Paddo Performance  ·  Banksmeadow

Privacy Policy

Last updated: August 2026

1. Who we are

This Privacy Policy explains how Paddo Pty Ltd (ACN 627 998 458) as trustee for the Paddo Performance Trust (ABN 73 303 753 123), trading as Paddo Performance (“Paddo Performance”, “we”, “us” or “our”), collects, uses, stores and discloses your personal information.

We are committed to protecting your privacy and handling your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Because we operate a health service (rehabilitation and allied health services), we are treated as an organisation covered by the Privacy Act regardless of our annual turnover, and we also handle health information in accordance with the Health Records and Information Privacy Act 2002 (NSW).

Our premises are located at 22/13-15 Baker Street, Banksmeadow NSW 2019. You can contact us about privacy matters at [email protected].

2. What this policy covers

This policy covers personal information we collect about members, casual visitors, people who enquire with us, people who apply to work or train with us, and visitors to our website and premises.

Important — coaches and practitioners. Coaches and allied health practitioners who operate from our facility are independent contractors, not employees. Where you engage one of them directly as their client, that practitioner is responsible for collecting, storing and protecting your health and personal information, and their own privacy practices apply. This policy does not cover information you provide directly to an individual coach or practitioner in the course of their own services to you.

3. The personal information we collect

Depending on how you interact with us, we may collect:

  • Contact and identity information — your name, email address, phone number and, where relevant, your company name.
  • Membership and billing information — the details on your membership application and the payment details needed to process your membership or casual pass.
  • Health information — any injury history, medical conditions or pre-exercise screening information provided on our member sign-up form and Terms and Conditions. Health information is “sensitive information” under the Privacy Act and is collected only with your consent (see Section 5).
  • Enquiry and interest information — the information you give us when you enquire, including what services you are interested in and how you heard about us.
  • Job application information — the details you provide when applying to work with us.
  • Access and security information — Salto entry logs and CCTV footage (see Section 9).
  • Images — photographs or video, where you have consented (see Section 8).

Health information held by us is limited. For members, we only hold the health information contained on the member sign-up form and Terms and Conditions. Where you train with an individual coach or practitioner, any further health information you provide is collected and held by that practitioner, not by us.

4. How we collect your information

We collect personal information directly from you when you complete a form on our website, sign up for a membership or casual pass, enquire about our services, apply to work with us, or attend our premises. We also collect access information automatically through our Salto entry system and CCTV cameras when you enter the facility.

Where it is reasonable and practicable, we collect personal information directly from you. If we receive information about you from someone else (for example, a referral), we handle it in accordance with this policy.

5. Sensitive and health information

Health information is treated as sensitive information under the Privacy Act. We collect it only where you have expressly consented and where it is reasonably necessary for us to provide our services safely — for example, so that we understand injuries or conditions that may affect your training.

By providing health information on our member sign-up form or Terms and Conditions, you consent to us collecting and holding that information for these purposes. You can ask us at any time to access or correct this information (see Section 14).

6. Why we collect and use your information

We collect, hold and use your personal information to:

  • provide and administer your membership, casual pass or other services;
  • process payments and manage billing;
  • respond to your enquiries and provide the information or services you have asked for;
  • understand injuries or conditions relevant to safe training;
  • manage access to and security of our premises;
  • consider your application to work with us;
  • send you news, offers and updates about Paddo Performance, where you have opted in (see Section 11); and
  • meet our legal, taxation, insurance and record-keeping obligations.

7. Who sees your information internally

Access to member and enquirer information within our systems is limited to our directors and management.

Coaches and practitioners are contractors. They do not have general access to member health or injury information. A coach or practitioner only sees your health or injury information where you are their own client and you have provided that information to them directly for the purpose of their services.

8. Photographs and video

From time to time we may take photographs or video within the facility, for example for technique checks, social media content or testimonials. We ask for your consent before filming or photographing you. If you do not wish to be filmed or photographed, please let a team member know and we will respect that.

9. CCTV and premises access

CCTV

Our premises are monitored by CCTV for the safety and security of members, staff and property. Signage stating that surveillance cameras are in use is displayed at the entry. CCTV footage is retained for no longer than 72 hours before it is overwritten, unless it is required for a specific incident, investigation or legal proceeding. Access to CCTV footage is limited to our directors and management.

Entry and exit logs (Salto)

Our Salto access system records entry to the facility using your access credentials. These logs are retained for approximately 3 days and are used only to operate the door and manage secure access. We do not use them to monitor attendance or for any other secondary purpose.

10. The systems we use and overseas storage

We use a number of third-party systems to run our business and deliver our services. These include:

  • GoHighLevel — our customer relationship management, forms, email marketing and website platform;
  • Stripe — payment processing;
  • Cliniko — rehabilitation and allied health booking;
  • Salto — access control;
  • monday.com — order and fulfilment tracking;
  • Google Workspace — email and document storage.

Some of these providers store data outside Australia. Where your personal information is stored or processed overseas, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles. By providing your information to us, you acknowledge it may be stored or processed overseas by these providers.

Health information and our CRM. We limit the health information we hold in our marketing CRM. The health information we hold about members is confined to what is provided on the member sign-up form and Terms and Conditions. Health information relating to a practitioner's own clients is held by that practitioner in their own systems.

11. Marketing communications

Where you have opted in, we send marketing communications about Paddo Performance, including to people who have enquired but not yet joined. We continue to send these until you unsubscribe. Every marketing email includes an unsubscribe link, and you can opt out at any time by using that link or by contacting us at [email protected].

We do not currently use tracking pixels on our website, and we do not currently upload customer email or phone lists to advertising platforms such as Meta or Google to build custom audiences. If we begin to do so in future, we will update this policy and disclose it, as uploading a list to an advertising platform is a disclosure of personal information to an overseas third party.

12. When we disclose your information

We do not sell your personal information. We disclose it only:

  • to the third-party service providers listed in Section 10, so they can perform their functions for us;
  • to an individual coach or practitioner where you have chosen to engage them directly;
  • where you have consented; or
  • where we are required or authorised by law to do so.

13. How long we keep your information

Member records. Cancelled member records are retained for seven (7) years after the membership ends, to comply with legal, taxation, contractual and insurance obligations. After this period, personal information is securely destroyed or permanently de-identified unless a longer retention period is required by law, or because of an ongoing dispute, investigation or legal proceeding.

Job applications. Unsuccessful job applications are generally retained for twelve (12) months after the recruitment process concludes, so that we can consider applicants for future opportunities and keep records of the process. After this period, applicant information is securely deleted or de-identified, unless the applicant has consented to longer retention or retention is required for legal or regulatory purposes.

Health records. Where we hold health information, we retain it for at least seven (7) years from the date of last service for adults. For anyone who was under 18 at the time, we retain it until they turn 25, in line with health records requirements.

CCTV and access logs. CCTV footage is retained for no longer than 72 hours and Salto access logs for approximately 3 days, as described in Section 9.

14. Access, correction and complaints

You can ask us to access the personal information we hold about you, or to correct it if it is inaccurate, out of date or incomplete. To make a request, contact us at [email protected]. We will respond within 30 days. There is generally no charge to access your information, although we may recover reasonable costs in some circumstances.

If you are concerned about how we have handled your personal information, please contact us at [email protected] and we will investigate and respond within 30 days. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.

15. Members under 18

The minimum age for access to our facility is 16, unless the person is accompanied by a trainer or guardian. Where we collect personal or health information about a person under 18, we require the consent of a parent or guardian, as a person under 18 generally cannot give valid consent to the collection of their own health information.

16. Data breach response

Paddo Performance has a documented data breach response process. If a suspected or actual data breach occurs — including unauthorised access to our GoHighLevel account, loss or theft of a laptop or mobile device, or accidental disclosure of personal information — our nominated Privacy Officer will immediately assess the incident, take steps to contain the breach, investigate what information has been affected, and determine whether the breach is likely to result in serious harm to any individual.

Where required under the Privacy Act 1988 (Cth) and the Notifiable Data Breaches scheme, we will notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable. All breaches, whether notifiable or not, are documented and reviewed to reduce the risk of future incidents.

Decision-maker: Paul Xydis (Business Owner / Director / Privacy Officer), or another nominated Privacy Officer if appointed. A decision not to notify is made only after assessing whether the breach is an eligible data breach under the Notifiable Data Breaches scheme, and legal or privacy advice is obtained where there is any uncertainty.

17. Automated decision-making

We use automated workflows in our CRM to support our team, not to replace human decision-making. For example, our system applies tags to an enquiry based on the interests a person identifies through our forms and their interaction with our content. These automations organise and route information; they do not make decisions that significantly affect a person without human involvement.

18. How we protect your information

We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Login access to our core systems (including GoHighLevel and Cliniko) is limited to our directors and management. Licensed coaches and practitioners have access to Cliniko for their own bookings and clients. We review access and security arrangements from time to time.

19. Changes to this policy

We may update this policy from time to time. The current version will always be available on our website, and the effective date at the top shows when it was last updated. Significant changes will be notified where appropriate.

20. Contact us

For any privacy question, request or complaint, contact us at [email protected].