Privacy Policy



1. Who We Are

Our website address is: https://alzi.net. This policy covers both our general website and our online personal training and nutrition coaching service.

2. The Personal Information We Collect

Depending on how you use our site, we may collect:

  • Contact details: name, email address, phone number.
  • Account details: membership level, date of birth (for age screening), how you heard about us.
  • Health and lifestyle information you provide through our Getting Started questionnaire and ongoing check-ins, including exercise readiness screening, dietary habits, and self-reported wellbeing information.
  • Payment information processed through our payment provider [insert provider, e.g. Stripe] — we do not store full card details ourselves.
  • Comments, IP address, and browser user agent string, if you leave a comment on the site (for spam detection).
  • Cookie data as described in Section 6 below.
Note for review: health/screening information is “sensitive information” under Australian Privacy Principle 3 and requires explicit consent to collect — confirm the consent checkbox wording on the intake form satisfies this before relying on it.

3. Why We Collect It

We use this information to:

  • Assess your eligibility and safety to participate in our coaching program.
  • Provide and personalise your coaching — programming, nutrition guidance, and check-ins.
  • Process payments and manage your membership.
  • Communicate with you about your account, coaching, or support requests.
  • Detect and prevent spam or misuse of the site.
  • Meet our legal and accounting obligations.

We do not use your health information for any purpose beyond delivering and safely administering your coaching, and we do not sell your personal information.

4. Comments

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymised string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service Privacy Policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

5. Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

6. Cookies

If you leave a comment on our site you may opt in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

7. Embedded Content From Other Websites

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

8. Who We Share Your Data With

If you request a password reset, your IP address will be included in the reset email.

We share personal information with the following categories of third parties, only as needed to provide our service:

  • Our hosting provider [insert, e.g. Hostinger], to store website and account data.
  • Our payment processor [insert provider], to process membership payments. We do not store your full payment card details.
  • Our form and membership platform providers (Formidable Forms, Simple WordPress Membership), used to manage your account and program data.
  • [If applicable] Our SMS/voice notification provider [e.g. Twilio], used only for account or care-related alerts you have opted into.
  • Your coach, for the purpose of delivering your program.
  • [If applicable, and only with your consent] A family or care account you choose to link your data to.

We do not share your health or screening information with any third party for marketing purposes, and we do not sell personal information.

Note for review: list every actual sub-processor/vendor here (hosting, payment, SMS, analytics, email) — this list must be accurate and complete, not illustrative.

9. How Long We Retain Your Data

If you leave a comment, the comment and its metadata are retained indefinitely, so we can recognise and approve any follow-up comments automatically instead of holding them in a moderation queue.

For registered users, we store the personal information provided in their user profile for as long as the account remains active, and for a period afterward as required for legal, accounting, or administrative purposes [insert retention period, e.g. 7 years for financial records under Australian tax law]. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

Health and screening information is retained only for as long as needed to safely deliver your coaching program and to meet our record-keeping obligations, after which it is deleted or de-identified in accordance with our data retention schedule. [Insert specific retention period.]

10. What Rights You Have Over Your Data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Under the Australian Privacy Principles, you may also request access to, or correction of, the personal information we hold about you, and you may make a complaint if you believe we have mishandled your personal information. [Insert process and contact for privacy complaints, and note the right to escalate to the Office of the Australian Information Commissioner (OAIC) if unresolved.]

11. Where Your Data Is Sent

Visitor comments may be checked through an automated spam detection service. [If any of your hosting, payment, or notification providers store or process data outside Australia, disclose this here, including which country/countries and what safeguards apply — this is a specific requirement under APP 8 for overseas disclosure.]

12. Data Security

[Insert a short description of security measures — e.g. encrypted connections (HTTPS), access controls limiting who can view health/screening data, and how payment data is handled (e.g. “we never store full card numbers; payments are processed directly by [provider]”).]

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via [email / site notice], and the “last updated” date below will reflect the most recent version.

14. Contact Us

For any questions about this Privacy Policy, or to make a data access, correction, deletion, or complaint request, contact us at [insert contact email/form].

Last updated: 2026