How We Use Your Information
We use your information to:
Provide healthcare services
Assess, diagnose and treat medical conditions
Prescribe medications safely
Coordinate your care
Communicate with healthcare providers involved in your care
Arrange appointments
Operate our patient portal and digital services
Process payments
Respond to enquiries and complaints
Meet legal, regulatory and professional obligations
Protect health and safety
Prevent fraud or misuse of our services
Carry out quality assurance and clinical audit activities
Improve our healthcare services
Measure, analyse and improve our websites, digital services and marketing
Conduct research where permitted by law
Where required by law we will obtain your consent before collecting, using or disclosing your information. In many situations, however, health information may be collected, used or shared where authorised or permitted under the Privacy Act 2020 and the Health Information Privacy Code 2020 without separate consent.
Where We Get Your Information From
We may collect information directly from you, including when you:
Register with ADHD Simple
Book appointments
Complete questionnaires or forms
Attend consultations
Use our patient portal
Contact us by telephone, email, SMS or other communications
We may also receive information from:
Your GP
Nurse practitioners
Psychiatrists
Psychologists
Specialists
Hospitals
Pharmacies
Laboratories
Radiology providers
Previous healthcare providers
Referring clinicians
Health insurers where applicable
ACC or other funding agencies where applicable
Government agencies where authorised or required by law
Family members, carers, whānau or support people that you have nominated or authorised
Parents, guardians or attorneys acting on your behalf
Other individuals authorised by you to provide information relevant to your healthcare
As part of providing healthcare we may receive referral letters, previous assessments, medication history, specialist reports, hospital discharge summaries, laboratory results, imaging reports and other information relevant to your treatment.
We take reasonable steps to ensure patients are aware when health information has been collected from sources other than themselves, in accordance with the Health Information Privacy Code 2020.
Telephone, Audio and Video Recordings
Where appropriate, we may communicate with you using telephone, audio and video technology.
Telephone calls may be recorded.
Audio and video consultations may also be recorded where appropriate.
Recordings may be used for purposes including:
Supporting the delivery of healthcare
Preparing accurate clinical documentation
Assisting transcription
Improving the accuracy of clinical records
Quality assurance
Staff education and training where appropriate
Investigating complaints or incidents
Meeting legal, regulatory or professional obligations
Recordings may be securely processed using approved technology providers to assist with transcription or preparation of clinical documentation.
Unless recordings are required for ongoing clinical care, legal, regulatory or other authorised purposes, they are retained only for a limited period before being securely deleted.
Clinical notes generated from consultations or telephone calls may become part of your permanent medical record.
Artificial Intelligence
We may use artificial intelligence (AI) technologies to assist clinicians with administrative tasks including:
Transcribing consultations
Preparing draft clinical notes
Summarising information
Producing clinical documentation
Improving operational efficiency
The AI technologies and providers we may use include large language model and generative AI services, such as those provided through Microsoft Azure OpenAI Service and Anthropic, and meeting and consultation transcription services, such as Vexa. Where consultations or meetings are conducted using video conferencing tools, including Microsoft Teams, calls may be recorded and transcribed to assist with preparing clinical documentation.
AI systems assist our clinicians but do not replace professional clinical judgement.
All diagnoses, prescribing decisions, treatment recommendations and clinical documentation are reviewed and approved by appropriately qualified healthcare professionals before becoming part of your clinical record.
Where AI service providers process personal information on our behalf, they do so under contractual arrangements designed to protect your information and only for the purposes of providing services to ADHD Simple.
Technology Providers and Cloud Services
We use secure electronic health record systems, patient management systems, cloud infrastructure and specialist technology providers to deliver our healthcare services.
The categories of technology providers we may use include:
Cloud hosting and infrastructure providers, including Microsoft Azure and Supabase
Communication and collaboration platforms, including Microsoft Teams and the underlying Microsoft Graph services that support them
Telephony and messaging providers, including Twilio, and services used to send and receive SMS and iMessage, including BlueBubbles
Email delivery and email verification providers, including Postmark and ZeroBounce
Payment processing providers, including Stripe
Mapping and address lookup providers, including Google Maps and Google Places
Error monitoring and performance providers, including Sentry
These providers may securely store or process information on our behalf and are required to maintain appropriate privacy, confidentiality and security safeguards.
Depending on the services being provided, your information may be securely stored or processed within New Zealand or in other countries where appropriate safeguards exist or where otherwise permitted under New Zealand law.
Cookies, Analytics and Marketing
When you use our websites and digital services, we and our service providers may use cookies, tags, pixels, software development kits and similar technologies to operate our services, understand how they are used, measure and improve performance, and deliver and measure marketing.
These technologies may collect information such as your device and browser details, IP address, pages viewed, links and buttons clicked, referring website, session activity, and campaign, referral and UTM parameters, as well as advertising and click identifiers.
The tools and providers we may use include:
Product analytics and session recording tools, including PostHog and Microsoft Clarity, which help us understand how our digital services are used and may record session activity such as pages viewed and interactions. We apply measures to reduce the capture of sensitive information in these recordings.
Tag management and web analytics tools, including Google Tag Manager and Google Analytics, which we use to manage measurement tags and to record website and conversion events.
Advertising and marketing platforms, including Meta and TikTok, which use cookies, pixels and advertising or click identifiers to help us deliver and measure advertising and understand campaign performance.
Email and customer messaging platforms, including Klaviyo, which we use to send communications and to understand engagement, such as whether messages are opened or links are clicked.
A/B testing and optimisation tools, which we use to test and improve the content, layout and performance of our digital services.
We use cookies and similar technologies that are strictly necessary to operate our services, as well as others that we use only where permitted or where you have provided consent in accordance with applicable law. You can manage non-essential cookies and similar technologies through the controls we provide and through your browser or device settings. Disabling some cookies may affect how our services function.
Where these technologies involve health information or could identify you as a patient, we apply additional care and only use them where lawful and subject to appropriate safeguards.
Who We Share Your Information With
We only share personal information where necessary to provide healthcare, comply with legal obligations or where otherwise authorised by law.
We may share your information with:
Your GP
Specialists involved in your care
Hospitals
Laboratories
Radiology providers
Pharmacies
Other healthcare providers involved in your treatment
Family members, carers or support people where authorised by you or otherwise permitted by law
Health insurers
ACC and other funding agencies
Government agencies where required by law
Professional advisers
Payment providers
Electronic health record providers
Patient portal providers
Secure cloud hosting providers
Communication, telephony and messaging providers
Email delivery and verification providers
AI service providers acting on our instructions
Analytics, marketing and advertising providers
Error monitoring and performance providers
IT support providers
Cybersecurity providers
All service providers acting on our behalf are required to maintain appropriate privacy, confidentiality and security safeguards.
How We Protect Your Information
We take reasonable technical, organisational and administrative measures to protect your information from unauthorised access, loss, misuse, alteration or disclosure.
These measures include:
Encryption
Multi-factor authentication
Role-based access controls
Audit logging
Secure cloud infrastructure
Regular backups
Security monitoring
Staff privacy training
Confidentiality obligations
Regular security reviews
Although no system can be guaranteed to be completely secure, we continually review and improve our security practices.
How Long We Keep Information
We retain personal information only for as long as necessary to provide healthcare services, comply with legal obligations and meet professional record-keeping requirements.
Temporary telephone recordings and consultation recordings are retained only for a limited period unless required for ongoing clinical care, legal, regulatory or other authorised purposes.
When information is no longer required it is securely destroyed or permanently de-identified where appropriate.
Your Privacy Rights
Under the Privacy Act 2020 and the Health Information Privacy Code 2020, you have the right to:
Request access to the personal information we hold about you, subject to any lawful exceptions.
Request correction of personal information that you believe is inaccurate, incomplete or misleading.
Be informed about how your personal information is collected, used and shared.
Withdraw your consent where we rely on your consent.
Make a complaint if you believe your privacy rights have been breached.
Requests to Correct Information
If you believe information we hold about you is factually inaccurate, incomplete or misleading, you may request that it be corrected.
Where appropriate, we will take reasonable steps to correct factual errors, such as incorrect contact details, medication information, dates, or other factual information.
Clinical records also contain the professional observations, assessments, diagnoses and opinions of healthcare professionals. These records form part of your medical history and are maintained to support safe and effective healthcare.
Where information accurately records a clinician's professional opinion, diagnosis, assessment or contemporaneous clinical observations, we may decide that the record should remain unchanged if it accurately reflects the clinician's assessment at the time it was made.
If you disagree with a clinical opinion or diagnosis, you may request that it be reviewed by the treating clinician. Where appropriate, updated clinical information or subsequent assessments may be added to your record.
If we decide not to make a requested correction, we will explain our decision and, where required by law, take reasonable steps to associate your request for correction or a statement of disagreement with your record.
We generally do not remove clinically relevant information from an accurate medical record where doing so would make the record incomplete, inaccurate or compromise the provision of safe healthcare. This includes information that was accurately recorded during the course of your assessment or treatment.
Access to Your Information
You may request access to the personal information we hold about you, including your health information, subject to any lawful exceptions under the Privacy Act 2020 or other applicable legislation.
In limited circumstances, some information may be withheld where permitted by law, including where disclosure could pose a serious risk to the health or safety of any person, unreasonably disclose another person's personal information, or where another statutory exception applies.
Making a Privacy Request
If you would like to access your information, request a correction, or have questions about how we handle your personal information, please contact us using the details provided in this Privacy Notice.
We aim to respond as soon as reasonably practicable and no later than 20 working days, unless an extension is permitted by law.
Complaints
If you are not satisfied with our response, you may make a complaint to the Office of the Privacy Commissioner.
Last updated
01 July 2026