This privacy notice describes how HA fitness Ltd (referred to as “we”, “us” or “our”) collects and processes personal information about you, including how we use and protect this information.
HA fitness Ltd is the data controller and we are responsible for your personal data. By providing us with your data, you warrant to us that you are over 16 years of age. It is very important that the information we hold about you is accurate and up to date. Please let us know if at any time your personal information changes by contacting us.
This privacy notice provides you with details of how we collect and process your personal data through this website, including any information you may provide when you purchase a product or service, sign up to our newsletter or take part in a prize draw or competition. It also includes the information we collect from you directly including when you contact us via email, telephone, SMS, social media, surveys or our health questionnaires.
Data Collection And Processing
We may collect data about you in a number of difference ways:
- By you providing the data directly to us (for example by filling in forms or by sending us emails)
We may receive data about you from third parties including:
- Analytics providers, such as Google
- Advertising networks, such as Facebook
- Search information providers, such as Google
- Providers of technical, payment and delivery services, such as PayPal
- Website hosting providers, such as Squarespace
The following details how we collect and process different the types of data.
1.1 Data Collected Directly From You
This includes the communication data we collect when you contact us for example by email, telephone, text, on our website, social media messaging, social media posting or any other communication that you send us. It also includes the data you provide when you complete one of our health questionnaire forms. This data may include your:
- Personal details (including name, date of birth)
- Contact details (including phone number, email address and postal address)
- Health and medical details (including information about injuries, health issues, pregnancies, medication and hospitalisation)
- Current and historical activity and fitness levels
- Emergency contact name and phone number (you must obtain this person's consent to both the disclosure and the processing of that personal information in accordance with this privacy notice).
- Payment information
- Communication data
- Any other information that you choose to provide to us
Our lawful ground for collecting and processing this data is to:
- Reply to your communications, enquiries and requests
- Provide and personalise our products and services
- Monitor interest and about our products and services
- Keep records about our transactions
- Send you non-marketing communication containing important information about our products and services
- Contact you with marketing and offers relating to products and services offered by us
- Send payment reminders to you and collect payments from you
- Establish, pursue or defend legal claims
We specifically collect health data to the extent that it is required to assess your readiness for physical exercise. Our lawful ground for this processing, is to comply with legal obligations to which we are subject and to cooperate with regulators and law enforcement bodies.
1.2 Customer And Purchasing Data
This includes data relating to any purchases of goods and/or services such as your name, title, billing address, delivery address email address, phone number, contact details and purchase details.
Our lawful ground for this data processing is to:
- Supply the goods and/or services you have purchased
- Keep records of purchases and transactions
- Create a contract between you and us and/or taking steps at your request to enter into such a contract
- Recommend goods and services that maybe of interest to you, in which to grow our business
1.4 User Data
This includes data about how you use our website and any online services, together with any data that you post for publication on our website or through other online services.
Our lawful ground for processing this data is to:
- Operate our website and ensure relevant content is provided to you
- Ensure the security of our website and to maintain backups of our website and/or database
- Properly publish and administer our website and our business
1.5 Technical Data
This includes data about your use of our website and online services. The source of this data is from our analytics tracking system. Data collected includes:
- Your IP address and details about your browser
- Your length of visit to pages on our website, page views and navigation paths
- Details about the number of times you use our website
- Time zone and broad geographical location
- Technology about the devices you use to access our website
Our lawful ground for processing this data is to:
- Analyse your use of our website and other online services
- Administer, protect and grow our business and website
- Deliver relevant content to you
- Measure and understand the effectiveness of our website, marketing and advertising, and devise future marketing strategies.
1.5 Marketing Data
This includes data about your preferences in receiving marketing from us, and communicating with us. We process this data to enable you to partake in our promotions such as competitions, prize draws and free give-aways, to deliver relevant website content to you, and measure or understand the effectiveness of this advertising.
Our lawful ground for this processing is to:
- Enable you to partake in our promotions such as competitions, prize draws and free give-aways
- Deliver relevant website content to you
- Measure and understand the effectiveness of our marketing
- Grow our business and decide on our future marketing strategies
You will receive marketing communications from us, if you have made a purchase or asked for information from us about our goods or services, or if you are not a customer, you gave us your details and agreed to receive marketing communications. In each case you have not opted out of receiving such communications since.
We will never share your personal data with any third party for marketing purposes.
You can ask us to stop sending you marketing messages at any time by following the opt-out links included on all marketing message sent to you or by contacting us at any time.
If you opt out of receiving marketing communications, this opt-out does not apply to communication and your personal data required to support transactions, such as purchases.
1.6 Sensitive Data
We do not collect any data that includes details about your:
- Race or ethnicity, religious or philosophical beliefs
- Sex life or sexual orientation
- Political opinions or trade union membership
- Genetic and biometric data
- Criminal convictions and offences
Where we are required to collect personal data by law, or under the terms of the contract between us and you do not provide us with that data when requested, we may not be able to perform the contract (for example, to deliver goods or services to you). If you don’t provide us with the requested data, we may have to cancel a product or service you have ordered but if we do, we will notify you at the time.
We will only use your personal data for the purpose it was collected. For more information on this please contact us. In case we need to use your details for an unrelated new purpose, we will let you know and explain the legal grounds for processing.
Disclosures Of Your Personal Data
We may have to share your personal data with the following providers:
- Service providers who provide IT and system administration services
- Professional advisers including lawyers, bankers, auditors and insurers
- Government bodies that require us to report processing activities
- Bookeepers, accountants and administrators
We require all third parties to whom we transfer your data to respect the security of your personal data and to treat it in accordance with the law. We only allow such third parties to process your personal data for specified purposes and in accordance with our instructions.
We have put in place security measures to prevent your personal data from being accidentally lost, used, altered, disclosed, or accessed without authorisation. We also allow access to your personal data only to those employees and partners who have a business need to know such data. They will only process your personal data on our instructions and they must keep it confidential.
We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach if we are legally required to.
We will only retain your personal data for as long as necessary to fulfil the agreed purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
When deciding what the correct time is to keep the data for we look at its amount, nature and sensitivity, potential risk of harm from unauthorised use or disclosure, the processing purposes, if these can be achieved by other means and legal requirements.
In some circumstances, we may anonymise your personal data for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
International Data Transfer
Your personal data may be transferred to, stored, and processed in a country that is not regarded as ensuring an adequate level of protection for personal information under European Union Law / by the European Commission. By submitting your personal data, you agree to this transfer, storing or processing.
Your Legal Rights
Under data protection laws you have rights in relation to your personal data that include the right to request access, correction, erasure, restriction, transfer, to object to processing, to portability of data and (where the lawful ground of processing is consent) to withdraw consent.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive or refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you.
If you are not happy with any aspect of how we collect and use your data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (ico.org.uk). We should be grateful if you would contact us first if you do have a complaint so that we can try to resolve it for you.
Changes To This Policy
You may request a copy of this privacy notice from us using the contact details set out above. We may modify or update this privacy notice from time to time.
If we change this privacy notice, we will notify you of the changes. Where changes to this privacy notice will have a fundamental impact on the nature of the processing or otherwise have a substantial impact on you, we will give you sufficient advance notice so that you have the opportunity to exercise your rights (e.g. to object to the processing).
We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist with your complaint or concern, you have the right to make a complaint to the data protection authority of the United Kingdom using their website ico.org.uk.