Terms and Conditions

BE CALM WITHIN & THE HIDDEN EDGE PRIVACY POLICY (Last updated July 2026)

This Privacy Policy explains how BCW Services Pty Ltd (ABN: 78 660 398 872), trading as Be Calm Within and The Hidden Edge, collects, holds, uses, and discloses personal and health information, in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the NSW Health Records and Information Privacy Act 2002 (HRIP Act).

This policy should be read alongside our Terms & Conditions, which also addresses confidentiality of session content.


1. What Information We Collect

Depending on how you interact with us, we may collect:

  • Contact details: name, email, phone number, address

  • Booking and payment information: appointment details, payment method, billing history (processed via Stripe)

  • Health and personal information: information you provide in pre-work forms (background history, distressing events, goals), information shared during sessions, and clinical notes made about your sessions

  • Session recordings and AI-generated content: where you consent, audio captured and transcribed by AI note-taking technology (see Section 6)

  • Website and communication data: enquiry form submissions, email correspondence, and general website usage data

We only collect health information that is reasonably necessary for providing therapeutic services to you.


2. How We Collect Information

We collect information directly from you, through pre-work forms, email, phone, our booking system, Zoom, Google Meet, and in-session conversation. We do not collect personal information about you from third parties without your knowledge, except where required for service delivery (e.g. payment processing via Stripe) or permitted by law.


3. Why We Collect and Use It

We use your information to:

  • Provide and tailor therapeutic services to you

  • Prepare for and document sessions

  • Process bookings and payments

  • Communicate with you about appointments and services

  • Meet our legal, clinical record-keeping, and professional obligations

  • Improve our services (using de-identified information only)

We do not use your personal or health information for direct marketing without your separate consent, and we do not sell your information to third parties.


4. Who We Share Information With

We may disclose limited information to trusted third parties who help us deliver our services, including:

  • Payment processing: Stripe (for handling card payments)

  • Video sessions: Zoom and Google Meet (for online appointments)

  • AI note-taking: Fieldy (see Section 6 below), where you have consented to its use

  • Professional obligations: where required by law, court order, or where there is a serious risk of harm to you or another person

We do not otherwise share your identifiable health information with third parties without your written consent.


5. Overseas Disclosure of Information

Some of the third-party services we use store or process data outside Australia. This may include:

  • Stripe: payment data may be processed on servers located overseas

  • Zoom and Google Meet: session data may be processed on servers located overseas

  • Fieldy: where used, audio is processed on servers located in the United States or European Union (you can read Fieldy's own privacy policy at fieldy.ai)

Where your information is disclosed overseas, we take reasonable steps to ensure it is handled securely, but you should be aware that overseas recipients may not be subject to the same privacy protections as apply in Australia. Where relevant (such as AI note-taking), we obtain your specific informed consent before this occurs, see Section 6.


6. Use of AI Note-Taking Technology (Fieldy)

With your explicit consent, we may use Fieldy, a wearable AI note-taking device, during sessions to support accurate clinical record-keeping.

If used:

  • Fieldy records the session, transcribes it, and generates an AI-assisted summary

  • The raw audio recording is deleted once the transcript has been generated

  • Data is processed on secure servers located in the United States or European Union, not Australia

  • All AI-generated notes are reviewed and edited by your practitioner before being added to your clinical file; AI output is a drafting aid only and is never treated as the final clinical record without review

  • You may decline the use of Fieldy at any time, before or during a session, without affecting your care

  • If another person is present in or audible during a session, their voice may also be captured

Consent to the use of Fieldy is collected separately via our client consent form and is not implied by this policy.


7. Use of NeurOptimal Neurofeedback

We use NeurOptimal®, a neurofeedback system, with some clients as part of session work. If this applies to you:

  • NeurOptimal® is a wellness tool and is not TGA-approved as a medical device. It is not used to diagnose any medical or psychological condition, and no diagnostic claims are made from its use.

  • Sensors are placed on your scalp and ears to read your brainwave (EEG) activity during a session. This is non-invasive and involves no stimulation; the system only reads activity and feeds information back to you in real time.

  • Session data generated by NeurOptimal® is processed on the dedicated NeurOptimal® system and is not shared with, or transmitted to, Fieldy or any other AI note-taking tool.

  • We will let you know at the time if your NeurOptimal® session data is stored locally only or is also backed up via NeurOptimal®'s own software/cloud service, and update this policy if that changes.

  • As with all services, you're welcome to ask questions about the process, and can decline or stop a NeurOptimal® session at any time.


8. How We Store and Protect Your Information

We take reasonable steps to protect your personal and health information from misuse, loss, unauthorised access, modification, or disclosure, including:

  • Secure, access-controlled storage of clinical records and pre-work documents

  • Encrypted transmission and storage where offered by third-party service providers

  • Limiting access to your information to your treating practitioner and, where relevant, essential administrative support


9. How Long We Keep Your Information

We retain clinical records for the period required by applicable professional and legal standards (generally a minimum of 7 years from your last appointment, or until age 25 for records relating to a client who was a minor when treated). After this period, records are securely destroyed or de-identified.


10. Access and Correction

You may request access to, or correction of, the personal and health information we hold about you at any time. We will respond within a reasonable timeframe and in accordance with the APPs and the HRIP Act. In limited circumstances (e.g. where access may pose a risk to your wellbeing), we may discuss the request with you before providing records directly.


11. Complaints

If you have a concern about how we have handled your personal information, please contact us using the details below. We will investigate and respond within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, or the NSW Information and Privacy Commission for matters relating to the HRIP Act.


12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. The current version will always be available on our website.


13. Contact Us

For any privacy-related questions, access requests, or complaints:

📧 Email: [email protected]
📞 Phone: 0452 255 484
🏢 Business Name: BCW Services Pty Ltd (trading as Be Calm Within and The Hidden Edge)
🌐 Website: www.becalmwithin.com