Privacy Policy
This explains which data we collect, why we collect it, and how we process it.
Healing Now Privacy Policy
Effective date: 1 June 2026 · Last revised: 25 September 2026
Healing Now (the “Company”) values the personal information of data subjects and has established and published this Privacy Policy (the “Policy”) having regard to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) of Australia, where the Company has its place of business, the Personal Information Protection Act of Korea and other applicable laws. This Policy explains what personal information the Company collects, uses, retains and destroys and for what purposes, and what rights data subjects may exercise.
Company Information
Company: Pretty Of System Pty Ltd (trading as Healing Now) · ABN: 45 661 645 692
Contact: admin@healingnow.ai · Phone: +61 439 007 010
Address: U11, 2200 Logan Road, Upper Mount Gravatt QLD 4122, Australia
Article 1 (Classification of the Company’s Role as a Personal Information Handler)
As a B2B service provider, the Company’s legal role is clearly distinguished as follows, depending on the type of personal information it processes. This distinction is the most important consideration when interpreting this Policy.
| Category | Information concerned | Role of the Company |
|---|---|---|
| (a) Personal information of Members (businesses) | Information about businesses and their officers and employees that the Company collects directly in the course of registration, contracting, payment and customer support | Personal information handler / Controller. The Company itself determines the purposes and means of collection and use. |
| (b) Information about Members’ end customers | Information about a Member’s own customers or patients that the Member enters into and processes on the platform (such as names, contact details, booking and treatment history, and consent forms) | Service provider / Processor. The Member is the controller, and the Company only stores and processes the information through its systems on the Member’s instructions. |
In case (b), the obligations of a controller, including obtaining consent to the collection and use of personal information, responding to the rights of data subjects and determining the purposes of use, are borne by the Member. The Company processes such information only within the scope of the Service Agreement and the outsourcing terms agreed with the Member, and does not use it for its own purposes without the Member’s express instructions or a requirement of law. End customers should first direct any requests concerning the processing of their personal information to the relevant Member (business).
Article 2 (Personal Information Collected and Methods of Collection)
The personal information of Members (businesses) that the Company collects directly as a controller is as follows.
| Category | Information collected |
|---|---|
| Required | Business name, contact person’s name, email address, phone number, and login credentials (username and encrypted password) |
| Payment-related | Payment method information, billing address, and payment and refund history (sensitive payment information such as card numbers is processed by the payment service provider) |
| Automatically collected | IP address, cookies, date and time of access, service usage records, device and browser information, and log data |
The Company collects personal information by the following methods.
- Entered or provided directly by Members in the course of registration, contracting, use of the Service and customer support enquiries
- Collected automatically through cookies, log analysis tools and similar means in the course of using the Service
- Returned by Third-Party Services, such as payment service providers, as the results of payment processing
Information of type (b), namely information about Members’ end customers, is processed solely as a result of Members entering or uploading it into the Service, and the Company does not collect it directly from the data subjects.
Article 3 (Purposes of Use of Personal Information)
The Company uses the personal information of Members (businesses) within the scope of the following purposes.
- Provision of the Service and performance of the agreement: account creation and authentication, provision of core functions such as bookings, POS and payments, and billing and settlement
- Customer support: handling enquiries and complaints, and delivering announcements and essential operational notices
- Service improvement and analysis: developing new features and improving usability and stability through de-identified and aggregated processing
- Security and prevention of misuse: access control, detection of abnormal activity, and dispute response
- Marketing (with consent): information about new services and events. Members may withdraw their consent to receive such information at any time.
- Compliance with legal obligations: record retention and reporting required under applicable laws
Article 4 (Outsourcing of Personal Information Processing)
To provide the Service smoothly, the Company outsources personal information processing tasks to specialist external providers as set out below. Through outsourcing agreements, the Company manages and supervises its service providers to ensure that they process personal information securely.
| Service provider (examples) | Outsourced tasks |
|---|---|
| Payment service provider (PSP) | Processing and settlement of subscription fees and in-store payments (payment method information such as card numbers is processed directly by the payment service provider and is not stored by the Company) |
| Cloud providers such as Google Cloud / Firebase | Data storage and operation of server infrastructure |
| Messaging providers such as Twilio / telecommunications carriers | Sending SMS and notification messages |
| Google (Reviews integration) | Providing Google Review request and integration functions |
The actual list of service providers may change depending on how the Service is operated, and any changes will be published through this Policy. With respect to the outsourced processing of end customer information entered by Members, the Company, as a processor for the Member (the controller), may sub-outsource processing to the infrastructure providers listed above and others, on the terms of the Service Agreement with the Member.
Article 5 (Provision of Personal Information to Third Parties)
- The Company does not provide Members’ personal information to third parties except with the Member’s consent or where specifically provided for by law.
- Where there is a lawful request from an investigative or supervisory authority under the law, the Company may provide personal information in accordance with the procedures and within the scope prescribed by applicable laws.
- Where personal information is transferred as a result of a business transfer, merger or similar event, the Company will give prior notice of that fact in accordance with applicable laws and take measures to protect the rights of data subjects.
Article 6 (Cross-Border Transfer of Personal Information)
- Because the Company has its place of business in Australia and uses cloud infrastructure and Third-Party Services, personal information may be transferred to, stored in and processed in Australia, the Republic of Korea, the United States, or any other country in which the servers of the relevant Third-Party Services are located.
- When transferring personal information overseas, the Company takes reasonable contractual and technical measures to ensure the level of protection required by applicable laws (including the Australian APPs and the Personal Information Protection Act of Korea).
- Data subjects may enquire about the specific details of an overseas transfer (such as the recipient, the destination country and the purpose of the transfer) using the contact details in Article 12.
Article 7 (Retention and Destruction of Personal Information)
- As a general principle, the Company destroys personal information without delay once the purposes of its collection and use have been achieved or the Member has withdrawn from the Service.
- However, where retention is required under applicable laws (such as laws relating to electronic commerce, taxation and accounting), the Company retains the relevant information separately for the period prescribed by those laws (for example, payment and transaction records are retained for the period prescribed by the applicable laws).
- End customer data entered by a Member is retained after the Service Agreement ends until the expiry of the grace period set by the Company (for example, 30 days) so that the Member can back it up, and is then destroyed, except where retention is required by law.
- Information in electronic file form is deleted using technical methods that make recovery impossible, and printed materials are destroyed by shredding or incineration.
Article 8 (Rights of Data Subjects and Users and How to Exercise Them)
- Members (as data subjects) may request access to, correction or deletion of, or suspension of the processing of their personal information, and may withdraw their consent. This includes the rights to request access and correction under the Australian APPs and the Personal Information Protection Act of Korea.
- These rights may be exercised through the settings menu within the Service or by contacting the Privacy Officer using the contact details in Article 12, and the Company will act within the period prescribed by applicable laws.
- Members may withdraw their consent to receive marketing information at any time, after which the sending of information for marketing purposes will cease.
- If an end customer wishes to exercise rights in relation to their personal information (information entered by a Member), they must make the request to the relevant Member (business), which is the controller. If the Company receives such a request directly, it will forward the request to the relevant Member and handle it in accordance with the Member’s instructions.
- Data subjects may lodge a complaint or apply for dispute resolution concerning the processing of personal information with a supervisory authority (for example, the Office of the Australian Information Commissioner (OAIC) or the Personal Information Protection Commission of the Republic of Korea).
Article 9 (Cookies and Automatically Collected Information (Logs))
- The Company uses cookies, similar technologies and access logs to provide the Service and to analyse its use.
- Cookies are used for purposes such as keeping users signed in, storing user preferences and analysing Service usage statistics.
- Data subjects may refuse or delete cookies through their browser settings; however, in that case the use of some Service functions may be limited.
Article 10 (Measures to Ensure the Security of Personal Information)
The Company implements the following security measures to ensure that personal information is processed securely.
- Technical safeguards, including encryption in transit and at rest
- Minimisation and control of access rights to personal information, and retention and review of access records
- System security management, including the installation and updating of security software and intrusion detection and prevention
- Training for personnel who handle personal information, and the establishment and implementation of internal management policies
- Physical access controls and the use of the security certifications of external infrastructure providers
Article 11 (Personal Information of Children)
- The Service is a B2B service intended for businesses, and the Company does not aim to collect directly the personal information of children under the age of 14 (or such other age as is prescribed by the laws of the relevant jurisdiction).
- Where a Member processes, through the Service, the personal information of end customers who are children, the Member, as the controller, is responsible for complying with the procedures required by applicable laws, such as obtaining the consent of a legal guardian.
Article 12 (Privacy Officer and Contact Details)
The Company has designated a Privacy Officer to oversee matters relating to the processing of personal information and to handle enquiries and complaints from data subjects.
Email: admin@healingnow.ai
Phone: +61 439 007 010
Article 13 (Governing Law and General Provisions)
- This Policy is based on the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) of Australia, where the Company has its place of business, and has also been prepared having regard to the privacy laws of other applicable jurisdictions, including the Personal Information Protection Act of Korea.
- Where two or more laws apply to a particular transaction or data subject, the Company endeavours, to a reasonable extent, to apply whichever of the levels of protection prescribed by the respective mandatory laws is more favourable to the data subject.
- If this Policy conflicts with an individual Service Agreement or the data processing terms agreed with a Member, the relevant Service Agreement prevails in respect of the Member’s end customer information (the processor domain).
Article 14 (Changes to this Privacy Policy)
- This Policy may be amended in response to changes in laws, policies or the Service.
- If the Company changes this Policy, it will give prior notice of the changes and their effective date through an announcement within the Service, by email or by other means.
- In the case of material changes (such as substantive changes to the information collected, the purposes of use or the provision of information to third parties), the Company will give notice with a reasonable advance notice period and, where necessary, obtain separate consent.
- This English version is provided for convenience. In the event of any inconsistency between the Korean and English versions, the Korean version shall prevail.
