BRIA Privacy Policy

Last updated: 15th August 2026

1. About This Privacy Policy

Bria respects your privacy and is committed to protecting the personal and health information entrusted to us.

This Privacy Policy explains how Neurolab PT PTY LTD, ABN 88 670 405 571, trading as Bria (“Bria”, “we”, “us” or “our”), collects, holds, uses, discloses and protects personal information in connection with the Bria mobile application, web application, website and associated services (collectively, the “Bria Platform”).

Bria is an Australian-based digital exercise prescription and rehabilitation support platform that enables healthcare practitioners to provide individualised exercise programs to their clients.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) where they apply to us.

Some information handled by Bria is health information and therefore sensitive information under Australian privacy law.

This Privacy Policy should be read together with the Bria Terms and Conditions of Use.


2. What Information Does Bria Collect and Store?

Bria is designed to minimise the amount of personal and health information collected and stored.

Depending on how you use Bria, we may collect and hold:

Contact Information

  • email address; and
  • telephone number.

Health and Exercise Information

  • diagnosis; and
  • exercises or exercise programs prescribed or approved by your healthcare practitioner.

Client Photographs and Videos

Bria may store photographs and videos captured by a healthcare practitioner of a client performing exercises prescribed or approved for that client.

These photographs and videos are used to provide the client with an individualised visual reference for performing their prescribed exercises.

A client’s diagnosis, prescribed exercise information, and photographs or videos associated with their healthcare may constitute health information and sensitive information under Australian privacy law.

Bria does not intend to collect or store information beyond what is reasonably necessary to provide the Bria service.


3. Information Bria Is Not Designed to Store

Bria is an exercise prescription and rehabilitation support platform and is not intended to operate as a comprehensive medical record or clinical practice-management system.

Unless functionality is changed and this Privacy Policy is updated accordingly, Bria is not designed to store comprehensive:

  • clinical consultation notes;
  • medical reports;
  • hospital records;
  • medication lists;
  • Medicare details;
  • NDIS participant numbers;
  • billing or payment information; or
  • comprehensive medical histories.

Healthcare practitioners remain responsible for maintaining their required clinical records separately from Bria.


4. How We Collect Information

Personal and health information may be collected:

  • directly from the client;
  • when a client creates or uses a Bria account;
  • from the client’s treating healthcare practitioner;
  • when a healthcare practitioner creates or updates an exercise program;
  • when a healthcare practitioner enters the client’s diagnosis;
  • when a healthcare practitioner captures or uploads a photograph or video of the client performing an exercise; or
  • from an authorised parent, guardian or representative where appropriate.

We aim to collect personal information only where it is reasonably necessary for the operation and provision of Bria.

Where sensitive or health information is collected, we will obtain consent where required by Australian privacy law.


5. Why We Collect Personal and Health Information

Bria collects, holds and uses personal and health information primarily to provide its exercise prescription and rehabilitation support services.

This includes using information to:

  • establish and manage user accounts;
  • identify and authenticate users;
  • enable healthcare practitioners to assign individual exercise programs;
  • provide clients with access to their prescribed exercises;
  • display relevant exercise instructions;
  • provide client-specific photographs and videos as visual exercise references;
  • enable healthcare practitioners to manage programs assigned to their clients;
  • provide technical support;
  • maintain the security and functionality of Bria;
  • troubleshoot technical problems;
  • respond to privacy, account or support enquiries; and
  • comply with applicable legal obligations.

We do not use health information for purposes unrelated to providing or supporting Bria unless we have appropriate authority or are permitted or required by law.


6. Client Photographs and Videos

Bria enables a healthcare practitioner to capture or upload photographs and videos of an individual client performing exercises prescribed or approved for that client.

The process is:

Practitioner captures the photograph or video → the content is stored within Bria’s Australian-hosted AWS infrastructure → the photograph or video is assigned only to that client’s individual exercise program → the client can access it through their Bria account.

Client photographs and videos:

  • are used to support the client’s individual exercise program;
  • are assigned only to that client’s program;
  • are not placed in a public exercise library;
  • are not placed in a shared client exercise library;
  • are not made available to other Bria clients;
  • are not used to create general exercise demonstrations for other clients;
  • are not published publicly;
  • are not used for advertising or marketing;
  • are not posted to social media;
  • are not sold;
  • are not used for unrelated secondary purposes; and
  • are not used to train artificial intelligence or machine-learning models.

Access to photographs and videos is restricted to the client, appropriately authorised healthcare practitioners and authorised technical personnel where access is reasonably necessary to provide, maintain, secure or support Bria.


7. Consent for Photographs and Videos

Healthcare practitioners must obtain appropriate consent before capturing or uploading identifiable photographs or videos of a client to Bria.

Where the client is a child or another person who cannot independently provide the necessary consent, consent may be provided by an appropriately authorised parent, guardian or representative where permitted by law.

Consent to the use of photographs or videos within Bria for an individual exercise program does not constitute consent for those photographs or videos to be used for advertising, marketing, social media, promotional material or other unrelated purposes.

Bria does not use client photographs or videos for those purposes.


8. How We Store Information

Bria uses Amazon Web Services (AWS) cloud infrastructure for data hosting and storage.

Bria’s production data, including client photographs and videos stored through the Platform, is hosted within Australia.

We take reasonable technical and organisational steps designed to protect personal and health information from:

  • misuse;
  • interference;
  • loss;
  • unauthorised access;
  • unauthorised modification; and
  • unauthorised disclosure.

Security measures may include appropriate access controls, authentication, system monitoring and other technical and organisational safeguards.

No electronic storage or transmission system can be guaranteed to be completely secure.


9. Australian Data Residency

Bria’s production data is hosted within Australia using AWS infrastructure.

Bria has intentionally adopted Australian data hosting for its client information.

At the date of this Privacy Policy, Bria does not ordinarily disclose Bria client personal or health information to overseas recipients.

If our data-hosting or information-handling arrangements materially change in the future, we will update this Privacy Policy and take any additional steps required under Australian privacy law.


10. Application Development and Technical Support

Bria engages Moonward, an Australian-based application development and technical support provider, to develop, maintain, secure and support the Bria Platform.

Moonward’s development and technical support team is based in Brisbane, Australia.

Authorised Moonward personnel may have access to Bria systems or information where reasonably necessary for legitimate technical purposes, including:

  • application maintenance;
  • technical support;
  • troubleshooting;
  • resolving technical faults;
  • security;
  • software updates; and
  • maintaining the functionality and reliability of Bria.

Access is limited to what is reasonably necessary for those functions and is subject to appropriate confidentiality, privacy and information-security requirements.

Moonward does not receive client information for its own independent marketing or commercial purposes.


11. Who Can Access Client Information?

Access to client information is restricted according to the person’s role and legitimate need for access.

Depending on the circumstances, information may be accessible to:

  • the client;
  • an authorised parent, guardian or representative where applicable;
  • the healthcare practitioner responsible for the client’s exercise program;
  • other appropriately authorised users involved in providing the service, where applicable;
  • authorised Bria personnel; and
  • authorised Moonward technical personnel where reasonably necessary to provide technical support, maintenance or security.

Bria does not make client information publicly available.


12. Disclosure of Personal Information

Bria does not sell personal or health information.

We may disclose personal information where reasonably necessary:

  • to provide and operate the Bria service;
  • to authorised service providers acting on our behalf;
  • to maintain, secure or troubleshoot the Platform;
  • with the individual’s consent;
  • where authorised or required by law; or
  • where otherwise permitted under applicable Australian privacy law.

Where a service provider handles personal information on Bria’s behalf, we take reasonable steps to ensure appropriate privacy, confidentiality and information-security arrangements apply.


13. Overseas Disclosure

At the date of this Privacy Policy, Bria’s production data is hosted in Australia and Bria’s application development and technical support provider operates through its Australian-based team.

Bria does not ordinarily disclose client personal or health information to overseas recipients.

If this changes, we will review our obligations under the Privacy Act and Australian Privacy Principles, including requirements relating to cross-border disclosure, and update this Privacy Policy where appropriate.


14. Children and Users Requiring Assistance

Bria may be used by children and by individuals who require assistance managing their exercise program.

Where appropriate, personal and health information may be provided or managed by an authorised parent, guardian or representative.

Healthcare practitioners must ensure that they have appropriate authority and consent before entering information or capturing photographs or videos relating to a child or person requiring supported decision-making.

We recognise that information relating to children and vulnerable individuals requires particular care and take reasonable steps to protect that information.


15. Healthcare Practitioner Responsibilities

Healthcare practitioners using Bria have independent professional, legal and privacy obligations regarding information about their clients.

Practitioners are responsible for:

  • ensuring they have appropriate authority to enter client information into Bria;
  • obtaining consent where required;
  • protecting their Bria account credentials;
  • only accessing information they are authorised to access;
  • ensuring information entered into Bria is reasonably accurate;
  • maintaining appropriate clinical records outside Bria; and
  • complying with applicable professional, privacy, confidentiality and health-record requirements.

Practitioners should not enter information into Bria that is not reasonably necessary for the intended functionality of the Platform.


16. Account Security

Users are responsible for taking reasonable steps to protect their Bria account.

Users should:

  • keep passwords confidential;
  • not share login credentials;
  • protect devices used to access Bria;
  • log out of shared devices; and
  • notify Bria if they believe their account or information has been accessed without authorisation.

We may require password resets or other security measures where reasonably necessary to protect users or the Platform.


17. Quality and Correction of Information

We take reasonable steps to ensure that personal information we hold is accurate, up to date, complete and relevant for the purposes for which it is used.

Users should notify Bria or their healthcare practitioner if they believe information held about them is inaccurate, incomplete or out of date.

Individuals may request correction of their personal information by contacting us using the details at the end of this Privacy Policy.

We will consider and respond to correction requests in accordance with applicable Australian privacy law.


18. Access to Your Personal Information

You may request access to personal information Bria holds about you.

Requests can be made using the contact details at the end of this Privacy Policy.

We may need to verify your identity before providing access.

In some circumstances, Australian law permits or requires us to refuse access to some or all of the requested information. If we refuse access, we will provide an explanation where required by law and information about available complaint mechanisms.


19. Account Closure and Deletion

Users may request closure of their Bria account and may contact us regarding deletion of personal information associated with their account.

We will handle deletion requests in accordance with applicable Australian privacy law.

Information will not be retained for longer than reasonably necessary for the purposes for which it is held, subject to any legal, security, backup, dispute-resolution or other legitimate retention requirements.

Where personal information is no longer required and we are not required or permitted to retain it, we will take reasonable steps to destroy or de-identify it.

Healthcare practitioners remain independently responsible for retaining any clinical records they are professionally or legally required to maintain outside Bria.


20. Data Breaches

Bria takes the security of personal and health information seriously.

If we become aware of a suspected privacy or data-security incident, we will assess and respond to the incident in accordance with our legal obligations.

Where a data breach is likely to result in serious harm and the requirements of the Notifiable Data Breaches scheme under the Privacy Act are met, we will notify affected individuals and the Office of the Australian Information Commissioner as required by law.

We will also take reasonable steps to contain and remediate identified security incidents.


21. Direct Marketing

Bria does not use client health information, prescribed exercise information, photographs or videos for direct marketing.

Client photographs and videos are not used for advertising, promotional material or social media.

If Bria offers optional marketing communications in the future, those communications will be managed in accordance with applicable Australian law and users will be provided with an appropriate method of opting out.


22. Cookies, Analytics and Technical Information

Bria may require limited technical information to operate, secure and maintain the Platform.

Where Bria uses cookies, analytics, crash reporting, device information, IP addresses or similar technologies, information about those practices will be disclosed in this Privacy Policy and, where required, at the point of collection.

Bria will not knowingly use technical or analytics information to create advertising profiles based on a client’s health information.

[This section must be confirmed with Moonward before publication to ensure it accurately reflects the final production application and website.]


23. Privacy Complaints

If you believe Bria has not handled your personal information appropriately or has breached your privacy rights, please contact us using the details below.

Please provide sufficient information for us to understand and investigate your concern.

We will:

  1. acknowledge your complaint within a reasonable period;
  2. investigate the circumstances;
  3. communicate with you where additional information is required; and
  4. provide an outcome or response within a reasonable period.

We aim to resolve privacy concerns directly wherever possible.

If you are not satisfied with our response, you may be entitled to make a complaint to the Office of the Australian Information Commissioner (OAIC).

Information about making a privacy complaint is available at the OAIC website.


24. Changes to This Privacy Policy

We may update this Privacy Policy from time to time where:

  • Bria’s functionality changes;
  • our information-handling practices change;
  • service providers change;
  • applicable privacy laws or regulatory requirements change; or
  • security or operational requirements change.

The current version will be published on the Bria website and will identify the date on which it was last updated.

Where a change materially affects how we handle users’ personal or health information, we will take reasonable steps to notify affected users and obtain further consent where required.


25. Contact Us

For privacy enquiries, requests to access or correct personal information, deletion requests or privacy complaints, please contact:

Bria
Operated by: Neurolab PT PTY LTD
ABN: 88 670 405 571

Privacy Contact: Chloe Holtham (Obst)
Email: info@neurolabpt.com.au
Website: www.neurolabpt.com.au/bria
Western Australia, Australia

You can also find information about Australian privacy rights from the Office of the Australian Information Commissioner (OAIC).


This Privacy Policy should be read together with the Bria Terms and Conditions of Use.