Privacy policy
More information
Lift Inner West Inner West Lift Pty Ltd (ABN 72 678 191 252) ("we", "us", "the studio") is a personal training and exercise physiology studio in Marrickville, Sydney. Because we provide health services and hold health information, we are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and by the NSW Health Records and Information Privacy Act 2002 (HRIPA). This policy explains what we collect, why, where it lives, who can see it, and your rights.
If you only read one paragraph, read this one: we collect your health information because we cannot train you safely without it, we store it in Australia, we deliberately keep it out of our overseas-hosted marketing and messaging tools, we never sell it, and you can see, correct or ask about any of it by emailing kris@liftinnerwest.com.au.
1. What we collect
Contact and identity details - your name, email, phone number, date of birth and emergency contact.
Health information - your answers to our pre-exercise screening and intake forms (health conditions, injuries, medications, relevant history), measurements, strength test results, and notes your trainer records about your sessions. If you see one of our accredited exercise physiologists, we also keep a clinical record (treatment notes and health fund claiming details) as the law requires.
Training data - your bookings, attendance, programs, logged workouts and results.
Photos - progress photos and meal photos, only if you have said yes to them (each has its own separate consent on our client agreement, and you can train with us without either).
Payment information - your direct debit arrangement is set up with and held by our payment provider; we hold your payment history (amounts and dates), not your bank or card details.
NDIS information - if you are an NDIS participant, your plan dates, goals relevant to your training, and your plan manager's contact details for invoicing.
Communications - emails and text messages between you and the studio.
A guardian's details - if you are under 18, your parent or guardian's name, contact details and signed consent.
We collect this directly from you (your forms, your conversations with your trainer, the client app), from your trainer's records of your sessions, and, if you are referred to our exercise physiology service, from your referrer with your knowledge.
2. Why we collect it
To deliver safe, effective training - screening, programming and progress tracking are the service.
To keep proper clinical records for exercise physiology services, as required by law.
To run your membership - bookings, reminders, billing and account administration.
To communicate with you about your sessions and your membership.
To meet our legal obligations - health record retention, tax and accounting, and responding to lawful requests.
To improve how the studio runs, using aggregated information that does not identify you.
For marketing (such as sharing your progress story) only with your separate, explicit opt-in, confirmed with you before each use. Saying no changes nothing about your service.
We do not use your information for automated decision-making, we do not use it to train AI models, and we never sell it.
3. Where your information lives
In plain terms:
Your health information, programs, results and photos live in PULSE, our own system, in a secure database hosted in Sydney, Australia. Access is restricted: your assigned trainers and the studio owner can see your records; other trainers cannot browse them; you can see only your own.
Photos are stored in private, access-controlled storage in that same Sydney database. They are never public, links to them expire, and only you, your assigned trainers and the studio owner can view them.
Your clinical exercise physiology record (if you see an EP) is kept in Nookal, an Australian practice management system.
Your intake and agreement forms are collected through Snapforms, an Australian forms provider.
Your contact details, bookings and our messages to you are managed in our client management system, GoHighLevel, which is hosted in the United States. We deliberately keep your health details out of that system: where a health record exists, GoHighLevel stores only a marker pointing back to PULSE, never the detail.
Your direct debit details (bank or card) are held by our payment provider, FFA PaySmart, an Australian direct debit company - not by us.
Our accounting (invoices and income records, including NDIS invoices addressed to your plan manager) lives in Xero.
4. Overseas disclosure
Most of your information, and all of your stored health information, stays in Australia. The exceptions we want you to know about:
GoHighLevel (United States) holds your contact details, booking history and our message threads with you. This is why our client agreement asks for your consent to that storage when you join. If you mention health details in a text or email conversation with us, those messages live in that system too - our systems never copy your health records there, but we cannot un-say what is written in a message thread.
Our web infrastructure routes traffic through international servers even though the data itself rests in Sydney.
Xero (accounting) may process invoice data outside Australia.
We remain accountable under Australian privacy law for information we send overseas, and we minimise what goes: health information is deliberately excluded from the overseas systems.
5. Who can see your information
Your assigned trainers and the studio owner - your full training record, to deliver your service.
Our exercise physiologists - your clinical record, if you use the EP service.
Studio contractors who help run our client messaging, under signed confidentiality agreements.
Your NDIS plan manager - invoice details only (your name, the service and the amount), if you are plan-managed.
Our service providers listed in section 3, each only for the purpose described there.
Professional advisers (accountant, lawyer, insurer) where genuinely required, and government bodies where the law requires it.
Nobody else. We do not share, rent or sell client lists, and we do not disclose your information for anyone else's marketing.
6. How we protect it
Health records are stored in Australia with access enforced in the database itself, not just the app screens - each person can only reach the records their role allows.
Staff sign in through secured, studio-controlled accounts; clients sign in with one-time email codes, so there is no client password to steal.
Photos live in private storage with expiring links.
Payment card and bank details never touch our systems.
Access by our systems' administrators is logged, and we maintain a written data breach response plan: if a breach ever put you at likely risk of serious harm, we would notify you and the Office of the Australian Information Commissioner (OAIC) as the Notifiable Data Breaches scheme requires.
7. How long we keep it
Health records are kept for the periods NSW law requires: 7 years after your last visit for adults, or until age 25 if you were under 18 when we treated or trained you. After the required period, records are securely deleted. Photos you ask us to delete are removed within 14 days of your request, unless a photo forms part of your clinical record, in which case the law requires us to keep it for the record retention period (we will tell you if that applies).
8. Your rights - access, correction, withdrawal
See your information: email kris@liftinnerwest.com.au or ask your trainer. We will provide it within 30 days, free of charge for reasonable requests.
Correct it: tell us and we will fix it promptly. Much of your record (contact details, measurements, workout history) is also visible to you in the client app.
Withdraw a consent: photo and marketing consents can be withdrawn at any time, effective immediately. Because we cannot train you safely without your health information, withdrawing that consent means ending your membership - talk to Kris and we will sort out your records properly, including what we are required by law to retain.
Opt out of marketing: every marketing message has an unsubscribe option, or just tell us. Service messages about your bookings and account continue while you are a member.
9. Complaints
If you think we have mishandled your information, please tell us first: email kris@liftinnerwest.com.au with "privacy" in the subject line. We will acknowledge your complaint within 7 days and respond fully within 30. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992) or, for health information in NSW, the NSW Privacy Commissioner (ipc.nsw.gov.au).
10. The website and the client app
Our website and the PULSE client app use cookies only for essential purposes - keeping you signed in and remembering your session. We do not run advertising trackers in the client app. Reviews shown on our website are public Google reviews.
11. Changes to this policy
When our practices change, this policy changes in the same breath - we keep it matched to what we actually do. Material changes are notified to current clients by email. The date at the top is the version date.
Contact: Kris Mount, Lift Inner West, Marrickville NSW - kris@liftinnerwest.com.au