Privacy Policy
This policy explains how personal information is handled by Hellspinbonus Meridian Studio in Australia and, where applicable, under the GDPR. Effective date: 5 August 2026.
1. Scope and governing framework
This Privacy Policy explains how Hellspinbonus Meridian Studio Pty Ltd collects, uses, stores, discloses and protects personal information when you visit this website, contact us, submit an inquiry, apply for membership, attend the venue, participate in an event or otherwise interact with our services.
We are established in Australia and aim to comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles and the Notifiable Data Breaches scheme. Where the General Data Protection Regulation applies to a person in the European Economic Area or United Kingdom, we also process personal data in accordance with applicable GDPR principles and rights. If a mandatory law gives you stronger rights than this Policy, that law prevails.
2. Privacy administrator and contact
Hellspinbonus Meridian Studio Pty Ltd is the organisation responsible for the personal information described in this Policy. Our principal contact address is 17 Marr Street, Dandenong VIC 3175, Australia. General privacy inquiries may be sent to the email address displayed on the Contact & FAQ page.
We do not appoint an external data protection officer unless applicable law requires one. Privacy requests are handled by an authorised member of our management team and are escalated where necessary.
3. Information we may collect
Depending on your interaction with us, we may collect identity and contact information, membership and booking details, communications, event registrations, preferences, accessibility requirements voluntarily provided by you, payment and transaction references supplied by payment providers, technical device and browser information, security logs, approximate location derived from an IP address, and records required for venue safety or dispute resolution.
We seek to avoid collecting sensitive information unless it is reasonably necessary, lawful and provided with appropriate consent or another legal basis. Please do not submit health, biometric, government identifier or other sensitive information through a general contact form unless we specifically request it for a legitimate purpose.
4. How information is collected
Information may be collected directly from you through forms, membership inquiries, event registrations, venue check-in, correspondence and customer support. We may also receive limited information from service providers that help us operate bookings, payments, security, analytics or communications, subject to appropriate contractual controls.
This website is designed to operate without externally hosted scripts, fonts, images or map embeds. The inquiry forms included in this local project store submitted entries only in the visitor’s browser storage and do not transmit them to us unless a production operator later connects a disclosed backend service.
5. Purposes of processing
We use personal information to provide and administer services; answer inquiries; manage memberships, bookings, events and venue access; communicate operational information; maintain safety and security; prevent fraud and misuse; improve accessibility and service quality; keep business and tax records; enforce agreements; and comply with legal obligations.
We do not sell personal information. We do not use personal information for unrelated direct marketing without an appropriate legal basis and a practical way to opt out.
6. Legal bases under GDPR
Where GDPR applies, processing may be based on performance of a contract or steps requested before entering a contract, compliance with a legal obligation, our legitimate interests in operating a secure and effective venue and website, protection of vital interests in an emergency, or consent where consent is the appropriate basis.
When we rely on legitimate interests, we consider the necessity of the processing and balance our interests against the rights and reasonable expectations of the individual. Consent may be withdrawn at any time, but withdrawal does not affect processing that was lawful before withdrawal.
7. Cookies and local storage
The current website does not require advertising cookies or third-party tracking pixels. It may use strictly necessary browser storage for interface functions, accessibility preferences and locally saved form entries. Further details are provided in the Cookie Policy.
If analytics, marketing or additional preference technologies are introduced in a production version, they must be documented and, where legally required, activated only after valid consent.
8. Disclosure and service providers
We may disclose information to professional advisers, technology and hosting providers, payment processors, security providers, event partners, insurers, regulators, courts or law-enforcement bodies when reasonably necessary and lawful. Providers may use information only for agreed services and must protect it appropriately.
We may also disclose information during a genuine corporate transaction such as a merger, restructuring or asset transfer, subject to confidentiality and applicable law.
9. Overseas transfers
Some service providers may process information outside Australia. Before using such providers, we assess the destination, contractual safeguards, security measures and legal requirements. Where GDPR applies, international transfers must use an approved transfer mechanism, adequacy decision or another lawful safeguard.
No transfer mechanism can eliminate all risk. We select providers proportionately and limit transferred data to what is reasonably necessary.
10. Retention and deletion
We retain personal information only for as long as reasonably necessary for the purpose collected, including legal, accounting, safety, insurance and dispute-resolution requirements. Retention periods depend on the type of record and the applicable obligation.
When information is no longer required, we take reasonable steps to delete, destroy or de-identify it. Backup copies may remain for a limited period until securely overwritten under normal system cycles.
11. Security measures and data breaches
We use reasonable administrative, physical and technical safeguards, including access controls, least-privilege practices, secure configuration, staff awareness, backups and incident response procedures. No method of storage or transmission is completely secure, so absolute security cannot be guaranteed.
If an eligible data breach is likely to result in serious harm, we will assess the incident and notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. Where GDPR applies, we will also meet applicable supervisory-authority and individual notification duties.
12. Access, correction and GDPR rights
You may request access to personal information we hold about you and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We may need to verify identity before acting and may refuse or limit a request only where permitted by law, with reasons where required.
Where GDPR applies, you may also have rights to erasure, restriction, objection, data portability, withdrawal of consent and protection against decisions based solely on automated processing that produce legal or similarly significant effects. These rights are subject to statutory conditions and exemptions.
13. Children and young people
Our venue may be open to young people under appropriate supervision and venue rules. We do not knowingly collect more information about a child than is reasonably necessary. Where consent is legally required from a parent or guardian, we will seek that consent before the relevant processing.
Parents or guardians who believe a child has provided personal information inappropriately should contact us so we can investigate and take suitable action.
14. Automated decisions and profiling
The current website does not make decisions based solely on automated processing that produce legal or similarly significant effects. We do not use hidden behavioural advertising profiles in this local build.
If future production services introduce materially significant automated decision-making, this Policy will be updated before the relevant processing begins and affected individuals will receive required information about the logic, consequences and available review rights.
15. Complaints and regulatory contacts
Please contact us first if you have a privacy concern. We will acknowledge and investigate complaints fairly, seek relevant information and provide a response within a reasonable period.
If you are not satisfied, you may be entitled to contact the Office of the Australian Information Commissioner or, where GDPR applies, the supervisory authority in the country of your habitual residence, workplace or alleged infringement.
16. Changes to this Policy
We may update this Policy when practices, services or legal requirements change. The latest version will be published on this page with a revised effective date. Material changes may also be highlighted through an appropriate notice.
This Policy is effective from 5 August 2026.