2. Information Collected or Received
3. How and why ETHOSGYMS use your Personal Information
4. Communication from ETHOSGYMS
5. Sharing your Information
6. Keeping your Information Secure
7. ETHOSGYMS Retention Policies
8. Staying in Control – Your Rights
ETHOSGYMS are based in the UK, however process personal information both within the UK/EEA and outside. Any personal information held by either ETHOSGYMS or the designated third parties complies with relevant EU GDPR legislations. Third parties which process personal information outside the UK/EEA on behalf of ETHOSGYMS have recognised equivalent legislation in places such as the US Privacy Shield, or a set of GDPR compliant Binding Corporate Rules (BCR).
- Information Collected or Received
ETHOSGYMS collect personal information from Members, Staff and Suppliers/Sub-contractors to run their business and provide you with their services. This personal information may include the following: name, date of birth, email address, contact number, company name, bank details and credit card details.
ETHOSGYMS also collect the following information:
Sensitive Information: The term “sensitive information” in this context refers to information related to your racial or ethnic origin, political opinions, religion or other beliefs, health, criminal background or trade union membership. Whilst ETHOSGYMS do not generally collect sensitive information unless it is volunteered by you, ETHOSGYMS do have a legal requirement to collect health data for the purpose of recording your self-assessment declaring readiness for physical exercise.
Photographs and Identification: In the interests of security and the prevention of crime, ETHOSGYMS may take a digital photograph of each Member or guest. Each Member or guest may also be required to provide a form of identification for verification and security purposes.
Audio-Video: ETHOSGYMS use CCTV in all gyms for health and security reasons. If you have any queries in relation to the use of CCTV operating in and around the gyms please contact email@example.com. ETHOSGYMS have a business legitimate interest to monitor service standards in Gym. ETHOSGYMS utilise mystery shopper services in which gym users may appear in the background however are never directly filmed. This footage is only used for the purposes of internal monitoring and training of ETHOSGYMS staff.
Digital: When visiting ETHOSGYMS website(s), your personal information may be collected, stored and used such as traffic data, location data, weblogs, communication data and resources that you access, as well as other personal information detailed above. If you connect to ETHOSGYMS or register for a tour of ETHOSGYMS using an external third-party application, such as Facebook, Instagram, or Twitter, these websites will have their own privacy statement which ETHOSGYMS suggest that you read before giving them your personal information. Connecting to ETHOSGYMS via a third-party application or service is optional and at your own discretion.
ETHOSGYMS will only collect the relevant information required for the purposes of processing and will not use this information for any other purpose without obtaining consent.
- How and why ETHOSGYMS use your Personal Information
The information in the above, section 2, may be used for the following purposes:
– To carry out ETHOSGYMS’s obligations arising from any contractual agreement;
– To contact you about non-contract aspects of your Membership, such as a change in usage patterns;
– To provide you with the information on products or services you request;
– To process payments and maintain accounts and records;
– To prevent crime, fraud and aid in the prosecution of offenders;
– To maintain membership records;
– To improve the ETHOSGYMS platform;
– To prevent or detect abuses of the ETHOSGYMS website;
– To create business performance statistics and analysis;
– To enable third parties to carry out technical, logistical, research or other functions on behalf of ETHOSGYMS;
– To send you newsletters and promotions, prize draws, and competitions;
– To conduct surveys and request feedback;
– To notify you about urgent comms such as a sudden closure of a Gym;
– To process your job application if you apply for employment at ETHOSGYMS;
– To collect information about your tastes and preferences, both when you tell us and by analysis of customer traffic, including using “cookies”;
– To read and respond to comments made regarding ETHOSGYMS services.
- Communication from ETHOSGYMS
On occasion, ETHOSGYMS may need to contact you. Primarily, these messages are delivered by email, text or phone, and every individual’s record is required to keep a valid email address and contact number on file to receive these messages.
In response to enquiries and when communicating with Members, ETHOSGYMS believe that the content is relevant, valuable, interesting and beneficial to you. ETHOSGYMS also believe that you would reasonably expect to receive the type of content that is sent to you as part of your relationship with ETHOSGYMS. Therefore, ETHOSGYMS’s current assessment is that the communication you receive is covered by the lawful basis for the processing of ‘Legitimate Interest’ under recital 47 within the GPDR. For all communication sent under the basis of legitimate interest, opt-out options are provided and detailed later within this section.
For all communication where consent is the only legal basis, preferences will be collected in advance.
ETHOSGYMS recognise that you value having control over your own information, so ETHOSGYMS gives you the choice of editing your communication preferences if you disagree with the above. For ETHOSGYMS Members and Ex-Members you may update these preferences by logging into the Members area through the login page of the website, (www.ETHOSGYMS.com). Alternatively, you may email firstname.lastname@example.org with your request.
Please note the following messages from ETHOSGYMS fall into the category of compulsory communication and therefore no opt-out options are available:
– Urgent Communication (such as unplanned closure of all or part of a Gym, reduced services, a change of opening times)
– Automatic Class Booking communication (such as booking confirmation, waiting list movement, cancellations)
– Contract and Subscription related communication (such as welcome emails, outstanding arrears, upcoming renewals, communication with the ETHOSGYMS Member Services Support Team).
You may receive communication from ETHOSGYMS via the following communication systems, all of which offer an opt-out service. Please note you must opt-out of each individual communication system should you wish to exercise that right;
Direct email communication from ETHOSGYMS staff via Outlook: To opt-out you can do either of the following, log into the member’s area on the website to update your communication preferences within the My Profile section. You can also request this specifically to email@example.com
- Sharing your Information
Arrears Collection: ETHOSGYMS reserves the right to forward a members information to a third party debt collection agency in the event of non-payment of fees when due. Further information on this process can be found in ETHOSGYMS Terms and Conditions.
ETHOSGYMS may share Member details with any organisation that acquires a Gym to which the Member has their Membership.
- Keeping your Information Secure
In regards to environmental and physical security, all ETHOSGYMS employees receive full training upon commencement of employment and subsequently on an annual basis thereafter. This is completed via an e-learning platform and group training sessions. Further to this, daily, weekly and monthly audits are completed.
- ETHOSGYMS Retention Policies
ETHOSGYMS have set company retention policies in place and these timescales are set in accordance with any applicable legislation and/or for any agreed legitimate reasons. Where none exists, then ETHOSGYMS will keep your information for the duration of any contract that you have entered into with ETHOSGYMS, and then for a period of 7 years after, at which time all the personal information will be pseudonymised.
After that 7 year duration, ETHOSGYMS will retain and use your pseudonymised information for the purpose of business statistics and analysis. ETHOSGYMS can retract this pseudonymisation to the extent necessary to comply with any legal obligations or to resolve disputes
- Staying in Control – Your Rights
ETHOSGYMS understand the importance of data subjects remaining in control of their personal data. ETHOSGYMS acknowledge the following rights you have under the GDPR, what they mean and how you can exercise them.
The Right to be Informed
The Right of Access
You have the right to access information that ETHOSGYMS hold about you. If you wish to receive a copy of the information that ETHOSGYMS hold, please submit a Subject Access Request form (SAR) which you can request from .firstname.lastname@example.org. Once ETHOSGYMS have received your form, they will provide a response within one month. If your request is unusually complex and likely to take longer than a month, you will be informed as soon as possible to tell you how long it’s likely to take.
Please note that whilst in most cases ETHOSGYMS will be happy to provide you with copies of the information you request, ETHOSGYMS nevertheless reserve the right, in accordance with section 8(2) of the DPA, not to provide you with copies of the information requested if to do so would take “disproportionate effort”, or in accordance with Article 12 of the GDPR to charge a fee or refuse the request if it is considered to be “manifestly unfounded or excessive”.
The Right to Rectification, Restrict Processing, Erasure, and to Object
You can ask ETHOSGYMS at any time to change, amend or pseudonymise the information that ETHOSGYMS hold about you or restrict ways in which your data may be processed. You can update ETHOSGYMS with amendments of personal information by submitting a request through the member services area of our website.
To pseudonymise the information, or object/request restriction of processing then please email email@example.com
ETHOSGYMS will aim to respond to any request as soon as possible, but no later than 1 month since receipt of the request. Please note that the right to erasure is not absolute and only applies in certain circumstances. For further information on this please visit the following link to the ICO’s website, https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure/
Right to Data Portability
You have the right to request that your personal data is transferred by ETHOSGYMS to another organisation (this is called “data portability”). Please contact us at firstname.lastname@example.org with the details of what you would like for ETHOSGYMS to do and ETHOSGYMS will endeavour to comply with your request. It may not be technically feasible, but ETHOSGYMS will work with you to try and find a possible solution.
Right to Prevent Automated Decision Making
You have a right to ask ETHOSGYMS to stop any automated decision making. ETHOSGYMS do not intentionally carry out such activities, but if you do have any questions or concerns ETHOSGYMS would be happy to discuss them with you so please email any concerns or queries to email@example.com
If you have any questions, comments or concerns about data privacy at ETHOSGYMS, please e-mail through a description to firstname.lastname@example.org and ETHOSGYMS will endeavour to resolve the issue for you. Alternatively, should you wish to escalate any concerns or questions, rather than contact ETHOSGYMS directly, please contact the supervisory authority The Information Commissioner’s Office (ICO). For more information please visit the ICO’s website https://ico.org.uk/.