Privacy Policy
How we collect, use, protect and manage personal information under Australian privacy law and the GDPR where applicable.
1. Scope and purpose
This Privacy Policy explains how Hellspin Bonuscress Atelier Pty Ltd collects, uses, stores, discloses and protects personal information when you visit this website, make an enquiry, subscribe to updates, arrange a screening or event, attend our premises, communicate with our team or otherwise interact with our services.
We seek to handle personal information consistently with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles, applicable Victorian law and, where the European Union or United Kingdom data protection rules apply to an individual, the General Data Protection Regulation and corresponding UK legislation. References to “personal information” include “personal data” where that expression is used by the GDPR.
2. Privacy administrator and contact
The organisation responsible for the processing described in this policy is:
7 Marungi Street, Mooroolbark VIC 3138, Australia
ACN 674 392 815
ABN 61 674 392 815
Email: info@hellspinbonuscressatelier.com
Phone: +61 3 8720 4951
Privacy requests may be submitted in writing by email or post. Email and telephone details are displayed as plain text throughout the website and are not interactive links.
3. Categories of information we collect
Depending on how you interact with us, we may collect identification and contact details, enquiry and booking information, event requirements, accessibility preferences voluntarily provided by you, correspondence, feedback, attendance records, transaction and invoice information, technical information about the device and browser used to access the website, and records required for security, insurance, legal or operational purposes.
We ask that you do not provide sensitive information unless it is reasonably necessary for the service requested. Where accessibility, dietary, health or other sensitive details are relevant to an event, we process them only for the stated operational purpose and with an appropriate legal basis.
4. How information is collected
Information may be collected directly from you through website forms, email, telephone, face-to-face communication, booking documentation, event planning conversations, surveys or feedback. We may also receive information from a person organising an event on your behalf, an authorised representative, a service provider involved in delivering the booking, publicly available sources, or technical logs created when the website is accessed.
If another person provides your information to us, that person should have authority to do so and should make this policy available to you where practicable.
5. Purposes of processing
We use personal information to respond to enquiries; assess availability; prepare proposals and booking arrangements; deliver screenings, venue hire and events; communicate operational instructions; provide accessibility support; process payments and refunds where relevant; maintain safety and security; manage suppliers; improve our facilities and services; administer subscriptions requested by you; investigate complaints; prevent misuse; comply with law; establish or defend legal claims; and maintain business and accounting records.
We do not sell personal information. We do not use personal information for unrelated direct marketing without an applicable permission or legal basis.
6. Legal bases under the GDPR
Where the GDPR applies, we rely on one or more of the following legal bases: processing necessary to take steps at your request before entering a contract; performance of a contract; compliance with a legal obligation; our legitimate interests in operating a secure, efficient and high-quality venue and website, provided those interests are not overridden by your rights; consent where consent is specifically requested; and, in exceptional cases, protection of vital interests or establishment, exercise or defence of legal claims.
Where processing is based on consent, consent may be withdrawn at any time without affecting processing that occurred before withdrawal.
7. Direct marketing and communications
We send promotional or newsletter communications only where you have requested them, consented to receive them, or another lawful basis permits the communication. You may opt out at any time by contacting us using the plain-text details in this policy. Service messages about an existing enquiry, booking, safety issue, legal notice or operational change are not marketing communications.
8. Disclosure to service providers and other recipients
We may disclose information to carefully selected providers that support website hosting, communications, payment processing, accounting, legal services, insurance, security, accessibility, event production, ticketing, venue operations, technical support, storage and business administration. Providers are permitted to use information only for authorised purposes and are expected to apply appropriate confidentiality and security measures.
Information may also be disclosed to regulators, courts, law-enforcement authorities, emergency services, professional advisers, insurers, a purchaser or successor in a legitimate business transaction, or another recipient where disclosure is required or authorised by law.
9. International transfers
Some service providers may process information outside Australia. Where the GDPR applies and information is transferred outside the European Economic Area or the United Kingdom, we use an available transfer mechanism such as an adequacy decision, approved standard contractual clauses or another legally recognised safeguard, together with supplementary measures where appropriate.
You may contact us for further information about the safeguards relevant to a particular transfer, subject to legal and confidentiality limitations.
10. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including the duration of an enquiry or booking, operational follow-up, warranty or dispute periods, taxation and accounting obligations, insurance requirements, safety records, limitation periods and legal claims. When information is no longer required, we take reasonable steps to delete it, anonymise it or securely isolate it from routine use.
11. Security
We use administrative, physical and technical safeguards proportionate to the nature of the information and the risks involved. Measures may include access controls, staff confidentiality obligations, secure configuration, backups, restricted records, vendor assessment, data minimisation and incident response procedures. No method of transmission or storage is completely secure, and absolute security cannot be guaranteed.
If a data breach is likely to result in serious harm or a high risk to individuals, we will assess notification obligations and notify affected individuals and relevant regulators where required.
12. Your rights and choices
Subject to applicable law, you may request access to personal information, correction of inaccurate or incomplete information, deletion, restriction of processing, objection to processing based on legitimate interests, portability of information you provided in a structured format, withdrawal of consent, and information about international safeguards. Australian residents may also request access and correction under the Australian Privacy Principles.
We may need to verify identity before acting on a request. A request may be refused or limited where the law permits, including where it would adversely affect another person’s rights, reveal protected material, interfere with legal obligations or be manifestly unfounded or excessive. We will explain any applicable limitation.
13. Children and young people
The website is directed to adults arranging cinema experiences and events. We do not knowingly collect personal information directly from children through the website without the involvement of a parent, guardian, school or authorised organiser. Event organisers should provide only information reasonably necessary for participation and safety.
14. Automated decision-making
We do not use personal information collected through this website to make decisions based solely on automated processing that produce legal or similarly significant effects. If this changes, we will provide the information and safeguards required by applicable law.
15. Cookies and local technologies
This website is designed to operate without advertising trackers or third-party analytics. Strictly necessary browser features may be used to support security, navigation and user-requested functionality. Detailed information is provided in the Cookie Policy. If non-essential cookies are introduced, they will not be activated for visitors subject to consent requirements unless valid consent has been obtained.
16. Complaints and supervisory authorities
Please contact us first so that we can investigate and respond to a privacy concern. We aim to acknowledge a complaint promptly and provide a substantive response within a reasonable period. Australian individuals may complain to the Office of the Australian Information Commissioner. Individuals in the European Economic Area or United Kingdom may also lodge a complaint with the data protection authority in the country where they live, work or believe an infringement occurred.
17. Changes to this policy
We may update this policy to reflect legal, technical or operational changes. The revised version will be posted on this page with a new effective date. Material changes will be highlighted where reasonably practicable. This version is effective from 5 August 2026.