Last updated: 28th July 2026

Privacy Policy

Effective date: 28 July 2026
Last reviewed: 28 July 2026

1. Identity of the Business

This Privacy Policy applies to Lisa Jolly, ABN 90 616 895 220, trading as The Parenting Company™ (“The Parenting Company”, “we”, “us” or “our”).

The Parenting Company is operated by Lisa Jolly as a sole trader in Victoria, Australia.

We are committed to managing personal information in an open, transparent and secure manner and in accordance with the privacy laws that apply to our activities, including:

the Privacy Act 1988 (Cth);

the Australian Privacy Principles contained in Schedule 1 to the Privacy Act 1988 (Cth);

the Health Records Act 2001 (Vic) and the Health Privacy Principles, where applicable;

the Spam Act 2003 (Cth); and

any other applicable privacy, health-record, direct-marketing or data-protection requirements.

Nothing in this Privacy Policy is intended to exclude, restrict or modify any right or remedy that cannot lawfully be excluded, restricted or modified.

2. Scope of this Privacy Policy

This Privacy Policy describes how we collect, hold, use, disclose, protect, retain and otherwise handle personal information when an individual:

visits or interacts with our website;

subscribes to our mailing list;

requests or downloads a free resource;

purchases a product, programme, course or service;

books or participates in a consultation, clarity call or other appointment;

completes an intake form, questionnaire, survey or other document;

communicates with us by email, telephone, social media, website form or another channel;

provides a testimonial, review or other content;

attends an event, workshop, webinar or programme; or

otherwise engages with The Parenting Company.

This Privacy Policy should be read together with any applicable collection notice, consent form, service agreement, website terms, terms and conditions or other notice provided at or before the time personal information is collected.

3. Meaning of Personal Information

For the purposes of this Privacy Policy:

Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information is true and whether or not it is recorded in a material form.

Sensitive information includes certain categories of personal information afforded additional protection under Australian privacy law, including health information and information about racial or ethnic origin, religious or philosophical beliefs, sexual orientation, disability or other matters prescribed by law.

Health information includes personal information or an opinion about an individual’s physical, psychological or mental health, disability, health services provided or proposed to be provided, and other information falling within the applicable statutory definition.

References to personal information in this Privacy Policy include sensitive information and health information where the context permits.

4. Personal Information We May Collect and Hold

The nature and extent of personal information collected will depend on the nature of an individual’s interaction with us and the products or services requested.

We may collect and hold the following categories of personal information.

4.1 Identity and contact information

This may include:

full name;

email address;

telephone number;

residential, postal or billing address;

age or date of birth, where reasonably necessary;

preferred method of communication;

emergency contact information, where relevant; and

information required to verify identity.

4.2 Booking, account and transaction information

This may include:

appointment dates and times;

booking and attendance records;

products or services purchased;

account or membership information;

payment status;

billing details;

transaction references;

invoice and receipt information;

refund or cancellation records; and

correspondence relating to purchases or bookings.

Payments may be processed by third-party payment processors.

We do not ordinarily collect or retain complete payment-card numbers, card verification codes or online banking credentials. Those details are generally collected and processed directly by the relevant payment provider.

4.3 Consultation and service information

When an individual books, enquires about or participates in a clarity call, consultation, programme, questionnaire or other service, we may collect information concerning:

parenting concerns, questions and goals;

family and household circumstances;

relationship or co-parenting circumstances;

pregnancy, birth and postnatal experiences;

a child’s age, health, development, behaviour, sleep or wellbeing;

parenting experiences and decision-making;

childhood experiences, upbringing and family patterns;

emotional responses, stressors and triggers;

physical, psychological or emotional wellbeing;

disability, neurodivergence or additional support requirements;

current or previous professional support;

information voluntarily disclosed during a consultation;

intake-form and questionnaire responses;

observations and factual records made during or following a service; and

notes reasonably required for service delivery, continuity, administration, safety or record keeping.

Some of this information may constitute sensitive information or health information.

We seek to collect only information that is reasonably necessary for our functions, activities and the provision of the product or service requested.

4.4 Information concerning children

Our products and services are generally arranged, purchased and managed by adults. However, a parent, guardian or authorised caregiver may provide personal or health information concerning a child where that information is reasonably necessary for the requested service.

Information concerning a child may include:

name or preferred name;

age or date of birth;

developmental information;

health or disability information;

sleep, feeding or behavioural information;

family and caregiving circumstances;

emotional or developmental concerns; and

information relevant to the support requested by the parent or guardian.

We do not knowingly invite children to submit personal information directly through our website without appropriate involvement from a parent, guardian or other authorised adult.

Information concerning children is handled with particular care and is not used for unrelated direct-marketing purposes.

4.5 Information concerning partners and other persons

An individual may provide information concerning a partner, co-parent, family member, child, professional or another person.

Where an individual provides another person’s personal information, the individual should ensure, where reasonably practicable and legally required, that:

the other person is aware that the information is being provided;

the other person has authorised the disclosure;

the information is accurate and relevant; and

there is an appropriate legal basis for providing the information.

Participation in a family or parenting service does not automatically entitle one participant to access information supplied confidentially by another participant.

Where more than one adult participates in a service, we may require each adult to separately acknowledge applicable collection notices and provide any consent required for the collection and handling of sensitive information.

4.6 Website and technical information

When an individual accesses our website, emails or digital resources, we may collect technical and usage information, including:

Internet Protocol address;

browser type and version;

device type and operating system;

approximate location derived from technical information;

dates and times of access;

pages viewed;

links selected;

referral source;

time spent on particular pages;

website navigation and interaction information;

cookie identifiers;

analytics information; and

information concerning interaction with emails or digital content.

4.7 Communications and submitted content

We may collect and retain:

emails;

telephone call records or summaries;

website-form submissions;

social-media messages;

enquiries;

feedback;

complaint information;

survey responses;

reviews and testimonials;

photographs;

audio or video material;

consent records; and

communication and marketing preferences.

We will not publish an identifiable testimonial, client story, photograph, audio recording or video recording without obtaining appropriate permission.

5. How We Collect Personal Information

We generally collect personal information directly from the individual to whom the information relates.

Personal information may be collected when an individual:

completes a website form;

creates an account;

books an appointment;

purchases a product or service;

subscribes to a mailing list;

requests or downloads a resource;

completes an intake form, questionnaire or survey;

participates in a consultation, call, workshop or programme;

communicates with us;

provides feedback or a testimonial; or

interacts with our website, advertisements, emails or online content.

We may also collect personal information from:

a partner, co-parent, parent, guardian or family member;

a person purchasing or arranging a service on another individual’s behalf;

an authorised representative;

a referral source;

a service provider involved in administering a booking, transaction or communication;

publicly available sources, where collection is lawful and reasonably necessary; or

another source where the individual has consented or where collection is otherwise authorised or required by law.

Where we receive unsolicited personal information, we will determine whether the information could lawfully have been collected by us. Where it could not lawfully have been collected and we are not otherwise required to retain it, we will take reasonable steps to destroy or de-identify it.

6. Collection Notices

Where required or appropriate, we may provide a specific collection notice at or before the time personal information is collected.

A collection notice may explain:

the purpose of the collection;

whether collection is required or voluntary;

the consequences of not providing the requested information;

the persons or organisations to whom information may be disclosed;

whether overseas disclosure is likely;

how to access or correct information; and

how to make a privacy complaint.

A collection notice applies in addition to this Privacy Policy. Where there is any inconsistency, the more specific collection notice will apply to the particular collection to the extent of that inconsistency.

7. Anonymity and Pseudonymity

Where lawful and practicable, individuals may communicate with us anonymously or by using a pseudonym.

We may be unable to provide certain products or services anonymously where it is reasonably necessary to:

verify identity;

process a payment;

administer a booking;

maintain an accurate service record;

provide personalised support;

respond to a complaint or access request;

manage safety concerns; or comply with a legal, insurance, taxation, professional or regulatory obligation.

8. Purposes for Which Personal Information Is Handled

We may collect, hold, use and disclose personal information for the purposes for which it was collected and for related purposes that would reasonably be expected in the circumstances.

These purposes may include:

providing consultations, educational resources, programmes, courses, digital products and other services;

assessing whether a requested service is appropriate;

understanding an individual’s circumstances and the support sought;

administering bookings and appointments;

processing purchases, payments, invoices, credits and refunds;

communicating about a booking, transaction, service or account;

preparing for and providing consultations;

maintaining service, consultation and business records;

providing follow-up information or support;

responding to enquiries, requests, complaints or feedback;

sending a resource requested by an individual;

managing subscriptions and communication preferences;

sending direct marketing where consent has been provided or where otherwise permitted by law;

maintaining and improving our website, products, services and resources;

analysing website traffic and engagement;

measuring advertising effectiveness;

maintaining security and preventing fraud, misuse or unlawful activity;

managing legal, accounting, insurance, taxation and administrative requirements;

obtaining professional advice;

managing disputes or legal claims;

protecting the rights, health, safety or wellbeing of clients, children, other persons or The Parenting Company;

complying with applicable laws, regulations, court orders or lawful requests; and

any other purpose disclosed at the time of collection or authorised by the individual.

We will not use or disclose personal information for a materially unrelated purpose unless:

the individual has consented;

the use or disclosure is required or authorised by law;

a permitted general situation or permitted health situation applies;

the use or disclosure is reasonably expected and legally permitted; or another lawful basis exists.

9. Sensitive Information and Health Information

We will collect sensitive information or health information only where:

the individual has provided consent and the information is reasonably necessary for one or more of our functions or activities;

collection is required or authorised by law;

a permitted general situation or permitted health situation applies;

collection is necessary to establish, exercise or defend a legal or equitable claim; or

another lawful basis applies.

Consent may be express or implied where the law permits, although express consent may be sought where the nature of the information or circumstances make this appropriate.

An individual may withdraw consent to future handling that depends on consent by contacting us.

Withdrawal of consent:

does not affect the lawfulness of handling undertaken before withdrawal;

does not require us to destroy information that we are legally required or permitted to retain; and

may affect our ability to provide or continue providing a product or service.

10. Consequences of Not Providing Personal Information

An individual is not required to provide information that is unrelated to the product or service sought.

Where requested information is reasonably necessary, failure to provide it may prevent or limit our ability to:

process a purchase;

administer a booking;

communicate with the individual;

understand the circumstances relevant to a consultation;

provide an appropriate product or service;

maintain required records;

address health or safety concerns; or comply with applicable obligations.

11. Direct Marketing

We may send educational, promotional or other commercial electronic communications where:

the recipient has provided express consent;

consent may lawfully be inferred from an existing relationship and the communication is relevant to that relationship; or

the communication is otherwise permitted by law.

Requesting a free resource, making an enquiry or purchasing a product or service does not, by itself, necessarily constitute consent to receive unrelated ongoing marketing.

Where express marketing consent is requested, we intend to present that consent separately from any consent required to receive the requested product, resource or service.

Commercial electronic messages sent by us will:

accurately identify Lisa Jolly or The Parenting Company as the sender;

include current contact information;

contain a clear and functional unsubscribe facility where required; and

otherwise comply with applicable direct-marketing laws.

An individual may withdraw marketing consent or unsubscribe at any time by:

using the unsubscribe facility contained in the communication; or

emailing [email protected].

We will action an unsubscribe request within five working days or any shorter period required by applicable law.

An unsubscribe request will not prevent us from sending non-marketing communications reasonably necessary to administer an existing booking, transaction, account, legal matter or requested service.

We do not sell, rent or trade personal information to data brokers or third parties for their independent direct-marketing purposes.

12. Disclosure of Personal Information

We may disclose personal information to third parties where reasonably necessary for our functions, activities or the purposes described in this Privacy Policy.

Recipients may include:

website hosts and technical support providers;

online form and questionnaire providers;

booking and calendar providers;

payment processors and financial institutions;

email and communication providers;

cloud-storage and document-management providers;

video-conferencing providers;

course, membership and digital-product platforms;

customer-management systems;

analytics, advertising and website-security providers;

accounting, bookkeeping and taxation advisers;

legal, insurance and other professional advisers;

contractors and consultants performing authorised functions;

regulators, courts, tribunals, law-enforcement bodies and government authorities;

emergency services or relevant professionals where necessary to address a serious threat to health or safety; and

any other person authorised by the individual or permitted by law.

We may also disclose personal information:

with the individual’s consent;

where disclosure is required or authorised by law;

to investigate or respond to suspected fraud, misconduct or unlawful activity;

to establish, exercise or defend legal rights;

in connection with a proposed or actual sale, transfer or restructuring of the business, subject to appropriate confidentiality and legal safeguards; or

where another permitted disclosure applies.

Service providers are given access only to information reasonably necessary to perform the relevant function. We take reasonable steps appropriate to the circumstances to engage providers that offer suitable privacy, confidentiality and information-security protections.

We do not disclose confidential or identifiable consultation information to a partner, co-parent, family member or other professional solely because that person has an involvement in the family.

Any such disclosure requires consent or another lawful basis.

13. Third-Party Service Providers

The service providers we use may change from time to time.

Providers currently used, or expected to be used, include:

Stripe, for payment processing and transaction administration;

Ivorey, including Ivorey Forms and Ivorey Courses, for forms, questionnaires, lead capture, digital products, courses and member content;

Calendly, for booking and appointment administration;

Xero, for accounting, invoicing, bookkeeping and financial records;

Google Analytics, for website traffic measurement and performance analysis;

Meta Pixel, for advertising measurement, conversion analysis and audience insights;

Zoom, for video conferencing and online consultations; and

Google Workspace, including Gmail and Google Drive, for email communications, document storage and file management.

Each provider handles information in accordance with its own terms, privacy policy, security arrangements and applicable legal obligations.

The inclusion of a provider in this Privacy Policy does not mean that every function offered by that provider is enabled or used.

14. Overseas Disclosure and Processing

Some third-party providers may store, process, transmit or permit access to personal information outside Australia.

Overseas recipients or processing facilities are likely to be located in:

the United States of America; and

other jurisdictions in which our service providers or their subcontractors operate data centres, support services or technical infrastructure.

The precise locations may vary over time as providers modify their infrastructure, corporate arrangements or subcontractor relationships.

Where it is practicable to identify additional countries in which overseas recipients are likely to be located, we will update this Privacy Policy or the relevant collection notice.

Before disclosing personal information overseas, we will take reasonable steps appropriate to the circumstances to assess and manage privacy risks and to satisfy applicable cross-border disclosure requirements.

Different privacy and data-protection laws may apply in an overseas jurisdiction. In certain circumstances, those laws may not provide protections equivalent to those available under Australian law.

Where health information is transferred outside Victoria, we will take reasonable steps required by applicable Victorian health privacy law to safeguard that information.

15. Cookies, Analytics and Advertising Technologies

Our website and digital platforms may use cookies, pixels, tags, software development kits and similar technologies.

These technologies may be used to:

operate essential website functions;

maintain website security;

remember user preferences;

understand website traffic;

measure website and content performance;

identify technical errors;

analyse how visitors use our website;

measure email interactions;

measure advertising performance;

attribute website visits or conversions to particular campaigns; and

support audience or advertising functions where lawfully enabled.

The technologies used may include:

essential cookies;

functional cookies;

analytics cookies;

email open and click tracking;

advertising or conversion pixels; and

third-party embedded content.

Where required by law or otherwise appropriate having regard to the nature of the technology and information collected, we may provide a cookie-management or consent mechanism.

Individuals may also manage cookies through their browser or device settings. Restricting cookies may affect the functionality or performance of parts of the website.

We do not intentionally configure advertising or retargeting technologies to collect information entered into consultation intake forms, health questionnaires or forms specifically designed to collect sensitive information.

Information collected through cookies and similar technologies may also be processed by the relevant third-party provider in accordance with that provider’s privacy policy.

16. Online Consultations, Recordings and Transcription

Online consultations may be conducted using Zoom or another video-conferencing provider.

Unless an individual is notified otherwise and appropriate consent has been obtained, consultations are not recorded.

Where recording, transcription or automated note taking is proposed:

the purpose will be explained before the technology is activated;

each adult participant will be informed;

consent will be obtained where required;

access, storage and retention arrangements will be considered;

the involvement of third-party technology providers will be disclosed where appropriate; and

participants will be given an opportunity to raise questions or decline where the proposed use depends on consent.

Participants must not record, transcribe or distribute a consultation without the knowledge and permission of all relevant participants and any other authority required by law.

17. Artificial Intelligence and Automated Processing

We may use artificial intelligence tools for:

general business administration;

content planning;

drafting or organising non-client material;

analysing de-identified information; or

developing educational material from information that does not identify an individual.

We do not knowingly enter identifiable client information, consultation notes, intake forms, health information or sensitive family information into publicly available artificial intelligence tools.

Before using an artificial intelligence, transcription or automated processing provider in connection with personal information, we will consider:

the categories of information involved;

the purpose of the proposed use;

whether the information can be de-identified;

where the information is stored or processed;

who may access it;

whether it may be retained or used to train a model;

the provider’s privacy and security arrangements;

available account and data-control settings;

deletion and retention arrangements;

the risks to affected individuals; and

whether notice or consent is required.

Where reasonably practicable, information will be de-identified before it is used for administrative analysis, educational development or similar purposes.

We do not currently arrange for a computer program to use personal information to make decisions that could reasonably be expected to significantly affect an individual’s rights or interests.

If that practice changes, we will update this Privacy Policy and provide any additional information required by law.

18. Storage and Security

Personal information may be held:

electronically in cloud-based systems;

within email and communication systems;

through booking, payment, accounting or service-delivery platforms;

on password-protected computers or devices;

in secure backups; or

in physical form where reasonably necessary.

We take reasonable administrative, technical and physical steps to protect personal information from:

misuse;

interference;

loss;

unauthorised access;

unauthorised modification; and

unauthorised disclosure.

Security measures may include:

password protection;

multi-factor authentication;

access controls;

secure cloud platforms;

software and device updates;

malware and security protections;

encrypted transmission or storage where available and appropriate;

secure backups;

confidentiality requirements;

restricted contractor access;

secure disposal procedures; and

periodic review of information holdings and provider arrangements.

The nature and extent of security measures will depend on the sensitivity, volume and location of the information and the potential consequences of unauthorised handling.

No electronic transmission or storage system can be guaranteed to be entirely secure. This does not limit our obligation to take reasonable steps to protect personal information.

An individual who believes their information may have been compromised should contact us promptly.

19. Data Breaches

We maintain procedures for identifying, containing, assessing and responding to suspected data breaches.

Where a suspected data breach occurs, we may:

take immediate steps to contain the incident;

investigate the cause and scope of the incident;

identify the information and individuals affected;

assess the likelihood and seriousness of potential harm;

take remedial action;

preserve relevant records and evidence;

review security controls and service-provider arrangements;

obtain legal, technical or professional advice; and

notify affected individuals, the Office of the Australian Information Commissioner, the Victorian Health Complaints Commissioner or another regulator where required or appropriate.

Where the incident constitutes an eligible data breach under the Privacy Act 1988 (Cth), we will comply with the applicable requirements of the Notifiable Data Breaches scheme.

20. Retention, Destruction and De-identification

We retain personal information only for so long as it is reasonably required for:

the purpose for which it was collected;

the provision and administration of products or services;

maintaining appropriate consultation, transaction and business records;

responding to enquiries, complaints or disputes;

managing legal claims;

taxation, accounting, insurance and audit requirements;

professional or regulatory obligations;

applicable limitation periods; and

any other period required or permitted by law.

Where we are required to retain health information as a private health service provider under Victorian law, applicable minimum retention periods may include:

at least seven years after the date on which an adult was last provided with a health service; or

where the individual was under 18 years of age when last provided with the health service, until that individual reaches 25 years of age.

Different retention periods may apply depending on:

the nature of the record;

whether the record concerns an adult or child;

whether the information constitutes a health record;

the capacity in which we collected the information;

taxation or financial-record requirements;

insurance requirements;

legal limitation periods; and any anticipated or existing complaint, investigation or proceeding.

When personal information is no longer required and we are not required or authorised to retain it, we will take reasonable steps to securely destroy it or permanently de-identify it.

Destruction may be delayed where information is contained within a secure backup system and immediate deletion is not reasonably practicable. In those circumstances, the information will remain protected and will not be actively used except where necessary for restoration, security or legal compliance.

21. Access to Personal Information

Subject to applicable legal exceptions, an individual may request access to personal information we hold about them.

A request may be made by contacting the Privacy Officer using the details set out below.

We may require reasonable evidence of identity before providing access.

Depending on the circumstances, access may be provided by:

supplying a copy of the relevant information;

permitting inspection;

providing an accurate summary;

explaining the information; or

providing access through another method agreed with the individual.

We will respond within a reasonable period and aim to provide a substantive response within 30 calendar days, unless a different period applies under relevant health-record or other legislation.

We may refuse or limit access where permitted or required by law, including where access would:

unreasonably affect another person’s privacy;

pose a serious threat to health or safety;

reveal information connected with legal proceedings;

reveal a commercially sensitive evaluative process;

be unlawful;

prejudice an investigation or enforcement activity; or

fall within another applicable exception.

Where access is refused, we will generally provide written reasons and information about available complaint mechanisms, unless it would be unreasonable or unlawful to do so.

We may charge a reasonable fee for providing access where permitted by law. We will not charge merely for making an access request.

22. Correction of Personal Information

An individual may request correction of personal information where they believe it is inaccurate, incomplete, out of date, irrelevant or misleading.

We will take reasonable steps to assess and, where appropriate, correct the information.

Where health information is concerned, correction may involve:

adding an appropriate notation;

attaching a statement supplied by the individual;

ensuring disputed information is not relied upon without relevant context; or

taking another step permitted or required by applicable law.

A correction request does not necessarily require the deletion or alteration of an original professional or factual record where retaining that record is required by law or appropriate record-keeping standards.

If we refuse to make a requested correction, we will generally provide written reasons and information concerning the available complaint process.

Where required, we may notify relevant third parties of a correction previously disclosed to them.

No fee will be charged merely for making a correction request.

23. Privacy Complaints

An individual who believes we have interfered with their privacy or failed to comply with an applicable privacy obligation may submit a complaint to the Privacy Officer.

Complaints should, where possible, include:

the complainant’s name and contact details;

a description of the act or practice complained about;

relevant dates;

copies of relevant communications or documents; and

the outcome sought.

We will:

acknowledge the complaint;

assess whether further information is required;

investigate the matter fairly and objectively;

take reasonable remedial action where appropriate; and

aim to provide a written response within 30 calendar days.

More complex matters may require additional time. Where this occurs, we will seek to inform the complainant of the reason for the delay and the anticipated next steps.

If the complainant is not satisfied with our response, they may be entitled to contact:

the Office of the Australian Information Commissioner; or

the Victorian Health Complaints Commissioner, where the complaint concerns health information or an applicable health service.

The individual may also have other rights or remedies under applicable law.

24. Changes to this Privacy Policy

We may amend this Privacy Policy from time to time to reflect changes to:

our products or services;

our information-handling practices;

the technology or service providers we use;

our legal or regulatory obligations; or

relevant regulatory guidance.

The current version will be published on our website and will state the date on which it was last updated.

Where a material change requires specific notice or consent, we will take reasonable steps to provide that notice or obtain the required consent before undertaking the relevant new handling activity.

We recommend reviewing this Privacy Policy periodically.

25. Contact Details

For privacy enquiries, access or correction requests, withdrawal of consent or privacy complaints, please contact:

Lisa Jolly
Sole trader trading as The Parenting Company™
ABN: 90 616 895 220

Privacy Officer: Lisa Jolly
Email: [email protected]
Telephone: 0488 646 329
Business location: Ocean Grove, Victoria 3226
Australia

View our Privacy Policy and Terms and Conditions here.

© 2026. All Rights Reserved.