Signed in as:
filler@godaddy.com
Signed in as:
filler@godaddy.com
PERSONAL DATA & PRIVACY POLICY
Pilates Empower provides Mat Pilates classes in venues in The Ribble Valley.
PERSONAL DATA AND PRIVACY In order for Pilates Empower to fulfil its function, I process personal data which relates to participants of classes and events. Pilates Empower is committed to maintaining the appropriate confidentiality, integrity and security of personal data that I process by complying with both legal and ethical obligations in respect of data protection and privacy. This policy sets out the principles Pilates Empower adheres to when processing personal data and outlines the operational aspect of the data processing activities.
I take the issue of security and data protection very seriously and strictly adhere to guidelines published in the General Data Protection Regulation (EU) 2016/679 which is applicable from the 25th May 2018, together with any domestic laws subsequently enacted. I am notified as a Data Controller with the Office of the Information Commissioner under registration number ZB679164 and I am the data controller of any personal data that you provide to me. Data Protection Officer is Emma Pourarian at Pilates Empower contactable at emma@pilatesempower.co.uk
WHAT PERSONAL DATA DO I COLLECT? Personal data is any information relating to an identifiable living individual. I collect information about individuals in three ways:
Personal/contact information: names, gender, contact (telephone, email, address, and dates of birth), as well as specific health details directly related to Pilates participants. These details are supplied to me by a participant on a pre-exercise health and consent questionnaire that all participants must complete for my insurance purposes prior to exercising and clients must proactively update the form if anything changes. The data on this questionnaire is held securely for the period during which the client attends classes.
Payment information: Payments or bookings are processed via the website through a secure booking system powered by Square enabling electronic payments by card. Clients have the option at point of booking if they wish to save card details in Square or not. Pilates Empower does not have access to any card details. If you wish to read Square’s full privacy policy, please visit their website: https://squareup.com/gb/en/legal/general/privacy
Newsletter: a regular newsletter may be sent from time to time to anyone who actively subscribes to it by entering their email address and name in the signup on the website. The newsletter mailing list of names and email addresses is maintained on web host GoDaddy. As subscribers sign up to the Newsletter themselves through the website signup, this ensures that subscribers have knowingly opted in to receive the newsletter. I do not add subscribers and I do not pass subscribers’ email details to any third party. Subscribers to the newsletter can opt-out of receiving the newsletter or change their preferences at any time by using the ‘Unsubscribe’ link at the bottom of each newsletter, or by contacting: emma@pilatesempower.co.uk
If individuals choose to supply any other information I handle this securely and treat it with appropriate confidentiality.
WHAT DO I DO WITH YOUR PERSONAL DATA? Pilates Empower will use the personal data provided on health questionnaires to give participants the most appropriate Pilates experience. I will also use the contact details supplied by participants on the health questionnaire to communicate with them for any information regarding their specific classes and sessions. For example, if a class is to be cancelled by adverse weather conditions or ill-health I will email, text, or call clients to let them know.
WHAT IS THE LEGAL BASIS FOR DATA PROCESSING? By law, Pilates Empower may only process personal data where it has a legal justification or requirement to do so. In accordance with that law, Pilates Empower processes personal data as described above because it is: Necessary for the performance of Pilates classes and sessions with participants: And/or necessary for the purposes of Pilates Empower’s legitimate interests, namely to fulfil its function as a Pilates service provider in accordance with applicable law and regulations and to conduct and manage the relationship with specific individuals. Where I use your personal data for Pilates Empower’ legitimate interests, I make sure that I consider any potential impact that such use may have on you. If I believe your interests or fundamental rights and freedoms override legitimate interests then I will not use your personal data on this basis and may seek your specific consent, and/or necessary for compliance with legal obligations.
Pilates Empower would not be able to fulfil its function and meet insurance requirements without processing personal data as described in this policy.
If you have any concerns about processing, please refer to details of “Your Rights in Relation to Personal Data” below.
YOUR RIGHTS IN RELATION TO PERSONAL DATAIndividuals whose personal data I process have certain rights in respect of that data, including:
RIGHT TO INFORMATION AND ACCESS — You have the right to request access to the information that I hold about you. In accordance with data protection laws, participants also have the right to receive a copy of any information I hold about them. On request, Pilates Empower will provide participants with copies of their personal data in a convenient format. Where technically feasible, Pilates Empower will also meet any participant’s request to transfer their data to a third party.
RECTIFICATION, ERASURE, AND RESTRICTION — You have the right to ask me to limit or cease processing or erase information I hold about you in certain circumstances. In responding to such requests, Pilates Empower will communicate to the individual concerned the impact of such restrictions or deletions, for example, on Pilates Empower’s ability to teach Pilates classes on their behalf. Pilates Empower takes reasonable steps to ensure that the personal data it holds about you is accurate and up-to-date and I will comply with any requests to rectify any inaccurate data I may hold about you. Requests for access to information regarding personal and financial information should be made in writing to emma@pilatesempower.co.uk, or by phone 01200 315633.
RIGHT TO OBJECT — You have the right to object to Pilates Empower using your information on the basis of its legitimate interests and the right to ask me not to process your personal data where relevant (see “What do I do with your personal data?” section above). Pilates Empower is committed to respecting individuals’ rights. You may action your rights by contacting me using the details provided above and I will comply with your requests unless I have a lawful reason not to do so. Pilates Empower will endeavour to handle any requests within a reasonable period and, in any event, within a month of the original request.
HOW PILATES EMPOWER MIGHT SHARE YOUR PERSONAL DATA Pilates Empower will only share personal data with third parties in the following 3 ways:
OTHER HEALTH PROFESSIONALS — with your express permission Pilates Empower will share relevant personal data with other health professionals, intended solely for your benefit.
SERVICE PROVIDERS AND SUPPLIERS — Pilates Empower may employ:
external IT consultants to provide support and development services in relation to Pilates Empower’s systems and databases. They may from time to time need to access information which may contain personal data for the purposes of systems testing and development.
third party providers to facilitate certain communications on its behalf, such as mail-outs providing notices of company meetings and elections, which requires them to access contact data. All such third parties are vetted by Pilates Empower to ensure they provide adequate levels of security when processing data.
GENERAL — In some circumstances, Pilates Empower may need to share your personal data where necessary with other third parties (including legal or other advisors, regulatory authorities, courts and government agencies) to enable me to enforce legal rights, or to protect the rights, property or safety of employees or where such disclosure may be permitted or required by law.
In all cases I require third parties to maintain appropriate security and confidentiality to protect information from unauthorised access or processing.
DATA SECURITY Pilates Empower will take appropriate technical and organisational measures to protect the personal data I transmit, store or otherwise process against accidental or unlawful destruction, loss, alteration or unauthorised disclosure or access. To this end, data stored on Pilates Empower computers and portable devices is password protected, and I do not send personal data of any participant over email. Any paper health questionnaire and consent forms are scanned into electronic format and stored on a database which is password protected. The paper forms are shredded. Unfortunately, as no data transmission over the Internet can be guaranteed to be 100% secure, Pilates Empower cannot guarantee the security of any Internet communication or transmission, though I strive to protect your personal data online, including through use of encryption and other measures. If you have reason to believe that your interaction with me is not secure, please notify me of the problem immediately by contacting me using the details below.
Prior to introducing new systems or technologies relevant to the processing of personal data, Pilates Empower will undertake the necessary impact assessments with a particular focus on any associated risks, and the system will be detailed here in the Personal and Data Privacy Policy.
HOW LONG DOES PILATES EMPOWER RETAIN PERSONAL DATA? Pilates Empower will only retain personal data for as long as is necessary to provide services or for as long as I reasonably require to retain the information for lawful business purposes or comply with a statutory or other legal requirement. Please contact me if you require further information about retention policies.
DATA BREACHES In the event of any breach of Pilates Empower systems impacting on the security of a participant’s or any other individual’s personal data, Pilates Empower will inform the affected participant(s) or individual(s) at the earliest opportunity describing the nature of the breach, the possible consequences and the measures being taken to remedy the situation in accordance with procedures and applicable law.
COMPLAINTS If you are unhappy with the way in which Pilates Empower processes your personal data, please contact me using the information provided below. You also have the right to lodge a complaint before the Information Commissioner’s Office (ICO), which is the UK data protection authority. Their contact details as are follows: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; Telephone: 0303 123 1113 or 01625 545 745; or https://ico.org.uk/global/contact-us/
CONTACT Please direct any comments or enquires relating to this policy to email to emma@pilatesempower.co.uk.
UPDATING THIS POLICY From time to time I may change data processing activities. I will notify you of any changes to this policy as required by law. I will also post an updated version on website. Date: 13th Feb 2025
Pilates Empower