ADHD Simple Patient Privacy Notice

This Privacy Notice explains how ADHD Simple collects, uses, stores, protects and shares your personal information when you use our services. We are committed to protecting your privacy and handling your information in accordance with the Privacy Act 2020, the Health Information Privacy Code 2020, and other applicable laws and professional obligations.

ADHD Simple Patient Privacy Notice

This Privacy Notice explains how ADHD Simple collects, uses, stores, protects and shares your personal information when you use our services. We are committed to protecting your privacy and handling your information in accordance with the Privacy Act 2020, the Health Information Privacy Code 2020, and other applicable laws and professional obligations.

Contact Details

If you have any questions about this Privacy Notice or how we handle your personal information, please contact us:

Email: [email protected]

Contact Details

If you have any questions about this Privacy Notice or how we handle your personal information, please contact us:

Email: [email protected]

What information we collect

We collect personal information only where it is reasonably necessary to provide healthcare services, operate our business, comply with legal obligations, protect health and safety, or improve our services.
Information we may collect includes:
  • Name, preferred name and previous names where relevant
  • Date of birth
  • Gender, pronouns and sex assigned at birth where clinically relevant
  • Residential and postal address
  • Email address
  • Telephone numbers
  • Emergency contact and next-of-kin details
  • Family members, carers, whānau and support people that you nominate
  • National Health Index (NHI) number and other healthcare identifiers
  • Medical history
  • Mental health history
  • ADHD assessments
  • Screening questionnaires
  • Diagnoses
  • Medications
  • Allergies
  • Blood pressure, pulse and other clinical observations
  • Blood test, ECG, laboratory and imaging results, where relevant or provided to us
  • Referral letters
  • Hospital discharge summaries
  • Specialist reports
  • Clinical notes
  • Treatment plans
  • Prescriptions
  • Appointment history
  • Insurance information
  • Billing and payment information
  • Communications with us, including telephone calls, SMS, iMessage, WhatsApp, email and in-app messages
  • Message and email metadata, including delivery, read, bounce and status information
  • Audio recordings of telephone calls
  • Audio and video recordings of consultations where applicable
  • Recordings and transcripts of online meetings and video consultations where applicable
  • Website and application usage information
  • Device information, IP addresses and push notification device tokens
  • Support and messaging metadata, including device and messaging identifiers used to route and deliver your messages
  • Cookie identifiers, advertising and click identifiers, and campaign, referral and UTM data
  • Security and audit logs
  • Consent records
  • Complaint records
  • Information required for legal, regulatory, safeguarding or fraud prevention purposes
Some information we collect is considered sensitive information, including health information. We only collect sensitive information where it is necessary, lawful and subject to appropriate safeguards.

What information we collect

We collect personal information only where it is reasonably necessary to provide healthcare services, operate our business, comply with legal obligations, protect health and safety, or improve our services.

Information we may collect includes:

  • Name, preferred name and previous names where relevant

  • Date of birth

  • Gender, pronouns and sex assigned at birth where clinically relevant

  • Residential and postal address

  • Email address

  • Telephone numbers

  • Emergency contact and next-of-kin details

  • Family members, carers, whānau and support people that you nominate

  • National Health Index (NHI) number and other healthcare identifiers

  • Medical history

  • Mental health history

  • ADHD assessments

  • Screening questionnaires

  • Diagnoses

  • Medications

  • Allergies

  • Blood pressure, pulse and other clinical observations

  • Blood test, ECG, laboratory and imaging results, where relevant or provided to us

  • Referral letters

  • Hospital discharge summaries

  • Specialist reports

  • Clinical notes

  • Treatment plans

  • Prescriptions

  • Appointment history

  • Insurance information

  • Billing and payment information

  • Communications with us, including telephone calls, SMS, iMessage, WhatsApp, email and in-app messages

  • Message and email metadata, including delivery, read, bounce and status information

  • Audio recordings of telephone calls

  • Audio and video recordings of consultations where applicable

  • Recordings and transcripts of online meetings and video consultations where applicable

  • Website and application usage information

  • Device information, IP addresses and push notification device tokens

  • Support and messaging metadata, including device and messaging identifiers used to route and deliver your messages

  • Cookie identifiers, advertising and click identifiers, and campaign, referral and UTM data

  • Security and audit logs

  • Consent records

  • Complaint records

  • Information required for legal, regulatory, safeguarding or fraud prevention purposes

Some information we collect is considered sensitive information, including health information. We only collect sensitive information where it is necessary, lawful and subject to appropriate safeguards.

How We Use Your Information

We use your information to:

  • Provide healthcare services

  • Assess, diagnose and treat medical conditions

  • Prescribe medications safely

  • Coordinate your care

  • Communicate with healthcare providers involved in your care

  • Arrange appointments

  • Operate our patient portal and digital services

  • Process payments

  • Respond to enquiries and complaints

  • Meet legal, regulatory and professional obligations

  • Protect health and safety

  • Prevent fraud or misuse of our services

  • Carry out quality assurance and clinical audit activities

  • Improve our healthcare services

  • Measure, analyse and improve our websites, digital services and marketing

  • Conduct research where permitted by law

Where required by law we will obtain your consent before collecting, using or disclosing your information. In many situations, however, health information may be collected, used or shared where authorised or permitted under the Privacy Act 2020 and the Health Information Privacy Code 2020 without separate consent.

Where We Get Your Information From

We may collect information directly from you, including when you:

  • Register with ADHD Simple

  • Book appointments

  • Complete questionnaires or forms

  • Attend consultations

  • Use our patient portal

  • Contact us by telephone, email, SMS or other communications

We may also receive information from:

  • Your GP

  • Nurse practitioners

  • Psychiatrists

  • Psychologists

  • Specialists

  • Hospitals

  • Pharmacies

  • Laboratories

  • Radiology providers

  • Previous healthcare providers

  • Referring clinicians

  • Health insurers where applicable

  • ACC or other funding agencies where applicable

  • Government agencies where authorised or required by law

  • Family members, carers, whānau or support people that you have nominated or authorised

  • Parents, guardians or attorneys acting on your behalf

  • Other individuals authorised by you to provide information relevant to your healthcare

As part of providing healthcare we may receive referral letters, previous assessments, medication history, specialist reports, hospital discharge summaries, laboratory results, imaging reports and other information relevant to your treatment.

We take reasonable steps to ensure patients are aware when health information has been collected from sources other than themselves, in accordance with the Health Information Privacy Code 2020.

Telephone, Audio and Video Recordings

Where appropriate, we may communicate with you using telephone, audio and video technology.

Telephone calls may be recorded.

Audio and video consultations may also be recorded where appropriate.

Recordings may be used for purposes including:

  • Supporting the delivery of healthcare

  • Preparing accurate clinical documentation

  • Assisting transcription

  • Improving the accuracy of clinical records

  • Quality assurance

  • Staff education and training where appropriate

  • Investigating complaints or incidents

  • Meeting legal, regulatory or professional obligations

Recordings may be securely processed using approved technology providers to assist with transcription or preparation of clinical documentation.

Unless recordings are required for ongoing clinical care, legal, regulatory or other authorised purposes, they are retained only for a limited period before being securely deleted.

Clinical notes generated from consultations or telephone calls may become part of your permanent medical record.

Artificial Intelligence

We may use artificial intelligence (AI) technologies to assist clinicians with administrative tasks including:

  • Transcribing consultations

  • Preparing draft clinical notes

  • Summarising information

  • Producing clinical documentation

  • Improving operational efficiency

The AI technologies and providers we may use include large language model and generative AI services, such as those provided through Microsoft Azure OpenAI Service and Anthropic, and meeting and consultation transcription services, such as Vexa. Where consultations or meetings are conducted using video conferencing tools, including Microsoft Teams, calls may be recorded and transcribed to assist with preparing clinical documentation.

AI systems assist our clinicians but do not replace professional clinical judgement.

All diagnoses, prescribing decisions, treatment recommendations and clinical documentation are reviewed and approved by appropriately qualified healthcare professionals before becoming part of your clinical record.

Where AI service providers process personal information on our behalf, they do so under contractual arrangements designed to protect your information and only for the purposes of providing services to ADHD Simple.

Technology Providers and Cloud Services

We use secure electronic health record systems, patient management systems, cloud infrastructure and specialist technology providers to deliver our healthcare services.

The categories of technology providers we may use include:

  • Cloud hosting and infrastructure providers, including Microsoft Azure and Supabase

  • Communication and collaboration platforms, including Microsoft Teams and the underlying Microsoft Graph services that support them

  • Telephony and messaging providers, including Twilio, and services used to send and receive SMS and iMessage, including BlueBubbles

  • Email delivery and email verification providers, including Postmark and ZeroBounce

  • Payment processing providers, including Stripe

  • Mapping and address lookup providers, including Google Maps and Google Places

  • Error monitoring and performance providers, including Sentry

These providers may securely store or process information on our behalf and are required to maintain appropriate privacy, confidentiality and security safeguards.

Depending on the services being provided, your information may be securely stored or processed within New Zealand or in other countries where appropriate safeguards exist or where otherwise permitted under New Zealand law.

Cookies, Analytics and Marketing

When you use our websites and digital services, we and our service providers may use cookies, tags, pixels, software development kits and similar technologies to operate our services, understand how they are used, measure and improve performance, and deliver and measure marketing.

These technologies may collect information such as your device and browser details, IP address, pages viewed, links and buttons clicked, referring website, session activity, and campaign, referral and UTM parameters, as well as advertising and click identifiers.

The tools and providers we may use include:

  • Product analytics and session recording tools, including PostHog and Microsoft Clarity, which help us understand how our digital services are used and may record session activity such as pages viewed and interactions. We apply measures to reduce the capture of sensitive information in these recordings.

  • Tag management and web analytics tools, including Google Tag Manager and Google Analytics, which we use to manage measurement tags and to record website and conversion events.

  • Advertising and marketing platforms, including Meta and TikTok, which use cookies, pixels and advertising or click identifiers to help us deliver and measure advertising and understand campaign performance.

  • Email and customer messaging platforms, including Klaviyo, which we use to send communications and to understand engagement, such as whether messages are opened or links are clicked.

  • A/B testing and optimisation tools, which we use to test and improve the content, layout and performance of our digital services.

We use cookies and similar technologies that are strictly necessary to operate our services, as well as others that we use only where permitted or where you have provided consent in accordance with applicable law. You can manage non-essential cookies and similar technologies through the controls we provide and through your browser or device settings. Disabling some cookies may affect how our services function.

Where these technologies involve health information or could identify you as a patient, we apply additional care and only use them where lawful and subject to appropriate safeguards.

Who We Share Your Information With

We only share personal information where necessary to provide healthcare, comply with legal obligations or where otherwise authorised by law.

We may share your information with:

  • Your GP

  • Specialists involved in your care

  • Hospitals

  • Laboratories

  • Radiology providers

  • Pharmacies

  • Other healthcare providers involved in your treatment

  • Family members, carers or support people where authorised by you or otherwise permitted by law

  • Health insurers

  • ACC and other funding agencies

  • Government agencies where required by law

  • Professional advisers

  • Payment providers

  • Electronic health record providers

  • Patient portal providers

  • Secure cloud hosting providers

  • Communication, telephony and messaging providers

  • Email delivery and verification providers

  • AI service providers acting on our instructions

  • Analytics, marketing and advertising providers

  • Error monitoring and performance providers

  • IT support providers

  • Cybersecurity providers

All service providers acting on our behalf are required to maintain appropriate privacy, confidentiality and security safeguards.

How We Protect Your Information

We take reasonable technical, organisational and administrative measures to protect your information from unauthorised access, loss, misuse, alteration or disclosure.

These measures include:

  • Encryption

  • Multi-factor authentication

  • Role-based access controls

  • Audit logging

  • Secure cloud infrastructure

  • Regular backups

  • Security monitoring

  • Staff privacy training

  • Confidentiality obligations

  • Regular security reviews

Although no system can be guaranteed to be completely secure, we continually review and improve our security practices.

How Long We Keep Information

We retain personal information only for as long as necessary to provide healthcare services, comply with legal obligations and meet professional record-keeping requirements.

Temporary telephone recordings and consultation recordings are retained only for a limited period unless required for ongoing clinical care, legal, regulatory or other authorised purposes.

When information is no longer required it is securely destroyed or permanently de-identified where appropriate.

Your Privacy Rights

Under the Privacy Act 2020 and the Health Information Privacy Code 2020, you have the right to:

  • Request access to the personal information we hold about you, subject to any lawful exceptions.

  • Request correction of personal information that you believe is inaccurate, incomplete or misleading.

  • Be informed about how your personal information is collected, used and shared.

  • Withdraw your consent where we rely on your consent.

  • Make a complaint if you believe your privacy rights have been breached.

Requests to Correct Information

If you believe information we hold about you is factually inaccurate, incomplete or misleading, you may request that it be corrected.

Where appropriate, we will take reasonable steps to correct factual errors, such as incorrect contact details, medication information, dates, or other factual information.

Clinical records also contain the professional observations, assessments, diagnoses and opinions of healthcare professionals. These records form part of your medical history and are maintained to support safe and effective healthcare.

Where information accurately records a clinician's professional opinion, diagnosis, assessment or contemporaneous clinical observations, we may decide that the record should remain unchanged if it accurately reflects the clinician's assessment at the time it was made.

If you disagree with a clinical opinion or diagnosis, you may request that it be reviewed by the treating clinician. Where appropriate, updated clinical information or subsequent assessments may be added to your record.

If we decide not to make a requested correction, we will explain our decision and, where required by law, take reasonable steps to associate your request for correction or a statement of disagreement with your record.

We generally do not remove clinically relevant information from an accurate medical record where doing so would make the record incomplete, inaccurate or compromise the provision of safe healthcare. This includes information that was accurately recorded during the course of your assessment or treatment.

Access to Your Information

You may request access to the personal information we hold about you, including your health information, subject to any lawful exceptions under the Privacy Act 2020 or other applicable legislation.

In limited circumstances, some information may be withheld where permitted by law, including where disclosure could pose a serious risk to the health or safety of any person, unreasonably disclose another person's personal information, or where another statutory exception applies.

Making a Privacy Request

If you would like to access your information, request a correction, or have questions about how we handle your personal information, please contact us using the details provided in this Privacy Notice.

We aim to respond as soon as reasonably practicable and no later than 20 working days, unless an extension is permitted by law.

Complaints

If you are not satisfied with our response, you may make a complaint to the Office of the Privacy Commissioner.

Last updated

01 July 2026