Privacy Policy

Effective 10 October 2026 · Last updated 10 October 2026

1. Who we are

NutriLink ("NutriLink", "we", "us") is an online platform that helps nutritionists run their practice and lets patients follow the nutrition care their practitioner has planned for them. It provides scheduling, meal planning, progress tracking, messaging and payment tools.

NutriLink is a software platform. It does not provide healthcare services and does not employ nutritionists. The nutritionists who use NutriLink are independent health practitioners who are responsible for their own clinical services and for their own obligations as health service providers.

The "data controller" for this platform is Raul Murua trading as NutriLink (273 Hay Street, East Perth, Western Australia, Australia). You can reach our privacy contact at privacy@nutrilink.pro.

2. Scope of this policy

This policy applies to personal information we collect through the NutriLink web and mobile application, including the public policy pages. It is written to align with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).

If you are a patient, note that your nutritionist also collects and holds health information about you, and their own professional and legal obligations (including health records legislation in their state or territory) apply to that relationship. This policy explains how the platform handles your information; your practitioner handles the clinical side of your care.

3. What information we collect

We only collect information that is reasonably necessary to run the service.

  • Account details: name, email address, role (nutritionist or patient), profile photo, and — for nutritionists — professional details they choose to publish (bio, qualifications, clinic contact details).
  • Health information (sensitive information): this is the core of the service. Depending on the feature, this includes meal logs, prescribed nutrition targets, body measurements and body-composition metrics, exercise logs, clinical documents (for example blood tests) uploaded by you or your practitioner, and clinical notes your practitioner records.
  • Appointment data: session times, type (in person or virtual), meeting links, prices and payment status.
  • Communication data: messages and file attachments exchanged between a patient and their nutritionist inside the app, and support tickets you submit.
  • Payment data: payments are processed by Stripe Payments Australia Pty Ltd (or the relevant Stripe entity). We receive a payment status and reference; we do not store your card number. Stripe handles your card details under its own privacy policy.
  • Technical data: device and browser information, IP address, and usage events needed to keep the service secure and to fix faults.

4. How we collect it

We collect information directly from you when you register, complete your profile, log meals or measurements, upload documents, book appointments, contact support or otherwise use the app.

Your nutritionist may also enter information about you (for example clinical measurements, a meal plan or notes) as part of your care — this is a normal part of a nutrition consultation and is visible to you inside the app.

We receive limited technical and payment confirmation data from our service providers when they process data on our behalf.

5. Why we use your information (and the legal basis)

We use personal information to: create and secure your account; deliver the features you use (plans, tracking, messaging, appointments); process payments; provide support; communicate service updates; and detect, prevent and respond to security issues or misuse.

We collect health information (sensitive information under the Privacy Act) only with your consent — which you give when you accept an invitation or use the features — and only where reasonably necessary for the functions of the platform.

We do not sell personal information, and we do not use health information for advertising or profiling. We do not disclose personal information to advertisers or data brokers.

6. Who can see your information inside NutriLink

Access inside the app is deliberately narrow:

  • A patient can see their own records, their assigned nutritionist’s professional profile, and their shared conversations.
  • A nutritionist can see only the patients they invited or are assigned, plus the plans they created.
  • Platform administrators can access records only for support, security and billing administration, under internal access controls.
  • The in-app AI support assistant cannot access any patient or account records: it answers product questions only.

7. Sharing outside NutriLink

We disclose personal information only to the service providers that help us run the platform, and only for the purposes above:

  • Hosting and application platform: NutriLink runs on the Base44 platform (application hosting, database, authentication and file storage).
  • Payments: Stripe (checkout, subscriptions, refunds). Stripe processes your payment details under its own terms and privacy policy.
  • Email delivery: transactional emails (invitations, confirmations, verifications, notifications) are sent through the platform’s email service.
  • Video consultations: when a nutritionist connects their own Google account, Google Meet rooms are created under the nutritionist’s own Google account; Google processes that connection under Google’s terms. Zoom or Microsoft Teams links pasted manually by a nutritionist are third-party services subject to their own providers.
  • Sign-in: if you choose Google sign-in, Google authenticates you and shares your basic profile (name and email) with us.

Some of these providers may store or process data outside Australia. Where information is disclosed overseas, we take reasonable steps to ensure the recipient handles it in a way that is consistent with the APPs, including through the platform provider’s contractual and security commitments. A current list of subprocessors is available on request.

We may also disclose information where required or authorised by law (for example to respond to a court order, or a notifiable data breach under the Notifiable Data Breaches scheme).

8. Storage and security

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures include encryption of data in transit, access controls so that users only reach the records that belong to them, authentication (including optional PIN lock and biometric unlock on the device), and the security practices of the underlying hosting platform.

No system is perfectly secure. Please also do your part: use a strong password, keep your PIN private, and tell us immediately if you think someone has accessed your account.

9. Data retention and deletion

We keep personal information only for as long as necessary to provide the service and to meet our legal obligations. Health records are retained for at least 7 years from the last contact, consistent with the minimum period required by the applicable health records legislation.

When you ask us to delete your account, we remove or de-identify the personal data we hold that is not required for legal or clinical record-keeping. Ask for deletion by submitting a ticket with the category "Privacy" in the Support section, or by emailing privacy@nutrilink.pro.

10. Your rights: access and correction

You can access and correct most of your information directly inside the app. You may also request access to, or correction of, the personal information we hold about you. We will respond within a reasonable time (usually 30 days) and, where we refuse a request, explain why and how to complain.

11. Anonymity and pseudonymity

Because NutriLink is a clinical platform, an identified account is necessary for the service to work safely (your nutritionist must know who they are treating). You cannot use the patient portal anonymously, but you can read the public policy pages anonymously.

12. Notifiable data breaches

If a data breach is likely to cause serious harm, we will follow the Notifiable Data Breaches scheme under the Privacy Act: we will assess the breach, notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required, and tell you what happened and what we recommend you do.

13. Complaints

If you have a privacy concern, contact us first at privacy@nutrilink.pro or through a support ticket. We will acknowledge your complaint and aim to resolve it within 30 days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner: oaic.gov.au or 1300 363 992.

14. Changes to this policy

We may update this policy as the service changes. The current version is always published at this page, with the effective date shown above. This version is effective 10 October 2026 and is scheduled for review by 10 October 2027.