Privacy Statement

Last updated: 20 August 2026

Holistic Services Group Pty Ltd (ABN 47 116 447 628) — referred to in this policy as HSG, we, us or our — is committed to protecting the privacy of the personal information we hold. This policy explains how we collect, hold, use, disclose and protect personal information across the whole of our business, not only through our website. This includes information about clients, program participants, enquirers, job applicants, specialist facilitators and other contractors, and suppliers.

We are bound by the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (the Privacy Act). The APPs govern the way in which we collect, use, hold, disclose and dispose of personal information. A copy of the Australian Privacy Principles is available from the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

What personal information do we collect?

Personal information you provide to us

We may collect personal information such as your name, email address, phone number, job title, employer or organisation, and business address when you make an enquiry, request a quote, book a program, subscribe to our newsletter, apply for a role with us, or otherwise contact us.

Information about program participants

Where a client organisation books a workshop, assessment or wellbeing program, we may collect limited contact and attendance information about the individual staff members who participate — for example, name and email address for booking or feedback purposes. Health and other sensitive information is handled differently, as set out below.

Health and other sensitive information

Some services — such as massage, health assessments and wellbeing consultations — involve a participant providing health or other sensitive information directly to the specialist facilitator delivering that service. Our facilitators are independent qualified practitioners who collect that information with the participant’s consent, hold it in their own records under their own professional and privacy obligations, and use it only to deliver that session. HSG does not receive or retain it, and it is never provided to the participant’s employer.

Ergonomic assessments are the exception, and we tell participants so before the assessment takes place. An ergonomic assessment produces a written report that is provided to the participant’s employer, because the employer needs it in order to act on the recommendations. We seek the participant’s consent before the assessment goes ahead. The report covers workstation observations, risk factors and practical recommendations such as equipment, set-up or task changes. Where you describe symptoms or a health condition to the assessor, that detail is not included in the employer’s report unless you agree to it. You will receive a copy of any report about you.

Website and usage data

When you visit our website, we automatically collect usage data such as your device’s IP address, browser type and version, the pages you visit, the date and time of your visit, time spent on those pages, and other diagnostic data.

Cookies

We use cookies and similar tracking technologies, including web beacons, to operate our website and understand how it is used. A cookie is a small file placed on your device; you can set your browser to refuse cookies, though some parts of our website may not function properly if you do so. Persistent cookies remain on your device until deleted or expired; session cookies are deleted when you close your browser.

We use Google Analytics, delivered through Google Tag Manager, to understand how our website is used and to improve it. We use this information for our own analysis. We do not sell or share it with other organisations for their own advertising, and we do not use social media tracking pixels on this website.

How we collect personal information

We collect personal information directly from you — for example, through our website enquiry form, by phone, by email, or in person — from the client organisation that has booked a program on behalf of its staff, from job applicants and their referees, and occasionally from publicly available sources for recruitment purposes. We do not collect personal information covertly.

Dealing with us anonymously

Where it is lawful and practicable, you may deal with us anonymously or under a pseudonym — for example, when making a general enquiry or completing a post-program feedback survey. For most of our services we will need your name and contact details in order to book, deliver or follow up on a program, and we will tell you when that is the case.

Why we collect, hold, use and disclose personal information

We collect, hold, use and disclose personal information to:

Where we rely on your consent — for example, to send you marketing communications or to collect sensitive information — we will seek that consent specifically, and you may withdraw it at any time.

Direct marketing

We may use your contact details to send you information about our programs, events and resources. Every marketing email includes a one-click unsubscribe link, and you can opt out at any time by using that link or by contacting us using the details below. Where we have obtained your contact details from your employer or another organisation rather than from you directly, you may ask us to tell you the source of that information, and we will do so unless it is impracticable or unreasonable to do so. We do not use health or other sensitive information for direct marketing, and we do not provide your details to other organisations for their own marketing.

Disclosure of personal information

We do not sell, trade or otherwise transfer your personal information to outside parties for their own use.

We may disclose personal information to:

Overseas disclosure

Some of the service providers we use to run our website, email and customer relationship management (CRM) systems may store personal information on servers located overseas, including in the United States. Where our specialist facilitators deliver a program in New Zealand or elsewhere in the Asia-Pacific region, they may receive limited contact or attendance information necessary to deliver that session in-country. Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through contractual protections where appropriate.

Storage and security of personal information

Personal information is stored electronically, primarily within our customer relationship management (CRM) system, which is protected by two-factor authentication (2FA) and password controls. Our website uses SSL encryption to protect information submitted through our enquiry forms. We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. No method of transmission over the internet or electronic storage is completely secure, and while we use commercially reasonable safeguards, we cannot guarantee absolute security. In the event of a data breach likely to result in serious harm, we will act in accordance with the Notifiable Data Breaches scheme administered by the OAIC.

How long we keep your personal information

We keep personal information only for as long as it is reasonably needed for the purpose it was collected, or as required by law. As a general rule, we retain enquiry and client records for seven (7) years after our last interaction with you, after which the information is securely destroyed or de-identified, unless we are required to retain it for longer to meet a legal, regulatory or contractual obligation.

Ergonomic assessment reports contain health information and are retained for seven (7) years from the date of the assessment, after which they are securely destroyed.

Access to and correction of your personal information

You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. We will respond to a request for access or correction within a reasonable time, generally within 30 days, and may ask you to verify your identity first. There is no charge for making a request, though we may charge a reasonable fee to cover the cost of giving access where permitted by law.

Deleting your personal information

You may ask us to delete the personal information we hold about you. We will consider each request individually. Australian law does not provide a general right to have all personal information deleted on request, unlike some overseas privacy regimes, and we may need to retain some information where we have a legal, regulatory or contractual obligation to do so, or where it is otherwise reasonably necessary, for example to complete a service already underway or to meet our record-keeping obligations. Where we are able to delete your information, we will do so, or de-identify it, within a reasonable time.

How to make a complaint

If you have a concern about how we have handled your personal information, please contact us using the details below. We will acknowledge your complaint and aim to resolve it within a reasonable time, generally within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au, or by phone on 1300 363 992.

Changes to this policy

We may update this policy from time to time to reflect changes in our practices or the law. The current version will always be available on this page, together with the date it was last updated.

Contact us

If you have any questions about this Privacy Statement, or wish to make an enquiry, access request, correction request or complaint, please contact our Privacy Officer at info@holisticservices.com.au or on 1300 889 073. You can also reach us via our contact page.

If you believe your personal information has been lost, misused, or accessed or disclosed without authorisation, please contact us immediately so that we can investigate and, where required, notify you and the OAIC under the Notifiable Data Breaches scheme.

Last updated: 20 August 2026.