{"id":28,"date":"2026-08-14T15:39:36","date_gmt":"2026-08-14T15:39:36","guid":{"rendered":"https:\/\/healthcarenotes.org\/?page_id=28"},"modified":"2026-08-14T15:39:36","modified_gmt":"2026-08-14T15:39:36","slug":"privacy","status":"publish","type":"page","link":"https:\/\/healthcarenotes.org\/?page_id=28","title":{"rendered":"Privacy Policy"},"content":{"rendered":"\t\t<article class=\"fn-public-page fn-policy-page\">\n\t\t\t<header class=\"fn-page-hero\"><span>FLOOR NOTES POLICY<\/span><h1>Privacy Policy<\/h1><p>This policy explains how Floor Notes collects, uses, discloses, secures and gives access to personal information connected with floornotes.org.<\/p><div class=\"fn-policy-meta\"><span>Effective 14 August 2026<\/span><span>Version 2.0.0<\/span><span>Applies to floornotes.org<\/span><\/div><\/header>\n\t\t\t<div class=\"fn-policy-layout\">\n\t\t\t\t<nav class=\"fn-policy-toc\" aria-label=\"On this page\"><b>On this page<\/b><a href=\"#fn-policy-1\">Scope and privacy approach<\/a><a href=\"#fn-policy-2\">Information we collect<\/a><a href=\"#fn-policy-3\">Payment information<\/a><a href=\"#fn-policy-4\">Clinical workspace boundary<\/a><a href=\"#fn-policy-5\">Why we use information<\/a><a href=\"#fn-policy-6\">Disclosure and service providers<\/a><a href=\"#fn-policy-7\">Retention and security<\/a><a href=\"#fn-policy-8\">Access, correction and choices<\/a><a href=\"#fn-policy-9\">Privacy complaints and changes<\/a><\/nav>\n\t\t\t\t<div class=\"fn-policy-body\">\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-1\">\n\t\t\t\t\t\t\t<h2>Scope and privacy approach<\/h2>\n\t\t\t\t\t\t\t<p>Floor Notes is operated by the Australian business operating Floor Notes. This policy applies to visitors, members, group administrators, contributors and people who contact us.<\/p><p>Floor Notes is designed as a professional education and workflow-support platform. It is not intended to collect patient records. Users must not enter patient names, dates of birth, addresses, record numbers, photographs or other identifying clinical information.<\/p>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-2\">\n\t\t\t\t\t\t\t<h2>Information we collect<\/h2>\n\t\t\t\t\t\t\t<p>We collect only information reasonably needed to provide and administer the service.<\/p>\t\t\t\t\t\t\t<ul><li>Account information, including name, email address, role and login credentials protected by WordPress.<\/li><li>Membership and entitlement information, including Stripe customer and subscription identifiers, plan, status and paid-period dates.<\/li><li>Profile preferences such as state, hospital name, ward, role and experience level.<\/li><li>Support, complaint, accessibility and contributor correspondence that you choose to send.<\/li><li>Security and technical records such as IP address, browser information, timestamps, error records and rate-limit events produced by hosting or security systems.<\/li><li>Learning records you intentionally save, including the activity, time claimed and reflective notes.<\/li><\/ul>\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-3\">\n\t\t\t\t\t\t\t<h2>Payment information<\/h2>\n\t\t\t\t\t\t\t<p>Payments are completed through Stripe Checkout. Floor Notes does not receive or store full card numbers, card security codes or digital-wallet credentials. Stripe may provide limited transaction information such as payment status, card brand, last four digits, billing country and invoice identifiers.<\/p><p>Stripe handles payment information under its own privacy and security terms. Payment methods displayed at checkout depend on Stripe configuration, customer location and device eligibility.<\/p>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-4\">\n\t\t\t\t\t\t\t<h2>Clinical workspace boundary<\/h2>\n\t\t\t\t\t\t\t<p>The Floor Notes Dashboard and Shift Lead Toolkit are designed to keep working text in the active browser session. This package does not intentionally save clinical drafts to WordPress, browser local storage, analytics or an external clinical system.<\/p><p>Temporary display can still involve handling information. Users must therefore use minimum necessary information, avoid identifiers, follow employer directions and close the workspace when finished.<\/p>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-5\">\n\t\t\t\t\t\t\t<h2>Why we use information<\/h2>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<ul><li>Create and secure accounts; confirm entitlement; provide paid modules and group seats.<\/li><li>Process checkout, invoices, renewals, plan changes, failed-payment recovery and cancellation.<\/li><li>Personalise ward and learning navigation without inferring patient facts.<\/li><li>Respond to support, accessibility, privacy, billing and content-correction requests.<\/li><li>Maintain service security, prevent fraud and investigate misuse.<\/li><li>Meet legal, accounting, tax, dispute and recordkeeping obligations.<\/li><li>Improve aggregate product usability where analytics have been lawfully enabled.<\/li><\/ul>\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-6\">\n\t\t\t\t\t\t\t<h2>Disclosure and service providers<\/h2>\n\t\t\t\t\t\t\t<p>Information may be disclosed to service providers only as reasonably required to operate Floor Notes, including WordPress hosting, Stripe, transactional email, security, backup and professional advisers. Providers may process data outside Australia. Their locations and contractual protections depend on the services configured by the operator.<\/p><p>We do not sell personal information. Group owners can see seat identity and membership assignment; they cannot see another nurse\u2019s password, personal CPD reflection, Dashboard draft or Shift Lead session.<\/p>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-7\">\n\t\t\t\t\t\t\t<h2>Retention and security<\/h2>\n\t\t\t\t\t\t\t<p>We retain account, subscription, transaction and correspondence records only for operational, security, legal and accounting needs. Retention periods vary by record type and applicable law. Expired records should be securely deleted or de-identified where lawful and practical.<\/p><p>Reasonable safeguards include HTTPS, role-based administration, signed Stripe webhooks, server-side secrets, secure password handling, restricted access, backups and logging. No internet service can guarantee absolute security.<\/p>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-8\">\n\t\t\t\t\t\t\t<h2>Access, correction and choices<\/h2>\n\t\t\t\t\t\t\t<p>You may request access to or correction of personal information held about you, subject to lawful exceptions. You may update certain account and billing information directly. Marketing consent can be withdrawn using the unsubscribe method in the message; essential service messages may still be sent.<\/p><p>Send a privacy request to maxillarvundi@gmail.com. We may need to verify identity before acting.<\/p>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-9\">\n\t\t\t\t\t\t\t<h2>Privacy complaints and changes<\/h2>\n\t\t\t\t\t\t\t<p>Privacy concerns are handled under the Complaints and Feedback Policy. If unresolved, eligible individuals may contact the Office of the Australian Information Commissioner.<\/p><p>This policy may be updated when the service, law or data practices change. Material changes will be identified by a new effective date and, where appropriate, communicated to members.<\/p>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t<section class=\"fn-policy-references\"><h2>Authoritative references<\/h2><ul><li><a href=\"https:\/\/www.oaic.gov.au\/privacy\/australian-privacy-principles\" target=\"_blank\" rel=\"noopener noreferrer\">Australian Privacy Principles \u2197<\/a><\/li><li><a href=\"https:\/\/www.oaic.gov.au\/privacy\/privacy-guidance-for-organisations-and-government-agencies\/health-service-providers\/guide-to-health-privacy\" target=\"_blank\" rel=\"noopener noreferrer\">OAIC Guide to Health Privacy \u2197<\/a><\/li><\/ul><\/section>\t\t\t\t\t<section class=\"fn-policy-contact\"><h2>Contact<\/h2><p>Questions about this policy can be sent to <a href=\"mailto:maxillarvundi@gmail.com\">maxillarvundi@gmail.com<\/a>. Do not include patient information.<\/p><\/section>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/article>\n\t\t\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-28","page","type-page","status-publish","hentry"],"brizy_media":[],"_links":{"self":[{"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=\/wp\/v2\/pages\/28","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=28"}],"version-history":[{"count":0,"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=\/wp\/v2\/pages\/28\/revisions"}],"wp:attachment":[{"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=28"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}