Privacy Policy

Effective date: 18 August 2024
Last updated: 27 July 2026

At HerBod, we are committed to protecting your privacy and handling your personal information responsibly. This Privacy Policy explains how we collect, use, store and disclose personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Health Records Act 2001 (Vic) and the Health Privacy Principles.

1. Who We Are

HerBod is a private women-only gym located in Monbulk, Victoria. We provide gym memberships, personal training, small group training, customised exercise programs and health and fitness coaching.

HerBod
ABN 85 519 257 101
1/142 Main Road
Monbulk VIC 3793
Email: accounts@herbod.com.au

2. What Information We Collect

Depending on your interactions with HerBod and the services you use, we may collect the following information.

Personal information

  • Name

  • Date of birth

  • Address

  • Email address

  • Phone number

  • Emergency contact details

  • Parent or legal guardian details for members under 18

Membership information

  • Membership type and status

  • Attendance and check-in records

  • Booking history

  • Training and program information

  • Communications and membership notes

  • Extended Access permissions and entry records

  • Payment and billing information

Health and fitness information

To assess exercise suitability and provide safe and appropriate coaching, we may collect:

  • Medical conditions

  • Current or previous injuries

  • Pain, physical limitations or movement restrictions

  • Relevant medication information

  • Pregnancy or postnatal status

  • Exercise and training history

  • Fitness goals and preferences

  • Pre-exercise screening responses

  • Information provided by a health or allied-health professional

  • Body measurements, progress records or assessment results where applicable

Health information is sensitive information. We only collect health information that is reasonably necessary to provide our services and with your consent where required.

Please tell us if your health circumstances change. Providing incomplete or inaccurate health information may affect our ability to provide services safely.

Website and digital information

When you use our website, member application or other digital services, we may automatically collect:

  • IP address

  • Browser and device information

  • Pages visited

  • Time spent on pages

  • Website interactions

  • Cookies and analytics information

CCTV and access information

CCTV may operate within and around HerBod. We may also record the date and time members enter or attempt to enter the facility using the Extended Access system.

3. How We Collect Information

We may collect information when you:

  • Complete an enquiry or contact form
  • Join as a member
  • Create or use a Gymdesk member account
  • Book or attend an appointment or session
  • Purchase a membership or service
  • Establish a Direct Debit arrangement
  • Apply for or use Extended Access
  • Contact us by telephone, email, SMS or social media
  • Complete a health screening, membership or consent form
  • Participate in an assessment or program review
  • Visit our website
  • Participate in a promotion, challenge or event
  • Provide feedback or make a complaint

We generally collect information directly from you. We may also collect information from a parent, legal guardian, carer, authorised representative, emergency contact or health professional where you have consented or collection is otherwise permitted by law.

4. Why We Collect Your Information

We may collect, hold and use your information to:

  • Respond to enquiries
  • Provide and administer memberships
  • Manage member accounts and bookings
  • Provide gym and Extended Access
  • Develop safe exercise programs
  • Provide personal training and coaching
  • Modify exercises to suit individual needs
  • Manage attendance and facility capacity
  • Communicate about memberships, bookings and services
  • Process payments and administer Direct Debits
  • Provide customer support
  • Monitor member progress
  • Contact an emergency contact where reasonably necessary
  • Maintain the safety and security of members and the premises
  • Investigate incidents, complaints or unauthorised access
  • Improve our services and member experience
  • Maintain business and financial records
  • Meet our legal, insurance and safety obligations

With your consent or where otherwise permitted by law, we may also send you newsletters, promotions, event information and gym updates.

You may unsubscribe from marketing communications at any time. We may still contact you with important operational messages relating to your membership, payments, appointments, safety or facility access.

5. Third-Party Service Providers

We do not sell or rent your personal information.

We use trusted third-party providers to operate HerBod and deliver our services. These currently include:

Gymdesk

We use Gymdesk to manage:

  • Member accounts and contact details

  • Memberships

  • Bookings

  • Attendance and check-ins

  • Member communications

  • Forms and membership records

Information entered into your Gymdesk account or collected through Gymdesk may be processed in accordance with Gymdesk’s privacy policy.

GoCardless

We use GoCardless to process Direct Debit payments.

GoCardless may collect and process information including your name, contact details, bank account information, payment authority and transaction history. HerBod does not independently store all banking information handled through the GoCardless payment system.

More information about how GoCardless processes personal information and your privacy rights is available in the GoCardless Privacy Centre.

Gallagher Security

We use Gallagher Security technology to manage Extended Access.

This system may process:

  • Member identity and access credentials

  • Extended Access permissions

  • The date and time of facility entry

  • Successful or unsuccessful access attempts

  • Information required to investigate an access or security incident

Other providers

We may also disclose relevant information to:

  • Website hosting and IT providers

  • Email and communications providers

  • Accountants, insurers and professional advisers

  • Contractors assisting with our services

  • Emergency services

  • Government, regulatory or law-enforcement authorities where required or authorised by law

We only disclose information reasonably necessary for these providers to perform their services.

6. Overseas Processing and Storage

Some third-party providers may store or process personal information outside Australia.

In particular, GoCardless states that most of its personal information is processed through its United Kingdom operations and may be shared with related entities and service providers in other countries.

Other technology providers may also use overseas servers or support services. Where information is disclosed or processed overseas, we take reasonable steps required by Australian privacy law to ensure it is appropriately protected.

7. Health Information

We may use health information to:

  • Assess exercise suitability
  • Identify potential risks
  • Develop personalised exercise programs
  • Modify or progress exercises
  • Reduce the risk of injury
  • Provide safe and appropriate coaching
  • Respond to an injury or emergency
  • Communicate with a health professional where you have provided consent

We will not use health information for an unrelated purpose unless you consent or the use is otherwise permitted or required by law.

8. Data Security

We take reasonable steps to protect personal and health information from:

  • Unauthorised access
  • Misuse
  • Interference
  • Loss
  • Improper disclosure
  • Unauthorised alteration

Information may be stored electronically or in paper form using secure systems, reputable third-party providers, password protection, access controls and physical security measures.

Although we take reasonable precautions, no electronic transmission or storage system can be guaranteed to be completely secure.

If an eligible data breach occurs, we will respond in accordance with the Notifiable Data Breaches scheme and other applicable legal requirements.

9. CCTV and Extended Access

CCTV may operate within and around HerBod for:

  • Member and visitor safety
  • Facility security
  • Incident investigation
  • Investigating theft, damage or unauthorised access
  • Monitoring compliance with membership and Extended Access conditions

CCTV footage and access records are only accessed where reasonably necessary. They may be disclosed to police, emergency services, insurers, legal advisers or other authorised parties where permitted or required by law.

10. Photography and Social Media

From time to time, we may take photographs or videos inside the gym or during HerBod activities and events.

We will seek permission before using an identifiable image or recording of a member for:

  • Social media
  • Advertising
  • Marketing
  • Website content
  • Printed promotional material

You may decline without affecting your membership or access to HerBod services.

Parent or legal guardian permission will be obtained before using identifiable promotional images of a member under 18.

Members and visitors must not photograph or record another person inside HerBod without their permission.

11. Cookies

Our website may use cookies and similar technology to:

  • Provide website functions
  • Improve website performance
  • Understand how visitors use the website
  • Remember user preferences
  • Improve your browsing experience

Most browsers allow you to restrict or disable cookies. Some website features may not function correctly if cookies are disabled.

12. Accessing or Correcting Your Information

You may request access to the personal or health information we hold about you.

You may also ask us to correct information that is inaccurate, incomplete, out of date or misleading.

We may need to verify your identity before processing your request. In limited circumstances, the law may permit or require us to refuse access. If this occurs, we will generally explain the reason unless doing so would be unlawful.

Requests can be sent to accounts@herbod.com.au.

13. Retention of Information

We retain personal and health information for as long as reasonably necessary to:

  • Provide our services
  • Maintain membership and training records
  • Meet legal, taxation, insurance and record-keeping obligations
  • Resolve disputes or complaints
  • Investigate incidents
  • Enforce our agreements

Health information will be retained for any minimum period required under Victorian law.

When information is no longer required, we take reasonable steps to securely destroy or permanently de-identify it, unless we are required or authorised to retain it.

14. Third-Party Websites and Applications

Our website, Gymdesk member application, Extended Access application, emails and social media pages may contain links to websites or services operated by third parties.

Those third parties manage personal information according to their own privacy policies. HerBod is not responsible for the content or privacy practices of independently operated third-party services.

15. Privacy Complaints

If you believe your privacy has been breached or your information has been mishandled, please contact us first so we can investigate and respond.

Please provide details of your concern and the outcome you are seeking. We will investigate your complaint and respond within a reasonable period.

16. Changes to This Policy

We may update this Privacy Policy when our services, systems, providers or legal obligations change.

The current version will be available on our website and will display the date it was last updated.

17. Contact Us

If you have questions about this Privacy Policy, wish to request access or correction, or would like to make a privacy complaint, please contact:

HerBod
ABN 85 519 257 101
1/142 Main Road
Monbulk VIC 3793
Email: accounts@herbod.com.au