Privacy Policy
Last updated: 28 August 2026
Reflect Renew Counselling ("Reflect Renew", "we", "us" or "our") respects your privacy and is committed to protecting your personal and health information.
This Privacy Policy explains how we collect, hold, use and disclose personal information when you:
- visit our website
- contact us or make an enquiry
- book an appointment
- participate in counselling sessions (including telehealth)
- otherwise interact with our services
Reflect Renew Counselling is operated by Deborah Haywood (ABN 51 513 591 548), trading as Reflect Renew Counselling.
Although Reflect Renew operates online and accepts clients from across Australia, the practice is based in Victoria and handles health information in accordance with:
- the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs)
- the Health Records Act 2001 (Victoria) and the Health Privacy Principles (HPPs)
Where clients are located in other Australian states or territories, additional state or territory health privacy legislation may also apply. Reflect Renew handles all client information in accordance with the highest applicable standard.
Contact Details
Privacy enquiries can be directed to:
Privacy Officer
Reflect Renew Counselling
Email: privacy@reflectrenew.com.au
Phone: (03) 8007 3516
Location: Sunbury, Victoria, Australia
What Personal Information We Collect
We may collect personal information such as:
- your name and preferred name
- date of birth
- contact details (email, phone number, address)
- emergency contact details
- where the client is under 18, the name, relationship and contact details of the parent or guardian who consents to counselling on their behalf, and details of any court or intervention orders they tell us about
- appointment information
- billing and payment information
- records of communications with you
Because Reflect Renew provides counselling services, we may also collect sensitive information and health information, including:
- information about your wellbeing and mental health
- presenting concerns or issues discussed in counselling
- medical or mental health history where relevant
- family or relationship context
- counselling goals
- session notes and clinical observations
- referrals, reports or relevant documents
We only collect information that is reasonably necessary to provide counselling services and operate the practice safely and professionally.
How We Collect Information
We usually collect information directly from you, including when you:
- contact us by phone or email
- complete an enquiry or intake form
- book a free Fit Call directly through the booking form on our website
- book and pay for a counselling session directly on our website
- complete the intake and consent form before your first session
- complete that form as the parent or guardian of a client under 18, giving consent on their behalf
- attend counselling sessions
- participate in telehealth sessions through Google Meet
Where appropriate and with your consent, we may also collect information from:
- referring health professionals
- other healthcare providers involved in your care
- insurers
If you provide information about another person (for example an emergency contact), you should ensure you are authorised to do so.
Informed Consent
Before counselling begins, we will provide you with information about the counselling process, including the nature of services offered, the approaches used, the potential benefits and risks, the limits of confidentiality, and your rights as a client.
You will be asked to provide informed consent before participating in counselling. Consent may be given in writing or verbally. Where verbal consent is provided, this will be documented in your clinical notes.
You may withdraw your consent at any time. Withdrawing consent will not affect the lawfulness of any information handling that occurred before consent was withdrawn.
Why We Collect and Use Personal Information
We collect, hold, use and disclose personal information in order to:
- provide counselling services
- assess whether our services are appropriate for you
- manage appointments and telehealth sessions
- maintain clinical and administrative records
- communicate with you about your care
- process payments and invoices
- liaise with other health professionals involved in your care (where appropriate and with your consent)
- comply with legal, ethical and professional obligations
- manage safety risks or emergencies
We generally only use or disclose information for the purpose for which it was collected, unless you consent otherwise or the law requires or permits it (see Limits of Confidentiality below).
Confidentiality
Confidentiality is a cornerstone of the counselling relationship. Information shared in counselling sessions is treated as confidential and will not be disclosed to third parties without your consent, except where required or permitted by law.
Professional supervision
Like all ACA-registered counsellors, Deborah takes part in regular professional supervision — a structured, confidential consultation that supports safe and ethical practice. Clinical work may be discussed in supervision, ordinarily without identifying you. If a situation ever made it necessary to discuss identifiable information, your consent would be sought first unless the law required or allowed otherwise. Supervisors are themselves bound by confidentiality.
Limits of Confidentiality
There are circumstances in which we may be required or permitted by law to disclose information without your consent. These include where:
- disclosure is required or authorised by law — for example, by a court order or subpoena
- Deborah reasonably believes disclosure is necessary to lessen or prevent a serious threat to a person's life, health or safety, and it is not reasonable or practicable to seek consent first
- child-protection reporting obligations require or allow a report. These laws differ between Australian states and territories, and which ones apply can depend on where you are. Whether or not a report is legally required in a particular case, Deborah takes the safety of children seriously and may report a reasonable concern that a child is being harmed or is at risk of harm, where the law allows her to
- in Victoria, under the Crimes Act 1958 (Vic), an adult who forms a reasonable belief that a sexual offence has been committed against a child under 16 by an adult must disclose it to Victoria Police, unless one of the legal exceptions applies
Only the information reasonably necessary for the purpose is disclosed. Wherever it is safe and lawful to do so, Deborah will talk any disclosure through with you first — and these limits are explained again as part of informed consent before counselling begins.
Online Bookings, Telehealth and Digital Storage
Reflect Renew uses trusted third-party service providers to operate the practice. These include:
- Acuity Scheduling (Squarespace) — our former booking system. It no longer takes new bookings; it continues to administer appointments made before the change, and records held there are retained in line with this policy
- Google Meet for telehealth sessions
- Google Workspace for secure digital storage of files and communications
- Postmark for booking-related email (confirmations, reminders and booking links)
- Stripe for processing payment when you book a session on our website
- Netlify for website hosting and processing of bookings made directly on our website
- Google Analytics 4 for website analytics (see Website Cookies below)
Booking directly on our website
Our website takes bookings for a free Fit Call, a counselling session and a check-in session. Whichever you book, the form asks for the same things: your first name, email address, chosen appointment time and timezone. We do not ask for anything else in order to make a booking.
When the booking is one you pay for — a counselling session or a check-in — the form also asks you to confirm that you have read and agree to the Counselling Service Agreement, and the booking records which version of the agreement you accepted and when. We do not record your network address as part of that acceptance. A free Fit Call asks for no agreement.
After a Fit Call booking is confirmed you are offered the chance to add an optional message. It is genuinely optional, and it is asked for after the booking exists rather than before. If your message includes information about your wellbeing or circumstances, it is handled as health information under this policy.
This information is used only to arrange, confirm, remind you about, and manage that booking. The booking is stored as an appointment in our Google Workspace calendar, and booking emails — confirmation, a reminder, any reschedule or cancellation confirmations, and before a first counselling session an invitation to complete the intake form — are delivered by Postmark. A Fit Call booking is confirmed by clicking a verification link we email to you; a session you pay for is confirmed once your payment completes, so there is no link to click.
If you begin a booking and do not finish it, the tentative booking and the details you entered are deleted automatically — within about 15 minutes for a Fit Call awaiting its verification link, and about 35 minutes for a session awaiting payment. If you cancel a booking, the appointment is removed from our calendar. To protect the booking system from misuse, our website host briefly holds rate-limiting counters based on your network address and a scrambled (hashed) form of your email address; these counters never contain your readable email address and are not used for any other purpose.
Paying for a session on our website
A Fit Call is free and involves no payment. A counselling session and a check-in session are paid for at the time you book them. When you book either of those, payment is handled by Stripe on Stripe's own secure payment page. Your card details are entered there, not here: Reflect Renew never receives, sees or stores your card number. What we keep against your booking is a reference to the payment in Stripe and the amount paid, so that a refund can be issued if one is needed.
For paid bookings, the version of the Counselling Service Agreement you accepted and the time you accepted it are also stored as administrative metadata with the Stripe transaction, so the acceptance record remains available — for example if a question about a refund arises — even if the calendar appointment is later cancelled.
Stripe handles your payment information under its own privacy policy and may store or process it overseas. If a session cannot be confirmed after payment — for example if the time is taken in the moments between paying and confirming — the payment is refunded in full automatically.
The intake and consent form
Before your first counselling session we ask you to complete a short intake form. It is not asked for before a Fit Call or a check-in session. It collects: your name, date of birth, best contact number or email, an emergency contact, and — if you choose to answer it — a few words about what is on your mind. That last answer is health information and is handled as such under this policy. The form also records which consent statements you agreed to, and when.
The website does not store your intake answers. They are sent directly to Deborah by email, through Postmark, and kept with your client record in Google Workspace. Postmark keeps a copy of the emails it delivers for 45 days as part of its own anti-abuse monitoring, after which it is deleted automatically. What remains against the booking in our calendar is only the fact that the form was completed, when, the version of the consent wording you agreed to, and a one-way scrambled (hashed) summary used to recognise a duplicate submission. None of your answers can be read from it.
Telehealth sessions are conducted via Google Meet. Neither Deborah nor the client records a session unless both have expressly agreed in advance. If a recording is ever agreed to, you will be told how it will be stored, who can access it and when it will be deleted, before recording begins.
Because sessions are held online, Deborah confirms your physical location at the start of each session and holds the emergency contact you provide at intake. This is so that, in the unlikely event of an emergency during a session, help can be directed to where you actually are.
These service providers use industry-standard security measures including encryption of data in transit and at rest. Their respective privacy policies are available on their websites. We take reasonable steps to satisfy ourselves that these providers handle information securely and consistently with applicable privacy laws.
Overseas Disclosure
Because Reflect Renew uses cloud-based systems, some information may be stored or processed outside Australia. For example, Acuity Scheduling (Squarespace), Google Workspace / Google Meet, Postmark, Stripe and Netlify may store or process information primarily in the United States, where these providers are based. Some also process data in other countries where they operate infrastructure; each provider's own privacy policy lists them.
Under Australian Privacy Principle 8, Reflect Renew remains accountable for the handling of your personal information by overseas recipients. We take reasonable steps to ensure these providers handle information in accordance with the Australian Privacy Principles. If you have concerns about overseas data handling, please contact us using the details above.
How We Protect Your Information
We take reasonable steps to protect the personal and health information we hold from misuse, loss, unauthorised access or disclosure. These steps include:
- use of secure, encrypted cloud storage systems
- multi-factor authentication on accounts that store or access client information
- password protection and access controls
- encrypted communications where practicable
- device-level security measures including screen locks and up-to-date software
- secure handling of any paper records
- confidentiality obligations
We regularly review our security practices to ensure they remain appropriate for a telehealth counselling practice. Cybersecurity risks are considered as part of our broader risk management approach, and we maintain appropriate insurance coverage in relation to data security.
Website Cookies
The Reflect Renew website uses Google Analytics 4 to understand how visitors use the site. Google Analytics collects information such as pages visited, time spent on the site, approximate geographic location (country/region level), device and browser type, and how you arrived at the site. Reflect Renew does not intentionally send Google your name, contact details or anything about your care. Google may collect cookies, online identifiers, and device and network information, which can in combination identify a browser or device.
Google Analytics uses cookies — small text files stored in your browser — to distinguish visitors and measure usage over time. Data collected is sent to and processed by Google on servers which may be located outside Australia, including in the United States (see Overseas Disclosure above).
We use Google Analytics to see which pages lead people to book, including as a conversion signal for our Google Ads. We do not use it to build advertising audiences, and we do not use it for remarketing — we never show you ads elsewhere because you visited this site.
If your browser sends a Global Privacy Control signal, analytics are switched off entirely for your visit and no information is sent to Google at all. If you would prefer not to be tracked, you can install the Google Analytics Opt-out Browser Add-on or adjust your browser's cookie settings.
Basic cookies may also be set by the website platform or booking system for functionality and security purposes.
Direct Marketing
Reflect Renew does not currently send marketing newsletters or promotional emails. You may receive service-related communications such as appointment confirmations, appointment reminders, telehealth links, and invoices or receipts. These communications are necessary to provide counselling services.
Anonymity
Where lawful and practicable, you may make a general enquiry anonymously. However, it is generally not possible to provide counselling services anonymously, because identity information is necessary for clinical records, appointment management and safety obligations.
How Long We Keep Records
Under Victorian health privacy law, health information and counselling records (including session notes, clinical observations, and all personal and health information held in relation to your care) must generally be retained for:
- at least 7 years after the last client contact, or
- if a client was under 18 when the information was collected, until they turn 25,
whichever is longer. When records are no longer required by law, they will be securely destroyed or permanently de-identified.
Administrative records that are not part of your health record — payment references, booking metadata, records of the agreement you accepted, delivery copies of emails — are kept only as long as tax, accounting, security and contract or dispute-resolution purposes require, which is generally shorter.
Access to Your Information
You may request access to the personal or health information we hold about you. To make a request, please contact us using the details above.
We may ask you to provide identification before releasing records. Requests relating to health information are usually responded to within 45 days, as required under Victorian health privacy law.
You may also request that incorrect or incomplete information be corrected. If we correct information that has previously been disclosed to a third party, we will take reasonable steps to notify that third party of the correction.
Data Breaches
If we become aware of a data breach involving personal information, we will promptly investigate and take appropriate steps to contain the breach and mitigate any potential harm.
Where a breach is likely to result in serious harm and we have been unable to prevent the likely risk of serious harm with remedial action, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.
We maintain appropriate insurance coverage to support our response in the event of a data breach.
Complaints
If you have a privacy concern or complaint, please contact Reflect Renew first so we can try to resolve the issue. We aim to acknowledge your complaint within 7 days and provide a substantive response within 30 days.
If you are not satisfied with our response, you may contact:
Office of the Australian Information Commissioner (OAIC)
www.oaic.gov.auHealth Complaints Commissioner (Victoria)
www.hcc.vic.gov.auFor complaints about the counselling service itself, see Code of conduct and complaints.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. The latest version will always be available on the Reflect Renew website.