Last Updated: 25 March 2025
1. OVERVIEW(a) HGB Studio Pty Ltd ATF the M&H Trust trading as North Flow Pilates (ABN 19 691 289 572) (North Flow Pilates, We, Our, Us) operates a Pilates studio business (Business), which provides Pilates instruction and other fitness services to customers (Services).

(b) Our website is located at www.northflowpilates.com (Website), and our North Flow Pilates mobile software application can be downloaded from Apple Store (Application). On Mindbody online, you can find us as North Flow Pilates.

(c) We are committed to protecting the privacy of individuals (You, Your, Yourself) we interact with in connection with the provision of our Services, through the Website, Application and otherwise in relation to the operation of our Business. We only ask for your personal information when we require it to provide the Services to you.

(d) We will handle Personal Information that we collect or obtain in connection with the provision of our Services in accordance with this Privacy Policy and Collection Policy (Policy) and the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles which are set out in the Privacy Act (Australian Privacy Principles). Personal Information has the meaning as defined in the Privacy Act (Personal Information).

(e) This Policy contains information about:

(i) how you may access your Personal Information held by us;

(ii) how to seek the correction of your Personal Information held by us; and

(iii) how to make complaints about any privacy-related concerns.

(f) This Policy also provides you with notice of the collection of your Personal Information by us.

(g) If we change this Policy, we will display the updated Policy on the Website and Application and we may also advise you in writing. If you object to any changes, you may contact us, and we will attempt to resolve your complaint within a reasonable time.

(h) By using our Services or otherwise supplying us your Personal Information, you consent to our collection, use, disclosure, storage, destruction and otherwise handling of Personal Information, in accordance with the terms of this Policy and the Australian Privacy Principles.

(i) If you provide a pseudonym to us or wish to remain anonymous, you can browse and view the Website and Application without restrictions, however we may not be able to provide you with the full extent of our Services and our interactions with you in relation to the Business may be limited. We may require that you accurately identify yourself so that we can take reasonable steps to provide accurate information as part of providing our Services (for example, we require our clients, suppliers, and associates to provide accurate contact details).

2. HOW DO WE COLLECT YOUR PERSONAL INFORMATION?

We may collect Personal Information through the following avenues:

(a) where you have requested our Services to be provided to you;

(b) where you complete a form or registration process in relation to our Services on the Website or Application, at our studio premises or otherwise;

(c) where you have inquired or otherwise communicated with us in person, over email or phone, or otherwise;

(d) where you make a booking for our Services;

(e) via our social media accounts where you wish to interact with us;

(f) where you attend an appointment for our Services;

(g) where you are interacting with the Website and Application, through the use of browser cookies or trackers; and

(h) in such other situations, which we will inform you from time to time, where we collect personal information from you that is reasonably necessary for the operation of our Website and Application and to provide the Services.

3. WHAT PERSONAL INFORMATION DO WE COLLECT?

(a) The kinds of Personal Information we may collect from you will depend on who you are (e.g. a client, supplier or prospective employee or contractor) and the nature of your interaction with us.

(b) We collect, use, and store the following types of Personal Information:

(i) For current, former, and prospective customers:

(A) Names;

(B) Addresses and email addresses;

(C) Phone numbers;

(D) Gender;

(E) Date of birth;

(F) Next of kin;

(G) Billing information;

(H) Health information, such as fitness status, pregnancy information and pre-existing medical conditions; and

(I) Other Personal Information that you may voluntarily provide to us to assist us to provide our Services

(ii) For current, former, and prospective suppliers:

(A) contact details such as names, email addresses, phone numbers, office address, postal address, and other geographical information;

(B) details about suppliers’ employee, directors, contractors, agents, and other representatives such as dates of birth, gender, email addresses, phone numbers, titles, and qualifications;

(C) business information such as banking details, business registrations, pricing information, hourly rates, and payment details; and

(D) other Personal Information that you may voluntarily provide to us to assist us to engage in a business relationship with you.

(iii) For prospective employees or contractors who will assist us to provide the Services to customers:

(A) contact details such as names, email addresses, phone numbers, office address, postal address, and other geographical information;

(B) details such as dates of birth, gender, titles, and qualifications;

(C) information we obtain about you from background and reference checks; and

(D) other Personal Information that you may voluntarily provide to us to assist us to consider whether to employ you.

(iv) Information about our staff, representatives and officers as required in the normal course of human resource management and business operations.

(v) Other Personal Information that you may voluntarily provide to us to assist us to conduct Business and provide our Services.

(c) Where:

(i) If you wish to receive our Services, some of the personal information we collect form you may be sensitive information as defined in the Privacy Act. We may need to collect sensitive information from you if you are a patient in order for us to provide our Services to you. Sensitive information may include things like information about your health, medical records, health history and test results. We will only collect sensitive information with your consent and through secure methods.

(ii) You wish to personally supply goods or services to us, engage us to provide Services to you or otherwise enter into a commercial relationship with us, you must provide accurate Personal Information to us as it will be impracticable for us be involved in a commercial relationship with you unless you do so (for example, we would not be able to meet with you, discuss work with you, communicate with you by email and phone or send you draft and completed deliverables).

(iii) You are not an individual but wish to supply goods or services to us, engage us to provide Services to you or otherwise enter into a commercial relationship with us, you must provide accurate Personal Information to us of the individual representatives of your organisation, as it will be impracticable for us be involved in a commercial relationship with you unless you do so (for example, we would not be able to meet with you, discuss work with you or communicate with you by email and phone).

4. WHAT DO WE DO WITH YOUR PERSONAL INFORMATION?

(a) We will not sell or trade your Personal Information to any third party, organisations, or individuals without your consent.

(b) We may use and disclose your personal information for the following purposes subject to clause 4(c) – clause 4(e):

(i) to provide you with further information about our Services, Website and Application;

(ii) to contact you in connection with the Services;

(iii) to provide our Services to you;

(iv) to personalise your experience of our Services and the Website and Application;

(v) to respond to feedback and complaints;

(vi) for enforcement of any contracts, you are a party to on our Website and Application ;

(vii) for direct marketing purposes with your consent (see section 8 below);

(viii) to notify you of important changes to our Website and Application or content on the Website and Application that may be of interest to you;

(ix) to understand customer trends and patterns so we can continue to develop our marketing and advertising strategies; and

(x) for any other purpose for which you give your consent.

(c) Where we collect any sensitive information about you, we use the sensitive information to help us provide our Services to you, for example, to understand whether you have any pre-existing health conditions and to tailor our Services accordingly. Otherwise, we do not use the sensitive information.

(d) We may also disclose your Personal Information:

(i) to third parties used by us to assist us to provide you with our Services, including our freelance contractors, other contractors (such as bookkeepers), technology service providers (such as website hosting service providers), social media providers, marketing agencies and targeted marketing facilitators; and

(ii) to lessen or prevent serious threats to the health and safety of an individual or the general public;

(iii) to assist in locating missing individuals;

(iv) to any duly authorised law enforcement officer, or any other person, authorised by any law to receive your Personal Information from us; and

(v) in circumstances permitted by the Privacy Act.

(e) We will not disclose sensitive information to any third party unless we have your consent or are otherwise permitted or required by law to do so.

5. HOW DO WE HOLD YOUR ELECTRONIC INFORMATION?

Where we hold your Personal Information, we will hold it by storing it electronically, by exporting it onto a computer or in hard copy.

6. DO WE SEND YOUR PERSONAL INFORMATION TO PARTIES OUTSIDE AUSTRALIA?

(a) From time-to-time, we use third-party service providers for digital cloud storage, web hosting or other technology-related Services in connection with providing our Services. We may disclose your Personal Information to these third party Services providers who may operate outside of Australia or operate in Australia with servers located outside of Australia (International Operators). We use third-party service providers for cloud storage, webhosting, email hosting or other technology service. We note as of the date of this Policy, we use the following key International Operators: Mailchimp, Google Cloud and Mindbody.

(b) As some of our third-party service providers operate globally, we cannot say with certainty where their servers are located or the countries out of which they operate at any given time. Further, these locations may be subject to change without notice to us.

(c) The Privacy Act and corresponding Australian Privacy Principle 8.1 requires us to ensure that, before disclosing Personal Information overseas, reasonable steps are taken to ensure that overseas recipients do not breach the Act or the applicable Australian Privacy Principles. It is not always possible for us to ensure that multinational companies, such as Facebook/Meta, Tik Tok, Twitter/X and Instagram, will not breach the Privacy Act or the applicable Australian Privacy Principles.

7. ARE WE RESPONSIBLE FOR THIRD PARTIES’ WEBSITES AND SOCIAL MEDIA LINKS?

(a) This Policy applies solely to Personal Information collected with regard to providing our Services, the operation of our Website and Application and otherwise in connection with the operation of our Business.

(b) We are not responsible for the collection of information and/or privacy practices of our third party websites that may be linked to from our Website and Application from time-to-time, or social media platforms which may be accessed via links on our Website and Application or on our emails.

(c) We refer you to the privacy policies and terms of use of the operators of any linked third party websites.

8. WILL WE SEND DIRECT MARKETING COMMUNICATIONS TO YOU?

(a) Your Personal Information may be used to offer you new goods and services, notify you of new developments to our existing goods and services, or any other promotional communication related to our goods and services, our studio or other things relating to our business.

(b) We may use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For more information about how targeted advertising works and how to opt out, you can visit the Your Online Choices educational page at https://youronlinechoices.com.au/opt-out/.

(c) If you do not wish to receive direct marketing communications from us, you may opt-out any time by clicking a link on the email communications sent to you or contacting us (see section 12).

(d) Additionally, you can opt out of targeted advertising on some of our third party advertisers using the following links:

(i) https://www.google.com/settings/ads/anonymous

(ii)https://www.facebook.com/settings/?tab=ads

(iii) http://optout.networkadvertising.org/

9. DO WE COLLECT PERSONAL INFORMATION THROUGH COOKIES AND ANALYTICS TOOLS?

(a) We collect device information, including information about your web browser, IP address, time zone, some of the cookies that are installed on your device, individual web pages or products that you view, what websites or search terms referred you to the Site, and information about how you interact with the Site using cookies and log files.

(b) We may use cookies technology to store data on your computer using the functionality of your browser. Many websites do this because cookies allow our Website and Application publisher to do useful things like find out whether the computer has visited the site before. You can modify your browser to prevent cookie use but if you do this, our Services (and our Website and Application ) may not work properly. The information stored in the cookie is used to identify you. This enables us to operate an efficient service and to track the patterns of behaviour of visitors to our Website and Application .

(c) In the course of serving advertisements to our Website and Application (if any), third-party advertisers or ad servers may place or recognise a unique cookie on your browser. The use of cookies by such third party advertisers or ad servers is not subject to this Policy but is subject to their own respective privacy policies.

(d) You can find out more about what a cookie is and how they’re used for targeted marketing purposes at this link: https://www.oaic.gov.au/privacy/your-privacy-rights/advertising-and-marketing/targeted-advertising

(e) We use Google Analytics to help us understand how our customers use our website. You can opt out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.

10. HOW DO WE KEEP PERSONAL INFORMATION SECURE?

(a) You should be aware that there are inherent risks associated with the transmission of information via the Internet. Data security measures can never be guaranteed. This means that while we take steps to protect your Personal Information, we cannot guarantee its security.

(b) If you suspect any misuse, loss, unauthorised access, modification, or disclosure of your Personal Information, please contact us immediately.

11. WILL WE TRANSFER YOUR PERSONAL INFORMATION?

If we are involved in a sale, merger, consolidation, change in control, transfer of substantial assets, reorganisation, or liquidation, we may, in our sole discretion, transfer, sell or assign your Personal Information collected by us to one or more relevant third parties.

12. WHAT IF YOU HAVE QUESTIONS OR COMPLAINTS?

(a) If you:

(i) have any questions about this Policy;

(ii) wish to request access to any Personal Information that we hold;

(iii) wish to be de-identified, or have your personal information deleted;

(iv) wish to correct or update your Personal Information; or

(v) wish to make a complaint or discuss any other privacy concerns you may have,

please contact us at:

email: Attention: The Privacy Officer, admin@northflowpilates.com; or

post: Attention: The Privacy Officer, 74 North St Hadfield VIC 3046.

(b) We reserve the right to charge for reasonable expenses that we may incur in preparing and sending you a copy of your Personal Information.

(c) If you believe we have breached our obligations under this Policy or the Australian Privacy Principles, please give us the opportunity to resolve matters by contact us first, in writing by email or by post. Once we have received a complaint, we will try to work with you to resolve the matter. The steps we may take to resolve the matter include:

(i) We may request further information from you. This will enable us to investigate the complaint and determine an appropriate solution.

(ii) We will discuss options for resolution with you. If you have suggestions about this this matter, please raise these with our Privacy Officer.

(iii) Where necessary, we will conduct an investigation and endeavour to do so within a reasonable time. we may have to conduct others in order to progress the investigation.

(d) If you are not satisfied with our response to your complaint, you may wish to contact the Office of Australian Information Commissioner (OAIC). For more information, please see their website https://www.oaic.gov.au/about-us/contact-us. Please note that the OAIC may decline to investigate until you have first raised the matter with us.