Privacy Policy

Last updated: 30 April 2026

Your privacy is important to us. At GP and Me, we treat your personal information sensitively and with the utmost care. This policy explains how we collect, use, and protect your information, and your rights under the Privacy Act 2020 and the Health Information Privacy Code 2020.

Changes in this Policy

This policy was last updated on 30 April 2026 to reflect GP and Me’s new and on ongoing operations from 281 Dominion Road, Mt Eden, Auckland as a primary healthcare provider.

Who We Are

We are GP+ME Limited. When we refer to “GP and Me”, “we”, or “us”, we mean GP+ME Limited and any associated entities as relevant.

What Personal Information We Collect

Background & Identity Information

  • Name, date of birth, gender, address, ethnicity, citizenship, National Health Index (NHI) number, and proof of identity (e.g., driver’s licence or passport).
  • Information about eligibility for public health services if you are enrolling with GP and Me.
  • Contact details including email, mobile number, next of kin and emergency contacts.

Health Information

  • Health history, previous services, insurance details, and records transferred from other providers with your consent.
  • Information from consultations, messages, and other interactions with GP and Me.
  • Clinicians may use AI tools to help draft clinical notes from audio transcripts, which are reviewed and added to your records only with your consent.

Payment Information

  • Bank or credit card details needed to process payments.

Device & Service Interaction Information

  • IP address, session details, location, cookies, and app/website usage analytics.

Withholding some information may affect our ability to provide services or the quality of care.

Why We Collect Your Information

We collect and use your personal information for the following purposes, and other directly related purposes:

  • Confirm your identity and create your patient profile in our practice management system
  • Confirm your eligibility to enrol for public health services with us, and eligibility for public funding.
  • Confirm your eligibility to receive publicly funded services. If you have received a consultation funded by Health New Zealand, for service evaluation, primary health care analysis to inform planning, funding, and service improvement.
  • To help manage GP and Me services and our partnerships with third parties, including securing funding or subsidies for consultations or treatments that are funded or partially funded by others.
  • Provide and coordinate your healthcare, maintain records, and make referrals.
  • Administer services, including billing, account arrears, and funding arrangements.
  • Evaluate and improve services, including for research, clinical audits, and planning.
  • Communicate with you about your care, updates, or health promotion.

Who We Share Your Information With

In connection with the above purposes, we may share your personal information with:

  • GP and Me clinicians, other employees, contractors, specialist providers and third parties (such as pharmacies, other health care providers and agencies) involved in your care.
  • Government agencies such as the Ministry of Health, Health New Zealand/Te Whatu Ora, ACC, Work and Income and other government agencies and regulators when required by law to do so.
  • The Primary Health Organisation GP and Me has funding or contractual arrangements with. 
  • Your health insurer, employers, or third-party service providers where they are providing access to our services or contributing to the cost of providing such services. 
  • Third-party service partners who help deliver or improve GP and Me's services, including analytics and advertising providers, always using secure and limited data.
  • Other third parties that help carry out our service, such as credit reporting or debt collection agencies, and New Zealand Transport Agency, Ministry of Social Development, ACC or other required government agencies.

How We Collect Information

  • Directly from you – when you register, use our patient portal app, or consult with clinicians.
  • Indirectly from other sources:
    • previous GPs (with your consent), health agencies, Health New Zealand, laboratories, specialists, hospitals and other service providers; and
    • insurers, banks, and other service providers where it is connection with the purposes above and required to facilitate providing, and receiving payment for, services.

Where We Store Your Information

  • Health records are stored in our Patient Management System (Indici).
  • Our data (which includes your information) is securely stored on secure cloud platforms, including Amazon Web Services (AWS), Google Workspace, and Microsoft 365 (OneDrive for Business and SharePoint Online).

Managing Information for Young People & Dependents

  • For patients under 16, accounts are usually linked to a parent or guardian.
  • Parents/guardians also have some rights to access health information for a child up until they reach the age of 16, unless confidentiality is required in the child’s best interest.
  • Young adults may request restricted sharing, which GP and Me will consider case by case in accordance with the Health Information Privacy Code, Privacy Act and Health Act 1956.

Your Rights

We take reasonable steps to make sure your information is accurate, up-to-date, and relevant for your care and treatment.

You have the right to:

  • Request access to or a copy of your health information. You don’t have to explain why you are requesting access, but may be required to provide proof of identity and pay an administration fee. 
  • Request corrections to ensure accuracy of your personal information. 
  • Attach a statement of correction of your health information. If we are not willing to change that information as requested, we will attach a statement of correction to your file.
  • Exercise these rights anytime via our Contact Us details on this website.

Retention of Information

  • Health information is retained securely for at least 10 years after your last appointment.
  • Records can be transferred to another healthcare provider upon your consent, while GP and Me may retain copies for legal compliance.

Cookies & Similar Technologies

  • We use various tracking technologies, including cookies, web beacons, and local storage to identify you across web sessions, personalise your experience, analyse usage, and deliver relevant advertising.
  • You can adjust your device settings to control cookies, though some services may not function fully without them.
Web beacons help us track when users visit our website or open our emails. Cookies are small files stored on your device that help us recognise you, while third-party cookies may track activity across websites for advertising or analytics. You can adjust your device settings to manage cookies, but some features of our services may not work if they are disabled. By using GP and Me services, you consent to our use of these technologies in accordance with this policy.

Changes to this Privacy Policy

GP and ME may update this policy from time to time and will post the latest version on our website.

Complaints

  • Contact your GP and ME provider first if you have concerns about your personal information or email: admin@gpandme.co.nz.
  • Unresolved complaints can be made to the Office of the Privacy Commissioner (OPC): https://privacy.org.nz

Contact Us

If you have questions about this policy or your privacy rights, please email:

To: admin@gpandme.co.nz
Subject: GP and Me Privacy