BEHAVIOUR HELP APP – PRIVACY POLICY - UNITED KINGDOM

Last updated: 03.09.2025

About Behaviour Help

In this Privacy Policy, references to “Behaviour Help”, “we”, “us” and “our” are references to Behaviour Help Pty Ltd (ABN 74 612 728 275).

This Privacy Policy explains how we collect and handle your personal information, and how you can contact us if you have questions.

Please note that our website may contain links to third-party websites that are not controlled or operated by Behaviour Help. We are not responsible for the privacy practices or the content of any other websites, so you should refer to the privacy policies and terms of use of any third-party websites for further information on their privacy procedures.

Who is the Data Controller?

Data Controller name: Behaviour Help Pty Ltd

Business address: 5A Hartnett Close, Mulgrave, Victoria 3170, Australia

Contact email: dolly@behaviourhelp.com

What personal data do we collect about you?

When you visit and browse our website, register for our services, and engage with our services and content, we collect and process the following categories of personal data about you:

Categories

  • Basic details: Your name, surname, email address, phone number, and data associated with your Google account if you sign up through your Google account.
  • Subscription data: Details about the services you subscribe to, the terms of your subscription.
  • Financial data: Your credit/debit card information, purchase details, transaction data, account details, and financial institution you use.
  • Employment/professional data: The organisation you work with, your role, the specific services you use, and the amount/type of work you undertake when using our services.
  • Technical data: Your IP address, browser settings, geolocation data, device type/model, operating system, and network configuration details.
  • Analytics data: How you browse our website, content, and services; referral page; your clicks; and time spent on pages.
  • Support provider data: If you are a support provider, we may collect your contact details and any relevant information about you.

Important information about Supported Individuals

Users who subscribe to our Services provide and process personal data of individuals (“Supported Individuals”) who are in need of positive behavioural support. This data may include the following:

  • Health and medical information such as information in relation to behaviour, general health and wellbeing, medical conditions, medications, vision and hearing, sleeping and other behaviour patterns, sensory needs and additional support requirements;
  • Sensitive information such as race or ethnic origin, religious beliefs, sexual orientation, and criminal history;
  • Behavioural data, including details in incident reports such as frequency, duration, and intensity of behaviours of concern;
  • Any details or information included on Functional Behaviour Assessments (FBAs) or Positive Behaviour Support Plans (PBSPs) and any data provided to us when you create FBAs or PBSPs via our Platform;
  • Opinions and information about preferences, strengths, and opinions.

When our users submit and process Supported Individuals’ data, they act as Data Controllers under EU and UK data protection laws. We act as Data Processors. Our users warrant that they have obtained appropriate consent from Supported Individuals before processing their personal data through our Services.

By what methods do we collect your data?

  • Data you voluntarily disclose to us: For example, when you sign up on our platform (name, email address, phone number).
  • Data we automatically collect: When you visit/browse our website and platform, we use third-party tools (e.g., Google Analytics) to collect IP address, device information, and browsing activity.
  • Data provided to us by our Users: Users may provide contact details of their support providers to enable use of our services.
  • Data obtained from third-party sources: We may obtain data from third parties (e.g., data brokers).

For what purposes do we collect your data?

  • Provide the Behaviour Help Platform and related services (including creating, managing, and sharing FBAs and PBSPs; behaviour tracking; intervention planning; progress monitoring; and incident analysis).
  • Provide, maintain, improve, and enhance the Platform’s features and functionality.
  • Facilitate customer and technical support; respond to enquiries and communications.
  • Contact you with important notices (Platform updates, changes to Terms or Privacy Policy) and information about products that may interest you.
  • Process payments.
  • Protect and enforce our rights, including intellectual property rights.
  • Manage and administer your account.
  • Comply with legal obligations; assist government and law enforcement agencies; as otherwise permitted by law.
  • Optimise and personalise your website and Platform experience.
  • Analyse how users interact with our website and services.
  • Ensure and maintain the security of our website and platform.
  • Send you marketing emails.

What legal bases do we rely on to process your data?

Contractual necessity (Article 6(1)(b) EU/UK GDPR)

  • Provide the Behaviour Help Platform and related services (including FBAs/PBSPs and related tools).
  • Provide, maintain, improve, and enhance Platform features.
  • Customer and technical support; respond to communications.
  • Important service notices (Platform updates, policy changes).
  • Process payments.
  • Manage and administer your account.

Legitimate interests (Article 6(1)(f) EU/UK GDPR)

  • Protect and enforce our rights, including IP rights.
  • Ensure and maintain the security of our website and platform.

Consent (Article 6(1)(a) EU/UK GDPR)

  • Optimise and personalise your experience of our website and Platform.
  • Analyse how users interact with our website and services.
  • Send marketing emails.

Legal obligation (Article 6(1)(c) EU/UK GDPR)

  • Comply with legal obligations; assist government and law enforcement agencies; as otherwise permitted by law.

Disclosure of your personal data to third parties

In providing our Services, we may disclose personal data to third parties for various purposes, including:

  • Third-party service providers performing services on our behalf (e.g., payment processing, verification, hosting, development, maintenance). See “Sub-processors we use to process your data”.
  • Compliance with law/regulation, binding court order/direction, or lawful requests (including regulatory and law enforcement authorities).
  • Where you have consented to the disclosure.
  • In connection with a transaction (e.g., sale, acquisition, bankruptcy) involving our business or assets.

Sub-processors we use to process your data

We engage third-party service providers to collect, process, and use personal data. Categories include:

  • Cloud service providers
  • Email marketing service providers
  • Payment processing service providers
  • Generative AI tools

To learn about specific service providers that we use, please contact us as described in this Privacy Policy.

International data transfers

When we transfer personal data of individuals residing in the EU & UK to a non-adequate jurisdiction, we implement mechanisms under Article 46 EU/UK GDPR.

Transfers outside the EU/EEA

We implement the European Commission’s 2021 Standard Contractual Clauses (SCCs):
https://commission.europa.eu/.../standard-contractual-clauses-scc_en

Transfers outside the UK

We rely on the UK ICO’s International Data Transfer Agreement/Addendum:
https://ico.org.uk/.../international-data-transfer-agreement-and-guidance/

We may transfer personal information outside of Australia for administrative or other business purposes. If we do so, we will update this Privacy Policy to identify where the recipients are located.

How we ensure the security of your data

We implement technical, organisational, and contractual security measures to ensure the confidentiality, integrity, and availability of data processed through our Website and Platform.

You can contact us via email to learn about the specific data security measures we implement.

How long do we retain your data?

We only retain personal data for as long as necessary for the purpose for which it was collected. When deciding retention periods, we consider:

  • Legal obligations requiring retention for a set time (e.g., tax/accounting regulations);
  • Specific characteristics of the individuals concerned;
  • Sensitivity of the personal data;
  • Your reasonable expectations and our commercial interests.

What are your rights over your personal data?

You may access or request correction of personal information that we hold about you. We will provide access within a reasonable timeframe (except where access may be denied under the Privacy Act or other law). There is no charge for requesting access, but reasonable costs (e.g., photocopying or postage) may apply.

EU/UK GDPR rights (where applicable)

  • Access the data we hold about you;
  • Request restriction of processing;
  • Rectify inaccurate data;
  • Request erasure (“right to be forgotten”);
  • Data portability (obtain and reuse your data for different services);
  • Object to direct marketing;
  • Withdraw consent at any time (where processing is based on consent).

How to exercise your rights

Postal address: 5A Hartnett Close, Mulgrave, Victoria 3170, Australia

Contact email: dolly@behaviourhelp.com

How to submit a complaint to the data protection authorities

If you reside in the EEA or the UK, you may file a complaint with your local data protection authority.

If you are based in the EU, see the directory here:
https://iapp.org/resources/global-privacy-directory/

For the UK, contact the Information Commissioner’s Office (ICO):
https://ico.org.uk

Complaint to the Australian Information Commissioner

If you reside in Australia and are concerned about how we have handled a privacy issue, you may contact the Office of the Australian Information Commissioner:
www.oaic.gov.au

Notice about Google Analytics

We use Google Analytics to collect data such as your IP address, technical device information, browser settings, referral page, content you engage with, clicks, and browsing activities on our website to analyse usage and improve our website, content, and services.

Learn more here:
https://policies.google.com/technologies/partner-sites

Notice about Stripe

We use Stripe to process subscription fee payments. Stripe may collect and process additional data (e.g., purchase time/date, card information, bank details).

See Stripe’s privacy policy:
https://stripe.com/privacy

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, legal obligations, or for other operational reasons. All changes will be published on our website. Where material changes are made, we will take reasonable steps to notify you. We encourage you to review this Privacy Policy periodically to stay informed about how we handle your personal information.