PRIVACY STATEMENT
Małgosia Underwood Pilates, a sole trader (“I”/”me”), am committed to protecting and respecting any personal information you share with me.
This statement describes what types of information I collect from you, how it is used by me, if I share it with others, how you can manage the information I hold and how you can contact me.
The contents of this statement may change from time to time so you may wish to check this page occasionally to ensure you are still happy to share your information with me. Where possible, I will also contact you directly to notify you of these changes.
This version of my Privacy Statement is live from 10th May 2018.
What information do I collect?
I collect information about you when you contact me via telephone, e-mail, my website, Facebook page, or Instagram page, and when you complete a PAR-Q (Physical Activity Readiness Questionnaire) form. I only collect information, which is necessary, relevant, and adequate for the purpose you are providing it for.
The information I collect includes the following:
How do I use this information?
I will only process information that is necessary for the purpose for which it has been collected. You will always have the option not to receive marketing communications from me (and you can withdraw your consent or object at any time). I will never send you unsolicited ‘junk’ email or communications, or share your personal information with anyone else who might. I do not sell your information to third parties.
There are various ways in which I may use or process your personal information. I list these below:
Consent
Where you have provided your consent, I may use and process your information to contact you from time to time about promotions, events, products, services or information which I think may be of interest to you (don’t worry, I won’t bombard you). You can withdraw your consent at any time by contacting me at [email protected].
Contractual performance
I may use and process your personal information where this is necessary to perform a contract with you and to fulfil and complete your orders, purchases and other transactions entered into with me.
Legitimate Interests
I may use and process your personal information as set out below where it is necessary for me to carry out activities for which it is in my legitimate interests as a business to do so.
Processing necessary for me to support customers with sales and other enquiries
I will respond to correspondence you send to me and fulfil the requests you make to me (for example: trial class, class cancellation or transfer, etc.)
Processing necessary for us to respond to understanding customers’ needs
I may undertake market analysis and research (including contacting you with customer surveys) so that I can better understand you as a customer and provide tailored offers and services that I think you will be interested in, as well as using your feedback to improve my services. I will only send marketing communications to you if you have provided your consent for me to do so or which we have obtained in the ways mentioned in the paragraph below.
Processing necessary for me to promote my business and services
I may send you marketing information from time to time after you have purchased a service from me or made an enquiry. I will only contact you with information about my own services (and in ways the law allows), which I hope you will like. You have the right to object to me sending you this information at any time.
You may see my advertising delivered online through social media, unless you object by unfollowing me.
I may contact you when there are changes to the class timetable, or I move premises.
Processing necessary for me to operate the administrative and technical aspects of my business efficiently and effectively
To verify the accuracy of information that I hold about you and create a better understanding of you as a customer, comply with a request from you in connection with the exercise of your rights (for example where you have asked me not to contact you for marketing purposes, I will keep a record of this on our suppression lists in order to be able to comply with your request).
To inform you of updates to my terms and conditions and policies.
Legal Obligation
I may process your personal information to comply with my legal requirements (such as collecting, storing and referring to a PAR-Q).
Vital Interest
Sometimes I will need to process your personal information to contact you if there is an urgent change or update I need to tell you about it.
How do I share this information?
I do not sell your information to third parties.
I do not share your information with third parties unless necessary. Where this is necessary, I comply with all aspects of the Data Protection Act (DPA) and will only do so if I have your consent.
How long do I keep your information for?
I will not hold your personal information in an identifiable format for any longer than is necessary. If you are a customer or otherwise have a relationship with me, I will hold personal information about you for a longer period than if I have obtained your details in connection with a prospective relationship.
If I have a relationship with you (e.g. you are a client or were at some point), I hold your personal information for 6 years from the date our relationship ends. I hold your personal information for this period to establish, bring or defend legal claims.
Where I have obtained your personal information following a request for a trial class, quotation or any other information on my services, I hold your personal information for 1 year and 6 months from the date I collected that information, unless during that period I form a relationship with you e.g. you become a client by purchasing a Class Pass. I hold your personal information for this period to give me an opportunity to form a relationship with you.
The only exceptions to the periods mentioned above are where:
How can you manage the information I hold about you?
You have the right as an individual to access your personal information I hold about you and make corrections if necessary. You also have the right to withdraw any consent you have previously given me and ask me to erase information I hold about you. You can also object to me using your personal information (where I rely on our business interests to process and use your personal information).
You have a number of rights in relation to your personal information under GDPR. You can:
1. ask for a copy of the information that I hold about you;
2. correct and update your information;
3. withdraw your consent (where I rely on it). Please see further How do I use this information.
4. object to my use of your information (where I rely on my legitimate interests to use your personal information) provided I do not have any continuing lawful reason to continue to use and process the information. When I do rely on my legitimate interests to use your personal information for direct marketing, I will always comply with your right to object.
5. erase your information (or restrict the use of it), provided I do not have any continuing lawful reason to continue to use and process that information
6. transfer your information in a structured data file (in a commonly used and machine readable format), where I rely on your consent to use and process your personal information or need to process it in connection with your contract.
You can exercise the above rights and/or manage your information by contacting me using the details below:
By email: [email protected]
By phone: 07948 395 010
If you have any specific data protection concerns or a complaint, you can address it to me at [email protected]
If you are unhappy, you have the right to lodge a complaint with a data protection regulator in Europe, in particular in a country you work or live or where your legal rights have been infringed. The contact details for the Information Commissioner’s Office, the data protection regulator in the UK, are below:
By post:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
By phone: 0303 123 1113
By email: [email protected]
This statement describes what types of information I collect from you, how it is used by me, if I share it with others, how you can manage the information I hold and how you can contact me.
The contents of this statement may change from time to time so you may wish to check this page occasionally to ensure you are still happy to share your information with me. Where possible, I will also contact you directly to notify you of these changes.
This version of my Privacy Statement is live from 10th May 2018.
What information do I collect?
I collect information about you when you contact me via telephone, e-mail, my website, Facebook page, or Instagram page, and when you complete a PAR-Q (Physical Activity Readiness Questionnaire) form. I only collect information, which is necessary, relevant, and adequate for the purpose you are providing it for.
The information I collect includes the following:
- Name
- Gender
- Date of birth
- Occupation
- Address
- Phone number
- Email address
- Emergency contact details
- Medical history
- Lifestyle, fitness level and goals
- Attendance records
- Any information within correspondence you send me
How do I use this information?
I will only process information that is necessary for the purpose for which it has been collected. You will always have the option not to receive marketing communications from me (and you can withdraw your consent or object at any time). I will never send you unsolicited ‘junk’ email or communications, or share your personal information with anyone else who might. I do not sell your information to third parties.
There are various ways in which I may use or process your personal information. I list these below:
Consent
Where you have provided your consent, I may use and process your information to contact you from time to time about promotions, events, products, services or information which I think may be of interest to you (don’t worry, I won’t bombard you). You can withdraw your consent at any time by contacting me at [email protected].
Contractual performance
I may use and process your personal information where this is necessary to perform a contract with you and to fulfil and complete your orders, purchases and other transactions entered into with me.
Legitimate Interests
I may use and process your personal information as set out below where it is necessary for me to carry out activities for which it is in my legitimate interests as a business to do so.
Processing necessary for me to support customers with sales and other enquiries
I will respond to correspondence you send to me and fulfil the requests you make to me (for example: trial class, class cancellation or transfer, etc.)
Processing necessary for us to respond to understanding customers’ needs
I may undertake market analysis and research (including contacting you with customer surveys) so that I can better understand you as a customer and provide tailored offers and services that I think you will be interested in, as well as using your feedback to improve my services. I will only send marketing communications to you if you have provided your consent for me to do so or which we have obtained in the ways mentioned in the paragraph below.
Processing necessary for me to promote my business and services
I may send you marketing information from time to time after you have purchased a service from me or made an enquiry. I will only contact you with information about my own services (and in ways the law allows), which I hope you will like. You have the right to object to me sending you this information at any time.
You may see my advertising delivered online through social media, unless you object by unfollowing me.
I may contact you when there are changes to the class timetable, or I move premises.
Processing necessary for me to operate the administrative and technical aspects of my business efficiently and effectively
To verify the accuracy of information that I hold about you and create a better understanding of you as a customer, comply with a request from you in connection with the exercise of your rights (for example where you have asked me not to contact you for marketing purposes, I will keep a record of this on our suppression lists in order to be able to comply with your request).
To inform you of updates to my terms and conditions and policies.
Legal Obligation
I may process your personal information to comply with my legal requirements (such as collecting, storing and referring to a PAR-Q).
Vital Interest
Sometimes I will need to process your personal information to contact you if there is an urgent change or update I need to tell you about it.
How do I share this information?
I do not sell your information to third parties.
I do not share your information with third parties unless necessary. Where this is necessary, I comply with all aspects of the Data Protection Act (DPA) and will only do so if I have your consent.
How long do I keep your information for?
I will not hold your personal information in an identifiable format for any longer than is necessary. If you are a customer or otherwise have a relationship with me, I will hold personal information about you for a longer period than if I have obtained your details in connection with a prospective relationship.
If I have a relationship with you (e.g. you are a client or were at some point), I hold your personal information for 6 years from the date our relationship ends. I hold your personal information for this period to establish, bring or defend legal claims.
Where I have obtained your personal information following a request for a trial class, quotation or any other information on my services, I hold your personal information for 1 year and 6 months from the date I collected that information, unless during that period I form a relationship with you e.g. you become a client by purchasing a Class Pass. I hold your personal information for this period to give me an opportunity to form a relationship with you.
The only exceptions to the periods mentioned above are where:
- the law requires me to hold your personal information for a longer period, or delete it sooner;
- you have raised a complaint or concern regarding a service offered by me, in which case I will retain your information for a period of 6 years following the date of that complaint or query; or
- you exercise your right to have the information erased (where it applies) and I do not need to hold it in connection with any of the reasons permitted or required under the law (see further How can you manage the information I hold about you).
How can you manage the information I hold about you?
You have the right as an individual to access your personal information I hold about you and make corrections if necessary. You also have the right to withdraw any consent you have previously given me and ask me to erase information I hold about you. You can also object to me using your personal information (where I rely on our business interests to process and use your personal information).
You have a number of rights in relation to your personal information under GDPR. You can:
1. ask for a copy of the information that I hold about you;
2. correct and update your information;
3. withdraw your consent (where I rely on it). Please see further How do I use this information.
4. object to my use of your information (where I rely on my legitimate interests to use your personal information) provided I do not have any continuing lawful reason to continue to use and process the information. When I do rely on my legitimate interests to use your personal information for direct marketing, I will always comply with your right to object.
5. erase your information (or restrict the use of it), provided I do not have any continuing lawful reason to continue to use and process that information
6. transfer your information in a structured data file (in a commonly used and machine readable format), where I rely on your consent to use and process your personal information or need to process it in connection with your contract.
You can exercise the above rights and/or manage your information by contacting me using the details below:
By email: [email protected]
By phone: 07948 395 010
If you have any specific data protection concerns or a complaint, you can address it to me at [email protected]
If you are unhappy, you have the right to lodge a complaint with a data protection regulator in Europe, in particular in a country you work or live or where your legal rights have been infringed. The contact details for the Information Commissioner’s Office, the data protection regulator in the UK, are below:
By post:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
By phone: 0303 123 1113
By email: [email protected]