Privacy Policy
SUB10 TRAINING AND RECOVERY LTD
How we collect, use, protect and share personal information
Organisation
SUB10 Training and Recovery Ltd (SUB10, we, us or our)
Privacy contact
gym@sub10.nz | 021 281 9191
In short: we collect only the personal information we reasonably need to operate SUB10, keep people and the Facility safe, administer memberships and payments, and provide bookings and services. We do not sell personal information.
1. About this policy
This policy applies when you become or apply to become a member, visit or use our Facility, use the SUB10 website or app, make a booking, attend a class or appointment, contact us, use our Wi-Fi, or otherwise interact with us. It should be read with your Membership Agreement and our Terms and Conditions.
We handle personal information in accordance with the Privacy Act 2020 and its information privacy principles. Personal information means information about an identifiable individual.
2. Personal information we collect
Depending on how you interact with us, we may collect:
identity and contact details, including your name, date of birth, address, email address, phone number and photograph;
membership and eligibility information, including your membership type, start and end dates, concessions, student or age eligibility, signed agreements and consents;
parent or guardian details and consents for members under 18, and limited information needed to manage use of the children’s area or attendance with an infant;
health, accessibility, emergency-contact and pre-exercise screening information you choose or are required to provide where reasonably necessary for safety or service delivery;
booking, class, Pilates, recovery-suite, massage and attendance information, including cancellations, waitlists and no-shows;
payment and account information, such as your chosen payment method, billing status, transaction history, failed payments, refunds and amounts owing. Payment credentials are generally collected and processed by Ezypay rather than stored by SUB10;
Facility access information, including app or access-credential identifiers, entry and exit records, tailgating alerts and access restrictions;
CCTV footage and incident, accident, complaint, conduct and health-and-safety records;
communications with us, including emails, forms, enquiries, feedback and membership cancellation requests;
photographs or recordings where we have given notice and obtained any consent required for the intended use;
website, app and device information, such as IP address, browser or device type, login records, app diagnostics, cookies, website interactions and device location used for enabled location-based features; and
Wi-Fi and systems-security information reasonably required to provide the service and protect our network and users.
3. How we collect information
We usually collect personal information directly from you through membership forms and agreements, the SUB10 app and website, bookings, communications, visits to the Facility, CCTV, access systems and your use of our services.
We may also receive information from a parent or guardian, an authorised representative, GymMaster, Ezypay, Baycorp or another debt-recovery provider, a health or emergency service, a coach or service provider, or another person involved in an incident or complaint. We may collect information from public sources where lawful and reasonably necessary.
Where we collect personal information about you from someone else, we will take reasonable steps to make you aware of the collection and the matters required by Privacy Principle 3A, unless an exception applies. This may include notice in this policy, in an email, in the app, on a form or directly from our staff.
4. Why we use personal information
We may use personal information to:
assess membership eligibility and establish, administer, suspend, cancel or renew memberships;
provide Facility access and deliver gym, group-fitness, Pilates, recovery, massage and related services;
manage bookings, attendance, waitlists, service capacity and member communications;
process payments, reconcile accounts, handle failed payments and refunds, and recover overdue amounts;
protect members, children, visitors, staff, contractors, property and systems, and investigate incidents or suspected unauthorised access;
respond to enquiries, complaints, privacy requests and emergencies;
meet health and safety, accounting, insurance, legal and regulatory obligations;
maintain and improve our services, Facility operations, website and app;
send operational messages and, where permitted, information about SUB10 services and offers; and
carry out another purpose that is directly related to the reason the information was collected, that you authorise, or that is permitted or required by law.
5. Is providing information optional?
You may choose not to provide personal information. However, if we cannot collect information reasonably required for a membership, payment, booking, access, age verification, health and safety, or a requested service, we may be unable to provide that membership, access or service. We will not ask for information that is not reasonably necessary for a lawful SUB10 purpose.
6. The SUB10 app, GymMaster and Ezypay
The branded SUB10 app and membership platform are provided by GymMaster. They enable account administration, bookings, documents, membership cancellation requests, payment-detail updates, attendance records and digital Facility access. SUB10 has enabled GymMaster’s location based check in feature. When you permit location access on your device, GymMaster may use your device location to support class or Facility check in. You can manage the app’s location permission through your device settings, although disabling it may prevent location based checkin from working.
Ezypay processes recurring payments and payment detail updates. Ezypay’s handling of payment information is also governed by the privacy and payment terms it provides to you. SUB10 may receive transaction status, payment reference, failed payment and account information needed to administer your membership, but we do not receive or retain your complete card security code.
You should keep your app login and access credentials secure, use your own credentials, and notify us promptly if you believe they have been compromised.
7. Who we may share information with
We may disclose personal information where reasonably necessary to:
authorised SUB10 staff, instructors and contractors who need it to perform their role;
GymMaster, Ezypay, Google Analytics, Mailchimp and providers of hosting, communications, access control, CCTV, IT support, accounting or professional services acting for us;
Baycorp or another reputable debt-recovery provider where an amount is lawfully overdue, and credit-reporting providers only where permitted by law;
Insurers, advisers, courts, tribunals, regulators, Police, emergency services or other authorities where authorised or required by law or reasonably necessary to address a serious safety, security or legal issue;
a parent, guardian or authorised representative where appropriate and lawful, taking account of the rights and interests of a young person; and
a prospective purchaser or successor if SUB10’s business is restructured, sold or transferred, subject to appropriate confidentiality and privacy safeguards.
We do not sell or rent personal information to third parties.
8. Overseas storage and processing
Some technology providers may store or process information outside New Zealand. For example, GymMaster states that its member app services may use hosting in New Zealand and other countries, including the United States, Singapore, Australia and Germany. Google Analytics and Mailchimp may also process information through systems or service providers located outside New Zealand.
Where an overseas organisation acts only as our storage or processing agent, we remain responsible for taking reasonable steps to protect the information. Where we disclose personal information to an overseas organisation for its own use, we will comply with Privacy Principle 12, including ensuring comparable safeguards or obtaining informed authorisation where required.
9. CCTV and access monitoring
CCTV and access monitoring systems operate at the Facility for safety, security, access control, incident investigation and protection of people and property. Our CCTV records video only and does not record audio. Cameras are not used in toilets, changing rooms, bathrooms or other areas where people would reasonably expect privacy. We do use CCTV in our Recovery room for safety reason's and monitoring.
Authorised people may review or disclose footage and access records only where reasonably necessary for these purposes, including an incident, insurance claim, legal proceeding or lawful request. Routine CCTV footage is generally retained for 14 days and is then overwritten or deleted. Relevant footage may be retained longer where reasonably necessary while an incident, claim, complaint or legal matter is being addressed.
10. Health information and emergencies
We treat health, injury, accessibility and emergency information as sensitive. We limit access to people who reasonably need it for safety, service delivery or administration. In an emergency, we may disclose relevant information to emergency services, a health practitioner, your emergency contact or another person where permitted by law and reasonably necessary to prevent or lessen a serious threat to health or safety.
11. Children and young people
Children and young people have privacy rights. For under 18 memberships, we may collect information from both the young person and their parent or guardian, including identity, age, contact, consent, payment, health and safety, attendance and access information. We will collect and use only what is reasonably necessary, explain our practices in an age appropriate way where practicable, and take the young person’s circumstances and interests into account.
Information about children using the designated children’s area, or infants attending in prams, will be collected only where reasonably necessary for safety, incident management or Facility operations. CCTV may incidentally capture children in monitored common areas.
12. Marketing and communications
We will send messages needed to administer your membership, payments, access, bookings, safety and Facility operations. These are service communications and may continue while your membership or an outstanding matter remains active.
We use Mailchimp to manage some mailing lists and send marketing or member communications. Mailchimp may process contact details, mailing list preferences and information about interactions with emails, such as delivery, opens or link clicks, to provide these services.
We may send information about SUB10 services or offers where permitted by law. You may unsubscribe from marketing using the link in the message or by contacting gym@sub10.nz. Unsubscribing from marketing will not stop necessary service communications.
13. Website, cookies and links
Our website uses Google Analytics and may use cookies or similar technologies to understand how people find and use the site, such as pages viewed, approximate location, device or browser information and interactions with website features. We use this information to maintain and improve our website and services.
You can manage cookies through your browser settings, although disabling some cookies may affect functionality. Google also provides controls and information about its handling of analytics data through its own privacy services.
Our website or app may link to services operated by others. Their handling of personal information is governed by their own privacy notices, except where they process information solely on our behalf.
14. Keeping information secure
We use reasonable physical, technical and organisational safeguards appropriate to the information we hold. These include limiting access by role, protecting accounts and systems, using reputable service providers, staff expectations and secure disposal practices. No storage or transmission method is completely risk free, so please contact us promptly if you suspect misuse of your account, app, access credential or personal information.
15. Retention
We keep personal information only for as long as it is reasonably required for the purpose for which it was collected, to administer an ongoing relationship, resolve a complaint or claim, recover a lawful debt, maintain safety and security records, or comply with legal, tax, accounting and insurance obligations. Backup copies may remain for a limited period until they are overwritten through normal system cycles.
16. Accessing and correcting your information
You may ask whether we hold personal information about you, request access to it, or ask us to correct it. Send your request to gym@sub10.nz and include enough information for us to identify you and the information concerned. We may ask for proof of identity or authority before responding.
We will respond as soon as reasonably practicable and within the time required by the Privacy Act 2020. In limited circumstances the Act allows us to withhold information or refuse a request. If we do not make a requested correction, you may ask us to attach a statement of correction to the information.
17. Privacy breaches
If a privacy breach occurs, we will take reasonable steps to contain it, assess the risk and reduce harm. If the breach has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected people as soon as practicable, unless an exception applies.
18. Questions and complaints
Please contact us first so we have an opportunity to address your concern:
Privacy contact
SUB10 Management
Email: gym@sub10.nz
Phone: 021 281 9191
Address: 67 Jellicoe Street, Te Puke 3119
Website: www.sub10.nz
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner at www.privacy.org.nz.
19. Changes to this policy
We may update this policy to reflect changes in our services, systems, providers or legal obligations. The current version will be available at www.sub10.nz and will show its effective date. If a change materially affects how we use or disclose existing member information, we will take reasonable steps to notify affected members before the change takes effect where practicable.

