Bodhi Holistic Hub

Privacy Policy


Version 2.0 — Effective Date: 28th June 2026

1. Purpose and Overview

Bodhi Holistic Hub Pty Ltd ACN 654 747 501 (Bodhi, we, us, our) is committed to protecting the privacy of everyone who interacts with our platform. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have in relation to it.

Bodhi Holistic Hub serves two groups of people: clients and practitioners.

Clients use our marketplace to discover, book, and pay vetted holistic practitioners. Clients do not subscribe to a plan, they simply create an account and pay for sessions as they book them.

Practitioners list their practice on Bodhi Holistic Hub and choose a plan that suits how they work:

  • Bodhi Essential — a marketplace listing and access to the practitioner community. Client data processed by Bodhi relates to marketplace bookings only.
  • Bodhi Flow — everything in Bodhi Essential, plus practice management tools that allow practitioners to manage their own clients' records, bookings, forms, and communications. Practitioners on this plan act as data controllers for their client data; Bodhi acts as their data processor.

Additional plans may be introduced in future. This Policy applies to everyone who uses Bodhi Holistic Hub — clients and practitioners alike — regardless of which plan a practitioner is on.

We have prepared this Policy to comply with both the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and the European Union's General Data Protection Regulation (GDPR).

Where different privacy frameworks apply, we will comply with the requirements that apply to your personal information in the relevant circumstances. Where it is practical and appropriate, we may apply privacy protections that exceed the minimum legal requirements.

By using our platform or services, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use our services.


2. Who This Policy Applies To

This Policy applies to all individuals whose personal information Bodhi collects or processes, including:

  • Clients who create accounts, use our matching quiz, book appointments, or otherwise interact with Bodhi Holistic Hub.
  • Practitioners who list their practice on Bodhi Holistic Hub, on any plan.
  • Visitors to our website.
  • Prospective users who enquire about our services.

This Policy does not apply to information about companies or legal entities, but does apply to information about the individual people within those entities.

If you provide us with personal information about another person — for example, booking a session on someone else's behalf — you confirm that you have their authority or consent to do so.

A note for practitioners using Bodhi's practice management tools

When you use Bodhi's practice management tools to manage your own clients, those clients' data is held by Bodhi on your behalf. In that context, you are the data controller and Bodhi is your data processor. Your obligations to your clients are described in Section 14, and a template privacy notice you can adapt for your own practice is at Appendix A.


3. Our Role: When We Are a Controller and When We Are a Processor

Privacy law distinguishes between data controllers (who decide why and how personal information is processed) and data processors (who process information on a controller's behalf). Bodhi plays both roles, depending on context.

3.1 When Bodhi is the data controller

Bodhi acts as the data controller for:

  • All information collected directly from clients using Bodhi Holistic Hub — account details, booking history, payment information, reviews, and matching quiz responses.
  • All information collected from practitioners in the context of their Bodhi Holistic Hub marketplace listing — profile details, qualifications, vetting documents, and booking data where Bodhi facilitates the transaction.
  • Website visitor data (cookies, analytics, session recordings, IP addresses).
  • Our own marketing communications and newsletter list.

As controller, Bodhi determines the purposes and means of processing and is directly responsible to you for compliance with the APPs and GDPR.

Where a practitioner enters, imports or otherwise provides personal information about a client into Bodhi, the practitioner must ensure that the client has been given an appropriate privacy notice explaining that their information will be stored and processed using Bodhi. Bodhi requires practitioners to make this notification before the information is entered into the practice management tool, or as soon as practicable afterwards, where prior notice is not reasonably possible.

3.2 When Bodhi is a data processor

When practitioners use Bodhi's practice management tools to store and manage records about their own clients — including clients who have no direct relationship with Bodhi Holistic Hub — Bodhi acts as a data processor on the practitioner's behalf. In that context:

  • The practitioner is the data controller: they determine what data is collected, why, and for how long.
  • Bodhi processes that data only on the practitioner's documented instructions.
  • Bodhi's obligations as processor are set out in the Practice Management Data Processing Addendum (DPA), which practitioners agree to at account creation, before any client data is entered into the platform.

If you are a client of a practitioner using Bodhi's practice management tools and have questions about how your data is handled, please contact that practitioner directly. The practitioner is primarily responsible for client-facing privacy decisions — including providing you with their own privacy notice. However, Bodhi remains responsible for protecting the information it holds and for processing it in accordance with the DPA and applicable privacy law.

For the purposes of this Policy, we use the terms "controller" and "processor" to explain our different roles in a way that is familiar to users in jurisdictions such as the European Union and United Kingdom. Under Australian privacy law, our obligations are assessed by reference to whether we collect, hold, use or disclose personal information, and we comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles in relation to those activities.


4. Information We Collect

4.1 Information you give us directly

When you create an account, book a session, submit an enquiry, or otherwise interact with our platform, you may provide:

  • Identity details: full name and, if you choose to upload one, a profile photo.
  • Contact details: email address, phone number, and (for practitioners) business address.
  • Account credentials: username and encrypted password.
  • Professional details (practitioners only): qualifications, certifications, professional memberships, modalities practised, and supporting documents submitted as part of our vetting process.
  • Financial details: payment card information for booking payments (collected and processed directly by Stripe — we do not store full card numbers); bank account details for practitioner payouts via Stripe Connect.
  • Booking information: dates, times, and service type.
  • Communications: messages sent through our in-platform messaging system, and support enquiries sent to us by email.
  • Content you create: practitioner profile text, photos, and articles or blog posts submitted to our Learning Hub.
  • Preferences and settings: notification preferences and Google Calendar connection settings.

4.2 Health and sensitive information

Because our platform connects people with holistic practitioners, some information we collect is health-related. We handle this category with additional care — see Section 5 for full details.

Health and sensitive information may be collected directly from you, generated through your use of the platform, entered by a practitioner using Bodhi's practice management tools, or included in communications, intake forms, profile notes or booking-related information.

4.3 Information we collect automatically

When you visit our website or use our platform, we automatically collect:

  • Device and technical data: IP address, browser type and version, operating system.
  • Usage data: pages visited, search queries, links clicked, and time spent on pages.
  • Session and behavioural data: Behavioural analytics tools, including Microsoft Clarity, are not used on pages where users enter or view sensitive or health-related information, including practitioner-client messages, intake forms, client notes, booking details, payment details, matching quiz free-text fields, or practice management client records. Even where form inputs are masked, we recognise that session recordings and behavioural analytics may reveal sensitive inferences about a user's health, wellness interests, practitioner preferences or service needs. For this reason, we limit behavioural analytics to general website and platform usability pages where sensitive information is not entered or displayed.
  • Cookies and similar technologies: see Section 12 for a full description by category.
  • Calendar availability: if you connect your Google Calendar, we collect free/busy scheduling data as described in Section 11.

4.4 Information we receive from third parties

We may receive personal information about you from:

  • Identity and document verification services used during practitioner vetting.
  • Stripe: confirmation of payment status and dispute information.
  • Social media platforms: if you register using a social login (for example, Sign in with Google), we receive the basic profile information you have authorised that platform to share.

4.5 Practitioners migrating to Bodhi's practice management system

Practitioners who migrate to Bodhi's practice management system from another system may import existing client records. The information that can be imported is limited to: full name, email address, date of birth, phone number, and postal address. No appointment history, clinical notes, or health records can be imported. The practitioner is responsible for ensuring they had a lawful basis to share that data with Bodhi's systems. Bodhi processes imported data exclusively on the practitioner's instructions and does not use it for any Bodhi Holistic Hub purpose.

4.6 Information practitioners import into Bodhi's practice management system

When a practitioner adds an existing client through Bodhi's practice management system by manually entering that client's contact details — for example, when onboarding a client they already work with outside of Bodhi — we receive the following information from the practitioner about that client: full name, email address, phone number, date of birth, residential or postal address, timezone, and emergency contact details (the name and contact number of the client's nominated emergency contact).

We use this information solely to:

  • Send the client a one-time invitation to create a Bodhi account if they do not already have one; or
  • Send the client a Care Team access request if they already have a Bodhi account.

Not all of this information is used for the purposes of sending an invitation or Care Team request. Only the client's name and email address are used to send the invitation or access request. All other fields entered by the practitioner — including date of birth, address, timezone, and emergency contact details — are stored in Bodhi as part of the practitioner's client record, processed by Bodhi on the practitioner's behalf as data processor. These fields are subject to the practitioner's own obligations as data controller, described in Section 14.

Emergency contact details are third-party personal information about a person who has no direct relationship with Bodhi. Bodhi stores this information solely to allow the practitioner to manage their client records. We do not contact emergency contacts directly and do not use emergency contact details for any purpose other than making them available to the practitioner within Bodhi's practice management tools.

Where a practitioner enters emergency contact details, the practitioner is responsible for ensuring that the client has authority to provide those details and that the emergency contact is informed where required by applicable law or professional obligations.

We do not use this information for marketing, profiling, or any other purpose.

Clients who receive an invitation and choose not to create an account may still receive transactional appointment notifications sent on the practitioner's behalf. These communications are informational only. We will not use a non-account client's email address for marketing purposes unless they subsequently create an account and opt in directly.


5. Sensitive and Health Information

Health information and certain other categories of personal information receive a higher level of protection under both the Privacy Act (as "sensitive information") and the GDPR (as "special category data"). This section explains how we handle these on our platform.

5.1 What health-related information we hold

On Bodhi Holistic Hub, health-related information may include:

  • Wellness goals and areas of focus you select or describe when completing our matching quiz (for example, stress management, fertility support, or chronic pain).
  • Any additional context you voluntarily provide in the free-text field of the matching quiz.
  • Information shared between you and a practitioner through our in-platform messaging system.
  • Client profile notes that a practitioner using Bodhi's practice management system adds to your record within their practice management system. These are free-text notes written by the practitioner about your sessions and progress, and are held by Bodhi on the practitioner's behalf.

5.2 How we handle sensitive information

We will:

  • Collect health-related information only with your explicit, informed consent or where otherwise permitted by law.
  • Collect only the minimum amount necessary for the stated purpose.
  • Restrict access to sensitive information to authorised personnel on a strict need-to-know basis.
  • Apply additional security measures to sensitive data, including encryption at rest and in transit.
  • Never use health or wellness information to create advertising audiences, lookalike audiences, behavioural advertising segments or marketing profiles.
  • Never sell sensitive information, or share it with third parties except as necessary to provide the service or as required by law.

5.3 The matching quiz

Our practitioner matching quiz asks you to:

  • Indicate whether you are looking for in-person or online sessions (and if in-person, your location).
  • Select your wellness goals from a curated list.
  • Optionally provide additional context in a free-text field.

You provide this information voluntarily. We use it, together with our AI matching algorithm (see Section 22), to recommend suitable practitioners. We process this information on the basis of your explicit consent, which you give when you submit the quiz. You may delete your quiz data at any time from your account settings.

Your quiz responses are not shared with practitioners directly. Practitioners see only the booking information you choose to share when you book with them.


6. Staff Access to Private Communications

Our baseline commitment

Bodhi staff do not routinely read private messages exchanged between practitioners and clients on our platform. Access is limited to defined operational circumstances, granted only to authorised personnel, and is always logged.

In this section, "private communications" includes messages exchanged through our platform between practitioners and clients, and any message attachments or booking-related notes that are not intended to be publicly visible.

6.1 When staff may access private communications

Authorised Bodhi personnel may access private platform messages only in the following circumstances:

  • Technical support: where a user has raised a support issue that requires us to inspect message content to diagnose a technical fault.
  • Safety and abuse: where we receive a report of conduct that may endanger a person's safety, constitute harassment or abuse, or involve illegal content.
  • Dispute resolution: where a practitioner and client have raised a formal dispute through our complaints process and message content is directly relevant to resolving it.
  • Fraud and platform integrity: where we have reason to suspect fraudulent activity, impersonation, or a serious breach of our Community Standards.
  • Legal obligation: where we are required to disclose communications by a court order, subpoena, or other legally binding demand.

Where access is required, we will access only the minimum amount of communication content reasonably necessary for the relevant purpose.

6.2 Access controls and logging

All access to private communications is:

  • Restricted to a small number of named, authorised personnel with a documented operational need.
  • Subject to internal review to confirm the access was justified.

Staff who access private communications without authorisation are subject to disciplinary action, up to and including termination of employment.

6.3 Your right to know

Where appropriate and legally permitted, we may inform you if your private communications have been accessed by Bodhi staff outside ordinary user-requested support handling, and explain the reason for that access.


7. How We Use Your Information

7.1 To provide and operate our services

  • Creating and managing your account.
  • Matching clients with suitable practitioners through our quiz and search features.
  • Processing bookings, payments, and refunds.
  • Enabling in-platform messaging between practitioners and clients.
  • Facilitating Google Calendar synchronisation for scheduling.
  • Conducting practitioner vetting and onboarding.
  • Providing Bodhi's practice management features, including forms, automated client communications, scheduling, and client profile management.
  • Sending one-time account invitations and Care Team access requests to clients added by practitioners, and managing Care Team connections between clients and practitioners.

7.2 To communicate with you

  • Sending booking confirmations, appointment reminders, and payment receipts (via Mailgun or Twilio SMS).
  • Responding to your support enquiries and complaints.
  • Sending important platform notices and policy updates — you cannot opt out of these service communications.
  • Sending marketing emails and newsletters, but only if you have opted in (see Section 17).

7.3 To keep the platform safe

  • Detecting and preventing fraud, abuse, and illegal activity.
  • Enforcing our Terms and Conditions and Community Standards.
  • Investigating complaints and disputes.

7.4 For analytics and improvement

  • We do not use health information, private messages, practitioner client notes, intake forms or matching quiz free-text responses for general analytics, behavioural analytics or product testing unless the information has first been de-identified or aggregated so that it no longer identifies you.
  • When testing new platform features, we use de-identified, aggregated or synthetic data wherever practicable, and not using sensitive health information for testing unless required for the feature and permitted by law.

7.5 To comply with legal obligations

  • Maintaining financial records for tax and audit purposes.
  • Responding to lawful requests from government authorities.
  • Notifying relevant authorities in the event of a reportable data breach.

7.6 Lawful basis for processing (GDPR)

For users in the EU or EEA, we rely on the following lawful bases:

  • Contract performance: processing necessary to provide the services you have requested.
  • Consent: where you have given us clear, specific consent — for example, marketing emails, quiz health data, and non-essential analytics cookies. Consent can be withdrawn at any time.
  • Legitimate interests: where we have a genuine business need that does not override your rights — for example, fraud prevention and platform security.
  • Legal obligation: where processing is required by Australian or other applicable law.

7.7 For Australian users

Where we collect sensitive information, including health information, we do so with your consent where required by the Privacy Act, and only where reasonably necessary for our functions or activities.


8. Sharing Your Information

We do not sell your personal information. We do not share it with third parties for their own marketing purposes. We share it only in the following circumstances.

8.1 Between practitioners and clients (on platform)

When you book a session, we share the information reasonably necessary for the practitioner to provide the service, such as your name, contact details, appointment time, service type, any additional information you choose to provide, and relevant payment or attendance status.

8.2 Practitioner profile information (publicly visible)

Practitioner profile information — including name, biography, qualifications, modalities, services, and pricing — is intentionally public and visible to anyone who visits Bodhi Holistic Hub. If you are a practitioner, by creating a listing you consent to your profile information being publicly accessible.

Practitioners should not include personal information about clients, testimonials, case studies or images of other people in their public profile unless they have obtained all necessary consents.

8.3 With our sub-processors and service providers

We engage trusted third-party service providers to help us operate the platform. These providers act as our processors and may only handle your personal information in accordance with our instructions. See Section 10 for the full list.

8.4 For legal and safety reasons

Where we disclose information for legal, safety, fraud or security reasons, we will disclose only what we reasonably consider necessary in the circumstances.

8.5 Business transfers

If Bodhi is involved in a merger, acquisition, or sale of assets, your personal information may be transferred to the successor organisation. We will notify you before your information is transferred and becomes subject to a different privacy policy.

8.6 With your consent

We will share your information with other parties if you have given us explicit consent to do so.

8.7 Care team data sharing

The Care Team feature is available to practitioners on plans that include practice management tools (currently Bodhi Flow, and any future plan that includes this functionality). It allows clients to connect their Bodhi account with practitioners they work with. When a client adds a practitioner to their Care Team — either by approving a practitioner's access request or by selecting practitioners during account setup — they authorise Bodhi to share their current contact details (full name, email address, and phone number) with that practitioner on an ongoing, automatically synchronised basis.

This sharing operates as follows:

  • Data scope: Each practitioner on a client's Care Team can access only the client's basic contact details — full name, email address, and phone number. They cannot access information associated with any other practitioner on the same Care Team, including intake forms, session notes, or records associated with another practitioner's engagement. Additional fields entered by the practitioner when adding a client — including date of birth, address, timezone, and emergency contact details — are not part of the Care Team sync. These remain part of the practitioner's own client record in Bodhi and are not shared via the Care Team feature.
  • Automatic synchronisation: If a client updates their contact details on their Bodhi profile, those changes are automatically reflected on the practitioner's end. This means practitioners always have current information without the client needing to notify them separately.
  • Revocation: Clients can remove a practitioner from their Care Team at any time from their account settings. Upon removal, the practitioner's access to the client's live profile data ceases immediately. Any contact details the practitioner entered manually when originally adding the client remain with the practitioner and are subject to the practitioner's own privacy and professional obligations.

9. International Transfers of Personal Information

Bodhi is an Australian company. Our primary platform infrastructure is hosted on Google Cloud Platform (GCP), with servers located in Sydney, Australia (GCP region: australia-southeast1). Cloudflare sits in front of the platform as a CDN and DDoS protection layer. Several of our other sub-processors are based in other countries, and your personal information may be transferred to and stored in those countries.

9.1 Transfers to the United States

Several key sub-processors — including Stripe, Klaviyo, Mailgun, Twilio, and Microsoft (Clarity) — are based in the United States. The United States does not have a formal adequacy decision under the GDPR.

Where personal information is transferred from the EU or EEA to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our data processing agreements with each US-based sub-processor.

Before disclosing personal information to an overseas recipient, we take reasonable steps required by APP 8 to ensure the recipient handles the information consistently with the Australian Privacy Principles, unless an exception applies. These steps may include contractual privacy and security obligations, data processing agreements, transfer assessments, security reviews and vendor due diligence.

9.2 Transfers within the EU

Typeform, which powers our practitioner matching quiz, is based in Spain and is subject to the GDPR. No additional transfer mechanism is required for data processed by Typeform.

9.3 New Zealand

Xero, our accounting and invoicing provider, is based in New Zealand. New Zealand has been granted an adequacy decision by the European Commission, meaning it is considered to provide adequate data protection for GDPR purposes.

9.4 Transfers from the EU or EEA to Australia

While Bodhi Holistic Hub is an Australian platform primarily serving Australian users, we receive bookings and account registrations from a small number of users located in the European Union and European Economic Area. The personal information of these users is hosted on our Australian infrastructure (Google Cloud Platform, Sydney region — as described in Section 10).

Australia does not currently hold a formal adequacy decision from the European Commission. For EU/EEA users, we rely on the following basis for the transfer of personal information to Australia:

For clients making bookings and for practitioners accessing the platform under a service agreement, we rely on Article 49(1)(b) of the GDPR — the transfer is necessary for the performance of a contract between you and Bodhi, or for the implementation of pre-contractual measures taken at your request.

We note that this derogation is applied in respect of our limited EU/EEA user base and the specific, transaction-based nature of their interaction with the platform. We will keep our approach to EU/EEA transfers under review and implement Standard Contractual Clauses or other appropriate safeguards if the nature or volume of EU/EEA transfers materially increases.

Our infrastructure provider for Australian-hosted data is Google Cloud Platform, which operates under appropriate data processing agreements as described in Section 10.


10. Our Sub-processors

The following table lists the third parties that process personal information on our behalf or in connection with our services. We review this list at least annually. If we add a new sub-processor that materially changes how your data is handled, we will notify affected practitioners with at least 14 days' notice.

Sub-processorPurposeLocationSafeguard / Transfer Mechanism
Stripe, Inc.Payment processing, subscription billing, and practitioner payouts (Stripe Connect)United StatesStandard Contractual Clauses; Stripe Data Processing Agreement
Google LLC Google Calendar integration (scheduling); Google Analytics (website traffic analytics); Google Gemini (AI matching algorithm — see Section 22) United States (data may be processed globally)Standard Contractual Clauses; Google DPA; Analytics IP anonymisation enabled
Microsoft CorporationMicrosoft Clarity (session recordings, heatmaps, and behavioural analytics)United StatesStandard Contractual Clauses; Microsoft DPA
Klaviyo, Inc.Marketing email campaigns and subscriber managementUnited StatesStandard Contractual Clauses; Klaviyo Data Processing Agreement
Mailgun Technologies (Sinch)Transactional emails (booking confirmations, reminders, account notifications)United StatesStandard Contractual Clauses; Mailgun Data Processing Agreement
Twilio Inc.SMS notifications and appointment remindersUnited StatesStandard Contractual Clauses; Twilio Data Processing Agreement
Typeform SLPractitioner matching quiz (data collection and processing)Spain (European Union)Subject to GDPR; no additional transfer mechanism required for EU data
Xero LimitedAccounting and invoicing for marketplace joining feesNew ZealandNZ Privacy Act 2020; New Zealand EU adequacy decision
Google Cloud Platform (Google LLC)Primary platform infrastructure and data hostingAustralia (GCP region: australia-southeast1, Sydney)Google Cloud DPA; data residency in Australia; ISO 27001 certified
Cloudflare, Inc.CDN, DDoS protection, and Web Application Firewall (sits in front of platform infrastructure)United States (traffic proxied globally; platform data remains on GCP Sydney)Standard Contractual Clauses; Cloudflare DPA

Where quiz responses include health or wellness-related information, those responses may constitute sensitive information. We apply additional safeguards before sending this information to Google Gemini, including limiting the information sent, using contractual protections, configuring the service so customer data is not used for model training where available, and avoiding unnecessary free-text processing.


11. Google Calendar Integration

Practitioners and clients may connect their Google Calendar to synchronise availability and prevent scheduling conflicts. This section describes how we handle Google account data in accordance with Google's API Services User Data Policy.

11.1 What data we access

We access only:

  • Calendar availability and free/busy information.
  • Event timing and scheduling metadata necessary for booking management.
  • The Google account email address associated with the calendar.

We do not access the content or titles of your calendar events, your attendee lists, or any data beyond what is strictly necessary for scheduling.

11.2 How we use this data

Google Calendar data is used exclusively to synchronise practitioner availability, prevent double-bookings, and send scheduling confirmations. We do not use it for marketing, profiling, or any other purpose. We do not share Google user data with any third party beyond what is necessary to operate the scheduling function. This use complies with Google's Limited Use requirements.

11.3 Retention and disconnection

  • Active scheduling data is retained while the integration is connected and your account is active.
  • Historical calendar event data is automatically deleted from our systems within 30 days of the event date.
  • You may disconnect your Google Calendar at any time via your account dashboard. All associated calendar data will be deleted from our systems upon disconnection.
  • Disconnecting your Google Calendar will stop future synchronisation and delete associated calendar data from our systems, but it will not automatically cancel existing bookings or appointment records already created through the platform.

12. Cookies and Tracking Technologies

We use cookies and similar technologies to make our platform work, understand how it is used, and improve your experience. This section explains each category of tracking technology we use and how you can control it.

12.1 What are cookies?

A cookie is a small text file placed on your device when you visit a website. Cookies help the site remember your preferences, keep you logged in, and collect information about how the site is used. You can manage cookies through your browser settings — see Section 12.4.

12.2 Types of tracking we use

Essential cookies

These are strictly necessary for the platform to function. Without them, logging in, making a booking, or completing a payment would not work. We do not require your consent to place essential cookies.

  • Session management (keeping you logged in).
  • Security tokens (CSRF protection).
  • Cloudflare security and load-balancing cookies.
  • Stripe payment security cookies.

Analytics — Google Analytics

We use Google Analytics with IP anonymisation enabled to understand how visitors use our platform (pages visited, traffic sources, device types). This data is aggregated. Google Analytics data is retained for 14 months. We place Google Analytics cookies only with your consent (or by default for Australian users — you may opt out at any time via your browser or cookie settings).

Behavioural analytics — Microsoft Clarity

What you should know about Microsoft Clarity

Microsoft Clarity records mouse movements, clicks, scrolling, and page interactions in the form of session recordings and heatmaps. These recordings help us identify usability issues and improve the platform. Clarity is configured to mask all form field inputs, meaning the content you type into any field on our platform — including the matching quiz free-text field — is not visible in session recordings. Session recordings are processed by Microsoft Corporation in the United States. We place Clarity only with your consent for EU/EEA users. You may opt out at any time by adjusting your cookie preferences.

Marketing cookies

We do not currently use third-party advertising or retargeting cookies on our platform. If we introduce marketing cookies in future, this Policy will be updated and your consent will be sought before any such cookies are placed.

We do not use Microsoft Clarity or equivalent session recording tools on pages where users enter or view sensitive information, including matching quiz free-text fields, intake forms, private messages, practitioner client notes, payment pages, account health preferences, or practice management client records.

12.3 Cookie consent — Australian and EU users

There is no legal requirement under Australian law for a cookie consent banner. We disclose our cookie use in this Policy and you may opt out of non-essential tracking at any time.

For users in the EU or EEA, we obtain your consent before placing any non-essential cookies (analytics and behavioural tracking), in accordance with the GDPR. A consent banner will be displayed to EU/EEA visitors.

12.4 How to manage or disable cookies

You can control cookies through your browser settings. Most browsers allow you to view and delete existing cookies, block specific types of cookies, and set preferences for individual websites. Blocking essential cookies will prevent core platform functions from working. Blocking analytics or behavioural cookies will not affect your ability to book or manage appointments.

For guidance on managing cookies in your browser, visit www.aboutcookies.org or www.allaboutcookies.org.


13. Data Retention Schedule

We retain personal information for as long as necessary to fulfil the purposes for which it was collected, comply with our legal obligations, and resolve disputes. The table below sets out our standard retention periods by data type.

Practitioners are responsible for selecting and applying any retention period required by their professional, legal or insurance obligations. Bodhi's default retention settings are a platform safeguard only and are not a substitute for professional record-keeping advice.

Data TypeRetention PeriodReason
Active account data (clients and practitioners)Duration of active accountNecessary to provide the service
Booking and transaction records7 years from the transaction dateTax Act (Cth) and GST record-keeping obligations
Payment card dataNot retained by Bodhi — tokenised by Stripe at point of entryPCI-DSS compliance; Bodhi does not store card numbers
Practitioner vetting documents (credentials and identity documents)Duration of active listing + 7 yearsCompliance record-keeping; defence of legal claims
Marketing opt-in and opt-out recordsUntil consent is withdrawn, then retained for 3 yearsSpam Act (Cth) compliance; evidence of consent
Support and complaint correspondence3 years from resolutionLegitimate business interest; legal claims limitation period
Google Calendar event data30 days from the event dateMinimal data principle; Google API requirements
Website analytics data (Google Analytics)14 months (set in GA4 admin)Standard Google Analytics retention; proportionality
Microsoft Clarity session recordings30 days from capture (Clarity default)Behavioural analytics; proportionality
Cookie consent records3 yearsEvidence of consent; Spam Act and GDPR compliance
Matching quiz responsesDuration of account or until deleted by user in account settingsBased on explicit consent; user-controlled deletion
Practice management client records (name, contact details, profile notes, form responses, booking history) — applicable to practitioners on Bodhi Flow and any future plan that includes practice management access Maximum 10 years from the date of last activity on the client record, or until the practitioner deletes the record, or until the practitioner's plan with practice management access ends + 30-day export window (whichever comes first) 10-year default safeguard for inactive records; practitioner as data controller may apply a shorter period; Bodhi deletes on instruction or on plan termination
Post-account-deletion residual backupsRemoved from encrypted backups within 90 days of account deletionTechnical necessity; secure deletion process
Fraud and compliance investigation records7 years from conclusionLegal obligation; defence of regulatory action
Data access request records3 years from fulfilmentEvidence of compliance
Legal hold dataUntil resolution of proceedings + 3 yearsLegal obligation

Practitioners on Bodhi Essential do not hold practice management client records through Bodhi. Their marketplace booking and transaction records are covered by the "Booking and transaction records" row above.

We conduct periodic data minimisation reviews and delete information that is no longer required. If you request deletion of your account, we will delete your personal information from our live systems within 30 days. Some information may be retained for legal or compliance reasons as noted in the table above.

Where practicable, we retain the outcome of verification checks rather than copies of identity documents. Where identity documents must be retained, we restrict access and delete them when they are no longer reasonably necessary.


14. Bodhi Practice Management System: Practitioner Client Data

This section is particularly relevant to practitioners on the Bodhi Flow plan, and to clients whose data a practitioner holds within the tool.

14.1 Practitioner obligations as data controller

When you use Bodhi's practice management system to store information about your own clients, you are the data controller. This means you are responsible for:

  • Having a lawful basis to collect and process each client's personal information.
  • Providing your clients with a clear privacy notice about how you use their data (a template is at Appendix A).
  • Responding to data subject requests (access, correction, deletion) made by your clients.
  • Keeping client records accurate and up to date.
  • Complying with any professional, regulatory, or insurance obligations that apply to your practice, including clinical record-keeping standards required by AHPRA or equivalent bodies. Note: Bodhi's practice management notes feature does not satisfy these requirements — see Section 14.2 for the full disclaimer.

14.2 Client profile notes

Bodhi allows practitioners to add free-text notes to a client's profile within the platform. These notes are visible only to the practitioner and are held by Bodhi as processor on the practitioner's behalf. Bodhi staff do not access client profile notes except in the limited circumstances described in Section 6. These notes do not constitute a clinical records system. They do not satisfy AHPRA professional record-keeping requirements or any equivalent obligations under state or territory law. Practitioners registered with AHPRA or subject to professional clinical record-keeping standards must maintain compliant records through appropriate systems — Bodhi's notes feature cannot be relied upon for this purpose.

14.3 Lawful basis for imported client data

If you import existing client records into Bodhi, those individuals were not directly informed that their data would be held on Bodhi's infrastructure. As the controller, it is your responsibility to ensure you had a lawful basis for the original collection and to inform your clients that their records are now held in Bodhi. We strongly recommend updating your client privacy notice (Appendix A provides a template) before completing any import. Practitioners must provide appropriate notice to clients before importing their information into Bodhi, unless prior notice is not reasonably practicable, in which case notice must be provided as soon as practicable after import.

14.4 Responding to data subject requests from practitioner clients

If one of your clients contacts Bodhi directly with a request to access or delete their records held in Bodhi, we will:

  • Acknowledge receipt and notify you as the relevant controller within 5 business days.
  • Assist you in fulfilling the request within the legally required timeframe.
  • Not act on the request ourselves without your instruction, unless required by law.

14.5 What happens to practice management client data when a plan ends?

If your subscription ends for any reason, we will:

  • Notify you at least 30 days before any data deletion (except in cases of termination for serious breach, where we will provide as much notice as practicable).
  • Provide you with a full export of all client records (name, contact details, profile notes, form responses, and booking history within Bodhi) in a portable, machine-readable format within 30 days of termination.
  • Permanently delete all practitioner client data from our systems within 60 days of termination, subject to any legal hold obligations.

If a practitioner downgrades from a plan with practice management access to one without (for example, from Bodhi Flow to Bodhi Essential), the same export and deletion process described above applies to their practice management client data. Full details are set out in the Practitioner Subscription Agreement and Data Processing Addendum.

14.6 Adding clients to Bodhi — practitioner obligations

When you add an existing client to your Bodhi account by entering their contact details directly, you represent and warrant that:

(a) this person is a current or former client of your practice; (b) you obtained their contact details through a legitimate professional relationship; (c) you have provided, or will promptly provide, the client with appropriate notification that their contact details have been shared with Bodhi Holistic Hub for the purpose of sending them a platform invitation; and (d) where you have collected emergency contact details, you have done so with the client's knowledge and you have a legitimate basis for sharing those details with Bodhi's systems.

Bodhi will send an invitation to the client on your behalf. You remain responsible for maintaining accurate contact details for clients who choose not to create a Bodhi account.

14.7 Care Team access

The Care Team feature allows clients to authorise Bodhi to share their contact details with you on an ongoing basis. Care Team access is granted exclusively by the client — you cannot access a client's live Bodhi information without their explicit consent.

If a client grants Care Team access, you will receive their current contact details (full name, email address, and phone number), which will update automatically if they change their details on their Bodhi profile.

If a client declines a Care Team request or later revokes access, you will retain only the contact details you entered manually when you originally added them as a client. Those details will not update automatically and are subject to your own privacy and professional record-keeping obligations.

You must not use contact details received through the Care Team feature for any purpose other than managing your professional relationship with that client.


15. Security of Your Information

We implement appropriate technical and organisational measures to protect personal information against unauthorised access, disclosure, alteration, and destruction.

15.1 What we do

  • Encryption in transit: all data transmitted between your device and our platform is encrypted using TLS.
  • Two-factor authentication (2FA): access to our admin dashboard requires two-factor authentication for all authorised personnel.
  • Encryption at rest: sensitive data categories are encrypted at rest.
  • Access controls: role-based access ensures staff can only access data relevant to their role.
  • Access logging: all staff access to personal information is automatically logged.
  • Cloudflare security: DDoS protection, Web Application Firewall, and traffic filtering are active at the infrastructure level.
  • Staff training: all Bodhi team members and contractors with access to personal information complete privacy and data security training.
  • Vendor reviews: we assess the security standards of sub-processors before engagement.

15.2 Your responsibilities

No system is completely secure. You are responsible for keeping your account credentials confidential, using a strong and unique password, and notifying us promptly at [email protected] if you suspect your account has been compromised.

We periodically review access permissions, monitor audit logs, apply security updates, maintain encrypted backups, and use secure development and vulnerability management practices appropriate to the nature and sensitivity of the information we hold.


16. Data Breach Response

16.1 Our response process

If we suspect that a data breach may be an eligible data breach under the Privacy Act, we will carry out a prompt and reasonable assessment, generally within 30 days. If we determine that the breach is likely to result in serious harm, we will notify the OAIC and affected individuals as required by the Notifiable Data Breaches scheme.

Where we act as processor, we will notify the relevant practitioner without undue delay after becoming aware of a personal data breach affecting their practice management client data.

16.2 Practice management data breach notification to practitioners

Where a breach involves practice management data held by Bodhi, we will notify the relevant practitioners within 72 hours of becoming aware. Practitioners (as controllers) are then responsible for determining whether they need to notify their own clients and/or the OAIC. We will cooperate fully to assist with that assessment.

To report a suspected security issue to us, please contact [email protected].


17. Marketing and Opting Out

We send marketing emails only to people who have opted in to receive them. You can opt out at any time by:

  • Clicking the Unsubscribe link at the bottom of any marketing email.
  • Emailing us at [email protected] with the subject line "Unsubscribe".

We will process your opt-out within 5 business days. You will continue to receive essential service emails (booking confirmations, security alerts, and policy updates) that are necessary for your use of the platform.

We send commercial electronic messages in accordance with the Spam Act 2003 (Cth), including by obtaining consent where required, identifying Bodhi as the sender and providing a functional unsubscribe facility.


18. Your Privacy Rights

You have a range of rights in relation to your personal information. Australian residents have equivalent rights under the APPs, including the right to access and correct personal information.

RightWhat it meansHow to exercise it
AccessRequest a copy of the personal information we hold about you. Email [email protected]. We will respond within 28 days (APPs) or one month (GDPR).
Correction / RectificationAsk us to correct inaccurate or incomplete personal information.Update your details in account settings, or contact us. We will correct records within 28 days.
Deletion (Erasure)Ask us to delete your personal information in certain circumstances.Contact us. Note: some data may be retained for legal or compliance reasons (see Section 13).
Restrict ProcessingAsk us to pause processing your information while a dispute is resolved.Contact us in writing. We will acknowledge within 5 business days.
Data PortabilityRequest your data in a portable, machine-readable format.Contact us. We will provide an export within 28 days.
ObjectObject to processing based on legitimate interests, or to direct marketing.Contact us or use the unsubscribe link. We will cease that processing immediately.
Withdraw ConsentWhere processing is based on consent, withdraw it at any time without penalty.Use account settings or contact us. Withdrawal does not affect prior lawful processing.
Human Review of Automated DecisionsRequest human review of any recommendation generated by our matching algorithm.Contact us at [email protected].

We do not charge a fee for access requests unless a request is manifestly unfounded, excessive, or repetitive. If we refuse a request, we will explain why and tell you how to complain.

Australian residents have rights under the Privacy Act and APPs, including rights to access and correct their personal information. Some additional rights listed below apply where the GDPR or another applicable privacy law applies, or where we choose to provide them as part of our privacy practices.


19. Reviews and Ratings

Clients may leave reviews and star ratings on practitioner profiles following a completed booking. Reviews are publicly visible on the practitioner's profile. By submitting a review, you consent to it being published and understand that it may be seen by anyone visiting our platform.

We reserve the right to remove reviews that breach our Community Standards (for example, defamatory content, hate speech, or false information). Practitioners may flag a review for investigation but cannot remove a genuine client review unilaterally.

Review data is retained for the duration of the practitioner's active listing and for 12 months after a listing closes.

When leaving a review, please avoid including sensitive personal information about yourself or others, including detailed health information, medical history, diagnosis, treatment details or information that could identify another person.

We may edit or remove reviews that contain sensitive personal information, identify another person without consent, or create legal, safety or privacy risks.


20. Children and Young People

The Bodhi Holistic Hub platform, across all plans, is accessible to users of all ages, including people under 18. We do not collect date of birth at account registration, and we do not impose an age gate on the platform.

The Bodhi Holistic Hub platform is intended for use by adults. We recommend that users be at least 18 years of age to create an account independently. Users aged 16 or 17 may use the platform with the knowledge and consent of a parent or guardian.

We do not collect date of birth at account registration and do not impose a technical age gate. Where a parent or guardian creates or manages an account on behalf of a person under 18, the parent or guardian is responsible for that person's use of the platform and consents to the collection of personal information in connection with that use.

If you become aware that a person under 16 has created an account without appropriate parental or guardian consent, please contact us at [email protected] and we will review the account and delete the personal information if appropriate.

Where a practitioner provides services to clients under 18, the practitioner is responsible for:

  • Obtaining appropriate parental or guardian consent before collecting or processing that client's personal information;
  • Ensuring that any health or wellness information collected about a minor is handled with additional care and in accordance with their professional obligations.

These obligations are set out in the Practitioner Terms and Conditions. Bodhi is not responsible for a practitioner's compliance with those obligations, but will investigate reports of misuse through our complaints process (Section 23).


21. Practitioner-Hosted Events

From time to time, practitioners listed on Bodhi Holistic Hub may host workshops, webinars, group sessions, or other events, which may be promoted through our platform. These events are organised and run by the practitioner, not by Bodhi.

If an event is recorded, the hosting practitioner is responsible for:

  • Informing participants before the event that recording is intended.
  • Obtaining clear consent from all participants.
  • Handling and retaining recordings in accordance with their own privacy obligations.

Bodhi is not responsible for the recording practices of individual practitioners. If you have concerns about how a practitioner handled a recording, please contact the practitioner directly. If the matter is not resolved, you may contact us at [email protected] and we will review whether any Community Standards or platform rules have been breached.

Where Bodhi processes event registration, payment or attendance information through the platform, we handle that information in accordance with this Policy. The practitioner remains responsible for event content, participant management and any recording they conduct.


22. AI-Powered Practitioner Matching

Our practitioner matching feature uses an AI algorithm powered by Google Gemini to analyse your quiz responses (location preference, wellness goals, and any optional additional context you provide) and generate a ranked list of practitioner recommendations.

There are a few things you should know about how this works:

  • Your quiz responses are processed by Google Gemini, which means that data is sent to Google's systems in the United States. We have Standard Contractual Clauses in place with Google for this transfer. See Section 10 for details.
  • Google does not use your quiz responses to train its AI models. We use a Google Gemini service configured so that customer data is not used for model training purposes. We configure the Google AI service so that customer data is not used to train Google's foundation models, where this setting is available under our service terms.
  • The recommendations produced are suggestions only — you are never obligated to book a practitioner we recommend, and you can browse and book any listed practitioner regardless of the matching output.
  • No automated decision is made that legally or significantly affects you. The algorithm produces a ranked list; the final decision is always yours.
  • You can request a human review of any recommendation by contacting us at [email protected].

We minimise the information sent to the AI matching system and do not include account credentials, payment information, private messages, practitioner notes or other practice management records in the matching prompt.

We do not use AI for any other purpose on our platform — including message templates, scheduling, or communications. All other features are operated without AI processing of your personal information.

Human review means a Bodhi team member will review the information used to generate the recommendation and explain, where reasonably possible, the main factors that influenced the result.


23. Complaints and Disputes

23.1 How to make a privacy complaint

If you believe we have not handled your personal information in accordance with this Policy or applicable law, please contact us first so we can try to resolve the matter directly:

Please mark your message with the subject line "Privacy Complaint" so it reaches the right person promptly.

We will acknowledge your complaint within 5 business days and aim to provide a substantive response within 30 days. For complex matters, we will keep you updated on our progress.

23.2 External complaint bodies

If you are not satisfied with our response, or prefer to contact a regulator directly, you may contact:

23.3 Privacy oversight

Privacy oversight at Bodhi is currently the responsibility of our founder. As the organisation grows, this responsibility will be transitioned to a designated privacy function. This Policy will be updated when that transition occurs. If you have a privacy question or concern that you would like escalated, please email [email protected] and mark it "For the attention of the founder."

Bodhi has assigned internal responsibility for privacy oversight to its founder, supported by external legal and technical advisers as required.


24. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page, display a notice on our website for 30 days, and email registered users and active subscribers with a summary of the key changes.

For minor or non-material changes, we may update the effective date without advance notice.

Continued use of our platform after a material change takes effect constitutes your acceptance of the revised Policy. If you do not agree with the changes, you may close your account.


25. Contact Us

If you have any questions about this Privacy Policy, need to access or correct your personal information, or want to exercise any of your privacy rights:

Bodhi Holistic Hub Pty Ltd   ACN 654 747 501
Email: [email protected]
Website: www.bodhiholistichub.com




Appendix A — End-Client Privacy Notice Template for Practitioners Using Bodhi's Practice Management Tools

How to use this template

Customise all fields in [square brackets] before sharing with your clients. This template is a starting point and does not constitute legal advice. If you are registered with AHPRA (for example, as a chiropractor or acupuncturist), you may have additional professional record-keeping obligations under your registration standards and should seek specific legal advice on those requirements.


Privacy Notice — [Your Practice Name]

What information we collect and hold

We collect personal information about you to provide our [modality] services. This may include your name, contact details (email, phone, address), date of birth, and notes about your sessions and progress that we record to support your ongoing care.

How we store your information

Your client records are stored using Bodhi's practice management tools, operated by Bodhi Holistic Hub Pty Ltd ACN 654 747 501 ("Bodhi"). Bodhi stores and processes your information on our behalf as our data processor. Bodhi does not use your information for any purpose other than operating the platform for our practice. Bodhi's privacy commitments are described at www.bodhiholistichub.com/legals/privacy.

Why we collect your information

We collect and use your information to provide and improve our services to you, to schedule and manage your appointments, to keep appropriate practice records, and to communicate with you about your sessions. Where required by law or our professional obligations, we may also need to retain certain records for a defined period.

Sharing your information

We do not sell your personal information or share it with third parties for their own purposes. We may share it where required by law, or in an emergency to protect your safety or the safety of others.

How long we keep your records

We retain your records for [INSERT PERIOD — e.g., 7 years from your last appointment, or as required by our professional or legal obligations]. After this period, records are securely destroyed.

We may collect health or wellness-related information where it is reasonably necessary to provide our services to you and where you have consented or where the law otherwise permits us to do so.

Your rights

You have the right to access, correct, and in some cases request deletion of your personal information held by us. To exercise these rights, or if you have any privacy questions, please contact [Your Name] at [your email address].

© 2026 Bodhi Holistic HubTMTerms|Privacy