 634 472 352) trading as HodieLabs · Version 1.0 · Effective March 2026
Policy at a glance
- We handle sensitive health, genetic and My Health Record data under Australian privacy law, only ever with your explicit consent.
- We never sell your personal information, and we never use your health data for third-party marketing.
- You can access, correct, or delete your data, and withdraw consent or revoke My Health Record access, at any time.
- All health data is encrypted at rest and in transit, with strict access controls and audit logging.
1. Introduction
TECH4GOOD Pty Ltd (ABN 87 634 472 352) trading as HodieLabs ("HodieLabs", "we", "us", or "our") operates a health and longevity optimisation platform that integrates diagnostics, biomarker tracking, genetic insights, and AI-assisted health intelligence. We are committed to protecting the privacy of every individual whose personal information we handle.
This Privacy Policy ("Policy") describes how we collect, use, disclose, hold, and protect your personal information, including sensitive health information and, where applicable, information accessed through the My Health Record system, in accordance with:
- the Privacy Act 1988 (Cth) ("Privacy Act"), including the Australian Privacy Principles ("APPs");
- the My Health Records Act 2012 (Cth) ("MHR Act") and the My Health Records (Whistleblower) Rules 2018;
- the Health Records Act 2001 (Vic) ("HRA");
- applicable guidelines issued by the Office of the Australian Information Commissioner ("OAIC") and the Australian Digital Health Agency ("ADHA"); and
- any other applicable Commonwealth or state/territory privacy legislation.
By using our platform, services, website, or mobile application (collectively, "Services"), you acknowledge you have read and understood this Policy. If you do not agree, please discontinue use of our Services.
2. My Health Record Access
2.1 Registered Healthcare Provider Status
HodieLabs has applied to the Australian Digital Health Agency to be registered as an organisation permitted to access the My Health Record ("MHR") system under the MHR Act. Access is used solely to support the health management needs of users who have provided explicit authorisation.
2.2 Strict Permitted Purposes
We will only access, collect, use, or disclose information from a user's MHR for the following permitted purposes:
- providing or facilitating the provision of healthcare to the individual;
- integrating MHR data into personalised health dashboards and longitudinal health tracking features within the HodieLabs platform, with your explicit consent;
- generating AI-assisted health insights, biomarker correlations, and health recommendations presented directly to the individual; and
- fulfilling our obligations as a registered MHR system operator.
We will never access your MHR for commercial profiling, advertising, insurance underwriting, employment purposes, or any purpose not expressly authorised by you and permitted under the MHR Act.
2.3 Secondary Use Prohibition
In accordance with section 64 of the MHR Act, HodieLabs will not use or disclose MHR information for any secondary purpose without your separate, express written consent. Except where required or permitted by law (for example, court order or serious threat to life).
2.4 Your MHR Controls
You retain full control over your MHR at all times. You may:
- grant or revoke HodieLabs' access to your MHR at any time via the My Health Record system (my.gov.au);
- restrict the documents or records visible to HodieLabs within your MHR; and
- cancel your MHR entirely via the ADHA.
Revoking access does not automatically delete information we have already lawfully collected and stored in our platform; separate deletion requests must be submitted to our Privacy Officer (see section 13).
3. Personal Information We Collect
3.1 Information You Provide Directly
- Identity information: full name, date of birth, sex, gender identity, contact details (email, phone, address).
- Account credentials: username and password (stored in encrypted form).
- Health questionnaires and self-reported data: lifestyle, exercise, nutrition, sleep, family medical history, and wellness goals.
- Subscription and payment information: processed by our PCI-DSS compliant payment provider; we do not store full card details.
3.2 Health and Sensitive Information
We collect the following categories of sensitive information only with your explicit consent:
- Biomarker and pathology data: blood panels, hormone levels, metabolic markers, HbA1c, lipid profiles, and other laboratory results.
- Body composition: DEXA scan results (bone density, lean mass, visceral fat), anthropometric measurements.
- Genomic and genetic data: results from partner genetic testing laboratories, including SNP variants, polygenic risk scores, and pharmacogenomic data.
- Wearable and device data: continuous glucose monitoring (CGM), heart rate variability (HRV), VO₂ max, sleep architecture, and other data from connected devices (where authorised).
- My Health Record data: as described in section 2, accessed only with your express authorisation.
- Mental health indicators: self-reported stress, anxiety, or mood data entered voluntarily by the user.
3.3 Automatically Collected Technical Data
- Device identifiers, IP address, browser type, and operating system.
- Usage logs: pages visited, features accessed, session duration, and interaction events.
- Cookies and similar tracking technologies (see section 11 for our Cookie Policy).
3.4 Information from Third Parties
- Pathology laboratories: test results transmitted directly with your authorisation.
- Genetic testing partners: genomic data packages from white-label laboratory partners.
- Referral practitioners: clinical notes or referrals shared by a treating practitioner with your consent.
- Identity verification providers: for account verification purposes only.
4. How We Use Your Personal Information
We use personal information only for purposes that are directly related to providing and improving our Services, or as otherwise required by law:
- Platform delivery: creating and maintaining your account, displaying personalised health dashboards, and generating AI-driven insights and recommendations.
- Health analytics: correlating biomarkers, genomic data, lifestyle inputs, and MHR data to produce longitudinal health trend reports.
- Clinical coordination: sharing summaries with treating practitioners or allied health professionals you have nominated.
- Service improvement: de-identified and aggregated analytics to enhance platform features and research (see section 7 on de-identification).
- Communications: sending service notifications, appointment reminders, and, where you have opted in, health education content.
- Legal and compliance: meeting our obligations under Australian law, responding to regulatory inquiries, and enforcing our Terms of Service.
- Safety: detecting and preventing fraud, security incidents, and harm to users or third parties.
We will not use your health information for marketing by third parties. We do not sell your personal information.
5. Disclosure of Personal Information
5.1 Authorised Disclosures
We disclose your personal information only in the following circumstances:
- With your consent: to treating practitioners, specialists, or allied health professionals you have nominated.
- Service providers: cloud infrastructure, data analytics, payment processing, and customer support vendors engaged under strict data processing agreements that prohibit secondary use (see section 5.2).
- Legal requirements: in response to a court order, subpoena, or regulatory direction from a body with lawful authority.
- Safety emergencies: where we reasonably believe disclosure is necessary to prevent a serious and imminent threat to the life or health of any person.
- Business transfers: in the event of a merger, acquisition, or asset sale, personal information may be transferred subject to equivalent privacy protections and advance notice to users.
5.2 Third-Party Service Providers
We engage carefully vetted third-party vendors, including cloud hosting providers (located in Australia or in countries with equivalent privacy protections), laboratory data integration partners, and AI processing infrastructure providers. All vendors are bound by contractual data processing agreements that:
- restrict use of your data solely to the provision of services to HodieLabs;
- prohibit onward transfer or disclosure without our written authorisation;
- require notification of any data breach affecting your information; and
- mandate deletion or return of data upon contract termination.
5.3 Overseas Disclosures
Some of our service providers may process data outside Australia. Where we transfer personal information overseas, we take reasonable steps to ensure the recipient country's privacy laws afford comparable protections, or we obtain your consent, in accordance with APP 8. We will not transfer MHR information overseas.
6. Consent and Your Choices
Where we rely on consent as the basis for collecting or using sensitive health information (including MHR data and genetic information), that consent will be:
- Informed: you will be clearly told what information is being collected and why, before collection occurs.
- Voluntary: you are not required to provide sensitive information as a condition of basic account access.
- Specific: separate consent is sought for each distinct purpose (e.g. genomic analysis, MHR access, practitioner sharing).
- Withdrawable: you may withdraw consent at any time without penalty, by contacting our Privacy Officer or adjusting your in-platform settings.
Withdrawal of consent may affect our ability to provide certain features of the platform that rely on that data.
7. De-identification and Research
HodieLabs may use de-identified, aggregated data for internal research and platform development. De-identification is performed in accordance with OAIC guidelines and the National Statement on Ethical Conduct in Human Research. De-identified data cannot reasonably be used to re-identify any individual.
We will not use your identifiable health information for research purposes without your separate, express written consent and, where required, appropriate ethics committee approval.
8. Data Quality and Accuracy
We take reasonable steps to ensure that the personal information we hold is accurate, complete, and up to date. You are encouraged to update your information via your account settings at any time. If you believe information we hold is inaccurate or out of date, please contact our Privacy Officer and we will take reasonable steps to correct it within 30 days (see section 13).
9. Data Security
We implement industry-standard technical and organisational security measures proportionate to the sensitivity of health and genetic data, including:
- Encryption: all health data is encrypted at rest (AES-256) and in transit (TLS 1.3 or higher).
- Access controls: role-based access control (RBAC), multi-factor authentication (MFA) for all staff, and least-privilege principles.
- Audit logging: all access to health records and MHR data is logged and subject to regular audit review.
- Penetration testing: annual third-party security assessments and vulnerability scanning.
- Incident response: a documented breach response plan aligned to the Notifiable Data Breaches scheme (NDB).
- Staff training: mandatory annual privacy and security training for all employees and contractors.
Despite these measures, no system is completely secure. We encourage users to use strong, unique passwords and to notify us immediately of any suspected unauthorised access to their account. For full detail, see our Data & Security page.
10. Data Retention
We retain personal information only for as long as necessary to fulfil the purpose for which it was collected, or as required by law:
- General account data: retained for the duration of your account plus 7 years after account closure, to comply with applicable records obligations.
- Health records (including pathology and DEXA data): retained for a minimum of 7 years from the date of the record, or 10 years where the individual was a minor at the time.
- MHR data: held only for as long as necessary to deliver the requested service and then deleted from our systems, subject to applicable law.
- Genomic data: retained for the period of your consent or until withdrawal. Upon withdrawal, genomic data is securely deleted within 30 days.
- Technical logs: retained for 12 months for security and operational purposes.
Secure deletion is conducted in a manner that prevents recovery. Upon written request, we will provide confirmation of deletion.
11. Cookies and Tracking Technologies
Our website and application use cookies and similar technologies. These include:
- Essential cookies: required for core platform functionality and security (cannot be disabled).
- Analytics cookies: used to understand usage patterns and improve our Services. These are de-identified and do not identify you personally.
- Preference cookies: remember your settings and display preferences.
We do not use advertising or third-party tracking cookies. You may manage cookie preferences via your browser settings; however, disabling essential cookies may impair platform functionality. We do not support "Do Not Track" browser signals at this time.
12. Your Privacy Rights
Under the Privacy Act, the MHR Act, and the HRA, you have the following rights in relation to your personal information:
- Access: to request access to the personal information we hold about you (APP 12).
- Correction: to request correction of inaccurate, incomplete, or out-of-date information (APP 13).
- Consent withdrawal: to withdraw consent at any time for uses of your information that are consent-based.
- Deletion: to request deletion of your information, subject to our legal retention obligations.
- Complaint: to lodge a complaint with us or directly with the OAIC (oaic.gov.au) or the Health Complaints Commissioner (Vic).
- MHR access revocation: to revoke our access to your My Health Record at any time via the ADHA portal.
To exercise any of these rights, please contact our Privacy Officer using the details in section 13. We will respond to access and correction requests within 30 days. We may need to verify your identity before processing requests. We will not charge you for making a privacy request, unless the request is manifestly unreasonable or repetitive, in which case we will notify you of any applicable fee before proceeding.
13. Privacy Officer and Complaints
HodieLabs takes privacy complaints seriously. If you have a concern about how we have handled your personal information, we encourage you to contact our Privacy Officer in the first instance:
Privacy Officer. TECH4GOOD Pty Ltd (trading as HodieLabs)
Email:
privacy@hodielabs.com
Postal: 85 Spring Street, Melbourne VIC 3000, Australia
Response time: within 30 days of receipt
If you are not satisfied with our response, or if we fail to respond within 30 days, you may escalate your complaint to:
- Office of the Australian Information Commissioner (OAIC): oaic.gov.au | 1300 363 992
- Health Complaints Commissioner (Victoria): hcc.vic.gov.au | 1300 582 113
- Australian Digital Health Agency (MHR-specific complaints): adha.gov.au
14. Children and Minors
Our Services are not directed at individuals under the age of 18 without the involvement of a parent or legal guardian. We do not knowingly collect personal information from minors without verified parental or guardian consent. If you are a parent or guardian and believe we have collected information from a child without appropriate consent, please contact our Privacy Officer immediately.
15. Changes to This Privacy Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or regulatory guidance. Where changes are material, particularly those affecting how we use health or MHR data, we will provide at least 30 days' notice by email, in-platform notification, and by posting the updated Policy on our website with a revised effective date.
Continued use of our Services after the effective date of any changes constitutes acceptance of the updated Policy. Where changes require fresh consent under the Privacy Act or MHR Act, we will obtain that consent separately before proceeding.
16. Definitions
- "Personal information" has the meaning given in the Privacy Act 1988 (Cth).
- "Sensitive information" has the meaning given in the Privacy Act 1988 (Cth) and includes health information and genetic information.
- "MHR" means My Health Record, as defined in the My Health Records Act 2012 (Cth).
- "Services" means the HodieLabs platform, website, mobile application, and any related services.
- "ADHA" means the Australian Digital Health Agency.
- "OAIC" means the Office of the Australian Information Commissioner.
This Privacy Policy was approved by the Board of TECH4GOOD Pty Ltd.