- Who we are
- What this policy covers
- The privacy laws we follow
- What we collect
- How we collect it
- Why we collect it
- Our legal bases (EEA and UK)
- Direct marketing
- Who we share it with
- Sending information overseas
- Automated decision-making
- Cookies and tracking
- How we keep it secure
- How long we keep it
- Your rights and choices
- Data breaches
- Children and young people
- Complaints and contact
- Other websites
- Changes to this policy
Metaform Australia Pty Ltd (ABN 42 688 579 464), trading as Metaform Fitness, runs a semi-private personal training studio in Fortitude Valley, Brisbane, and delivers online coaching to members anywhere in the world.
In this policy, “Metaform”, “we”, “us” and “our” mean Metaform Australia Pty Ltd. “You” means anyone whose personal information we hold: members, trial participants, casual visitors, prospects, online coaching clients, corporate-scheme members, newsletter subscribers, website visitors, referees, job applicants and anyone who contacts us.
Studio
Ground Level, 100 Brookes Street, Fortitude Valley QLD 4006, Australia
Phone
0485 003 695
Privacy contact
The Privacy Officer, at the email or postal address above
2. What this policy covers
This policy applies to everything we do, including:
- Our websites: mformfitness.com.au, /online and /personaltraining, plus any booking, signup, checkout or member portal page we link you to.
- The studio itself: training sessions, 24/7 gym access, assessments, testing and events.
- Our online coaching, delivered through a third-party coaching app.
- Our email, SMS, phone and social media communications.
- Job applications and staff recruitment.
We serve members and prospects outside Australia, so this policy is written to meet Australian law first, then to give people in other regions the rights their own law gives them.
Australia. We comply with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles. We collect health information and we provide services intended to maintain or improve your health, so we do not rely on the small business exemption. We treat ourselves as fully covered by the Act. We also comply with the Notifiable Data Breaches scheme, the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth), and with state and territory health records legislation where it applies to members living in those jurisdictions.
European Economic Area and United Kingdom. Where the EU GDPR or UK GDPR applies to our handling of your information, we comply with it. Section 7 sets out our legal bases and section 15 your rights. We have not appointed an EU or UK representative because we do not currently target our services at those markets. If that changes we will appoint one and update this policy.
New Zealand. We comply with the Privacy Act 2020 (NZ) and its Information Privacy Principles for New Zealand residents.
Canada. We comply with PIPEDA for Canadian residents.
United States. We honour the rights given by state privacy laws including the California Consumer Privacy Act as amended by the CPRA, and equivalent laws in Virginia, Colorado, Connecticut, Utah, Texas and other states as they commence.
Where two laws conflict, we apply whichever gives you the stronger protection.
4.1 Identity and contact information
Name, date of birth, gender (optional), email address, secondary email, mobile, home and work phone numbers, postal and residential address, occupation and employer (optional), and a photo for your member profile if you provide one.
4.2 Health and other sensitive information
This is the most sensitive category we hold, and we only collect it with your consent:
- Medical conditions, injuries, surgeries, medications and other health history you disclose on a pre-exercise questionnaire, a waiver, or verbally to a coach.
- Emergency contact details: name, relationship to you, phone and email. Please make sure that person knows you have given us their details.
- Coach notes about your training: modifications, movements to avoid, how you responded to a session, wellbeing observations relevant to programming.
- Performance and body data: strength and force plate testing results from our VALD equipment, body measurements, weight, and progress photos you choose to upload.
- Disability-related goals and plan information if you train with us under an NDIS self-managed or plan-managed arrangement.
We do not collect information about your racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record or union membership, and we ask that you do not send it to us.
4.3 Membership, booking and attendance information
Membership type and start date, contract term, class and personal training bookings, cancellations and no-shows, session attendance, gym entry and exit records from the door access system and check-in kiosks, and your access fob or tag identifier.
4.4 Payment and billing information
Billing name and address, membership pricing, direct debit and card payment records, invoices, receipts, arrears and payment failures.
Your card and bank account numbers are captured and stored by our payment providers, not by us. We use Ezidebit for recurring direct debit membership billing, Stripe for card payments including online coaching checkout, and Zeller for EFTPOS at the studio. We see only masked card details, the payment method type and the transaction outcome.
4.5 Online coaching information
If you use our app-based coaching, the coaching platform holds your programs, logged workouts, weights and reps, body metrics, habit and nutrition tracking you choose to enter, progress photos, and messages between you and your coach.
4.6 CCTV
We operate security cameras that record continuously, 24 hours a day, for the safety of members and staff, for access control and for incident investigation. This matters most for 24/7 access, when there is no coach in the building.
Coverage includes the entrance, the gym floor and the training and common areas. There are no cameras in the bathrooms or change areas. Footage is held for 30 days and is then automatically overwritten, unless we have kept a specific clip because of an incident. Signage is displayed at the entrance.
4.7 Website and technical information
When you use our websites, our website platform records your IP address, approximate location derived from it, browser and device type, operating system, referring page, the pages you view, how long you stay, what you click, and the campaign parameters that brought you here. Some of this comes from cookies and similar technologies. See section 12 for what we do and do not run.
4.8 Communications
Emails, SMS messages, web form submissions, live chat, social media messages and comments, call notes, review responses, and your marketing preferences and opt-outs.
4.9 Media for marketing
Photographs and video taken in the studio, member testimonials and stories, and content you tag us in. We only publish images in which you are identifiable if you have given us consent, and you can withdraw that consent at any time.
4.10 Job applicants
Resume, qualifications and certifications (including Cert III/IV, First Aid and CPR), work history, referee details, right to work evidence, and where the role requires it, a Working with Children or NDIS Worker Screening check result.
4.11 Information you are not required to give us
You can deal with us anonymously or under a pseudonym when you make a general enquiry, ask about pricing, or book a gym tour. We cannot do that for membership, training, billing or anything involving your safety in the gym, because we need to know who you are and what your body can do.
Directly from you: signup and enquiry forms on our website, the GymMaster signup and member portal, booking calendars, pre-exercise questionnaires and waivers, conversations with coaches and staff at the studio, email, SMS, phone and social media, and in-app entries in the coaching platform.
Automatically: cookies and tracking pixels on our websites, door access and check-in records, CCTV, and testing equipment on the gym floor.
From third parties, where you have authorised it or the third party is permitted to give it to us:
- Fitness Passport, if you access us through your employer’s corporate fitness scheme. We receive enough information to verify your eligibility and record your visits, and we report your visit counts back to Fitness Passport for billing.
- Referrers, including existing members and referral partners such as allied health practices. If someone gives us your details, we will tell you where we got them the first time we contact you.
- Advertising and social platforms, which give us aggregated campaign data and, where you submit a lead form on their platform, your contact details.
- Google, when you leave a public review of our business.
- Referees and screening bodies, for job applicants.
We use personal information to:
- Set up and manage your membership, contract and account.
- Program your training safely, which is the entire reason we ask about injuries and medical conditions. A coach needs to know what to avoid before they load you up.
- Run and staff sessions, and manage bookings, waitlists and cancellations.
- Give you access to the studio, including 24/7 access, and keep the building secure.
- Take payment, manage direct debits, chase arrears and keep accounting records.
- Track your progress and give you results from testing and assessments.
- Respond to enquiries, complaints and requests.
- Send you service messages: booking confirmations, schedule changes, payment failures, closures and safety notices. These are not marketing and you cannot opt out of them while you remain a member.
- Send you marketing, with your consent or where the law otherwise allows it. See section 8.
- Respond to accidents, injuries and medical emergencies, including contacting your emergency contact and giving relevant health information to paramedics or a treating practitioner.
- Improve our services, our website and our marketing, using analytics and aggregated reporting.
- Recruit, onboard and manage staff and contractors.
- Meet our legal obligations, including work health and safety, tax, insurance and, where relevant, NDIS record-keeping.
- Establish, exercise or defend legal claims, and enforce our terms and membership agreements.
We will not use your information for an unrelated purpose unless you would reasonably expect it, you have consented, or the law requires or permits it.
| What we do | Legal basis |
|---|---|
| Deliver your membership, sessions and coaching | Performance of a contract |
| Take payment and manage billing | Performance of a contract |
| Keep accounting, tax and insurance records | Legal obligation |
| Building security, CCTV, access control, fraud prevention | Legitimate interests: safety of members and staff, protection of property |
| Analytics, service improvement, business reporting | Legitimate interests: running and improving the business |
| Marketing emails and SMS | Consent, or legitimate interests for our own similar services to existing members, always with an opt-out |
| Advertising and analytics cookies | Consent |
| Health information, testing data, progress photos | Explicit consent, and where relevant Article 9(2)(h) for the provision of health-related services |
| Responding to a medical emergency | Vital interests |
| Publishing your photo, video or testimonial | Consent |
| Defending legal claims | Legitimate interests, and Article 9(2)(f) for health information |
With your consent, or where the Spam Act allows it because you are an existing member and the message is about similar services, we may send you:
- Email newsletters and campaigns.
- SMS messages about offers, events, challenges and re-engagement.
- Targeted or lookalike advertising on Meta, Google, TikTok and LinkedIn, which may involve us providing a hashed version of your email address or phone number to those platforms for audience matching.
Every marketing email has an unsubscribe link and every marketing SMS accepts STOP. You can also email info@mformfitness.com.au and ask us to stop, and we will action it. Opting out of marketing does not opt you out of service messages about your membership.
We do not sell your personal information, and we do not share it with third parties for their own direct marketing.
We disclose personal information to the following categories of recipient, only as far as they need it to do their job for us, and under contracts requiring them to protect it.
9.1 Our people
Coaches, studio staff, our bookkeeper and our directors, on a need-to-know basis. Coaches see the health and training information they need to program safely for you. All staff are bound by confidentiality obligations.
9.2 Service providers
| Provider | What They Do For Us | Where They Process Data |
|---|---|---|
| GymMaster (Treshna Enterprises Ltd) | Member management, memberships, bookings, check-in, door access, billing records | New Zealand |
| HighLevel Inc. (GoHighLevel / LeadConnector) | Website hosting, forms, booking calendars, CRM, email and SMS sending | United States |
| ABC Trainerize | Online coaching app, programs, tracking, in-app messaging | United States and Canada |
| VALD Performance | Force plate and strength testing platform, athlete profiles | Australia |
| Fitness Passport | Corporate fitness scheme eligibility and visit reporting | Australia |
| Ezidebit (Global Payments) | Recurring direct debit membership billing | Australia |
| Stripe | Card payments, including online coaching checkout | Australia, United States and Global |
| Zeller | EFTPOS card payments at the studio | Australia |
| Xero | Accounting and invoicing | Australia and New Zealand |
| Google (Workspace, Analytics, Business Profile, Ads) | Email and file storage, website analytics via Google Analytics, reviews, advertising | United States and Global |
| Meta Platforms (Facebook, Instagram) | Social presence, messaging, advertising, Meta Pixel, audience matching | United States and Global |
| TikTok, LinkedIn | Social presence and advertising | United States and Global |
We review this list as our systems change. It is accurate as at the last updated date at the top of this page.
9.3 Other recipients
- Emergency and medical services, if you are injured or unwell at the studio.
- Your employer’s scheme operator, being Fitness Passport, for visit verification and billing, if you joined through that scheme. We share your visit records, not your health information.
- Insurers, lawyers and professional advisers, where we need advice or need to deal with a claim.
- Government bodies, regulators, courts and law enforcement, where the law requires or authorises it. If we receive a request we consider improper or overly broad, we will push back on it.
- A buyer or successor, if we sell or restructure the business. We would require them to keep handling your information in line with this policy, and we would tell you.
We do not disclose your health information to anyone for marketing, and we do not use it in advertising audiences.
Several of our providers are based outside Australia, as set out in the table above. The main overseas destinations are New Zealand, the United States and Canada.
Before we disclose personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through contractual commitments and, where relevant, Standard Contractual Clauses or the UK Addendum for transfers out of the EEA and UK. Where a transfer relies on your consent, we will tell you and ask for it. You can ask us for more detail about the safeguards for a particular transfer.
We do use automated systems that process your information in routine ways: automatic direct debit processing, access control that opens the door when your tag is valid, marketing automation that decides which email sequence you receive, and advertising audience matching. None of these decide anything significant about you without a human involved.
If this changes, we will describe the logic, the information used and the consequences here, in line with the transparency requirements taking effect in Australia in December 2026.
Our websites use cookies and similar technologies:
- Strictly necessary: page delivery, security, session handling and form submission, set by our website platform. These cannot be turned off.
- Functional: remembering preferences and pre-filling forms.
- Analytics: understanding how people find and use the site so we can improve it. We use Google Analytics, which sets cookies and collects the technical information described in section 4.7.
- Advertising: measuring campaign performance and showing you relevant ads. We use the Meta pixel, which tells Meta that you visited our site or took an action such as starting a booking, so we can measure our advertising and show ads to people like you.
Separately from cookies, we advertise on Meta, Google, TikTok and LinkedIn, and that can involve providing a hashed version of your email address or phone number to those platforms for audience matching. That is described in section 8.
Your choices.
- Block or delete cookies in your browser settings at any time. Blocking strictly necessary cookies will break parts of the site.
- Opt out of Google Analytics across all websites using Google’s browser add-on.
- Control how Meta uses your activity through your Facebook or Instagram ad preferences.
- Email us and ask to be excluded from our advertising audiences.
If you are in a region that requires consent before non-essential cookies are set, including the EEA and the UK, we ask for your consent before setting analytics or advertising cookies, and you can change your choice at any time.
Global Privacy Control. We honour the GPC signal as an opt-out of the sale or sharing of personal information for targeted advertising where the law requires us to.
Some pages embed third-party content, such as booking calendars, checkout pages, review widgets and video players. Those providers may set their own cookies, and their privacy policies apply to what they collect.
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. These include:
- Reputable providers with their own security programs, rather than home-grown systems.
- Access controls, so staff only see what their role requires, and prompt removal of access when someone leaves.
- Multi-factor authentication on our core business accounts, and passwords held in a password manager rather than shared.
- API keys and credentials kept out of shared documents, and rotated if exposed.
- Encryption in transit for our websites and member portal.
- Physical security at the studio, including access control and CCTV.
- Card and bank details handled by PCI-compliant payment providers, not stored by us.
- Staff training on privacy and confidentiality.
No system is perfectly secure. We cannot guarantee the security of information you send us over the internet, and you send it at your own risk. If something does go wrong, section 16 explains what we do.
| Information | How Long We Keep It |
|---|---|
| Member records, contracts, health and training history | 7 years after your membership ends |
| Financial and billing records | 7 years, as required by the Corporations Act and tax law |
| Injury, incident and accident records | 7 years after the incident, longer if a claim is on foot, or until a minor turns 25 |
| Prospect and lead records where you never joined | 2 years after your last contact with us |
| Marketing subscriber records | Until you unsubscribe, plus a permanent suppression record so we do not contact you again |
| CCTV footage | 30 days, then automatically overwritten, unless a clip is kept for an incident |
| Door access and check-in logs | 2 years |
| Website analytics data | Up to 26 months |
| Job applications from unsuccessful applicants | 12 months, unless you ask us to keep you on file |
| Staff records | 7 years after employment ends |
Where we are required to keep a record, we will keep it even if you ask us to delete it, and we will tell you that is why.
15.1 Everyone
You can:
- Ask what we hold about you and get a copy.
- Correct anything inaccurate, out of date, incomplete or misleading.
- Withdraw consent you previously gave, including for health information, marketing and use of your photo. Withdrawing consent does not undo what we did before, and for health information it may mean we can no longer safely coach you.
- Opt out of marketing at any time.
- Complain to us, and then to a regulator. See section 18.
We will respond to an access or correction request within 30 days. We do not charge for making a request. We may charge a reasonable cost-based fee for giving access if the request is large, and we will tell you before we do. We will ask you to verify your identity first, so we do not hand your information to someone else.
We can refuse access or correction in the limited cases the Privacy Act allows, for example where giving access would unreasonably affect someone else’s privacy. If we refuse, we will tell you why in writing and how to complain.
15.2 Additional rights in the EEA and UK
You also have the right to erasure, to restrict processing, to data portability, to object to processing based on legitimate interests, and to object to direct marketing at any time. You can lodge a complaint with your national supervisory authority or, in the UK, the Information Commissioner’s Office.
15.3 New Zealand
You have the access and correction rights in the Information Privacy Principles, and you can complain to the Office of the Privacy Commissioner.
15.4 Canada
You have the right to access your personal information and challenge its accuracy, and to withdraw consent subject to legal and contractual restrictions. You can complain to the Office of the Privacy Commissioner of Canada.
15.5 United States
Depending on your state, you may have the right to know what we collect, to access a copy, to delete it, to correct it, to opt out of targeted advertising and of any sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights.
We do not sell personal information, and we do not share it for cross-context behavioural advertising in the sense those terms are used in the CCPA, other than the advertising cookies and hashed audience matching described in sections 8 and 12, which you can opt out of using the mechanisms in those sections or by emailing us. We do not knowingly sell or share the personal information of anyone under 16. You can use an authorised agent to make a request; we will ask for proof of authority.
15.6 Photos, video and testimonials
If you have agreed to appear in our marketing and change your mind, email us. We will stop using the material going forward and remove it from our own channels where we reasonably can. We cannot always retract material already published by third parties, reshared, or printed.
How to exercise any of these
Email info@mformfitness.com.au with “Privacy request” in the subject line, or write to us at the studio address in section 1.
The minimum age for membership is 18. We will consider a member under 18 only where a parent or guardian consents, signs the membership agreement, and completes the health questionnaire and waiver on their behalf. The parent or guardian’s contact details are recorded on the account, and they can exercise the rights in section 15 for their child.
We do not knowingly collect personal information from children under 16 through our websites without parental consent. If you believe a child has given us their information, email us and we will delete it.
Start with us. Email info@mformfitness.com.au with “Privacy complaint” in the subject line, or write to The Privacy Officer, Metaform Fitness, Ground Level, 100 Brookes Street, Fortitude Valley QLD 4006.
We will acknowledge your complaint within 5 business days and give you a written response within 30 days. If we need longer, we will tell you why and when to expect an answer.
If you are not satisfied, you can escalate to the regulator for your region:
| Region | Regulator |
|---|---|
| Australia | Office of the Australian Information Commissioner, oaic.gov.au, 1300 363 992 |
| United Kingdom | Information Commissioner’s Office, ico.org.uk |
| EEA | Your national data protection authority |
| New Zealand | Office of the Privacy Commissioner, privacy.org.nz |
| Canada | Office of the Privacy Commissioner of Canada, priv.gc.ca |
We review this policy at least annually and whenever we add or change a system that handles personal information. The current version is always at mformfitness.com.au/privacy, with the effective date at the top.
If we make a change that materially affects how we use your information, we will tell you by email or a notice on the website before it takes effect. Continuing to use our services after that means you accept the updated policy.