LEGAL

Privacy Policy

Last reviewed 14 August 2026

Corporate Care Pty Ltd (ABN 82 153 849 104) provides workplace health services, including corporate flu vaccination programs, across Australia and New Zealand. This policy explains what personal information we collect, why, how we protect it, and the choices you have.

We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including the Notifiable Data Breaches scheme.

The short version

  • We collect only what we need to run our programs and our company — nothing is sold, and nothing is shared for advertising.
  • If you’re vaccinated through one of our programs, we record the minimum information required for the Australian Immunisation Register. Your employer receives participation reporting — who attended — to run and invoice the program; your clinical information is never shared with them.
  • Your health information is held in systems hosted in Australia, with access strictly limited to authorised personnel.
  • You can ask us at any time what we hold about you, ask us to correct it, or make a complaint — contact details are at the end of this page.

What we collect, and why

If you visit our website. You can browse our website without providing personal information. We use a small number of cookies and, subject to your cookie preferences, Google Analytics — our Cookie Policy (opens in new tab) explains exactly what is set, why, and how to change your preferences at any time via the Cookie preferences link in the footer. Where our website links to other sites — such as government resources — their privacy practices are their own.

If you contact us for your organisation. When you request a quote or get in touch, we ask for your name, work email, phone, company and approximate headcount, and anything you choose to tell or send us about your program. Each item has a job: your work email ensures you receive information related to your program and your company; your organisation’s approximate headcount helps us prepare an accurate quote; files you upload (such as previous program reports or tender documents) help us scope the service you’re asking for. We never ask employers for employee lists; occasionally an employer may choose to provide employee contact details on their own initiative, and where that happens we use them only for the program and handle them under this policy.

If you apply to work with us. We collect your application details, CV and professional registration information for one purpose — assessing your application and contacting you about work opportunities.

If you’re vaccinated through one of our programs. We collect the minimum information needed to run your booking and record your vaccination on the Australian Immunisation Register (AIR): your identity and contact details, Medicare details where you provide them (or your home address where you don’t hold a Medicare card), your booking, your digitally recorded consent, and the details of the vaccination itself that the register requires — including, where the register requires it, whether you are pregnant at the time of vaccination. Our AIR reporting page sets out exactly what is reported. Health information is sensitive information under the Privacy Act, and we collect it from you only with your consent.

To run a safe, efficient and evidence-based program, our nurses also ask brief screening questions before vaccinating — for example, about previous reactions to a vaccine. These answers are not routinely recorded. If a vaccination can’t go ahead, or in the rare event of an adverse reaction, we document what is clinically necessary to keep you safe and to meet our obligations as a health provider.

Bookings are made through a secure booking form on our website that connects directly to our program software, which is hosted in Australia. Appointment reminders by email or SMS contain scheduling information only; they never include health information. If you book online, your vaccination certificate is delivered by email as a PDF and contains only the minimum details required for a valid certificate.

If you redeem a flu vaccination voucher at a partner pharmacy, we don’t share your details with the pharmacy — you present your voucher, and the pharmacy collects its own information as your vaccination provider. The pharmacy then confirms the redemption to us — typically your name, the voucher used, the pharmacy and the date — so the program can be invoiced and reported correctly.

What your employer receives — and what they never see

Your employer receives participation reporting — who attended each clinic — so the program can be managed, recorded and invoiced correctly, along with program-level reporting such as coverage across sites.

Your clinical information is never shared with your employer. What the nurse records, and what we report to the Australian Immunisation Register, stays between you, us and the register — employers cannot look up your AIR record. Where an employee needs to show proof of vaccination, their own certificate or myGov immunisation history statement does that job.

How we hold and protect your information

Our records are digital — we do not keep paper records. Personal information is stored in systems hosted in Australia — apart from the limited business-tool storage described under “Overseas access” — and protected by technical and organisational controls. We take reasonable steps to protect it from misuse, interference and loss, and from unauthorised access, modification or disclosure.

Access to your information is strictly limited to authorised personnel, and only to what is necessary for the operation, administration and delivery of our programs and services.

If we suspect a data breach, we will assess and contain it promptly; where it is likely to result in serious harm, we will notify the individuals at risk and the Office of the Australian Information Commissioner (OAIC), as the Notifiable Data Breaches scheme requires.

Who we share information with

We share personal information only with the kinds of recipients needed to run our services, and only what each needs:

  • providers who host and support our systems, and the Australian partner who develops and supports our program software;
  • services that help our website run — Google Analytics for visitor statistics (subject to your cookie preferences — see the Cookie Policy (opens in new tab)) and Cloudflare, the security service our website traffic passes through;
  • your employer — participation and program-level reporting (who attended, coverage across sites), never clinical information;
  • a secure third-party payment gateway, if you pay us by card — your card details go to the gateway and are never stored on our systems;
  • our accountant — who sees business records only: client names, contact details and invoicing, never participant health information;
  • legal or insurance advisers — only if and when a specific matter requires it, and always in line with the Privacy Act;
  • government bodies where the law requires or authorises it — see the next section.

Service providers receive only the personal information they need to deliver their service and are bound by confidentiality and privacy obligations. We use personal information for the purposes described in this policy and for closely related purposes you would reasonably expect. We do not sell personal information, and we do not share it for advertising.

Information we must report by law

Vaccination providers are required by law to report vaccinations administered in Australia to the Australian Immunisation Register — our AIR reporting page explains what this means for you. This is the only record we are required to upload. If you redeem a voucher at a partner pharmacy, that pharmacy is the vaccination provider and reports to the register itself.

Overseas access

Our systems, and the personal information they hold, are hosted in Australia. From time to time, authorised personnel may need to access our systems from outside Australia to run and support our programs. When that happens, the information remains held in our Australian systems, the same strict access controls apply, and we meet any additional privacy requirements that apply to that access.

Like most businesses, we rely on trusted service providers for everyday tools — email, file storage, and the systems that help us run the company — and some of these may store information on servers outside Australia. This affects business and contact information only, never health information, which stays in our Australian-hosted program software. These providers are bound by privacy obligations, and we take reasonable steps to ensure your information is handled consistently with the Australian Privacy Principles wherever it is stored.

Beyond that, we do not routinely disclose personal information overseas, except as part of delivering our New Zealand programs — described below.

New Zealand

We deliver our New Zealand programs through a contracted local partner, bound by privacy obligations. New Zealand’s Privacy Act 2020 applies to information we handle about New Zealand participants, and we meet its requirements — including the Health Information Privacy Code where it applies to health information. New Zealand individuals can also complain to the Office of the Privacy Commissioner (privacy.org.nz (opens in new tab)).

Communications

We don’t run marketing campaigns. What you’ll receive from us is the work itself: booking links, program information and appointment reminders; quotes, proposals and follow-ups on services you’ve asked about; a reminder if you hold a voucher you haven’t yet redeemed; and, where you’ve shown interest in another service we provide, information about that service. Anything beyond essential program communication, you can switch off at any time — use the link in the message or contact us.

After a program, we may invite feedback through an optional survey. Feedback is used to improve our services and is published only with consent. We also use de-identified, aggregated information — numbers, never identities — in our own reporting and published statistics.

How long we keep information

We keep health records for the period health-records legislation requires in the states and territories where we operate — at least seven years from the last time we provided you a service or, if you were under 18 when the information was collected, until you turn 25. Other personal information is kept only as long as needed for the purposes above or as law requires, then destroyed or de-identified.

Access and correction

You can ask what personal information we hold about you, and ask us to correct it, by contacting our Privacy Officer (details below). We’ll verify your identity before releasing information, and respond within a reasonable period — usually within 30 days. There is no fee for making a request; a reasonable administrative fee may apply for providing copies. In the rare case we need to refuse a request, we’ll tell you why in writing and how to complain.

Complaints

If you have a concern about how we’ve handled your personal information, contact our Privacy Officer first — we will acknowledge your complaint, look into it, and give you a written response, usually within 30 days. If you’re not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au (opens in new tab). New Zealand individuals can contact the Office of the Privacy Commissioner at privacy.org.nz (opens in new tab).

Visitors from the UK, Switzerland or the EEA

If you browse our website from these regions, analytics cookies stay off unless you turn them on — see our Cookie Policy (opens in new tab). If you contact us from these regions, your information is handled with the protections described in this policy.

Contact us

Privacy Officer, Corporate Care Pty Ltd
Email: [email protected]
Phone: 1300 79 74 10
Post: Attn: Privacy Officer, Corporate Care, 2-14 Kings Cross Road, Potts Point NSW 2011, Australia

Changes to this policy

We review this policy regularly and update it when our practices or the law change. The date at the top of this page shows when it was last reviewed.

Corporate Care acknowledges the Traditional Custodians of the lands across Australia on which we work and live. We pay our respects to Elders past and present, and recognise their continuing connection to land, waters and community.