Privacy Policy

Last updated: 13 August 2026


1. About this policy

This policy explains what personal information I collect when you visit damianbuilds.com or use the Hazar pre-call chat, how I use and protect it, and what your rights are.

I am Damian Yazbeck, trading as DAMIANSLIFE (ABN 68 155 841 042), a personal trainer and AI consultant based in Sydney, Australia. I am bound by the Privacy Act 1988 (Cth) as a health service provider, which means all thirteen Australian Privacy Principles apply to how I handle your information.

If you have questions about this policy or want to exercise your privacy rights, email [email protected].


2. What I collect and why

Information How I collect it Why I collect it
Name and email address Cal.com booking form To confirm your appointment and contact you before our call
Booking notes and intake answers Cal.com booking form To understand your goals and situation before our conversation
Chat transcript Hazar pre-call chat To prepare a summary of our pre-call conversation
Health and fitness information Hazar pre-call chat See below
Email correspondence Direct email To communicate with you and keep a record of our interaction

I collect only what I need to deliver the service. I do not sell, rent, or trade your personal information to anyone.

Health and fitness information

If you share health, fitness, injury, or medical details during the Hazar chat, I collect that information to provide appropriate service before our call. Health and fitness information is treated as sensitive information under Australian law and equivalent standards internationally. I collect it for service delivery only - never for advertising - and do not share it with any third party beyond the processors named in this policy (Fireworks AI for inference, my Finland server for storage). It is deleted at the 12-month mark (see Section 6). Before the chat begins, you are asked to confirm your consent to this collection explicitly.


3. The Hazar pre-call chat

Before your booking call, you may use Hazar, an AI-powered chat that helps me understand your goals and situation before we speak.

How Hazar works:

When you send a message in the chat, the content of that message is sent to Fireworks AI, Inc., a company based in the United States, which processes it to generate a response. This happens every time you use the chat - it is how the service works, not an occasional transfer.

What I do not send to Fireworks AI:

Your name, email address, and booking details are not included in the messages sent to Fireworks AI.

Fireworks AI data handling:

Based on Fireworks AI's published API terms, messages sent through the API are not stored beyond the time needed to generate a response and are not used to train their models. I have not independently verified these claims against the specific plan in use - if their terms change, this policy will be updated. You should review Fireworks AI's own privacy policy for your rights in relation to their processing.

Automated decisions:

Hazar does not make decisions about whether to accept you as a client. It produces a summary of the conversation that I read before deciding whether to proceed. Every decision is made by me, not by the chat.

Consent:

Before you send your first message, you are asked to confirm that you have read this policy and the pre-chat disclosure. That confirmation covers the data flows described in this section and in Section 4.


4. Overseas processing

Fireworks AI - United States

Your chat messages are processed by Fireworks AI, Inc. in the United States. This occurs every time you use the Hazar chat.

By using the Hazar chat and checking the consent box before your first message, you acknowledge that your messages will be processed by Fireworks AI in the United States. Australian Privacy Act protections do not apply to Fireworks AI's handling of your messages, and you cannot seek redress under the Privacy Act 1988 (Cth) for that processing. Please review Fireworks AI's privacy policy for your rights in relation to their processing.

If you are located in the EU or EEA, transfers of your personal data to Fireworks AI are governed by EU Standard Contractual Clauses (Commission Implementing Decision 2021/914, Module Two - Controller to Processor). If you are located in the UK, transfers are additionally governed by the UK Addendum to those Standard Contractual Clauses. Fireworks AI's Data Processing Agreement is available at trust.fireworks.ai.

My server - Finland

A transcript of your chat conversation is stored on a private server I own and operate in Finland. This is my own infrastructure, not a third-party service. Transferring data to my own server is not a disclosure to an overseas recipient under the Privacy Act. For EU and EEA users, this means your transcript is stored within EU territory.

Cal.com - United States

When you book a call, your booking details are processed by Cal.com. See Section 7 for details.


5. How I store and protect your information

Transcripts and booking records are stored on a private server I operate in Finland. The server is not publicly accessible and is protected by encrypted storage and access controls. I am the only person with access to this server.

I take reasonable steps to protect your personal information from misuse, loss, unauthorised access, modification, and disclosure. If I engage any service that handles your information on my behalf, I require that they maintain appropriate security standards.


6. How long I keep your information

Chat transcripts:

12 months from the date of the conversation, then deleted automatically. Transcripts are retained to allow resolution of any queries or disputes about the pre-call conversation and to support service improvement. This includes any health or fitness information you share during the chat. After 12 months, transcripts are deleted - unless you have become an active client, in which case relevant intake information is held for the duration of our coaching relationship and then deleted.

Aggregate themes:

Non-identifying patterns derived from multiple conversations, with no link to any individual, are retained indefinitely for service improvement purposes. These summaries do not contain your name, contact details, or any information that could identify you.

Booking records (my calendar copy):

3 years from the date of the booking, consistent with standard business record-keeping. Cal.com's own retention policy governs the copy they hold.

Email correspondence:

Retained while our business relationship is active, then deleted within 12 months of our last contact.


7. Third-party booking service - Cal.com

When you book a call through this site, your booking details - including your name, email address, and any information you enter in the booking form - are collected directly by Cal.com, a third-party scheduling service. Cal.com may process this data outside Australia. I receive a copy of your booking details in my calendar.

Cal.com participates in the EU-US Data Privacy Framework and offers Standard Contractual Clauses for EU and UK data subjects. Cal.com's privacy policy governs how they handle your booking data: cal.com/privacy.


8. Your rights and how to contact me

Access and correction:

You can request access to the personal information I hold about you, or ask me to correct information that is inaccurate, incomplete, or out of date. Email [email protected] and I will respond within 30 days.

Deletion:

To request deletion of your personal information, email [email protected]. I will action your request within 30 days. Note: once your messages have been processed by Fireworks AI, I cannot retrieve or delete any copies that Fireworks AI may hold. Please review Fireworks AI's privacy policy for your deletion rights in relation to their processing.

Complaints:

If you have a concern about how I have handled your personal information, please contact me first at [email protected]. If I cannot resolve your concern within 30 days, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.

Data breaches:

If a data breach occurs that is likely to result in serious harm to any individual, I will notify the OAIC and the affected individuals as required under the Notifiable Data Breaches scheme.


9. International users

Governing law and jurisdiction

This policy is governed by the laws of Australia. Any disputes relating to this policy are subject to the jurisdiction of Australian courts.

If you access these services from outside Australia, your personal information may be transferred to, stored, and processed in Australia and in other countries where service providers operate - currently the United States (Cal.com for bookings, Fireworks AI for AI inference) and Finland (my private server). I apply the Australian Privacy Principles as the minimum standard for all users globally.

EU, EEA, and UK

GDPR (General Data Protection Regulation) does not currently apply to my services. My site does not target EU or EEA audiences, and my Finland server does not constitute a GDPR establishment under the European Data Protection Board's guidelines on territorial scope (EDPB Guidelines 3/2018). I have not appointed an EU or UK representative, which is proportionate at the current scale of this service.

Regardless of location, I voluntarily extend the following rights to all users, including those in the EU, EEA, and UK:

Consent withdrawal:

Where processing is based on your consent, you may withdraw consent at any time by emailing [email protected]. Withdrawal does not affect the lawfulness of processing before withdrawal.

EU/EEA supervisory authority:

If you are located in the EU or EEA, you have the right to lodge a complaint with the supervisory authority in your country of residence. Details of EU supervisory authorities are available at edpb.europa.eu.

UK supervisory authority:

If you are located in the UK, you may complain to the Information Commissioner's Office at ico.org.uk.

Transfer disclosures for EU/UK users:

See Section 4 for the SCC mechanism covering Fireworks AI. Your chat transcript is stored on my Finland server, within EU/EEA territory.

Canada

I endeavour to comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). If your privacy concern is not resolved by contacting me directly, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.

New Zealand

I endeavour to comply with the New Zealand Privacy Act 2020. If your privacy concern is not resolved by contacting me directly, you may contact the New Zealand Office of the Privacy Commissioner at privacy.org.nz.

California

If you are a California resident with questions about your privacy rights, please contact me at [email protected].