Dayna Privacy Policy
1. About This Policy
Dayna is operated by POWR DATA PTY LTD (ACN 692 119 476 / ABN 37 692 119 476), referred to in this policy as "POWR DATA", "we", "our" or "us".
Dayna is a companion-style application that helps people record meals, experiences, reflections and goals and share selected information with a linked practitioner. Dayna is not an emergency service and does not replace professional medical, psychological or dietetic care.
This Privacy Policy explains how POWR DATA collects, holds, uses, shares and protects personal information through:
- the Dayna patient mobile application;
- the Dayna practitioner web portal;
- the Dayna administration functions;
- related emails, notifications, support services and websites; and
- the systems and service providers used to operate Dayna.
This policy should be read together with any collection notice, consent screen or terms presented when a person creates or uses a Dayna account.
POWR DATA handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
We also comply with applicable state and territory health information laws where they apply to our handling of health information.
2. Who This Policy Applies To
This policy applies to:
- patients invited to use Dayna;
- practitioners who invite and support patients through Dayna;
- people who contact us about Dayna;
- people who submit feedback or support requests;
- administrators and authorised personnel who operate Dayna; and
- other individuals whose personal information is provided to us in connection with Dayna.
Dayna is currently available only to people aged 18 years or over. Access is provided through an invitation from a participating practitioner.
3. The Information We Collect
The information we collect depends on how a person uses Dayna.
3.1 Patient Account and Profile Information
We may collect:
- first name, last name and preferred name;
- email address;
- mobile telephone number;
- Australian state or territory;
- date of birth;
- account and profile identifiers;
- authentication and account-status information;
- practitioner invitation information;
- the identity of linked practitioners;
- sharing-consent and safety-acknowledgement records;
- notification preferences; and
- account-deletion and relationship-status information.
A patient's date of birth is used to confirm that they meet Dayna's current minimum-age requirement. Age is self-declared and is not independently verified through identity documentation.
3.2 Health and Sensitive Information
Dayna collects information that may be considered health information or sensitive information, including:
- meal and snack photographs;
- meal occasions and food descriptions;
- food categories or tags;
- information about where a meal occurred;
- whether a meal was planned or decided in the moment;
- who the patient was with;
- how much of a meal the patient reports completing;
- feelings and emotional-state selections;
- written meal reflections;
- diary entries about eating, feelings, experiences or eating-disorder thoughts;
- information about what helped during a difficult experience;
- recovery-related goals;
- goal check-ins and reflections;
- practitioner-created goals and comments; and
- information that may reveal that a person is receiving eating-disorder-related support.
We recognise that eating-disorder-related information, emotional reflections and meal records can be particularly sensitive. We apply heightened care to their collection, access, storage and sharing, and limit access to people and providers who require it for an authorised purpose.
We collect this health and sensitive information with the patient's express consent because it is reasonably necessary to provide Dayna's patient-practitioner features and related account, privacy and security functions.
3.3 Meal Photographs
Patients may use their camera or photo library to add a meal or snack photograph.
Adding a photograph is optional.
Dayna removes available EXIF metadata, including location metadata, when a photograph is captured or selected through the app. Dayna does not intentionally collect the location where a photograph was taken.
Photographs are stored in private storage and are made available to an authorised linked practitioner through time-limited access links when the relevant entry is shared.
3.4 Practitioner Information
For practitioners, we may collect:
- name and preferred name;
- email address and telephone number;
- practice name, type and contact details;
- business address or suburb;
- website details;
- billing email;
- legal entity name;
- Australian Business Number;
- Medicare provider number;
- Accredited Practising Dietitian status and number;
- relevant eating-disorder credentials or references;
- professional experience information;
- patient-group information;
- subscription and entitlement status;
- payment and invoice references;
- patient invitations and practitioner relationships; and
- practitioner-created goals and comments.
3.5 Feedback and Communications
If a person contacts us or submits feedback, we may collect:
- their name and contact details;
- account identifier;
- feedback category and rating;
- device platform;
- the content of their message;
- support correspondence; and
- information needed to investigate and respond.
Feedback may contain health or other sensitive information if the person chooses to include it. People should avoid including unnecessary sensitive information in general feedback or email correspondence.
3.6 Technical Information
We may collect or process limited technical information needed to operate and secure Dayna, including:
- account and session identifiers;
- login and security-event timestamps;
- app version;
- operating-system version;
- device model;
- technical crash and error information;
- push-notification tokens;
- notification-delivery information;
- server and security logs;
- audit records;
- network connectivity status; and
- IP addresses incidentally processed by hosting and infrastructure providers.
Dayna does not collect advertising identifiers.
4. How We Collect Information
We collect information:
- directly from patients during registration, onboarding and use of Dayna;
- directly from practitioners through registration and use of the practitioner portal;
- when a practitioner creates an invitation or enters a goal or comment;
- when a patient captures or selects a photograph;
- when a person contacts us or submits feedback;
- automatically when necessary for authentication, security, notifications, crash reporting and technical operation;
- from payment providers in relation to practitioner subscriptions; and
- from our service providers where necessary to operate or support Dayna.
Where practicable, we collect information directly from the individual concerned.
5. Why We Collect, Hold and Use Information
We collect, hold and use personal information to:
- create and administer patient and practitioner accounts;
- verify age eligibility;
- connect patients with their invited practitioners;
- allow patients to record meals, reflections and goals;
- make shared entries available to authorised practitioners;
- allow practitioners to review shared information and provide goals or comments;
- operate account, security and notification features;
- send invitations, account notices and other transactional communications;
- administer practitioner subscriptions and payments;
- provide support and respond to feedback;
- investigate technical faults;
- monitor the security and reliability of Dayna;
- prevent unauthorised access, misuse and fraud;
- maintain privacy-preserving audit records;
- manage account suspension and deletion;
- comply with legal and regulatory obligations; and
- establish, exercise or defend legal rights.
We do not use patient health information for advertising.
We do not use patient health information for direct marketing. If we send optional promotional communications about Dayna in the future, we will do so only where permitted by law and will provide a clear way to opt out.
We do not sell personal information.
6. Sharing Information With Practitioners
6.1 Sharing by Default
Dayna is designed to support communication between a patient and their linked practitioner.
New meal logs, diary entries and goal check-ins are shared with the patient's linked practitioner by default once they contain sufficient saved content and reach a shareable status.
Incomplete drafts that have not reached the applicable shareable status are not visible to practitioners.
6.2 Individual Sharing Control
Patients may change the sharing setting of an individual entry.
When sharing is on:
- the entry may be viewed by an authorised linked practitioner; and
- associated content, including photographs, feelings and reflections, is included in that sharing.
When sharing is off:
- the entry remains visible to the patient;
- the entry is not visible to a linked practitioner;
- associated photographs and content are not made available to the practitioner; and
- the private entry is excluded from practitioner-facing statistics and calculations.
Changing an entry from shared to private removes practitioner access immediately. Changing it from private to shared makes it available subject to the normal entry-status rules.
Patients may also delete an entry. Deleting an entry removes it from the practitioner's view immediately.
6.3 Practitioner Relationships
A practitioner can access eligible shared information only while there is an active relationship between that practitioner and the patient.
When the relationship ends, the practitioner's access through Dayna ends immediately.
A newly linked practitioner does not automatically receive access to entries created before that practitioner relationship began. Historical information will only be made available where Dayna provides an appropriate sharing function and the patient clearly chooses to share it.
A patient may be linked to more than one practitioner. Each practitioner relationship is assessed separately.
6.4 Practitioner-Created Information
Practitioners may create goals and add comments within Dayna. This information is visible to the relevant patient.
Practitioners are responsible for ensuring that information they enter is appropriate, accurate and consistent with their professional obligations.
7. When We Disclose Information
We may disclose personal information:
- to a patient's authorised linked practitioner in accordance with the sharing settings described above;
- to technology providers that help us host, secure and operate Dayna;
- to email and notification providers;
- to payment providers for practitioner billing;
- to professional advisers, insurers, auditors or contractors where reasonably necessary;
- where required or authorised by law;
- to investigate suspected unlawful activity, security incidents or misuse;
- where reasonably necessary to prevent or lessen a serious threat to life, health or safety and the law permits the disclosure; or
- with the individual's consent.
Service providers may only receive the information reasonably necessary for their role.
POWR DATA administrators can access account, identity, billing, feedback and privacy-redacted audit information where required to operate Dayna. The standard administration portal does not provide administrators with a patient clinical-record browsing screen.
A limited number of authorised operational personnel may have technical access through secured infrastructure-management tools. This access is restricted to legitimate operational, security, support or legal purposes.
8. Service Providers and Overseas Processing
Dayna's primary database, account information, health-related records and uploaded meal photographs are hosted in Sydney, Australia.
Some supporting services process limited information outside Australia. These services currently include:
- Supabase, for database, authentication, file storage and backend services, with Dayna's primary project hosted in Sydney. Supabase is a United States-based provider and authorised support or subprocessors may operate overseas;
- Resend, for account, invitation, feedback and transactional email delivery, with processing that may occur in the United States;
- Expo, Apple Push Notification service and Google Firebase Cloud Messaging, for push-notification delivery, with processing that may occur in the United States and other countries;
- Sentry, for technical crash reporting, hosted in the European Union;
- Stripe, for practitioner subscription and payment processing, with processing that may occur in Australia, the United States and other countries;
- Microsoft Azure, for delivery of the practitioner portal's static web application, using international infrastructure and content-delivery services; and
- Apple and Google, for mobile-application distribution and related platform services.
The practitioner portal's health information is transmitted directly between the practitioner's browser and Dayna's Australian-hosted backend. Patient health content is not hosted in the Azure static website.
We take reasonable steps to select reputable providers, limit the information supplied to them and require appropriate privacy and security protections through applicable contractual and service arrangements.
Where Australian Privacy Principle 8 applies, we take reasonable steps before disclosing personal information overseas to ensure the recipient handles it consistently with applicable Australian privacy requirements. Depending on the circumstances, POWR DATA may remain accountable under Australian privacy law for the overseas recipient's handling of that information.
Overseas providers may also be required to handle information under the laws applying in their jurisdictions.
9. Emails and Push Notifications
9.1 Emails
Dayna may send:
- account confirmation emails;
- password-reset and security emails;
- practitioner invitation emails;
- account-deletion notices;
- subscription and billing communications; and
- support or feedback-related communications.
A patient invitation email may reveal that the recipient has been invited to connect with a named practitioner or practice. People who share access to the recipient's email account may therefore see that a practitioner relationship exists.
We minimise sensitive information in email. Detailed feedback and health-related content are retained within secured Dayna systems rather than included in administrative email notifications wherever practicable.
9.2 Push Notifications
Dayna may send push notifications through Expo and the notification services operated by Apple or Google.
A push notification may be visible on a locked device depending on the user's device settings.
Dayna does not intentionally include meal descriptions, diary content, feelings, goals or other health details in push-notification titles or bodies. Patient-facing notifications use general wording and controlled destination links.
Users may manage optional notification categories within Dayna or through their device settings. Essential security or account notifications may not be capable of being disabled within the app.
10. Crash Reporting and Technical Diagnostics
Dayna uses Sentry to identify crashes and technical faults in the mobile application.
Crash reports may include:
- error type and stack trace;
- app version and release;
- device model;
- operating-system name and version; and
- technical navigation or network-event details needed to diagnose the fault.
Crash reporting is configured not to attach:
- names;
- email addresses;
- telephone numbers;
- user or account identifiers;
- IP addresses;
- meal or diary content;
- reflections or goal content;
- screenshots;
- screen recordings;
- request or response bodies; or
- authentication and signed-storage tokens.
Technical filters are used to remove URL query strings and other potentially sensitive values before crash information is submitted.
Crash information is processed in the European Union and is used only to maintain the security, stability and technical performance of Dayna.
11. No Advertising, Tracking or AI Processing
Dayna does not currently:
- display third-party advertising;
- use advertising SDKs;
- collect advertising identifiers;
- track users across unrelated apps or websites;
- use behavioural advertising;
- use product-analytics or session-replay tools;
- sell personal information; or
- use artificial intelligence to analyse patient or practitioner information.
If we propose a future feature that materially changes these practices, we will conduct a privacy review and update this policy and relevant consent information before the feature is introduced.
12. Device Permissions
Dayna may request permission to use:
- the camera, so a patient may take an optional meal or snack photograph;
- the photo library, so a patient may select an optional photograph; and
- push notifications, so Dayna may provide enabled reminders, announcements and account information.
These permissions are optional. A patient may record an entry without adding a photograph, and Dayna remains usable if notification permission is declined.
Dayna does not currently request access to:
- precise or approximate location;
- microphone or audio recording;
- speech recognition;
- contacts;
- calendar;
- Bluetooth;
- HealthKit or fitness information;
- motion or fitness sensors; or
- advertising tracking.
13. How Information Is Stored and Protected
We take reasonable technical and organisational measures to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
Current measures include:
- encryption in transit;
- encryption at rest for primary database and file storage;
- private storage for meal photographs;
- expiring access links for photographs;
- role-based access controls;
- database row-level security;
- server-side authorisation checks;
- separation between patient, practitioner and administrator permissions;
- secured authentication and session management;
- protected service credentials;
- privacy-redacted audit records;
- security and account-event logging;
- restricted operational access;
- vulnerability and dependency management;
- backup and recovery controls;
- multi-factor authentication for privileged access;
- monitoring and incident-response procedures; and
- regular review and testing of security controls.
No system can guarantee absolute security. Individuals should use a unique password, protect access to their devices and notify us promptly if they suspect unauthorised access.
14. Data Retention
We retain identifiable information only for as long as reasonably necessary to provide Dayna, meet legal requirements, resolve disputes and maintain security.
Generally:
- active account and health information is retained while the account remains active;
- an entry deleted by a patient is immediately hidden from the patient-facing and practitioner-facing service and is permanently removed when the account is erased or under the applicable deletion process;
- notification-delivery logs are retained for a limited operational period;
- privacy-redacted audit records may be retained for security, accountability and legal purposes;
- de-identified statistics may be retained after an account is deleted;
- practitioner billing and transaction records may be retained where required for tax, accounting, fraud-prevention or legal purposes;
- Stripe may retain payment and transaction information under its own legal obligations; and
- encrypted backups may temporarily retain information that has been removed from the live system until those backups expire under the applicable backup-retention schedule.
Information in backups is not used for ordinary business purposes. If a backup is restored, deletion records and requests will be reapplied where reasonably practicable.
We periodically review the information we retain and delete or de-identify information that is no longer required.
We may retain limited de-identified and aggregated information after account deletion for security, service administration, reporting and improvement of Dayna. We take reasonable steps to ensure this information cannot reasonably be used to identify an individual and do not attempt to re-identify it except where required or authorised by law.
15. Deleting Entries and Accounts
15.1 Deleting an Entry
A patient may delete an individual meal or diary entry through Dayna.
The entry and associated photograph are immediately removed from the practitioner's view. The data may remain securely within the live system until permanent deletion occurs as part of the applicable account or retention process.
15.2 Patient Account Deletion
Patients may delete their Dayna account through the app.
Patient account deletion removes from the live Dayna system:
- account and profile information;
- meal and diary entries;
- photographs;
- feelings and reflections;
- goals and goal check-ins;
- practitioner comments associated with the patient;
- practitioner relationships;
- notification tokens; and
- other identifiable health information.
We may retain:
- de-identified information, such as a broad age range and state or territory;
- privacy-redacted security and audit records; and
- records that must be retained by law and no longer directly identify the patient where practicable.
Deletion from the live system is immediate once the request is completed. Copies may remain in encrypted backups until the applicable backup-retention period expires.
15.3 Practitioner Account Deletion
Practitioner-account deletion may be subject to a notice or grace period before it is completed. Billing records and other information required for legal, accounting or subscription purposes may be retained after the practitioner account closes.
15.4 Records Independently Held by Practitioners
Deleting information from Dayna does not necessarily delete information that a practitioner has lawfully recorded or retained separately outside Dayna.
Practitioners are independently responsible for their own clinical, professional and legal recordkeeping obligations.
16. Accessing, Correcting or Requesting a Copy of Information
Individuals may ask us to:
- provide access to personal information we hold about them;
- correct information that is inaccurate, incomplete, out of date, irrelevant or misleading;
- provide a copy of their information in a reasonably available format; or
- explain how their information has been handled.
Some profile information can be reviewed or corrected directly within Dayna.
Other requests are handled manually by POWR DATA.
A request may be made using the contact details at the end of this policy. The requester should provide enough information for us to identify the relevant account and understand the request.
We may need to verify the requester's identity before providing access or making a correction.
We will respond within a reasonable period. If we refuse access or correction where permitted by law, we will generally explain the reason and the available complaint options.
We will not charge for making a request. We may charge a reasonable amount for the cost of providing access where permitted by law, but we will discuss this with the requester beforehand.
17. Consent and Withdrawal
Patients provide consent during onboarding to the collection and handling of health and sensitive information required to operate Dayna.
Patients may control whether an individual eligible entry is shared with their practitioner through the entry's sharing setting.
A patient may also:
- change a shared entry to private;
- delete an entry;
- ask their practitioner to end the relationship;
- contact POWR DATA about privacy concerns; or
- delete their Dayna account.
Withdrawing consent or ending sharing may limit Dayna's ability to provide practitioner-connected features.
Withdrawal does not affect handling that occurred lawfully before the withdrawal.
18. Children and Young People
Dayna currently requires patients to be at least 18 years old.
Date of birth is requested during onboarding and the age requirement is enforced through the application and backend. The date entered is self-declared and is not independently verified.
Dayna does not currently provide parental or guardian-consent functionality.
If Dayna is extended to people under 18 in the future, we will review the consent, safeguarding and privacy arrangements and update this policy before enabling that access.
19. Data Breaches
We maintain processes for responding to suspected loss, unauthorised access, misuse or disclosure of personal information.
If we suspect that an eligible data breach may have occurred, we will conduct a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 calendar days, as required by the Privacy Act.
If we have reasonable grounds to believe an eligible data breach has occurred, we will notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable, where required by law.
20. Privacy Complaints
A person may contact us if they believe we have mishandled their personal information or breached this policy.
Please provide:
- contact details;
- a description of the concern;
- relevant dates or account details; and
- the outcome being requested.
We will acknowledge, investigate and respond to the complaint within a reasonable period.
If the person is dissatisfied with our response, they may contact the Office of the Australian Information Commissioner.
Office of the Australian Information Commissioner
Website: www.oaic.gov.au
Telephone: 1300 363 992
21. Changes to This Policy
We may update this policy when Dayna's features, information-handling practices, service providers or legal obligations change.
The current version will be published at:
https://www.daynahealth.com/privacy
The effective date and last-updated date will appear at the beginning of the policy.
Where a change materially affects how existing personal or health information is handled, we will provide an appropriate notice and obtain additional consent where required.
We review this policy periodically and whenever there is a material change to Dayna's features, information handling or applicable legal obligations.
22. Contact Us
Privacy Officer
POWR DATA PTY LTD
ACN 692 119 476
ABN 37 692 119 476
Email: privacy@daynahealth.com
Website: www.daynahealth.com
For POWR DATA's general company privacy policy, see the POWR DATA Privacy Policy.