Privacy Policy
Last updated 22 September 2026
-
Introduction
- NEWCHURCHTEK PTY LTD (ACN 159 180 337) as trustee for C D & A VAN NIEUWKERK FAMILY TRUST (ABN 33 589 622 372), trading as You'reOnTime (we, us, our), recognises the importance of protecting the privacy and the rights of individuals in relation to their personal information.
- This privacy policy explains how we collect, hold, use and disclose personal information through:
- our website at youreontime.com (Site);
- the You'reOnTime salon, spa, barber and clinic management software, including its web, desktop and mobile applications (Platform); and
- the consumer-facing services we host on behalf of businesses that use the Platform, including online booking pages (for example at youreontime-booking.com), custom branded client apps, electronic forms, gift voucher, membership and product stores, reviews pages, self check-in, and appointment confirmation, reminder and marketing messages (together, Client Services).
- We respect your rights to privacy under the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs), and we manage personal information in accordance with those requirements, including the Notifiable Data Breaches scheme.
- If you are in the European Economic Area (EEA) or the United Kingdom, we also uphold your rights under the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR and Data Protection Act 2018 (UK GDPR). Your rights under the GDPR and UK GDPR are set out in clause 17.
- If you are in Bermuda, we also respect your rights under the Personal Information Protection Act 2016 (PIPA). Your rights under PIPA are set out in clause 18.
- You do not have to provide personal information to us. However, if you do not, we may not be able to provide the Site, the Platform or the Client Services to you, or the business you are booking with may not be able to provide its services to you.
- This privacy policy should be read together with our Terms of Service. If you are a Client (defined below), it should also be read together with the privacy policy of the business you are dealing with.
-
Who this policy applies to, and our role
- This privacy policy applies to three groups of people (each referred to as you, your):
- Customers – businesses that subscribe to the Platform, and their owners, directors, employees, contractors and other staff who are given access to the Platform;
- Clients – individuals who are customers of a Customer, and whose personal information is entered into the Platform by a Customer or who use a Customer's Client Services (for example, to book an appointment online, complete a form, buy a gift voucher or leave a review); and
- Visitors – individuals who visit our Site, contact us, subscribe to our mailing lists or otherwise interact with us without being a Customer or Client.
- Customers and Visitors. We decide how and why your personal information is processed. Under the GDPR and UK GDPR we are the "data controller" of that information.
- Clients. When you book with, buy from or otherwise deal with a Customer through the Platform or its Client Services, the Customer decides how and why your personal information is collected and used. The Customer is the "data controller" (or, under the Privacy Act, the APP entity that collects your information) and we process your personal information on the Customer's behalf and on its instructions as a "data processor". This applies whether your information was entered by the Customer or entered by you on a booking page, app or form that we host for the Customer.
- Because the Customer controls Client information:
- the Customer's own privacy policy applies to how it uses your information, including any consultation notes, photographs, health information or marketing preferences it records about you;
- the Customer is responsible for obtaining any consents required from you, and for responding to your requests to access, correct or delete your information; and
- if you contact us with a request about information held in a Customer's records, we will refer you to the Customer or pass your request on to them, and we will assist them in responding. See clause 16 for details.
- As an exception, we act as a data controller of limited Client information in our own right where we:
- operate, secure and maintain the Platform and Client Services, including detecting fraud, abuse, spam and security incidents;
- send you a one-time code by SMS or email so you can log in to a Client Service;
- respond to enquiries, complaints or data removal requests you send directly to us;
- comply with our own legal obligations; and
- produce aggregated or de-identified statistics that do not identify you.
- Our obligations to Customers in respect of Client information are set out in our Terms of Service and, for Customers subject to the GDPR or UK GDPR, our data processing terms.
- This privacy policy applies to three groups of people (each referred to as you, your):
-
What is personal information?
- When used in this privacy policy, the term "personal information" has the meaning given to it under the Privacy Act, and includes "personal data" under the GDPR and UK GDPR and "personal information" under PIPA.
- In general terms, it is any information or opinion about an identified individual, or an individual who is reasonably identifiable. This may include your name, address, telephone number, email address, date of birth, appointment history and IP address.
- "Sensitive information" (called "special category data" under the GDPR and UK GDPR) is a subset of personal information that receives extra protection. It includes health and medical information, information about racial or ethnic origin, religious beliefs, sexual orientation, and biometric information. In the context of the Platform this most commonly means health, allergy, skin, medication and pregnancy information recorded in consultation forms and client notes.
- We may also collect information that is not personal information because it does not identify you or anyone else, for example aggregated statistics about how the Site and Platform are used.
- We do not sell personal information. Your personal information will not be shared, sold, rented or disclosed other than as described in this privacy policy.
-
What personal information we collect
- Visitors. We may collect:
- your name, email address, telephone number and business name when you make an enquiry, request a demo or call, subscribe to a mailing list, register for a partner program or submit any form on the Site;
- the content of your communications with us;
- technical information about your visit, described in clause 9; and
- publicly available information about your business from websites and directory listings, for marketing and market analysis purposes.
- Customers. We may collect:
- the name, email address, telephone number, job title and login credentials of each person who accesses the Platform;
- business name, business or company numbers, billing, mailing and business addresses, and time zone;
- subscription and billing information, including bank account, credit card or other payment details, which are collected and stored by our payment processors rather than by us;
- identity documents where required to verify your business, for example when enabling payment processing;
- records of how you use the Platform, including audit logs of actions taken by each user, support requests, and feedback; and
- any information you enter into the Platform about your business, staff and Clients.
- Clients. Depending on which Client Services the Customer has enabled and how you use them, we may process on the Customer's behalf:
- your name, email address and mobile telephone number;
- your postal or residential address, date of birth and gender, where the Customer asks for them;
- details of your appointments, including the location, services, staff member, date and time, price, deposit and payment status, attendance and cancellation history, and any notes you add when booking;
- your purchase history, including gift vouchers, memberships, packages, products and loyalty points;
- answers, signatures and photographs you provide in electronic forms, including consultation, consent, intake and release forms, which may include health and other sensitive information (see clause 5.6);
- notes, photographs, service records and preferences the Customer records about you;
- emergency contact details, where the Customer asks for them;
- your communication preferences, including whether you have agreed to receive marketing from the Customer;
- messages you exchange with the Customer through the Platform, including replies to reminders;
- reviews and ratings you leave for the Customer; and
- technical information about your use of Client Services, described in clause 9.
- We only process sensitive information about Clients where the Customer has a lawful basis to collect it, which will usually be your explicit consent given to the Customer, and we only use it to provide the Platform to the Customer.
- Visitors. We may collect:
-
Online booking and other Client Services
- This clause explains what happens to your personal information when you use a Customer's online booking page, client app or other Client Service. Each Client Service is branded with the Customer's name and logo and displays "Powered by You'reOnTime" with a link to this privacy policy.
- Making a booking. When you book online you choose a location, one or more services, a staff member (or "first available") and a date and time. To complete the booking you provide your name, email address and mobile telephone number, and may add notes for the Customer. We use this information to create the appointment in the Customer's calendar, to send you confirmation and reminder messages, and to allow the Customer to contact you about the appointment. Login is not required to make a booking.
- Client login. You may log in to a Client Service to view, change or cancel your bookings and manage your details. We verify your identity by sending a one-time code to your mobile number or email address. We do not ask you to create a password for Client Services and we do not use social media logins. Your login is specific to the Customer whose Client Service you are using.
- Confirmations, reminders and two-way messaging. The Platform sends appointment confirmations, reminders, follow-ups and rebooking prompts by SMS, email and app notification on behalf of the Customer. These are service messages that form part of the booking you have requested, not marketing. You can reply to confirm, cancel or leave a message, and your reply is delivered to the Customer's inbox in the Platform. You can ask the Customer to stop sending reminders at any time, but the Customer may then require you to confirm appointments in another way.
- Online payments, deposits, vouchers, memberships and store purchases.
- A Customer may require a deposit, pre-payment or a card to be held on file when you book, and may charge cancellation or no-show fees in accordance with its own cancellation policy, which is shown to you before you book. You may also buy gift vouchers, memberships, packages and products from a Customer's online store.
- Card payments are processed by third-party payment processors integrated with the Platform, which may include Stripe, Windcave and Square, depending on the Customer's configuration. You enter your card details directly into a secure form or page provided by the payment processor. We do not receive, store or transmit your full card number, expiry date or security code. We receive and store a payment token, the card brand, the last four digits of the card, the amount, and the status of the transaction so that the Customer can reconcile payments and, where you have agreed, charge deposits or fees to your card on file.
- Payment processors act as independent data controllers of the information you give them, and their own privacy policies apply. Payment processors may also use your information to prevent fraud and comply with their legal obligations.
- When you buy a gift voucher for another person, we collect the recipient's name and email address or mobile number so that the voucher can be delivered. You confirm you have the recipient's permission to give us this information.
- Electronic forms and health information. A Customer may ask you to complete consultation, consent, intake, waiver or release forms online or on a device in the salon before or during an appointment. The questions are set by the Customer and may ask for health, allergy, medication, pregnancy and other sensitive information that the Customer needs to provide its services safely. Your answers and signature are stored against your record in the Customer's account. The Customer is the controller of this information and is responsible for obtaining your consent. We do not use form answers for any purpose of our own.
- Reviews. If you leave a review through a Client Service, the Customer may choose to publish your rating, review text, first name and the date of the review on its booking page. Reviews are not linked to your email address or telephone number when displayed. Contact the Customer if you want a review edited or removed.
- Contact forms and maps. Messages you send through a Customer's contact page are delivered to the Customer. Booking pages embed Google Maps to show the Customer's locations. Google may collect technical information about your device when a map is displayed, under Google's privacy policy.
- Custom branded client apps. Where a Customer offers a branded mobile app, the app is built and operated by us on the Customer's behalf and processes the same information as the online booking page. The app may request permission to send you push notifications; you can withdraw this permission in your device settings. The app store from which you download the app may also collect information under its own privacy policy. Requests to delete data held in a client app can be made at youreontime.com/dataremoval.
- Marketing sent by Customers. Customers can use the Platform to send email and SMS marketing campaigns, promotions, birthday messages and automated follow-ups to their Clients. Customers are responsible for complying with applicable marketing laws, including the Spam Act 2003 (Cth) and, in the EEA and UK, the ePrivacy rules, and for obtaining and recording your consent where required. Every marketing email includes an unsubscribe link and every marketing SMS includes an opt-out instruction. Opting out of a Customer's marketing does not stop appointment confirmations and reminders. We do not use Customers' Client lists to market our own services.
- Information shared between businesses. Each Customer's Client records are separate. We do not share your information with other Customers, and we do not combine your bookings across different businesses into a single profile.
- Booking on behalf of someone else. If you book an appointment, buy a voucher or complete a form for another person, including a child in your care, you confirm that you are authorised to provide their information and to agree to this privacy policy on their behalf.
-
How we collect personal information
- We collect personal information directly from you where it is reasonable and practicable to do so, including:
- when you make an enquiry, request a call or demo, or fill in any form on the Site;
- when you sign up for, log in to and use the Platform;
- when you use a Client Service, including booking online, logging in, completing a form, making a purchase, leaving a review or replying to a message;
- during conversations with our representatives by email, telephone, chat or any other channel;
- when you subscribe to a mailing list or register for a partner program;
- when you visit links shared in our social media posts, emails or landing pages; and
- automatically through cookies, log files and similar technologies when you use the Site, Platform or Client Services (see clause 9).
- We collect Client personal information indirectly when a Customer enters it into the Platform, imports it from another system, or records it during an appointment.
- We collect Customer and Visitor information from third parties where permitted by law, including from payment processors, identity verification providers, publicly available business directories and social media platforms.
- We collect personal information directly from you where it is reasonable and practicable to do so, including:
-
Why we use personal information, and our lawful bases
- We collect, hold, use and disclose personal information for the purposes set out below. Where the GDPR or UK GDPR applies, we rely on the lawful basis shown next to each purpose.
- Providing the Platform and Client Services – creating and managing accounts, processing bookings, sending confirmations and reminders, processing payments, hosting forms and stores, and providing support. Lawful basis: performance of a contract with Customers; for Clients, we process on the Customer's instructions under the Customer's lawful basis (usually contract or consent).
- Security and integrity – authenticating users, sending one-time login codes, preventing fraud, spam and abuse, keeping audit logs, and investigating incidents. Lawful basis: legitimate interests in keeping the Platform secure, and compliance with legal obligations.
- Communicating with you – answering enquiries, sending service notices, billing and changes to terms. Lawful basis: performance of a contract and legitimate interests.
- Improving our products – analysing how the Site, Platform and Client Services are used, testing features, and fixing errors, using aggregated or pseudonymised data wherever possible. Lawful basis: legitimate interests.
- Marketing our own services to Customers and Visitors – sending newsletters, product updates and promotions, and running remarketing campaigns. Lawful basis: consent, or legitimate interests where permitted for existing customers, with an opt-out in every message.
- Complying with the law – meeting tax, accounting, anti-money-laundering and record-keeping obligations, responding to lawful requests from regulators and law enforcement, and establishing or defending legal claims. Lawful basis: legal obligation and legitimate interests.
- Business changes – evaluating and completing a merger, acquisition, financing or sale of all or part of our business. Lawful basis: legitimate interests.
- Where we rely on consent, you may withdraw it at any time by contacting us, and this will not affect processing that took place before you withdrew. Where we rely on legitimate interests, we have balanced those interests against your rights and you may object as described in clause 17.
- We do not use personal information for a purpose that is unrelated to the purpose for which it was collected unless you consent or the law permits or requires it.
-
What happens if we can't collect your personal information?
- If you do not provide the personal information described above:
- we may not be able to provide the Platform or Client Services to you, or a Customer may not be able to accept your booking or provide its services to the same standard or at all;
- we may not be able to send you confirmations, reminders or information you have asked for; and
- we may be unable to tailor the content of the Site to your preferences.
- If you do not provide the personal information described above:
-
Cookies, analytics and tracking technologies
- When you visit our Site our servers record your IP address, the date and time of your visit, the pages accessed, the referring website, the type of browser, operating system and device used, and screen resolution. We use this information for statistical and administrative purposes, to secure the Site and to understand how it is used.
- We use analytics and advertising services on our Site, which may include Google Analytics, Google Ads remarketing and the Meta (Facebook) Pixel. These services use cookies and similar identifiers to measure traffic, understand which content is useful, and show you relevant advertising on other websites. You can opt out of Google Analytics at tools.google.com/dlpage/gaoptout and manage advertising preferences through Google and Meta's ad settings.
- We may also use email and marketing automation tools that record whether emails we send are opened and which links are clicked.
- The Platform and Client Services use strictly necessary cookies and local storage to keep you logged in, remember your booking progress and preferences, protect against cross-site request forgery, and balance load across our servers. These cannot be switched off without breaking the service.
- We may use privacy-focused performance monitoring and error reporting tools on the Platform and Client Services to detect and fix faults. Where these collect personal information, we configure them to collect the minimum needed.
- We do not place advertising or social media tracking cookies on Client Services, and we do not use Client Services to build advertising profiles of Clients.
- Most browsers allow you to refuse or delete cookies. If you are in the EEA or UK, we will only set non-essential cookies on the Site with your consent, which you can withdraw through the cookie settings on the Site or your browser. If you refuse cookies, some features of the Site, Platform or Client Services may not work.
- The Site and Client Services may contain content embedded from third parties such as Google Maps, YouTube and social networks. These providers may set their own cookies and collect information about your device, which we do not control. Please refer to their privacy policies for further information.
- The Site and Client Services contain links to websites we do not control, including Customers' own websites and social media pages. We are not responsible for the privacy practices of those websites, and we encourage you to read their privacy policies before providing personal information to them.
Our Site
The Platform and Client Services
Your choices
Links
-
Who we disclose personal information to
- We may disclose personal information to:
- our directors, employees and contractors who need it to perform their roles;
- service providers that help us operate the Site, Platform and Client Services, including cloud hosting and data storage providers, database and backup providers, SMS and email delivery providers, push notification services, payment processors, mapping services, customer support and helpdesk tools, analytics and error monitoring providers, and identity verification providers;
- the Customer whose Client Service you use, or into whose Platform account your information is entered, and other staff of that Customer with permission to view Client records;
- third-party applications that a Customer chooses to connect to its Platform account, such as accounting software, at the Customer's direction;
- our professional advisors, including accountants, auditors, lawyers and insurers;
- debt collectors, credit reporting bodies, courts, tribunals and regulators where a Customer fails to pay for our services;
- law enforcement, regulators and government agencies where required or authorised by law, or where necessary to protect the rights, property or safety of any person;
- a prospective or actual purchaser or investor in connection with a change of control of our business, as described in clause 10.5; and
- any other person with your consent or at your direction.
- We only disclose personal information to service providers that are bound by contract to keep it confidential, to use it only to provide services to us, and to protect it to a standard consistent with this privacy policy and applicable law. For service providers that process Client information on our behalf, we enter into written data processing terms as required by the GDPR and UK GDPR.
- We do not disclose personal information to third parties for their own direct marketing purposes, and we do not sell personal information.
- Where a Customer connects a third-party application to the Platform, or shares a link to its Client Service on a third-party website or social network, that third party's privacy policy governs its handling of your information.
- If there is a change or potential change to the control of our business through a sale, merger, assignment or transfer of the business or its assets, we may disclose personal information, including our Customer and Client databases, to the prospective purchaser, assignee or transferee to the extent permitted by law. Any such disclosure will be made in good faith, under confidentiality obligations, and the recipient will be bound to honour this privacy policy in respect of information transferred.
- We may disclose personal information to:
-
Where personal information is stored, and overseas transfers
- We are based in Australia. The Platform and Client Services are hosted with third-party cloud providers, and some of our service providers, including SMS and email delivery, payment processing, analytics and support tools, are located or store data outside Australia, including in the United States and the EEA. This means personal information may be transferred to, stored in and accessed from countries other than the one in which you live, and those countries may have data protection laws that differ from your own.
- Before we disclose personal information overseas, we take reasonable steps, as required by APP 8, to ensure the recipient will handle it in a manner consistent with the APPs. This includes contractual protections, assessment of the recipient's privacy and security practices, and ongoing review.
- Where the GDPR or UK GDPR applies and we transfer personal information outside the EEA or UK, we rely on one or more of the following safeguards:
- a decision by the European Commission or UK Government that the destination country provides an adequate level of protection;
- the European Commission's Standard Contractual Clauses, or for UK transfers the International Data Transfer Agreement or UK Addendum, together with any supplementary measures identified in a transfer risk assessment; or
- another mechanism permitted under Chapter V of the GDPR or UK GDPR.
- Where PIPA applies, we transfer personal information overseas only where we are satisfied that the overseas recipient will provide a comparable level of protection, whether through contractual mechanisms, binding corporate rules or otherwise, or where another exception under PIPA applies.
- We maintain a register of our sub-processors and the locations in which they process personal information. Customers may request a copy of this register and will be notified of changes to it in accordance with our data processing terms.
-
Direct marketing from us
- We may send Customers and Visitors marketing communications about the Platform, new features, offers and events that we consider may interest you, by email, SMS, telephone, post and through advertising platforms, in accordance with applicable marketing laws including the Spam Act 2003 (Cth), the Do Not Call Register Act 2006 (Cth) and, in the EEA and UK, the ePrivacy rules.
- We only send electronic marketing to Visitors with your consent. We may send electronic marketing to existing Customers about similar products and services without further consent where the law permits, and you can opt out at any time.
- You can opt out of our marketing at any time by clicking the unsubscribe link in any email, replying STOP to any SMS, or contacting us at youreontime.com/contact with "Unsubscribe" in the subject line. We will action your request promptly, and in any event within the time required by law. Opting out of marketing does not stop us sending you service messages about your account.
- We do not send our own marketing to Clients, and we do not use Customers' Client lists for our own marketing. Marketing you receive from a Customer is sent by that Customer and is described in clause 5.10.
- We do not provide personal information to other organisations for their own direct marketing.
-
Security
- We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include:
- encrypting data in transit using TLS, and encrypting data at rest with our hosting providers;
- hosting the Platform with providers that maintain independently audited security programs;
- role-based access controls, individual logins, PINs and audit logs within the Platform so that Customers can limit which staff can see Client information and financial data;
- one-time codes for Client logins, and never storing full payment card details on our systems;
- restricting our own staff's access to personal information to what is needed to provide support, and requiring them to keep it confidential;
- regular backups, monitoring, patching and vulnerability management; and
- written contracts with service providers requiring appropriate security measures.
- Customers are responsible for keeping their login credentials secure, for configuring staff access permissions appropriately, and for the security of devices used to access the Platform.
- Although we take these steps, no transmission over the Internet and no method of electronic storage is completely secure, and we cannot guarantee absolute security. If you become aware of any unauthorised access to your account, please contact us immediately.
- We maintain records to demonstrate our compliance, including a record of processing activities, consent records, a data breach register, sub-processor and transfer registers, and staff privacy training records.
- We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include:
-
How long we keep personal information
- We keep personal information only for as long as it is needed for the purposes for which it was collected, including to satisfy legal, accounting and reporting requirements, and then delete or de-identify it. In deciding how long to keep information we consider its amount, nature and sensitivity, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and applicable legal requirements.
- Customer account information. We keep Customer account, billing and transaction records for the life of the subscription and for seven years after it ends, to meet Australian tax and corporate record-keeping requirements and to establish or defend legal claims.
- Client information held in a Customer's account. The Customer decides how long Client records are kept while its subscription is active, subject to its own legal obligations, and can delete individual Client records at any time. When a Customer's subscription ends, we retain its account data, including Client records, for a limited period so that the Customer can export it or reactivate the account, and then delete it from our production systems. Customers may request earlier deletion. Deleted data may persist in encrypted backups for a further period until those backups are cycled.
- Client Service logins and messages. One-time login codes expire within minutes. SMS and email delivery logs are kept for as long as needed to demonstrate delivery, investigate problems and comply with telecommunications and anti-spam laws.
- Marketing information. We keep records of marketing consent and opt-outs for as long as needed to honour your preferences. If you opt out we keep your contact details on a suppression list so that we do not contact you again.
- Visitor enquiries. We keep enquiry and support correspondence for as long as needed to respond and for a reasonable period afterwards for reference and quality purposes.
- We may keep de-identified or aggregated information indefinitely for research, statistical and product improvement purposes, as it no longer identifies you.
-
Data breaches
- If a data breach involving personal information occurs, we will contain the breach, assess the risk of harm to affected individuals and take remedial action as quickly as possible.
- Where a breach is likely to result in serious harm to individuals, we will notify the Office of the Australian Information Commissioner and affected individuals as required by the Notifiable Data Breaches scheme in the Privacy Act.
- Where the GDPR or UK GDPR applies and we are the controller, we will notify the relevant supervisory authority within 72 hours of becoming aware of a breach that is likely to result in a risk to individuals' rights and freedoms, and notify affected individuals without undue delay where the risk is high.
- Where a breach affects Client information we process on behalf of a Customer, we will notify the affected Customer without undue delay after becoming aware of it and provide the information the Customer needs to meet its own notification obligations. The Customer, as controller, is responsible for notifying its Clients and regulators.
- Where PIPA applies, we will notify the Bermuda Privacy Commissioner and affected individuals without undue delay of any breach that is likely to adversely affect individuals.
-
Accessing, correcting and deleting your personal information
- You may request access to, correction of, or deletion of the personal information we hold about you at any time by contacting us using the details in clause 22. We will respond within a reasonable time, and in any event within 30 days.
- Customers can view and update most of their account and staff information directly in the Platform, and can export their data, including Client records, at any time.
- Clients can view and update the details held about them by logging in to the Customer's Client Service, where the Customer has enabled it. Because the Customer controls your record:
- requests to access, correct or delete information held in a Customer's account should be made to the Customer in the first instance, and the Customer can act on them directly in the Platform;
- if you send such a request to us, we will pass it to the Customer without undue delay and assist the Customer to respond, unless the request concerns information we hold as controller under clause 2.5, which we will handle ourselves; and
- you can submit a data removal request for information held in a client app at youreontime.com/dataremoval.
- We may need to verify your identity before actioning a request, and we may ask you for enough information to locate your records. We will not charge for making a request or for correcting information. We may charge a reasonable fee for providing access where the request is manifestly unfounded, excessive or repetitive, or where the law otherwise permits.
- There may be circumstances where we cannot grant access or delete information, for example where doing so would interfere with the privacy of others, where we are required by law to keep the information, or where it is needed to establish or defend legal claims. If that happens we will tell you in writing, give reasons where we can, and explain how you can complain.
- If we do not agree that information needs to be corrected, you may ask us to attach a statement to the record noting that you believe it is inaccurate, and we will do so.
- You may withdraw your consent to our collection and use of your personal information at any time by contacting us. We will then delete, destroy or return your information to the extent we are permitted by law. This may mean you can no longer use the Site, Platform or Client Services.
-
Your rights under the GDPR and UK GDPR
- If you are in the EEA or the United Kingdom, you have the following rights in relation to personal information of which we are the controller:
- The right to be informed – to be told how we use your personal information, which this privacy policy does;
- The right of access – to obtain confirmation that we are processing your personal information and a copy of it, together with information about the processing;
- The right to rectification – to have inaccurate personal information corrected and incomplete information completed;
- The right to erasure – to have your personal information deleted in certain circumstances, for example where it is no longer needed for the purpose it was collected or you withdraw consent, unless we have an overriding legal reason to keep it;
- The right to restrict processing – to ask us to suspend processing of your personal information in certain circumstances, for example while we verify its accuracy or consider an objection;
- The right to data portability – to receive personal information you have provided to us in a structured, commonly used, machine-readable format (for example a .csv file), and to have it transmitted to another controller where technically feasible;
- The right to object – to object to processing based on our legitimate interests, and to object at any time to processing for direct marketing, in which case we will stop;
- Rights in relation to automated decision-making and profiling – not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you (see clause 19); and
- The right to withdraw consent – where we rely on consent, to withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- These rights are subject to conditions and exceptions under the GDPR and UK GDPR. We will respond to a request within one month of receiving it. We may extend this by up to two further months where a request is complex or we receive several requests, and we will tell you if this is the case. We may ask you to verify your identity before we respond.
- Where a Customer is the controller of your personal information, these rights are exercisable against the Customer. We will pass your request to the Customer and assist it to respond, as described in clause 16.3.
- To exercise any of these rights, contact us at youreontime.com/contact.
- You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EEA member state or UK where you live, work or where the alleged infringement occurred. Contact details for EEA authorities are available at edpb.europa.eu, and for the UK Information Commissioner's Office at ico.org.uk. We would appreciate the chance to address your concerns first, so please contact us before approaching a supervisory authority.
- If you are in the EEA or the United Kingdom, you have the following rights in relation to personal information of which we are the controller:
-
Your rights under Bermuda's PIPA
- If you are in Bermuda, you have the following rights in relation to your personal information:
- The right to access – to request access to the personal information we hold about you, and to be told the purposes for which it is used and the persons to whom it has been disclosed, within the prescribed timeframes;
- The right to correction – to request that we correct personal information that is inaccurate or incomplete;
- The right to erasure and blocking – in certain circumstances, to ask us to erase or block personal information that is no longer relevant for the purposes for which it was collected;
- The right to object to processing – to object to processing of your personal information for direct marketing purposes, or where the processing is likely to cause substantial damage or distress;
- The right to withdraw consent – to withdraw consent to the processing of sensitive personal information at any time; and
- The right to complain – to lodge a complaint with the Bermuda Privacy Commissioner if you believe your privacy rights have been breached.
- These rights are subject to conditions and exceptions under PIPA, and to prescribed timeframes for our response. Where a Customer controls your personal information, we will pass your request to the Customer and assist it to respond.
- To exercise any of these rights, contact us at youreontime.com/contact.
- Bermuda Privacy Commissioner: email info@privacy.bm, website privacy.bm, address Clarendon House, 2 Church Street, Hamilton, Bermuda.
- If you are in Bermuda, you have the following rights in relation to your personal information:
-
Automated decision-making and profiling
- We do not make decisions about you based solely on automated processing that produce legal effects or similarly significant effects on you.
- The Platform includes automated features that Customers can configure, such as sending reminders at set intervals, applying deposit or cancellation rules, offering "first available" staff, targeting marketing campaigns using criteria such as last appointment date or birthday, and flagging Clients with a history of missed appointments. These features operate on the Customer's instructions, and any decision to refuse a booking or charge a fee is made under the Customer's own policies and can be reviewed by the Customer on request.
- We use automated fraud, spam and abuse detection to protect the Platform. Where such detection would result in an account being suspended, a member of our team reviews the decision.
-
Children
- The Site and Platform are intended for use by businesses and are not directed at children. You must be at least 18 years old to create a Customer account.
- Client Services are not directed at children under 16, and we do not knowingly collect personal information directly from children under 16 without the consent of a parent or guardian. Bookings, purchases and forms for a child should be completed by a parent or guardian on the child's behalf. Customers are responsible for complying with any age-related requirements that apply to their services.
- If you believe we have collected personal information from a child without appropriate consent, please contact us and we will take steps to delete it.
-
Complaints
- If you believe that your privacy has been breached, or you have a concern about how we have handled your personal information, please contact us using the details in clause 22 and provide details so that we can investigate.
- We will acknowledge your complaint, treat it confidentially, investigate it, and aim to resolve it within 30 days, and in any event within the time required by the Privacy Act, the GDPR, the UK GDPR or PIPA, as applicable. If we need more time we will tell you why and when you can expect a response.
- If you are not satisfied with our response, you may complain to the relevant regulator:
- Australia: Office of the Australian Information Commissioner, oaic.gov.au;
- EEA: the data protection authority in your member state, listed at edpb.europa.eu;
- United Kingdom: Information Commissioner's Office, ico.org.uk;
- Bermuda: Office of the Privacy Commissioner for Bermuda, privacy.bm.
- If your complaint concerns how a Customer has used your personal information, you should raise it with the Customer, and you may also complain to the regulator in the country where the Customer is located.
-
Contacting us
- If you have any questions about this privacy policy, wish to exercise any of your rights, or want to make a complaint, please contact our Privacy Officer via our website at youreontime.com/contact or by post to NEWCHURCHTEK PTY LTD, Attention: Privacy Officer, at our registered office in Australia.
- Requests to delete data held in a client app can also be submitted at youreontime.com/dataremoval.
- We will treat your requests and complaints confidentially, and our representative will contact you within a reasonable time to discuss your concerns and the options for resolving them.
-
Changes to this privacy policy
- We may update this privacy policy from time to time to reflect changes in our practices, the Platform or the law. The current version will always be available on our website, and the date of the latest update appears at the top of this page.
- Where a change materially affects how we handle your personal information, we will notify Customers by email or through the Platform before the change takes effect. Customers are responsible for letting their Clients know about changes that affect them. Your continued use of the Site, Platform or Client Services after the change takes effect means you accept the updated policy.
- This privacy policy covers the Australian, European Union, United Kingdom and Bermuda jurisdictions. Portions of this privacy policy are based on a template © Progressive Legal Pty Ltd (ACN 607 068 708) trading as Progressive Legal (2021). All Rights Reserved. This privacy policy was last updated 22 September 2026.