Legal

Privacy Policy

We ask you for more than most gyms do: your injuries, your medical history, your emergency contact. We ask because a coach cannot program safely without it. This page explains exactly what we collect, why, who else sees it, and how to get it back, corrected or deleted.
Effective 3 August 2026
Last updated 3 August 2026
Version 1.0
1. Who we are

Metaform Australia Pty Ltd (ABN 42 688 579 464), trading as Metaform Fitness, runs a semi-private personal training studio in Fortitude Valley, Brisbane, and delivers online coaching to members anywhere in the world.

In this policy, “Metaform”, “we”, “us” and “our” mean Metaform Australia Pty Ltd. “You” means anyone whose personal information we hold: members, trial participants, casual visitors, prospects, online coaching clients, corporate-scheme members, newsletter subscribers, website visitors, referees, job applicants and anyone who contacts us.

Studio
Ground Level, 100 Brookes Street, Fortitude Valley QLD 4006, Australia

Email
info@mformfitness.com.au

Phone
0485 003 695

Privacy contact
The Privacy Officer, at the email or postal address above

2. What this policy covers

This policy applies to everything we do, including:

  • Our websites: mformfitness.com.au, /online and /personaltraining, plus any booking, signup, checkout or member portal page we link you to.
  • The studio itself: training sessions, 24/7 gym access, assessments, testing and events.
  • Our online coaching, delivered through a third-party coaching app.
  • Our email, SMS, phone and social media communications.
  • Job applications and staff recruitment.

We serve members and prospects outside Australia, so this policy is written to meet Australian law first, then to give people in other regions the rights their own law gives them.

3. The privacy laws we follow

Australia. We comply with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles. We collect health information and we provide services intended to maintain or improve your health, so we do not rely on the small business exemption. We treat ourselves as fully covered by the Act. We also comply with the Notifiable Data Breaches scheme, the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth), and with state and territory health records legislation where it applies to members living in those jurisdictions.

European Economic Area and United Kingdom. Where the EU GDPR or UK GDPR applies to our handling of your information, we comply with it. Section 7 sets out our legal bases and section 15 your rights. We have not appointed an EU or UK representative because we do not currently target our services at those markets. If that changes we will appoint one and update this policy.

New Zealand. We comply with the Privacy Act 2020 (NZ) and its Information Privacy Principles for New Zealand residents.

Canada. We comply with PIPEDA for Canadian residents.

United States. We honour the rights given by state privacy laws including the California Consumer Privacy Act as amended by the CPRA, and equivalent laws in Virginia, Colorado, Connecticut, Utah, Texas and other states as they commence.

Where two laws conflict, we apply whichever gives you the stronger protection.

4. What personal information we collect

4.1 Identity and contact information

Name, date of birth, gender (optional), email address, secondary email, mobile, home and work phone numbers, postal and residential address, occupation and employer (optional), and a photo for your member profile if you provide one.

4.2 Health and other sensitive information

This is the most sensitive category we hold, and we only collect it with your consent:

  • Medical conditions, injuries, surgeries, medications and other health history you disclose on a pre-exercise questionnaire, a waiver, or verbally to a coach.
  • Emergency contact details: name, relationship to you, phone and email. Please make sure that person knows you have given us their details.
  • Coach notes about your training: modifications, movements to avoid, how you responded to a session, wellbeing observations relevant to programming.
  • Performance and body data: strength and force plate testing results from our VALD equipment, body measurements, weight, and progress photos you choose to upload.
  • Disability-related goals and plan information if you train with us under an NDIS self-managed or plan-managed arrangement.

We do not collect information about your racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record or union membership, and we ask that you do not send it to us.

4.3 Membership, booking and attendance information

Membership type and start date, contract term, class and personal training bookings, cancellations and no-shows, session attendance, gym entry and exit records from the door access system and check-in kiosks, and your access fob or tag identifier.

4.4 Payment and billing information

Billing name and address, membership pricing, direct debit and card payment records, invoices, receipts, arrears and payment failures.

Your card and bank account numbers are captured and stored by our payment providers, not by us. We use Ezidebit for recurring direct debit membership billing, Stripe for card payments including online coaching checkout, and Zeller for EFTPOS at the studio. We see only masked card details, the payment method type and the transaction outcome.

4.5 Online coaching information

If you use our app-based coaching, the coaching platform holds your programs, logged workouts, weights and reps, body metrics, habit and nutrition tracking you choose to enter, progress photos, and messages between you and your coach.

4.6 CCTV

We operate security cameras that record continuously, 24 hours a day, for the safety of members and staff, for access control and for incident investigation. This matters most for 24/7 access, when there is no coach in the building.

Coverage includes the entrance, the gym floor and the training and common areas. There are no cameras in the bathrooms or change areas. Footage is held for 30 days and is then automatically overwritten, unless we have kept a specific clip because of an incident. Signage is displayed at the entrance.

4.7 Website and technical information

When you use our websites, our website platform records your IP address, approximate location derived from it, browser and device type, operating system, referring page, the pages you view, how long you stay, what you click, and the campaign parameters that brought you here. Some of this comes from cookies and similar technologies. See section 12 for what we do and do not run.

4.8 Communications

Emails, SMS messages, web form submissions, live chat, social media messages and comments, call notes, review responses, and your marketing preferences and opt-outs.

4.9 Media for marketing

Photographs and video taken in the studio, member testimonials and stories, and content you tag us in. We only publish images in which you are identifiable if you have given us consent, and you can withdraw that consent at any time.

4.10 Job applicants

Resume, qualifications and certifications (including Cert III/IV, First Aid and CPR), work history, referee details, right to work evidence, and where the role requires it, a Working with Children or NDIS Worker Screening check result.

4.11 Information you are not required to give us

You can deal with us anonymously or under a pseudonym when you make a general enquiry, ask about pricing, or book a gym tour. We cannot do that for membership, training, billing or anything involving your safety in the gym, because we need to know who you are and what your body can do.

5. How we collect personal information

Directly from you: signup and enquiry forms on our website, the GymMaster signup and member portal, booking calendars, pre-exercise questionnaires and waivers, conversations with coaches and staff at the studio, email, SMS, phone and social media, and in-app entries in the coaching platform.

Automatically: cookies and tracking pixels on our websites, door access and check-in records, CCTV, and testing equipment on the gym floor.

From third parties, where you have authorised it or the third party is permitted to give it to us:

  • Fitness Passport, if you access us through your employer’s corporate fitness scheme. We receive enough information to verify your eligibility and record your visits, and we report your visit counts back to Fitness Passport for billing.
  • Referrers, including existing members and referral partners such as allied health practices. If someone gives us your details, we will tell you where we got them the first time we contact you.
  • Advertising and social platforms, which give us aggregated campaign data and, where you submit a lead form on their platform, your contact details.
  • Google, when you leave a public review of our business.
  • Referees and screening bodies, for job applicants.
6. Why we collect and use your information

We use personal information to:

  1. Set up and manage your membership, contract and account.
  2. Program your training safely, which is the entire reason we ask about injuries and medical conditions. A coach needs to know what to avoid before they load you up.
  3. Run and staff sessions, and manage bookings, waitlists and cancellations.
  4. Give you access to the studio, including 24/7 access, and keep the building secure.
  5. Take payment, manage direct debits, chase arrears and keep accounting records.
  6. Track your progress and give you results from testing and assessments.
  7. Respond to enquiries, complaints and requests.
  8. Send you service messages: booking confirmations, schedule changes, payment failures, closures and safety notices. These are not marketing and you cannot opt out of them while you remain a member.
  9. Send you marketing, with your consent or where the law otherwise allows it. See section 8.
  10. Respond to accidents, injuries and medical emergencies, including contacting your emergency contact and giving relevant health information to paramedics or a treating practitioner.
  11. Improve our services, our website and our marketing, using analytics and aggregated reporting.
  12. Recruit, onboard and manage staff and contractors.
  13. Meet our legal obligations, including work health and safety, tax, insurance and, where relevant, NDIS record-keeping.
  14. Establish, exercise or defend legal claims, and enforce our terms and membership agreements.

We will not use your information for an unrelated purpose unless you would reasonably expect it, you have consented, or the law requires or permits it.

7. Our legal bases (EEA and UK)
Where we rely on legitimate interests, we have weighed our interests against your rights and concluded ours do not override yours. You can ask us for our reasoning, and you can object.
8. Direct marketing

With your consent, or where the Spam Act allows it because you are an existing member and the message is about similar services, we may send you:

  • Email newsletters and campaigns.
  • SMS messages about offers, events, challenges and re-engagement.
  • Targeted or lookalike advertising on Meta, Google, TikTok and LinkedIn, which may involve us providing a hashed version of your email address or phone number to those platforms for audience matching.

We do not sell your personal information, and we do not share it with third parties for their own direct marketing.

9. Who we share your information with

We disclose personal information to the following categories of recipient, only as far as they need it to do their job for us, and under contracts requiring them to protect it.

9.1 Our people

Coaches, studio staff, our bookkeeper and our directors, on a need-to-know basis. Coaches see the health and training information they need to program safely for you. All staff are bound by confidentiality obligations.

9.2 Service providers

 

Provider What They Do For Us Where They Process Data
GymMaster (Treshna Enterprises Ltd) Member management, memberships, bookings, check-in, door access, billing records New Zealand
HighLevel Inc. (GoHighLevel / LeadConnector) Website hosting, forms, booking calendars, CRM, email and SMS sending United States
ABC Trainerize Online coaching app, programs, tracking, in-app messaging United States and Canada
VALD Performance Force plate and strength testing platform, athlete profiles Australia
Fitness Passport Corporate fitness scheme eligibility and visit reporting Australia
Ezidebit (Global Payments) Recurring direct debit membership billing Australia
Stripe Card payments, including online coaching checkout Australia, United States and Global
Zeller EFTPOS card payments at the studio Australia
Xero Accounting and invoicing Australia and New Zealand
Google (Workspace, Analytics, Business Profile, Ads) Email and file storage, website analytics via Google Analytics, reviews, advertising United States and Global
Meta Platforms (Facebook, Instagram) Social presence, messaging, advertising, Meta Pixel, audience matching United States and Global
TikTok, LinkedIn Social presence and advertising United States and Global

We review this list as our systems change. It is accurate as at the last updated date at the top of this page.

9.3 Other recipients

  • Emergency and medical services, if you are injured or unwell at the studio.
  • Your employer’s scheme operator, being Fitness Passport, for visit verification and billing, if you joined through that scheme. We share your visit records, not your health information.
  • Insurers, lawyers and professional advisers, where we need advice or need to deal with a claim.
  • Government bodies, regulators, courts and law enforcement, where the law requires or authorises it. If we receive a request we consider improper or overly broad, we will push back on it.
  • A buyer or successor, if we sell or restructure the business. We would require them to keep handling your information in line with this policy, and we would tell you.

We do not disclose your health information to anyone for marketing, and we do not use it in advertising audiences.

10. Sending information overseas

Several of our providers are based outside Australia, as set out in the table above. The main overseas destinations are New Zealand, the United States and Canada.

Before we disclose personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through contractual commitments and, where relevant, Standard Contractual Clauses or the UK Addendum for transfers out of the EEA and UK. Where a transfer relies on your consent, we will tell you and ask for it. You can ask us for more detail about the safeguards for a particular transfer.

11. Automated decision-making
We do not make decisions about you that have a legal or similarly significant effect using automated processing alone. A person reviews any decision that materially affects your membership, billing or access.

We do use automated systems that process your information in routine ways: automatic direct debit processing, access control that opens the door when your tag is valid, marketing automation that decides which email sequence you receive, and advertising audience matching. None of these decide anything significant about you without a human involved.

If this changes, we will describe the logic, the information used and the consequences here, in line with the transparency requirements taking effect in Australia in December 2026.

12. Cookies and tracking

Our websites use cookies and similar technologies:

  • Strictly necessary: page delivery, security, session handling and form submission, set by our website platform. These cannot be turned off.
  • Functional: remembering preferences and pre-filling forms.
  • Analytics: understanding how people find and use the site so we can improve it. We use Google Analytics, which sets cookies and collects the technical information described in section 4.7.
  • Advertising: measuring campaign performance and showing you relevant ads. We use the Meta pixel, which tells Meta that you visited our site or took an action such as starting a booking, so we can measure our advertising and show ads to people like you.

Separately from cookies, we advertise on Meta, Google, TikTok and LinkedIn, and that can involve providing a hashed version of your email address or phone number to those platforms for audience matching. That is described in section 8.

Your choices.

  • Block or delete cookies in your browser settings at any time. Blocking strictly necessary cookies will break parts of the site.
  • Opt out of Google Analytics across all websites using Google’s browser add-on.
  • Control how Meta uses your activity through your Facebook or Instagram ad preferences.
  • Email us and ask to be excluded from our advertising audiences.

Global Privacy Control. We honour the GPC signal as an opt-out of the sale or sharing of personal information for targeted advertising where the law requires us to.

Some pages embed third-party content, such as booking calendars, checkout pages, review widgets and video players. Those providers may set their own cookies, and their privacy policies apply to what they collect.

13. How we keep your information secure

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. These include:

  • Reputable providers with their own security programs, rather than home-grown systems.
  • Access controls, so staff only see what their role requires, and prompt removal of access when someone leaves.
  • Multi-factor authentication on our core business accounts, and passwords held in a password manager rather than shared.
  • API keys and credentials kept out of shared documents, and rotated if exposed.
  • Encryption in transit for our websites and member portal.
  • Physical security at the studio, including access control and CCTV.
  • Card and bank details handled by PCI-compliant payment providers, not stored by us.
  • Staff training on privacy and confidentiality.

No system is perfectly secure. We cannot guarantee the security of information you send us over the internet, and you send it at your own risk. If something does go wrong, section 16 explains what we do.

14. How long we keep your information
We keep personal information only as long as we need it, then destroy or de-identify it.

 

Information How Long We Keep It
Member records, contracts, health and training history 7 years after your membership ends
Financial and billing records 7 years, as required by the Corporations Act and tax law
Injury, incident and accident records 7 years after the incident, longer if a claim is on foot, or until a minor turns 25
Prospect and lead records where you never joined 2 years after your last contact with us
Marketing subscriber records Until you unsubscribe, plus a permanent suppression record so we do not contact you again
CCTV footage 30 days, then automatically overwritten, unless a clip is kept for an incident
Door access and check-in logs 2 years
Website analytics data Up to 26 months
Job applications from unsuccessful applicants 12 months, unless you ask us to keep you on file
Staff records 7 years after employment ends

Where we are required to keep a record, we will keep it even if you ask us to delete it, and we will tell you that is why.

15. Your rights and choices

15.1 Everyone

You can:

  • Ask what we hold about you and get a copy.
  • Correct anything inaccurate, out of date, incomplete or misleading.
  • Withdraw consent you previously gave, including for health information, marketing and use of your photo. Withdrawing consent does not undo what we did before, and for health information it may mean we can no longer safely coach you.
  • Opt out of marketing at any time.
  • Complain to us, and then to a regulator. See section 18.

We will respond to an access or correction request within 30 days. We do not charge for making a request. We may charge a reasonable cost-based fee for giving access if the request is large, and we will tell you before we do. We will ask you to verify your identity first, so we do not hand your information to someone else.

We can refuse access or correction in the limited cases the Privacy Act allows, for example where giving access would unreasonably affect someone else’s privacy. If we refuse, we will tell you why in writing and how to complain.

15.2 Additional rights in the EEA and UK

You also have the right to erasure, to restrict processing, to data portability, to object to processing based on legitimate interests, and to object to direct marketing at any time. You can lodge a complaint with your national supervisory authority or, in the UK, the Information Commissioner’s Office.

15.3 New Zealand

You have the access and correction rights in the Information Privacy Principles, and you can complain to the Office of the Privacy Commissioner.

15.4 Canada

You have the right to access your personal information and challenge its accuracy, and to withdraw consent subject to legal and contractual restrictions. You can complain to the Office of the Privacy Commissioner of Canada.

15.5 United States

Depending on your state, you may have the right to know what we collect, to access a copy, to delete it, to correct it, to opt out of targeted advertising and of any sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights.

We do not sell personal information, and we do not share it for cross-context behavioural advertising in the sense those terms are used in the CCPA, other than the advertising cookies and hashed audience matching described in sections 8 and 12, which you can opt out of using the mechanisms in those sections or by emailing us. We do not knowingly sell or share the personal information of anyone under 16. You can use an authorised agent to make a request; we will ask for proof of authority.

15.6 Photos, video and testimonials

If you have agreed to appear in our marketing and change your mind, email us. We will stop using the material going forward and remove it from our own channels where we reasonably can. We cannot always retract material already published by third parties, reshared, or printed.

How to exercise any of these
Email info@mformfitness.com.au with “Privacy request” in the subject line, or write to us at the studio address in section 1.

16. Data breaches
If we suffer a data breach that is likely to result in serious harm to you, we will assess it promptly, contain it, and notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware, and notify you where the breach is likely to result in a high risk to your rights. We will tell you what happened, what information was involved and what you should do about it.
17. Children and young people

The minimum age for membership is 18. We will consider a member under 18 only where a parent or guardian consents, signs the membership agreement, and completes the health questionnaire and waiver on their behalf. The parent or guardian’s contact details are recorded on the account, and they can exercise the rights in section 15 for their child.

We do not knowingly collect personal information from children under 16 through our websites without parental consent. If you believe a child has given us their information, email us and we will delete it.

18. Complaints and how to contact us

Start with us. Email info@mformfitness.com.au with “Privacy complaint” in the subject line, or write to The Privacy Officer, Metaform Fitness, Ground Level, 100 Brookes Street, Fortitude Valley QLD 4006.

We will acknowledge your complaint within 5 business days and give you a written response within 30 days. If we need longer, we will tell you why and when to expect an answer.

If you are not satisfied, you can escalate to the regulator for your region:

 

Region Regulator
Australia Office of the Australian Information Commissioner, oaic.gov.au, 1300 363 992
United Kingdom Information Commissioner’s Office, ico.org.uk
EEA Your national data protection authority
New Zealand Office of the Privacy Commissioner, privacy.org.nz
Canada Office of the Privacy Commissioner of Canada, priv.gc.ca
19. Other websites
Our site links to third-party sites and embeds third-party tools, including booking calendars, checkout pages, review widgets and social media. We are not responsible for their privacy practices. Read their policies before you give them your information.
20. Changes to this policy

We review this policy at least annually and whenever we add or change a system that handles personal information. The current version is always at mformfitness.com.au/privacy, with the effective date at the top.

If we make a change that materially affects how we use your information, we will tell you by email or a notice on the website before it takes effect. Continuing to use our services after that means you accept the updated policy.

← Back to Metaform Fitness