Legal
Privacy Policy
Last updated: 30 July 2026
Members Request Desk is operated by NEMO Australia Pty Ltd (ABN 60 631 429 055), 39 River Oak Circuit, Kellyville NSW 2155, Australia (“we”, “us”). We provide automated membership suspension request tools for businesses using Mindbody. This policy explains how we handle personal information, in line with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and — where it applies — the EU/UK GDPR.
Our two roles
When a member submits a request, the Mindbody business decides why and how the data is used (the controller); we handle it on that business's instructions to carry out the suspension (the processor). Please also read your business's own privacy policy. For our own website and account data — business staff accounts and website visitors — we decide how it is used, so we are the controller.
What we collect
We deliberately keep our data footprint minimal. From a member submitting a suspension request:
- Name, email and phone — used only to match the member to their Mindbody record.
- The Mindbody client and contract IDs we match to.
- Suspension details: requested start, duration, and a reason category only (non-medical / medical / staff).
- A record that consent was given (timestamp + policy version), and technical data (IP, device) for security.
We do not collect date of birth unless a business's documented matching rule specifically requires it; where it is requested, it is used only to confirm identity and kept no longer than needed.
We may collect a reason category that says medical, but we do not collect diagnoses, certificates or other health details. Medical evidence is handled directly by the business. We also neverhandle payment card details (any suspension fee is processed by the business's own Mindbody merchant account).
Why we use it — purpose and lawful basis
Under the GDPR, purpose and lawful basis are separate questions. Where the GDPR applies, we rely on the bases below; we use consent only where it is genuinely the correct basis.
| Data | Purpose | Lawful basis (GDPR) | Recipients | Retention |
|---|---|---|---|---|
| Name, email, phone, Mindbody IDs | Verify identity and carry out the requested suspension | Contract / legitimate interests | Mindbody, the business | De-identified 24 months after the request closes |
| Verification codes | Confirm it is really the member | Legitimate interests (security) | Twilio (SMS), Resend (email) | Single-use; purged within 30 days |
| Consent record + technical data (IP, device) | Audit, dispute resolution, security | Legal obligation / legitimate interests | Supabase, Vercel | De-identified with the request |
| Business account & billing data | Provide and bill the service | Contract | Stripe | 5 years (Australian tax law) |
We currently use no analytics or marketing cookies; if we ever introduce them, they will be consent-based where consent is legally required (see our Cookie Policy).
Who we share it with
We use trusted providers to run the service and do not sell personal information:
- Supabase — database & authentication (Sydney, Australia)
- Vercel — website & application hosting (global edge; US region)
- Twilio — SMS delivery (United States)
- Resend — email (United States)
- Stripe — business billing (United States / global)
- Mindbody — the business's own system we integrate with (United States)
This list matches the subprocessor table published in our Trust Centre, which shows each provider's purpose, the data involved and its processing location; we will update both and notify customers before adding a new provider.
Cross-border disclosure
Our primary database is hosted in Australia (Sydney). Some providers process limited data overseas — their confirmed countries and the data involved are listed in the subprocessor table above and in our Trust Centre. Where information is disclosed overseas we take reasonable steps to ensure it is handled consistently with the APPs, and rely on appropriate safeguards (such as Standard Contractual Clauses) for GDPR transfers. The Trust Centre and this policy describe the same data flow.
Storage & security
Business Mindbody credentials are AES-256-GCM encrypted at rest and only decryptable server-side. Records are separated per business with row-level access controls. Secrets are never committed to source control or written to logs, and access is limited to authorised personnel. No system is perfectly secure, but we take reasonable steps to protect personal information.
Retention
We keep personal information only as long as it is needed, and enforce that automatically rather than by promise alone:
- Verification codes are stored only as one-way hashes, expire within minutes, and are purged within 30 days.
- Closed suspension requests are automatically de-identified 24 months after they close — the personal fields are removed while non-identifying operational records are kept for audit integrity.
- On account closure, we delete or de-identify personal data within 30 days, and revoke Mindbody access. A business can request an export before closure.
- Billing records are retained for 5 years as required by Australian tax law.
- Backups are encrypted; deleted data ages out of backups on our provider's standard rotation.
Data breach notification
If a data breach occurs that is likely to result in serious harm, we will notify affected businesses and the Office of the Australian Information Commissioner in accordance with Australia's Notifiable Data Breaches scheme, and — where the GDPR applies — the relevant supervisory authority and affected individuals without undue delay. As a processor, we will notify the affected business (the controller) promptly so it can meet its own obligations.
Children
The Service is intended for business staff and adult members. We do not knowingly collect information from children; memberships for minors are managed by the business and the member's parent or guardian under the business's own terms.
Your rights
You may access the personal information we hold and ask us to correct it (APPs 12–13). Under the GDPR you may also request erasure, restriction or portability, or object to processing and withdraw consent. Because we act as a processor for member suspension data, such requests may be directed to your business; we will assist. For data we control, contact us below.
Complaints
In Australia, if you are unhappy with how we have handled your information, contact us first; you may then complain to the Office of the Australian Information Commissioner (oaic.gov.au). In the EU/UK you may lodge a complaint with your local supervisory authority.
Contact
NEMO Australia Pty Ltd — privacy@membersrequestdesk.com — 39 River Oak Circuit, Kellyville NSW 2155, Australia.