When you supply your personal details to Rhiannon Lewis (R Lewis Fitness), they are stored and processed as per the information below. This is to ensure compliance with the Data Protection Act 2018, which includes the General Data Protection Regulation (GDPR).
1) We collect information on your Health in order to provide you with the most effective physical activity or massage treatment. Your requesting personal training or a massage treatment and your agreement to provide that care constitutes a contract. You can, of course, refuse to provide the information, but if you were to do that we would not be able to provide personal training or massage treatments.
2) We have a Legitimate Interest in collecting that information, because without it we could not do our job safely or effectively.
3) We also think it is important to be able to contact you to confirm your appointments with us, provide home exercises or to update you on something which may affect your care. This again constitutes Legitimate care but this time it is your legitimate interest.
4) Provided we have you consent, we may send you general health information in the form of articles, newsletters, suggested references, or images. You can withdraw this consent at any time. To withdraw contact Rhiannon Lewis via emailing firstname.lastname@example.org.
5) We have a legal obligation to retain your records for 6 years after your most recent massage treatment. Personal Training information is stored for up to 8 years. You can ask us to delete your records if you wish. Otherwise we will retain your records indefinitely.
Your records are stored:
On paper – Stored within a secure Home Office in locked filing cabinets, and the Home is always locked and alarmed when unoccupied.
On a private laptop – This is password protected, backed up regularly, and is stored in a locked and alarmed home.
Private Gym Computer – “Creation” Studio, Heswall holds contact telephone numbers and email addresses for personal training client and massage clients who use the facilities. This is password protected and the building is locked when out of use.
We will never share your data with anyone who does not need access without your written consent. Only the following will have access to your data:
• “Survey Monkey” may hold your contact email address from previous surveys that we have sent to you.
• “Mail Chimp” may be used to co ordinate our messages and emails, and your name and email address may be stored on their server.
• Creation Training Studio may hold your telephone number and email address when we book appointments on their computer system “appointy”
• Social Media Platforms – Facebook, Instagram, Twitter, may store images and text information in line with their own GDPR guidelines. You can decline to be featured in any social media posts.
You have the right to see what personal data of yours we hold and you can also ask us to correct any factual errors. You can also ask us to erase your records provided any legal timeframe has ended. We hold your information responsibly and want you to be confident in our handling of your data. If, however, you feel we are mishandling your personal data in some way, you have a right to complain.