top of page

Privacy Policy

At Gym Geek we are committed to protecting your privacy.


We collect and process personal data about you to provide the services you use, operate our business, meet our contractual and legal obligations , protect the security of our systems and our members.


Personal data collected about our gym users


Under the General Data Protection Regulation (Regulation (EU) 2016/679) ('GDPR') and Data Protection Act 2018 ('the Act'), personal data is defined as 'any information relating to an identified or identifiable natural person ('data subject'), by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.


We also collect the following information:


Sensitive information: The term “sensitive information” in this context refers to information related to your racial or ethnic origin, religion or other beliefs and health.

Whilst we do not generally collect sensitive information unless it is volunteered by you, we do specifically collect health data to the extent that is required to assess for physical exercise. By providing the sensitive information to us, you are consenting to our using it in the manner set out in this policy.



It is important that the personal information we hold about you is accurate and up to date. Please inform us of any changes by emailing us at




A Data Controller is the individual or legal person, or entity, who and is responsible to keep and use personal data in paper or electronic files. We are the data controller as defined by relevant controls data protection laws and regulation.




The lawful bases for processing are set out in Article 6 of the GDPR. At least one of these must apply whenever personal data is to be processed:



(a) Consent: you have given Gym geek (e.g. any of the following depending on the situation freely, specific, informed, or unambiguous) consent for your personal data to be processed for a specific purpose.


(b) Contract performance: the processing is necessary for the performance of a contract you have with Gym Geek, which had asked you to take specific steps before entering into a contract.


(c) Compliance with legal obligation: the processing is necessary for Gym Geek to comply with the law (e.g. the tax/social security obligation/employment law) (not including contractual obligations).


(d) Protection of vital interests: the processing is vital to an individual's survival.


(e) Public interest: the processing is necessary for Gym Geek to perform a task that is in the public interest or for its official functions, and the task or function has a clear basis in law.


(f) Legitimate interests: the processing is necessary for Gym Geek legitimate interests, or the legitimate interests of a third-party, unless there is a good reason to protect the individual’s personal data that overrides those legitimate interests.




• The right of access.

• The right to rectification.

• The right to erasure or right to be forgotten.

• The right to restriction of processing.

• The right to be informed.

• The right to data portability.

• The right to object.

• The right not to be subject to a decision based solely on automated processing.


Under the GDPR and the Act, you may ask for a copy of the information we hold about you and you may request rectifications be made to this information if it is inaccurate or not up to date.





Information that you provide by completing forms in writing, email, through our web site or social media. This includes information provided at the time of registering with us, to use our website (where applicable), to enter into a contract for our services, to support or subscribe to our services (where applicable), to request materials or to request further services, when you respond to a survey and/or when you report a problem with any of our communication channels or services.


We collect the following classes of information:


• name(s) and address(es), email, phone number(s) and other relevant (e.g. age group, interests, subscriptions, etc.) personal details and preferred (e.g. activities, events, news, and etc.);

• staff details relevant to their employment status;

• use of social media relating to Gym Geek;

• photographs, recordings (audio and video)*;

• information about our relationship with you, correspondence, meeting notes, attendance at events etc

• occupation, skills and professional activity, network(s) and interests;

• Financial information (e.g. bank details) where they may be relevant to our needs;

• When you make a phone call or send an e-mail to seek information about our clubs/services;

• Recruitment and employment;

• Referrals by email or other method whether directly or indirectly;

• When you have used our services or benefited from our services in any ways including but not limited to club membership;

• Through your request for publications and other marketing materials;

• Through your registration for events;

• Through your contacting us with enquiries and comments

• Through our use of the Cookies on our website (please see the Cookies section below).

• We may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them.

• Details of transactions you carry out and of the fulfilment of your orders.

• Details of your access to our databases or other materials.


We may also collect cookies during your visits to our website. Please refer to our Cookie Policy here.




There are two main ways in which we collect your personal data:


a) directly from you

• that you provide to us; and

• that we automatically collect (e.g. IP addresses, OBA); and

b) from third parties.



Personal data that you give to us may be through several ways. These may include:

• directly via our website

• providing information via on-line forms or surveys

• collecting your data through a contractual or commercial relationship with you e.g. for membership subscriptions or attending a fee-paying event;

• via a form which could be online as part of our website or a form provided to us as a hard copy or electronically; and

• contacting us with enquiries or comments by telephone, email or hard copy correspondence.


Personal data may be given to us through another organisation with which you have registered or a corporate membership, and we may be required to process that data in order to fulfil services that you expect of us. This could include one of the following:


• via another authorised body with whom joint education or professional development takes

place; and

• via professional bodies with whom there is a sharing of registration for events or activities.




We will process any of your personal data, in accordance with our obligations under the Act and the GDPR, for the following reasons:

• to provide you with the services you have requested;

• to comply with the Act and the GDPR;

• for administrative purposes;

• to assess enquiries; and

• to provide you with information about us and our services. If, at any time, you do not wish to receive further information about us and our services, contact us at




We never buy personal data from third parties or trade data with other companies. However, there are times when we must collect debt and we may share your information with our appointed debt collection agents.


We will share your personal data with our group companies and or partners where it is in our legitimate interests to do so.




Our site may, from time to time, contain links to and from the websites of our partner networks, advertisers, and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.




The data that we collect from you will be processed at our servers in the UK.



If personal data is transferred outside the UK or EEA to a country without a designated adequacy rating, Gym Geek will request the data subject's consent before processing the data, unless the processor's Binding Corporate Rules, Standard Contractual Clauses or ad-hoc contractual clauses stipulate that the data will be processed in accordance with the GDPR.






To help protect the privacy of data and personally identifiable information you transmit through use of this our website, we maintain physical, technical, and administrative safeguards. We update and test our security technology on an ongoing basis. We restrict access to your personal data to those employees who need to know that information to provide benefits or services to you. In addition, we train our employees about the importance of confidentiality and maintaining the privacy and security of your information. We commit to taking appropriate disciplinary measures to enforce our employees' privacy responsibilities.





We store your personal data in accordance with our data retention policy. This policy is reviewed and updated internally to ensure we do not store your data for longer than is necessary. We also review how and where we store any data to ensure that we meet our obligation to store data securely.


In addition, some of the data we hold may be subject to certain legal and regulatory obligations, which provide a minimum retention period for different types of data. The retention period varies depending on the data we hold.




Gym Geek uses fundamental cookies on its website.





This privacy policy was written on 12th October 2021. Gym Geek Online reserves the right to vary this privacy policy from time to time. Such variations become effective on posting on this website. Your subsequent use of this website or submission of personal information will be deemed to signify your acceptance to the variations.





Questions, comments, and requests regarding this privacy policy should be addressed to


You also have the right to lodge a complaint with the UK data protection regulator, the Information Commissioner's Office (“ICO”). For further information please refer to the ICO website and/or postal address:


Information Commissioner's Office

Wycliffe House

Water Lane




bottom of page