Privacy Policy

Med Nest Nursing Pty Ltd (ABN 37 687 748 376)

Effective Date: December 2025
Last Updated: December 2025

Plain English Summary

A. Introduction

Who We Are

Med Nest Nursing Pty Ltd (trading as MedNest, we, us, our) is a healthcare staffing agency based in Victoria, Australia. We connect qualified healthcare professionals—including Food Service Assistants (FSA), Personal Care Assistants/Assistants in Nursing (PCA/AIN), Enrolled Nurses (EN), and Registered Nurses (RN)—with aged care facilities, hospitals, and home care providers across Victoria.

What This Policy Covers

This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you:

This policy applies to all users, applicants, and visitors, whether you are based in Australia or overseas.

Key Definitions

Personal Information: Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not. Examples include your name, email address, phone number, and employment history.

Sensitive Information: A subset of personal information that includes health information, criminal records, membership of professional or trade associations, and other categories defined in the Privacy Act 1988 (Cth). This type of information receives additional protections under Australian law.

Health Information: Information or an opinion about the health or disability of an individual, including information about their healthcare services, which is also personal information or could be used to identify them. In Victoria, health information is regulated by the Health Records Act 2001 (Vic).

B. What Personal Information We Collect

We collect the following categories of personal information, depending on how you interact with MedNest:

1. Identity and Contact Information

Examples: Full name, email address, phone number, residential address (house number, street, suburb, postcode, state), gender, date of birth

Required for: Account creation, application processing, communication

Optional/Required: Required for applications; optional for general website browsing

2. Account Credentials

Examples: Email address, password (stored in encrypted/hashed form only)

Required for: Account login, session management

Optional/Required: Required if you create an account

3. Employment and Professional Information

Examples: Desired roles (FSA, PCA/AIN, EN, RN), years of experience, availability (weekdays, weekends, nights), mode of transport, referral source (how you heard about MedNest), professional qualifications, certifications (name/description only; certificates uploaded separately)

Required for: Assessing suitability, matching you with roles

Optional/Required: Required for job applications

4. Right-to-Work and Compliance Information

Examples: Australian work rights (hours per week eligible to work), visa status (if applicable)

Required for: Legal compliance, client requirements

Optional/Required: Required for job applications

5. Emergency Contact Information

Examples: Emergency contact name, phone number, email address

Required for: Workplace health and safety compliance

Optional/Required: Required for job applications

6. Uploaded Documents

Examples: Resume/CV, cover letter, professional certifications, qualifications, credentials (e.g., AHPRA registration documents, training certificates)

Required for: Application review, credentialing, verification

Optional/Required: Resume required; other documents optional but may be necessary for specific roles

File Types: PDF, DOC, DOCX (validated by content, not extension only)

7. Feedback and Communications

Examples: Messages submitted via our feedback form, customer support inquiries

Required for: Responding to your requests, improving our services

Optional/Required: Optional

8. Technical and Usage Data

Examples: IP address, device type, browser type, pages visited, time spent on pages, referring website, date/time of access

Required for: Website functionality, security monitoring, analytics, troubleshooting

Optional/Required: Automatically collected when you use our website

Collection Method: Server logs, cookies, analytics tools

9. Chatbot Interaction Data

Examples: Questions you ask our AI chatbot, conversation history during your session

Required for: Providing chatbot responses, improving AI accuracy

Optional/Required: Optional (only if you use the chatbot feature)

10. Administrative and Audit Data

Examples: Application status (submitted, under review, interview, pool, withdrawn), login timestamps, login count, session activity logs

Required for: Application management, security monitoring, fraud prevention

Optional/Required: Automatically recorded for authenticated users

C. Sensitive Information and Health Information

Sensitive Information We May Collect

In the course of healthcare recruitment and workforce compliance, we may collect sensitive information as defined by the Privacy Act 1988 (Cth), including:

When and Why We Collect Sensitive Information

We only collect sensitive information where:

Note: The current version of the application form in the codebase collects professional and employment details but does not explicitly capture immunisation records, police checks, or AHPRA numbers in structured fields. If such information is required for specific roles, it may be collected through uploaded documents (e.g., certificates, clearances) or during subsequent onboarding steps. If you provide sensitive information in uploaded documents or free-text fields, this policy applies.

Victorian Health Privacy Principles (HPPs)

If we collect health information about you (e.g., immunisation records, fitness-for-work certificates), we handle it in accordance with the Health Records Act 2001 (Vic) and the Health Privacy Principles (HPPs), in addition to the Australian Privacy Principles. Health information is subject to stricter protections and is only used for purposes directly related to healthcare recruitment, placement, and compliance.

D. How We Collect Information

1. Directly From You

Most personal information is collected directly when you:

2. Automatically

We collect technical and usage data automatically through:

3. From Third Parties (Where Applicable)

We may receive information from:

We only collect information from third parties where you have provided consent, where it is publicly available, or where permitted or required by law.

E. Why We Collect, Use, and Disclose Information (Purposes)

We collect, use, and disclose your personal information for the following purposes, which are reasonably necessary for our functions and activities as a healthcare staffing agency:

1. Recruitment and Application Processing

2. Placement and Workforce Management

3. Legal and Regulatory Compliance

4. Client Relationship Management

5. Communication and Customer Support

6. Website Functionality and Security

7. AI Chatbot Responses

8. Analytics and Service Improvement

Lawful Basis (Australian Context)

We handle personal information in accordance with the Australian Privacy Principles (APPs). We rely on:

For sensitive information, we rely on your explicit consent or a specific exception under the Privacy Act (e.g., legal requirement, threat to life/health/safety).

F. Disclosure of Personal Information

We may disclose your personal information to third parties in the following circumstances:

1. Client Healthcare Facilities

If you apply for roles through MedNest, we may disclose your application details, qualifications, and documents to healthcare facilities (aged care, hospitals, home care providers) that we partner with, for the purpose of recruitment, placement, and workforce management.

2. Service Providers and Technology Partners

We engage third-party service providers to support our platform. These providers may access or process your personal information on our behalf:

We take reasonable steps to ensure these providers handle your information securely and in accordance with Australian privacy laws, including through contractual obligations requiring confidentiality, security measures, and compliance with privacy principles.

3. Background Check and Credentialing Providers

With your consent, we may disclose your information to:

4. Professional Advisers and Auditors

We may disclose information to:

5. Government Agencies and Regulators

We may disclose information where required or authorised by law to:

6. Business Transfers

If MedNest is involved in a merger, acquisition, sale of assets, or restructure, your personal information may be disclosed to prospective buyers or successors, subject to confidentiality obligations and continued privacy protection.

Disclosure Without Consent

We may disclose your personal information without your consent where:

G. Cross-Border Disclosure (Overseas Transfers)

Some of the service providers we use may store or process your personal information outside Australia. This includes:

How We Protect Your Information Overseas

When we disclose information to overseas recipients, we take reasonable steps to ensure:

We select reputable service providers with strong privacy and security practices, and we include contractual protections requiring them to:

Countries where data may be processed: United States, Singapore, Australia, European Union member states (depending on service provider configuration and data routing).

H. Cookies and Analytics

What Are Cookies?

Cookies are small text files placed on your device (computer, smartphone, tablet) when you visit a website. They help websites remember your preferences, enable functionality, and collect usage data.

How We Use Cookies

We use cookies and similar technologies for:

Assumption: The codebase does not explicitly integrate third-party analytics tools (e.g., Google Analytics) in the provided files. If analytics are added in future, this section applies.

Types of Cookies We Use

Managing Cookies

You can control cookies through your browser settings:

Most browsers accept cookies by default. Refer to your browser’s help documentation for instructions on managing cookies. If you block or delete cookies, some features of the MedNest website may not function correctly, such as staying logged in or submitting forms.

I. Security and Storage

How We Protect Your Information

We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Our security measures include:

Storage Locations

Limitations of Security

While we implement robust security measures, no system is completely secure. We cannot guarantee absolute security against all threats. You are responsible for:

J. Data Retention

How Long We Keep Your Information

We retain your personal information only as long as reasonably necessary for the purposes described in this policy, or as required by law.

Retention Periods

Information Type Retention Period
User accounts and login data Retained while your account is active. If you do not log in for 3 years, we may contact you to confirm whether you wish to keep your account active.
Job applications (active status) Retained while your application is active (submitted, under review, interview, or applicant pool status).
Job applications (withdrawn) Retained for 12 months after withdrawal, then archived or deleted unless we have a legal obligation to retain them longer.
Uploaded documents (resumes, certificates) Retained in line with the associated application. If you withdraw your application, documents are retained for 12 months then deleted.
Feedback submissions Retained for 2 years for quality improvement purposes, then anonymised or deleted.
Server logs and security logs Retained for up to 90 days for security monitoring and troubleshooting, then deleted.
Chatbot conversation data Session-based only. Not permanently stored on our servers. Sent to OpenAI for processing (see OpenAI’s data retention policy).
Email communications Retained in line with the purpose (e.g., support requests retained for 2 years).

Legal and Regulatory Retention

We may retain information longer where:

Deletion and Anonymisation

When information is no longer needed:

K. Access, Correction, and Your Choices

Accessing Your Information

You have the right to request access to the personal information we hold about you. To request access:

We will provide access unless:

If we refuse access, we will provide written reasons and inform you of your right to complain.

Correcting Your Information

If you believe any information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, you can request correction by:

We will take reasonable steps to correct your information within 30 days. If we refuse to correct information, we will:

Withdrawing Your Application

You can withdraw your job application at any time by:

Withdrawing your application does not delete your account or information immediately. See Section J (Data Retention) for retention periods.

Deleting Your Account

To request deletion of your account and associated information:

Note: We may retain certain information where required by law (e.g., tax records, employment records) or for legitimate business purposes (e.g., fraud prevention).

Current Implementation Note: The codebase does not include a self-service account deletion feature. All deletion requests are handled manually by our team.

Unsubscribing from Communications

We only send transactional emails (e.g., password reset, application confirmations). If we send promotional or marketing emails in future, you will be able to unsubscribe using the link in the email or by contacting info@mednest.com.au.

Opting Out of the Chatbot

Use of the chatbot is optional. If you prefer not to use it, simply do not click on the chatbot widget. Your questions will not be sent to our AI provider unless you actively submit them.

L. Notifiable Data Breaches (NDB Scheme)

Australia’s Notifiable Data Breaches Scheme

Under the Privacy Act 1988 (Cth), if we experience an "eligible data breach"—that is, unauthorised access to or disclosure of personal information that is likely to result in serious harm to affected individuals—we are required to:

What We Will Do in the Event of a Data Breach

If a data breach occurs, we will:

What You Should Do

If you suspect your account has been compromised:

M. Children’s Privacy

MedNest is not intended for use by children under the age of 18. We do not knowingly collect personal information from children under 18 without appropriate consent and lawful basis.

If we become aware that we have inadvertently collected information from a person under 18 without proper consent, we will take steps to delete that information as soon as practicable. If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us at info@mednest.com.au.

N. Complaints and Contact

How to Make a Privacy Complaint

If you have concerns about how we have handled your personal information, please contact us first:

Please include:

We aim to respond to complaints within 30 days. If we need more time, we will let you know.

Escalation to Regulators

If you are not satisfied with our response, you may lodge a complaint with:

For health information complaints (Victoria):

O. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in:

How We Notify You of Changes

We will post the updated policy on this page with a new "Last Updated" date. If we make significant changes that materially affect how we handle your personal information, we may also:

Your Continued Use

Your continued use of the MedNest website or services after changes are posted constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.

Contact Us

Med Nest Nursing Pty Ltd
ABN: 37 687 748 376
Email: info@mednest.com.au
Postal Address: [Insert postal address]
Phone: [Insert phone number]

Legal References (December 2025 Verification)

This Privacy Policy is based on the following Australian legislation, regulations, and authoritative guidance current as at December 2025:

Verification Notes

Additional Considerations

End of Privacy Policy
Version: 1.0
Effective Date: December 2025
Last Reviewed: December 2025
Next Review Due: December 2026 (or sooner if significant changes occur)