1Who you're dealing with
LMTLESS Training is a registered business name of Oliver Dylan Price, a sole trader operating in New South Wales, Australia.
| Business name | LMTLESS Training |
| Operator | Oliver Dylan Price (sole trader) |
| ABN | 67 816 703 481 |
| Location | New South Wales, Australia |
| Contact | lmtlesstraining@gmail.com |
Throughout this policy, “I” and “me” mean that business. There is no one else in it — no staff, no contractors, no agency. I am the only person who reads your screening.
2Which privacy laws apply to me
Most Australian businesses turning over less than $3 million a year are exempt from the Privacy Act 1988 (Cth). I am not one of them. The exemption doesn't apply to a business that provides a health service and holds health information, and the regulator lists “assessing, maintaining or improving an individual's physical health” as providing a health service — naming gyms specifically when they collect health information.
So I am bound by the Australian Privacy Principles under the Privacy Act, and by the 15 Health Privacy Principles under the Health Records and Information Privacy Act 2002 (NSW), which covers private-sector operators in NSW who collect or hold health information regardless of turnover.
I'd rather say that plainly than pretend the exemption covers me. It means you have enforceable rights here, and they're set out in section 8.
3What I collect
When you subscribe
- Your name and email address
- A record that a payment succeeded, its amount and date, and which plan you're on
Payments are processed by Stripe. I never see or hold your card number. Stripe handles the card details and tells me only that you paid.
In the health screening
- Injuries, current and past, and any physical restrictions
- Medical conditions, and medications that affect exercise
- Answers to standard pre-exercise safety questions
- Your training history, available equipment, schedule and goals
- Your typed name and the date, as your signature on the participation agreement
Every week after that
- Check-in answers: sessions completed, how they felt, soreness, sleep, anything that hurt
- Any pain or injury you report, and what I changed in response
- On the Plan + Form Review tier, video you send of yourself lifting
- Emails between us
Almost everything in the last two lists is health information, which both Acts treat as sensitive — a higher standard than an email address. I collect it only with your consent, which you give by completing the screening, and only because I can't write a program that's safe for you without it. You can decline any individual question. If declining means I can't program safely around something, I'll tell you rather than guess.
4Why I collect it
| Information | What it's for |
|---|---|
| Screening answers | Deciding whether it's safe for you to start, whether you need clearance from a GP or physio first, and what the program has to work around |
| Equipment, schedule, goals | Writing a program you can actually do, in the place you actually train |
| Weekly check-ins | Adjusting the next block. This is the entire product |
| Pain reports | Changing or removing exercises the same day, and knowing when to tell you to see a physio |
| Lift videos | Written technique feedback, on the review tier only |
| Name, email, payment record | Sending your program, and running the subscription |
I don't use any of it for anything else. If I ever wanted to — a case study, an example in a video, research — I would ask you first, specifically, and a no costs you nothing.
5Who else sees it
No other human being reads your screening or your check-ins. But your information passes through services run by other companies, and you should know which:
| Service | What it handles |
|---|---|
| Stripe | Card details and subscription billing. I never see your card number. Stripe stores payment data, some of it outside Australia |
| Google (Forms, Sheets, Drive, Gmail) | Your screening and check-in answers, the client list, your program files, and our email. Google stores data on servers in a number of countries, which may include outside Australia |
Under Australian Privacy Principle 8, sending your information overseas is a disclosure I have to tell you about, so: by using the forms and email, your information may be stored outside Australia on Google's and Stripe's infrastructure. Both are large providers with published security practices, but neither is Australian, and I can't guarantee a foreign provider will handle your information exactly as Australian law requires.
Otherwise, I disclose your information only when
- You ask me to. For example, forwarding a summary to your physio — only with your say-so, each time.
- Someone's life or safety is at serious risk and disclosure is necessary to lessen it.
- The law requires it — a court order, a subpoena, a regulator exercising a statutory power.
What I will never do
- Sell your information, or anything derived from it, to anybody
- Hand it to a supplement company, an insurer, an employer, or an advertiser
- Use your health information to target advertising, here or anywhere else
- Quote you, name you, or use your before-and-after anything without asking first
6How it's stored and protected
- Screenings and check-ins arrive in Google Forms and stay in a Google account used only for this business, never a personal or shared one
- That account has two-factor authentication switched on
- Nothing is shared to a link that anyone with the URL can open
- Health information is not copied into any spreadsheet, notes app or messaging thread outside that account
- Devices that access it are password-protected and encrypted
No system is perfectly secure, and I won't claim otherwise. What I can tell you is that the number of places your screening exists is deliberately small.
7How long I keep it
Under Part 4 of the NSW HRIP Act, a private-sector health service provider must keep health information for 7 years from the last time a service was provided, where it was collected from an adult. Where information was collected from someone under 18, it must be kept until they turn 25.
That's a legal floor, not a preference. It means that if you cancel, I can't simply delete your screening on request — the obligation to retain it overrides the usual right to erasure. After the retention period ends, health information is destroyed.
Information that isn't health information — your email address, billing records — is kept while you're a client and afterwards only as long as tax law requires, then deleted. Billing records generally need to be kept for 5 years under Australian tax law.
8Your rights
Access
You can ask for a copy of everything I hold about you: your screening, every check-in, every program. Email me and I'll send it within 30 days, free, in a readable format. I can only refuse in the narrow circumstances the Acts allow, and if I do I have to tell you why in writing.
Correction
If something I hold is wrong, out of date or incomplete, tell me and I'll fix it. If I disagree that it's wrong, you have the right to have a statement of your view attached to the record, and I'll attach it.
Anonymity
You can deal with me anonymously for general questions. You can't do it as a client — I can't write a safe program for someone whose injury history I don't have.
Complaints
If you think I've mishandled your information, tell me first. I'll respond within 30 days. If you're not satisfied, or you'd rather not come to me at all, you can go straight to either regulator:
Office of the Australian Information Commissioner
1300 363 992 · oaic.gov.au
Information and Privacy Commission NSW
1800 472 679 · ipc.nsw.gov.au
9If there's a data breach
The Notifiable Data Breaches scheme applies to me. If your information is lost or accessed without authorisation and it's likely to cause you serious harm, I have to notify both you and the Australian Information Commissioner as soon as practicable. I'll tell you what happened, what was exposed, and what to do about it. I won't sit on it.
10This website
- The site has no analytics, no tracking pixels and no advertising cookies. I don't know who visits it
- It loads fonts from Google Fonts, which means Google receives your IP address when the page loads. That's a consequence of using a web font and it's true of most of the web
- The monthly plan document ticks off sessions using your own browser's local storage. That data never leaves your device and I can't see it
- Clicking a plan takes you to Stripe, which has its own privacy policy covering what happens there
11Changes to this policy
If I change it, the version number and date at the top change too. If a change materially affects how your health information is handled, I'll email you about it rather than quietly updating the page.
12Contact
Olly Price — LMTLESS Training
Privacy questions get answered like pain reports do — quickly, and by me.