Privacy policy

Last updated: 12 September 2026

Privacy policy (v3.11)

1. About this policy

  1. MAME Creative Pty Ltd (ABN 89 691 093 802), trading as ViaClara (ViaClara, we, us, our), is committed to protecting the privacy of all individuals who use our platform. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs).
  2. ViaClara is a web-based platform that connects parents and carers of neurodivergent children (Parent Users) with allied health practitioners who commit to neuroaffirming practices (Practitioner Users). Given the nature of our platform, we handle health information and information about children, which we treat with the highest level of care and in accordance with our obligations under APP 3, APP 6, and APP 11.
  3. By using ViaClara, you consent to the collection, use, and disclosure of your personal information as described in this Policy. If you do not agree, please cease using the platform.
  4. We may update this Policy from time to time. We will notify you of material changes by email or prominent notice on the platform. The current version is always available at www.viaclara.com.au/privacy.
  5. This Policy, and the ViaClara platform, is directed at and intended for use by individuals located in Australia. ViaClara does not currently offer its services to, or knowingly collect personal information from, individuals located in the European Union, the United Kingdom, or other jurisdictions with data protection laws broader than the Privacy Act. If ViaClara expands its services to such jurisdictions in future, this Policy will be updated accordingly before that expansion takes effect.

2. What information we collect

  1. Parent Users. When you register and use ViaClara as a parent or carer, we may collect:
    1. Account information: first name, last name, email address, and password (hashed).
    2. Child information: your child's age range, and their areas of challenge (such as communication or daily living skills), which we map to relevant practitioners' areas of expertise. You may also search directly by area of expertise and save that search to run again later. ViaClara does not collect or store clinical diagnoses - see Section 3 for further information.
    3. Search and matching preferences: suburb or geographic area, and the types of practitioners or areas of expertise you search for. If you save a search, this information (including suburb) is retained so the search can be run again later.
    4. Help Wanted Ads: if you post a Help Wanted Ad, we collect the details you provide - such as your child's age range and support needs, your suburb, availability, preferred mode of delivery, urgency, and NDIS or language requirements - and any responses you receive from practitioners. See clause 6 of the Parent Terms for how long your ad remains visible to practitioners, and Section 10 (Data Retention) below for how long the ad record itself is kept.
    5. Communications: the content of messages you send to practitioners via ViaClara's messaging feature. These messages may contain health information about your child.
    6. Support and feedback communications: if you contact us - for example, via our contact-us form, our feedback widget, or by choosing to share a reason when deleting your account - we collect the content of your submission. Where you use our contact-us form, this also includes your full name and the email address you signed up with. These forms are hosted by Tally, a third-party provider (see Section 5.3), and submissions are additionally retained in an internal Google Sheets business tool for our review and response - see Section 5.3 and Section 10 for further detail, including how long this data is kept.
    7. Terms and Privacy Policy acceptance: a timestamped record of your acceptance of the Platform Terms, Parent Terms, and this Privacy Policy at account creation (consent type, acceptance timestamp, IP address, and browser/device information). See Section 10 for how long this record is retained.
    8. Marketing consent: if you opt in at sign-up, a timestamped record of your consent to join ViaClara's marketing mailing list (including the exact wording you were shown), and, if you later unsubscribe, a record of that withdrawal. See Section 4.3 and Section 10 for how this is used and retained.
    9. Multi-factor authentication (MFA) and trusted devices: if you enable MFA on your account, we collect a record of any device you choose to “remember” - device/browser type, and the dates that trust was created, last used, and will expire - so you are not asked to re-verify on that device each time you log in. See Section 10 for how long this record is retained.
    10. Block records: if you block another user, a record of that block (including timestamps) is retained permanently, including if you later unblock that user or delete your account. This record is limited to the user IDs involved, the direction of the block, and the timestamp - no message content or profile information is retained under this permanent-retention exception. It is retained for safety and legal purposes and is available for legal discovery. See Section 8 (Messaging) for further information.
    11. Reports you submit or are the subject of: if you submit a report about another user or item of content, we collect the reason category you select, any free-text details and evidence you choose to provide, and a point-in-time copy of the reported content captured at the time of the report. If you are the subject of a report, we hold the same categories of information about you. See Section 10 for how long this is retained.
    12. Proactive content-scan flags: ViaClara uses automated scanning to check messages, Help Wanted Ads and responses, practitioner profiles, and minor Resources Hub article edits for content that may breach our Platform Content Policy. If your content is flagged by this scan, we hold a record of the flag and the matched content pending review; a flag alone does not result in any action against your account.
    13. Admin review of reports: if a report or a scan flag involving you is reviewed by a ViaClara administrator, we keep a record of that review, including the date and the outcome (but not the content of any internal review notes beyond what is already captured above).
  2. Practitioner Users. When you register and use ViaClara as an allied health practitioner, we may collect:
    1. Basic profile information: full name, profession, email address, phone number, suburb, website, mode of delivery, profile photo, areas of expertise, age groups served, education, availability, and NDIS registration status. Your ABN and professional registration/membership number are also displayed on your profile - see Section 2.2A. Your suburb is also geocoded to approximate coordinates, used internally to power proximity-based search ranking (see Practitioner Terms clause 9(a)). These coordinates are intended to be used for ranking purposes only and are not displayed publicly.
    2. Extended profile information (Pro and Business Builder Plans): social media page links, video introduction, professional experience, additional qualifications, memberships, and languages spoken.
    3. Registration credential information: ABN, and - where applicable to your profession - an AHPRA registration number or professional association membership number. This information is collected to verify your eligibility to register as a Practitioner User. The verification check performed, and its confidence level, varies by profession - see clause 3(f) of the Practitioner Terms and Section 2.2A below for the applicable tier for your profession.
    4. Verification information: neuroaffirming attestation data and parent verification responses.
    5. Insurance information: confirmation that you hold current professional indemnity insurance.
    6. Working With Children Check (WWCC) attestation: confirmation that you hold a current Working With Children Check (or equivalent state/territory clearance), and the date of your attestation. ViaClara collects this attestation only - it does not collect your WWCC or application number, and does not independently verify your WWCC status. See clause 3(h) of the Practitioner Terms.
    7. NDIS provider attestation: if you attest to being a registered provider with the NDIS Quality and Safeguards Commission, we collect a record of that attestation (and, if applicable, a record that you have declined to make it), so that it can be displayed to Parent Users to assist their decision-making. This attestation is optional and is separate from, and more specific than, the plain NDIS registration status field described above. ViaClara does not independently verify this attestation and relies on your self-reported status. See clause 3(l) of the Practitioner Terms.
    8. Terms and Privacy Policy acceptance: a timestamped record of your acceptance of the Platform Terms and this Privacy Policy at account creation, and of the Practitioner Terms at the fuller registration/profile-creation step (consent type, acceptance timestamp, IP address, and browser/device information). See Section 10 for how long this record is retained.
    9. Marketing consent: if you opt in at sign-up, a timestamped record of your consent to join ViaClara's marketing mailing list (including the exact wording you were shown), and, if you later unsubscribe, a record of that withdrawal. See Section 4.3 and Section 10 for how this is used and retained.
    10. Communications: messages sent to Parent Users, peer-to-peer messages (Business Builder Plan), and content published to the Resources Hub.
    11. Support and feedback communications: if you contact us - for example, via our contact-us form, our feedback widget, or by choosing to share a reason when deleting your account - we collect the content of your submission. Where you use our contact-us form, this also includes your full name and the email address you signed up with. These forms are hosted by Tally, a third-party provider (see Section 5.3), and submissions are additionally retained in an internal Google Sheets business tool for our review and response - see Section 5.3 and Section 10 for further detail, including how long this data is kept.
    12. Subscription and billing: plan type, payment history, and billing details processed by our third-party payment provider. We do not store your full card number.
    13. API and analytics data (Pro and Business Builder Plans): data about API requests that returned your profile, including how often your profile was retrieved, used for platform administration and (Phase 2) practitioner-facing AI visibility analytics.
    14. Multi-factor authentication (MFA) and trusted devices: if you enable MFA on your account, we collect a record of any device you choose to “remember” - device/browser type, and the dates that trust was created, last used, and will expire - so you are not asked to re-verify on that device each time you log in. See Section 10 for how long this record is retained.
    15. Block records: if you block another user, a record of that block (including timestamps) is retained permanently, including if you later unblock that user or delete your account. This record is limited to the user IDs involved, the direction of the block, and the timestamp - no message content or profile information is retained under this permanent-retention exception. It is retained for safety and legal purposes and is available for legal discovery.
    16. Reports you submit or are the subject of: if you submit a report about another user or item of content, we collect the reason category you select, any free-text details and evidence you choose to provide, and a point-in-time copy of the reported content captured at the time of the report. If you are the subject of a report, we hold the same categories of information about you. See Section 10 for how long this is retained.
    17. Proactive content-scan flags: ViaClara uses automated scanning to check messages, Help Wanted Ads and responses, practitioner profiles, and minor Resources Hub article edits for content that may breach our Platform Content Policy. If your content is flagged by this scan, we hold a record of the flag and the matched content pending review; a flag alone does not result in any action against your account.
    18. Admin review of reports: if a report or a scan flag involving you is reviewed by a ViaClara administrator, we keep a record of that review, including the date and the outcome (but not the content of any internal review notes beyond what is already captured above).
    19. Referral program activity: if you participate in our optional Referral Program, your referral code; a summary of each referral you have made (the referred colleague's name, referral status, and the date and type of any reward granted); and, if you yourself joined ViaClara via a colleague's referral, a record of that referral (the referrer's name, the code you used, status, and any reward you received). See Practitioner Terms clause 22 for how the program works, and Section 10 for how long this is retained.
  3. Some of this information is displayed publicly on your ViaClara profile, and some is retained internally only. Specifically:
    1. Your ABN and your professional registration or membership number (where applicable to your profession) are displayed publicly on your practitioner profile, together with the name of the relevant register or association. This allows Parent Users and other members of the public to independently verify your credentials via the relevant public register.
    2. Your insurance information and Working With Children Check attestation (both described below), and any administrative correspondence relating to your registration, are retained internally only and are not displayed on your profile.
  4. Where no independently verifiable register exists for your profession (Nutritionist, Equine-assisted Therapist without an underlying registration), any qualification or training information you choose to disclose is displayed with a clear notice that it has not been independently verified.
  5. Public Display of Credential Information. We display certain credential information publicly to help Parent Users make informed decisions and to allow independent verification of practitioner credentials, consistent with our obligations under AHPRA's Guidelines for Advertising Regulated Health Services and our general commitment to transparency on the platform.
  6. The confidence level associated with a publicly displayed registration or membership number varies by profession, because the underlying registers vary in how they are maintained and verified. Where a register does not independently verify the accuracy of its own listings, or is known to be incomplete, we display an additional notice alongside the credential to reflect this. Current details of which checks apply to which professions are available at www.viaclara.com.au/faq#safety-and-trust.
  7. By registering as a Practitioner User, you consent to the public display of your ABN and professional registration/membership number as described in this Section. If you do not wish for this information to be displayed publicly, you should not register as a Practitioner User on ViaClara.
  8. Information Collected Automatically. We automatically collect certain information when you use ViaClara, including:
    1. Device and browser information: IP address, browser type and version, operating system, and device identifiers.
    2. Usage information: aggregated, anonymised information about how you use the website and app - such as pages viewed, features used, time spent on pages, links clicked, referral URLs, and search queries performed - collected via Google Analytics (GA4). This data is cookie-based and session-level: it is not linked to your ViaClara account or user ID, and none of it is collected until you consent to analytics cookies. See Section 9 and our Cookie Policy for the cookies involved and consent mechanics, and Section 10 for how long this data is retained. ViaClara does not currently operate a separate, account-linked internal usage log.
    3. Safety and audit log data: where a blocked user attempts to respond to a Help Wanted Ad, we record the actor's ID, target's ID, ad ID, block direction, IP address, and timestamp in a tamper-evident audit log. No message content, profile content, or other personal information is captured in this log. This log is retained permanently and is never deleted, including after account deletion. It is used for platform safety, dispute resolution, and legal discovery purposes.
    4. Cookies and similar technologies: see Section 9 (Cookies) for details.

3. Sensitive information and health information

  1. Important: ViaClara handles health information. Under the Privacy Act, health information is a category of sensitive information and attracts the highest level of privacy protection. We only collect health information with your express consent and for the specific purposes described in this Policy.
  2. ViaClara handles the following categories of sensitive and health information:
    1. Functional support needs: information about the support needs of a child provided by a Parent User, described by challenge area (such as communication, daily living skills, or sensory processing) rather than clinical diagnosis. ViaClara's platform is designed so that clinical diagnosis data is not collected or stored - Help Wanted Ads and onboarding forms use functional descriptors, not diagnostic fields. Any diagnostic information a user chooses to include in a free-text field is entered at their own risk and is handled as sensitive information.
    2. Diagnostic context incidentally included: any diagnostic or clinical information that may be shared through the messaging feature, our support and feedback forms, or incidentally included in other free-text fields.
    3. Neuroaffirming practice attestation: information provided by Practitioner Users regarding their clinical approach.
  3. We collect sensitive and health information only:
    1. With your express, informed consent obtained at the time of collection;
    2. For the primary purpose of connecting Parent Users with suitable Practitioner Users; and
    3. Where reasonably necessary for the proper functioning of the platform, as described in Section 4 of this Policy.
  4. We do not use health information for advertising, profiling, or AI model training without your separate, express consent.

4. How we use your information

  1. We collect, hold, and use personal information for the following purposes:
  2. Providing the Platform. We use your information to:
    1. Creating and managing your ViaClara account;
    2. Matching Parent Users with Practitioner Users based on support needs, location, and preferences;
    3. Enabling direct messaging between Parent Users and Practitioner Users;
    4. Processing subscription payments and managing billing;
    5. Providing booking functionality (Business Builder Plan - via third-party integration);
    6. Displaying practitioner profiles in search results and AI-assisted discovery tools;
    7. Enabling peer networking between practitioners (Business Builder Plan);
    8. Facilitating the publication of Resources Hub articles (Business Builder Plan); and
    9. Verifying that a new practitioner registration does not correspond to a previously suspended, restricted, or removed Practitioner Account, by cross-checking registration/membership number, ABN, and other identifying information provided at registration (see Practitioner Terms clause 3(i)).
  3. Platform Improvement and Analytics. We use your information to:
    1. Analysing how the platform is used to improve features and user experience;
    2. Monitoring platform performance and security;
    3. Generating aggregated, de-identified analytics and reports (including AI visibility analytics for Practitioner Users on eligible plans, and aggregated Help Wanted Ad demand statistics - see Section 10); and
    4. Conducting internal research to improve platform search and matching, including: analysing and testing the weighting of search ranking factors disclosed in clause 9 of the Practitioner Terms (which include availability, profile completeness, filter-match relevance, proximity, and Neuroaffirming Verification Badge status); refining how challenge areas selected by Parent Users are mapped to practitioners' areas of expertise; analysing search and messaging patterns to identify where parents are not finding suitable matches; and running comparative tests of different ranking configurations. Availability, as a ranking factor, is set and updated by the practitioner themselves and is not verified by MAME CREATIVE PTY LTD - see Practitioner Terms cl.3(k) and Parent Terms cl.4(i). This research is conducted using aggregated or de-identified data where reasonably practicable. Subscription tier is not a factor in search ranking order, and this research does not seek to make it one, other than via the languages-spoken field described below. Subscription tier does determine whether certain profile fields - including languages spoken, per Practitioner Terms cl.7(d)(i) - exist on a practitioner's profile, which in turn determines eligibility to appear in an exact-match search filtered on that field, as disclosed in clause 9 of the Practitioner Terms. Where an exact-match search (including one filtered by language) returns no results, ViaClara may surface suggested practitioners who do not meet every applied filter, clearly labelled as suggestions. Any change to ranking factors, or to which profile fields or filters are limited by subscription tier, will be reflected in an update to the Practitioner Terms and this Policy. This research does not extend to using health information for profiling or AI model training - see Section 3.
  4. Communications. We use your information to:
    1. Sending you service-related notifications (e.g. new messages, booking confirmations, subscription renewals);
    2. Responding to your enquiries and support requests; and
    3. Sending you updates about ViaClara features, security notices, or policy changes that affect your use of the platform;
    4. Sending you marketing communications, such as newsletters, platform updates, or content we think may interest you, only where you have given express consent by opting in via the marketing consent checkbox at sign-up. We do not rely on inferred consent under the Spam Act 2003 (Cth) for these communications. Every marketing message includes a functional unsubscribe mechanism, valid for at least 30 days, that does not require you to log in or provide further personal information. You can withdraw your consent at any time via that link or your account settings, and we will action your request promptly. Opting out of marketing communications does not affect your receipt of service-related or legally required notifications, such as new-message or Help Wanted Ad response alerts.
  5. Legal and Compliance. We use your information to:
    1. Complying with our obligations under the Privacy Act, the Notifiable Data Breach Scheme, and other applicable laws;
    2. Enforcing our Terms and Conditions and other platform policies;
    3. Protecting the rights, property, or safety of ViaClara, our users, or the public; and
    4. Reviewing user reports and proactively detected content, and taking action - including referral to AHPRA, the eSafety Commissioner, police, or the OAIC where appropriate.

5. Disclosure of your information

  1. Disclosure to Other Users. ViaClara facilitates connections between Parent Users and Practitioner Users. Accordingly:
    1. Practitioner profile information (as described in Section 2.2 and subject to your plan) is displayed to any visitor to the platform searching or browsing for allied health support, whether or not they are logged in as a Parent User.
    2. Messages you send via the platform are disclosed to the intended recipient only.
    3. Peer-to-peer messages are disclosed to the named practitioner recipient only (Business Builder Plan).
    4. Practitioner users' ABN and professional registration/membership number are displayed on their public profile page, visible to any visitor to the platform (not only logged-in Parent Users), consistent with Section 2.2A.
  2. Disclosure via API to AI Systems. Practitioner Users - Important Consent Notice: By subscribing to a Pro Plan or Business Builder Plan, you consent to your practitioner profile data being made available via ViaClara's API to third-party AI systems and AI-assisted search tools, for the purpose of improving your discoverability to families seeking allied health support. You can withdraw this consent at any time - either by turning AI visibility off in your account settings (which does not affect your plan, tier, or fees), or by downgrading to the Pay As You Go plan - and can turn it back on at any time while subscribed to the Pro Plan or Business Builder Plan.
  3. Practitioner profile data (including name, profession, areas of expertise, and availability) may be disclosed to third-party AI systems via our API. Availability, like all other fields disclosed via the API, is self-reported by the practitioner via their own dashboard and is not verified by MAME CREATIVE PTY LTD (see Practitioner Terms cl.3(k)). The API discloses the practitioner's current availability status as a raw value; it does not carry the staleness indicator or other in-app context shown on ViaClara's own search results and profile pages. A family who reaches a practitioner's ViaClara profile - for example, by following a link from a third-party AI result - will see that practitioner's availability status displayed in full, including any indication that it may be out of date. This occurs by default upon subscription to a Pro Plan or Business Builder Plan (see clause 15(a) of the Practitioner Terms), and practitioners can turn API visibility off at any time in their account settings - independent of their plan tier and at no change to their subscription fee - or by downgrading to the Pay As You Go plan (clause 15(d)). The specific fields exposed are a fixed set determined by ViaClara - not individually selectable by the practitioner - and are designed to exclude sensitive and operational data by default (including email address, phone number, exact location, and messaging data). The API does not require authentication and may be accessed by any third-party AI system, including AI assistants and search tools that are not affiliated with, vetted, or controlled by ViaClara. ViaClara does not control, and is not responsible for, how a third-party AI system uses, presents, summarises, or stores data obtained from the API - including that turning API visibility off stops future disclosure but cannot remove or affect any copy of profile data already retrieved by a third-party AI system beforehand. See clause 15 of the Practitioner Terms for further detail.
  4. Third-Party Service Providers. We engage third-party service providers to operate ViaClara's infrastructure and services. These providers act as our data processors and are contractually required to handle personal information only for the purposes we specify. The country listed reflects each provider's primary data processing location as at the date of this Policy. Providers may process or store data across multiple jurisdictions as part of their global infrastructure - see each provider's own privacy policy or data processing agreement for current detail. Our current service providers include:
    1. Supabase (database hosting) - United States. Database and authentication services.
    2. Stripe (payment processing) - United States (primary). Payment processing. Stripe's own privacy documentation states personal data may be stored and processed in any country where Stripe has operations or engages service providers.
    3. Calendly Inc - United States. Appointment booking (Business Builder Plan).
    4. Brevo (transactional and marketing email) - European Union (primarily Belgium, France, and Germany). Transactional email, and (where you have opted in) marketing email, including list membership management via Brevo's Contacts API. Brevo's privacy policy discloses possible transfers to the United States and India.
    5. Google Analytics (usage analytics) - United States (primary). Usage analytics. GA4 does not allow selection of a specific data storage region; processing occurs on Google's global infrastructure. Cookies are only set, and data only collected, after a visitor consents via the Cookie Preference Centre - see Section 9 and our Cookie Policy for the full cookie inventory and the 14-month analytics data retention period.
    6. Vercel (website hosting / application infrastructure) - United States (primary). Vercel's infrastructure spans AWS, Azure, and GCP across multiple global regions; some data processing always passes through US-based systems regardless of configured region.
    7. Google Maps/Places API (location and mapping services) - United States (primary). Geocoding and location/mapping services supporting suburb- and area-based search and matching. Google's own privacy policy governs how this data is processed on its global infrastructure.
    8. Tally (Tally BV) - feedback and enquiry forms - European Union. Tally's servers hosting user data and form submissions are located within the EU (Tally's own published Cookie Policy identifies the controller as Tally BV, a Belgian company, consistent with the EU location stated here). Embedded on ViaClara, consent-gated behind Functional cookie consent (see Cookie Policy Sections 4B and 5), for: contact-us enquiries, early-access/founding-practitioner waitlist registration forms, and the site-wide feedback widget. Also linked from the account-deletion confirmation screen as an account-deletion feedback prompt - this link opens tally.so in a new browser tab rather than embedding Tally content on ViaClara, so no ViaClara script, iframe, or cookie is involved and it sits outside the Cookie Policy's consent-gating scope, the same treatment given to any other outbound link to a third-party site. Planned, not yet live: Net Promoter Score (NPS) surveys - expected a couple of months post-launch; not a current data flow, and should not be treated as an active collection category until it ships. Tally's own privacy policy governs how data is processed once a visitor reaches tally.so.
    9. Google Sheets (internal business operations tool) - United States (primary) / Google's global infrastructure. This account is a personal (non-Workspace) Google Account, not a Google Workspace account, so no data-residency or region-selection option is available. Used internally to collate the free-text content of account-deletion feedback, contact-us enquiries, and general platform feedback submitted via the Tally forms described above (the “Biz Ops” dashboard), for the founder's review and response. Access is currently limited to a single account, with 2-step verification enabled. This account does not currently carry a Google Workspace Data Processing Addendum - a planned migration to a Workspace account with a DPA is tracked as a pre-launch item. See Section 10 for how long this data is retained.

    Some of these providers are located outside Australia. See Section 6 (Overseas Disclosure) for further information.

  5. Legal Disclosure. We may disclose your personal information to law enforcement, regulatory authorities, or courts where required by law, including under the Privacy Act, the Notifiable Data Breach Scheme, or a valid court order.
  6. Business Transfer. If MAME Creative Pty Ltd undergoes a merger, acquisition, sale of assets, or other change of control, your personal information may be transferred to the acquiring entity as part of that transaction, provided the acquiring entity agrees to handle that information in a manner consistent with this Policy. We will notify you via email and/or prominent notice on the platform before your personal information is transferred and becomes subject to a different privacy policy, and you will retain your existing rights under this Policy, including the right to request deletion, in relation to the transferred information.
  7. If MAME Creative Pty Ltd ceases operations without a successor entity, your personal information will be securely deleted or de-identified in accordance with Section 10, rather than transferred.
  8. We will not sell, rent, or trade your personal information to third parties for marketing purposes.

6. Overseas disclosure

  1. Some of our third-party service providers are located outside Australia, including in the United States and the European Union. When your personal information is transferred overseas, we take reasonable steps to ensure that the overseas recipient handles it in a manner that is consistent with the APPs.
  2. By using ViaClara, you consent to your personal information being transferred to, and stored in, countries outside Australia, including countries that may not have data protection laws equivalent to those in Australia.
  3. In the event that an overseas recipient breaches the APPs, MAME Creative Pty Ltd will remain accountable to you in accordance with APP 8.

7. Children's privacy

  1. Note: ViaClara's service involves the collection of information about children. We take our obligations in this regard very seriously.
  2. ViaClara collects information about children from their parents or legal guardians only. We do not knowingly collect personal information directly from children. Information about children - including any health or support need information - is treated as sensitive information and is subject to the same protections described in Section 3 of this Policy.
  3. By providing information about your child, you confirm that:
    1. You are the parent or legal guardian of the child about whom you are providing information; and
    2. You consent to ViaClara collecting, using, and storing that information for the purposes described in this Policy.
  4. Parents and legal guardians may request the deletion of their child's personal information at any time by contacting us at privacy@viaclara.com.au. See Section 11 (Your Rights) for further information.

8. Messaging and communications data

  1. ViaClara's messaging feature enables direct communication between Parent Users and Practitioner Users. Message content may contain health information about a child.
  2. With respect to message data:
    1. All message content is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256 encryption.
    2. Message content is accessible only to the named participants in the conversation.
    3. Message content is retained for 24 months after the date of the last message in a thread, after which it is permanently and securely deleted. See Section 10 (Data Retention) for full retention periods.
    4. Message content is never used for advertising, profiling, or AI model training without your separate, express consent.
    5. ViaClara uses automated scanning to check message content for matches against a defined set of safety and compliance concerns (see “Proactive content-scan flags” in Section 2, “What information we collect”, above). A ViaClara staff member reviews message content only following an automated match, a user report, a credible safety concern, or where required by applicable law.
  3. Important Messaging Disclaimer: ViaClara's messaging feature is provided for the purpose of initial connection between parents and practitioners. Do not share Medicare numbers, medical records, or other documents containing sensitive identifying information via this messaging service. ViaClara is not responsible for the content of messages exchanged between users. Practitioners must comply with their professional confidentiality obligations at all times.

9. Cookies and tracking technologies

  1. ViaClara uses cookies and similar tracking technologies to provide and improve the platform. A cookie is a small text file stored on your device when you visit a website.
  2. We use the following categories of cookies. This is a summary - for the full cookie inventory, exact retention periods, and how to manage your preferences, see our Cookie Policy.
    1. Strictly necessary cookies - session management; keeping you logged in. Cannot be disabled; required for the platform to function.
    2. Functional cookies - remembering your preferences, such as search filters and location; and powering certain embedded third-party tools, such as our contact and waitlist forms. Disabled if you opt out via the Cookie Preference Centre.
    3. Analytics cookies - understanding how the platform is used; improving features. Disabled if you opt out via the cookie banner.
    4. AI visibility analytics (Phase 2) - tracking how practitioner profiles appear in AI-assisted searches. Practitioner consent obtained separately at subscription.
  3. You can manage cookie preferences via your browser settings or our Cookie Preference Centre (accessible via the cookie banner on your first visit, or via our Cookie Policy). Disabling certain cookies may affect platform functionality.

10. Data retention

  1. We retain personal information only for as long as necessary to provide our services or as required by law. The following retention periods apply:
    1. Account profile data: identity fields de-identified within 30 days of account closure - or, if you're still party to an active conversation at that time, once that conversation's own retention period ends (see the Message content row below). Disposal: de-identification (fields removed or replaced with a placeholder). The underlying anonymised account record is not immediately deleted - see our Data Retention Schedule for further detail.
    2. Multi-factor authentication (MFA) and trusted devices: until the trust period on that device expires - 30 days from when you chose to “remember” it. This is different from most other rows on this page, which run from account closure: a trusted-device record's only purpose is to let you skip re-verification within its 30-day window, so it is deleted automatically once that window passes, whether or not your account remains open. Disposal: secure/hard deletion.
    3. Child profile information (name/alias, age range, support needs, interests): 30 days after account deletion - this applies regardless of any linked Help Wanted Ad or conversation. Disposal: secure deletion.
    4. Child information disclosed via a Help Wanted Ad response (point-in-time snapshot of the above, taken when a practitioner responds): 24 months from the date of the practitioner's response - an independent retention period, not tied to the parent's account status. Disposal: secure deletion (bundled with the response record).
    5. Help Wanted Ad record (the ad itself - title, description, location, and other details you provide when posting; distinct from the response snapshot above): automatically removed from practitioner-facing search 45 days after posting, or 45 days after last renewal (renewal available up to twice). Following removal from practitioner search, retained in a form visible only to the posting Parent User for a further 180 days, so they can review it or use it as the basis for a new ad. At the end of that period, or immediately if the Parent User deletes the ad themselves, the individual record is permanently deleted. Anonymised, aggregated statistics extracted from the ad (with no information capable of identifying the Parent User or their child) may be retained indefinitely. Disposal: secure deletion (individual record); aggregated data is not personal information once de-identified.
    6. Message content: 24 months from date of last message in thread. Disposal: permanent secure deletion (cryptographic erasure).
    7. Support and feedback communications (account-deletion feedback, contact-us enquiries, and general platform feedback submitted via Tally forms - see Section 5.3 - additionally retained in an internal Google Sheets business tool for founder review and response): 24 months from date of submission, then deleted. Treated with the same sensitivity as health/child information given the realistic likelihood that free-text fields incidentally include health-adjacent content about a child, and that the contact-us form additionally captures your full name and sign-up email address directly. Disposal: manual secure deletion - this data is not currently subject to an automated purge mechanism.
    8. Payment and billing records: 7 years from transaction date (ATO requirement). Disposal: secure deletion.
    9. Referral Program records (referral code, and records of referrals you have made or received through the Practitioner Referral Program - see Practitioner Terms clause 22 - including status and any reward granted): Rewarded referrals: 7 years from the date the reward was granted (working assumption that a referral reward is a “transaction” for ATO purposes, not yet lawyer-confirmed). Voided or abandoned referrals: not yet settled - 2 years (matching Content Moderation Records' free-text clock) or 3 years (matching Proactive Content-Scan Matches) are both under consideration; pending lawyer decision. Referrals involving a practitioner removed for cause: retained for the same period as Registration Credential Data for that removal. Disposal: secure deletion, once the applicable period is confirmed. Known gap, not yet resolved: the current account-deletion mechanism cannot delete or de-identify these records for any practitioner with referral history (rewarded or abandoned) - only pending referrals are voided on removal today. This must be fixed before this row's disposal method reflects actual practice.
    10. Practitioner verification data (Neuroaffirming Verification Badge, peer/patient confirmations): permanent - retained indefinitely as a trust signal, and is not affected by deletion of either party's account (see Practitioner Terms clause 12). Disposal: not deleted.
    11. API request logs (practitioner attribution data): 12 months from date of collection. Disposal: secure deletion.
    12. Aggregated AI visibility analytics (Business Builder Plan - Phase 2, not yet available): indefinite once de-identified (no individual re-identification possible). This feature has not yet launched - this row describes the intended policy and will be confirmed against actual implementation before this feature ships. Disposal: not applicable - not personal information once de-identified.
    13. Content moderation records (reports, decisions, account warnings): structured reason code retained indefinitely as a low-detail moderation-history signal. Free-text detail cleared at the earlier of (a) 30–90 days after a practitioner's review response, or (b) 2 years from notification if no review is requested. Disposal: secure deletion (free-text detail only; the structured reason code is not deleted).
    14. User reports - structured fields (reason category, status, timestamps, and whether the report has been referred to an external authority): retained indefinitely. Disposal: not deleted.
    15. User reports - free-text detail, evidence, and content snapshot: 5 years from the date of the report for reports categorised as harassment/abuse or safety/child harm; the same period as Content moderation records above for all other report categories; and permanently, overriding both, once a report has been referred to an external authority. The 5-year and permanent-on-referral figures are working assumptions pending lawyer sign-off - see our Data Retention Schedule for the full reasoning. Disposal: secure deletion of these fields only; the structured fields above are unaffected.
    16. Admin review of reports (a record of every admin review of a report or content-scan flag, including the date and outcome): retained permanently - this record is insert-only and no deletion path currently exists. This differs from an earlier internal design target of “active account + 3 years” for this record, which has not been built - see our Data Retention Schedule for further detail. Disposal: not deleted.
    17. Proactive content-scan matches (automated flags not escalated into a report): 3 years from the date of the match - a provisional figure, not yet formally ratified. A match that is later escalated into a report instead follows the User reports retention above. Disposal: secure deletion.
    18. Practitioner profile review records (60-day review cadence - see Platform Content Policy clause 7.4): practitioner's active account + 3 years from the date of the review. Not currently enforced by an automated purge mechanism - manual deletion is required until one is built. Disposal: manual secure deletion.
    19. Data breach investigation records and NDB notifications: 7 years from breach date. Disposal: secure deletion.
    20. Consent event log (Messaging Consent Notice, API/AI visibility consent, Working With Children Check attestation, and future consent types not separately carved out below): duration of active account + 3 years. Disposal: secure deletion.
    21. Marketing consent record (your opt-in/opt-out decision for ViaClara's marketing mailing list, and the exact wording you were shown): duration of active account + 3 years, matching the Consent Event Log figure above - with one exception: if you unsubscribe, or your account is closed, a minimal suppression record is kept indefinitely so you are not inadvertently re-added to the mailing list by a future data import or resubscription. This suppression record contains no raw email address - it stores only a salted HMAC-SHA256 hash of your (lowercased, trimmed) email address, used solely as a lookup key to check and enforce suppression. It is retained under APP 11.2's exception for records reasonably necessary for our own compliance purposes, and is not used for any other purpose. Disposal: secure deletion (consent record); the hashed suppression record is retained indefinitely, by design, and is not purged.
    22. System logs and security logs (automatically generated by our hosting and database infrastructure providers): retained only for the default period provided by our infrastructure providers, typically ranging from a few hours to several days depending on the specific service and plan. ViaClara does not currently extend this retention period beyond the applicable provider default. Disposal: not independently controlled by ViaClara - deletion follows each provider's own infrastructure practices.
    23. Block records: retained permanently - limited to user IDs, block direction, and timestamps (no message content or profile information). Survives account deletion and is never removed. Retained for safety, dispute resolution, and legal discovery purposes. Disposal: not deleted - permanent retention, field-limited as described.
    24. Audit log records (safety events): retained permanently - limited to actor ID, target ID, ad ID, block direction, IP address, and timestamp (no message content or profile information). Survives account deletion and is never removed. Append-only; cannot be modified after creation. Disposal: not deleted - permanent retention, field-limited as described.
    25. Registration credential data (AHPRA registration number, professional association membership number): split by how your account ends - permanent if your account is removed or suspended for a conduct or safety reason (Practitioner Terms clause 6(e)); 7 years from account closure for a voluntary or good-standing departure. Disposal: secure deletion (7-year group only).
    26. Professional indemnity insurance confirmation: 7 years from account closure, flat, not split by how your account ends - treated as general commercial/compliance data, consistent with the Payment and Billing Records row above, rather than the permanent/7-year split applied to Registration credential data above (this is a warranty/compliance confirmation under Practitioner Terms clause 14, not a child-safety screening credential - see the Data Retention Schedule for the full reasoning). This is a different treatment from the Registration credential data and WWCC attestation data rows, which are permanently retained for clause 6(e) removals by deliberate design - see those rows for the separate, child-safety-driven reasoning that does not apply here. Disposal: secure deletion.
    27. WWCC (Working With Children Check) attestation data - the practitioner-record fields confirming your attestation (distinct from the Consent Event Log entry recording the attestation's acceptance, covered separately above): split by how your account ends - permanent if your account is removed or suspended for a conduct or safety reason (Practitioner Terms clause 6(e)); 7 years from account closure for a voluntary or good-standing departure - mirroring the Registration credential data split above, on the basis that WWCC attestation data has an equally direct nexus to child safety. Disposal: secure deletion (7-year group only).
    28. Terms and Privacy Policy acceptance records (your recorded acceptance of the Platform Terms, and the Parent Terms or Practitioner Terms applicable to you, and this Privacy Policy - captured at account creation and, for practitioners, again at registration): 7 years from account closure, flat, not split by how your account ends - this evidence underpins enforcement of every substantive clause in the relevant Terms document, so it is treated in the same general commercial/compliance bucket as the Professional indemnity insurance confirmation and Payment and Billing Records rows above, rather than the shorter default that otherwise applies to the Consent Event Log. Disposal: secure deletion.
  2. On expiry of the applicable retention period, personal information is securely deleted or de-identified in accordance with APP 11.2. De-identified information may be retained for analytical or product improvement purposes.
  3. Note on backups: where data is deleted from active systems in accordance with the periods above, it is also purged from routine system backups within 60 days.
  4. You may request early deletion of your personal information (subject to our legal retention obligations) by contacting us at privacy@viaclara.com.au. See Section 11 (Your Rights) for further information.

11. Your privacy rights

  1. Under the Privacy Act and APPs, you have the following rights in relation to your personal information held by ViaClara:
  2. Access. You have the right to request access to the personal information we hold about you. We will respond to access requests within 30 days. We may charge a reasonable fee to cover the cost of providing access where permitted by law. We will not charge for simply making the request.
  3. Correction. If you believe that personal information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, you may request that we correct it. We will take reasonable steps to correct the information within 30 days of receiving your request.
  4. Deletion. You may delete your own account at any time via your account settings. This takes effect immediately - your public profile is removed from search and your access to the platform is revoked immediately. Some information is retained after deletion in accordance with the retention periods described in Section 10 and our Data Retention Schedule (for example, financial records required to be retained for 7 years, and safety-related block records retained permanently). If you are unable to delete your account via your account settings, contact us at privacy@viaclara.com.au and we will action your request within 30 days.
  5. What happens to your name and photo: most of your personal information (including your email, phone number, and password) is anonymised or removed immediately on deletion. Your name (and, if you are a Practitioner, your profile photo) may continue to be visible for a limited time to anyone you have an existing, unexpired conversation with (see Section 10 - conversations are retained for up to 24 months from the most recent message), so that person can still identify who they were speaking with. This information is permanently removed or replaced with a placeholder 30 days after your account is deleted, or when the relevant conversation reaches the end of its own retention period, whichever is later. As part of the account-deletion flow, you may also be shown an optional link to share feedback about your decision via a third-party form (see Section 5.3, Tally) - this is entirely optional and opens in a new browser tab. If you use this optional link, the content of your feedback is handled as described in Section 2 (“Support and feedback communications”) and retained as described in Section 10, separately from, and unaffected by, the deletion of your account.
  6. What happens to your underlying account record: beyond the specific cases above, your account record may be retained in a de-identified form - containing no information capable of identifying you - where this is necessary as a technical reference for other records ViaClara is required to retain permanently or for an extended period (for example, a safety-related block record or a verification record). Retaining a de-identified record in this way is not the same as retaining your personal information, and is done in accordance with APP 11.2 of the Privacy Act.
  7. Account Inactivity. If you are a Parent User, or a Practitioner User on the Pay As You Go plan, and you have not logged in to ViaClara for 12 months, your account will be treated as inactive. We will send you two email notices - approximately 30 days and 7 days beforehand - inviting you to log in to keep your account active. If you do not log in before that time, your account will be deleted and your information handled in the same way as described above under Deletion. Logging in at any point before your account is treated as inactive cancels this process. This inactivity policy does not apply to Practitioner Users on the Pro Plan or Business Builder Plan - your account and public profile remain active for as long as your subscription remains current, regardless of how often you log in to the platform.
  8. Withdrawal of Consent. Where we rely on your consent to process your personal information (including health information, marketing communications, or API visibility consent), you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. Some withdrawals may affect the features available to you on ViaClara.
  9. Data Portability (Export). ViaClara provides a Data Export function in your account settings that allows you to download a copy of your data in a machine-readable format.
  10. If you are a Practitioner User, this includes: your account information; your registration and credential information (ABN, registration/membership number), attestation records (Working With Children Check, professional indemnity insurance, NDIS provider status), and the underlying consent records for these and other acceptances - including your initial Platform Terms and Privacy Policy acceptance recorded at signup, before your practitioner profile existed, together with your acceptance of the Practitioner Terms recorded at registration (each including timestamp, IP address, and browser/device information); your verification history; your subscription, billing, and credit-adjustment history; your submitted Resources Hub articles; your notifications; a count-only summary of favourites and endorsements you have received; and your referral program activity - your referral code, a summary of each referral you have made (the referred colleague's name, referral status, and the date and type of any reward granted), and, if you yourself joined via a colleague's referral, a record of that referral (referrer's name, the code you used, status, and any reward you received).
  11. If you are a Parent User, this includes: your account information; your child profile information; your saved searches; your Help Wanted Ads - including which child profile each ad relates to - and the responses you have received to them, including the point-in-time snapshot of your child's and ad's details that was disclosed to the responding practitioner at the time of their response; your conversations; your notifications; the verifications you have given to practitioners; and your consent records - your acceptance of the Platform Terms, Parent Terms, and this Policy, and your response to the Messaging Consent Notice - together with your account-linked cookie consent history.
  12. Both Parent and Practitioner Users - your export also includes your block history and, if you have enabled multi-factor authentication, a record of devices you have chosen to trust. For each user you have blocked, this shows the date you blocked them, and your current status: active, or - if you have since unblocked them - the date you did so. This reflects your current status only; it does not reconstruct every occasion on which you may have blocked and unblocked the same user over time. Consistent with Section 8 and clause 7(f) of the Parent Terms / clause 13(c) of the Practitioner Terms, your export reflects only blocks you have made. It does not, and will never, disclose whether another user has blocked you. Your trusted-device record shows device/browser type and the dates trust was created, last used, and will expire - it never includes the underlying device token itself.
  13. Two categories of internally-held information are not included in this self-service export: administrative notes recorded when the supporting evidence for a practitioner attestation is reviewed, and internal payment-processor reference identifiers. These remain available on request - see Section 11.1 (Access). Support and feedback communications submitted via our Tally-hosted forms (Section 5.3) are similarly not currently included in this self-service export, and are available on request via the same mechanism.
  14. Complaints. If you believe we have mishandled your personal information, please contact us in the first instance at privacy@viaclara.com.au. We will investigate and respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
    1. Website: www.oaic.gov.au
    2. Phone: 1300 363 992
    3. Post: GPO Box 5218, Sydney NSW 2001

12. Security

  1. MAME Creative Pty Ltd takes reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure in accordance with APP 11. Our security measures include:
    1. Encryption of all personal information in transit using TLS 1.2 or higher;
    2. Encryption of message content at rest using AES-256 encryption at the application level (see Section 8); other personal information is protected at rest by encryption provided as a default feature of our hosting and database infrastructure providers;
    3. Multi-factor authentication (MFA) for all administrative access to ViaClara systems;
    4. Role-based access controls limiting employee access to personal information on a strict need-to-know basis;
    5. Regular security assessments and, where appropriate, independent penetration testing;
    6. Secure deletion protocols in accordance with our Data Retention Schedule; and
    7. Vendor security assessments for all third-party service providers who process personal information on our behalf.
  2. While we implement these measures, no internet transmission or electronic storage system is completely secure. We cannot guarantee the absolute security of information transmitted to us. If you believe there has been a security incident involving your personal information, please contact us immediately at privacy@viaclara.com.au.

13. Data breach notification

  1. MAME Creative Pty Ltd is subject to the Notifiable Data Breach (NDB) Scheme under Part IIIC of the Privacy Act. If a data breach occurs that is likely to result in serious harm to one or more individuals, and we are unable to prevent that harm through remedial action, we will:
    1. Notify affected individuals as soon as practicable, and in any event within 30 days of confirming the eligible breach;
    2. Simultaneously notify the Office of the Australian Information Commissioner (OAIC);
    3. Provide affected individuals with a description of the breach, the type of information involved, and the steps we recommend they take; and
    4. Publish a notification on www.viaclara.com.au for a minimum of 12 months.
  2. Our full data breach response procedures are set out in our Data Breach Policy, which is available on request.
  1. ViaClara may contain links to third-party websites and services (including Calendly for appointment booking, and social media platforms linked from practitioner profiles). This Policy does not apply to those third-party platforms. We encourage you to review the privacy policies of any third-party platforms you use. ViaClara is not responsible for the privacy practices of third-party platforms.

15. AI and automated decision-making

  1. ViaClara uses AI-assisted features to improve the discoverability of practitioners. Specifically:
    1. Practitioner profile data (for users on Pro and Business Builder Plans) is made available via an API to third-party AI systems, enabling practitioners to appear in AI-assisted searches conducted by families. The API exposes a fixed set of fields determined by ViaClara - sensitive information such as email, phone number, and exact location is excluded by design. This API does not require authentication and may be accessed by any third-party AI system, including systems not affiliated with, vetted, or controlled by ViaClara. ViaClara does not control how a third-party AI system uses, presents, or stores data obtained from the API.
    2. API request logs are used for platform administration and security, including an admin dashboard that shows aggregate AI agent traffic (total requests, most searched professions, most frequently surfaced practitioners). ViaClara does not currently generate individual search-pattern profiles from this data as a matter of practice. Access to the underlying logs and the aggregate AI-agent-traffic dashboard is restricted to the platform's most senior administrative tier; a lower-privilege support-admin tier used for routine platform administration is automatically excluded from this dataset. Any access additionally requires a valid multi-factor authentication check, verified fresh at the time of access rather than relied upon from an earlier login. Every view of this data is itself logged (who accessed it and when), for accountability and audit purposes. See our Data Retention Schedule for how long both the underlying request-log data and this access log are retained.
    3. AI visibility analytics (Business Builder Plan - Phase 2) will provide individual practitioners with data about how often their profiles were retrieved or appeared in AI-assisted search results.
  2. These features do not make automated decisions that have a legal or similarly significant effect on individuals. Matching between Parent Users and Practitioner Users is not fully automated - it surfaces results for human review and decision-making. ViaClara does not use automated profiling to determine access to the platform or subscription pricing.
  3. We are transparent with our cyber insurers and business partners about the AI features we use, in line with emerging best practices for AI-enabled platforms.

16. Contact us

  1. For all privacy-related enquiries, access requests, correction requests, or complaints, please contact our Privacy Officer:
    1. Organisation: MAME Creative Pty Ltd (trading as ViaClara)
    2. Email: privacy@viaclara.com.au
    3. Postal address: PO Box 85, Berowra Heights NSW 2082
    4. Response time: we will acknowledge your enquiry within 5 business days and respond in full within 30 days.

Questions about this policy?

We're happy to clarify anything. Get in touch and we'll get back to you.

Contact us