top of page

Privacy Policy

Mind Logistics Psychology & Performance and The Business Psychologist

Effective date: Version 1.0 · effective 1 October 2026

Responsible entity: Tenneile Manenti (sole trader), ABN 47 609 195 852

Privacy contact: Tenneile Manenti, Privacy Officer · hello@mindlogistics.com.au · 0481 326 463 · G6/9 Bay Street, Southport QLD 4215

Our commitment


We recognise that people share personal, workplace and sometimes highly sensitive information with us. We are committed to handling that information lawfully, respectfully and transparently, and to maintaining professional confidentiality while providing practical psychological, coaching and organisational services.

1. About this Policy

This Privacy Policy explains how Tenneile Manenti (ABN 47 609 195 852) trading as Mind Logistics Psychology & Performance and The Business Psychologist (we, us or our) collects, holds, uses, discloses, secures and otherwise manages personal information.

It applies to clinical psychology, individual support, performance coaching, executive and leadership services, workplace and organisational psychology, psychosocial risk services, workshops, training, speaking, assessments, website interactions and related administration.

We handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, applicable health and other laws, and the professional standards and obligations applying to registered psychologists, including the Code of conduct for psychologists.

This Policy is a general statement of our information-handling practices. A more specific collection notice, consent form, Scope of Works or participant information document may apply to a particular service. If those documents provide more specific information about a collection, they should be read with this Policy.

2. Our service environments

Mind Logistics provides individual and clinical psychology services. The Business Psychologist provides coaching, workplace and organisational psychology, psychosocial risk and business advisory services. The Business Psychologist currently operates as an operating division of Mind Logistics, under the same responsible entity identified above.

Although the same psychologist or related personnel may work across both service environments, clinical and organisational services are maintained as separate engagements and, where practicable, through separate systems, permissions and records. Information is not routinely transferred between those service environments merely because they are related or use the same Practitioner. A transfer requires consent or another lawful basis and must be professionally appropriate.

3. Personal information we collect and hold

The kinds of information we collect depend on the service and the person’s relationship with us. They may include:

  • identity and contact information, including name, date of birth, address, email address, telephone number and emergency contact details;

  • business, employment and professional information, including role, employer, employment history, qualifications, responsibilities and workplace relationships;

  • billing, payment, booking and attendance information;

  • communications, enquiries, complaints, feedback and correspondence;

  • clinical, health and sensitive information, including physical and mental health information, symptoms, diagnoses, treatment history, disability, psychological injury, medication and risk or safety information;

  • information about racial or ethnic origin, religious beliefs, sexual orientation, criminal history, professional memberships or other sensitive matters where relevant and lawfully collected;

  • coaching goals, session information, professional observations, working notes and agreed actions;

  • survey responses, interview material, assessment information, psychometric results, reports and test-related information;

  • workplace, team, cultural, psychosocial hazard, incident and organisational information;

  • information supplied by a client, employer, referrer, insurer, treating practitioner, representative, support person or other authorised source;

  • website, device and technical information, including IP address, browser type, cookies and website activity; and

  • images, audio, video or transcripts only where their collection is lawful, necessary and appropriately consented to.

We may hold opinions and professional assessments about an individual. Information collected in the course of providing a health service may be health information and therefore sensitive information under the Privacy Act.

4. How we collect information

We usually collect personal information directly from the individual through enquiries, intake forms, consent documents, appointments, assessments, surveys, sessions, workshops, emails, telephone calls, videoconferencing, our website and other interactions.

We may also collect information from:

  • a business Client that nominates a Participant for a service;

  • an employer, manager, colleague or organisational representative;

  • a referrer, GP, psychologist, medical practitioner or other service provider;

  • an insurer, rehabilitation provider, lawyer, regulator or government agency;

  • a parent, guardian, authorised representative or support person;

  • publicly available sources where collection is lawful and relevant; and

  • third-party assessment, booking, payment, communication and technology providers.

When we collect information from another person, we take reasonable steps to notify the individual of the collection and relevant matters at or before our first substantive contact, or as soon as reasonably practicable. The precise collection notice may depend on the service and the sensitivity of the information.

5. Information provided about Participants

Where a business Client gives us a Participant’s contact information, the Client is expected to be authorised to provide it and to have informed the Participant that we may contact them. We may use the information to:

  • provide information and consent documents;

  • make direct contact with the Participant;

  • arrange and confirm appointments, assessments, workshops or other activities;

  • administer participation and communicate about the engagement; and

  • provide the agreed service and maintain appropriate professional and administrative records.

The Client’s provision of Participant information does not authorise us to add the Participant to a marketing list or use their information for unrelated promotional activities. Any marketing consent must be obtained directly from the Participant where required.

6. Why we collect, hold, use and disclose information

We collect, hold, use and disclose personal information where reasonably necessary for our functions and activities, including to:

  • respond to enquiries and determine an appropriate service pathway;

  • provide clinical, coaching, assessment, organisational, workplace, training, speaking and advisory services;

  • arrange appointments and communicate with Clients and Participants;

  • obtain and document informed consent and agreed confidentiality or reporting arrangements;

  • conduct assessments, surveys, interviews and consultations and prepare agreed reports or recommendations;

  • manage clinical, safety, risk, mandatory reporting and emergency issues;

  • administer accounts, payments, refunds, debt recovery, contracts and records;

  • manage quality, complaints, supervision, professional consultation, insurance and legal obligations;

  • maintain, secure, improve and troubleshoot our systems and services;

  • comply with law, professional obligations, court orders and regulatory requirements; and

  • conduct direct marketing only where permitted and with the consent required by law.

We will not use or disclose personal information for an unrelated purpose unless the individual has consented or the use or disclosure is otherwise required or authorised by law.

7. Business Clients, Participants and reporting

In an employer-funded or organisation-funded engagement, the contracting Client and the individual Participant may be different people. Payment by a business does not, by itself, entitle that business to private session content, professional notes, raw assessment data or unrestricted information about the Participant.

Before the service begins, we aim to identify and explain:

  • the purpose of the engagement;

  • whether participation is voluntary, directed or otherwise required;

  • the information we expect to collect;

  • who will receive information or reports;

  • whether attendance, goals, progress, themes, assessment outcomes or other information may be reported;

  • what will remain private; and

  • the intended use and limitations of any report or output.

If the Client seeks a material change to the purpose or reporting framework, we may require a revised agreement and fresh Participant information or consent before proceeding.

8. Professional confidentiality and disclosure

Psychologists and other personnel must respect privacy and confidentiality in accordance with applicable law and professional obligations. Confidential information may be used or disclosed where:

  • the individual has given informed consent;

  • the use or disclosure is within the agreed service and reporting framework;

  • disclosure is required or authorised by law, court order or compulsory process;

  • a mandatory reporting obligation applies;

  • use or disclosure is permitted to address a serious threat or other safety concern;

  • confidential professional supervision, consultation, insurance or legal advice is reasonably required; or

  • the information has been properly de-identified and its use is otherwise lawful and professionally appropriate.

We take care to disclose only information reasonably necessary for the relevant purpose. Group sessions and workshops involve additional confidentiality risks because other participants may hear information. We may establish ground rules but cannot guarantee another participant’s conduct.

9. Who we may disclose information to

Depending on the service and lawful authority, recipients may include:

  • the individual and their authorised representative;

  • the contracting Client within the agreed reporting framework;

  • our practitioners, employees, contractors and administrative personnel who need access for their work;

  • professional supervisors and consultants;

  • referrers, treating practitioners and other service providers with consent or another lawful basis;

  • assessment publishers and platform providers;

  • technology, cloud hosting, client management, booking, payment, communication, transcription and document service providers;

  • accountants, auditors, insurers, lawyers, debt recovery providers and other professional advisers;

  • courts, tribunals, regulators, government agencies, law enforcement and emergency services where required or authorised; and

  • a purchaser or successor in connection with a proposed restructuring or transfer of the practice, subject to appropriate confidentiality, privacy and professional safeguards.

Our service providers are expected to handle personal information only for authorised purposes and with appropriate confidentiality, security and privacy protections.

10. Assessments and psychometric information

Assessment information may include personal and sensitive information, responses, scores, professional interpretations and restricted test materials. We use assessment information only for the purpose explained in the relevant Scope, consent document or collection notice.

Test questions, scoring keys, manuals, raw data and restricted materials may be owned or licensed by third-party publishers. Access or disclosure may be limited where reasonably necessary to protect test security, comply with professional obligations or licence conditions, or avoid a serious threat, subject to applicable legal rights. Where direct access cannot appropriately be given, another lawful access arrangement may be discussed.

Unless separately agreed and professionally appropriate, an assessment result should not be treated as the sole basis for recruitment, promotion, remuneration, discipline, termination, fitness-for-work or another significant employment decision.

11. Service quality, feedback and training

We may use information relating to the administration and delivery of services to monitor and improve service quality. This may include inviting a Client or Participant to provide voluntary feedback. Participation is optional and will not affect access to or receipt of services.

We may use properly de-identified and aggregated information for internal professional development, supervision, training and service improvement, provided that Clients and Participants are not reasonably identifiable and confidential business information is not disclosed.

Identifiable information, recordings, quotations, case material, assessment results or feedback will not be used for training, promotional material, testimonials or case studies without separate express written consent from each affected person.

12. Direct marketing

We may send information about services, resources, events or updates only where permitted by the Privacy Act, Spam Act 2003 (Cth) and other applicable laws. Where information is sensitive, or where the person would not reasonably expect marketing, we will obtain the individual’s consent before using the information for direct marketing.

Consent to receive a service is not consent to receive marketing. Marketing consent is optional and will not affect access to services. Each electronic marketing message will identify the sender and provide a simple means to unsubscribe. We will action an unsubscribe request within the period required by law.

We do not use Participant details supplied by an employer or other business Client for marketing unless the Participant separately consents.

13. Recordings, images and transcripts

We do not audio-record, video-record, photograph, transcribe or monitor a private session, meeting, assessment or workshop unless the collection is lawful, reasonably necessary and the affected people have been appropriately informed and have given any consent required. A specific consent may explain the purpose, access, storage, retention, proposed use and withdrawal arrangements.

A Client or Participant must not record, transcribe or monitor a service without the prior informed consent of the Practitioner and every affected person.

14. Artificial intelligence and automated tools

We may use technology or artificial intelligence tools to support authorised administration, analysis or drafting. We remain responsible for professional judgment and take reasonable steps to handle personal and sensitive information consistently with privacy, confidentiality, security and professional obligations.

We do not permit automated output to replace professional assessment or judgment. We do not currently arrange for a computer program to make a decision solely or substantially about an individual that could reasonably be expected to significantly affect that individual’s rights or interests. If our practices change, we will review and update this Policy and provide any notice required by law.

15. Website, cookies and online services

Our website and online services may use cookies, analytics and similar technologies to operate the website, remember preferences, understand general usage and improve content. These technologies may collect device, browser, IP address and activity information. Our website is hosted on Wix, which uses cookies necessary to operate the site, and we use Google Analytics to understand general website usage. Visitors can manage or block cookies through their browser settings. [CONFIRM: whether a cookie preference banner is enabled on the Wix site.]

Links to third-party websites are provided for convenience. We are not responsible for the privacy practices of third parties and encourage individuals to review their policies.

16. Overseas disclosures and cloud services

Some technology, assessment, communications or cloud providers may store or process information outside Australia or permit support access from overseas. Before using an overseas provider or disclosing personal information overseas, we take reasonable steps appropriate to the circumstances and consider our obligations under APP 8.

Likely overseas recipient countries: United States and member states of the European Union. [CONFIRM BEFORE PUBLICATION: data location for OBM Hub (GoHighLevel platform) — awaiting Brian; and that Zanda and Medical Objects store data in Australia.]

The location of a provider or its data centres may change. We will keep this section under review and update the Policy where our likely overseas disclosures materially change.

17. Security and storage

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include:

  • role-based access controls and separation of clinical and organisational records where practicable;

  • password protection, multi-factor authentication, encryption and secure transmission where appropriate;

  • secure practice management, client relationship management and cloud systems;

  • physical security for paper records and devices;

  • confidentiality obligations, staff training and supervision;

  • vendor due diligence and contractual protections;

  • backups, software updates, monitoring and incident-response processes; and

  • secure destruction or de-identification when information is no longer required.

No method of electronic transmission or storage is completely secure. Individuals should avoid sending highly sensitive information through an insecure channel and should promptly tell us if they suspect a relevant communication or account has been compromised.

18. Retention and destruction

We retain professional and administrative records for as long as reasonably necessary for the purpose collected and for the periods required by law, professional standards, insurance requirements, contractual obligations and legitimate practice needs. Different periods may apply to clinical records, organisational records, assessment materials, financial records and records relating to children.

Confirmed retention schedule: Clinical records are retained for at least seven years after the last contact with the client, consistent with professional obligations for psychologists. We do not provide services to people under 18. Financial and administrative records are retained for the periods required by law, including tax record-keeping requirements.

When information is no longer required and we are not legally or professionally required to retain it, we take reasonable steps to destroy it securely or de-identify it. Backup and archival copies may persist for a limited period until securely overwritten or destroyed in accordance with system cycles.

19. Access to personal information

An individual may request access to personal information we hold about them. A request may be made using the contact details at the end of this Policy. We may ask for proof of identity or authority before providing access.

We will respond within a reasonable period. Access may be refused or limited where permitted or required by law, including where access would have an unreasonable impact on another person’s privacy, reveal commercially sensitive evaluative information, compromise test security, be unlawful, prejudice an investigation or pose a serious threat. If access is refused, we will generally give written reasons and available complaint options, unless it would be unreasonable or unlawful to do so.

We will not charge for making an access request. If permitted by law, we may charge a reasonable amount for giving access after discussing the likely cost. Access to professional records is distinct from ownership of copyright, working papers or assessment materials.

20. Correction of personal information

An individual may ask us to correct personal information they believe is inaccurate, out of date, incomplete, irrelevant or misleading. We may also take reasonable steps to correct information on our own initiative.

Where we do not agree that a correction is required, the individual may ask us to associate a statement with the record explaining their position. We will respond and provide reasons and complaint options as required by law.

21. Data breaches

We maintain processes to identify, contain, assess and respond to suspected privacy or security incidents. Where a data breach is likely to result in serious harm and the Notifiable Data Breaches scheme applies, we will notify affected individuals and the Office of the Australian Information Commissioner as required. We may also notify professional regulators, insurers, law enforcement or other bodies where required or appropriate.

22. Privacy enquiries and complaints

A person may contact us with a privacy question or complaint using the details below. Please provide enough information for us to understand the concern. We will acknowledge and investigate the matter, may seek further information, and aim to provide a response within 30 days or otherwise within a reasonable period.

Privacy Officer: Tenneile Manenti, Privacy Officer

Email: hello@mindlogistics.com.au

Telephone: 0481 326 463

Postal address: G6/9 Bay Street, Southport QLD 4215

If the person is not satisfied with our response, they may complain to the Office of the Australian Information Commissioner at www.oaic.gov.au. Concerns about the professional conduct of a registered psychologist may also be raised with the appropriate health complaints entity or Ahpra, depending on jurisdiction and subject matter. We encourage individuals to contact us first where appropriate so we have an opportunity to address the concern.

23. Anonymity and pseudonyms

Where practicable and lawful, a person may make a general enquiry or interact with us without identifying themselves or by using a pseudonym. We may be unable to provide clinical, assessment, contractual, billing or other professional services without sufficient identifying information.

24. Children and people requiring decision support

Where services involve a child, a person with impaired decision-making capacity or a person requiring communication or decision support, we will consider capacity, authority, consent, confidentiality, the person’s preferences and best interests in accordance with applicable law and professional obligations.

Practice position on services to children: We do not currently provide services to people under 18 years of age.

25. Changes to this Policy

We may update this Policy when our services, systems, providers, legal obligations or information-handling practices change. The current version will be available on our website and will state its effective date. We will provide additional notice where required or where a change materially affects how personal information is handled.

26. Contact us

Tenneile Manenti trading as “Mind Logistics Psychology & Performance” and “The Business Psychologist”

ABN: 47 609 195 852

Address: G6/9 Bay Street, Southport QLD 4215

Email: hello@mindlogistics.com.au

Telephone: 0481 326 463

Website: https://www.mindlogistics.com.au/

bottom of page