Protecting your personal data
We are committed to safeguarding your personal information and we comply with all data protection laws including:
- The Data Protection Act 2018;
- The General Data Protection Regulation (GDPR); and
- Any regulations made under or to supplement either of the above, relating to the personal information that we collect about you
- What personal data we collect about you;
- Why we collect that personal data;
- Who we share your personal data with;
- Why we might contact you and how you can change that;
- How long we retain your personal data;
- How we keep your personal data secure; and
- What rights you have in relation to your personal data.
At Projekt 42 we are committed to protecting your privacy. We collect and process personal data about you to provide the services you use, operate our business, meet our contractual and legal obligations, protect the security of our systems and our customers, or fulfil other legitimate interests. Our Privacy Notice explains how we collect, use, share and protect your personal information. When we update this policy, we will post any changes on our website. In addition, when visiting our website, we will provide you with “just in time” notices at the moment of data collection. If you have any queries about this Notice please contact us at 117 Leith Walk, Edinburgh, EH6 8NP. Alternatively, send an email to email@example.com
Identity of data controller: The Data Controller in respect of this Privacy Notice is Projekt 42 SC045938.
When do we collect information?
We collect your personal information when you:
- Complete an Online Membership Agreement
- Book or attend an exercise class or lesson
- Ask us for more information about a product or service, or contact us with a question or complaint
- Take part in a competition, prize draw or survey
- Contact our Member Services support team through telephone, email or online chat
- Send an email to an @projekt42.co.uk email account
- You have an accident in our gyms or there was an incident where you were a witness or personally affected
- When you book classes, courses and inductions
- CCTV – when you are using our gyms (see the Projekt 42 CCTV Policy)
- When you use the Projekt 42 App
- When our teams take photos of your attendance at the gym, part of an event or in a class (Your permission will be asked beforehand)
When using our gyms CCTV is being recorded 24 hours a day and actively monitored throughout the day. CCTV is permanently erased after 90 days.
We may also collect, match or acquire information about you from other organisations such as Google and Facebook.
What information do we collect?
The information we collect is required for the purpose of creating your Member Account and for you to attend our wellness centre. Such information allows you to be identified as a member of Projekt 42 and includes:
- Name, date of birth, gender, e-mail address, postal address, telephone number, health declaration and whether you require disabled access
- Credit or debit card information, information about your bank account number and sort code or other banking information. Note that we do not store your bank or credit card details on our web servers
- Your usage records and duration of visits
- Your preferences for particular products or services or interests when you tell us what they are – or when we assume what they are, depending on how you use our products and services
- Your contacts with us, such as a note or recording of a call you make to our contact centre, an email or other records of any contact you have with us
- Your membership information – such as dates of payment owed and received, the services you use and any other information related to your account
How do we use this information?
We will use your personal information to provide you with the services, products or information that you have requested, for administration purposes, to improve your website experience, and marketing. We may need to share your information with our service providers, associated organisations and agents for these purposes. We may use your information to:
- Process your membership application through Clubright, our chosen membership software
- Bill you for using our services as part of your membership
- Keep you informed about our services including operational matters relating to your Membership
- Provide relevant services to you
- Confirm your attendance to exercise classes or lessons
- To allow you to monitor your gym usage in your member's area
- To share gym event photos on our internal social media platform called workplace (Your permission will be asked first before a picture is taken)
- Contact you with offers or promotions based on our analysis of how you use our services and what we think will be of interest to you (unless you choose not to receive our marketing messages)
- Respond to any questions or concerns you might have about our services
- Understand how you use our services, to help us develop relevant and updated services
- Carry out research and statistical analysis to monitor how customers use our services
- Prevent and detect fraud or other crimes
- Covid-19 Track & Trace - To help prevent the spread of infection around the UK we will support the NHS Track & Trace system. If requested by the NHS to provide visitor information, due to an outbreak in the vicinity of our gym, we will supply your name, mobile and time of arrival and departure for members who had recently visited the specific site. This is voluntary and you are able to request to have your data excluded. Please email us at firstname.lastname@example.org with your name and we will not pass your details on.
We’ll store your information for as long as you are a Member of Projekt 42, or the following cancellation and to meet legal requirements including financial audit, anti-fraud and money laundering regulations. We will store your information for no more than 6 years from the last activity on the account. An ‘activity’ can be classified as access into a gym, a payment made on the membership account or a comment added to the membership following contact with Projekt 42. We may contact you about Projekt 42 services during these 6 years if you haven’t opted out of receiving marketing communications from us.
Projekt 42 will only send you information relating to your membership. We will not share your data with any 3rd parties for marketing purposes. If you cancel your membership with Projekt 42 we will only send you information that we think will be of interest to you. If you want to opt-out of receiving marketing messages from us, please visit your profile section within the Members Area of the website. You can choose to opt-out of all marketing or select your marketing preferences. Alternatively, if you are no longer a member, and wish to remove your consent to receive marketing please contact by email to email@example.com
Keeping your personal information secure
We have a dedicated team whose function is to secure our clients’ information and also take appropriate measures to ensure that the information we collect and maintain is kept secure, accurate and up to date and kept only for so long as is necessary for the purposes for which it is used. We ensure the organisations that provide us with services related to your membership have appropriate security measures and only process your information in the way we have authorised them to. These organisations will not be entitled to use your personal information for their own purposes. Communications over the internet (such as emails) aren’t secure unless they’ve been encrypted. Your communications may go through a number of countries before being delivered – as this is the nature of the internet. We can’t accept responsibility for any unauthorised access or loss of personal information that’s beyond our control.
Will we disclose the information we collect to outside parties?
We may share information about you with:
- Service providers, agents and associated organisations to allow us to service your membership and communicate with you; for example, financial institutions to process payments, and freelance personal trainers when you sign up to classes
- Law enforcement agencies, regulatory organisations, courts or other public authorities where we have a legal obligation to do so
- Covid-19 Track & Trace - To help prevent the spread of infection around the UK we will support the NHS Track & Trace system. If requested by the NHS to provide visitor information, due to an outbreak in the vicinity of our gym, we will supply your name, mobile and time of arrival and departure for members who had recently visited the specific site. This is voluntary and you are able to request to have your data excluded. Please email us at firstname.lastname@example.org with your name and we will not pass your details on
We’ll release information if it’s reasonable for the purpose of protecting us against fraud, defending our rights or property, or to protect the interests of our customers.
If we’re reorganised or sold to another organisation, we may transfer any personal information we hold about you to that organisation. We will inform you if we do.
Use of personal data for automatic decision making
We do not intend to use your personal data for automatic decision making.
We use tools such as Google Analytics for collecting personal data about our website visitor’s online activities over time and across different web sites for marketing purposes. This is so we can ensure our website gives you the best possible experience.
Your privacy rights
You have the following rights in relation to your data privacy: the right of access; the right of rectification; the right of erasure (the “right to be forgotten”); the right to restriction of processing; the right to be notified; the right to data portability; the right of objection; and the right to not be subject to automated profiling.
Access. You have the right to ask for a copy of the information we hold about you and to have any inaccuracies in your information corrected. Please contact us through email to email@example.com, the contact us section of the website or writing to the address below. There is not normally a fee for this service.
Rectification. If you believe we’re holding inaccurate information about you, or your personal details change, please update your profile on the Projekt 42 website in the member’s area. Debit, Credit and Bank account changes can be made in your member's area on the Projekt 42 website.
Erasure. You have the right to the erasure of the data we hold on you, when it is no longer needed for the purposes of your Membership, or when you withdraw your consent for our processing (and we have no other lawful basis to hold your data).
Restriction. You have the right to ask us to place restrictions on processing your data in certain circumstances.
Notification. You have the right to be notified of any rectification, erasure or restrictions in relation to your personal data.
Portability. You have a right to receive the data we hold on you electronically in a format that allows it to be easily transferred to another data controller.
Object. You have the right to object to data processing of your personal data for direct marketing or profiling purposes.
Profiling. You have the right not to be subject to any decision based on automatic processing of your personal data.
The address to be used to obtain a copy of your personal information is: please contact us at 117 Leith Walk, Edinburgh, EH6 8NP. Alternatively, send an email to firstname.lastname@example.org