Clinic policies

Privacy policy

Last updated 27 July 2026

Your privacy matters to us, and so does your trust. This policy explains what personal and health information we collect, why we need it, who we share it with, and how you can access it.

The Cynophobia Clinic is operated by Berrick Psychology Pty Ltd (ABN 27 162 662 035). Our services are provided by Anthony Berrick, a registered psychologist (Ahpra registration PSY0001012753).

The rules we follow

We handle your information in line with:

  • the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles
  • the Health Records and Information Privacy Act 2002 (NSW) and its 15 Health Privacy Principles
  • the Psychology Board of Australia's Code of conduct, which sets our professional obligations on confidentiality, consent and record keeping
  • the Health Practitioner Regulation National Law, which governs our registration and conduct

Health information is treated as sensitive information under the Privacy Act, which means it carries a higher level of protection than ordinary personal information.

What we collect

We only collect what we need to provide safe, effective therapy.

Identifying details

Your name, date of birth, address, phone number and email. For a child, we also collect the names and contact details of parents or guardians, and details of anyone else with parental responsibility.

Health information

Your reasons for seeking help, relevant history, current symptoms, treatment goals, session notes, assessment results, treatment plans, and correspondence with your GP or other practitioners. Where relevant, we also collect information about your experiences with dogs and any incidents that contributed to your fear.

Administrative information

Your Medicare number, referral and mental health treatment plan, private health fund details, NDIS plan details, insurer or claim numbers, appointment history, invoices and payment records. We use a third-party payment processor and do not store your full card number.

Emergency contacts

The name and number of someone we can contact if we have a serious concern for your safety. We'll ask your permission before contacting them, unless there's an immediate risk to life.

Website information

If you use our contact form, we collect what you send us. Our website also collects standard technical information such as your browser type, device and pages visited, which we use to keep the site working and understand what people find useful. You can refuse cookies through your browser settings without losing access to the site.

How we collect it

Usually directly from you — in your Roadmap session, in your sessions, through forms you complete, or by phone and email.

Sometimes we collect information about you from someone else: a referral and treatment plan from your GP, a report from another health practitioner, a request from your insurer or plan manager, or information from a parent about their child. If we receive information about you from a third party and you weren't aware of it, we'll tell you unless doing so would be unreasonable or unsafe.

You can ask to deal with us anonymously or under a pseudonym, but we usually can't provide therapy that way — we can't claim Medicare rebates, and we may not be able to keep you safe if we can't identify you. We'll discuss the options with you.

Why we collect it

  • to assess what's going on and plan therapy with you
  • to provide and document your treatment, as we're professionally required to do
  • to communicate with you about appointments
  • to liaise with your GP or referrer, with your consent
  • to process Medicare, NDIS, insurer or private health claims
  • to manage payments, invoices and refunds
  • to meet our legal, insurance and professional obligations

We do not sell your information, and we don't use your health information for marketing. We won't use your story, image or any detail of your treatment in our advertising. Professional advertising rules prohibit us from publishing client testimonials, so we won't ask you for one.

Who we share it with

Your information stays confidential. We disclose it only in these situations.

With your consent

  • your GP or referring practitioner — we're required to write to them at the start and end of a Medicare-funded course of treatment
  • other practitioners involved in your care, such as a paediatrician, psychiatrist or school counsellor
  • a family member, partner or support person you nominate
  • your NDIS plan manager, insurer or employer's insurer, where they're funding your treatment

To run the practice

Our practice management and telehealth software providers, our payment processor, and Services Australia when we claim a Medicare rebate for you. Each is bound to protect your information, and we only give them what they need.

Anthony also takes part in professional supervision and peer consultation, as required of psychologists. Where a case is discussed, identifying details are removed wherever possible, and everyone involved is bound by the same confidentiality obligations.

Without your consent

There are a small number of situations where the law or our professional duty requires us to disclose information even if you'd prefer we didn't:

  • where there's a serious and imminent risk to your life or safety, or to someone else's
  • where we're required to report a child at risk of significant harm
  • where a court subpoenas your records, or a law compels disclosure
  • where disclosure is needed to respond to a complaint, claim or regulatory investigation involving us

If this happens, we'll tell you wherever it's safe and practical to do so, and we'll disclose only what's necessary. We'll always talk through these limits with you at the start, so nothing comes as a surprise.

Children and young people

When we work with a child, we usually need a parent or guardian's consent, and parents are closely involved in the therapy. We'll agree with you at the outset what will be shared and what stays between us and your child.

Young people who are mature enough to make their own decisions about treatment can consent for themselves, and can ask us to keep some things private from their parents. We'll be honest with everyone about how we're handling this, and we'll always act on a serious safety concern.

How we keep it safe

Records are held electronically in password-protected, encrypted practice management software, with access limited to those who need it. Any paper records are kept in locked storage. Devices are encrypted and password-protected.

Telehealth sessions use transport encryption (TLS/HTTPS). We don't record sessions unless you've given written consent. Email and SMS are convenient but not fully secure, so we keep clinical detail in them to a minimum — tell us if you'd rather we didn't email you at all.

Our systems are hosted in Australia wherever possible. Some software providers may store or back up data overseas; where that happens we take reasonable steps to ensure your information is protected to Australian standards.

How long we keep it

We're legally required to keep health records for a minimum period, even after you finish therapy:

  • Adults — at least 7 years from your last appointment
  • Children — until they turn 25

After that, records are securely destroyed or de-identified. This means we can't delete your clinical record on request during the retention period, though you can ask us to correct it.

Seeing and correcting your record

You have a right to access the information we hold about you. Just ask — in writing is best. We'll respond within 30 days, and we may ask you to verify your identity.

Rather than handing over raw session notes, we'll usually offer to go through your record with you, or provide a written summary, because notes are written in professional shorthand and can be easy to misread.

We can only refuse access in limited circumstances — for example where it would pose a serious threat to someone's life or health, or would unreasonably affect another person's privacy. If we refuse, we'll explain why in writing and tell you how to complain.

If something in your record is wrong or out of date, tell us and we'll correct it. Where we disagree about a clinical opinion, we'll add your comments to the record rather than remove ours. There's no charge to access your record; we may charge a reasonable fee for a lengthy report or extensive copying, and we'll tell you the cost first.

If something goes wrong

If your information is lost or accessed without authorisation and it's likely to cause you serious harm, we'll notify you and the Office of the Australian Information Commissioner as soon as practicable, as required by the Notifiable Data Breaches scheme. We'll tell you what happened, what it means for you, and what to do next.

Complaints

If you're unhappy with how we've handled your information, please tell us first — email info@thecynophobiaclinic.com.au or call (02) 9191 1523. We'll acknowledge your complaint within 5 business days and aim to resolve it within 30 days. Raising a concern won't affect your care.

If you're not satisfied with our response, you can take it further:

  • Office of the Australian Information Commissioner — privacy complaints under the Privacy Act. 1300 363 992, oaic.gov.au
  • NSW Information and Privacy Commission — health information privacy in NSW. 1800 472 679, ipc.nsw.gov.au
  • Ahpra — concerns about a practitioner's conduct. 1300 419 495, ahpra.gov.au
  • NSW Health Care Complaints Commission — complaints about health services in NSW. 1800 043 159, hccc.nsw.gov.au

Changes to this policy

We review this policy regularly and will publish any updates here with a new date at the top. If we make a significant change to how we handle your information, we'll tell you directly.

Contact us

Please contact us if you have questions about this policy.