Privacy Policy.
Empower Pilates Group Pty Ltd (ABN 48 647 518 938)
186 Great Eastern Highway, Midland WA 6056
2/308 The Broadway, Ellenbrook WA 6069
1. About this policy
Empower Pilates Group Pty Ltd (Empower, we, us, our) operates Pilates studios in Midland and Ellenbrook, Western Australia. We respect your privacy and are committed to handling your personal information openly, lawfully and securely.
This policy explains how we collect, hold, use, disclose, secure and dispose of personal information, including health information, and how you can access, correct or complain about our handling of your information. It is our privacy policy for the purposes of Australian Privacy Principle (APP) 1 of the Privacy Act 1988 (Cth) (Privacy Act).
We are covered by the Privacy Act. The small business exemption does not apply to us. Under the Privacy Act, any business that provides a health service and holds health information must comply with the Australian Privacy Principles regardless of its annual turnover (OAIC — Small business). We provide exercise and movement services and collect health information such as injuries, pregnancy status and medical conditions, so we treat ourselves as an APP entity and comply in full.
We also comply, where applicable, with the Spam Act 2003 (Cth), the Do Not Call Register Act 2006 (Cth), the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act, and the statutory cause of action for serious invasions of privacy that commenced on 10 June 2025 (OAIC — Statutory tort for serious invasions of privacy). The Privacy and Responsible Information Sharing Act 2024 (WA), which commenced on 1 July 2026, applies to Western Australian public sector entities rather than private businesses such as Empower (Government of Western Australia); we nevertheless apply comparable transparency standards to automated decision-making, as set out in section 8.
2. Who and what this policy covers
This policy applies to all personal information we handle about:
· clients, members, class participants, trial and casual attendees, and people who enquire about our services;
· parents, guardians and emergency contacts;
· people who visit our website, book through our online booking platform, or interact with us on social media;
· job applicants, employees, contractors and instructors (noting that acts and practices directly related to a current or former employment relationship and an employee record are exempt from the Privacy Act, although we still handle employee information in line with this policy as a matter of good practice); and
· suppliers, partners and other business contacts.
3. The kinds of personal information we collect and hold
3.1 General personal information
· Name, preferred name, date of birth and gender.
· Contact details: address, email address, telephone and mobile numbers.
· Emergency contact name, relationship and contact details.
· Membership, pass and package details, class bookings, attendance, cancellations, waitlists and visit history.
· Payment and billing information: billing name and address, payment card token, direct debit details, transaction history, invoices and refunds. Full card numbers are handled by our payment processor and are not stored by us.
· Records of your communications with us, including emails, SMS, in-app messages, social media messages, phone notes and feedback.
· Marketing preferences, consents and opt-outs.
· Images and video where you appear in studio photography, class recordings or promotional content, which we only capture and use with your consent.
· Website and app usage information: IP address, device and browser type, pages viewed, referring URLs and cookie identifiers.
3.2 Sensitive information, including health information
Health information is sensitive information and attracts higher protection under the Privacy Act. With your consent, we collect health information that is reasonably necessary for us to deliver safe exercise services, including:
· pre-exercise screening and health questionnaire responses;
· injuries, surgeries, chronic conditions, disabilities and physical limitations;
· pregnancy and post-natal status, including clearance to exercise;
· medications relevant to exercise, and allergies;
· practitioner referrals, exercise physiology or physiotherapy notes, and clearance letters you give us;
· incident and injury reports arising in our studios; and
· goals, progress notes and instructor observations relating to your physical condition.
We collect sensitive information only where you consent and the information is reasonably necessary for one or more of our functions or activities, or where the collection is otherwise permitted by the Privacy Act — for example, where it is necessary to lessen or prevent a serious threat to life, health or safety.
You are not obliged to give us your health information. If you choose not to, we may be unable to safely admit you to some or all classes, and we may need to decline, limit or modify the services we provide.
3.3 Information about children and young people
We provide services to people under 18 only with the consent of a parent or guardian. Where a young person cannot give informed consent, we deal with their parent or guardian and record consent in their file. We assess capacity on a case-by-case basis and, where a young person is capable of understanding, we deal with them directly with respect for their privacy.
3.4 Unsolicited information
If we receive personal information we did not ask for and could not lawfully have collected, we will destroy or de-identify it as soon as practicable, unless it is contained in a Commonwealth record or the law requires otherwise.
4. How we collect personal information
We collect personal information directly from you wherever it is reasonable and practicable to do so, including when you:
· create an account, sign a waiver, or complete a health screening or intake form;
· book, reschedule or cancel a class, purchase a pass, membership or gift card;
· attend a studio, class, workshop, challenge or event;
· contact us by phone, email, SMS, our website forms or social media;
· subscribe to our newsletter or enter a competition, challenge or promotion; or
· apply for a role with us.
We may also collect personal information from third parties, including:
· our booking and client-management platform and payment processor;
· referring health practitioners, with your consent;
· your parent, guardian, carer or emergency contact where appropriate;
· corporate wellness, class-pass or partner programs through which you access our studios;
· our marketing, advertising and analytics providers, in aggregate or pseudonymous form; and
· publicly available sources, such as social media pages where you have interacted with us.
5. Anonymity and pseudonymity
You may deal with us anonymously or under a pseudonym where it is lawful and practicable — for example, when making a general enquiry about class times or pricing. We cannot provide classes, memberships, payments or health-related services anonymously, because we need to identify you to keep you safe and to meet our record-keeping and insurance obligations.
6. Why we collect, hold, use and disclose personal information
6.1 Primary purposes
· Providing our services: registering you, screening you for safe participation, taking bookings, managing classes, waitlists, attendance and access, and adapting exercises to your condition.
· Managing your account: memberships, passes, suspensions, cancellations, payments, direct debits, invoicing, refunds and debt recovery.
· Health and safety: responding to injuries or medical events, contacting your emergency contact, and completing incident reporting.
· Communicating with you about your bookings, account, class changes, studio operations and policy updates.
· Managing our business: staffing and rostering, instructor handover notes, training and supervision, quality and complaints management, insurance, accounting, audit and tax.
· Recruitment and management of staff and contractors.
· Complying with our legal obligations and responding to lawful requests.
6.2 Secondary purposes
We will only use or disclose your personal information for a secondary purpose where:
· you have consented;
· you would reasonably expect us to do so and the secondary purpose is related to the primary purpose (or, for sensitive information, directly related to it);
· it is required or authorised by or under an Australian law or a court or tribunal order; or
· another permitted general situation or permitted health situation under the Privacy Act applies.
6.3 Direct marketing
We use your contact details to send you studio news, class schedules, offers, challenges, events, wellness content and partner promotions. We do this only where you would reasonably expect it or you have consented, and:
· we never use or disclose your health or other sensitive information for marketing without your express consent;
· every commercial electronic message we send includes a functional unsubscribe facility and identifies us, in line with the Spam Act 2003 (Cth);
· we do not make telemarketing calls to numbers on the Do Not Call Register except where permitted;
· you can opt out at any time by using the unsubscribe link, replying STOP to an SMS, adjusting your notification settings in your account, or contacting our Privacy Officer; and
· we will action your opt-out promptly and free of charge, and we will tell you the source of your information on request.
We do not sell, rent or trade your personal information.
7. Who we disclose personal information to
We disclose personal information only as described in this policy, and only to the extent necessary.
Recipients may include:
Booking and client-management platform
Payment providers
Communications providers
Instructors and studio team
Health practitioners
Professional advisers and service providers
Partner and corporate programs
Regulators, courts and law enforcement
Purchasers of our business
For the purpose of:
Client management, booking, membership, communications, point-of-sale and reporting system
Card and direct debit processing, chargebacks and refunds (for example, Stripe, Inc. as engaged through our booking platform)
Email and SMS delivery services used to send booking confirmations and newsletters
Access to the health information they need to keep you safe in class
Physiotherapists, exercise physiologists and doctors, where you consent or where necessary to lessen or prevent a serious threat to life, health or safety
Accountants, bookkeepers, auditors, IT support, insurers and insurance brokers, lawyers and debt recovery agents
Class-pass, corporate wellness and partner programs you choose to use, limited to what is needed to validate your access
Where required or authorised by law, or to respond to a subpoena, warrant or lawful request
A prospective purchaser or investor as part of a due diligence process, subject to confidentiality
8. Automated decision-making and our use of artificial intelligence
We are transparent about the technology we use. This section is also our disclosure for the purposes of APPs 1.7 to 1.9 of the Privacy Act, which require APP entities to describe certain automated decision-making in their privacy policies from 10 December 2026 (OAIC consultation on ADM transparency guidance).
8.1 How we use AI
We use artificial intelligence tools, including generative AI features within our software and general-purpose AI assistants, for:
· Marketing and content drafting — drafting newsletters, social media posts, blog and campaign copy, and summarising campaign results;
· Client communications — drafting and suggesting replies to enquiries, reminders and follow-up messages, which a member of our team reviews and approves before sending; and
· Analytics, reporting and forecasting — preparing attendance, retention, class capacity and revenue reporting and trend forecasts for our studios.
8.2 Rules we apply to AI
· No automated decisions about you. We do not use AI or other automated systems to make, or to perform a function substantially and directly related to making, any decision that could reasonably be expected to significantly affect your rights or interests. Decisions about your membership, pricing, medical clearance, class suitability, access, refunds, complaints and employment are always made by a person. Where AI has produced a draft, summary or report that informs such a decision, a person reviews the underlying information and makes the decision.
· Human review. AI outputs are treated as drafts. A team member checks them for accuracy before they are sent, published or relied on.
· Minimising what goes in. We do not enter your health information or other sensitive information into general-purpose or publicly available AI tools. Where we use AI on client data, we use it within our client-management platform under our contract with that provider, or on de-identified or aggregated data.
· No AI training on your information. We do not permit our AI tools to use your personal information to train publicly available AI models, and we configure enterprise settings to that effect where the tool allows it.
· Accuracy and record-keeping. AI-generated text is never used as a substitute for a clinical or safety record. Health, incident and progress records are written and verified by our team.
· Ongoing review. We assess new AI features for privacy impact before adopting them, consistent with OAIC guidance on privacy and the use of commercially available AI products (OAIC, 21 October 2024).
8.3 Automated processing that does happen
Some routine, non-significant processing in our systems is automated, for example: booking confirmations, waitlist promotion, class reminders, membership renewal and direct debit runs, late-cancellation fees applied under our published terms, and segmentation of marketing lists. These are administrative applications of our published rules rather than decisions about your rights or interests, and you can always ask a person to review the outcome.
8.4 AI inside our client-management platform
Our client-management platform, Momence, Inc., discloses that it uses third-party sub-processors including OpenAI, L.L.C. (USA) for AI product features, together with providers such as Amazon Web Services, Inc. (USA) for hosting, Stripe, Inc. (USA) for payments, and email and messaging providers (Momence Privacy Policy). Where you interact with AI-assisted features in that platform, the platform’s own privacy terms also apply.
If you would like to know more about how we use AI in relation to your information, contact our Privacy Officer using the details in section 15.
9. Overseas disclosure
Our client-management platform is provided by Momence, Inc., which is based in San Francisco, United States, and which states that personal data may be stored and processed in any country in which it, its sub-processors and third-party service providers operate, including the United States (Momence Privacy Policy). Its published sub-processors are located mainly in the United States, with some in Estonia, France, Portugal, Austria and Panama.
This means your personal information, including health information, may be disclosed to and stored in those countries. Before disclosing personal information overseas we take reasonable steps to ensure the overseas recipient does not breach the Australian Privacy Principles, as required by APP 8, including by relying on the provider’s contractual data protection commitments. If an overseas recipient handles your information in a way that breaches the APPs, we may be accountable for that act or practice under section 16C of the Privacy Act.
Some other tools we use, such as email, SMS, accounting and analytics services, may also store information overseas, principally in the United States.
10. How we keep your information secure
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, including:
· storing client records in access-controlled cloud systems rather than paper files wherever possible;
· role-based access, so team members only see the information they need, with instructors limited to the health and booking details relevant to the classes they teach;
· individual accounts, strong passwords and multi-factor authentication on our business systems;
· encryption in transit for our website, booking platform and payments, and reliance on a PCI-DSS compliant payment processor so that we do not store full card numbers;
· confidentiality obligations and privacy training for staff and contractors;
· secure storage of any paper forms in locked cabinets, and secure destruction when no longer needed;
· reviewing the security practices of our service providers before we engage them; and
· device security, screen locks and prompt removal of access when a team member leaves.
11. Retention and destruction
We keep personal information only for as long as we need it for the purposes described in this policy, or as required by law. Our standard practice is:
· Health and client service records: at least 7 years from the date of the last service. For clients who were under 18, we keep records until they turn 25.
· Financial and tax records: at least 5 years, as required by the Income Tax Assessment Act 1936 (Cth) and related tax law, and 7 years for company records under the Corporations Act 2001 (Cth).
· Incident and injury reports: at least 7 years from the incident, or longer where a claim is on foot or reasonably anticipated.
· Marketing lists: until you opt out, after which we retain a minimal suppression record so we do not contact you again.
· Unsuccessful job applications: up to 12 months, unless you ask us to delete them sooner.
· CCTV footage, where used: no longer than 30 days unless it is needed for an incident, claim or investigation.
When information is no longer needed and we are not required to keep it, we destroy it securely or de-identify it.
12. Data breaches
We maintain a data breach response plan. If we suspect a data breach we will contain it, assess it within 30 days, and take remedial action. If we believe an eligible data breach has occurred — one likely to result in serious harm to any individual whose information is involved — we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, as required by the Notifiable Data Breaches scheme (OAIC — About the NDB scheme). Because we hold health information, we treat any breach involving client health records as high risk.
13. Accessing and correcting your information
You have the right to ask for access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.
· Make your request to our Privacy Officer using the details in section 15.
· We will ask you to verify your identity.
· We will respond within 30 days. Where possible we give access in the form you ask for.
· Access is free. If a request requires substantial work we may charge a reasonable cost-based fee, which we will tell you about before we start. We do not charge for making a correction.
· We may refuse access or correction in the limited circumstances allowed by the Privacy Act — for example, where giving access would pose a serious threat to life, health or safety, would unreasonably affect another person’s privacy, or would prejudice a legal proceeding. If we refuse, we will tell you why in writing and explain how to complain.
· If we correct information we have already disclosed, we will notify the recipient on your request unless it is impracticable or unlawful. If we do not agree to correct information, you can ask us to attach a statement of your view to the record, and we will do so.
You can update most of your own contact details, marketing preferences and payment details directly in your account in our booking platform.
14. Our website, cookies and analytics
Our website and booking pages use cookies and similar technologies to keep you signed in, remember your preferences, measure traffic and improve our marketing. Some of these are set by third parties, including analytics and advertising platforms, which may collect information about your device and browsing. You can control or delete cookies in your browser settings, though some features may not work properly if you disable them. Where we run advertising, we may use hashed contact details to build audiences with advertising platforms; you can ask us to stop including you by contacting our Privacy Officer.
Our website may contain links to other websites. We are not responsible for the privacy practices of those sites.
15. Contact us, and how to complain
Privacy Officer: Ciara Parry, Director
Empower Pilates Group Pty Ltd, 186 Great Eastern Highway, Midland WA 6056
Email: hello@empowerpilatesstudios.com.au
Phone: 0483 934 522
If you have a question, want access to your information, or wish to complain about how we have handled your personal information, please contact our Privacy Officer. Please describe your concern and what outcome you are seeking.
We will acknowledge your complaint within 5 business days and respond substantively within 30 days. If we need longer, we will tell you why and keep you informed.
If you are not satisfied with our response, you can complain to the OAIC:
· Online: oaic.gov.au/privacy/privacy-complaints
· Phone: 1300 363 992
· Post: GPO Box 5218, Sydney NSW 2001
You may also have rights under the statutory cause of action for serious invasions of privacy, which allows individuals to bring proceedings in court in certain circumstances.
16. Changes to this policy
We review this policy at least annually and whenever our systems, providers or legal obligations change. The current version is always available at our studios on request and on our website. Where changes are significant we will tell you by email or through our booking platform. Material changes take effect from the date published.
Version: 1.0
Effective date: 10 September 2026
Next scheduled review: 10 September 2027
Please reach out to us for more information.

