Book Free Pain Assessment

Privacy Policy

Last Updated: January 15, 2026

Who We Are
Harmony Quantum Health Solutions Pty Ltd, trading as Andrea Quintal Portas, provides health facilitation services in Victoria, Australia. We are committed to protecting your privacy under the Australian Privacy Act 1988, Victorian Health Records Act 2001, and GDPR (for EU clients).

Information We Collect
• Personal Information: Name, email, phone, address, date of birth
• Health Information: Medical history, current conditions, medications, pain levels, symptoms
• Session Information: Notes from sessions, progress tracking, treatment plans
• Payment Information: Processed by Kajabi, Stripe, and PayPal (we do not store credit card details)
• Technical Information: IP address, browser type, pages visited (via website cookies)

How We Use Your Information
• To provide and deliver our services
• To communicate with you about sessions and programs
• To maintain your health records
• To process payments
• To improve our services
• To comply with legal obligations

Legal Basis for Processing (GDPR - EU Clients)
For EU clients, we process your data based on:
• Contract: Your purchase of a package or session constitutes our contract. Processing is necessary to fulfill services you've purchased.
• Consent: You explicitly agree to processing of your health data and sharing with necessary third-party service providers
• Legal Obligation: Compliance with Australian and EU law

By purchasing services, you consent to data sharing with third-party platforms (Calendly, Kajabi, Stripe, PayPal, Zoom, email providers) as these are essential to our business operations. If you prefer not to use these platforms, you may attend in-person sessions and request all documentation be handled manually by contacting us before enrollment.

GDPR Applicability (USA & Brazil Clients)
GDPR applies only to EU/EEA residents. Clients in the USA and Brazil are governed by Australian privacy law and any applicable local privacy laws in their jurisdiction. However, we extend similar privacy protections to all clients regardless of location.

How We Protect Your Information
• Secure storage on password-protected systems
• Encrypted transmission of data
• Limited access (only Andrea has access to client records)
• Regular security reviews
• Third-party platforms (Calendly, Kajabi, Stripe, PayPal, Zoom) meet industry security standards

Information Sharing
We do NOT sell or rent your information. We share information:
• With third-party service providers essential to our operations (Calendly, Kajabi, Stripe, PayPal, Zoom, email providers)
• With your explicit consent for other purposes
• When required by law (court order, preventing serious harm, mandatory reporting of child, adult, or senior abuse)
• With your healthcare providers (only with your written consent)

By engaging our services, you consent to necessary data sharing with third-party platforms. Alternative: Attend in-person and request manual documentation handling.

International Data Transfers
We are based in Australia. Third-party platforms (Calendly, Kajabi, Stripe, PayPal, Zoom) may store data in the US or other countries. These providers comply with GDPR through Standard Contractual Clauses or adequacy decisions where applicable.

Your Rights
Under Australian Privacy Act and GDPR (EU clients), you have the right to:
• Access your personal and health information
• Request corrections to inaccurate information
• Request deletion of your information (subject to legal retention requirements)
• Withdraw consent for processing
• Object to processing of your data
• Request a copy of your data (data portability)
• Lodge a complaint with supervisory authority (OAIC in Australia, or your local data protection authority in EU)

Data Retention
We retain your information for:
• Health records: 7 years after last session (Victorian legal requirement)
• Financial records: 7 years (Australian tax law)
• Marketing communications: Until you unsubscribe

Cookies
Our website uses essential cookies for functionality. We do not use tracking or advertising cookies. You can disable cookies in your browser settings.

Children's Privacy
Our services are mostly for adults (18+). For clients under 18, parental/guardian consent is required and we collect only necessary information.

Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. The current version is always available on our website at www.andreaquintalportas.com/privacy-policy. We recommend checking periodically for updates. We are not required to notify you of minor updates by email.

Contact & Complaints
Questions or concerns about privacy?
Email: [email protected]
Phone: +61 477 602 010

To lodge a complaint:
• Australia: Office of the Australian Information Commissioner (OAIC) - www.oaic.gov.au
• EU: Your local Data Protection Authority


By using our services, you consent to this Privacy Policy and necessary data sharing with third-party service providers.