top of page

PRIVACY POLICY.

This Privacy Policy explains how No Nonsense Avalon collects, uses, stores and shares personal information when you visit our website, contact us, make a booking, purchase a service or membership, attend an appointment or class, complete a form, or otherwise interact with us.

No Nonsense Avalon provides health, fitness and wellness services. Because of this, some of the information we collect may include health information, which is sensitive information and is handled with additional care.

By using our website, booking platform, services, forms or facilities, you agree to the collection and handling of your personal information as described in this Privacy Policy.

Who we are

In this Privacy Policy, “No Nonsense Avalon”, “we”, “us” and “our” refers to No Nonsense Avalon.

Our website is hosted by Wix. We use Mindbody as our booking, client management, payment and communications platform. We may also use third-party platforms and tools for analytics, advertising, marketing, SMS, health fund claiming, forms, waivers, payment processing, security and business administration.

Our website may also link to No Nonsense Magnesium, which is a separate ecommerce website hosted by Shopify.

This Privacy Policy applies to No Nonsense Avalon. If you click through to No Nonsense Magnesium or another third-party website, that website’s own privacy policy and terms will apply.

Personal information we collect

The personal information we collect depends on how you interact with us.

We may collect:

  • your name;

  • email address;

  • phone number;

  • date of birth;

  • address, suburb or postcode;

  • emergency contact details;

  • booking history;

  • attendance history;

  • membership, package or pass details;

  • service, class, workshop or event purchases;

  • payment and transaction information;

  • health fund or claiming information, where relevant;

  • forms, waivers, consents and intake information;

  • notes, messages or enquiries you send to us;

  • communication and marketing preferences;

  • feedback, reviews, survey responses or testimonials;

  • photographs, videos or social media content, where you have given consent or where you interact with us publicly;

  • CCTV footage if you attend our premises;

  • website usage information, such as browser type, IP address, device information, pages viewed and how you interact with our website.

 

Health and sensitive information we collect

When you book or attend a health, fitness, massage, bodywork, rehabilitation, red light, infrared, counselling, coaching or related service, we may collect health information that is reasonably necessary to provide that service.

This may include:

  • medical history;

  • current symptoms, injuries, pain, conditions or treatment goals;

  • medications or relevant health conditions you choose to disclose;

  • pregnancy or postnatal information, where relevant to your care;

  • lifestyle, exercise, sleep, stress or recovery information;

  • treatment notes;

  • practitioner observations;

  • progress notes;

  • referral information;

  • reports, letters or information from other health professionals, where relevant;

  • contraindications, precautions or safety information;

  • information required to assess whether a service, treatment, class or recovery modality is suitable for you.

 

We collect health information so that our practitioners can assess suitability, provide appropriate care, modify services where needed, reduce risk, communicate with you about your care, and meet our legal, insurance and professional obligations.

We only collect sensitive information where it is reasonably necessary for our services, where you have consented, or where we are otherwise permitted or required by law.

How we collect personal information

We may collect personal information when you:

  • visit our website;

  • submit a website enquiry or lead form;

  • call, email, text or message us;

  • book or purchase through Mindbody;

  • create or update a Mindbody account;

  • complete an intake form, waiver, consent form, health questionnaire or online form;

  • attend an appointment, class, workshop or event;

  • purchase a membership, package, service, gift card or product;

  • subscribe to our email or SMS marketing;

  • enter a competition, promotion, giveaway or challenge;

  • provide feedback, a review or testimonial;

  • interact with us on social media;

  • are recorded by CCTV while attending our premises;

  • are referred to us by another practitioner, health professional, insurer, employer, family member or another person, where appropriate.

 

Where possible, we collect information directly from you. In some cases, we may collect information from a parent, guardian, carer, referring practitioner, health professional, insurer, booking platform, health fund claiming provider or other third party where it is reasonable and lawful to do so.

Website, cookies and analytics

When you visit our website, certain information may be collected automatically by Wix and other tools we use. This may include:

  • IP address;

  • device type;

  • browser type;

  • operating system;

  • location or time zone information;

  • referring website;

  • pages visited;

  • date and time of visit;

  • clicks, interactions and browsing behaviour.

 

We may use cookies, pixels, tags, web beacons and similar technologies to operate our website, remember preferences, understand website traffic, improve user experience, measure marketing performance and provide relevant advertising.

We may use analytics tools, including Google Analytics, to understand how visitors use our website, which pages are useful, how people find us, and how our marketing performs.

You can usually manage or disable cookies through your browser settings. Some website features may not function properly if cookies are disabled.

Advertising, pixels and retargeting

We may use advertising and retargeting tools, including Meta Pixel and similar advertising technologies, to understand how people interact with our website and to show relevant advertising on platforms such as Facebook, Instagram, Google and other advertising networks.

These tools may collect or receive information from our website and other places on the internet and use that information to provide measurement services and targeted advertising.

This may include information about:

  • pages you visit;

  • buttons or links you click;

  • forms you start or submit;

  • bookings or purchases you make or attempt to make;

  • your device, browser and IP address;

  • how you interact with our website or advertisements.

You can manage some advertising preferences through the settings of the relevant advertising platform, such as Meta, Google or your browser.

Mindbody bookings and payments

We use Mindbody to manage bookings, client accounts, purchases, memberships, packages, class attendance, appointment reminders, waitlists, payments and client communications.

When you book, purchase or create an account through Mindbody, your information may be collected and processed by Mindbody and its payment providers. This may include your contact details, booking history, attendance history, purchase history, membership status, payment details and account information.

We do not usually receive or store your full credit card details. Payment information is generally processed by Mindbody or its payment processing partners.

Your use of Mindbody may also be subject to Mindbody’s own privacy policy and terms.

Health fund claiming

Where a service is eligible for health fund claiming, we may collect and use information needed to process or support a health fund claim.

This may include:

  • your name;

  • appointment or service details;

  • practitioner details;

  • provider number information;

  • health fund membership or card information;

  • transaction or claim result information.

 

Health fund claiming may be processed through third-party claiming terminals, software, payment systems, health fund platforms or related providers.

Each health fund has its own rules, eligibility requirements and privacy practices. We are not responsible for how your health fund handles your information once it has been submitted to or processed by them.

Forms, waivers and consents

We may use online forms, lead forms, intake forms, health questionnaires, waivers and consent forms to collect information needed to respond to enquiries, assess service suitability, manage risk and provide services.

These forms may be hosted through Wix, Mindbody or another third-party form, waiver or business administration provider.

The information you provide in these forms may include personal information and health information. Please only provide information that is accurate and relevant to your enquiry, booking or service.

Email and SMS marketing

Where permitted, we may use your contact details to send email or SMS marketing about our services, classes, events, workshops, offers, products, promotions, updates or information we think may be relevant to you.

We may use third-party email and SMS marketing providers to create, send and manage these communications.

Marketing communications may include tracking technologies that help us understand whether messages were opened, clicked or acted on.

You can opt out of marketing communications at any time by using the unsubscribe link in an email, following the opt-out instructions in an SMS, adjusting your communication preferences where available, or contacting us directly.

Even if you opt out of marketing, we may still send service-related communications, such as booking confirmations, appointment reminders, payment notices, class updates, cancellation notices, policy updates or information directly related to services you have booked or purchased.

Appointment reminders and service communications

We may send you service-related communications by email, SMS, phone or through Mindbody. These may include:

  • booking confirmations;

  • appointment reminders;

  • class updates;

  • cancellation or waitlist notifications;

  • membership or package updates;

  • direct debit or payment notices;

  • follow-up information relevant to your appointment or service;

  • important business, safety or policy updates.

These communications are part of providing our services and may continue even if you opt out of marketing.

CCTV

We may use CCTV at our premises for safety, security, incident management, insurance, theft prevention and protection of clients, staff, practitioners and property.

CCTV footage may capture your image if you attend our premises.

CCTV footage is not used for general marketing purposes. We may review or disclose CCTV footage where reasonably necessary for safety, security, incident investigation, insurance, legal, regulatory or law enforcement purposes.

No Nonsense Magnesium and Shopify

Our website may link to No Nonsense Magnesium, which is hosted by Shopify.

If you leave the No Nonsense Avalon website and purchase products through No Nonsense Magnesium, your personal information may be collected through Shopify and other ecommerce-related providers. This may include order details, shipping information, billing information and payment information.

No Nonsense Magnesium should have its own privacy policy that applies to product purchases made through that website.

 

How we use your personal information

We use personal information to:

  • provide our services;

  • manage bookings, classes, appointments, waitlists and attendance;

  • process payments, memberships, packages, passes and invoices;

  • create and manage client accounts;

  • communicate with you about bookings, reminders, changes, cancellations and service updates;

  • assess suitability for services, classes, treatments and recovery modalities;

  • provide appropriate care, treatment, exercise, massage, bodywork, recovery, coaching or related services;

  • keep treatment, health, consent and attendance records;

  • respond to enquiries, feedback or complaints;

  • provide customer support;

  • manage health fund claiming where available and relevant;

  • operate and improve our website;

  • understand website traffic and user behaviour;

  • measure advertising and marketing performance;

  • provide relevant advertising and retargeting;

  • manage email and SMS campaigns;

  • manage promotions, events, workshops, competitions or giveaways;

  • improve our services, systems and client experience;

  • maintain safety and security at our premises;

  • manage incident reporting, insurance and risk;

  • meet legal, accounting, taxation, professional and regulatory obligations;

  • protect the safety of clients, staff, practitioners and the public;

  • prevent fraud, misuse, security issues or unlawful activity.

 

When we share personal information

We may share personal information where reasonably necessary for our business, services, legal obligations, client care, safety or administration.

This may include sharing information with:

  • practitioners, staff, contractors or team members involved in providing services to you;

  • Mindbody and related booking, payment and communication providers;

  • Wix and website-related providers;

  • Google Analytics and other analytics providers;

  • Meta, Google and other advertising or retargeting providers;

  • email marketing and SMS providers;

  • form, waiver and consent-management providers;

  • payment processors and financial institutions;

  • health funds or health fund claiming providers, where relevant and requested;

  • insurers, legal advisers, accountants, bookkeepers or professional advisers;

  • IT, cloud storage, software, security and administration providers;

  • CCTV, security or incident-management providers;

  • referring practitioners or other health professionals, with your consent or where otherwise permitted by law;

  • parents, guardians, carers or authorised representatives, where appropriate;

  • regulators, courts, law enforcement agencies or government bodies where required or authorised by law;

  • another provider or business owner if our business is sold, restructured or transferred.

We only share personal information where we have a valid reason to do so and, where appropriate, we take reasonable steps to ensure third parties handle that information securely.

We do not sell your personal information.

Overseas storage and disclosure

Some of the platforms and service providers we use, including Wix, Mindbody, Shopify, Google, Meta, email and SMS marketing providers, payment providers, analytics tools, advertising platforms and cloud-based software providers, may store or process information outside Australia.

By using our services, website and booking systems, you acknowledge that your personal information may be transferred, stored or accessed in countries outside Australia where those providers operate.

Where reasonably practicable, we use reputable providers and take reasonable steps to protect personal information handled by third parties.

Health records and retention

We retain personal information for as long as reasonably necessary to provide our services, manage our business, comply with legal and professional obligations, resolve disputes, maintain records and meet insurance, accounting and taxation requirements.

Health records may need to be kept for minimum legal retention periods. In NSW, private health service providers generally need to retain adult health information for at least 7 years from the last occasion a health service was provided, and health information collected while a person was under 18 until that person reaches 25 years of age.

When information is no longer required, we take reasonable steps to securely destroy, delete or de-identify it, unless we are required or permitted by law to retain it.

Security of personal information

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.

These steps may include:

  • password-protected systems;

  • restricted access to client information;

  • secure booking and payment platforms;

  • staff and practitioner confidentiality expectations;

  • secure storage of records;

  • system access controls;

  • reasonable administrative, technical and physical safeguards;

  • secure disposal or deletion of information where appropriate.

No method of electronic transmission or storage is completely secure. While we take reasonable steps to protect your information, we cannot guarantee absolute security.

Data breaches

If we become aware of a data breach involving personal information, we will take reasonable steps to contain, assess and respond to the breach.

Where required by law, we will notify affected individuals and the Office of the Australian Information Commissioner.

Accessing or correcting your personal information

You may request access to the personal information we hold about you. You may also ask us to correct information that is inaccurate, incomplete, out of date or misleading.

To make a request, please contact us using the details below.

We may need to verify your identity before providing access or making changes. In some circumstances, we may be unable to provide access to certain information, for example where access would impact another person’s privacy, breach confidentiality, create a safety risk, or where we are legally permitted to refuse access.

Deleting information

You may ask us to delete personal information we hold about you. We will consider your request and take reasonable steps where appropriate.

In some cases, we may be required or permitted to retain certain information, including health records, transaction records, legal records, insurance records or information required for regulatory, taxation or professional reasons.

Children and minors

We may collect personal and health information about children or minors where they receive services from us, attend classes, participate in programs, or are included in a family booking or enquiry.

Where appropriate, we collect information from or with the involvement of a parent, guardian or authorised representative.

Anonymity and pseudonymity

Where practical, you may interact with us anonymously or using a pseudonym. However, for most bookings, health services, memberships, payments, health fund claims and client records, we need accurate personal information so we can provide services safely and effectively.

Third-party websites

Our website may contain links to third-party websites, platforms or services. We are not responsible for the privacy practices, security or content of third-party websites.

You should read the privacy policy of any third-party website or platform you use.

Complaints

If you have a question, concern or complaint about how we handle your personal information, please contact us first so we can try to resolve it.

Email: info@nononsenseavalon.com

Please include your name, contact details and a clear description of your concern.

We will aim to respond within a reasonable timeframe. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner or, where relevant, the NSW Information and Privacy Commission.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our business, services, systems, legal obligations or privacy practices.

The updated version will be posted on our website with the updated date.

bottom of page