Vitality Fitness Tavistock - Privacy Policy
Effective Date: 9th October 2024
Vitality Fitness Tavistock (“VFT”, “we”, “us” or “our”) is committed to protecting the privacy and personal data of our members, prospective members, visitors and other individuals who interact with us.
This Privacy Policy explains what personal data we collect, how and why we use it, the lawful bases we rely upon, who we may share it with, how long we retain it, and the rights available to you under applicable UK data-protection law, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and other applicable UK data-protection legislation, as amended from time to time.
We aim to handle personal data fairly, lawfully, securely and transparently.
1. Who We Are
The data controller responsible for your personal data is:
Vitality Fitness Tavistock Ltd
Company No. 15505902
Pixon Lane, Tavistock, Devon, PL19 9AZ
Email: hello@vitalityfitnesstavistock.com
Telephone: 01822 366335
If you have any questions about how we use your personal data, wish to exercise your rights, make a Subject Access Request or raise a data-protection concern, please contact us using the details above.
2. Personal Data We Collect
Depending on how you interact with us, we may collect and process the following categories of personal data.
2.1 Membership and Identity Information
This may include:
- your name;
- date of birth;
- postal address;
- email address;
- telephone number;
- membership number or account identifier;
- membership type and status;
- membership start date;
- renewal information;
- suspension information;
- cancellation information; and
- other information provided during registration or membership administration.
We use ClubRight as our membership-management software. Personal data relating to your membership, account, communications, attendance, payments and access may therefore be processed through ClubRight where applicable.
2.2 Payment and Transaction Information
We may process information relating to:
- membership payments;
- Direct Debit arrangements;
- transaction history;
- payment status;
- failed or overdue payments;
- refunds; and
- billing information.
We use London & Zurich to administer and collect Direct Debit payments on our behalf.
Where a third-party payment provider processes your payment information, we may not hold your complete banking or card details directly.
2.3 Health and Fitness Information
Where relevant and voluntarily provided, we may collect health-related information including:
- medical conditions;
- injuries;
- disabilities;
- accessibility requirements;
- information relevant to safe participation in exercise;
- information provided through health questionnaires; and
- information you choose to disclose to staff regarding your health or fitness.
Health information may constitute special-category personal data under UK data-protection law.
Where we process special-category health information, we will only do so where we have:
- an appropriate lawful basis under Article 6 UK GDPR; and
- an appropriate additional condition under Article 9 UK GDPR.
We only collect health information where it is relevant and necessary for a legitimate purpose.
2.4 Gym Usage, Attendance and Access-Control Information
We may collect information relating to your use of our premises and facilities, including:
- gym entry and exit information;
- membership check-ins;
- door-entry records;
- access-control records;
- attendance dates and times;
- sign-in information;
- attempted or unsuccessful access;
- membership-app information associated with access; and
- access permissions.
2.5 CCTV and Video-Surveillance Information
We operate CCTV and video surveillance in and around certain areas of our premises.
Where an individual can be identified from CCTV footage, that footage constitutes personal data.
Further information about our use of CCTV is set out in Section 8.
2.6 Communications
We may process communications between you and VFT, including:
- emails;
- telephone communications;
- text messages;
- WhatsApp messages;
- social-media messages;
- website enquiries;
- complaints;
- feedback; and
- other correspondence.
2.7 Access, Complaint, Audit and Conduct Information
Where necessary for the operation and management of the gym, we may create or retain records relating to:
- health and safety matters;
- access-control issues;
- unauthorised access;
- alleged breaches of membership terms;
- alleged breaches of gym rules;
- complaints and concerns;
- access reviews;
- staff observations;
- audit records;
- notes and internal records; and
- actions taken following a review or follow-up.
These records may contain personal data relating to members, visitors or other identifiable individuals.
2.8 Website and Technical Information
When you use our website or other digital services, we may collect information such as:
- IP address;
- browser type;
- device information;
- access times;
- pages viewed;
- cookie identifiers; and
- other technical or usage information.
3. Where We Obtain Your Personal Data
We normally obtain personal data directly from you when you:
- join the gym;
- manage your membership;
- contact us;
- use our facilities;
- make a payment;
- complete a form;
- communicate with our staff;
- submit an enquiry or complaint; or
- otherwise interact with us.
We may also obtain or generate personal data from:
- ClubRight;
- access-control systems;
- door-entry systems;
- CCTV systems;
- London & Zurich;
- payment processors;
- members of staff;
- personal trainers;
- contractors acting on our behalf;
- another member or visitor who provides relevant information;
- service providers;
- insurers;
- professional advisers;
- law-enforcement bodies; and
- public authorities where appropriate.
Where personal data is obtained from another source, we will only process it where we have an appropriate lawful basis.
4. Why We Use Your Personal Data
4.1 Membership Administration
We use personal data to:
- create and maintain your membership;
- provide access to the gym;
- administer renewals;
- administer suspensions;
- process cancellations;
- manage payments;
- provide membership services; and
- communicate with you about your membership.
The lawful basis will normally be that processing is necessary for the performance of our contract with you, or to take steps at your request before entering into a contract.
4.2 Access to and Management of Our Facilities
We may use membership, attendance and access-control information to:
- provide authorised entry;
- confirm membership status;
- maintain attendance information;
- identify access-control issues;
- investigate possible unauthorised access;
- maintain facility security;
- support health and safety;
- help us understand who is entering the building;
- manage membership access; and
- administer and enforce membership arrangements.
Our lawful basis may be:
- performance of our contract with you; and/or
- our legitimate interests in operating a safe, secure and properly managed fitness facility.
4.3 Safety, Security and Access Management
We may process personal data to:
- protect members, staff and visitors;
- protect our premises and property;
- prevent or investigate crime;
- respond to accidents or safety matters;
- respond to security concerns;
- investigate complaints;
- manage health and safety matters;
- support safeguarding;
- respond to emergencies; and
- establish, exercise or defend legal claims.
Our lawful basis may include:
- our legitimate interests;
- compliance with a legal obligation;
- protection of vital interests; or
- another lawful basis available under UK data-protection law.
4.4 Gym Rules, Membership Conduct and Access Auditing
Where reasonably necessary, we may process personal data to:
- investigate potential breaches of membership terms;
- investigate potential breaches of gym rules;
- investigate possible unauthorised entry;
- identify or clarify access matters;
- maintain access-review records;
- maintain audit records;
- protect members and staff;
- ensure fair and consistent operation of the gym; and
- respond to disputes or complaints.
Our lawful basis will normally be our legitimate interests in protecting our premises, members, staff and business and in operating the gym safely and effectively.
4.5 Communications
We use your contact information to:
- respond to enquiries;
- provide customer service;
- send important membership information;
- notify you about operational matters;
- communicate about payments;
- respond to complaints; and
- manage your relationship with us.
This processing may be necessary for our contract with you or for our legitimate interests in communicating effectively with members and customers.
4.6 Marketing
Where permitted by law, we may contact you about:
- services;
- promotions;
- events;
- membership offers;
- gym updates; and
- relevant news.
Where consent is required, we will obtain it before sending marketing communications.
You may opt out of marketing communications at any time.
4.7 Health and Safety Information
Where you provide health-related information, we may use it where necessary to:
- support safe participation in gym activities;
- respond to a health and safety concern;
- make reasonable adjustments;
- deal with an emergency; or
- protect your vital interests or those of another person.
Where health data constitutes special-category data, we will identify and document an appropriate Article 6 lawful basis and Article 9 condition before processing it.
4.8 Legal and Regulatory Requirements
We may process personal data where necessary to:
- comply with applicable law;
- comply with regulatory obligations;
- respond to legally valid requests;
- cooperate with regulators;
- cooperate with law-enforcement agencies;
- maintain financial records;
- maintain tax and accounting records; or
- establish, exercise or defend legal claims.
5. Our Legitimate Interests
Where we rely on legitimate interests, those interests may include:
- operating a safe and secure gym;
- protecting members, staff, visitors and property;
- helping us understand who has entered the premises;
- preventing and investigating misuse of our facilities;
- controlling access to the premises;
- preventing unauthorised access;
- carrying out routine access reviews;
- investigating complaints;
- enforcing membership terms;
- enforcing gym rules;
- maintaining appropriate audit records;
- protecting our business from fraud, misuse or unlawful activity;
- maintaining effective business operations; and
- improving our services and facilities.
Where we rely on legitimate interests, we consider whether the processing is:
- necessary for the relevant purpose;
- proportionate;
- reasonably expected; and
- balanced against the rights and interests of the individuals concerned.
6. Special-Category Personal Data
Certain types of personal data receive additional legal protection. This includes information concerning a person's physical or mental health.
Where we process special-category personal data, we will ensure that:
- an appropriate Article 6 lawful basis applies;
- an appropriate Article 9 condition applies;
- the information is relevant to the purpose;
- access is restricted appropriately; and
- it is retained only for as long as necessary.
We do not currently use facial-recognition technology or biometric identification through our CCTV systems.
7. Access-Control and Attendance Information
Our membership, app, door-entry or access-control systems may record when members access or attempt to access the gym.
We may use this information for:
- granting authorised access;
- verifying attendance;
- supporting health and safety;
- helping us understand who is in the building;
- security;
- identifying access problems;
- reviewing possible unauthorised access;
- resolving membership issues;
- carrying out access audits; and
- enforcing membership terms or gym rules.
Where reasonably necessary to review or clarify a particular access matter, access-control information may be considered alongside other relevant information, including:
- ClubRight membership records;
- attendance records;
- CCTV footage;
- staff observations;
- customer communications;
- complaints; and
- audit records.
Any such review will be limited to what is reasonably necessary for the relevant purpose.
8. CCTV and Video Surveillance
8.1 Why We Use CCTV
VFT operates CCTV and video surveillance in and around relevant areas of our premises for purposes including:
- protecting the safety of members, staff and visitors;
- supporting health and safety;
- supporting safeguarding;
- helping us understand who has entered the building;
- preventing and detecting crime;
- protecting property;
- maintaining security;
- managing access to the premises;
- reviewing possible unauthorised access;
- investigating complaints or security concerns; and
- where reasonably necessary, reviewing potential breaches of gym rules or membership terms.
8.2 Lawful Basis for CCTV
Our principal lawful basis for processing CCTV footage is normally our legitimate interests in maintaining the safety, security and effective management of our premises.
CCTV information may also be processed where necessary to:
- comply with a legal obligation;
- respond to a lawful request;
- establish, exercise or defend a legal claim; or
- protect the vital interests of an individual in appropriate circumstances.
8.3 How CCTV Is Monitored
CCTV is not used for continuous monitoring or tracking of individual members as part of their normal gym use.
Footage may, however, be reviewed where there is a specific and legitimate reason to do so, including:
- routine access-control checks;
- an access query;
- possible unauthorised entry;
- a safety concern;
- a safeguarding concern;
- an accident;
- a complaint;
- suspected theft or criminal activity;
- damage to property; or
- a suspected breach of membership terms or gym rules.
Any review of footage will be limited to what is reasonably necessary and proportionate for the relevant purpose.
8.4 Access Reviews and CCTV
As part of our routine access-control checks, authorised staff may review CCTV footage to help ensure that individuals entering the gym have valid access.
Where another person appears to enter immediately behind a member without separately scanning or signing in, VFT may contact the member to clarify the circumstances and remind them of the correct access procedure.
Members may be asked, where appropriate, to ensure that the entrance door closes behind them and to direct any other person entering the premises to use their own valid QR code, membership access or appropriate pass.
The fact that another person enters close behind a member will not, by itself, be treated as conclusive evidence that the member knowingly facilitated unauthorised access.
Where appropriate, the member may be given an opportunity to clarify the circumstances before any further action is taken.
8.5 Cross-Referencing CCTV With Other Records
Where reasonably necessary to review or clarify a particular access, safety or security matter, CCTV footage may be considered alongside other relevant information, including:
- membership records;
- ClubRight records;
- attendance information;
- door-entry records;
- access-control information;
- staff observations;
- customer communications;
- complaints; and
- audit records.
This may include identifying which membership account accessed the premises at a particular time where necessary to review an access or security matter.
We will only combine or compare information where there is a legitimate reason to do so.
8.6 Records Created From CCTV and Access Reviews
Where CCTV footage is reviewed in relation to an identifiable individual, we may create:
- an access-review record;
- an audit record;
- a follow-up note;
- a complaint record;
- a security record; or
- another internal record summarising relevant information.
Where such a record identifies an individual, it constitutes personal data and will be handled in accordance with this Privacy Policy.
Where possible, internal access-review records may use a member number rather than the member’s name in order to minimise the amount of identifying information recorded.
A member number remains personal data where it can be linked back to an identifiable member and will therefore be protected accordingly.
8.7 Who Can Access CCTV
Access to CCTV systems and footage is restricted to authorised persons who have a legitimate reason to access it.
We take reasonable measures to prevent:
- unauthorised access;
- inappropriate disclosure;
- alteration;
- accidental loss; and
- misuse.
8.8 CCTV Retention
CCTV footage is retained only for as long as reasonably necessary for the purposes for which it was collected.
Our CCTV recording system may automatically overwrite recordings as part of its normal operation. The length of time that routine footage remains available may therefore depend on the operation and storage capacity of the CCTV system.
Where CCTV footage is identified as relevant to a particular matter, VFT may temporarily save or retain a clip for purposes including:
- an access-control query;
- possible unauthorised access;
- a safety or security matter;
- safeguarding;
- a complaint;
- an investigation;
- an insurance matter;
- a legal matter;
- a law-enforcement request; or
- a Subject Access Request.
Where a clip is temporarily saved for an access-control review or similar operational purpose, it will only be retained for as long as reasonably necessary to complete that follow-up.
Once the purpose for retaining the footage has concluded, and there is no other legitimate reason for it to be retained, the saved footage may be securely deleted.
Before removing a temporarily saved CCTV clip, VFT may check whether:
- the access query or follow-up has been completed;
- there is an ongoing complaint or request relating to the footage; or
- there is another reason why the footage needs to be retained.
Where VFT becomes aware that particular CCTV footage is relevant to an active complaint, Subject Access Request, investigation, legal matter, insurance matter or safeguarding concern, appropriate steps may be taken to preserve the footage while that matter is being handled.
We periodically review our CCTV retention arrangements to ensure footage is not retained for longer than reasonably necessary.
8.9 Disclosure of CCTV
We may disclose relevant CCTV footage where lawful and necessary to:
- the police;
- other law-enforcement agencies;
- insurers;
- solicitors or other professional advisers;
- courts;
- regulatory authorities;
- CCTV or security service providers acting on our behalf; or
- another organisation where disclosure is legally required or otherwise lawful and necessary.
We will not routinely disclose CCTV footage to third parties.
8.10 CCTV Signage and Transparency
Appropriate CCTV signage is displayed at or around areas covered by surveillance.
Our signage is intended to make individuals aware that:
- CCTV is in operation;
- Vitality Fitness Tavistock is responsible for the surveillance;
- footage is used for safety, security and access-management purposes; and
- further information about our processing is available through this Privacy Policy.
9. Sharing Your Personal Data
We may share personal data where necessary with service providers and other organisations, including:
- ClubRight, our membership-management software provider;
- London & Zurich, which administers Direct Debit collections on our behalf;
- payment processors;
- IT and software providers;
- website and hosting providers;
- communications providers;
- CCTV providers;
- security providers;
- access-control providers;
- accountants;
- solicitors and other professional advisers;
- insurers;
- contractors acting on our behalf;
- law-enforcement agencies;
- courts;
- regulators; and
- public authorities where required or permitted by law.
Where another organisation processes personal data on our behalf, we take reasonable steps to ensure appropriate data-protection arrangements are in place.
Some organisations may act as independent data controllers for certain processing. Where applicable, their own privacy notices will explain how they process personal data.
We do not sell personal data.
10. International Transfers
Some of our suppliers or service providers may store or process personal data outside the United Kingdom.
Where personal data is transferred outside the UK, we will take reasonable steps to ensure that:
- the transfer is lawful;
- appropriate safeguards are in place; and
- the personal data continues to receive an appropriate level of protection.
Safeguards may include:
- UK adequacy regulations;
- approved contractual safeguards; or
- another lawful transfer mechanism recognised under UK data-protection law.
You may contact us for further information about any safeguards that apply.
11. How Long We Keep Personal Data
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected or subsequently retained.
When determining retention periods, we consider:
- our contractual obligations;
- legal requirements;
- regulatory requirements;
- tax and accounting requirements;
- health and safety requirements;
- security requirements;
- potential complaints;
- potential legal claims;
- dispute-resolution requirements; and
- legitimate business needs.
Examples include:
- Membership records: retained throughout the membership and for an appropriate period afterwards where necessary for legal, contractual, accounting or dispute-resolution purposes;
- Financial and transaction records: retained in accordance with applicable accounting and tax requirements;
- CCTV footage: routine CCTV recordings are retained only for as long as reasonably necessary and may be automatically overwritten through the normal operation of our CCTV system. Where a specific clip is temporarily saved for an access-control, safety, security, safeguarding or other legitimate purpose, it will be retained only for as long as reasonably necessary for that purpose and will then be securely deleted unless there is a continuing reason to retain it;
- Access-control and attendance records: retained for as long as reasonably necessary for membership administration, safety, security, auditing and dispute resolution;
- Access-review and audit records: retained for as long as reasonably necessary to manage the access matter and any related membership, complaint, legal, regulatory or insurance issues;
- Complaint records: retained for as long as reasonably necessary to manage and respond to the complaint and any related legal or regulatory matters;
- Communications: retained for as long as reasonably necessary for the purpose of the communication and any associated membership, complaint, dispute or legal matter;
- Marketing information: retained until consent is withdrawn, an objection is made, or the information is no longer required.
We periodically review the personal data we retain and securely delete or anonymise information that is no longer necessary.
12. Data Security
We take appropriate technical and organisational measures to protect personal data against:
- unauthorised access;
- accidental loss;
- inappropriate disclosure;
- alteration;
- destruction; and
- misuse.
Measures may include:
- passwords;
- restricted user permissions;
- access controls;
- secure systems;
- staff procedures;
- secure storage;
- appropriate contracts with service providers; and
- limiting access to information to persons who need it for their role.
While no security system can guarantee absolute security, we take reasonable and proportionate steps to protect the information entrusted to us.
13. Your Data-Protection Rights
Depending on the circumstances and the lawful basis relied upon, you may have the following rights.
13.1 Right of Access
You may ask us to confirm whether we process your personal data and request access to that personal data.
13.2 Right to Rectification
You may ask us to correct personal data that is inaccurate or complete information that is incomplete.
13.3 Right to Erasure
In certain circumstances, you may ask us to delete your personal data.
This right is not absolute and may not apply where we are legally entitled or required to retain the information.
13.4 Right to Restrict Processing
In certain circumstances, you may ask us to restrict how your personal data is processed.
13.5 Right to Data Portability
Where applicable, you may have the right to receive certain personal data in a structured, commonly used and machine-readable format or ask for it to be transferred to another organisation.
13.6 Right to Withdraw Consent
Where we rely upon your consent, you may withdraw that consent at any time.
Withdrawal will not affect processing that was lawful before the consent was withdrawn.
13.7 Right to Object
You may have the right to object to processing based upon our legitimate interests.
You also have the right to object at any time to the use of your personal data for direct marketing.
13.8 Automated Decision-Making
You may have rights relating to certain decisions made solely by automated means where those decisions produce legal or similarly significant effects.
VFT does not currently use solely automated decision-making or profiling that produces legal or similarly significant effects in relation to members.
14. Providing Personal Data to Us
Certain personal data is necessary for us to provide membership services.
For example, we may need your:
- name;
- contact information;
- membership information;
- payment information; and
- information necessary to provide access to the premises.
If you do not provide information that is necessary for us to enter into or perform our membership agreement with you, we may be unable to provide some or all of our services.
Other information may be optional, and we will make this clear where appropriate.
15. Subject Access Requests
You have the right to request access to personal data we hold about you.
A Subject Access Request may include personal data contained within:
- ClubRight records;
- membership records;
- attendance records;
- access-control information;
- door-entry information;
- communications;
- complaint records;
- access-review records;
- audit records; and
- CCTV footage in which you are identifiable, where that footage is still held by VFT at the time of the request.
Where information also contains personal data relating to another individual, we may need to:
- redact information;
- consider whether consent is appropriate; or
- withhold certain information where permitted or required by law.
We may ask you for reasonable information necessary to:
- confirm your identity; or
- help us locate the information you are requesting.
We will respond to valid Subject Access Requests within the timeframe required by applicable data-protection law.
Where requested personal data is no longer held because it was deleted or overwritten before the request was received in accordance with our normal retention arrangements, we will explain this where appropriate.
16. Preservation of Information Relating to Requests or Complaints
Where we become aware that particular personal data is relevant to:
- a Subject Access Request;
- a complaint;
- an ongoing review;
- anticipated legal proceedings;
- an insurance claim;
- a safeguarding matter; or
- a regulatory matter,
we may take reasonable steps to preserve relevant information and prevent its routine deletion or overwriting while the matter is being handled.
This may include preserving relevant CCTV footage beyond the period for which it would otherwise have been retained.
17. Complaints
If you have concerns about how we have handled your personal data, please contact us so that we have an opportunity to investigate and respond.
Vitality Fitness Tavistock Ltd
Pixon Lane
Tavistock
Devon
PL19 9AZ
Email: hello@vitalityfitnesstavistock.com
Telephone: 01822 366335
You also have the right to raise a concern with the Information Commissioner's Office (ICO), the UK's data-protection regulator.
Further information is available at www.ico.org.uk.
18. Cookies and Tracking Technologies
Our website may use cookies and similar technologies to:
- operate the website;
- remember preferences;
- understand website usage;
- improve our services; and
- where applicable, support marketing activities.
Where consent is legally required for non-essential cookies, we will request consent before those cookies are placed.
You can manage cookies through our website cookie controls and through your browser settings.
19. Children and Young People
Where we provide services to children or young people, we take appropriate steps to ensure that their personal data is handled fairly, securely and transparently.
We take account of:
- the individual's age;
- their understanding of how their information is used;
- the nature of the services being provided; and
- whether parental or guardian involvement is appropriate or required.
Where parental or guardian involvement is required, we will take appropriate steps to obtain the necessary information or permissions.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to our services;
- changes to our systems;
- changes to how we process personal data;
- changes to suppliers or service providers;
- changes in legal or regulatory requirements; or
- improvements to our privacy practices.
The latest version will display its version number and effective date.
Where we introduce a materially new use of personal data, we will update our privacy information and take reasonable steps to inform affected individuals where required.
Previous versions of this Privacy Policy will be retained internally so that we can identify which version applied at a particular time.
21. Contact Us
For questions about this Privacy Policy, requests relating to your personal data, Subject Access Requests or data-protection complaints, please contact:
Vitality Fitness Tavistock Ltd
Pixon Lane, Tavistock, Devon, PL19 9AZ
Email: hello@vitalityfitnesstavistock.com
Telephone: 01822 366335