Hemexa
← Back to home

Privacy Policy

Last updated: 2 July 2026

Hemexa Pty Ltd ACN 696 914 753, ABN 48 696 914 753 (“Hemexa”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal information and health information.

This Privacy Policy explains how we collect, use, disclose, store and protect your personal information when you use Hemexa's website, member application, health dashboard, pathology coordination service, health insights, educational content, communications and related services.

By using Hemexa, creating an account, becoming a member, submitting health information, or using any part of our service, you acknowledge that we will handle your personal information as described in this Privacy Policy.

1. Who we are

Hemexa is operated by Hemexa Pty Ltd ACN 696 914 753, ABN 48 696 914 753, located at International Tower 3, Level 17/300 Barangaroo Ave, Barangaroo NSW 2000, Australia.

Hemexa provides a preventative health information, blood-result tracking, pathology coordination and health insights platform for adults in Australia. Hemexa is not an emergency service and does not replace care from your GP, specialist, allied health practitioner or other healthcare provider.

2. Laws we comply with

We handle personal information and health information in accordance with applicable Australian privacy laws, including:

  • the Privacy Act 1988 (Cth)
  • the Australian Privacy Principles
  • the Health Records and Information Privacy Act 2002 (NSW)
  • other applicable state and territory health records legislation, including the Health Records Act 2001 (Vic) and the Health Records (Privacy and Access) Act 1997 (ACT), where relevant to a member's location
  • the Spam Act 2003 (Cth)
  • the Notifiable Data Breaches scheme
  • other applicable laws and regulatory obligations

3. Types of information we collect

We may collect personal information, sensitive information and health information about you, including:

  • Account information: name, email address, phone number, date of birth, sex, residential address, account login details, emergency contact details, and membership status.
  • Health information: pathology requests, pathology results, biomarkers and blood test data, health questionnaire responses, symptoms, health goals, lifestyle information, medications, allergies, prior health records you upload, and health plan data.
  • Pathology information: pathology provider details, collection status, appointment information, laboratory status, practitioner review status, and abnormal-result escalation records.
  • Payment information: membership plan, billing status, transaction history, invoices and receipts. We do not store your full payment card details.
  • Technical information: IP address, device information, browser type, login activity, pages viewed, session data, and analytics events.
  • Communications information: emails, support requests, survey responses, and marketing preferences.

4. How we collect information

We collect information in several ways, including:

  • directly from you when you create an account, complete onboarding, complete health questionnaires, or contact us
  • from Laverty Pathology when they provide pathology status, reports or results
  • from practitioner reviewers when they review pathology requests or results
  • from payment processors, authentication providers, and analytics providers
  • when you paste a supplement retailer product URL in the member app, we send that URL to Jina AI (Reader) to fetch public product page text for name and dose suggestions (allowlisted retailers only; we do not send your health records in that request)
  • from your device or browser when you use our website or platform
  • from publicly available sources where relevant and lawful

5. Why we collect your information

We collect personal information and health information so that we can provide, operate, manage, improve and protect the Hemexa service, including to:

  • create and manage your Hemexa account
  • provide membership services
  • coordinate pathology testing through Laverty Pathology
  • display and interpret pathology results in your dashboard
  • generate educational insights and health plans
  • allow practitioner reviewers to review pathology requests and results for safety purposes
  • identify and respond to abnormal or safety-relevant results
  • contact you about your account, testing, results, and service updates
  • process payments and manage renewals
  • provide customer support
  • improve the platform using aggregated, de-identified data
  • maintain security and prevent fraud
  • comply with legal and regulatory obligations
  • send marketing communications where permitted by law and your preferences

6. Health information consent

Health information is sensitive information. Before you submit health information or begin health onboarding, we will ask you to give specific, informed consent to Hemexa collecting, using and disclosing your health information for the purposes described in this Privacy Policy, including by requiring you to tick or select a consent confirmation at the relevant step in the Hemexa app. Continuing to use the health-related parts of the service after giving that consent constitutes ongoing consent for the same purposes.

You may withdraw consent by contacting us. If you withdraw consent, we may not be able to continue providing some or all of the Hemexa service to you.

7. Pathology providers

To provide the Hemexa service, we disclose relevant personal information and health information to Laverty Pathology (under Healius), our pathology provider. This includes your name, date of birth, sex, contact details, pathology request information, and clinical information needed to collect, process and report pathology results.

Laverty Pathology may collect information directly from you and handles your information under their own privacy policies and legal obligations.

8. Practitioner reviewers and healthcare providers

Hemexa discloses relevant personal information and health information to registered Australian medical practitioners (My CHO GPs) who review pathology requests, results, and safety issues. This review is limited and is not a full medical consultation or ongoing clinical relationship.

If we reasonably believe there is a serious risk to your health or safety, we may disclose relevant information to your GP, another healthcare provider, Laverty Pathology, emergency services, regulators, or other persons where reasonably necessary or legally permitted.

9. AI, algorithms and automated systems

Hemexa may use artificial intelligence, machine learning, algorithms and automated systems to help provide the service, including to organise and summarise pathology results, generate educational explanations, identify trends, and create dashboard insights.

Importantly, when we use AI systems, we strip identifiable information from your data before processing. AI systems receive your pathology results and health data, but do not know your name, contact details, or other personal identifiers. This ensures your privacy is protected even when AI processes your health information.

We may use de-identified, anonymised or aggregated information to improve our AI systems, analytics, and product features. We do not use identifiable health information to train public AI models unless we have your consent.

10. De-identified, anonymised and aggregated information

We may create de-identified, anonymised or aggregated information from your data for purposes including analytics, product development, research, quality improvement, and service improvement. We will take reasonable steps to ensure that de-identified information does not identify you.

11. Overseas disclosure and storage

Some of our service providers store or process personal information outside Australia. Our vendors and their locations include:

  • Supabase: Cloud database (data centres in Australia and US)
  • Stripe: Payment processing (United States)
  • Clerk: Authentication and account management (United States)
  • PostHog: Analytics and product insights (United States, European Union)
  • Resend: Email delivery (United States)
  • Sentry: Error monitoring and security logging (United States)
  • Svix: Webhook management (United States)
  • Anthropic and OpenAI: AI processing for de-identified health analysis (United States)
  • Jina AI (Reader): Supplement product page text extraction when you paste a retailer URL in the member app (United States)
  • Vercel: Application hosting and speed monitoring (United States)

Before disclosing personal information to overseas recipients, we take reasonable steps to protect the information and ensure appropriate safeguards are in place. You acknowledge that overseas providers may be subject to different privacy and data protection laws from those in Australia.

Unless a specific exception under the Australian Privacy Principles applies, we remain accountable for personal information we disclose to our overseas service providers as if we had handled it ourselves, and we require our vendors to protect your information consistently with this Privacy Policy.

12. Direct marketing

We may send you marketing communications about Hemexa, health education, product updates, or related services where permitted by law and your communication preferences. You can unsubscribe from marketing communications at any time.

Even if you unsubscribe from marketing, we may still send you non-marketing communications about your account, membership, billing, pathology testing, results availability, abnormal results, service changes, security, and legal notices.

13. Cookies and analytics

We use cookies, pixels, local storage, analytics tools and similar technologies to operate and improve our website and platform. These technologies help us keep you logged in, remember preferences, understand website usage, improve performance, and detect errors.

You may be able to disable cookies in your browser settings. If you disable cookies, some parts of Hemexa may not work properly.

14. Who we disclose information to

We may disclose personal information and health information to:

  • Laverty Pathology and other pathology providers
  • Practitioner reviewers and healthcare providers where appropriate and lawful
  • Payment processors, authentication providers, and cloud hosting providers
  • Analytics providers, AI and software providers
  • Professional advisers, including lawyers and accountants
  • Regulators, courts, law enforcement, or government bodies where required or permitted by law
  • Emergency services or emergency contacts where reasonably necessary for safety
  • Business partners or prospective purchasers in connection with a corporate transaction, subject to appropriate confidentiality protections
  • Other parties where you consent or where permitted by law

We do not sell your identifiable health information.

15. Data security

We take reasonable steps to protect personal information and health information from misuse, interference, loss, unauthorised access, modification and disclosure. These steps include:

  • encryption in transit and at rest
  • access controls and authentication controls
  • audit logs and role-based permissions
  • secure hosting and monitoring
  • staff and contractor access controls
  • confidentiality obligations with service providers
  • vendor due diligence
  • security reviews and incident response processes

No system is completely secure. We cannot guarantee that information will be secure in all circumstances. You are responsible for keeping your account credentials secure and telling us promptly if you suspect unauthorised access.

See our Security page for a member-friendly summary of technical safeguards, including file fingerprints, results locking, and what we never do with health information.

16. Data breaches

If we become aware of a data breach affecting personal information or health information, we will assess and respond to the breach in accordance with applicable law, including the Notifiable Data Breaches (NDB) scheme.

Where the NDB scheme requires notification (where a data breach is likely to cause serious harm), we will notify affected individuals and the Office of the Australian Information Commissioner. Health data breaches can meet the serious harm threshold quickly given the sensitive nature of the information involved.

We will also take steps such as investigating the incident, containing the breach, notifying service providers, resetting credentials, improving security controls, and communicating with affected users.

17. Data retention

We retain personal information and health information for as long as reasonably necessary to provide the service, comply with legal obligations, maintain records, resolve disputes, manage risk, support clinical governance, and meet insurance requirements.

Health information retention: Consistent with retention periods commonly applied to health records in NSW, we generally retain adult health information for a minimum of 7 years from the last occasion a health service was provided through Hemexa. This means we may not be able to delete health information immediately even if you request deletion.

If we are required or permitted to retain information by law or professional standards, we may not be able to delete it immediately even if you request deletion or close your account. When information is no longer required, we will take reasonable steps to destroy, delete, de-identify or anonymise it unless we are required or permitted to retain it.

18. Accessing and correcting your information

You may request access to personal information we hold about you. You may also request correction of information if you believe it is inaccurate, out of date, incomplete, or misleading.

We may need to verify your identity before responding to access or correction requests. We will respond within a reasonable period. In some cases, we may refuse access or correction where permitted by law. If we refuse a request, we will explain why, unless it would be unreasonable or unlawful to do so.

19. Deleting your account or information

You may request deletion of your account or certain personal information by contacting us.

We will consider deletion requests in accordance with applicable law. We may refuse, delay or limit deletion where information is required or permitted to be retained for:

  • the health record retention period described above (generally a 7-year minimum for adult health information)
  • pathology records and practitioner review records
  • legal, regulatory or professional obligations
  • accounting, tax or audit obligations
  • fraud prevention, security, or dispute resolution
  • insurance, clinical governance, or safety monitoring
  • backup integrity or enforcement of Terms and Conditions

If we cannot delete information, we may restrict access to it, archive it, or de-identify it where appropriate and lawful. Deleting your account may prevent us from providing the service to you.

20. Accuracy of information

We rely on you to provide accurate, complete and current information. You should update your account details and relevant health information if they change. If information is inaccurate, incomplete or out of date, Hemexa insights, pathology coordination, and safety communications may be affected.

21. Children

Hemexa is intended for adults aged 18 and over. We do not knowingly provide the service to children. If we become aware that we have collected personal information or health information from a person under 18, we may delete, de-identify, restrict or retain that information as required or permitted by law.

22. Third-party links and services

The Hemexa website or platform may link to third-party websites, services, or resources. We are not responsible for the privacy practices, content or security of third-party websites or services. You should read the privacy policies of third parties before providing information to them.

23. Corporate transactions

If Hemexa is involved in a merger, acquisition, restructure, financing, sale of assets, or similar transaction, personal information may be disclosed to advisers, potential counterparties, investors, purchasers or related parties. Where practicable, we will take reasonable steps to ensure that information remains protected.

24. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify you by email, in-app notice, or website notice. If we make a material change to how we collect, use or disclose health information, we may ask for your consent again where required.

25. Complaints

If you have a privacy concern or complaint, please contact us first. We will consider your complaint and respond within a reasonable period. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) or, where applicable, a state or territory health privacy regulator such as the Information and Privacy Commission NSW.

26. Contact us

For privacy questions, access requests, correction requests, deletion requests or complaints, contact:

Privacy Officer
Hemexa Pty Ltd
Email: hello@hemexa.health
Address: International Tower 3, Level 17/300 Barangaroo Ave, Barangaroo NSW 2000