Privacy Policy

last updated: 20th October, 2024

INTRODUCTION 

This Privacy Policy applies to BASE ATTAK LTD PTY (“we,” “us,” or “our”) and our website, www.baseattak.com.au. 

BASE ATTAK is committed to protecting your personal information in accordance with the Australian Privacy Principles and other applicable data protection laws under the Information Privacy Act 2024. It is our policy to respect and uphold individuals’ privacy rights in the collection, use, and dissemination of personal information. 

This Privacy Policy outlines how we collect, use, and protect your personal information on our website. We are dedicated to ensuring your privacy and the security of your personal information. By using our website, you agree to the terms of this Privacy Policy. 

TERMINOLOGY 

Personal Information: Refers to any data that can be used to identify an individual, such as names, addresses, contact details, and similar information. 

Sensitive Information: Includes details related to political opinions, religious beliefs, professional or trade association memberships, sexual preferences, and health information of an individual. 

GENERAL PRINCIPLES 

The following principles guide our information-handling practices: 

  • We will not collect personal information unless it is essential for our business operations.
  • Personal information will only be collected lawfully and fairly.
  • Personal information will not be used or disclosed for purposes other than those for which it was collected, unless such use or disclosure is reasonably expected or explicitly authorised by the individual. 
  • We will take reasonable steps to ensure the personal information we hold is accurate, complete, and up-to-date.
  • We will take appropriate measures to protect personal information from misuse, loss, or unauthorised access. 
  • Where appropriate, we will inform individuals about the type of personal information we collect and hold. 
  • Upon request, and where applicable, individuals will be granted access to their personal information.
  • We will only transfer personal information to a foreign country if the recipient country has privacy laws comparable to those under Australian privacy legislation.
  • Sensitive information will not be collected without the individual's consent
  • ‍We retain your personal information only as long as necessary to fulfil the purposes outlined in this policy or as required by law. For instance, we keep transaction data for tax and regulatory compliance.

INFORMATION WE COLLECT 

We collect personal information directly from you through various channels, including phone calls, emails, our website, apps, or in person. 

When you visit our website, we may collect the following information: 

  • Personal Information: We may collect your name, email address, phone number, and other contact information when you send a comment via our submit a request via the online form or sign up for a newsletter. 
  • Usage Data: We may collect information about how you interact with our website and services. This includes data such as your IP address, browser type and version, the pages you visit, the date and time of your visit, time spent on each page, and unique device identifiers.

When Using Our Services 

If you sign up, book classes, or manage memberships through our third-party provider, Gymdesk, we may collect: 

  • Personal Information: First name, last name, username, marital status, date of birth, age, and gender. For customer support, you may need to provide your username and password details. 
  • Contact Information: Billing address, postal address, email address, and phone numbers needed to complete your application or membership agreement. 
  • Financial Information: Bank account and credit card details, which are processed securely through Gymdesk and not stored by us. Gymdesk complies with PCI-DSS standards to ensure secure payment handling.
  • Transaction Information: Details about payments made to us, services received, and records of communications.
  • Profile Information: Your username, interests, preferences, feedback, survey responses, and information obtained through Gymdesk when you use its services, enter competitions, or report issues.
  • Member Information: Attendance rates and usage details of our services, along with personal information, emergency contacts, and other relevant data.
  • Sensitive Information: Health-related data (e.g., injuries, medical conditions) that may be necessary for our services. This may include height, weight, diet (including nutritional plans), strength, body photographs, fitness goals/achievement, medical history, medications, smoking status, pregnancy status and other health-related information.
  • Marketing and Communications Information: Your preferences for receiving marketing communications, including invitations to events and relevant personal information.

 

Payment Processing 

Gymdesk may offer paid products and services. In these cases, Gymdesk uses third-party payment processors (e.g., Stripe) to handle payments. 

Important Points: 

  • Base Attak and Gymdesk do not store or collect your payment card details. These details are provided directly to our third-party payment processors. 
  • The use of your personal information by these payment processors is governed by their own Privacy Policy. 
  • Our payment processors comply with PCI-DSS standards, which are set by the PCI Security Standards Council, including major brands like Visa, Mastercard, American Express, and Discover. These standards ensure the secure handling of payment information.

Stripe 

Their Privacy Policy can be viewed at 

https://stripe.com/us/privacy 

Gymdesk 

Their Privacy Policy can be viewed at 

https://docs.gymdesk.com/help/privacy 

https://gymdesk.com/page/mobile-app-privacy-policy 

https://gymdesk.com/page/terms

COOKIE POLICY 

We use cookies and similar technologies to enhance your experience on our website and for analytics purposes. You can manage your cookie preferences through your browser settings. 

For more information about the cookies Gymdesk uses and your choices regarding cookies, please visit Gymdesk Cookies Policy or the Cookies section of their Privacy Policy. 

HOW WE USE YOUR INFORMATION 

We may use your personal information for the following purposes: 

  • To Provide Services: Deliver the products or services you have requested.
  • Booking Management: Facilitate class bookings and schedule changes.
  • Safety and Well-being: Ensure your safety during fitness classes.
  • Payment Processing: Manage payments and memberships.
  • Marketing Communications: Send you information about our products and services, including promotions for Base Attak events.
  • Website Improvement: Enhance our website and the products and services we offer.
  • Legal Compliance: Meet legal and regulatory requirements. 
  • Account Support: Assist you when you register for an account or request support.
  • Class Modifications: Process any modifications to classes. 
  • Member Identification: Distinguish members from non-members to maintain safety and security within our services. 

HOW WE PROTECT YOUR INFORMATION 

We take the security of your personal information seriously and implement appropriate measures to protect it from unauthorised access, use, or disclosure.

 

  • Third-Party Service Providers: We partner with service providers like Gymdesk, which ensure secure hosting environments and use encryption for data storage and transmission. (You can view their security measures in their Terms)
  • Encryption Technologies: We utilise industry-standard encryption to safeguard your payment information and other personal data. However, please note that no method of online transmission or electronic storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security. 
  • External Links: Our website may contain links to third-party sites, including social media platforms. We are not responsible for the privacy practices or content of these external sites.

Data Breach Notification 

In the event of a data breach, we will notify affected individuals and the relevant authorities within the legally required time frames.

SHARING YOUR INFORMATION 

Base Attak will only share your personal information with your written consent, except when required by law. We may also use your information internally for advertising or marketing purposes related to Base Attak services, products, or events. 

  • Email Communications: We will only send you emails if you have opted in to receive them or if they are in response to your inquiries. We use return email addresses solely to respond to your messages and may share these addresses with third-party service providers to facilitate email transmission. All other communications will occur through your Gymdesk account. 
  • Privacy of Your Information: We do not use or share personally identifiable information for purposes beyond what we have described without giving you the opportunity to opt out or restrict such uses. 
  • Third-Party Service Providers: We may share your personal information with third-party service providers for services such as payment processing, email marketing, and website analytics. We require these providers to protect your personal information and use it only for the purposes we specify. 
  • Non-Identifying Data: We may also use aggregated, non-identifying data for market research, planning, website improvement, or sharing insights with advertisers and partners. For example, we might inform advertisers about visitor numbers to specific areas of our website or the demographic breakdown of registration submissions. 

Disclosure Without Prior Authorization 

In certain circumstances, Base Attak may be legally permitted or required to disclose your personal information without your written consent, including: 

  • When there is reason to believe that disclosure is necessary to prevent a threat to health or life; 
  • If Base Attak suspects unlawful activity and personal information is needed to investigate the suspected misconduct; 
  • When disclosure is required or authorised by law or reasonably necessary to enforce legal obligations. 
  • If we believe that such disclosure is necessary to protect our rights, property, or safety or the rights, property, or safety of others.

YOUR CHOICES 

Marketing Consent (Opt-In/Opt-Out)

We may send you promotional emails about new classes or events only if you have opted in to receive them. You can opt out at any time by clicking the 'unsubscribe' link in the email or by contacting us directly. 

Please note that even if you opt out of marketing communications, you may still receive transactional or administrative messages related to your account or any products and services you have requested.

Your Rights Regarding Your Personal Data 

You have rights concerning your personal data, which you can exercise by contacting us. We may require you to verify your identity before processing any requests. We will aim to respond to your request as quickly as possible.

 

Your Rights Include: 

  • Access, Update, or Delete Your Personal Data: You can access, update, or request deletion of your personal data directly through your Gymdesk account settings. If you need assistance, please contact us. You are also entitled to request a copy of the personal data we hold about you. 
  • Correct Your Personal Data: If the information we have about you is incomplete or inaccurate, you can request that it be corrected. 
  • Object to Processing: You may object to our processing of your personal data if we are relying on legitimate interests for processing and you have specific reasons related to your situation. You also have the right to object if we process your personal data for direct marketing purposes. 
  • Request Erasure: You can request the deletion of your personal data if there is no valid reason for us to continue processing it. 
  • Withdraw Your Consent: If you have consented to our processing of your personal data, you can withdraw that consent at any time. Please note that withdrawing consent may limit your access to certain features of our services. 

CONSENT 

By providing your health information, you consent to its use for ensuring your safety during fitness activities. You may withdraw your consent at any time by contacting us.

 

PRIVACY NOTICE UPDATES 

We may update this privacy notice as necessary to reflect changes in privacy laws, regulations, or industry best practices. These revisions aim to maintain the protection of your personal information and ensure compliance with evolving legal requirements.

 

If we make significant changes to this policy, we will notify you via email or by posting a notice on our website. If you have any objections to the Privacy Policy, please refrain from accessing or using the site. 

UPDATING CONTACT DETAILS AND COMMUNICATION PREFERENCES 

You may update your contact details or opt-out of receiving marketing materials and other communications from Base Attak at any time by contacting us via telephone at 0490 778 937 or by writing to baseattak@hey.com