Privacy Policy

The Rugby Dietitian

Last updated: March 2026

www.therugbydietitian.com | info@therugbydietitian.com

The Rugby Dietitian is a trading name of Freney Health Pty Ltd (ABN 67 696 131 914). References to “The Rugby Dietitian”, “we”, “us”, and “our” throughout this policy refer to Freney Health Pty Ltd.

1. Introduction

The Rugby Dietitian (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal information responsibly. This Privacy Policy explains how we collect, use, store, and protect your personal information when you:

Visit our website

Book nutrition consultations or services

Purchase digital products or programs

Subscribe to communications

Engage with us online or offline

We comply with the Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). As a provider of dietitian services, your health information is treated as sensitive information and afforded the highest level of protection under the Act.

2. What Information We Collect

Personal Information

This may include:

Name

Email address

Phone number

Date of birth

Billing or payment information

Address (if required for products or services)

Health & Performance Information

Where relevant to nutrition services, we collect information including:

Medical history and current health conditions

Dietary intake and nutrition history

Training load and athletic performance data

Body composition or blood work results (including biomarker testing)

Lifestyle habits, sleep, and recovery data

This information is classified as sensitive health information under the Privacy Act 1988 and is subject to strict additional protections. We collect this information only with your express consent and only to the extent necessary to provide our services.

Technical Information

When you visit our website, we may automatically collect:

IP address

Browser and device type

Pages visited and time on site

Cookies and analytics data

3. How We Use Your Information

We use your information only for the primary purpose for which it was collected, or directly related secondary purposes you would reasonably expect. This includes:

Providing nutrition consultations and coaching services

Developing personalised nutrition advice and programs

Processing payments and managing bookings

Sending requested resources or products

Fulfilling biomarker testing and result interpretation services

Improving our services and website experience

Communicating relevant education, updates, or offers (with your consent)

Meeting legal, professional, and record-keeping obligations

We will never sell your personal data. Health information will not be used for marketing purposes without your separate explicit consent.

4. Use of Artificial Intelligence Tools

This section explains how we use AI-assisted tools in our practice and what this means for your personal and health information.

We use the following AI-powered tools to support the delivery of our services:

Google Gemini (via Google Workspace) — Consult Recording & Notes

We may use Gemini, Google’s AI assistant integrated into Google Workspace, to assist with recording, transcribing, or summarising consultation sessions. This means your consultation content — including health information you share during a session — may be processed by Gemini within our Google Workspace environment.

Important protections that apply:

We use a paid Google Workspace account. Under Google’s contractual commitments, your data is not used to train or improve Google’s AI models without our prior permission.

Your content is not reviewed by Google’s human reviewers outside our Workspace domain without permission.

Google Workspace’s existing access controls, encryption, and security standards apply to all Gemini-processed data.

Your consent is required before any consultation is recorded. We will ask for your explicit consent at the start of any recorded session. You may decline recording at any time, and we will conduct the session without it.

Claude by Anthropic — Meal Plan & Nutrition Analysis

We use Claude, an AI assistant developed by Anthropic, to assist with analysing meal plans, dietary data, and nutrition information as part of preparing recommendations for clients.

When using Claude for this purpose:

We apply data minimisation practices — where possible, we use client reference codes rather than full names or identifiers when entering data into Claude.

We enter only the information necessary for the specific analytical task.

All AI-generated analysis is reviewed and applied by our qualified dietitian before any recommendations are made to you. No clinical decisions are made solely by AI.

Anthropic’s data handling: Claude.ai (Teams/Pro plans) and the Anthropic API operate under terms that do not use your inputs to train Anthropic’s models by default. Data is processed on Anthropic’s US-based servers. This constitutes an overseas disclosure under APP 8 — see Section 7 for details.

Your Rights Regarding AI Processing

Under the Australian Privacy Principles and the OAIC’s guidance on AI, you have the right to:

Know that AI tools are being used to process your health information (which this section provides)

Consent to or decline AI-assisted recording of consultations

Request that your information not be processed through AI tools where practicable (note this may affect the scope of services we can provide)

Ask questions about how AI is used in your care by contacting us directly

AI-generated outputs are used to support our clinical work. They are not substitutes for professional dietetic judgement. Our qualified dietitian reviews all AI-assisted analysis before it is used in your care.

5. Marketing Communications

If you subscribe to our email list or content:

You may receive educational material, program updates, or relevant offers

You can unsubscribe at any time via the link in any email

Your health or clinical information will never be used for marketing purposes

We aim to keep all communications relevant and valuable.

6. Data Storage, Security & Retention

Security Measures

We take reasonable steps to protect your personal and health information, including:

Google Workspace (paid business account) with access controls and two-factor authentication

Password protection on all platforms and devices used in service delivery

Data minimisation when using AI tools — using reference codes rather than identifiers where possible

Professional confidentiality standards consistent with our obligations as a registered dietitian

Secure payment processing via trusted third-party providers

No internet transmission or electronic storage is completely secure. However, we implement industry-standard protections and respond promptly to any identified risks.

Data Retention

In accordance with Australian health records legislation (including the Health Records and Information Privacy Act 2002 (NSW) and equivalent state legislation):

Health records for adult clients are retained for a minimum of 7 years from the date of the last service provided.

Health records created when a client was under 18 years of age are retained until that individual turns 25.

Records are securely deleted after the applicable retention period, with no foreseeable legal need remaining.

A record of destruction is maintained as required.

7. Sharing Your Information

We only share your personal information when necessary to deliver our services or comply with legal obligations. We do not share health information without your consent unless required by law.

Third-Party Service Providers

The following service providers may access or process your data in the course of service delivery. All operate under contractual data processing agreements:

Google LLC (Google Workspace including Gemini) — client records storage, document management, email, consult recording and AI-assisted transcription. Data processed on servers located in the United States.

Anthropic, PBC (Claude) — AI-assisted nutrition and meal plan analysis. Data processed on servers located in the United States.

Squarespace Inc. — website hosting and client intake forms. Data processed in the United States.

Zapier Inc. — automated workflow and data transfer between platforms. Data processed in the United States.

Acuity Scheduling — appointment booking and scheduling. Data processed in the United States.

Payment processor (e.g., Stripe or Square) — secure payment processing. We do not store card details.

We are not responsible for the privacy practices of third-party platforms beyond our contracted obligations. We encourage you to review their privacy policies.

Other Disclosures

We may also disclose information:

To other health professionals involved in your care, with your consent

Where required or authorised by law, court order, or regulatory authority

To our professional indemnity insurer if required in connection with a claim

8. Overseas Data Storage & Transfer

Your personal and health information is stored and processed on servers located outside Australia. Our primary service providers — Google (Workspace and Gemini), Anthropic (Claude), Squarespace, Zapier, and Acuity Scheduling — operate on United States-based infrastructure.

In accordance with Australian Privacy Principle 8 (Cross-Border Disclosure), we have taken the following steps to ensure your information is protected:

Google Workspace operates under a Data Processing Agreement that commits Google to protections substantially equivalent to the Australian Privacy Principles.

Anthropic operates under terms that restrict use of your data for model training and provide enterprise-grade security protections.

Zapier, Squarespace, and Acuity Scheduling operate under comparable contractual data protection terms.

By engaging our services, you acknowledge and consent to your personal and health information being stored and processed in the United States under these protections. If you have concerns about this, please contact us before engaging our services.

9. Cookies & Website Analytics

Our website (hosted on Squarespace) may use cookies to:

Improve website functionality and user experience

Analyse traffic and usage patterns (via analytics tools)

Personalise content where applicable

You can disable cookies through your browser settings, though some website features may not function correctly as a result.

10. Data Breach Notification

In the event of a data breach that is likely to result in serious harm to any individual whose information is involved, we will:

Contain the breach and assess the risk of harm as quickly as possible

Notify affected individuals as soon as practicable

Notify the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988

We maintain a data breach response plan to ensure rapid and appropriate action. If you believe your information held by us has been compromised, please contact us immediately at info@therugbydietitian.com.

11. Access & Correction

You have the right to:

Request access to the personal or health information we hold about you

Request correction of any information that is inaccurate, incomplete, or out of date

Withdraw consent to the use of your information (where consent is the basis for processing), noting this may affect our ability to provide services

Request that your information not be processed through AI tools where practicable

We will respond to access and correction requests within a reasonable time (typically within 30 days). In limited circumstances, access may be refused on grounds permitted under the Privacy Act — we will explain any refusal in writing.

12. Children & Young Athletes

If a client is under 18 years of age:

Written consent from a parent or legal guardian is required before services commence.

The parent or guardian must provide consent on the child’s behalf, including consent to any AI-assisted tools used in service delivery.

Records created during this period are subject to the extended retention period described in Section 6.

We take particular care with the information of young athletes and will not share it beyond what is necessary for service delivery.

13. Direct Marketing

We only use personal information for direct marketing purposes where:

You have consented to receive marketing communications, or

You are an existing client and the communication is directly relevant to services you have previously engaged

Health and clinical information is never used for direct marketing. You may opt out at any time via the unsubscribe link in any email or by contacting us directly.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, tools, or legal obligations. The most current version will always be available on our website. We encourage you to review this policy periodically.

15. Complaints

If you have a concern or complaint about how we have handled your personal or health information, please contact us first:

The Rugby Dietitian

Email: info@therugbydietitian.com

Website: www.therugbydietitian.com

We will acknowledge your complaint within 5 business days and endeavour to resolve it within 30 days.

If you are not satisfied with our response, you may contact:

Office of the Australian Information Commissioner (OAIC)

Website: www.oaic.gov.au | Phone: 1300 363 992 | GPO Box 5218, Sydney NSW 2001

This Privacy Policy was last reviewed and updated in March 2026. The Rugby Dietitian — ABN 67 696 131 914.