Privacy policy
Last updated 15 September 2026
Supriva holds information about people’s professional lives, and some of it is sensitive. This policy says plainly what we collect, why, who sees it and how long we keep it. It is written to be read, not filed. If something in it is unclear, the Privacy Officer at privacy@supriva.com.au will answer.
Who we are
Supriva is run by Supriva Pty Ltd (ACN 701 292 088, ABN 85 701 292 088), an Australian company based in New South Wales. We are bound by the Privacy Act 1988 and the Australian Privacy Principles. Because we handle health information, we are covered by the Act whatever our size.
Our Privacy Officer is responsible for how we handle personal information and for answering requests and complaints. Reach them at privacy@supriva.com.au.
Who this policy is about
Several groups of people, and the policy says which parts apply to each.
- Supervisors and practitioners who hold a Supriva account. Most of this policy is about you.
- People you supervise, or who supervise you, who are also members and see some of your information because you work together.
- Practitioners’ own clients, who are never on Supriva, but who may be discussed in a supervision session. The section headed If you are a practitioner’s client is for them.
- People on the public supervisor registers of ACA and PACFA, whether or not they have heard of us. The section headed If you are on a public register is for them.
- Visitors to our public pages, and people on our waitlist, about whom we hold very little.
What we collect, and why
We collect information at the moment it is needed, and we tell you why at that moment. This is the whole of it.
When you create an account
Your name and email address, and a password, which we never store in a readable form. If you sign in with Google, Google tells us your name and email address and confirms you control that address. We use these to run your account and to reach you.
Your registration
Which registering body you are registered with, ACA or PACFA, your registration number, your registration level, your renewal date, and how long you have been registered. This is sensitive information under the Privacy Act, and we ask for your consent before collecting it, as its own step. We use it to check your registration against your body’s public register, to work out which supervision rules apply to you, and, if you are a supervisor, to show your credentials on your profile.
Your details
A phone number, so a supervisor can reach you about a session. Your date of birth, which only a supervisor you book can see. Your pronouns, if you choose to give them, so people address you correctly.
Your practice
Your career stage and a band describing your client-contact hours, because your registering body’s supervision requirement depends on both. Where you practise, as a suburb, state and locality, and whether you meet online, in person or both. If you offer in-person sessions, the address, which we check with Google’s address validation service so a practitioner arrives at the right door.
Who you would feel at ease with
If you choose to tell us, a preference about the gender of your supervisor, and about their background or lived experience: First Nations-informed practice, culturally and linguistically diverse, migrant or refugee experience, LGBTQIA+ affirming, or faith-informed. This is optional, and the screen says so. A preference like this can say something about you, so we treat it as sensitive: it is used only to shape who we show you, it is never displayed to anyone, and it is never combined with anything else.
If you are a supervisor
Your certificate of currency for professional indemnity insurance. An AI service reads it once, at upload, to take the cover dates and type of cover, and a person at Supriva checks anything it cannot read. The certificate itself is stored where nobody, including us, can open it again; what we keep is the reading.
Your profile photo and, if you add one, a short video. Your answers about how you work, the kinds of supervision you offer and who you work with. If you give us your practice’s website address, we read the site to get a sense of how you write and keep a short note of that, not a copy of the site. From your answers, an AI service drafts two paragraphs for your profile, which you read and approve before anyone sees them. The fees you set.
Your calendar, if you connect one
With Google, we ask only to see when you are busy. With Microsoft, the permission Microsoft offers lets us read your calendar, but we keep only the busy intervals. Either way, what we store is that a time is taken, never what is in it. The credential you give us is encrypted with a key that is not kept with your data, and you can disconnect at any time, which deletes it.
Your practice management system, if you connect one
Halaxy, Cliniko, Splose, Zanda or Acuity. We hold the credential you give us, encrypted the same way, and use it only to read when you are busy. Disconnecting deletes it.
People you already supervise
A supervisor can invite the practitioners they already work with by giving us their names and email addresses. We email each person once, on the supervisor’s behalf, saying who invited them and where their details came from. If they do not join within 30 days, we delete what we were given.
Bookings and payments
Which sessions you book, whether they went ahead, and the record of hours that produces. Payment is handled by Stripe. Your card details go to Stripe and never pass through us; what we hold is a reference to your Stripe record. If you are a supervisor, Stripe also holds your payout details and whatever identity information Stripe needs to pay you. We issue the supervisor’s invoice to the practitioner on the supervisor’s behalf, and our own invoice for our booking fee.
Video sessions
Sessions happen over video inside Supriva. We record who joined and when, so that a session counts. We do not record audio or video, and we do not transcribe sessions.
Support
When you write to support@supriva.com.au, your message and our replies are held in our email.
The waitlist
An email address, and nothing else, so we can tell you when Supriva opens.
Automatically
Our servers keep logs of requests for 90 days, including the address your device connects from and the pages you asked for. Anything that would identify you in a web address, such as an email address or a one-time link, is removed before it is written. We set five cookies, all of which the site needs to work: one that keeps you signed in, one that protects forms from forgery, one that records a paused sign-in, one that remembers for a day that you arrived through a supervisor’s link, and one that remembers which part of your dashboard you were last looking at. We run no analytics and set no tracking cookies.
Sensitive information
The Privacy Act treats some information more strictly, and it reaches this policy in two forms.
Your registering body membership. The Act’s category is membership of a professional association. We collect it with your consent, as a step of its own, because checking it is how a supervisor becomes findable and how we know which rules apply to you.
Preferences that imply something. A preference for a faith-informed or LGBTQIA+ affirming supervisor is not a fact about you, but it can suggest one. We collect these preferences only if you offer them, use them only in matching, show them to nobody, and never combine them with anything else.
Supervision discusses clinical work, and those conversations stay between the people in the session. We do not record, transcribe or keep any part of what is said, so we collect no health information about you, or about anybody you work with.
How we use your information
We use what we collect to run your account; to check your registration; to work out your supervision requirement and record hours towards it; to show practitioners the supervisors who fit what they have told us about their practice; to take bookings and collect payment on the supervisor’s behalf; to run sessions; to keep your record of supervision; to answer you; and to keep the platform safe.
Two things we do not do. We do not decide whether your hours meet your requirement. We record the supervision you book through Supriva and report it towards your requirement; whether your registering body accepts those hours is their decision. We do not recommend supervisors. We show you who fits what you told us, and we check the registration and insurance details supervisors give us. The choice is yours.
We will send you messages about your account, your sessions and your record, which you cannot opt out of while you have an account. We will also send you news about Supriva and invitations to the community events we run, and every one of those carries an unsubscribe. We never share your information for anyone else’s marketing, and we never sell it.
Who sees your information
The people you work with Australia
A supervisor sees a practitioner’s name, contact details, date of birth, registration, practice details and record of sessions with them. A practitioner sees a supervisor’s public profile and their sessions together. You are in a supervision relationship, and this is what holding one takes.
Stripe United States
Payment and payout details, and the identity information Stripe requires of the people it pays. Stripe handles payments.
Amazon Web Services Sydney
Everything we hold, since our systems run there, including the services that host video, read insurance certificates and draft profile text. The region we use is in Sydney, and the services that process the most sensitive material are pinned to it.
Google United States
The address of your practice, if you offer in-person sessions, which we send to Google to check. The email address you sign in or connect a calendar with, as a hint to Google’s sign-in page. Email you exchange with our team, since our own email runs on Google Workspace. When you sign in with Google or connect a Google calendar, information flows the other way: Google tells us your name and email, or when you are busy.
Microsoft United States
Only the email address you connect an Outlook calendar with, as a hint to Microsoft’s sign-in page. The calendar itself flows from Microsoft to us, and we keep only the busy times. We send Microsoft nothing else about you.
Your registering body Nothing
We read their public registers. We send them nothing about you.
Regulators and courts Australia
What the law requires, when it requires it.
Our staff can see what they need to do their jobs. One internal tool lets our team resolve a registration number against our copy of the public registers when reviewing a registration claim; it returns the register’s own public page, never a name.
Information that leaves Australia
Stripe holds information about you in the United States. Google holds the practice address we send it to check, and the email our team exchanges with you, since our own email runs on Google Workspace. Microsoft holds nothing about you from us beyond the email address you connect a calendar with; the calendar itself is already theirs.
For each of them we take reasonable steps so that they handle information in line with the Australian Privacy Principles, principally through their contracts with us and their published privacy commitments. The Amazon Web Services region we use is in Sydney, and the services that process the most sensitive material, video and the AI that reads certificates and drafts profile text, are all pinned there and never send data elsewhere to balance load.
How we protect it
Your information is encrypted in transit and at rest. Our systems run in Australia, access is limited to the people who need it and is logged, and we keep those logs so that if something goes wrong we can find out what. Credentials you give us for your calendar or practice system are encrypted with a key held separately from the data.
We never store your password. What we keep is a scrambled form that cannot be turned back into the original, so there is nothing for anyone to read, including us. Nobody at Supriva can look up your password or tell you what it is; if you have forgotten it, we can only help you set a new one.
We have a written data breach response plan. If a breach is likely to cause you serious harm, we will tell you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
How long we keep it
| Information | Kept for |
|---|---|
| Your account and profile | While your account is open, and 30 days after you close it, then deleted or de-identified. |
| Your record of supervision sessions and hours | Exported to you when you close your account, then kept for seven years, then deleted. Seven years is the period your registering body or a court may ask about. |
| Insurance readings and registration-check evidence | With the record, for seven years. |
| Payment and invoice records | Five years, as tax law requires. |
| Calendar and practice-system credentials, and busy times | Until you disconnect, which deletes them. |
| Details of people you invited who did not join | 30 days. |
| Waitlist addresses | Until you open an account, or twelve months after Supriva opens. |
| Server logs | 90 days. |
| Backups | 14 days. |
Seeing and correcting your information
Most of what we hold about you is on your dashboard and your profile, and you can change most of it there yourself.
For everything, your account will include an export that gives you a complete copy of what we hold, in a form you can read and a form another system can read. Because it is yours, it is free.
For anything you cannot see or change yourself, write to the Privacy Officer at privacy@supriva.com.au from the address on your account. We will confirm the request is yours before acting on it, and we will answer within 30 days. If you have closed your account, write from the address it was registered under; your record of supervision outlives your account and you can still have a copy.
If we correct something, we will tell you. If we decline a request, we will tell you why in writing, and how to complain.
If you are a practitioner’s client
You are never on Supriva, and we never know who you are. Your practitioner may discuss their work with you in supervision, which is a requirement of their profession and exists to protect you. We do not record or transcribe sessions, so nothing said in one is held by us. If you have a question about information a practitioner has discussed about you, your practitioner is the right person to ask first. If you believe Supriva holds information about you, write to privacy@supriva.com.au and we will look.
If you are on a public register
ACA and PACFA publish registers of their supervisors. To check that a supervisor on Supriva is who they say they are, we keep a copy of the smallest part of those registers that answers that question: the body, the registration number, the state, whether the person is listed as a supervisor, the address of their public register page, and their name held only in a scrambled form we cannot reverse.
We hold no email address, phone number or practice address from the registers, we never use the copy to contact anyone, and we refresh it from the registers themselves. If you are on a register and have never used Supriva, that is all we hold about you. The register is the source; if you think our copy is wrong, tell us, and we will check it against the register.
Complaints
If you think we have mishandled your information, write to the Privacy Officer at privacy@supriva.com.au. We will acknowledge your complaint, look into it, and reply within 30 days. If you are not satisfied with our answer, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Changes to this policy
When we change this policy we update the date at the top. We keep every earlier version, and you can ask us for the one that applied on any given day. If a change affects how we use information you have already given us, we will tell you before it takes effect.
Contact
Privacy Officer, Supriva Pty Ltd, privacy@supriva.com.au.
The terms for the public parts of this site are the website terms of use.