PRIVACY POLICY

GymBuddy Privacy Notice (UK)
Last updated: Dec 4th 2019

GymBuddy respects your right to privacy. This Privacy Notice explains who we are, how we collect, share and use personal information about you, and how you can exercise your privacy rights. This Privacy Notice only applies to personal information that we collect through our website at GymBuddy.com and our mobile applications (collectively, the “Site”). This Privacy Notice applies to you if you use our Site in the UK.

If you have any questions or concerns about our use of your personal information, then please contact us using the contact details provided at the bottom of this Privacy Notice.

The Site is not intended for or directed to persons under the age of 13, and we will not knowingly collect information from persons under 13. To provide information to us through registration or in any other manner on the Site, you must be 13 years of age or older.

1. What Does GymBuddy Do?

GymBuddy enables consumers to find, book and attend a Gym location, services or products offered and operated by fitness studios, gyms, trainers, venues or other third parties through our social media platform. GymBuddy Health & Fitness Ltd is located in the U.K.

2. What Personal Information Does GymBuddy Collect?

We collect or receive personal information in a few different ways via the Site. Often, you choose what information to provide, but sometimes we require certain information in order for you to use, and for us to provide you with, the Site and the experiences you reserve or access through the Site.

Data You Provide To Us. There are a variety of different ways you may provide data to us, such as:

Account Creation. To create an account, you need to provide data including information such as your name, email address, phone number and a password. If you make a purchase or sign up for a subscription, you will need to provide payment and billing information via Stripe that we do not hold on record.

Profile.To complete your profile, you may provide other information, such as a photo or birthdate.

Posting and Uploading. We collect personal information from you when you provide, post or upload it to our Site, such as when you respond to a survey or provide a class rating or review.

Third Party Data.You may not provide information to us about someone else unless you have obtained the prior consent of the other person for us to receive and use their information, such as for emergency contact or referral purposes.

Data Collected Automatically Through Your Use of the Site.

We log usage data when you visit or otherwise use our Site, such as when you view or click on content or ads (on or off our Site), perform a search, browse, schedule a reservation and install or update one of our mobile apps. Specifically, the information we collect automatically may include information like internet protocol (“IP”) address, device type, unique device identification numbers, browser-type, broad geographic location (e.g. country or city-level location) and other technical information. We may also collect information about how your device has interacted with our Site, including the pages accessed and links clicked.

We may also collect precise geolocation data pertaining to your mobile device, if you have consented to providing this to us through your device settings. We may use this information to provide, promote, and improve our services (for example, by showing you classes that are close to your location) and for related reasons, such as fraud prevention and security purposes. Please note that if you do not consent to providing your geolocation data, certain features of the mobile application may not work.

The information we collect automatically enables us to better understand the visitors who come to our Site, where they come from, and what content on our Site is of interest to them. This enables us to improve the quality and relevance of our Site to our visitors.

Cookies, Web Beacons and Other Similar Technologies.

We use cookies and similar technologies (e.g., web beacons, pixels, ad tags and device identifiers) to recognize you and/or your device(s) on, off and across the Site, including when you use different devices. To learn more, including how to change your cookie settings, please see our Cookie Notice.

Data From Others.

From time to time, we may receive personal information about you from third party sources to assist us in providing, evaluating and improving our Site and offerings, but only where these third parties represented that you gave your consent either or are otherwise legally permitted or required to disclose your personal information to us. For example, studio partners may provide information to us in connection with a reservation you make or a class that you take, for example if there is an issue with your reservation. We may also collect information from third-party services like Facebook if you use one of these services to log into or integrate with our Site. This information may include your name, email address, gender, city, and state or your friends or contacts on such sites. Logging in through these third-party services may allow you to interact with other users that maintain accounts through those services. Further, if you choose to integrate your GymBuddy account with your iOS HealthKit or similar application, we may receive certain sensitive personal information such as heart rate and calorie information to help track your activity, personalize your experience and improve our service.

3. What Does GymBuddy Do with the Personal Information it Collects?

GymBuddy uses personal information it receives for several purposes:

Site: To operate and maintain our Site and the products and services offered through our Site. For example, we use personal information to fulfill your reservation and purchase requests, including processing payments, and to customize your experience on our Site, such as by tailoring the content or experiences we show you.

Communication: To contact you through email, phone, postal mail, notices posted on our websites or apps, and other ways. We will send you messages about the availability of our Site, security, customer service, or other service-related issues. We also send messages about the Site, updates, reminders, and promotional messages in accordance with your communications preferences. You may change your communication preferences at any time. Please be aware that you cannot opt-out of receiving service messages from us, including security and legal notices.

Customer Support: In connection with customer service inquiries and matters, such as to investigate, respond to and resolve complaints and service issues.

Marketing: For marketing purposes, such as to develop our marketing strategy and offer contests, sweepstakes, or other promotions and to fulfill any related awards or discounts;

Research and Development: For research, analytical, recordkeeping, and reporting purposes; to develop and test new products, features and ideas; to learn about our customer base and Site and to evolve and improve our Site, products and services.

Security and Investigations: We use your information to maintain the security of our Site, including to verify your identify, investagate or prevent possible fraud or other violations of our Terms of Use this Privacy Notice and/or in connection with possible attempts to harm our members, visitors, studio partners or other third parties.

Other: For any other purpose identified at the point of collection or otherwise with your consent.

5. Who does GymBuddy Share My Personal Information With?

We may disclose your personal information to the following categories of recipients or in the following circumstances:

- third party services providers and partners who provide data processing services to us (for example, to support the delivery of, provide functionality on, or help to enhance the security of our Site, payment card processors, customer support vendors, hosting vendors, scheduling providers and market research and marketing vendors), or who otherwise process personal information for purposes that are described in this Privacy Notice or notified to you when we collect your personal information.

- to our group companies, to provide, develop, improve, and analyze the Site and our offerings.

- to any venue, studio, instructor or other provider that makes available a class, activity or experience you reserve or use through our Site and their third-party providers, so that they can process the applicable reservation or activity and make available classes and services to you;

- to anyone who visits our Site if you voluntarily share information about yourself in a public area on our Site, such as a public profile or class ratings. You should be aware that any content or information you choose to disclose in these areas can be read, collected and used by other users, the general public and other sites (including search engines).

- to any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary as a matter of applicable law or regulation, to exercise, establish or defend our legal rights, or to protect your vital interests or those of any other person;

- in connection with an actual or potential merger, sale, acquisition, investment, assignment, reorganization, joint venture, or transfer of all or part of GymBuddy’ business, assets, affiliates, including if GymBuddy should ever file for bankruptcy or a related proceeding, provided that we inform the relevant third party it must use your personal information only for the purposes disclosed in this Privacy Notice;

- to your employer (or similar entity), if you participate in any enterprise solutions or corporate programs;

- to any other person with your consent to the disclosure.

6. How does GymBuddy Keep My Personal Information Secure?

We use appropriate technical and organisational measures to protect the personal information that we collect and process about you. The measures we use are designed to provide a level of security appropriate to the risk of processing your personal information. We monitor our systems for possible vulnerabilities and attacks. However, we cannot guarantee 100% security of any information that you send us.

7. International Data Transfers

Your personal information may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different to the laws of your country (and, in some cases, may not be as protective). Specifically, our Site servers are located in the United States, and our group companies and third-party service providers and partners operate around the world. This means that when we collect your personal information we may process it in any of these countries.

However, we have taken appropriate safeguards to require that your personal information will remain protected in accordance with this Privacy Notice. These include implementing the European Commission’s Standard Contractual Clauses (and in the future may include Privacy Shield or similar certification) for transfers of personal information between our group companies, which require all group companies to protect personal information they process from the EEA in accordance with European Union data protection law. Our Standard Contractual Clauses can be provided on request. We have implemented similar appropriate safeguards with our third-party service providers and partners and further details can be provided upon request.

8. Data Retention

We retain personal information we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements).

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.

9. Your data protection rights

You have the following data protection rights:

- If you wish to access, correct, update or request deletion of your personal information, you can do so by contacting us as explained below.

- In addition, you can object to the processing of your personal information, ask us to restrict processing of your personal information or request portability of your personal information. Again, you can exercise these rights by contacting us.

- You have the right to opt-out of marketing communications we send you at any time. You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in the marketing emails we send you or via our preference center. To opt-out of other forms of marketing (such as postal marketing or telemarketing), then please contact us.

- Similarly, if we have collected and process your personal information with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.

- You have the right to complain to a data protection authority about our collection and use of your personal information. For more information, please contact your local data protection authority. (Contact details for data protection authorities in the European Economic Area, Switzerland and certain non-European countries (including the US and Canada)

You may contact us as explained in the “How to contact us” heading below. We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.

10. Third Party Sites

Our Site may contain links to third-party websites or mobile apps, including social sharing features and other related tools. Please be aware that GymBuddy does not control these linked websites or apps and that this Privacy Notice does not apply to any information you give to the owner of these websites or apps. We encourage you to read the privacy policy of any third-party website or app that you visit before you provide them with any information.

11. Updates to this Privacy Notice

We may update this Privacy Notice from time to time in response to changing legal, technical or business developments. When we update our Privacy Notice, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material Privacy Notice changes if and where this is required by applicable data protection laws. You can see when this Privacy Notice was last updated by checking the “last updated” date displayed at the top of this Privacy Notice.

12. How to contact us

If you have any questions or concerns about our use of your personal information, please contact GymBuddy Health & Fitness Ltd (the data controller) https://www.gymbuddy.co.uk/web/public/contact