Privacy Policy
Privacy Policy – Svasa Stillness
Last updated: 26 September 2025
1) Who we are
“Svasa Stillness” (“we”, “our”, “us”) provides yoga, Pilates, and wellness services. This Privacy Policy explains how we collect, use, disclose, and protect your personal information across our website, studio, and related services.
This Policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
2) Scope
This Policy applies to personal information we handle as a business operating in Australia. If other laws give you additional rights (e.g., GDPR for EU visitors), contact us and we’ll work to honour them where required.
3) What we collect
We may collect the following information:
- 
Identity & contact: name, email, phone number, address.
 - 
Account & booking: membership details, class bookings, communications with us.
 - 
Payment: processed securely via Stripe (card payments) or Afterpay (buy-now-pay-later). We do not store full card numbers.
 - 
Health & wellbeing: any conditions you disclose when booking, filling in intake forms, or speaking with staff. This is requested to ensure your safe participation.
 - 
Media consent: from time to time we may take photos or videos for promotional purposes (e.g., social media, website). You will always have the option to notify us in advance if you do not want to appear, and we will take all reasonable steps to ensure you are excluded.
 - 
Website & device: IP address, browser type, usage data, and cookies (see section 8).
 - 
Minors: for under-18s, we collect the child’s name, age, relevant health notes, and the parent/guardian’s contact details.
 
Where lawful and practicable (e.g., casual enquiries), you may interact with us anonymously or using a pseudonym.
4) How we obtain consent
- 
Adults: By booking a class, purchasing a membership, or otherwise providing information, you give implied consent for us to collect and use your personal information as described here.
 - 
Health information: By answering the health question during booking or providing details in writing/verbal form, you give explicit consent for us to use that information solely to support safe participation.
 - 
Media consent: Participation in studio activities may include photos/videos. If you do not wish to appear, you must inform us before class or via email, and we will take reasonable steps to exclude you.
 - 
Marketing: By providing your contact details, you consent to receive service communications. We may also send promotional emails unless you opt out. You can withdraw from marketing anytime by clicking “unsubscribe” or contacting us.
 - 
Minors: A parent/guardian must book on behalf of under-18s and is deemed to provide consent for collection and use of the child’s information.
 
5) How we use personal information
- 
Manage memberships, bookings, and payments.
 - 
Ensure safe participation in classes (using health details only for that purpose).
 - 
Communicate essential updates (class changes, service notices).
 - 
Share promotions or newsletters (unless you opt out).
 - 
Improve our website and services.
 - 
Comply with legal, tax, and regulatory obligations.
 
6) Sharing & overseas disclosure
We do not sell your personal information. We may share it with:
- 
Payment processors: Stripe (US/Ireland) and Afterpay (AU/NZ/US).
 - 
Service providers: booking platforms, email platforms (e.g., Mailchimp, US), website hosts (may include US/EU/SG), analytics providers (e.g., Google Analytics, US).
 - 
Authorities: where required by law.
 
Consistent with APP 8, we take reasonable steps to ensure overseas providers safeguard information.
⚠️ Third-party responsibility: We are not responsible for the privacy practices of Stripe, Afterpay, or other third-party providers — please review their policies.
7) Data retention
- 
Financial/transaction records: kept for up to 7 years (required by law).
 - 
Health information: kept only while relevant to participation and safety, then securely deleted.
 - 
Media consent preferences: recorded and respected as long as you are a member/client.
 - 
Backups/logs: retained temporarily as part of IT/security practices.
 
When no longer required, information is securely destroyed or anonymised.
8) Cookies & analytics
We use cookies and similar technologies for:
- 
Essential: site functions and security.
 - 
Analytics: e.g., Google Analytics to improve site experience.
 - 
Marketing: tracking campaign performance (if enabled).
 
You can manage or disable cookies in your browser. Essential cookies cannot be disabled.
9) Children & parents/guardians
- 
All bookings for under-18s must be made by a parent/guardian, who consents to data collection and health disclosures.
 - 
We do not knowingly collect information directly from under-16s.
 - 
Parents/guardians may access or correct their child’s information at any time.
 
10) Security & data breaches
We apply reasonable technical and organisational safeguards (e.g., HTTPS, access controls, encryption in transit).
If a data breach occurs that is likely to result in serious harm, we will:
- 
Contain and assess the breach promptly.
 - 
Notify affected individuals with recommendations to minimise risk.
 - 
Notify the Office of the Australian Information Commissioner (OAIC) where required.
 
11) Your rights
You can request to:
- 
Access or correct your personal information.
 - 
Request deletion (subject to legal requirements).
 - 
Withdraw consent for marketing or health data processing.
We may need to verify your identity (and for minors, parental authority). If a request is refused, we’ll explain why and how to complain. 
12) Complaints
Please send all privacy complaints in writing to:
Svasa Stillness – Privacy Officer: Anmool Kaur
Email: admin@svasastillness.com
Phone: +61 451 413 147
We will respond within 30 days. If you are not satisfied, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
13) Changes
We may update this Policy from time to time. The new effective date will be published above, and material changes will be notified via our website or by email to active members.
