top of page

Privacy Policy

Effective date: 7 August 2026

​

1. About this policy​

MBS Fitness is operated by Kirill Anisimov (ABN 65 805 491 484) under the business name MBS Fitness Hobart. In this policy, “MBS Fitness”, “we”, “us” and “our” refer to that business.

​

We respect your privacy and are committed to handling personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles and other applicable requirements.

​

This policy explains how we collect, hold, use and disclose personal information through our website at www.mbsfit.net, the MBS Fitness mobile app, enquiries, consultations, forms, bookings and payments. It also applies to group classes, gym access, personal training, online coaching, kids and youth programs, school-holiday programs, AdaptFit and NDIS-related services, competitions, events, referrals, retail purchases and other MBS Fitness activities. It covers information collected through in-person, telephone, email, SMS, app, social-media and other communications.

​

This policy applies to all payment arrangements, including casual purchases, class packs, upfront programs, recurring memberships or subscriptions, direct debits and in-app purchases. It does not set or change any price, commitment period, cancellation rule, refund rule or expiry date. Those matters are governed by the offer shown at purchase and our Terms and Conditions.

​

This policy is not a substitute for a specific privacy notice or consent request that we may provide when collecting health information, media, NDIS information or other sensitive information.

​

2. Personal information we collect​

The information we collect depends on how you deal with us.

​

Identity and contact information: We may collect your name, date of birth, address, email, phone number, profile photograph, preferred contact method and emergency contact details.

​

Parent, guardian and family information: We may collect the details of a parent or guardian, the relationship between an adult and a child, authorised contacts, consent records and sibling or dependent information needed to administer family bookings.

Account and service information: We may collect account details, membership status, plan or package information, bookings, waitlists, cancellations, attendance, session usage, training history, enquiries, feedback, complaints and customer-support records.

Health and fitness information: We may collect fitness goals, experience, injuries, medical conditions, disability, support needs, allergies, medication information relevant to safe participation, pre-exercise screening, fitness assessments, progress information, nutrition information, incident reports and other information needed to provide safe and suitable services.

​

NDIS-related information: We may collect participant and nominee details, an NDIS participant number, plan-management information, goals, support needs, service agreements, session notes, invoices and information required for service delivery, claims, audits, incidents or regulatory obligations.

​

Payment and transaction information: We may collect billing details, payment status, recurring-payment or subscription status, purchase history, receipts, refunds and limited payment-method details supplied by a payment provider. Full card details are generally processed by the relevant payment provider and are not stored directly by MBS Fitness.

​

Gym-access and safety information: We may collect induction and waiver records, access permissions, FOB or mobile-access records, entry times, safety reports and records of suspected misuse.

​

Communications and marketing information: We may collect messages, call notes, marketing preferences, consent records, referral sources, competition or promotion entries and responses to surveys.

​

Images and recordings: We may collect photographs, video, audio, testimonials and training footage where an appropriate notice has been provided or consent has been obtained.

​

Website and app information: We may collect an internet protocol address, browser and device type, operating system, app version, device or advertising identifiers, push-notification token, cookie identifiers, pages or features used, referring page, approximate location where enabled, diagnostic information, crash data and similar usage information.

​

Because MBS Fitness provides services intended to assess, maintain or improve health, personal information collected in providing those services may be health information and therefore sensitive information under Australian privacy law.

​

3. How we collect personal information​

We usually collect information directly from you when you create an account or profile; book a consultation, class, program or appointment; purchase or manage a membership, subscription, class pack, program, product or in-app purchase; complete a contact, registration, health, screening, waiver, consent, incident, feedback or competition form; use the website, app, member area, gym-access system or connected features; communicate with us in person, by phone, email, SMS, app, social media or messaging service; or attend a session, event, school program, community program or NDIS service.

​

We may also collect information from a parent, guardian, nominee, carer or authorised representative. Where authorised or lawful, we may collect information from an NDIS plan manager, support coordinator, provider, government body or other authorised participant in a person’s supports; a school, community organisation, referral partner or event organiser; coaches, contractors or service providers involved in delivering or administering services; payment, booking, access-control, app-store or account-login providers; or another person you have authorised.

​

If we receive unsolicited personal information that we could not lawfully have collected, we will take reasonable steps to destroy or de-identify it where required.

​

4. Children and young people​

We provide services to children and young people. Parents or guardians generally manage accounts, bookings, payments and consents for children who do not have the capacity to make their own privacy decisions.

​

The Privacy Act does not set one age at which a young person automatically has capacity to consent. Where appropriate, we consider the young person’s maturity and ability to understand what is proposed. We may seek the agreement of both the young person and their parent or guardian, particularly for health information, photographs, video, testimonials or optional uses of information.

​

We only collect information about a child that is reasonably necessary to provide or administer the service, protect safety or meet legal obligations. We do not use a child’s health or NDIS information for targeted advertising.

​

5. Why we collect, hold, use and disclose information​

We may handle personal information to respond to enquiries, provide consultations and establish or manage accounts, memberships, subscriptions, bookings, waitlists, attendance, payments, refunds and receipts. We may also use it to assess whether a service is suitable and to deliver safe, individualised boxing, fitness, personal-training, online-coaching, kids, youth, gym-access or AdaptFit services.

​

We may use personal information to plan sessions, monitor progress, communicate with coaches, maintain service records and manage NDIS service agreements, invoicing, participant communications, audits, incidents and lawful reporting. When reasonably necessary, we may use it to contact a parent, guardian, nominee, emergency contact, health professional or emergency service, or to send confirmations, reminders, schedule changes, payment notices, account messages and other service communications.

We may also handle personal information to manage the premises, gym access, safety, security, complaints, incidents, insurance and legal claims; process purchases and prevent fraud or misuse; improve our programs, website, app, communications and customer experience; and conduct de-identified reporting, analysis, quality assurance and business administration.

​

Where you have consented or where otherwise permitted by law, we may use personal information to send marketing or publish photographs, video or testimonials. We may also handle information to comply with tax, accounting, employment, NDIS, health and safety, child-safety, law-enforcement, court, insurance and other legal or regulatory obligations.

​

We will not use or disclose personal information for an unrelated purpose unless you consent or the use or disclosure is otherwise permitted or required by law.

​

6. Sensitive and health information​

We only collect sensitive information, including health, disability and NDIS information, where it is reasonably necessary for our services and we have the person’s valid consent or another legal basis applies.

​

Consent must be informed, voluntary, current and specific. We will not treat acceptance of this policy alone as consent for every possible use of sensitive information. Where appropriate, we use a separate health, NDIS, media or other consent process. Consent may be withdrawn for future handling, although withdrawal may affect our ability to safely provide a service or meet legal obligations.

​

We limit access to sensitive information to people who need it to perform their role. We do not use health or NDIS information for direct marketing without consent.

​

7. If you do not provide information​

You may browse general information on our public website without identifying yourself. Where practical, you may also make a general enquiry anonymously or using a pseudonym.

​

However, we normally need accurate identifying, contact, health, booking and payment information to provide a consultation or service, manage safety, contact someone in an emergency, process a payment or meet legal obligations. If required information is not provided, we may be unable to provide some or all of the requested service.

​

8. Website, app, cookies and similar technologies​

Our website and app may use cookies, software development kits, pixels and similar technologies for essential functions such as security, login, bookings, checkout and remembering preferences. We may also use these technologies for app and website performance, diagnostics, fraud prevention, analytics, service improvement and advertising or campaign measurement where enabled and permitted.

​

Depending on the feature and device settings, the app may collect or receive device identifiers, app activity, crash information, push-notification tokens and approximate location information. If you sign in using Apple, Google or another login provider, we may receive the account information you authorise that provider to share.

​

You can manage non-essential cookies through our consent controls where available and through your browser or device settings. Blocking some technologies may affect website or app functions. More information should be read with our Cookie Policy.

We do not knowingly send health-form responses, NDIS information or other sensitive information to advertising platforms for targeted advertising.

​

9. Direct marketing and service communications​

With your consent, we may send information about MBS Fitness classes, programs, events, products and offers by email, SMS, app notification or another channel you select.

You can opt out at any time by using the unsubscribe function, replying “STOP” where available, changing your app preferences or contacting us. We will process an opt-out within the period required by law. Opting out of marketing does not stop necessary service communications such as booking confirmations, safety notices, payment notices or changes to a service you use.

We do not sell or rent personal information. We do not use health or NDIS information for direct marketing unless valid consent has been obtained.

​

10. Photographs, video and testimonials​

We may take or use identifiable photographs, video, audio, testimonials or progress material only after providing an appropriate notice and obtaining consent where required. Promotional media consent is optional and is separate from the agreement to participate in training.

​

For a child or young person, we will obtain consent from a parent or guardian where appropriate and may also seek the young person’s agreement, depending on their maturity and the proposed use.

​

Consent may be withdrawn for future use by contacting us. We will take reasonable steps to stop new uses, but it may not always be possible to retrieve material already printed, published or shared by others.

​

11. Who we may disclose information to​

Where reasonably necessary and lawful, we may disclose personal information to authorised MBS Fitness staff, coaches and contractors on a need-to-know basis. We may also disclose information to website, app, booking, customer-management and cloud-hosting providers, including Wix; payment and transaction providers, which may include Wix Payments, Stripe, PayPal, Square, Apple or Google where used; email, SMS, messaging, push-notification and customer-support providers; and access-control, IT, cybersecurity, analytics and advertising providers where enabled.

​

We may disclose information to accounting, bookkeeping, insurance, legal and other professional advisers, or to a parent, guardian, nominee, carer, emergency contact or authorised representative. Where required or agreed, we may disclose information to the NDIA, the NDIS Quality and Safeguards Commission, plan managers, support coordinators and other authorised NDIS parties. We may also share relevant information with schools, community organisations or program partners where necessary for an agreed activity.

​

Where authorised or required, we may disclose information to emergency services, health professionals, insurers, law-enforcement agencies, courts, regulators or government bodies. In connection with a proposed sale or restructure of the business, information may also be disclosed to a prospective purchaser or adviser, subject to appropriate confidentiality and legal safeguards.

We aim to disclose only the minimum information reasonably necessary for the relevant purpose.

​

12. Overseas storage and disclosure​

Some of our technology, app, payment, communication, analytics and support providers operate or store data outside Australia. Based on the locations used by our current major platforms, overseas recipients or processing locations are likely to include the United States, Ireland, Israel and Singapore. Other locations may apply where a provider uses global group companies or subprocessors.

​

Where the Australian Privacy Principles apply to an overseas disclosure, we take reasonable steps required by law to protect the information. Overseas recipients may also be subject to the laws of their country. Provider locations can change, so you may contact us for more information about a particular service.

​

13. Security and retention​

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include access controls, strong authentication, secure platforms, staff confidentiality requirements, software updates, backups, payment-provider security controls and limiting access to what a person needs for their role.

​

No internet, mobile or storage system is completely secure. If a data incident occurs, we will contain and assess it and, where the Notifiable Data Breaches scheme applies, notify affected individuals and the Office of the Australian Information Commissioner when required.

​

We keep information only for as long as it is reasonably needed for service, safety, accounting, insurance, dispute-resolution and legal or regulatory purposes. Different records may have different required retention periods. When information is no longer required, we take reasonable steps to securely destroy or de-identify it, subject to lawful retention requirements and normal backup cycles.

​

14. Access, correction, deletion and withdrawal of consent​

You may ask us to provide access to personal information we hold about you, correct information that is inaccurate, out of date, incomplete, irrelevant or misleading, delete information or close an account where deletion is available and lawful, withdraw consent for future handling, or explain the source of personal information used for direct marketing where required.

​

You may use available account settings or contact us using the details below. We may need to verify your identity or authority before acting. There is no fee to make a request. If permitted by law, we may charge reasonable costs of providing access after informing you in advance.

​

We will respond within a reasonable period and normally aim to do so within 30 days. We may refuse or limit a request where the law permits or requires it, including where records must be retained. If we refuse, we will provide written reasons and information about how to complain where required.

​

Requests concerning a child or a person represented by someone else will be handled with regard to the individual’s capacity, privacy, legal authority and best interests.

​

15. Automated platform functions​

Our systems may automatically process bookings, waitlists, renewals, payment attempts, reminders, access permissions, fraud checks or similar administrative actions. These functions support service administration and are not intended to make decisions that significantly affect a person’s legal rights or interests.

​

If we introduce automated decision-making using personal information that could reasonably be expected to significantly affect a person’s rights or interests, we will update this policy and provide the information required by law.

​

16. Privacy complaints and enquiries​

If you have a privacy question, request or complaint, please contact:

The Privacy Contact is MBS Fitness at 115 Cove Hill Road, Bridgewater TAS 7030. You can email enquiries@mbsfit.net or call 0434 029 537.

​

Please describe the issue and provide enough information for us to investigate it. We will treat complaints respectfully and without reprisal. We aim to acknowledge a complaint within 7 days and provide a response within 30 days, although complex matters may take longer. If more time is needed, we will let you know.

​

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au/privacy/privacy-complaints.

​

NDIS participants may also raise concerns about the privacy or dignity of their supports with the NDIS Quality and Safeguards Commission at www.ndiscommission.gov.au.

​

17. Third-party services and links​

Our website and app may link to external websites, social-media services, app stores or payment services. Those third parties have their own privacy practices and terms. We encourage you to review them before providing information directly to those services.

 

18. Changes to this policy​

We may update this policy when our services, providers, technology or legal obligations change. The current version and effective date will be published on our website and made available through the app where appropriate. If a change materially affects how we handle information already collected, we will take reasonable steps to notify affected people and obtain consent where required.

bottom of page