Legal

Privacy
Policy

Effective date: 26 August 2026

1. Purpose

This Privacy Policy sets out how Coachy Ventures Pty Ltd, trading as Gymnastics Online (in this Policy, GO), collects, holds, uses, discloses, secures, retains, and destroys personal information, sensitive information, and health information in connection with the operation of the Gymnastics Online platform (the Platform). It records the position of the organisation on each material aspect of privacy and data protection across every jurisdiction in which GO operates, and identifies the persons within Coachy Ventures Pty Ltd who are accountable for the matters addressed.

This Policy is published in accordance with the obligation in Australian Privacy Principle 1.3 that an APP entity must have a clearly expressed and up-to-date policy about the management of personal information. The matters specified in APP 1.4 are addressed in Sections 4.4, 4.6, 4.13, 4.14, 4.21 and 5 of this Policy.

This Policy is not legal advice and is not a contract. It is to be read together with the Gymnastics Online Terms of Use, the GO Privacy Procedure (GO-PRI-003), and the other documents listed in Section 9.4.

2. Scope

2.1 Application

This Policy applies to:

  • Coachy Ventures Pty Ltd (ACN [insert]) and any related body corporate or trading name (collectively, GO);
  • every employee, officer, director, contractor, sub-contractor, intern, volunteer, and ambassador of GO;
  • every third-party content contributor engaged by GO, including without limitation Crystal Yeo (engaged through YEOCO Pty Ltd) and the dietitians and sports psychologists named in the GO content contributor register;
  • every sub-processor and outsourced technology provider listed in the GO Outsourced Technology Provider Register;
  • the GO Platform, in all jurisdictions of operation and on all devices and channels through which the Platform is accessed; and
  • every category of personal information, sensitive information, and health information described in the GO Sensitive Records Register, regardless of the form in which it is held.

2.2 Jurisdictional scope

The Platform operates in five jurisdictions: Australia, New Zealand, Canada, the United States of America, and the United Kingdom. The body of this Policy expresses GO's primary position by reference to Australian law, on the basis that Coachy Ventures Pty Ltd is incorporated in Australia and the Platform's data infrastructure is located in Australia. Where the law of another jurisdiction imposes additional or different obligations on GO, those obligations are addressed in the corresponding Annex:

  • Annex A — Australia (covered in the body of this Policy)
  • Annex B — New Zealand
  • Annex C — Canada
  • Annex D — United States of America
  • Annex E — United Kingdom

The European Union is expressly excluded from the current scope of the Platform. GO does not solicit users from, or target the Platform to, persons in the European Economic Area, and personal information of EEA residents is not knowingly collected. Should the EU be added to GO's launch markets in a future version, this Policy will be amended to incorporate an EU annex.

2.3 Out of scope

This Policy does not address:

  • information security technical controls, which are governed by the GO Information Security Policy (GO-SEC-001) and supporting technical procedures;
  • cyber-incident detection, containment, and recovery, which are governed by the GO Cyber Incident Response Plan (GO-SEC-009);
  • the day-to-day implementation of the rights and obligations stated in this Policy, which is the function of the GO Privacy Procedure (GO-PRI-003) and the supporting procedures listed in Section 9.4; and
  • the conduct of an individual coach, parent, gymnast, club administrator, or other user of the Platform in relation to information that does not constitute personal information of which GO is the holder.

3. Definitions and interpretation

In this Policy:

Statutory definitions (Australia)

Personal information has the meaning given by section 6(1) of the Privacy Act 1988 (Cth):1

“personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable: (a) whether the information or opinion is true or not; and (b) whether the information or opinion is recorded in a material form or not.”

— Privacy Act 1988 (Cth), s 6(1)

Sensitive information has the meaning given by section 6(1) of the Privacy Act 1988 (Cth), and includes (relevantly for the Platform) health information, racial or ethnic origin, religious beliefs, sexual orientation or practices, and biometric information that is to be used for the purpose of automated biometric verification or biometric identification, or biometric templates.2

Health information has the meaning given by section 6FA of the Privacy Act 1988 (Cth) and includes:3

“(a) information or an opinion about: (i) the health, including an illness, disability or injury, (at any time) of an individual; or (ii) an individual’s expressed wishes about the future provision of health services to the individual; or (iii) a health service provided, or to be provided, to an individual; that is also personal information; or (b) other personal information collected to provide, or in providing, a health service to an individual; or (c) other personal information about an individual collected in connection with the donation, or intended donation, by the individual of his or her body parts, organs or body substances; or (d) genetic information about an individual in a form that is, or could be, predictive of the health of the individual or a genetic relative of the individual.”

— Privacy Act 1988 (Cth), s 6FA

GO holds health information within the meaning of paragraph (b) above in respect of any wellness check-in, soreness map, injury log, or coach-to-parent communication that concerns a specific gymnast. Voice recordings made by a verified coach that identify a specific minor by name and concern the minor's physical condition or performance are health information for the purposes of this Policy.

APP entity has the meaning given by section 6 of the Privacy Act 1988 (Cth). Coachy Ventures Pty Ltd is an APP entity. The small business operator exemption in section 6D does not apply because GO provides a health service within the meaning of section 6FB and holds health information.4

Eligible data breach has the meaning given by section 26WE of the Privacy Act 1988 (Cth) — broadly, unauthorised access to, unauthorised disclosure of, or loss of personal information in circumstances where a reasonable person would conclude that the access, disclosure, or loss would be likely to result in serious harm to any of the individuals to whom the information relates.5

Other defined terms

Platform means the Gymnastics Online Progressive Web Application, including the related infrastructure, databases, content libraries, voice-note pipeline, wellness check-in interface, and parent/coach/admin dashboards.

Parent means an account-holder who is a parent or legal guardian of one or more gymnasts and is the subscription-paying user of the Platform.

Gymnast means a minor aged 6 to 18 inclusive, supervised on a Parent's account, whose use of the Platform is authorised by the Parent.

Coach means an individual whose Platform access permits the creation of coach-to-parent communications, the recommendation of exercises from the senior-coach-reviewed library, or both, where the feature is enabled in the relevant jurisdiction.

Club administrator means an individual whose Platform access permits oversight of coaches and parents associated with a registered gymnastics club.

Sub-processor means a third party engaged by GO to process personal information on GO's behalf. The current list of sub-processors is published with this Policy and updated as it changes.

Sensitive Records Register means the document of that name (GO-PRI-002), maintained in accordance with Australian Privacy Principle 1.2, which itemises every category of personal information held by GO, the system in which it is held, its retention period, and its access controls.

4. Policy statements

This Section sets out GO's binding positions on each material aspect of privacy and data protection. Each sub-section identifies the applicable legislative obligation, quotes the operative provision verbatim, and states GO's position. Roles and accountabilities for each position are consolidated in Section 5.

4.1 Compliance commitment

GO complies with the Privacy Act 1988 (Cth) and each of the 13 Australian Privacy Principles set out in Schedule 1 of that Act.6 GO also complies with each of the privacy and data-protection laws specified in Annexes B to E that apply by reason of GO's collection or processing of personal information from individuals in the corresponding jurisdiction.

Australian Privacy Principle 1.1 states the object that this commitment is designed to give effect to:

“1.1 The object of this principle is to ensure that APP entities manage personal information in an open and transparent way.”

— Privacy Act 1988 (Cth), Schedule 1, APP 1.1

GO commits to managing personal information in a manner that gives substantive effect to that object, and to designing the Platform in accordance with privacy-by-design and privacy-by-default principles.

4.2 Open and transparent management of personal information

GO maintains practices, procedures, and systems that ensure compliance with the Australian Privacy Principles and that enable GO to deal with privacy inquiries and complaints. Australian Privacy Principle 1.2 provides:

“1.2 An APP entity must take such steps as are reasonable in the circumstances to implement practices, procedures and systems relating to the entity’s functions or activities that: (a) will ensure that the entity complies with the Australian Privacy Principles and a registered APP code (if any) that binds the entity; and (b) will enable the entity to deal with inquiries or complaints from individuals about the entity’s compliance with the Australian Privacy Principles or such a code.”

— Privacy Act 1988 (Cth), Schedule 1, APP 1.2

The practices, procedures, and systems by which GO discharges this obligation include the documents listed in Section 9.4 (Related GO documents), the role allocations in Section 5 of this Policy, the Sensitive Records Register, the privacy-impact-assessment process operated by the Compliance & Risk Manager, and the privacy-training requirements applicable to GO personnel and contractors.

Australian Privacy Principle 1.3 requires an APP entity to have a clearly expressed and up-to-date policy. APP 1.4 specifies the minimum content of that policy:

“1.4 Without limiting subclause 1.3, the APP privacy policy of the APP entity must contain the following information: (a) the kinds of personal information that the entity collects and holds; (b) how the entity collects and holds personal information; (c) the purposes for which the entity collects, holds, uses and discloses personal information; (d) how an individual may access personal information about the individual that is held by the entity and seek the correction of such information; (e) how an individual may complain about a breach of the Australian Privacy Principles, or a registered APP code (if any) that binds the entity, and how the entity will deal with such a complaint; (f) whether the entity is likely to disclose personal information to overseas recipients; (g) if the entity is likely to disclose personal information to overseas recipients—the countries in which such recipients are likely to be located if it is practicable to specify those countries in the policy.”

— Privacy Act 1988 (Cth), Schedule 1, APP 1.4

This Policy contains the information required by APP 1.4 at the following locations: paragraph (a) — Section 4.4 and the Sensitive Records Register; paragraph (b) — Sections 4.4 and 4.6; paragraph (c) — Section 4.7; paragraph (d) — Sections 4.13 and 4.14; paragraph (e) — Section 4.21; and paragraphs (f) and (g) — Section 4.9.

This Policy is made available free of charge on the Gymnastics Online website in accordance with Australian Privacy Principle 1.5. A copy of this Policy will be provided in any reasonable form requested by an individual in accordance with APP 1.6, free of charge.

From 10 December 2026, additional obligations apply under new Australian Privacy Principles 1.7, 1.8, and 1.9 introduced by Part 15 of the Privacy and Other Legislation Amendment Act 2024 (Cth) in respect of decisions made solely, or substantially and directly, by the operation of a computer program.7 This Policy will be amended to address those additional obligations before they commence. The GO position on automated decision-making is stated in Section 4.19 below.

4.3 Anonymity and pseudonymity

Australian Privacy Principle 2 provides:

“2.1 Individuals must have the option of not identifying themselves, or of using a pseudonym, when dealing with an APP entity in relation to a particular matter. 2.2 Subclause 2.1 does not apply if, in relation to that matter: (a) the APP entity is required or authorised by or under an Australian law, or a court/tribunal order, to deal with individuals who have identified themselves; or (b) it is impracticable for the APP entity to deal with individuals who have not identified themselves or who have used a pseudonym.”

— Privacy Act 1988 (Cth), Schedule 1, APP 2

GO recognises that the safeguarding, sub-processor-billing, and parent-gymnast linkage functions of the Platform render anonymous dealing impracticable for substantive use of the service. However, GO offers pseudonymous interaction in the following circumstances:

  • a Parent may use a display name that is not the Parent's legal name on the Parent profile, provided that legal-name identification is provided to the billing process operated by Stripe for the purpose of payment;
  • a Gymnast's profile is identified by an opaque server-side identifier; the Gymnast's display name within the Platform may be a first name only or a chosen pseudonym, subject to the Parent's discretion;
  • inquiries about the Platform made through general contact channels may be made anonymously or pseudonymously, subject to GO's ability to respond meaningfully; and

a complaint under Section 4.21 may be made pseudonymously, except that GO is unable to action a complaint to its conclusion (including by the application of any remedy) without sufficient identifying information to verify the complainant's relationship to the personal information in question.

4.4 Collection of personal information

GO collects personal information only where the information is reasonably necessary for one or more of GO's functions or activities, in accordance with Australian Privacy Principle 3.2:

“3.2 If an APP entity is an organisation, the entity must not collect personal information (other than sensitive information) unless the information is reasonably necessary for one or more of the entity’s functions or activities.”

— Privacy Act 1988 (Cth), Schedule 1, APP 3.2

Australian Privacy Principle 3.5 and APP 3.6 govern the means by which personal information is collected:

“3.5 An APP entity must collect personal information only by lawful and fair means. 3.6 An APP entity must collect personal information about an individual only from the individual unless: (a) if the entity is an agency: ... ; or (b) it is unreasonable or impracticable to do so.”

— Privacy Act 1988 (Cth), Schedule 1, APP 3.5 and APP 3.6

The categories of personal information that GO collects, the source from which each category is collected, and the function or activity that makes the collection reasonably necessary are recorded in the GO Sensitive Records Register and summarised below.

Categories of personal information GO collects

Parent identification and contact information: legal name, email address, mobile phone number, billing address, payment card information (collected and held by Stripe as a sub-processor; tokenised reference only is held by GO);

Gymnast information: first name and chosen display name, age and date of birth, club affiliation, competitive level, apparatus focus, parent linkage;

Coach information: legal name, email address, club affiliation, federation membership number, identification information collected for working-with-children-check verification (Australia and equivalent in each jurisdiction);

Club administrator information: legal name, email address, club affiliation, role;

Wellness data (which is health information): structured-data-only wellness check-in entries (energy level, body-map soreness, per-apparatus “request extra help” selections from a closed list);

Coach-to-parent voice notes (which are health information when they concern a specific minor's physical condition or performance): audio recordings, transcripts, moderation flags;

Platform-usage information: device type, operating system, browser, IP address, page-view logs, login times, session duration, content consumed;

Communications: messages between Parent and Coach (direct, with the Club Admin Email address copied only on a safeguarding red-flag escalation), complaint and inquiry correspondence;

Photo and short-video content of a Gymnast: captured by a Coach within the Platform and shared with the linked Parent. This is a paid-tier feature (free-tier accounts do not have access to it) and is collected only following a separate, explicit parental consent step taken at paid-tier signup, which the Parent may retract at any time. See Section 4.12 for the retention rule specific to this category.

GO does not collect personal information that is not reasonably necessary for one or more of the functions or activities described in the Sensitive Records Register, and GO does not knowingly collect personal information about an individual who has not consented to its collection (where consent is required under APP 3 or the equivalent provision of the law of any other jurisdiction in which the Platform operates).

Source of collection

GO collects personal information directly from the individual or, in the case of a Gymnast, from the Parent. The Parent-Gymnast link is established when the Parent creates the Gymnast profile directly on the Parent account. Separately, a Parent links to a Coach by means of an invite code or QR code issued by that Coach; no Coach can view, message, or be connected to a Gymnast or Parent until the Coach has cleared the GO coach verification gate (credentials check, Working with Children Check, region-appropriateness check, and either club sanction or a GO-direct Trust and Safety sanction for an independent coach). GO does not engage in self-pairing at the Coach-verification level: every Coach-Parent link requires the Coach to have passed verification first.

4.5 Collection of sensitive information and health information

Sensitive information (including health information) is subject to the more stringent collection conditions in Australian Privacy Principle 3.3:

“3.3 An APP entity must not collect sensitive information about an individual unless: (a) the individual consents to the collection of the information and: ... (ii) if the entity is an organisation—the information is reasonably necessary for one or more of the entity’s functions or activities; or (b) subclause 3.4 applies in relation to the information.”

— Privacy Act 1988 (Cth), Schedule 1, APP 3.3

GO collects sensitive information (including health information) only with the consent of the individual concerned or, where the individual is a minor, with the consent of the Parent. Consent is recorded as expressly and granularly as the GO consents-table data model permits, and is operationally documented in the GO Consent Management Procedure (GO-PRI-007).

GO collects no sensitive information other than the categories listed in the Sensitive Records Register. In particular:

  • GO does not collect biometric information to be used for the purpose of automated biometric verification or biometric identification, and GO does not collect biometric templates;

GO does not collect information about racial or ethnic origin, political opinion, religious belief, philosophical belief, sexual orientation or practices, or criminal record, except where collection of working-with-children-check status (which may incidentally disclose absence of disqualifying convictions) is required by the law of the relevant jurisdiction in respect of a Coach or Club administrator;

GO does not collect calorie counts, weight, body composition, or any data point from which body composition can be derived. This exclusion is a substantive feature of the GO product and is described publicly in the GO content guardrails.

Voice recordings of a Coach that name a specific Gymnast and concern the Gymnast's physical condition or performance are health information for the purposes of section 6FA of the Privacy Act 1988 (Cth). GO's collection, processing, retention, and destruction of voice recordings is described in Section 4.16.

4.6 Notification at the point of collection

Australian Privacy Principle 5 requires GO, at or before the time of collection (or as soon as practicable thereafter), to notify the individual of the matters set out in APP 5.2:

“5.1 At or before the time or, if that is not practicable, as soon as practicable after, an APP entity collects personal information about an individual, the entity must take such steps (if any) as are reasonable in the circumstances: (a) to notify the individual of such matters referred to in subclause 5.2 as are reasonable in the circumstances; or (b) to otherwise ensure that the individual is aware of any such matters.”

— Privacy Act 1988 (Cth), Schedule 1, APP 5.1

GO discharges this obligation by means of: (a) this Policy; (b) just-in-time notification at each point of collection within the Platform (most importantly, the wellness check-in interface and the voice-note record interface); (c) the GO Terms of Use; and (d) the GO Children's Online Privacy Procedure (GO-PRI-004), which contains an age-appropriate explanation of collection practices presented to the Parent at the point of Gymnast pairing.

4.7 Use and disclosure of personal information

GO uses and discloses personal information only for the primary purpose for which it was collected, or for a permitted secondary purpose. The applicable rule is Australian Privacy Principle 6:

“6.1 If an APP entity holds personal information about an individual that was collected for a particular purpose (the primary purpose), the entity must not use or disclose the information for another purpose (the secondary purpose) unless: (a) the individual has consented to the use or disclosure of the information; or (b) subclause 6.2 or 6.3 applies in relation to the use or disclosure of the information.”

— Privacy Act 1988 (Cth), Schedule 1, APP 6.1

Primary purposes for which GO collects, holds, uses, and discloses personal information

provision of the GO Platform and its content, communication, community, and educational features;

verification of the relationship between a Parent and a Gymnast, and between a Coach and a Club;

mediation of coach-to-parent communications, including by means of artificial-intelligence-assisted transcription and moderation in accordance with Section 4.16;

operation of the wellness check-in feature, including escalation in accordance with the dual-gate wellness procedure described in the GO Safeguarding documentation;

billing and subscription administration;

safeguarding and incident response;

compliance with the law (including law-enforcement requests where lawful);

operation of the GO complaints and inquiries function in accordance with Section 4.21;

internal analytics for the improvement of the Platform, on a de-identified basis to the maximum extent practicable; and

the affiliate programme described in the GO Marketing Procedure (GO-MKT-002).

Permitted secondary use and disclosure

GO will use or disclose personal information for a secondary purpose only where: (a) the individual has consented; (b) the individual would reasonably expect GO to use or disclose the information for the secondary purpose and the secondary purpose is related (or, in the case of sensitive information, directly related) to the primary purpose; (c) the use or disclosure is required or authorised by or under an Australian law or court or tribunal order; or (d) another exception in APP 6.2 applies.

GO does not sell personal information. GO does not trade in personal information. GO does not use personal information for behavioural advertising, and GO does not engage in behavioural advertising on the Platform.

4.8 Direct marketing

Direct marketing is governed by Australian Privacy Principle 7:

“7.1 If an organisation holds personal information about an individual, the organisation must not use or disclose the information for the purpose of direct marketing.”

— Privacy Act 1988 (Cth), Schedule 1, APP 7.1

APP 7.2 permits direct marketing of personal information (other than sensitive information) to an individual where the organisation collected the information from the individual, the individual would reasonably expect the use, the organisation provides a simple opt-out, and the individual has not opted out. APP 7.4 permits direct marketing of sensitive information only with consent. GO's direct-marketing position is:

  • GO sends marketing communications by email to Parents only (not to Gymnasts, not to Coaches, not to Club administrators acting in that capacity);
  • GO provides a one-click unsubscribe in every marketing email, in accordance with APP 7.3(c) and section 18 of the Spam Act 2003 (Cth);
  • GO will not send unsolicited marketing communications by SMS;
  • GO does not use sensitive information for direct marketing; and
  • a Parent may opt out of direct marketing at any time by using the unsubscribe link in any marketing communication or by contacting the Compliance & Risk Manager.
  • APP 7.8 expressly preserves the application of the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth) to GO's direct-marketing activities.8

4.9 Cross-border disclosure of personal information

Australian Privacy Principle 8.1 imposes an accountability obligation on an APP entity that discloses personal information to an overseas recipient:

“8.1 Before an APP entity discloses personal information about an individual to a person (the overseas recipient): (a) who is not in Australia or an external Territory; and (b) who is not the entity or the individual; the entity must take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles (other than Australian Privacy Principle 1) in relation to the information.”

— Privacy Act 1988 (Cth), Schedule 1, APP 8.1

The effect of section 16C of the Privacy Act 1988 (Cth) is that an act done or practice engaged in by the overseas recipient that would (if engaged in by GO) breach the APPs is taken to be a breach by GO.9 GO therefore manages overseas disclosure as a substantive accountability risk and not as a contractual formality.

GO's cross-border disclosure position

The primary GO position is that personal information collected from individuals in Australia is hosted in Australia and is not disclosed to overseas recipients in the ordinary course of providing the Platform. Specifically:

  • all personal information is hosted in Amazon Web Services region ap-southeast-2 (Sydney), with the disaster-recovery replica in ap-southeast-4 (Melbourne) — both in Australia;
  • transcription is performed by Microsoft Azure AI Speech Australia East at launch, and is to migrate to a self-hosted faster-whisper instance on Fly.io Sydney at volume — both in Australia;

artificial-intelligence inference is performed by Anthropic Claude models accessed via Amazon Bedrock in ap-southeast-2 (Sydney) with Zero Data Retention enabled, so that no personal information is logged or retained by the inference provider — all processing occurs in Australia;

personally-identifying entities are stripped from text before any inference call by means of a self-hosted Microsoft Presidio container in ap-southeast-2 (Sydney).

Where personal information is collected from an individual in New Zealand, Canada, the United States, or the United Kingdom, the data flows to the Australian hosting infrastructure described above. The applicable cross-border-transfer mechanism (which is, in each case, an outbound transfer from the relevant jurisdiction to Australia, not an outbound transfer from Australia) is described in the corresponding Annex. The transfer impact assessment and standard contractual clauses that GO relies on for EEA/UK transfers (if any) are maintained by the Compliance & Risk Manager and are accessible to data subjects on request.

Sub-processors with overseas links

Stripe, Vimeo, ActiveCampaign, Resend, and Cloudflare operate under multi-region arrangements that may, in defined and disclosed circumstances, involve disclosure to a country other than Australia. The current sub-processor list is maintained and published with this Policy and identifies, for each sub-processor, the data category processed, the country in which processing occurs, and the cross-border-transfer mechanism relied upon.

GO does not disclose health information of Gymnasts to overseas recipients except where required to enable a specifically-requested feature of the Platform (no such cross-border feature is currently active).

4.10 Quality of personal information

Australian Privacy Principle 10 requires GO to take reasonable steps to ensure that personal information held, used, or disclosed by GO is accurate, up-to-date, and complete:

“10.1 An APP entity must take such steps (if any) as are reasonable in the circumstances to ensure that the personal information that the entity collects is accurate, up-to-date and complete. 10.2 An APP entity must take such steps (if any) as are reasonable in the circumstances to ensure that the personal information that the entity uses or discloses is, having regard to the purpose of the use or disclosure, accurate, up-to-date, complete and relevant.”

— Privacy Act 1988 (Cth), Schedule 1, APP 10

GO maintains the quality of personal information by: (a) collecting personal information directly from the individual concerned (or, for a Gymnast, from the Parent); (b) inviting the individual to verify and update the personal information held by GO at each material interaction with the Platform; (c) acting promptly on a request for correction made under Section 4.14; and (d) destroying or de-identifying personal information that is no longer required for any purpose for which it may be used or disclosed.

4.11 Security of personal information

Australian Privacy Principle 11.1 sets the security standard:

“11.1 If an APP entity holds personal information, the entity must take such steps as are reasonable in the circumstances to protect the information: (a) from misuse, interference and loss; and (b) from unauthorised access, modification or disclosure.”

— Privacy Act 1988 (Cth), Schedule 1, APP 11.1

“Reasonable steps” is assessed in the circumstances, having regard to (relevantly) the nature of the APP entity, the amount and sensitivity of the personal information held, the consequences of the breach for affected individuals, and the practicability and cost of available security measures.10 GO holds health information about minors and treats the relevant standard of reasonable steps as elevated. The recent Federal Court decision in Australian Clinical Labs Limited v Australian Information Commissioner [2025] FCA 1224 confirms that the standard expected of an entity that holds health information is substantial.11

GO's information security position

The technical and organisational measures by which GO discharges the APP 11.1 obligation are set out in full in the GO Information Security Policy (GO-SEC-001). In summary, GO maintains:

  • encryption at rest using AWS Key Management Service with region-pinned keys (no key export);
  • encryption in transit using TLS 1.2 or above, with TLS 1.3 preferred;
  • Rails Active Record Encryption applied to sensitive fields at the application layer;
  • mandatory multi-factor authentication for Coach, Club administrator, and Admin accounts;
  • tenant (club) isolation at the database layer;
  • audit logs on every administrative view of safeguarding-related personal information;
  • a Microsoft Presidio personally-identifying-entity stripping pipeline applied before any inference call;
  • a documented vulnerability-management programme, including annual external penetration testing;
  • multi-availability-zone PostgreSQL with KMS-encrypted snapshots and Australian-region disaster recovery;
  • a documented Cyber Incident Response Plan, including tabletop exercises;
  • contractual security commitments and data-processing addenda with every sub-processor.

GO does not engage in any conduct that would foreseeably degrade the security of personal information held by GO. The Compliance & Risk Manager is accountable for the operation of the information-security control set described above; the Operations & Systems Manager is accountable for its technical implementation; and the Managing Director is the executive sponsor.

4.12 Retention and destruction

Australian Privacy Principle 11.2 requires the destruction or de-identification of personal information that is no longer needed:

“11.2 If: (a) an APP entity holds personal information about an individual; and (b) the entity no longer needs the information for any purpose for which the information may be used or disclosed by the entity under this Schedule; and (c) the information is not contained in a Commonwealth record; and (d) the entity is not required by or under an Australian law, or a court/tribunal order, to retain the information; the entity must take such steps as are reasonable in the circumstances to destroy the information or to ensure that the information is de-identified.”

— Privacy Act 1988 (Cth), Schedule 1, APP 11.2

Retention periods for each category of personal information are set out in the GO Data Retention and Destruction Policy (GO-PRI-006). The following retention rules are material to this Policy:

  • raw audio of a Coach voice note is destroyed no later than 72 hours after the Coach's acceptance of the corresponding transcript;
  • a Coach voice-note transcript is retained for the lifecycle of the corresponding report, in accordance with the report-type retention rules in the Data Retention and Destruction Policy;
  • a wellness check-in entry is retained for the purpose stated in the Privacy Procedure and subject to the data-protection-impact-assessment determination recorded against that purpose;
  • an injury log is retained for the duration of the Gymnast's account plus the safeguarding audit-trail retention period;
  • audit logs of administrative views of safeguarding data are retained for seven (7) years from the date of the view;
  • backup data is retained for thirty (30) days from the date of backup; thereafter backup data is destroyed in the ordinary course;

personal information of a Parent following account closure is destroyed within thirty (30) days, except for information that GO is required to retain by reason of an Australian law (including the Income Tax Assessment Act 1997 (Cth) and the Income Tax Assessment Act 1936 (Cth)), a court or tribunal order, or an active complaint or claim.

photo and short-video content captured by a Coach and shared with a Parent under the paid photo/video sharing feature is held in a temporary server-side buffer only — no copy is retained on the Coach’s device — and is automatically purged, with hard deletion of the image or video binary, no later than 48 hours after capture. Audit metadata about the sharing event (but not the image or video itself) is retained in accordance with the audit-log retention rule below;

Where a category of personal information includes information that is required to be retained by law and information that is not so required, GO retains only the information that is required, and destroys or de-identifies the remainder.

4.13 Access to personal information

Australian Privacy Principle 12.1 establishes the right of access:

“12.1 If an APP entity holds personal information about an individual, the entity must, on request by the individual, give the individual access to the information.”

— Privacy Act 1988 (Cth), Schedule 1, APP 12.1

Australian Privacy Principle 12.3 identifies the limited circumstances in which GO is not required to give access:

“12.3 If the APP entity is an organisation then, despite subclause 12.1, the entity is not required to give the individual access to the personal information to the extent that: (a) the entity reasonably believes that giving access would pose a serious threat to the life, health or safety of any individual, or to public health or public safety; or (b) giving access would have an unreasonable impact on the privacy of other individuals; or (c) the request for access is frivolous or vexatious; or (d) the information relates to existing or anticipated legal proceedings between the entity and the individual, and would not be accessible by the process of discovery in those proceedings; or (e) giving access would reveal the intentions of the entity in relation to negotiations with the individual in such a way as to prejudice those negotiations; or (f) giving access would be unlawful; or (g) denying access is required or authorised by or under an Australian law or a court/tribunal order; or (h) both of the following apply: (i) the entity has reason to suspect that unlawful activity, or misconduct of a serious nature, that relates to the entity’s functions or activities has been, is being or may be engaged in; (ii) giving access would be likely to prejudice the taking of appropriate action in relation to the matter; or (i) giving access would be likely to prejudice one or more enforcement related activities conducted by, or on behalf of, an enforcement body; or (j) giving access would reveal evaluative information generated within the entity in connection with a commercially sensitive decision-making process.”

— Privacy Act 1988 (Cth), Schedule 1, APP 12.3

APP 12.4 requires GO to respond within a reasonable period after the request is made. The GO operational standard is twenty (20) business days from receipt of a verified request, with extension where the request is voluminous or complex and the individual is notified of the reason for and length of the extension. GO does not charge a fee for the making of a request, and any charge for giving access will not be excessive. The procedure for handling an access request, including identity verification and the safeguarding-related exception to access on best-interests-of-the-child grounds, is set out in the GO Subject Access and Correction Request Procedure (GO-PRI-008).

4.14 Correction of personal information

Australian Privacy Principle 13.1 establishes the right of correction:

“13.1 If: (a) an APP entity holds personal information about an individual; and (b) either: (i) the entity is satisfied that, having regard to a purpose for which the information is held, the information is inaccurate, out of date, incomplete, irrelevant or misleading; or (ii) the individual requests the entity to correct the information; the entity must take such steps (if any) as are reasonable in the circumstances to correct that information to ensure that, having regard to the purpose for which it is held, the information is accurate, up to date, complete, relevant and not misleading.”

— Privacy Act 1988 (Cth), Schedule 1, APP 13.1

Where GO refuses to correct personal information following a request, GO will give the individual written notice setting out the reasons for refusal (except to the extent that it would be unreasonable to do so) and the mechanisms available to complain about the refusal, in accordance with APP 13.3. Where GO refuses to correct, and the individual so requests, GO will associate with the personal information a statement that the individual considers it inaccurate, out of date, incomplete, irrelevant, or misleading, in accordance with APP 13.4. GO will not charge an individual for the making of a correction request, for correcting personal information, or for associating a statement with personal information, in accordance with APP 13.5(b).

4.15 Children's privacy

The GO Platform is designed for use by minor Gymnasts aged 6 to 18, supervised on an adult Parent's account. Children's privacy is therefore central to GO's design and operation, and is subject to dedicated rules in each jurisdiction. GO's position is as follows.

GO's children's privacy commitments (cross-jurisdictional)

GO collects no more personal information about a Gymnast than is reasonably necessary for the function or activity for which it is collected;

a Gymnast under 13 years of age accesses the Platform only through a Parent account, and the Parent provides verifiable consent in accordance with the law of the jurisdiction in which the Gymnast is located;

there is no direct messaging between a Coach and a Gymnast; coach-to-gymnast-relevant communication is routed Coach → Parent directly, with the Club Admin Email address copied only where a safeguarding red-flag escalation applies;

structured-data-only wellness check-ins permit a Gymnast to make selections from closed lists, but do not invite or store free-text content authored by a Gymnast;

there is cryptographic segregation between the Parent tile and the Gymnast tile, such that an item authored or selected by a Gymnast is not visible to the Parent unless the Gymnast has affirmatively elected to share it with the Parent (with the default set to off);

GO does not present advertising to a Gymnast and does not engage in behavioural advertising to any user of the Platform; and

the Gymnast is provided with a child-comprehensible explanation of the Platform's privacy practices, which is a separate document available from the Children's Online Privacy Procedure (GO-PRI-004).

Australian Children's Online Privacy Code

The Office of the Australian Information Commissioner released an exposure draft of the Australian Children's Online Privacy Code on 31 March 2026. Public consultation closes on 5 June 2026, and the registration of a Code under section 26GC of the Privacy Act 1988 (Cth) is anticipated.12 GO has designed its children's privacy architecture to satisfy the Code's anticipated requirements regardless of whether the Code applies to GO as a matter of law. The OAIC's view on whether GO is a “health service” within an exclusion to the Code, or a “designated internet service” within scope, is a matter on which legal counsel's view has been sought and is recorded in the GO Children's Online Privacy Procedure (GO-PRI-004).

The detailed jurisdictional rules applicable to a child Gymnast's personal information are set out in the corresponding Annex.

4.16 Voice recordings, transcription, and artificial-intelligence processing

The Platform's voice-note feature accepts a Coach's spoken audio, transcribes it, applies a two-layer moderation step, and presents the resulting transcript to the Coach for acceptance before transmission to the Parent (via the Club administrator role). GO's position on this feature is:

  • voice audio is processed in the Australian region (Microsoft Azure AI Speech Australia East at launch; faster-whisper on Fly.io Sydney at volume);
  • personally-identifying entities (including names, dates of birth, and addresses) are stripped from the transcript by a self-hosted Microsoft Presidio container before any artificial-intelligence inference is performed;

artificial-intelligence inference is performed by Anthropic Claude models accessed via Amazon Bedrock in region ap-southeast-2 with Zero Data Retention enabled — no personal information is retained or used by the inference provider for any purpose, including model training;

raw audio is destroyed no later than 72 hours after the Coach's acceptance of the corresponding transcript;

the moderation steps applied to a transcript do not constitute a decision under APP 1.7 (when it commences on 10 December 2026), because the Coach is the human decision-maker who accepts (or rejects) the transcript before any consequential action is taken; and

no automated decision-making affecting the rights or interests of an individual is performed on, or as a result of, voice-note processing.

The GO position on artificial intelligence more generally is stated in the GO AI Governance Policy (GO-AI-001), which is anchored to GO's five hard rules — GO never approves; AI never decides; dual-gate wellness; no traffic-light risk presentation; mandatory-reporting Red Flag routing — and is operationalised by the human-in-the-loop procedure (GO-AI-005).

4.17 Sub-processors and third-party providers

The current GO sub-processor list is maintained by the Compliance & Risk Manager and published with this Policy. It includes (and may include other named providers from time to time):

  • Amazon Web Services Australia Pty Ltd (Sydney, AU): hosting, storage, encryption (KMS), database, queueing;
  • Microsoft Pty Ltd (Australia East, AU): transcription (Azure AI Speech);
  • Anthropic, PBC (accessed via Amazon Bedrock ap-southeast-2, AU; Zero Data Retention enabled): artificial-intelligence inference for transcript moderation;
  • Stripe Payments Australia Pty Ltd: payment processing (cards, subscriptions);
  • Vimeo, Inc.: video content delivery;
  • Resend, Inc.: transactional email delivery;
  • Twilio (Australia) Pty Ltd: SMS and voice (where used);
  • ActiveCampaign, LLC: customer-relationship-management and marketing-email platform;
  • Zapier, Inc.: workflow automation (in particular, Facebook community auto-add and auto-revoke);
  • Cloudflare, Inc.: static-content delivery (no behavioural tracking, no third-party analytics).

Each sub-processor is bound by a data-processing addendum that imposes obligations equivalent to those imposed on GO by this Policy and the law of the relevant jurisdiction. The DPAs include, at a minimum: confidentiality, security measures appropriate to the personal information processed, sub-processor onboarding controls, breach notification within 48 to 72 hours, return or destruction of personal information on termination, and audit rights. The agreement with Anthropic, PBC includes an express commitment that personal information is not used for training of artificial-intelligence models.

4.18 Notifiable data breaches

Part IIIC of the Privacy Act 1988 (Cth) — “Notification of eligible data breaches” — establishes the Notifiable Data Breaches scheme.5 The definition of an eligible data breach is set out in section 26WE:

“26WE(2) For the purposes of this Act, an eligible data breach happens if: (a) both of the following conditions are satisfied in relation to personal information held by an entity: (i) there is unauthorised access to, or unauthorised disclosure of, the information; (ii) a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates; or (b) both of the following conditions are satisfied in relation to information held by an entity: (i) the information is lost in circumstances where unauthorised access to, or unauthorised disclosure of, the information is likely to occur; (ii) assuming that unauthorised access to, or unauthorised disclosure of, the information were to occur, a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates.”

— Privacy Act 1988 (Cth), s 26WE(2)

If GO is aware that there are reasonable grounds to suspect that there may have been an eligible data breach, but is not aware of reasonable grounds to believe that the relevant circumstances amount to an eligible data breach, GO must carry out an assessment in accordance with section 26WH:

“26WH(2) The entity must: (a) carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe that the relevant circumstances amount to an eligible data breach of the entity; and (b) take all reasonable steps to ensure that the assessment is completed within 30 days after the entity becomes aware as mentioned in paragraph (1)(a).”

— Privacy Act 1988 (Cth), s 26WH(2)

The Office of the Australian Information Commissioner has stated that thirty (30) days is a maximum and that entities should endeavour to complete the assessment in a shorter timeframe.13 The GO operational standard, as recorded in the GO Notifiable Data Breaches Procedure (GO-PRI-005), is to complete the assessment within seven (7) calendar days of awareness, with the 30-day statutory maximum reserved for cases of genuine complexity.

If GO is aware that there are reasonable grounds to believe that there has been an eligible data breach, GO must prepare a statement in accordance with section 26WK:

“26WK(3) The statement must set out: (a) the identity and contact details of the entity; and (b) a description of the eligible data breach that the entity has reasonable grounds to believe has happened; and (c) the kind or kinds of information concerned; and (d) recommendations about the steps that individuals should take in response to the eligible data breach.”

— Privacy Act 1988 (Cth), s 26WK(3)

GO must then give a copy of the statement to the Commissioner as soon as practicable, and take steps to notify the contents of the statement to the individuals to whom the relevant information relates, in accordance with section 26WL.14

The procedural detail of GO's eligible-data-breach response — including triage, escalation, sub-processor coordination, communications with affected individuals, regulator notification, and post-incident review — is contained in the GO Notifiable Data Breaches Procedure (GO-PRI-005) and the GO Cyber Incident Response Plan (GO-SEC-009).

4.19 Automated decision-making and artificial intelligence

GO's position is that no decision affecting the rights or interests of an individual is made solely by, or substantially and directly by, the operation of a computer program. This position is non-negotiable and is reflected in two of GO's five hard rules: “GO never approves” and “AI never decides”.

From 10 December 2026, new Australian Privacy Principles 1.7, 1.8, and 1.9 require an APP entity that uses a computer program to make decisions affecting the rights or interests of an individual to set out, in the entity's privacy policy, the kinds of personal information used, the kinds of decisions made solely by the operation of computer programs, and the kinds of decisions for which a thing substantially and directly related to making the decision is done by the operation of a computer program.7 Because GO does not make and will not make automated decisions of the kind described in APP 1.8, the information that APP 1.8 would otherwise require to be set out in this Policy is the negative position that GO does not engage in such conduct. This Policy will be amended to address the APP 1.7 to APP 1.9 obligations in detail prior to the 10 December 2026 commencement date.

Where artificial-intelligence inference is used in the Platform (for example, to assist the Coach in drafting a coach-to-parent voice-note transcript), the artificial-intelligence output is advisory only, is moderated, and is the subject of a human acceptance step (by the Coach) before any consequential action is taken. The two-layer moderation pipeline and the dual-gate wellness escalation rule operate as substantive safeguards against any drift toward automated decision-making, and are described in the GO AI Governance Policy (GO-AI-001).

4.20 Serious invasion of privacy (statutory tort)

From 10 June 2025, a person who is the subject of a serious invasion of their privacy has a statutory cause of action under Schedule 2 of the Privacy Act 1988 (Cth).15 The cause of action is set out in clause 7 of Schedule 2 and arises where: (a) the defendant invaded the plaintiff's privacy by intruding on the plaintiff's seclusion, by misusing information that relates to the plaintiff, or by both; (b) a person in the plaintiff's position would have had a reasonable expectation of privacy in all of the circumstances; (c) the invasion of privacy was intentional or reckless; (d) the invasion of privacy was serious; and (e) the public interest in the plaintiff's privacy outweighs any countervailing public interest.

Where the plaintiff was under 18 years of age when the invasion of privacy occurred, proceedings must be commenced before the plaintiff's 21st birthday.16 The maximum exposure period in respect of an invasion of privacy concerning a Gymnast aged 6 (the youngest age in GO's target demographic) is therefore approximately fifteen (15) years. The Compliance & Risk Manager records this exposure as a material liability factor in the GO Risk Register (GO-RIS-001).

GO's position is that the Platform's architecture — including the absence of any direct coach-to-gymnast messaging channel, the cryptographic segregation of Parent and Gymnast tiles, the absence of free-text input by Gymnasts, the dual-gate wellness escalation rule, and the role-based access controls on safeguarding-related personal information — is designed to make it very unlikely that any act of GO or of a Coach or Club administrator acting through the Platform would constitute a serious invasion of privacy. GO will defend any proceeding to the contrary, will indemnify Coaches and Club administrators on the terms recorded in their respective agreements, and maintains insurance against this liability.

4.21 Complaints about a breach of this Policy

An individual who considers that GO has acted in a manner that interferes with the privacy of the individual, or has breached this Policy or any Australian Privacy Principle, may make a complaint as follows:

Step 1 — complain to GO

The complaint may be made by email to the Compliance & Risk Manager at the contact address published on the Gymnastics Online website, or by any other reasonable means. GO will acknowledge receipt of a complaint within five (5) business days. GO will investigate the complaint and respond substantively within thirty (30) calendar days of receipt. The response will set out GO's findings, any remedy that GO is willing to provide, and a clear statement of the complainant's next available step if dissatisfied.

Step 2 — escalate to the Office of the Australian Information Commissioner

A complainant who is dissatisfied with GO's response, or who does not receive a substantive response within thirty (30) days, may make a complaint to the Office of the Australian Information Commissioner under section 36 of the Privacy Act 1988 (Cth). Information about how to complain to the OAIC is published at https://www.oaic.gov.au/privacy/privacy-complaints.

Civil penalty consequences for a serious or repeated interference with privacy are set out in section 13G of the Privacy Act 1988 (Cth).17 GO records the maximum statutory penalties against a body corporate (currently up to the greater of A$50,000,000, three times the value of any benefit obtained from the conduct, or 30% of adjusted turnover during the breach turnover period) as a material liability factor.

The contact details for the Office of the Australian Information Commissioner are:

  • Telephone: 1300 363 992 (Monday to Thursday, 10am to 4pm AEST/AEDT)
  • Website: https://www.oaic.gov.au/contact-us
  • Mail: GPO Box 5288, Sydney NSW 2001

5. Roles and responsibilities

The persons within Coachy Ventures Pty Ltd t/a Gymnastics Online with responsibility for the matters addressed in this Policy are identified below. Detailed RACI mapping for each procedural step is recorded in the GO Privacy Procedure (GO-PRI-003).

Managing DirectorExecutive sponsor of this Policy. Accountable to the Board for GO's overall privacy posture. Authorising signatory for material changes to this Policy. Decision-maker of last resort for an eligible-data-breach notification and for a refusal of access or correction on safeguarding grounds.
Operations & Systems ManagerAccountable for the technical implementation of the information-security control set described in Section 4.11. Accountable for the operation of the Platform's pseudonymisation, encryption, retention, and destruction controls. Operational owner of the sub-processor onboarding workflow.
Compliance & Risk ManagerDocument owner of this Policy. Accountable for: maintaining the Sensitive Records Register; receiving and triaging complaints under Section 4.21; conducting privacy impact assessments; assessing suspected eligible data breaches under section 26WH; coordinating with sub-processors; preparing the statement required by section 26WK; coordinating regulator and broker liaison; maintaining the Risk Register entry for the statutory tort exposure described in Section 4.20.

Head Coach (Crystal Yeo, YEOCO Pty Ltd)

Content quality and clinical-safety sign-off. Maintains the chain of accountability for the content of the senior-coach-reviewed library and is identified to users in accordance with APP 5.2.

Build vendor lead (Launch Assembly)

Accountable for delivery of the Platform's technical privacy architecture to the specification described in this Policy and supporting documents.

Coaches and Club administrators

Bound by this Policy in respect of their use of the Platform and any personal information of a Parent, Gymnast, or other user of the Platform that comes into their possession or control by reason of their role.

Parents

Custodial decision-maker for their Gymnast(s). Provides verifiable consent on behalf of a minor Gymnast where required. May exercise rights of access, correction, complaint, and (where applicable) erasure on behalf of a minor Gymnast.

Sub-processors

Bound by a data-processing addendum that incorporates the obligations summarised in Section 4.17 and the law of the jurisdiction in which the sub-processor processes personal information.

Board of Coachy Ventures Pty Ltd

Endorses this Policy and reviews privacy-compliance attestation on an annual basis (or more often where a notifiable matter so requires). Approves the GO Risk Register.

6. Procedure

The day-to-day implementation of this Policy is governed by the GO Privacy Procedure (GO-PRI-003) and the supporting procedures listed in Section 9.4. Where any inconsistency arises between this Policy and a procedure, this Policy prevails until the procedure is amended.

7. Records and evidence

GO maintains the following records in connection with this Policy:

  • the Sensitive Records Register (GO-PRI-002), as the authoritative inventory of personal information held by GO;
  • the Consent Register (GO-PRI-010), recording each consent provided by a Parent, a Gymnast, a Coach, and a Club administrator, including the date, the version of the relevant consent statement, and the manner of capture;
  • the Subject Access and Correction Register (GO-PRI-011), recording every request received, the date received, the identity verification step, the response date, the response substance, and any extension granted;

the Data Breach Register (GO-PRI-012), recording every suspected and actual data breach, the assessment outcome, the statement prepared (if any), the date of notification to the Commissioner and to affected individuals, and the remedial action taken;

the Outsourced Technology Provider Register (GO-VEN-001), recording every sub-processor, the data-processing addendum reference, the country in which processing occurs, and the date of the most recent insurance certificate; and

the Privacy Impact Assessment Register (GO-PRI-013), recording every privacy impact assessment conducted, the assessor, the date, the determination, and the documents reviewed.

8. Breach and non-compliance

A breach of this Policy by a GO employee, officer, or contractor may result in: (a) for employees and officers — disciplinary action up to and including termination of employment, in accordance with the GO Code of Conduct and the applicable employment instrument; (b) for contractors — termination of the contract in accordance with its terms; and (c) for any person — referral to law-enforcement authorities where the breach involves conduct that may amount to a criminal offence.

A breach of this Policy by a Coach or Club administrator may result in suspension or termination of access to the Platform, notification of the relevant gymnastics federation, and (in the case of conduct concerning a Gymnast) referral to the Office of the eSafety Commissioner, the relevant state child-protection authority, or both, in accordance with the GO Mandatory Reporting Procedure (GO-SAF-004).

Nothing in this Section limits any right that GO has under contract, statute, or general law to seek damages or other relief in respect of a breach of this Policy.

9. References and authority

9.1 Statutes and regulations

Australia

Privacy Act 1988 (Cth) (in force) — including Schedule 1 (Australian Privacy Principles), Part IIIC (Notifiable Data Breaches scheme), and Schedule 2 (Statutory tort for serious invasions of privacy)

Privacy and Other Legislation Amendment Act 2024 (Cth) (partly in force; Part 15 commences 10 December 2026)

Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth) (in force)

Privacy Regulation 2013 (Cth) (in force)

Spam Act 2003 (Cth) (in force)

Do Not Call Register Act 2006 (Cth) (in force)

My Health Records Act 2012 (Cth) (in force; referenced for completeness only)

Online Safety Act 2021 (Cth) (in force)

Telecommunications (Interception and Access) Act 1979 (Cth) (in force; referenced for completeness only)

Australian Children's Online Privacy Code — exposure draft released by the OAIC on 31 March 2026 (consultation; closes 5 June 2026)

New Zealand — see Annex B.

Canada — see Annex C.

United States of America — see Annex D.

United Kingdom — see Annex E.

9.2 Regulator guidance and codes

Office of the Australian Information Commissioner — Australian Privacy Principles guidelines (Chapters 1 to 13)

Office of the Australian Information Commissioner — Notifiable Data Breaches scheme guidance (Parts 1 to 5)

Office of the Australian Information Commissioner — Privacy Impact Assessment guide

Office of the eSafety Commissioner — Basic Online Safety Expectations Determination (Cth)

Sport Integrity Australia — National Integrity Framework

9.3 Standards and frameworks

ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements

ISO/IEC 27701:2019 — Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management

ISO/IEC 27018:2019 — Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors

ISO/IEC 42001:2023 — Artificial intelligence — Management system

Australian Government — Voluntary AI Safety Standard (Department of Industry, Science and Resources, September 2024)

Australian Government — Australia's AI Ethics Principles (Department of Industry, Science and Resources)

National Principles for Child Safe Organisations (Australian Human Rights Commission)

United Nations Committee on the Rights of the Child — General Comment No. 25 (2021) on children's rights in relation to the digital environment

9.4 Related GO documents

GO Privacy Procedure (GO-PRI-003) — the companion procedure to this Policy

GO Sensitive Records Register (GO-PRI-002)

GO Children's Online Privacy Procedure (GO-PRI-004)

GO Notifiable Data Breaches Procedure (GO-PRI-005)

GO Data Retention and Destruction Policy (GO-PRI-006)

GO Consent Management Procedure (GO-PRI-007)

GO Subject Access and Correction Request Procedure (GO-PRI-008)

GO International Data Transfer Procedure (GO-PRI-009)

GO Privacy Impact Assessment Register (GO-PRI-013)

GO Information Security Policy (GO-SEC-001)

GO Cyber Incident Response Plan (GO-SEC-009)

GO AI Governance Policy (GO-AI-001)

GO SaMD Scope Statement (GO-AI-008)

GO Outsourced Technology Provider Register (GO-VEN-001)

GO Mandatory Reporting Procedure (GO-SAF-004)

GO Code of Conduct (GO-GOV-001)

GO Risk Register (GO-RIS-001)

10. Review and continuous improvement

This Policy is owned by the Compliance & Risk Manager and is reviewed at the cadence stated in the Document Control section. Material changes to this Policy take effect only after approval by the Managing Director and endorsement by the Board, and are recorded in the Version History table on page 2.

Feedback on this Policy may be directed to the Compliance & Risk Manager at the contact address published on the Gymnastics Online website. GO welcomes feedback from regulators, advisers, insurers, partners, users, and members of the public.

11. Annexes

Annex A — Australia

The Australian privacy law position is set out in the body of this Policy. No separate Annex content is required for Australia.

Annex B — New Zealand

Where the Platform collects personal information from an individual in New Zealand, the Privacy Act 2020 (NZ) applies. The 13 Information Privacy Principles are set out in Part 3 of that Act.18 In respect of health information about an identifiable individual, the Health Information Privacy Code 2020, issued by the Privacy Commissioner under section 32 of the Act, modifies the IPPs and supplies 13 health-information-specific rules.

GO's position in respect of personal information of an individual in New Zealand is to comply with each of the IPPs and (where applicable) with each of the rules of the Health Information Privacy Code 2020. The substantive obligations imposed by the Privacy Act 2020 (NZ) are substantially similar to those imposed by the Privacy Act 1988 (Cth) and the GO architecture described in the body of this Policy is designed to meet the more stringent of the two standards in each case.

In particular:

  • IPP 6 (access to personal information) and IPP 7 (correction of personal information) are operationalised by the GO Subject Access and Correction Request Procedure (GO-PRI-008);

IPP 11 (limits on disclosure of personal information) and IPP 12 (disclosure outside New Zealand) are operationalised by the position stated in Section 4.7 of this Policy and the GO International Data Transfer Procedure (GO-PRI-009);

Part 6 of the Privacy Act 2020 (NZ) (notifiable privacy breaches) is operationalised by the GO Notifiable Data Breaches Procedure (GO-PRI-005); a breach that is notifiable under the New Zealand scheme is reported to the Office of the Privacy Commissioner in addition to (or in lieu of) reporting to the OAIC, depending on the jurisdictional scope of the breach;

The cross-border transfer mechanism for outbound transfers from New Zealand to Australia is recorded in the GO International Data Transfer Procedure (GO-PRI-009).

Annex C — Canada

Where the Platform collects personal information from an individual in Canada, the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (Canada) (PIPEDA) and the applicable provincial privacy law apply.19 Quebec residents are subject to Law 25, the Act to modernize legislative provisions as regards the protection of personal information, S.Q. 2021, c. 25. British Columbia residents are subject to the Personal Information Protection Act, S.B.C. 2003, c. 63. Alberta residents are subject to the Personal Information Protection Act, S.A. 2003, c. P-6.5.

GO's position in respect of personal information of an individual in Canada is to comply with the 10 fair information principles set out in Schedule 1 of PIPEDA and the additional obligations imposed by the applicable provincial law. Where Quebec residents are affected, GO will also designate a person responsible for the protection of personal information and will conduct a privacy impact assessment in respect of any cross-border transfer, in accordance with section 17 of Law 25.

Sub-processors that may process personal information of an individual in Canada are identified in the GO Outsourced Technology Provider Register (GO-VEN-001). The cross-border transfer of personal information from Canada to Australia is documented by means of a service agreement that incorporates contractual safeguards equivalent to PIPEDA's accountability principle (Principle 4.1.3 of Schedule 1).

Annex D — United States of America

Where the Platform collects personal information from an individual in the United States who is under 13 years of age, the Children's Online Privacy Protection Act of 1998, 15 U.S.C. §§ 6501–6506 (COPPA) and the rule promulgated thereunder by the Federal Trade Commission at 16 C.F.R. Part 312 apply. The amended COPPA Rule, published at 90 Fed. Reg. 16,936 on 22 April 2025, classifies voiceprints as “personal information” and imposes additional written-information-security-program and data-retention-policy requirements that take effect on 22 April 2026.20

GO's position is:

  • a Gymnast located in the United States must be aged 13 or older to access the Platform; a hard age-gate is applied at login;
  • GO does not knowingly collect personal information of a child under 13 in the United States; where GO becomes aware of such collection, the personal information is destroyed within seven (7) calendar days;

voice audio is processed in Australia and destroyed within 72 hours of transcript acceptance, in accordance with Section 4.16 of this Policy. The amended COPPA Rule's voiceprint provisions are therefore not engaged on the merits;

the written information security program and the written data retention policy required by the amended COPPA Rule are evidenced by the GO Information Security Policy (GO-SEC-001) and the GO Data Retention and Destruction Policy (GO-PRI-006);

the kidSAFE+ Safe Harbor program is the subject of a planned two-stage application: a pre-launch COPPA compliance review followed by a post-launch Safe Harbor application.

Where state-level law imposes additional obligations on the Platform — including without limitation the Maryland Age-Appropriate Design Code Act, the New York Stop Addictive Feeds Exploitation for Kids Act (SAFE for Kids Act), the California Age-Appropriate Design Code Act (subject to ongoing constitutional litigation), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Code §§ 1798.100 et seq.), and the children's-data provisions of the privacy statutes of other states (Colorado, Connecticut, Virginia, Utah, and others) — GO will comply with the additional obligations applicable in respect of users located in the relevant state. The state-level position is recorded in the GO US State Privacy Compliance Matrix (GO-PRI-014).

Annex E — United Kingdom

Where the Platform collects personal data from an individual in the United Kingdom, the UK GDPR and the Data Protection Act 2018 (UK) apply. The Information Commissioner's Office's Age Appropriate Design Code (“Children's Code”) issued under section 123 of the Data Protection Act 2018 (UK) applies to information society services likely to be accessed by children.21

Article 5 of the UK GDPR sets out the seven principles relating to processing of personal data:

“Article 5 — Principles relating to processing of personal data — (1) Personal data shall be: (a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’); (b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes (‘purpose limitation’); (c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’); (d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’); (e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (‘storage limitation’); (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’). (2) The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).”

— Regulation (EU) 2016/679, as retained in UK domestic law (UK GDPR), Article 5

GO's position in respect of personal data of an individual in the United Kingdom is:

  • GO will identify a lawful basis for each processing activity under Article 6 of the UK GDPR (and, in respect of any special category data, under Article 9);
  • the Children's Code's 15 standards are operationalised in the GO Children's Online Privacy Procedure (GO-PRI-004);

Cross-border transfer from the United Kingdom to Australia (which is not an “adequate” jurisdiction for the purposes of Articles 44 to 50 of the UK GDPR) is subject to the International Data Transfer Agreement issued by the Information Commissioner's Office, or to the International Data Transfer Addendum read with the European Commission's Standard Contractual Clauses, in each case supplemented by a Transfer Impact Assessment;

a representative under Article 27 of the UK GDPR is to be appointed (DataRep or equivalent) prior to launch of the Platform in the United Kingdom; the appointment is recorded in the GO Outsourced Technology Provider Register (GO-VEN-001);

a personal data breach that is notifiable under Article 33 of the UK GDPR is notified to the Information Commissioner's Office within 72 hours of GO becoming aware of the breach, in accordance with the GO Notifiable Data Breaches Procedure (GO-PRI-005).

Where the United Kingdom Information Commissioner's Office issues a binding interpretive guidance that differs materially from any position taken in this Policy, this Policy is amended to align with the guidance.

References

  1. Privacy Act 1988 (Cth), section 6(1) — definition of ‘personal information’.
  2. Privacy Act 1988 (Cth), section 6(1) — definition of ‘sensitive information’. Sensitive information attracts the more stringent collection conditions in APP 3.3 and the additional consent requirement in APP 7.4.
  3. Privacy Act 1988 (Cth), section 6FA. Note: ‘health information’ is a category of ‘sensitive information’ within the meaning of section 6(1).
  4. Privacy Act 1988 (Cth), section 6C(1). The small business operator exemption in section 6D does not apply where the entity provides a health service and holds health information (section 6D(4)(b)) or where the entity trades in personal information (section 6D(4)(c)). The Coachy Ventures Pty Ltd position is that the small business exemption is not available regardless of turnover and the entity is therefore an APP entity in full.
  5. Privacy Act 1988 (Cth), Part IIIC — ‘Notification of eligible data breaches’ — Divisions 1 to 5 (sections 26WA to 26XB). The Notifiable Data Breaches scheme is administered by the Office of the Australian Information Commissioner: https://www.oaic.gov.au/privacy/notifiable-data-breaches.
  6. Privacy Act 1988 (Cth), Schedule 1, ‘Australian Privacy Principles’. Authoritative text published by the Office of the Australian Information Commissioner at https://www.oaic.gov.au/privacy/australian-privacy-principles/read-the-australian-privacy-principles. Current compilation of the Act available at https://www.legislation.gov.au/C2004A03712/latest.
  7. Privacy and Other Legislation Amendment Act 2024 (Cth), Schedule 1, Part 15 — ‘Automated decisions and privacy policies’. New APP 1.7, APP 1.8 and APP 1.9 commence on 10 December 2026 and impose additional privacy policy obligations in respect of decisions made solely, or substantially and directly, by the operation of a computer program. See OAIC, ‘Chapter 1: APP 1’, https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information.
  8. Spam Act 2003 (Cth); Do Not Call Register Act 2006 (Cth). APP 7.8 expressly provides that APP 7 does not apply to the extent that these Acts apply.
  9. Privacy Act 1988 (Cth), section 16C. Where an APP entity discloses personal information to an overseas recipient and APP 8.1 applies, an act done or practice engaged in by the overseas recipient that would (if engaged in by the entity) breach the APPs is taken to be a breach by the disclosing entity.
  10. Office of the Australian Information Commissioner, ‘Chapter 11: APP 11 Security of personal information’, Australian Privacy Principles guidelines. ‘Reasonable steps’ is assessed in the circumstances; for an organisation that holds health information about minors, the OAIC’s position is that the standard is elevated. See https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines.
  11. Australian Clinical Labs Limited v Australian Information Commissioner [2025] FCA 1224. The Federal Court found that Australian Clinical Labs Limited had contravened APP 11.1(b) by failing to take reasonable steps to protect personal information, and section 26WH by failing to carry out a reasonable and expeditious assessment. The Court ordered civil penalties totalling A$5.8 million on 30 October 2025.
  12. Office of the Australian Information Commissioner, ‘Children’s Online Privacy Code — exposure draft’, 31 March 2026. Public consultation closes 5 June 2026. Registration of a Code under section 26GC of the Privacy Act 1988 (Cth) is anticipated, with a likely registration deadline of 10 December 2026. Status: consultation. See https://www.oaic.gov.au/engage-with-us/consultations.
  13. Privacy Act 1988 (Cth), section 26WH(2)(b). The OAIC has stated that 30 days is a maximum and entities should ‘endeavour to complete the assessment in a much shorter timeframe, as the risk of serious harm to individuals often increases with time’: OAIC, ‘Part 4: Notifiable Data Breach (NDB) Scheme’, Data breach preparation and response.
  14. Privacy Act 1988 (Cth), section 26WK(3). The statement must contain the identity and contact details of the entity, a description of the eligible data breach, the kinds of information concerned, and recommendations about the steps that individuals should take in response.
  15. Privacy Act 1988 (Cth), Schedule 2, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth). Schedule 2 commenced on 10 June 2025 and establishes a statutory cause of action for serious invasions of privacy. The cause of action is set out in clause 7 of Schedule 2.
  16. Privacy Act 1988 (Cth), Schedule 2, clause 14(3). Where the plaintiff was under 18 years of age when the invasion of privacy occurred, the limitation period extends until the plaintiff’s 21st birthday. This extends the maximum exposure period for an invasion of privacy concerning a child aged 6 (the youngest age in GO’s target demographic) to approximately 15 years.
  17. Privacy Act 1988 (Cth), section 13 and section 13G. Civil penalties for serious or repeated interferences with privacy are set in section 13G. Maximum penalties for body corporates were substantially increased by the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth) and may reach the greater of A$50,000,000, three times the value of any benefit obtained, or 30% of adjusted turnover during the breach turnover period.
  18. Privacy Act 2020 (NZ), section 22 and Schedule 1 (Information Privacy Principles 1–13). The Health Information Privacy Code 2020, made under section 32 of the Act, applies to health agencies and modifies the IPPs by 13 health-information-specific rules.
  19. Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (Canada). Schedule 1 contains the 10 fair information principles. Provincial laws — Personal Information Protection Act, S.B.C. 2003, c. 63 (British Columbia); Personal Information Protection Act, S.A. 2003, c. P-6.5 (Alberta); Loi 25 / Act to modernize legislative provisions as regards the protection of personal information, S.Q. 2021, c. 25 (Quebec) — apply where deemed substantially similar.
  20. Children's Online Privacy Protection Rule, 16 C.F.R. Part 312, as amended by the Federal Trade Commission's recent final rule (the “amended COPPA Rule”). Statutory authority: Children's Online Privacy Protection Act of 1998, 15 U.S.C. §§ 6501–6506. The amended Rule classifies voiceprints as “personal information” and imposes additional written-information-security-program and written-data-retention-policy obligations. Specific Federal Register publication details and the effective and compliance dates should be confirmed against the current 16 C.F.R. Part 312 text at the time this Policy is finalised. The working in-force date for the additional obligations relevant to GO is 22 April 2026.
  21. Regulation (EU) 2016/679, as retained in domestic law by the European Union (Withdrawal) Act 2018 (UK), as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019/419 (UK) — the ‘UK GDPR’. Read together with the Data Protection Act 2018 (UK), the Privacy and Electronic Communications (EC Directive) Regulations 2003 (UK), and the Information Commissioner’s Office Age Appropriate Design Code (‘Children’s Code’) issued under section 123 of the Data Protection Act 2018 (UK).

AdBlock

REGISTER YOUR INTERST TODAY!
We’re excited to connect! Fill in this form to register your club’s interest in working with Gymnastics Online. A team member will follow up with more information shortly.
Contact Details:
Club Details:
Marketing by

AdBlock

REGISTER YOUR INTERST TODAY!
Looking to support your gymnast’s training at home? Fill out this quick form to register your interest in Gymnastics Online. Our friendly team will follow up soon with details and next steps.
Contact Details:
Marketing by

AdBlock

REGISTER YOUR INTERST TODAY!
Thinking about joining Gymnastics Online? Complete this quick form to register your interest — our friendly team will follow up soon to answer your questions and help you get started.
Contact Details:
Marketing by