
Privacy policy
How JCMT PTY LTD, trading as Legends Gym, collects, uses, discloses and safeguards your personal information under the Australian Privacy Principles.
JCMT PTY LTD, trading as Legends Gym, is committed to protecting your privacy and the confidentiality of your personal information. This policy outlines how we collect, use, disclose and safeguard your personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
01
Collection of personal information
We collect personal information from website visitors and members for purposes directly related to our services and operations. The types of personal information we may collect include:
- Identity and contact information — name, email address, phone number, address, date of birth, gender.
- Membership and billing information — payment details securely stored by our third-party provider, Gym Master, for billing only. We do not store full payment details on our systems.
- Health and fitness information — collected through exercise questionnaires and trainer assessments. We obtain explicit consent before collecting sensitive health information.
- Website usage and technical data — pages visited, time on site, IP address and device information.
- Media — photos or videos taken at the gym or during events, with your consent where appropriate.
02
Use of personal information
We use your personal information to process your membership application and manage your account, process payments, communicate with you about your membership, and provide our fitness services and programs including personal training.
- To schedule classes, personal training sessions and other services.
- To personalise your experience and tailor our services to your preferences.
- For marketing and advertising, where you have consented or as otherwise permitted by law.
- To comply with our legal and regulatory obligations.
03
Disclosure of personal information
We may disclose your personal information to payment processors, marketing platforms, scheduling software providers, analytics providers, and legal or regulatory authorities where required by law. We do not sell or rent your personal information to third parties.
04
Data security
We have implemented reasonable measures to protect your information from misuse, interference, loss, unauthorised access, modification or disclosure — including encryption in transit and at rest, firewalls, access controls, regular security audits and mandatory staff training. In the event of a data breach we will assess, contain and remediate, and notify affected individuals in accordance with our legal obligations.
05
Data retention
We retain your personal information for as long as necessary to fulfil the purposes for which it was collected. Membership information is retained for the duration of your active membership and for seven years afterwards, to comply with accounting and tax regulations and to resolve any disputes.
Sections 6–12 continue
Cookies and tracking, access and correction, complaints, overseas disclosure, children's privacy, changes to this policy, and contact details. Paste the remaining clauses from the current policy into this same structure.
