Privacy Policy

Niche Dental (ABN 27 284 318 084). Effective 18/08/2026.

 

1. About this policy

Niche Dental (ABN 27 284 318 084) (“Niche Dental”, “we”, “us”) is an Australian consultancy providing infection prevention and control, clinical governance, accreditation, radiation safety and education services to dental practices and organisations. This policy explains how we collect, use, hold and disclose personal information, and how you can contact us about it.

We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). Where a state or territory health records law applies to information we hold on behalf of a client practice, we handle that information in line with the client’s obligations under that law and the terms of our engagement with the client.

 

2. What personal information we collect

The kinds of personal information we collect depend on how you deal with us.

If you contact us or make an enquiry:

  • Your name, organisation, role, email address and phone number.
  • The content of your enquiry and any information you choose to include.

If you enrol in an online course or attend training:

  • Your name, email address, organisation and role.
  • Course enrolment, progress and completion records, and the details needed to issue a CPD certificate in your name.
  • Payment details, which are collected and processed by our payment provider. We do not store full card numbers.
  • Feedback, survey responses and testimonials you choose to give us.

If you subscribe to updates:

  • Your name, email address and organisation, and records of which emails you open or click so we can keep our updates relevant.

If your practice or organisation engages Niche Dental for advisory, review, document or accreditation work:

  • Contact details of the people we work with in your organisation.
  • Information about your practice provided for the purpose of the engagement. This can include staff training and competency records, immunisation and exposure records, incident and complaint records, audit findings, photographs of clinical areas, and equipment and process records.
  • Occasionally, information about patients where a practice provides it to us for a specific purpose, for example reviewing an incident. We ask practices to de-identify patient information wherever possible.

If you speak at, host or attend an event with us:

  • Your name, role, organisation, contact details and dietary or access requirements you provide.

If you visit our website:

  • Technical information such as your IP address, browser type, device, pages visited and time on site, collected through cookies and analytics tools described in section 7.

 

3. How we collect it

We collect personal information directly from you when you complete a form on our website, enrol in a course, email or call us, sign an engagement, attend a session or subscribe to updates. We collect information about your organisation from you and from people you authorise, and from publicly available sources such as your practice website or Ahpra register where that is needed for an engagement. We use cookies and analytics tools to collect website usage information automatically.

 

4. Why we collect and use it

We collect, hold and use personal information to:

  • Respond to your enquiry and provide the services or courses you have asked for.
  • Deliver, record and certify training, including issuing CPD certificates.
  • Carry out advisory, review, document and accreditation engagements for client practices and organisations, and provide reports and deliverables to them.
  • Process payments and keep accounting and tax records.
  • Send you course information, regulatory updates and news about our services where you have subscribed or would reasonably expect it. You can unsubscribe at any time using the link in every email.
  • Improve our website, courses and services.
  • Meet our legal obligations and manage our business, including insurance and dispute resolution.

We do not sell personal information. We do not share client or enquiry information with product or equipment suppliers, and we do not have commercial arrangements with suppliers that involve your information.

 

5. Who we disclose it to

We disclose personal information only where it is needed to do the things described above, where you have agreed, or where the law requires it. This includes:

  • People in your own organisation who are part of the enquiry or engagement.
  • Service providers who help us run our business, listed in section 6.
  • Professional advisers such as our accountant, lawyer and insurer, where relevant.
  • Regulators, courts or other bodies where the law requires it.

Information a client practice provides to us for an engagement is treated as confidential. We do not disclose it to any other client, supplier or third party without the practice’s agreement, other than to the service providers below or where the law requires.

 

6. Service providers and overseas disclosure

We use trusted third party providers to run our website, courses, communications and administration. Some of these providers store information outside Australia. By providing personal information to us you acknowledge that it may be stored or processed by the providers below in the countries indicated. We take reasonable steps to ensure each provider protects information to a standard consistent with Australian privacy law.

  • Thinkific (Canada): online course platform, enrolments, progress records and certificates.
  • Brevo (European Union): email updates and course communications.
  • Zapier (United States): automation between our systems.
  • Google Workspace and Microsoft 365 (data may be stored in Australia, the United States or other regions): email, documents and calendar.
  • Dropbox (United States): document storage for engagements.
  • FreshBooks (Canada): invoicing and accounting.
  • Stripe and PayPal (United States): payment processing.
  • GoDaddy (United States) and WordPress: our website and contact form.
  • Google Analytics (United States): website usage analytics.
  • Trello (Atlassian, United States): project and task management for engagements.
  • Anthropic’s Claude (United States): AI assistant used to help draft documents and analyse information provided by clients. Information shared with this service is not used to train the provider’s models.

 

7. Cookies and analytics

Our website uses cookies and similar technologies to make the site work, remember your preferences and understand how visitors use the site. Analytics information is aggregated and does not identify you personally. You can set your browser to refuse cookies or to alert you when cookies are being sent, though some parts of the site may not work as intended if you do. Our website may contain links to other sites; we are not responsible for the privacy practices of those sites.

 

8. How we hold and protect information

We hold personal information in secure cloud services protected by access controls, multi-factor authentication and encryption in transit. Access is limited to Kylie Robb and any contractor working on a specific engagement under a confidentiality obligation. Photographs and records collected during onsite reviews are stored in the engagement folder for that client and are not published or shared. We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

 

9. How long we keep it

We keep personal information for as long as we need it for the purpose it was collected, and for as long as the law requires. As a guide, enquiry records are kept for two years, course and CPD records for seven years so certificates can be re-issued, engagement records for seven years, and accounting records for seven years. We retain records beyond these periods where they remain relevant to an ongoing client relationship, a professional obligation or a potential claim. Where information is no longer needed for any purpose, we may delete or de-identify it.

 

10. Access and correction

You can ask to access the personal information we hold about you, or ask us to correct it, by contacting us using the details in section 13. We will respond within a reasonable time, usually 30 days. There is no charge to make a request. If we cannot give you access or make a correction we will tell you why. Course participants can also view and update their own details by logging in to the course platform.

 

11. Complaints

If you have a concern about how we have handled your personal information, please contact us first using the details in section 13. We take complaints seriously and will respond within 30 days. If you are not satisfied with our response you can contact the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.

 

12. Changes to this policy

We may update this policy from time to time. The current version will always be published on this page with its effective date.

 

13. Contact us

Kylie Robb, Founder and Managing Director

Niche Dental (ABN 27 284 318 084)

PO Box 14, Sans Souci NSW 2219, Australia

Email: kylie.robb@niche.dental

Phone: 0438 628 664