HYBRID WALL Back to plans →
Your information

Privacy Policy

This policy explains how JLC COMPANY PTY LTD, trading as THE HYBRID GROUP CONSULTING, manages personal information through Hybrid Wall and related business activities.

Version and effective date: 24 July 2026

The important split: your gym controls the member relationship and decides what member information is entered. THG operates and supports the platform on the gym’s instructions and handles its own billing, support and security information.

1. Who we are and when this policy applies

JLC COMPANY PTY LTD ACN 683 020 984, ABN 96 683 020 984, trading as THE HYBRID GROUP CONSULTING (THG, we, us), provides Hybrid Wall to gym businesses.

This policy applies to personal information we handle when operating the Platform, providing demos and evaluations, processing subscriptions, responding to enquiries, securing our systems and conducting our business.

A participating gym is generally responsible for deciding which member information is collected and why. Members should also read their gym’s privacy notices and contact their gym first about information the gym controls.

2. Information we collect and how we collect it

Depending on how the Platform is configured and used, we may handle:

  • business and account details such as names, email addresses, phone numbers, roles, gym details and login identifiers;
  • subscription and transaction details, while payment card information is handled by Stripe rather than stored by THG;
  • member profile and community information such as names, profile photos, posts, reactions, achievements, attendance and leaderboard entries;
  • programming and performance information such as workouts, results, personal bests, challenge entries, training history and, where a member chooses to connect Myzone, MEP totals and workout summaries;
  • photos, videos, advertising, event and other content uploaded by a gym or user;
  • support communications, setup information, feedback and correspondence; and
  • technical and security information such as device, browser, approximate network information, timestamps, authentication events, diagnostic records and usage logs.

Fitness, wellbeing or similar information may be sensitive information in some circumstances. It should be entered only where the gym has obtained any consent or other authority required by law.

Myzone connection is optional. A member’s account is matched using their login email, the email is not copied into a public leaderboard, and only an opted-in nickname is shown on the gym screen. Myzone passwords and raw heart-rate samples are not collected by the Platform. Members can hide themselves from the public board or disconnect and remove synced summaries from My Hub.

We collect information directly from customers and users, from the gym that provides or configures an account, automatically through use of the Platform, and from service providers involved in authentication, payments, forms, support or hosting.

3. Why we use information

We use personal information where reasonably necessary to:

  • provide, configure, personalise and support the Platform;
  • authenticate users, manage permissions and protect accounts;
  • publish authorised workouts, leaderboards, achievements, community content and gym displays;
  • process subscriptions, maintain business records and communicate about the service;
  • diagnose faults, improve performance, develop features and understand use;
  • detect misuse, investigate security events, prevent fraud and enforce our agreements;
  • comply with legal obligations and respond to lawful requests; and
  • send relevant product or business communications where permitted, with unsubscribe options for marketing.

We may use aggregated or de-identified information for product analytics and improvement where it no longer identifies an individual.

The Platform may calculate standings, streaks, achievements, operational prompts and similar outputs from information entered by users or gyms. These features support gym operations and engagement; they are not intended to make legal, employment, insurance, medical or other decisions that significantly affect an individual.

4. When information is shared

We may disclose information to:

  • the relevant gym, its authorised staff and users according to account permissions;
  • hosting, database, authentication, payment, email, form, analytics, support and security providers that help operate the service;
  • professional advisers, insurers and auditors where reasonably necessary;
  • a buyer or successor in connection with a genuine business restructure or sale, subject to appropriate confidentiality; and
  • regulators, courts, law enforcement or other parties where required or authorised by law, or reasonably necessary to protect rights, safety and security.

Service providers may include Netlify for web hosting, Supabase and its infrastructure providers for database, authentication and storage, Stripe for payments, Myzone where a gym and member enable that connection, and approved communication, form or support providers used for a particular workflow.

Some providers may store or process information outside Australia, including in the United States or other regions selected for the service. Locations can change as providers update their infrastructure. We take reasonable steps appropriate to our role to use reputable providers and contractual or technical safeguards.

We do not sell personal information.

5. Storage, security and retention

We use safeguards appropriate to the information and service, including access controls, separate customer environments or data controls, encrypted connections, multi-factor authentication for administrative access where available, logging, backups and restrictions on staff and service-provider access.

No internet service is completely secure. Customers and users must protect their credentials, devices and local networks and promptly report suspected unauthorised access.

We retain information only for as long as reasonably necessary for the purposes described above, the contract, security, backup cycles and legal obligations. Following subscription termination, available Customer Data may be deleted after 60 days unless a different period is agreed or retention is required. Backup and security copies are deleted through normal protected cycles.

If we confirm an eligible data breach, we will assess and respond to it and notify affected customers, individuals or regulators where required by applicable law.

6. Access, correction, choices and complaints

You may ask for access to, or correction of, personal information we hold about you. We may need to verify your identity and may refer a request to the relevant gym where it controls the information. Legal exceptions may apply, and we will explain a refusal where required.

You may opt out of marketing using the unsubscribe method in the message or by contacting us. Operational, security and service communications may still be sent while an account or subscription remains active.

To make a privacy request or complaint, contact us using the details below and explain the issue. We will acknowledge and investigate it within a reasonable period. If you are not satisfied and the Privacy Act applies, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.

This policy may be updated as the Platform, providers or legal requirements change. We will publish the current version here and provide additional notice for material changes where appropriate.

7. Contact

Privacy contact JLC COMPANY PTY LTD · ACN 683 020 984 · ABN 96 683 020 984
Trading as THE HYBRID GROUP CONSULTING · Queensland 4566
jay@thehybridgroup.co