Plain-English summary
Heart Safe Wellness is a business of Heart Safe Australia Pty Ltd. We collect personal information when you contact us, enquire about or book our services, participate in a workshop or retreat, subscribe to communications, or use our website.
We use your information to respond to enquiries, provide and administer our services, manage participant safety, process invoices and bank-transfer payments, send requested communications, improve our services, and meet legal, insurance and record-keeping obligations.
We do not sell or rent personal information. We do not collect or store credit-card or payment-card details.
Some information, such as medical conditions, pregnancy, injuries, medications and allergies, is sensitive information under the Privacy Act 1988 (Cth). We collect this information only with consent and only where reasonably necessary to manage participant safety.
You may ask us to access or correct your personal information, withdraw consent to marketing, or complain about how we handle your information. Contact us using the details in this policy.
This policy should be read together with our Terms & Conditions and Cookie Notice. For avoidance of doubt, this Privacy Policy does not set or vary our cancellation, transfer or payment terms.
1. Who we are
In this policy, “Heart Safe Wellness”, “we”, “us” or “our” means:
Heart Safe Australia Pty Ltd trading as Heart Safe Wellness
ABN: 22 642 092 993
Based in: Sydney Northern Beaches, New South Wales, Australia
Phone: 1300 728 354
Website: https://www.heartsafewellness.au/
Privacy contact
Privacy enquiries should be directed to:
Privacy Contact
Heart Safe Australia Pty Ltd trading as Heart Safe Wellness
Email: [email protected]
Phone: 1300 728 354
Address: PO Box 716, Manly, NSW, 1655
We aim to respond to privacy enquiries within a reasonable time and, where applicable, within the timeframes described in this policy.
2. Scope of this policy
This policy explains how we collect, hold, use, disclose, store, protect and otherwise handle personal information in connection with:
- our website;
- website enquiry forms;
- corporate wellness workshops;
- mindfulness, awareness and breathwork programs;
- individual coaching;
- retreats and team-building experiences;
- participant waivers and medical declarations;
- subscription communications;
- group and individual communications; and
- related client administration.
This policy applies primarily to individuals in Australia. It is intended to support our compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Where reasonable and practicable, we are also guided by the APPs when handling personal information about individuals located outside Australia.
3. Personal information we collect
The personal information we collect depends on how you interact with us and the services you request.
3.1 Enquiry form information
Our website includes an embedded enquiry form provided through Zoho Forms. Depending on the fields completed, we may collect:
- first name and last name;
- company name;
- street address;
- city;
- state or territory;
- postcode;
- role or position;
- email address;
- phone number;
- website address;
- number of employees or participants;
- the wellness services you are interested in;
- free-text questions or other information you choose to provide; and
- CAPTCHA, verification and security information needed to protect the form from misuse.
Please do not include unnecessary sensitive information in a general enquiry form.
3.2 Booking and client administration information
When you or your organisation books our services, we may collect:
- booking details;
- quotation and invoice details;
- organisation and contact details;
- participant lists provided by a corporate client;
- dietary requirements;
- accessibility requirements;
- emergency contact details;
- venue and accommodation information;
- correspondence with us; and
- information needed to administer the booked service.
3.3 Health and safety information
For some activities, we may ask participants to complete a Participant Waiver & Medical Declaration. This may include information about:
- heart, lung or blood-pressure conditions;
- seizure conditions;
- mental-health conditions;
- pregnancy;
- injuries or physical limitations;
- medications;
- allergies;
- relevant medical history; and
- other information relevant to safe participation.
This information is sensitive information under the Privacy Act 1988 (Cth).
We collect sensitive information only:
- with the participant’s consent;
- where it is reasonably necessary to manage safety and risk;
- for the specific purposes explained at the time of collection; and
- using appropriate safeguards.
Health and safety information is not shared with the broader participant group or disclosed to a client organisation except where the participant has consented, disclosure is necessary for safety, or disclosure is otherwise authorised or required by law.
3.4 Photographs, video and testimonials
We may take photographs or video at workshops, retreats or other events. We may also collect testimonials.
We collect, use and publish identifiable photographs, video and testimonials only where we have obtained appropriate written consent.
Consent may specify:
- the material that may be used;
- the purpose of use;
- the platforms or channels where it may appear; and
- whether the person may be identified by name.
A person may withdraw future consent by contacting us. Withdrawal does not affect use that occurred lawfully before withdrawal, and some material may already have been distributed or cached by third parties.
3.5 Website technical information
When you use our website, we or our website provider may collect technical information such as:
- IP address;
- browser type;
- device type;
- operating system;
- approximate location derived from technical information;
- pages visited;
- links accessed;
- date and time of visits;
- referring website; and
- error and log information.
This information may be collected through cookies and similar technologies.
3.6 Marketing and communications information
If you subscribe to or receive communications from us, we may collect:
- email address;
- communication preferences;
- subscription and consent records;
- delivery information;
- open data;
- click data;
- unsubscribe records; and
- correspondence relating to communications.
Our group communications and individual communications from our founder may be sent using Zoho Campaigns.
3.7 Information we do not collect
Clients pay us by bank transfer. We do not collect, process or store credit-card or payment-card details at any time.
Any payment-card details should never be entered into our website, enquiry forms or email correspondence. We do not hold payment-card information because we do not accept payment by card.
4. How we collect personal information
We may collect personal information:
4.1 Directly from you
For example, when you:
- complete our website enquiry form;
- email or telephone us;
- contact us through another communication channel;
- enquire about or book a service;
- attend a workshop, retreat or coaching session;
- provide information in person;
- complete a Participant Waiver & Medical Declaration;
- sign a consent form; or
- subscribe to communications.
4.2 From a corporate client
A corporate client may provide us with information about its employees or participants when it books a service on their behalf.
Where a corporate client provides personal information to us, we expect the organisation to notify its employees or participants that their information will be provided to Heart Safe Wellness and handled in accordance with this policy.
Participants may contact us directly if they have questions about information provided on their behalf.
4.3 Automatically through our website
We may collect technical information automatically through cookies, server logs, analytics and similar technologies.
5. Why we collect, hold, use and disclose personal information
We collect, hold, use and disclose personal information for purposes including:
- responding to enquiries;
- preparing quotations;
- communicating about requested services;
- providing and administering booked services;
- organising workshops, retreats, coaching and team-building activities;
- managing participant health and safety;
- assessing whether particular activities may be suitable for a participant;
- maintaining participant registers and emergency contact lists;
- arranging venues, accommodation and guest facilitators;
- managing dietary and accessibility requirements;
- issuing invoices;
- recording and reconciling bank-transfer payments;
- sending the “Healthy Mind + Body + Spirit” subscription communications;
- sending requested group and individual communications;
- managing consent and communication preferences;
- obtaining and managing photography, video and testimonial consents;
- improving our services and website;
- maintaining business, insurance, risk-management and compliance records;
- responding to complaints and requests;
- preventing fraud, misuse or security incidents;
- exercising or defending legal rights; and
- complying with legal obligations.
We do not sell or rent personal information.
We do not use personal information for unrelated purposes unless:
- you consent;
- the use is required or authorised by law;
- an exception under the Privacy Act or APPs applies; or
- the information has been de-identified so that it can no longer reasonably identify you.
6. Health information and consent
6.1 Sensitive information
Health information collected through a Participant Waiver & Medical Declaration is sensitive information under the Privacy Act 1988 (Cth).
We collect it only with express consent, usually through a signed waiver or declaration. Consent should be informed, voluntary, current and specific to the purpose for which the information is collected.
6.2 Purpose and access
We use health information only where reasonably necessary for:
- participant safety;
- risk assessment and management;
- deciding whether an activity may require modification or should be avoided;
- responding to an incident or emergency;
- insurance and claims management; and
- related legal or safety obligations.
Access is restricted to people who need the information for those purposes, such as an appropriate facilitator, authorised Heart Safe Wellness personnel, an insurer or a medical professional.
Health information is not shared with the broader group. It is not provided to the client organisation except with consent, where necessary to keep a participant safe, or where authorised or required by law.
6.3 Emergencies
In an emergency, we may disclose relevant health information to emergency services, medical professionals or another person responsible for providing urgent assistance where reasonably necessary to protect a person’s life, health or safety.
6.4 Access, correction and deletion requests
A participant may ask us to:
- access their health information;
- correct health information that is inaccurate, out of date, incomplete or misleading; or
- delete health information where it is no longer required and deletion is legally permitted.
We may need to retain health information for insurance, legal, safety or record-keeping purposes. In those circumstances, we may be unable to delete it immediately, but we will explain the reason.
Requests should be made in writing to [email protected].
6.5 De-identification and destruction
We will destroy or de-identify health information when it is no longer required, subject to legal, insurance, safety and record-keeping obligations.
7. Direct marketing and communications
7.1 Communications we may send
We may send:
- “Healthy Mind + Body + Spirit” weekly or monthly communications;
- newsletters and group emails;
- information about Heart Safe Wellness services;
- wellbeing guidance and exercises;
- event or retreat information; and
- individual communications from our founder, Max, where appropriate.
These communications may be sent using Zoho Campaigns.
7.2 Consent and applicable laws
We only send commercial electronic messages where we have consent or where sending the message is otherwise permitted by the Spam Act 2003 (Cth) and other applicable laws.
We will identify the sender and include our contact details in commercial communications.
7.3 Unsubscribe
Every marketing communication will include a functional unsubscribe facility.
We aim to action unsubscribe requests within five business days and in accordance with the Spam Act 2003 (Cth). You may also contact us directly to opt out.
Opting out of marketing will not affect:
- a booking;
- a service already requested;
- safety-related communications;
- invoices or payment records; or
- other transactional or service-related messages necessary to administer an engagement.
Transactional and service-related communications about a booked engagement are not marketing and may continue to be sent.
You may opt out of marketing at any time without affecting your booking or access to a service.
8. Cookies and analytics
8.1 What cookies are
Cookies are small text files or similar technologies placed on a device when a website is accessed. They may help a website remember preferences, operate securely, understand usage and improve performance.
8.2 Types of cookies
We may use:
- Essential cookies, which support core website functions, security and form operation;
- Functional cookies, which remember preferences and improve the website experience; and
- Analytics cookies, which help us understand how visitors use the website and how the website performs.
Some cookies may be set by third-party providers, including our website or technology providers.
8.3 Managing cookies
You can manage, block or delete cookies through your browser settings. Browser settings differ between providers.
Refusing essential cookies may affect website functionality, including enquiry forms or other features.
Further information may be provided in our separate Cookie Notice once published.
9. Disclosure to third parties
We may disclose personal information to the following categories of recipients where reasonably necessary for the purposes described in this policy.
9.1 Zoho
We use:
- Zoho Forms for website enquiry forms; and
- Zoho Campaigns for group communications and individual communications.
Zoho may process enquiry data, contact details, communication preferences and communications on our behalf.
9.2 Website hosting and technology providers
Abacus AI hosts and supports the website for us and may process website technical information, log information and security data.
9.3 Professional advisers
We may disclose information to:
- accountants;
- bookkeepers;
- auditors;
- lawyers;
- professional advisers; and
- other service providers,
where necessary for billing, financial administration, legal advice, insurance, compliance or business administration.
9.4 Insurers and brokers
We may disclose information to our insurers and insurance brokers where necessary to:
- arrange or maintain insurance;
- assess risk;
- manage an incident;
- make or respond to a claim; or
- meet an insurance obligation.
Our public liability and professional indemnity insurance is held under Heart Safe Australia Pty Ltd (ABN 22 642 092 993) with Berkley Insurance Company trading as Berkley Insurance Australia, policy reference 202008-1271 R5 BIA.
9.5 Retreat venues, accommodation providers and guest facilitators
We may disclose the information needed to deliver a booked service to:
- retreat venue partners;
- accommodation providers;
- international venue partners, including partners in Fiji;
- massage therapists;
- Traditional Chinese Medicine practitioners;
- acupuncture or acupressure practitioners;
- yoga teachers;
- fitness trainers;
- other guest facilitators; and
- event or logistics providers.
The information may include:
- participant names;
- contact details;
- participant lists;
- dietary requirements;
- accessibility requirements; and
- health information relevant to safe participation.
We aim to disclose only the minimum information reasonably necessary for the particular service.
9.6 Emergency services and medical providers
We may disclose relevant information to emergency services, medical providers or other responders where necessary in an emergency or where authorised or required by law.
9.7 Government agencies, regulators and courts
We may disclose information to government agencies, regulators, courts, law-enforcement bodies or other authorities where required or authorised by law.
9.8 Third-party protections
We take reasonable steps to ensure that third-party recipients handle personal information consistently with the APPs or are bound by confidentiality, privacy or security obligations appropriate to the services they provide.
We do not sell or rent personal information.
10. Overseas disclosure
10.1 Providers and locations
Personal information may be disclosed to or stored in countries outside Australia because:
- Zoho Forms and Zoho Campaigns may store or process information on servers located outside Australia, including in the United States and other countries; and
- retreat venue partners, accommodation providers and service providers may operate in Fiji or other countries.
10.2 Different privacy protections
Privacy laws in countries outside Australia may differ from Australian privacy law and may not provide the same level of protection.
Where required, we will take reasonable steps to ensure that an overseas recipient does not breach the APPs in relation to the information.
By providing personal information to us, you acknowledge that it may be disclosed to and stored or processed in countries outside Australia as described in this policy and consent to that overseas disclosure where consent is required.
10.3 International retreats
If you attend an overseas retreat, including a retreat in Fiji, additional information may need to be provided to overseas venues, accommodation providers, transport providers, guest facilitators or emergency services.
We will aim to disclose only information reasonably necessary to provide the booked service and manage participant safety.
11. Storage and security
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.
Our safeguards may include:
- restricted access to personal information;
- password protection;
- multi-factor authentication on relevant accounts;
- secure cloud systems;
- confidentiality obligations for staff and contractors;
- access controls for health and safety information;
- locked storage for hard-copy records;
- secure handling of signed waivers and consent forms;
- security measures applied by our technology providers; and
- secure destruction or de-identification when information is no longer needed. No system is completely secure. We do not guarantee absolute security, but we take reasonable steps appropriate to the nature of the information and the risks involved.
12. Retention and destruction
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law.
Our current intended retention periods are:
- Enquiry records that do not convert to a booking: approximately 12 months;
- Client and booking records: approximately 7 years to support tax, insurance and legal requirements;
- Participant health declarations and waivers: approximately 7 years for insurance, safety and liability purposes; and
- Marketing consent and subscription records: until consent is withdrawn, subject to any record-keeping obligations.
These periods are estimates and may change depending on the circumstances, including an unresolved complaint, legal claim, insurance matter, investigation or statutory obligation.
When information is no longer required, we will take reasonable steps to securely destroy it or de-identify it so that it can no longer reasonably identify an individual.
13. Access and correction
13.1 Access
You may request access to personal information we hold about you under the APPs.
Requests should be made in writing to:
Please provide enough information for us to identify you and locate the relevant information. We may need to verify your identity before responding.
We aim to respond to an access request within 30 days, subject to the nature and complexity of the request.
We may charge a reasonable administrative fee for providing access, but we will confirm any proposed fee before charging it.
13.2 When access may be refused
In limited circumstances, we may refuse access where permitted or required by law. For example, refusal may be permitted where access would:
- pose a serious threat to the life, health or safety of a person;
- have an unreasonable impact on another person’s privacy;
- prejudice legal or dispute-resolution proceedings;
- reveal confidential commercial information;
- be unlawful; or
- be otherwise permitted under the Privacy Act 1988 (Cth).
If we refuse access, we will explain the reasons unless it would be unreasonable or unlawful to do so. We will also explain how you may complain or seek further review.
13.3 Correction
You may ask us to correct personal information that is inaccurate, out of date, incomplete, irrelevant or misleading.
We will take reasonable steps to assess and action a correction request. If we do not agree that a correction is required, we will explain why and, where appropriate, attach a statement to the relevant record noting that you dispute its accuracy.
14. Notifiable Data Breaches
If we become aware of unauthorised access to, unauthorised disclosure of, or loss of personal information, we will assess the incident promptly.
Where the incident is an eligible data breach that is likely to result in serious harm, we will notify:
- affected individuals; and
- the Office of the Australian Information Commissioner (OAIC),
in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
Where required, we will explain:
- what happened;
- the kinds of information involved;
- what steps we have taken;
- what affected individuals can do to reduce potential harm; and
- how to contact us for further information.
15. Privacy complaints
If you believe we have mishandled your personal information, please contact our Privacy Contact in writing:
Privacy Contact
Email: [email protected]
Phone: 1300 728 354
Address: PO Box 716, Manly, NSW, 1655
Please describe:
- what happened;
- the information or privacy concern involved;
- the date or approximate date;
- the outcome you are seeking; and
- any supporting information.
We will acknowledge and investigate the complaint and aim to provide a response within a reasonable time.
If you are not satisfied with our response, or if we do not respond within a reasonable time, you may contact the:
Office of the Australian Information Commissioner
Website: https://www.oaic.gov.au/
Phone: 1300 363 992
You may also wish to contact the Australian Communications and Media Authority regarding alleged breaches of the Spam Act 2003 (Cth).
16. Children
Our services are for people aged 18 years and over.
We do not knowingly collect personal information from anyone under 18. If we become aware that we hold personal information about a person under 18, we will take reasonable steps to delete it, unless we are required or permitted by law to retain it.
17. Changes to this policy
We may update this Privacy Policy from time to time to reflect:
- changes to our services;
- changes to our technology providers;
- changes to privacy practices;
- legal or regulatory developments; or
- operational requirements.
When we update the policy, we will publish the new version on our website and update the “Last updated” date at the top of the policy.
18. Contact us
For general enquiries:
Heart Safe Australia Pty Ltd trading as Heart Safe Wellness
ABN: 22 642 092 993
Based in: Sydney Northern Beaches, New South Wales, Australia
Phone: 1300 728 354
Website: https://www.heartsafewellness.au/
Privacy email: [email protected]
Postal address: PO Box 716, Manly, NSW, 1655
For privacy enquiries, complaints, access requests or correction requests, please contact our Privacy Contact at [email protected].