Privacy Policy

Sarah O'Brien Nutrition / Privacy Policy


Hi there! This website,, is owned and operated by me, Sarah O’Brien (ABN 71686035881).

If you have any questions or need further information, please email me:

Email address:

This document sets out my Privacy Policy. It describes how I collect and manage your personal information when you interact with this site. I take this responsibility very seriously. If you have any questions or concerns about how your personal information is being handled, please do not hesitate to contact me.

I comply with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth) (Privacy Act).

 I understand that visitors from the EU may access this site, so I also aim to comply with the General Data Protection Regulations (GDPR).

Personal Information

If you engage with me via this website, or choose to become my client I may ask to collect the following kinds of personal information from you, including:

Contact details

  • your name
  • your email address
  • your residential address including the country that you live in
  • your phone or contact number/s

Interests & preferences

  • your opinion about future topics, products or services that may interest you


  • information that allows me to tailor my content to your needs when you sign up for one of my webinars, workshop or promotional events


  • with your consent, I may collect your IP address, and information about your browsing history to help me improve the usability and appeal of my website

Collection and Use


How and when


 I may collect your personal information by various means including:

  • Client engagement ie; new client intake forms and consultation notes/records
    • Refer below re intake forms
  • Emails from you
  • Text messages from you
  • Phone calls from you
  • Signing up for workshops or talking events
  • In person at workshops or talking events
  • Website contact form
  • Via a third party ie; in the case of a referred client, co-managed client, or competition entry/workshop attendee if part of a collaboration with another practitioner/organisation
  • an opt-in form for my mailing list
  • website cookies




I use this information to:

  • provide tailored, individualised and relevant nutrition and educational services as required/at your request ie; via a face to face consultation
  • provide you with relevant news and updates about my services
  • improve this website and the services I provide
  • respond to your enquiries
  • help you to better understand my services
  • monitor visitor and/or client satisfaction
  • improve my services
  • provide more relevant information
  • provide news about my services
  • provide news about developments in nutrition and wellbeing

I will only collect your personal information:




The following legal grounds relating to specifications by the GDPR justify the collection of said information;

  • with your full awareness and consent, such as when you email me, tick a checkbox or fill in a form to provide me/us with information
  • if I need it to provide you with information or services that you request
  • if I/we are legally required to collect it
  • for necessary administrative processes if you become my client
  • if I believe that I can demonstrate a legitimate interest in using your data for marketing purposes, although I will always give you a choice to opt out

Sensitive Information




I understand that some personal information is particularly sensitive.

I will only collect sensitive information by methods that are reasonably secure, such as:

  • face to face ie; during a one on one consultation ie; via case taking notes
  • through my intake form when you book an appointment
    • I use Google forms through G Suite for this purpose. If you have any concerns around this, please let me know and we will find a way around this ie; a paper-based intake form may be provided
  • when you send me written information ie; in an email
  • via a phone conversation



The reason I collect this information is:

This information is required to allow me to safely and knowledgeably; assist, support, empower and educate you about holistic nutrition (diet, lifestyle and nutritional supplementation) in a manner that is specific to you and your individual situation.

It is also so that I can provide you with the services you have contracted for, and to ensure that I am providing you with the most appropriate services


Types of information


The sensitive information I ask you to provide for this purpose may include;

Your name, date of birth, contact details, next of kin, doctor’s details, occupation, health history (including past and current supplements, medications, diagnoses, allergies and intolerances and any other relevant information specific to your health), your familial medical history, information gathered during a review of relevant body systems (ie; immune or gastrointestinal system), review of any pathology or functional testing reports, review and analysis of your dietary intakes, lifestyle factors (ie; sleep, hobbies, living arrangements).




I am committed to securely storing and handling your sensitive information.

Sensitive information is stored in a locked filing cabinet (if in hardcopy) / on a password protected computer or on the cloud through G Suite as is detailed further below (if softcopy).




Only I may access sensitive material.

Cloud Storage


Some sensitive information may be stored securely online, or in the cloud through G Suite.

  • You can find out more about their security provisions here:
  • If you have any concerns around this, please let me know and we will find a way around this ie; paper-based case notes may be taken.

Collection from minors


Sensitive information may be collected from children under the age of 18 under the following circumstances:

  • in the presence of their parents
  • eg with their parent or guardian’s full consent

All information collected from minors is securely stored in accordance with this privacy policy.

Destruction policy

Patient records are kept indefinitely inline with my association’s guidelines.

Professional Considerations

As a nutritionist I am subject to strict confidentiality requirements and I take my duty of care seriously. I am also dedicated to protecting the security of your information.

You may choose not to provide me with your personal information, however; specific and correct information must be provided at all times to ensure the quality and safety of any advice given.

If you do not provide me with accurate personal information, I may not be able to carry out my services as expected or achieve the purpose for which the information has been sought.

I am required to identify my clients by collecting their name and address, and failure to provide this information means I cannot offer my services to you.

Use of Personal Information

Reasons why I may disclose your personal information include:

  • if requested by yourself for provision to another practitioner or medical professional or if co-working on your case with another practitioner
  • to provide you with the services you have requested

Legal disclosure

I will also disclose your information if required by law to do so or in circumstances permitted by the Privacy Act – for example, where I have reasonable grounds to suspect that unlawful activity, or misconduct of a serious nature, that relates to my functions or activities has been, is being or may be engaged in, and in response to a subpoena, discovery request or a court order.

If you have any concerns regarding the disclosure of your personal information, please do not hesitate to get in touch with me to discuss this personally.

Disclosure overseas

I will use all reasonable means to protect the confidentiality of your personal information while in my possession or control. I will not knowingly share any of your personal information with any third party other than the service providers who assist me in providing the information and/or services I am providing to you. To the extent that I do share your personal information with a service provider, I would only do so if that party has agreed to comply with our privacy standards as described in this privacy policy. However, some of my service providers may be overseas and may not be subject to Australian Privacy Laws or compliant with GDPR. Please contact me if you have any concerns about the potential disclosure of your information.


Policy statement

I take responsibility for the security and risk management related to your information and regularly revisit this policy and ensure up to date compliance.

 I manage risks to your personal information by:

  • storing files securely
  • ensuring that only I have access to sensitive information
  • releasing information to service providers on a strictly need-to-know basis, and
  • conducting regular audits of my security systems

As mentioned above, your personal information may also be stored with a third-party provider, where it will be managed under their security policy:

  • G Suite:

From time to time I may combine information provided by you with information gathered from:

  • Facebook
  • Google Analytics
  • personal contact

If you do not wish this to occur, please contact me.

Access to Information

You can contact me to access, correct or update your personal information at any time. Unless I am subject to a confidentiality obligation or some other restriction on giving access to the information which permits me to refuse you access under the Privacy Act, and I believe there is a valid reason for doing so, I will endeavour to make your information available you within 30 days.

If you wish to request access or correction please contact me in writing via email at and expect a reply within 5 days.


Complaint procedure

If a breach of this Privacy Policy occurs, or if you wish to a request a change to your personal information, you may contact me by sending an email outlining your concerns to me at and I will endeavour to respond within 48  hours.

Complaint to external body

Should a complaint be made directly to me, any dispute may then be taken to external dispute resolution such as mediation, then complaint may go to OAIC (Office of the Australian Information Commissioner).

If you are not satisfied with my response to your complaint you may seek a review by contacting the Office of the Australian Information Commissioner using the information available at”

Notification of Change

Notification procedure

Should any changes be made to this policy a new version will be posted to

Notification of Breach

If I have reason to suspect that a serious data breach has occurred and that this may result in harm or loss to you, I will immediately assess the situation and take appropriate remedial action. If I still believe that you are at risk, I will notify the Office of the Information Commissioner and either notify you directly, or if that is not possible, publicise a notification of the breach on this website.