Last Revised: May 2018
Purpose of Processing Personal Data: We collect personal data so that we can provide you with fitness services including gym membership, exercise classes, and personal training. We store CCTV images for the safety and security of our customers and staff.
The Data Controller: KD Fitness Ltd trading as Ocean Fitness, a company registered in England & Wales (company number 5904335). You can contact us at: email@example.com
What type of personal data do we collect about you?
“Personal data” means any information about an individual from which that person can be identified. We collect personal data from you when you subscribe to this website, when you contact us about our services, when you join our gym, or when you purchase exercise classes or other fitness services from us.
We may collect the following types of information:
- Identity Data includes first name, last name, and title
- Contact Data includes billing address, email address and telephone numbers
- Financial Data includes bank account details collected and used solely for purposes of preparing a Direct Debit agreement for your gym membership.
- Transaction Data includes details about payments from you and other details of products and services you have purchased from us
- Fitness Data includes training programs, fitness tests, your age, gender, height and weight, and any health conditions that we need to be aware of in order to safely provide you with fitness services.
- Profile Data includes your gym membership card number, your Ocean Fitness website password and username as applicable.
- Usage Data includes information about how you use our products and services, including when you visit the gym and the exercise classes you attend
- Technical Data includes internet protocol (IP) address, browser type and version, and the pages you visit on this website
- CCTV Footage public areas of the gym are monitored by CCTV to ensure the safety and security of our Members and Staff
Links to other websites
Our Website may, from time to time, contain links to third party websites. If you follow a link to any of those third party websites, please note that those websites have their own privacy policies and we do not accept any responsibility or liability for those practices. Please check those policies before you submit any personal data to those websites.
No information from children under age 16
This Website and our Gym are not intended for children and we do not knowingly collect data relating to children. If you are under the age of 16, please do not attempt to register with us at this Website or provide any personal information about yourself to us. If we learn that we have collected personal information from a child under the age of 16, we will promptly delete that information.
If you believe we have collected personal information from a child under the age of 16, please contact us at firstname.lastname@example.org
How do we use the information we gather?
We use your personal data for the purposes and legal bases set out below:
- Processing that is necessary for the performance of a contract or to enter into such a contract with you
- To register a new customer, create and maintain your customer account
- To provide gym membership, exercise classes and other fitness services to you
- To process membership payments and purchases
- To provide personalised fitness programs appropriate for your health, abilities, and goals
- To provide fitness tests for you to track your progress
- To promote our products and services
- For the safety and security of our staff and customers
- To manage and operate our gym, and monitor usage of the gym facilities
- To manage and operate our website, and monitor how our Website is used
- To provide you with information, products or services that you request from us
Do we share your personal information with third parties?
We may disclose the relevant parts of your personal data to third parties who provide a service to us, including:
- Global Iris and Paypal, who provide card payment processing services
- Rapidata, who provide Direct Debit processing services
- Fitness Age, who provide cloud based fitness test software
How do we keep your data secure?
We use a variety of security technologies and procedures to help protect your personal data from unauthorised access and use. We will continue to revise policies and implement additional security features as new technologies become available.
Where we have given you a password which enables you to access certain parts of our Website, you are responsible for keeping that password confidential. We ask you not to share your password with anyone.
If you purchase exercise classes or gym membership from our website, the card payments are processed by Global Iris or Paypal as third party payment providers. Your web browser communicates directly with the Global Iris or Paypal website, over a secure encrypted link. We do not store or process your card payment details. Global Iris or Paypal are responsible for your payments information which will be subject to their privacy policies.
How long do we store your data?
- We store your personal data during the time that you are a customer for purposes of providing you the services, and for up to two years after you cease to be a customer
- If you have never been a customer, but have requested information or a tour from us, we may store your data for up to one year
We reserve the right to store or delete your personal data earlier or later than this if required to do so by an applicable law or regulation, including the GDPR and for the exercise or defence of legal claims.
Where we store your personal data
The personal data that we collect from you is stored at secure Data Centres within the European Economic Area (EEA).
Below is a summary of your rights. You may exercise your rights by contacting us at email@example.com
- Right of Access You can request a copy of the personal data we hold about you.
- Right to Erasure (‘Right to be Forgotten’) You have the right to request that your personal data be deleted in certain circumstances
- Right to Restriction of Processing You can ask that we restrict your personal data (i.e., keep but not use) in certain circumstances
- Right to Object You have a right to object to the processing of your personal data in those cases where we are processing your personal data in reliance on our legitimate interests. In such a case we will stop processing your personal data unless we can demonstrate compelling legitimate interests which override your interests.
- Right to Complain
You have the right to lodge a complaint with the Data Protection Authority if you are unhappy with how we are processing your personal data.
Our postal address is:
96 Dominion Road