Privacy Policy
Last updated: August 2026
Institute for Self Crafting Pty Ltd, trading as Institute for Self Crafting, Hollie Wildëthorn, Wise Women Gathering and Wise Gatherings (“we”, “our” or “us”), respects your privacy and is committed to protecting the personal and health information entrusted to us.
This Privacy Policy explains how we collect, hold, use, disclose and protect personal information across our websites, platforms, educational programmes, events, products and clinical services.
We handle personal information in accordance with applicable Australian privacy law, including the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs). As a private health service provider operating in NSW, our handling of health information is also governed by the Health Records and Information Privacy Act 2002 (NSW) and Health Privacy Principles (HPPs).
This Policy applies to services provided through:
memberships and courses
events, gatherings and retreats
psychotherapy and counselling
clinical supervision
educational and professional programmes
digital and physical products
other services provided by Institute for Self Crafting Pty Ltd.
Some services, particularly psychotherapy and other clinical services, are also governed by separate informed consent and clinical agreements.
1. Who We Are
Legal entity: Institute for Self Crafting Pty Ltd
Trading names: Institute for Self Crafting, hollie wildëthorn, Wise Women Gathering and Wise Gatherings
Country of operation: Australia
Contact: admin (a) selfcraft.me
Institute for Self Crafting Pty Ltd is responsible for the personal information it collects and holds.
For people located in jurisdictions where the term applies, including the EU/EEA, we may also act as the controller of personal information collected through our services.
2. Information We Collect
The information we collect depends upon the service you use.
General personal information
This may include:
name; email address; mailing address; telephone number; account information; communications you send to us; membership or course participation; purchase and transaction records; event registrations; marketing preferences; IP address, browser and device information; website usage information; and information collected through cookies and similar technologies.
Health and sensitive information
When providing psychotherapy, counselling or other health-related services, we collect health information and other sensitive personal information reasonably necessary to provide those services.
This may include information concerning psychological and emotional health, personal and family history, relationships, trauma history, neurodivergence, medications, treatment, previous or current health care, risk and safety, therapeutic goals and other information disclosed during the course of therapy.
Information collected in the course of providing a health service is treated as health information and protected accordingly.
Clinical information may be recorded in progress notes and other clinical records.
Our general websites and membership platforms are not intended to collect detailed clinical information. Please do not submit sensitive clinical information through general website forms, community posts or social media unless specifically requested to do so through an appropriate channel.
3. How We Collect Information
We may collect information through:
membership and course registrations;
event registrations;
newsletter subscriptions;
online purchases;
psychotherapy and clinical intake processes;
therapy, counselling and supervision sessions;
communications sent directly to us;
contact forms;
social media;
cookies and analytics;
payment and booking systems;
automation and administrative systems; and
with specific consent, AI-assisted recording and transcription used for clinical documentation.
Most health information is collected directly from the person receiving the service. Where information is collected from another person or organisation, we do so where consent has been provided or where collection is otherwise permitted or required by law.
4. How We Use Information
We may use personal information to:
provide psychotherapy, counselling and supervision;
maintain appropriate clinical records;
deliver memberships, courses, programmes and events;
fulfil orders;
manage bookings and payments;
communicate about services someone has requested or purchased;
respond to enquiries and provide support;
send marketing communications where permitted;
operate and improve our websites, platforms and services;
administer our business;
maintain security;
meet professional, insurance, taxation, legal and regulatory obligations; and
respond to circumstances where use or disclosure is authorised or required by law.
Health information is only used or disclosed for the purpose for which it was collected, a directly related purpose that would reasonably be expected, with consent, or where otherwise permitted or required by law.
5. Artificial Intelligence and AI-Assisted Technology
The Institute uses artificial intelligence and AI-assisted technology in selected areas of its administrative, educational, creative and clinical work.
AI may assist with planning, organisation, research, drafting, editing, educational development, administrative work and preparation of materials.
We remain responsible for work produced or decisions made with the assistance of AI. AI does not replace professional judgement, therapeutic relationship, clinical reasoning or ethical responsibility.
5.a) AI-assisted clinical documentation
With the client’s specific knowledge and consent, we may use Plaud to record and transcribe a psychotherapy session and generate a structured draft clinical note.
The purpose of recording is to assist the practitioner with accurate and timely clinical documentation.
The recording and transcript are working materials used to prepare the clinical note. AI-generated notes are reviewed and, where necessary, corrected by the treating practitioner before becoming part of the clinical record.
AI is not authorised to independently diagnose clients, determine treatment, undertake risk assessment or make clinical decisions.
Clients are not required to consent to AI-assisted recording. A client may decline recording or ask for it not to be used during a particular session without disadvantage to their therapeutic care.
Separate informed consent is obtained for this use.
5.b) AI processing and third-party providers
AI services may require information to be processed by third-party technology providers.
Plaud currently advises that it uses enterprise AI services provided by third parties including OpenAI, Google and Microsoft to perform aspects of transcription and AI processing, and that customer content processed through these services is not used to train their AI models under Plaud’s arrangements with those providers.
Plaud’s technology, subprocessors and data-handling arrangements may change. We periodically review the privacy and security arrangements of AI services used with clinical information.
5.c) General-purpose AI
General-purpose AI services may be used for business, educational, research and professional purposes.
We do not provide identifiable client health information to general-purpose AI services.
Where clinical experience informs professional reflection, education, research, supervision preparation or development of resources, information is de-identified or abstracted wherever reasonably practicable.
AI is not used to make autonomous clinical decisions about clients.
6.Recording, Transcription and AI-Assisted Documentation
The Institute uses audio, video, transcription and AI-assisted technologies for a range of legitimate purposes across its clinical, educational and organisational work.
This may include psychotherapy sessions, meetings, supervision, Circlecraft teaching and training sessions, book clubs, courses, workshops and other educational or professional gatherings.
The purpose of a recording, how it is processed and stored, whether it is retained, and who may access it depends upon the context in which the recording is made.
People participating in recorded sessions or meetings are informed about the recording where appropriate, including its purpose and intended use. Consent is obtained where required by law or where the nature of the information or setting makes consent appropriate.
Meetings, teaching and educational sessions
Meetings, teaching sessions, book clubs, supervision, workshops and other Institute activities may be recorded or transcribed to assist with purposes such as:
creating meeting notes and action items;
preparing summaries or records;
supporting teaching and educational resources;
allowing participants to revisit teaching;
documenting decisions and discussions;
supporting accessibility;
developing or improving Institute materials; and
reducing administrative workload.
AI-assisted tools, including Plaud, may be used to transcribe, summarise or organise these recordings.
Where recordings are intended to be made available to participants after a session, this will be made clear to participants.
A recording made for one purpose will not automatically be used for another purpose. For example, participation in a recorded teaching session does not by itself constitute consent for a participant’s contribution to be used in public marketing, research or unrelated educational material.
Where sensitive or confidential information is discussed, additional care is taken regarding recording, access, storage and subsequent use.
AI-assisted clinical documentation
The Institute uses AI-assisted recording and transcription to support timely and accurate clinical documentation.
With the client’s specific consent, psychotherapy sessions may be recorded using Plaud for the purpose of transcription and preparation of a draft clinical note.
These recordings and transcripts are working documentation materials rather than the final clinical record. AI-generated notes are reviewed and, where necessary, corrected by the treating practitioner before becoming part of the clinical record.
Clients may decline AI-assisted recording or ask for it not to be used during a particular session without disadvantage to their therapeutic care. Where recording is declined, clinical documentation will be completed by another method.
Recordings and working transcripts created for this purpose are deleted when no longer reasonably required for preparation and review of the clinical note, subject to applicable legal, professional and recordkeeping requirements.
Cannabis-Assisted Psychotherapy
Cannabis-Assisted Psychotherapy (CAPT) sessions are video recorded as part of the clinical safety and accountability framework for psychotherapy conducted while a client is in an altered state.
The purpose of these recordings is different from AI-assisted documentation recordings. CAPT video recordings provide a record of the care provided during the altered-state session and support client safety and clinical accountability.
CAPT video recordings are stored securely within Halaxy and treated as sensitive health information.
They are not used for marketing, teaching, training, research or other secondary purposes without separate, specific consent or another lawful basis for that use.
The recording of CAPT sessions, including its purpose, storage, access and retention, is explained as part of the specific informed consent process for Cannabis-Assisted Psychotherapy.
7. Payment Information
Payments are processed through third-party payment and practice-management providers, including Stripe, PayPal and Halaxy where applicable.
We do not ordinarily directly store complete payment card details. Where payment details are retained by a payment or clinical practice-management provider for authorised future transactions, they are held within that provider’s system rather than in our general business records.
8. Service Providers and Disclosure
We use third-party providers to operate different parts of the Institute.
Depending upon the services you use, these may include providers of:
payment processing;
email and communications;
website hosting;
membership and course platforms;
booking and practice management;
cloud and data storage;
videoconferencing;
automation;
accounting and administration; and
AI-assisted transcription and documentation.
Current providers may include Stripe, PayPal, MailerLite, Squarespace, Mighty Networks, GoDaddy, Zapier, Halaxy, Zoom and Plaud.
We may also disclose information to professional advisers, insurers, technology support providers or authorities where reasonably necessary, authorised by you or required or permitted by law.
We do not sell personal or health information.
We do not disclose health information to third parties for their own direct marketing.
9. Overseas Processing and Storage
Some of the technology providers we use store or process information outside Australia.
This means personal information may be transmitted to or processed in other jurisdictions.
Where health information is involved, we take the sensitivity of the information and applicable Australian and NSW requirements into account when selecting and configuring services and determining whether overseas processing is appropriate.
Plaud’s AI-assisted processing may involve infrastructure or subprocessors located outside Australia, including in the United States and other jurisdictions identified by Plaud from time to time.
Where appropriate, information about overseas AI processing is provided as part of the consent process before identifiable clinical information is processed in this way.
We take reasonable steps to use service providers with appropriate privacy, security and contractual safeguards.
10. Storage and Security
Information is held across systems appropriate to the service being provided.
These may include our clinical practice-management system, email provider, membership platform, website systems and other secure third-party services.
We take reasonable steps to protect personal and health information from misuse, interference, loss and unauthorised access, modification or disclosure.
Measures may include:
password and device security;
multi-factor authentication where available;
encryption provided by relevant services;
restricting access to authorised people;
selecting reputable technology providers;
minimising unnecessary copies of sensitive information;
maintaining appropriate backups;
reviewing privacy and security settings; and
securely deleting information when it is no longer required.
No electronic system can be guaranteed to be completely secure. If a privacy or data-security incident occurs, we will investigate and respond in accordance with applicable law, including the Notifiable Data Breaches scheme where applicable.
11. Clinical Records and Data Retention
Different information is retained for different periods according to its purpose and applicable legal requirements.
General business and transaction records may be retained for periods required by taxation, corporate or other laws.
Health records are subject to specific retention requirements.
For private health service providers in NSW, adult health records are generally required to be retained for at least seven years from the last occasion on which a health service was provided. Where health information was collected while a person was under 18, different requirements apply and records are generally retained until the person reaches 25 years of age.
We may retain information for longer where required or permitted by law or where reasonably necessary for legal, insurance or professional purposes.
Temporary recordings and transcripts created solely to assist preparation of a clinical note are not intended to replace the clinical record and are deleted when no longer reasonably required, subject to applicable requirements.
12. Access and Correction
You may request access to personal or health information we hold about you and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
Some exceptions to access may apply under privacy or health-records legislation.
We may need to verify your identity before providing access.
For clinical records, requests are managed in accordance with applicable Commonwealth and NSW health privacy requirements.
13. Deletion Requests
You may ask us to delete personal information we hold.
Whether information can be deleted depends upon the type of information and our legal and professional obligations.
We may be required to retain clinical records, financial records and certain other information for prescribed periods even where deletion has been requested.
Where information is no longer required and there is no legal or professional reason to retain it, we take reasonable steps to securely delete or de-identify it.
14. Cookies and Website Analytics
Our websites may use cookies and similar technologies to operate the website, improve user experience, understand website traffic and support marketing activities.
You can control cookies through your browser and, where available, website consent settings. Disabling some cookies may affect website functionality.
15. Marketing Communications
We may send marketing communications where you have opted in or where otherwise permitted by law.
When you purchase from us, we may use your email address to send information related to your purchase and occasional communications about relevant Institute offerings, subject to applicable marketing and privacy laws.
You may unsubscribe at any time through the link included in marketing emails or by contacting us.
Health information is not used for direct marketing without specific consent.
We do not provide personal information to third parties for their own marketing.
16. International Visitors
If you are located outside Australia, additional privacy rights may apply under the laws of your jurisdiction.
For people in the EU/EEA, applicable lawful grounds for processing may include performance of a contract, legitimate interests, consent and compliance with legal obligations.
Nothing in this section reduces the protections that apply to health information under Australian law.
17. Complaints
If you have a concern about how we have handled your personal or health information, please contact us first so that we can investigate and respond.
Email: admin (a) selfcraft.me
You may also have the right to make a complaint to:
Office of the Australian Information Commissioner (OAIC)
for matters arising under the Privacy Act 1988 and Australian Privacy Principles.
Information and Privacy Commission NSW (IPC NSW)
for matters arising under the Health Records and Information Privacy Act 2002 (NSW).
18. Changes to this Policy
Privacy, technology and AI services change over time.
We may update this Privacy Policy to reflect changes in our services, technology providers, professional requirements or applicable law.
The current version will be published with its most recent update date.
Contact
Institute for Self Crafting Pty Ltd
Australia
Email: admin (a) selfcraft.me