Privacy Policy
Privacy Policy
Last updated: 29 June 2026
1. Introduction
The proprietors trading under the registered business name Livan Fitness as CrossFit Highfields (ABN 67 657 031 199, referred to in this Policy as "we," "us," or "our") are committed to protecting the personal information of every member, casual participant, prospective member, guardian, and visitor who interacts with our facility at Unit 4/15 Darian Street, Highfield Industrial Estate,Highfields, Queensland, or with our website located at www.crossfithighfields.com.au. The document that follows explains what information we gather, the reasons for which it is collected, the manner in which it is held and protected, and the rights available to you in respect of it.
Although our operation falls below the three-million-dollar turnover threshold that ordinarily attracts a small-business exemption, we are nonetheless bound by Australian privacy law. The reason lies in the nature of our activities: a business that provides a health service and holds health information is expressly removed from the exemption under section 6D of the Privacy Act 1988 (Cth). Because pre-exercise medical screening forms part of our intake process, we are subject to the Act in full, and we treat that obligation as a benefit to the people who train with us rather than a mere formality.
2. The Legal Framework Governing This Policy
Our handling of personal information is regulated principally by the Privacy Act 1988 (Cth) and by the thirteen Australian Privacy Principles ("APPs") contained in Schedule 1 to that Act. The APPs set the standard for collection, use, disclosure, storage, access, and correction across the whole of our dealings with your information.
Account has been taken of recent reform. The Privacy and Other Legislation Amendment Act 2024 (Cth), the bulk of which commenced on 10 December 2024, strengthened the powers of the regulator and introduced, with effect from 10 June 2025, a statutory tort permitting individuals to bring an action for serious invasions of privacy. Where we disclose information to organisationsthat operate electronic marketing on our behalf, the Spam Act 2003 (Cth) governs that conduct. Because our services are offered exclusively to persons within Queensland and the broader Australian community, the European General Data Protection Regulation does not apply, and we do not direct our services to individuals in the European Union.
3. The Categories of Personal Information We Collect
Personal information, as defined by the Act, means information or an opinion about an identified individual, or an individual who is reasonably identifiable. In the ordinary course of running the gym, we collect the following categories.
Identity and Contact Details: Your full name, residential or postal address where supplied, email address, and telephone number, gathered so that we may administer your membership and communicate with you.
Health and Medical Information: Responses to pre-exercise screening questions, including disclosures concerning cardiovascular conditions, diabetes, respiratory illness, injury history, pregnancy, and any other matter bearing upon your capacity to train safely.
Financial and Payment Information: The bank account particulars recorded on the direct debit authority form, together with the schedule of fees applicable to your membership category.
Emergency and Guardian Details: The name and contact particulars of a nominated emergency contact and, in the case of a participant under eighteen years of age, the details of the responsible parent or guardian.
Participation Records: Attendance history, class bookings, program notes, and coaching observations recorded to support your training.
Technical and Website Data: Information generated when you visit our website, including internet protocol address, browser type, pages viewed, and the duration of your visit, collected through the analytics tools described in Section 6.
4. Sensitive Information and Health Data
Health information occupies a protected category under the Act and is classified as "sensitive information," attracting a higher threshold for collection. As a general rule, we collect sensitive information only where you have consented to its collection and where the information is reasonably necessary for our functions. Consent is sought at the point of intake, when you complete the health questionnaire, and the purpose is made plain to you at that moment: to permit our coaching staff to assess risk, to modify programming where a condition warrants caution, and to seek medical clearance where prudence requires it.
We do not use your health information for any purpose unrelated to the safe delivery of fitness services, and we do not sell it, trade it, or disclose it for marketing. Access within our organisationis confined to those staff members who require it in order to coach you safely or to administer your account. Should you decline to provide health information that we consider material to your safety, we may be unable to permit your participation, a limitation imposed not by preference but by our duty of care toward you.
5. How and From Whom We Collect Information
Wherever it is reasonable and practicable to do so, we collect personal information directly from you. Collection occurs through several ordinary channels: the completion of membership application forms and health questionnaires, the submission of a signed direct debit authority by email or in person, enquiries made by telephone or electronic message, and conversations with our coaching staff during the course of training.
On occasion, we may receive information about you from a third party, such as a parent or guardian enrolling a minor, an emergency contact you have nominated, a referring health practitioner, or, in the case of supports funded under the National Disability Insurance Scheme, a participant's plan manager or support coordinator. Where information reaches us indirectly and you would not reasonably expect us to hold it, we will, so far as the circumstances allow, take steps to notify you of the collection consistent with Australian Privacy Principle 5.
6. Cookies, the Squarespace Platform, and Third-Party Analytics
Our website is hosted on the Squarespace platform, which deploys cookies and similar technologies necessary for the site to function and to record aggregate usage. A cookie is a small text file placed on your device that allows a website to recognise your browser across pages and visits. Most browsers permit you to refuse or delete cookies through their settings, although doing so may affect the functionality of certain features.
In support of our marketing and to better understand how visitors engage with our content, we use, or intend to use, the following third-party tools.
Google Analytics: A web analytics service provided by Google that reports on website traffic and visitor behaviour in aggregate form, assisting us to improve the site.
Meta (Facebook) Pixel: A measurement tool provided by Meta Platforms that records actions taken on our website, enabling us to evaluate the effectiveness of advertising and to present relevant content to audiences on Facebook and Instagram.
Each of these providers operates under its own privacy terms, and the data they gather is governed by their respective policies in addition to this one. Where the technologies described here involve the placement of cookies, further detail is presented through the cookie notice generated by the Squarespace platform at the point of your visit.
7. The Purposes for Which We Use Your Information
Consistent with Australian Privacy Principle 6, we use personal information only for the purpose for which it was collected, for a directly related secondary purpose that you would reasonably expect, or where you have otherwise consented. The principal purposes are set out below.
Service Delivery: To register and administer your membership, to schedule and conduct group sessions, personal training, school and sporting group activities, open gym access, and NDIS supports, and to maintain the records associated with them.
Health and Safety: To assess and manage the risks attaching to physical exertion, to respond to injury or medical emergency, and to contact your nominated emergency contact where necessary.
Billing and Account Management: To process direct debit payments, to manage dishonouredtransactions, and to keep an accurate financial record of your account.
Communication: To respond to your enquiries, to issue notices concerning timetable changes or facility matters, and to provide information relevant to your training.
Improvement and Marketing: To analyse website engagement and, where you have not opted out, to send you promotional material concerning our programs and offers.
Legal and Regulatory Compliance: To meet our obligations under applicable laws, including those governing fitness services, taxation, and the National Disability Insurance Scheme.
8. Direct Marketing and Electronic Communications
From time to time, we may contact you with information about classes, events, pricing offers, or other matters likely to interest a person who trains with us. Any electronic marketing of that kind is conducted in accordance with the Spam Act 2003 (Cth), which requires that we hold your consent, identify ourselves clearly, and provide a functional means of unsubscribing. Should you no longer wish to receive promotional communications, you may opt out at any time by using the unsubscribe facility contained in the message or by contacting us directly, and we will give effect to your request without undue delay. Communications that are purely operational in character, such as a notice that a class has been cancelled or that a payment has been dishonoured, fall outside the definition of marketing and may continue to be sent for so long as you hold an active account.
9. Disclosure of Your Personal Information
We do not sell or rent personal information, and disclosure occurs only where it is necessary and lawful. Recipients may include the following.
Our Staff and Contractors: Coaching and administrative personnel who require access in order to deliver services or administer accounts, each of whom is bound to maintain confidentiality.
Financial Institutions and Payment Processors: The banks and intermediaries through which direct debit transactions are processed.
NDIS Participants' Representatives: Where supports are funded under the National Disability Insurance Scheme, the relevant plan managers, support coordinators, or the National Disability Insurance Agency, as required to administer those supports.
Technology and Service Providers: The Squarespace platform, analytics providers, and other suppliers engaged to operate our website and business systems.
Professional Advisers and Authorities: Legal advisers, accountants, insurers, and government or regulatory bodies, where disclosure is required or authorised by law.
In each instance, disclosure is confined to the information reasonably necessary for the purpose, and we take reasonable steps to ensure that recipients handle the information consistently with the standards described here.
10. Disclosure to Overseas Recipients
Certain service providers on whom we rely store data on servers located outside Australia. The Squarespace platform, Google, and Meta each maintain infrastructure in the United States and in other jurisdictions, with the consequence that some information may be held or processed overseas. Under Australian Privacy Principle 8, we take reasonable steps to ensure that any overseas recipient handles your information in a manner consistent with the APPs, principally by relying on providers that publish their own privacy commitments and contractual safeguards. By providing information through our website or otherwise consenting to the use of these platforms, you acknowledge that a limited transfer of this nature may occur. We do not otherwise disclose personal information to overseas recipients for our own purposes.
11. Security and Protection of Information
Reasonable steps are taken to protect the personal information we hold against misuse, interference, loss, and unauthorised access, modification, or disclosure, as required by Australian Privacy Principle 11. Physical records, including paper direct debit forms and health questionnaires, are stored securely and access to them is restricted to authorised personnel. Electronic records are held on systems protected by access controls, and we engage reputable platform providers whose own security measures supplement our own. Despite the diligence applied, no method of transmission over the internet and no system of electronic storage can be guaranteed to be entirely impervious, and we cannot warrant absolute security. You are encouraged to assist by keeping any account credentials confidential and by notifying us promptly of any suspected compromise.
12. Notifiable Data Breaches
Should a data breach occur that is likely to result in serious harm to an individual whose information we hold, we will comply with the Notifiable Data Breaches scheme established under Part IIIC of the Privacy Act 1988 (Cth). Our response involves assessing the breach without unreasonable delay, taking remedial action to contain it, and, where the threshold of likely serious harm is met, notifying the affected individuals and the Office of the Australian Information Commissioner as the law requires. The notification will set out the nature of the breach, the kinds of information involved, and the steps you may take in response.
13. Retention and Destruction of Information
Personal information is retained only for so long as it is required to fulfil the purposes for which it was collected, or for so long as a law or a legitimate business need obliges us to keep it. Financial records, for instance, are kept for the periods prescribed by taxation law, while health and membership records are retained for a reasonable interval after your account closes, both to honourour duty of care and to address any matter that may subsequently arise. Once information is no longer required and we are not legally compelled to keep it, we take reasonable steps to destroy it or to de-identify it, in keeping with Australian Privacy Principle 11.2.
14. Access to and Correction of Your Information
You hold the right, under Australian Privacy Principles 12 and 13, to request access to the personal information we hold about you and to seek the correction of information that is inaccurate, out of date, incomplete, irrelevant, or misleading. A request of either kind may be made through the contact details in Section 18. We will respond within a reasonable period, ordinarily not exceeding thirty (30) days, and we will provide access in the manner you request where it is reasonable to do so. Access may be declined in the limited circumstances permitted by the Act, such as where granting it would pose a serious threat to the life or health of a person or would unreasonably affect the privacy of others, and where we refuse a request, we will give you written reasons and explain the avenues available to you.
15. NDIS Participants
Participants who access supports funded under the National Disability Insurance Scheme are entitled to particular care in the handling of their information. We manage that information in a manner consistent with the National Disability Insurance Scheme (Code of Conduct) Rules 2018, respecting the privacy, dignity, and autonomy of each participant. Information relating to a participant's supports is shared only with those persons who are properly involved in delivering or administering them, and only to the extent necessary for that purpose.
16. Minors and Young Participants
Where a participant is under eighteen years of age, we collect and handle their information through, and with the consent of, a parent or legal guardian. Communications concerning a minor's membership are directed to the responsible adult, and we apply the same protective standards to a young person's health and contact information as we do to that of any other member, with appropriate sensitivity to their age.
17. Making a Privacy Complaint
Should you believe that we have mishandled your personal information or have breached the Australian Privacy Principles, we ask that you raise the matter with us in the first instance through the contact details below, so that we may investigate and seek to resolve it promptly. We will acknowledge your complaint, examine the circumstances, and provide a written response within a reasonable time. Where you remain dissatisfied with our handling of the matter, you are entitled to refer the complaint to the Office of the Australian Information Commissioner, the independent regulator, which may be contacted on 1300 363 992 or online at www.oaic.gov.au.
18. Changes to This Policy and How to Contact Us
Our practices and our legal obligations may change over time, and we may revise this Policy accordingly. The current version will be published at www.crossfithighfields.com.au, bearing the date of its most recent revision, and your continued use of our services or website following any update signifies your acceptance of the amended terms. Where a change materially affects the manner in which we handle your information, we will take reasonable steps to bring it to your attention.
Enquiries, access and correction requests, and complaints concerning this Policy may be directed to the Operator by email to antlivcf@outlook.com, by post to Unit 4/15 Darian Street, Highfield Industrial Estate, Highfields, Queensland, or through the website at www.crossfithighfields.com.au.