Privacy Policy
Last updated
To be confirmed: legal review required before publication
About this policy
This policy explains what personal information HPNA collects through this website, why we collect it, who we disclose it to, how long we keep it, how we protect it, and how you can ask for access to it or ask us to correct it. HPNA provides independent business valuations for healthcare businesses across Australia. If you want to know what an engagement involves before you send us anything, read how it works or about HPNA.
This website is operated by Beach Group Australia Pty Ltd (ABN 17 699 866 718), trading as HPNA, referred to below as HPNA, we or us.
Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded in a material form. That definition is in section 6(1) of the Privacy Act 1988.
HPNA handles personal information in accordance with the Australian Privacy Principles, the 13 principles in Schedule 1 to the Privacy Act 1988. The Office of the Australian Information Commissioner (the OAIC) states that the Australian Privacy Principles govern the collection, use and disclosure of personal information, an organisation's governance and accountability, the integrity and correction of personal information, and the rights of individuals to access their personal information. The OAIC is the regulator that oversees them. Australian Privacy Principle 1 requires a clearly expressed and up to date policy describing how an entity manages personal information. This is that policy.
To be confirmed: confirm whether the entity is covered by the Privacy Act 1988 or applies the Australian Privacy Principles voluntarily. The OAIC states that a small business is one with an annual turnover of $3 million or less, and that most small businesses are not covered. It also states that some businesses are covered whatever their turnover, including health service providers, businesses that trade in personal information, Commonwealth contractors and credit reporting bodies, and that a small business may choose to be covered. Valuation files for healthcare businesses can carry health information, so this question should be settled before the policy is published.
What we collect
The enquiry form
When you complete the form on request a valuation or contact you give us your name, email address and phone number, the business name, the business type, your state or territory, an approximate annual revenue band, the purpose of the valuation, your preferred timeframe and a short description of the business and what you need. Those fields let us work out whether we can help and what an engagement would involve.
The form also records the page you were on when you submitted it and any campaign parameters in the web address that brought you there, so we know which part of the site prompted the enquiry.
Files you attach
The form accepts a small number of documents in common financial, document and image formats. Owners of healthcare businesses usually attach financial statements, tax returns, management reports, a lease, a shareholder or partnership agreement, practitioner service agreements, or a report exported from a practice management or dispensing system.
Material of that kind carries personal information about identifiable individuals even though it is prepared for a commercial purpose. Practitioner billing and service reports, contractor and service-fee arrangements, wage and superannuation records, and the terms on which a practitioner occupies a suite all identify people. The usual examples in this sector are Medicare and MBS billing summaries for a medical or allied health practice, script volume and dispensing reports for a pharmacy, participant service agreements and plan-management reports for an NDIS provider, and rostering and award classification records for an aged care or community care business.
Send only what is needed to answer the question you are asking us, and remove or aggregate identifiers where you can. A practice can usually be valued from practitioner-level billing that is de-identified or shown by practitioner code rather than by name.
Patient, participant, resident and client records
Please do not attach patient, participant, resident or client records.
Sensitive information is a subset of personal information under section 6(1) of the Privacy Act 1988 and it includes health information about an individual. It attracts additional protection. HPNA values businesses, not the people treated or supported by them, and does not need health information about a patient or a participant to do that. If a document you send contains it, tell us, and we will confirm whether we need the document at all or whether a redacted or aggregated version is enough.
Correspondence and engagement records
If an engagement proceeds we also hold the correspondence, notes, financial and operational information and working papers created in the course of it. What is held depends on the scope agreed for that engagement.
Technical information
This website is delivered by a cloud hosting provider whose systems keep short-lived request records that may include an internet protocol (IP) address, the browser used and the pages requested. To limit automated abuse of the enquiry form, the site counts recent submissions against a one-way hash of the requester's IP address, which is an irreversible fingerprint, rather than against the address itself. Where an automated bot check is enabled on the form, the provider of that check also processes technical information about the request.
Analytics, and your choice about it
Two things are worth separating here. The first is Cloudflare Web Analytics, which our hosting provider adds to every page. It counts page views and referrers in aggregate, sets no cookies, stores nothing on your device and does not follow you to other websites, so it runs without asking you. The second is Google Analytics, which does track across a session. It is loaded through Google Tag Manager only if you accept analytics when asked, and not at all if you decline. Your choice is stored in your own browser under a single local storage key, is not sent to us, and can be changed at any time. The website sets no cookies of its own.
Why we collect it and how we use it
Australian Privacy Principle 3 limits the collection of personal information to what is reasonably necessary for our functions and activities, and Australian Privacy Principle 6 limits use and disclosure to the purpose it was collected for, a directly related purpose you would reasonably expect, or a purpose you consent to. We collect the information above to:
- respond to your enquiry and confirm the scope, purpose, valuation date and fee of a possible engagement
- carry out a valuation engagement, if one proceeds, and communicate with you and the advisers you nominate
- keep our own business, accounting and quality records
- understand in aggregate how this website is used, where you have consented to analytics
- meet obligations imposed on us by law
We do not sell personal information and we do not disclose it to anyone for their own marketing. To be confirmed: confirm whether HPNA sends any marketing or newsletter communications. If it does, this policy must describe the direct marketing conditions and the opt-out required by Australian Privacy Principle 7.
Decisions about your enquiry are made by people
A valuation conclusion is an opinion formed by a valuer, not an output of a model or a calculator, and this website publishes no automated valuation tool. To be confirmed: confirm that every enquiry is read by a person and that no automated triage, scoring or screening feature is applied to enquiries, so that this section can state it plainly.
At the time of writing the OAIC states that from 10 December 2026, an entity covered by the Privacy Act must add information to its privacy policy where it has arranged for a computer program to make, or to do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect the rights or interests of an individual, and personal information about that individual is used in the operation of the program. The policy must then describe the kinds of personal information used and the kinds of decisions made solely by the operation of such a program. To be confirmed: confirm before 10 December 2026 whether any tool used by HPNA, including any enquiry triage, scoring or screening feature, falls within that obligation, and update this section if it does.
Who we disclose it to
We disclose personal information to:
- the provider that delivers our email, so that your enquiry and our acknowledgement reach their destination
- the cloud hosting and storage providers that run this website and hold the enquiry record
- your accountant, lawyer or other adviser, where you ask us to deal with them
- professional advisers of our own, where we need advice about a matter
- anyone else you direct us to, or where disclosure is required or authorised by law
To be confirmed: named service providers used for website hosting, enquiry storage and email delivery, and the terms on which each holds information
Disclosure outside Australia
Some of the providers described above may store or process information on servers outside Australia. Australian Privacy Principle 8 requires an entity, before it discloses personal information to an overseas recipient, to take such steps as are reasonable in the circumstances to ensure that the recipient does not breach the Australian Privacy Principles. Section 16C of the Privacy Act 1988 goes further: an entity that discloses personal information to an overseas recipient remains accountable for acts and practices of that recipient that would breach those principles.
To be confirmed: the countries in which each service provider stores or processes personal information, and the contractual protections in place
How we store and protect it
Australian Privacy Principle 11 requires an entity to take reasonable steps to protect personal information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure. Information submitted through this website is sent over an encrypted connection, attachments are checked before they are accepted, and access to enquiry records and engagement files is restricted to the people who need it. No transmission over the internet and no system of storage is completely secure, and we cannot promise absolute security.
The Notifiable Data Breaches scheme applies to entities covered by the Privacy Act 1988. The OAIC states that where a data breach involving personal information is likely to result in serious harm, the entity must notify the affected individuals and the OAIC. We will follow that scheme if a breach affecting your information occurs.
How long we keep it
We keep enquiry records and engagement files for as long as we need them for the purpose they were collected for and for as long as we are required to keep them by law, including tax and limitation periods. When neither applies, we take reasonable steps to destroy the information or to de-identify it.
To be confirmed: retention periods for enquiry records that do not become engagements, and for valuation working papers and reports
Access and correction
Australian Privacy Principle 12 gives you the right to ask for access to the personal information we hold about you, and Australian Privacy Principle 13 requires us to take reasonable steps to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Ask us through the form on our contact page and tell us what you are looking for.
We may need to confirm your identity first. We do not charge you for making a request. The OAIC's guidance on Australian Privacy Principle 12 is that an organisation may impose a charge for giving access provided the charge is not excessive, that a charge must not be used to discourage a request, and that the organisation should tell the individual in advance if a charge may be imposed and the likely amount. We will follow that guidance, so if retrieving a large volume of material would involve a charge we will tell you the likely amount before we start and you can decide whether to go ahead. The same guidance says an organisation must respond in a reasonable period after the request is made, and that as a general guide a reasonable period should not exceed 30 calendar days. If we cannot give you access or make a correction, we will tell you why in writing and how to take the matter further.
Dealing with us anonymously
Australian Privacy Principle 2 gives you the option of dealing with an entity anonymously or under a pseudonym where that is lawful and practicable. You can read this entire website, including the glossary and the insights articles, without telling us who you are, and you can ask a general question about how valuations work without identifying yourself. We cannot prepare a valuation, or reply to a written enquiry, without contact details.
Complaints
If you think we have handled your personal information in a way that breaches the Australian Privacy Principles, tell us first. Send us the details through the form on our contact page, setting out what happened and what you would like us to do. We will investigate and respond to you in writing.
The OAIC asks that you complain to the organisation first. Its guidance states that if the organisation does not respond to your complaint in 30 days, or you are not happy with the response, you can then lodge a complaint with the OAIC. The OAIC publishes its complaint form and its current contact details on its own website.
Changes to this policy
We may update this policy as our systems, providers or obligations change. The date at the top of this page shows when it was last updated. Material changes will be described here rather than made silently.
Contact
Beach Group Australia Pty Ltd (ABN 17 699 866 718), trading as HPNA. Privacy enquiries go through the form on our contact page.
See also our website terms of use and our disclaimer.
References
- Office of the Australian Information Commissioner, Australian Privacy Principles, accessed 4 September 2026.
- Federal Register of Legislation, Privacy Act 1988, accessed 4 September 2026.
- Office of the Australian Information Commissioner, Chapter 8: APP 8 Cross-border disclosure of personal information, accessed 4 September 2026.
- Office of the Australian Information Commissioner, Chapter 12: APP 12 Access to personal information, accessed 4 September 2026.
- Office of the Australian Information Commissioner, Notifiable data breaches, accessed 4 September 2026.
- Office of the Australian Information Commissioner, Before you lodge a privacy complaint with us, accessed 4 September 2026.
- Office of the Australian Information Commissioner, Small business, accessed 4 September 2026.
- Office of the Australian Information Commissioner, Chapter 1: APP 1 Open and transparent management of personal information, accessed 4 September 2026.
