real-steel-green

real steel logo

Privacy Policy                                   

Date of last review: 04/02/2021

 

Who we are:

 

Real Steel Fitness Ltd

Unit 7 Green Lane Newtown Trading Estate Tewkesbury
GL20 8HD

(01684) 439505

Our website address is: www.realsteelfitness.co.uk

 

What personal data we collect and why we collect it

 

  • Definitions

 

  1. Personal data is information about a person which is identifiable as being about them. It can be stored electronically or on paper and includes images and audio recordings as well as written information.
  2. Data protection is about how we, as an organisation, ensure we protect the rights and privacy of individuals, and comply with the law, when collecting, storing, using, amending, sharing, destroying or deleting personal data.

 

2) Responsibility

 

  1. Overall and final responsibility for data protection lies with the director, who is responsible for overseeing and ensuring this policy is upheld.
  2. All employees are responsible for observing this policy, and related procedures, in all areas of their work.

 

3) Overall policy statement

 

  1. Real Steel Fitness Ltd needs to keep personal data about its membersfor the purpose of customer membership within the gym.
  2. We will collect, store, use, amend, share, destroy or delete personal data only in ways which protect people’s privacy and comply with the General Data Protection Regulation (GDPR) and other relevant legislation.
  3. We will only collect, store and use the minimum amount of data that we need for clear purposes, and will not collect, store or use data we do not need.
  4. We will only collect, store and use data for:
    • purposes for which the individual has given explicit consent, or
    • purposes that are in our organisation’s legitimate interests, or
    • contracts with the individual whose data it is, or
    • to comply with legal obligations, or
    • to protect someone’s life, or
    • to perform public tasks.
  5. We will provide individuals with details of the data we have about them when requested by the relevant individual.
  6. We will delete data if requested by the relevant individual unless we need to keep it for legal reasons.
  7. We will endeavour to keep personal data up-to-date and accurate.
  8. We will store personal data securely.
  9. We will keep clear records of the purposes of collecting and holding specific data, to ensure it is only used for these purposes.
  10. We will not share personal data with third parties without the explicit consent of the relevant individual, unless legally required to do so.
  11. We will endeavour not to have data breaches. In the event of a data breach, we will endeavour to rectify the breach by getting any lost or shared data back. We will evaluate our processes and understand how to avoid it happening again. Serious data breaches which may risk someone’s personal rights or freedoms will be reported to the Information Commissioner’s Office within 72 hours, and to the individual concerned.
  12. To uphold this policy, we will maintain a set of data protection procedures for our organisation and customers to follow.

Data protection procedures:

 

1) Introduction

 

  1. Real Steel Fitness Ltd has a data protection policy which is reviewed regularly. In order to help us uphold the policy, we have created the following procedures which outline ways in which we collect, store, use, amend, share, destroy and delete personal data.
  2. These procedures cover the main, regular ways we collect and use personal data. We may from time to time collect and use data in ways not covered here. In these cases we will ensure our Data Protection Policy is upheld.
  3. Mr Lewis Murphy, Director of Real Steel Fitness Ltd will take responsibility for ensuring effective data management.

 

  • General procedures

 

  1. Data will be stored securely. When it is stored electronically, it will be kept in password protected files. When it is stored online in a third-party website (e.g. Google Drive) we will ensure the third party comply with the GDPR. When it is stored on paper it will be filed carefully in a locked filing cabinet.
  2. When we no longer need data, or when someone has asked for their data to be deleted, it will be deleted securely. We will ensure that data is permanently deleted from computers, and that paper data is shredded.
  3. We will keep records of consent given for us to collect, use and store data. These records will be stored securely.

 

  • Mailing list

 

  1. We will maintain a mailing list. This will include the names and contact details of people who wish to receive, publicity and promotional emails from Real Steel Fitness Ltd.
  2. When people sign up to the mailing list, we will explain how their details will be used, how they will be stored, and that they may ask to be removed from the list at any time. We will ask them to give separate consent to receive publicity and promotional messages and will only send them messages which they have expressly consented to receive.
  3. We will not use the mailing list in any way that the individuals on it have not explicitly consented to.
  4. We will provide information about how to be removed from the list with every mailing.
  5. We will use mailing list providers who store data within the UK, EU or the USA.

 

  • Supporting & contacting individuals

 

  1. From time to time, individuals contact Real Steel Fitness Ltdabout membership enquiries.
  2. We will request explicit, signed consent before sharing any personal details with the council or any other relevant third party.
  3. We will not keep information relating to an individual’s personal situation for any longer than is necessary for the purpose of providing them with the support they have requested.
  4. When contacting people on this list, we will provide a privacy notice which explains why we have their information, what we are using it for, how long we will keep it, and that they can ask to have it deleted or amended at any time by contacting us.

 

7) Breaches

 

GDPR or DPA 2018 personal data breach

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

If a breach occurs the Nominated person will risk assess the situation using the following guidelines:

  • consider the likelihood and severity of the risk to people’s rights and freedoms, following the breach. When this assessment has been made, if it’s likely there will be a risk then the ICO will be informed, if it’s unlikely then it will not be reported.

GDPR introduces a duty on all organisations to report certain types of personal data breach to the relevant supervisory authority. This must be done within 72 hours of becoming aware of the breach, where feasible.

  • inform individuals whose data has been breached without undue delay.
  • notify employees and keep a record of any personal data breaches, regardless of whether notification of the ICO is required.

 

9) Review

 

These procedures will be reviewed every two years or sooner if legislation or the nominated person changes.

 

Website Data

 

Comments

 

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

 

Media

 

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

 

Cookies

 

If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

 

Embedded content from other websites

 

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

 

How long we retain your data

 

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

 

What rights you have over your data

 

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

 

Where we send your data

Visitor comments may be checked through an automated spam detection service.

Further Terms & Conditions

 

You are advised to review your security and privacy settings should you wish to limit the data being collected about you. This information may include but is not limited to:

  • Your server address,
  • Your top-level domain name (for example .com, .gov, .uk etc),
  • The date and time of your visit to the site,
  • The pages you accessed, and documents downloaded,
  • The previous site you have visited,
  • The type of browser you are using.

 

Your Consent

By using our site, you are consenting to our Privacy Policy. We will review this Privacy Policy periodically, and if we ever change our Privacy Policy, we shall post any changes on this page so that you are always kept informed of the information we collect, how we use it and the circumstances under which we disclose it, if at all.
If you have any questions or comments about our Privacy Policy, please contact us atrealsteelfitness@hotmail.co.uk

 

Disclaimer

Real Steel Fitness Ltd accepts no responsibility for the content on external sites. External links are presented without warranty, express or implied.

Significant measures have been employed to protect this site from malicious attacks by third parties. Real Steel Fitness Ltd accepts no responsibility for any content or software that may have been maliciously placed upon its website without its knowledge. You must ensure protection and your consent to use this website at your own risk.

This policy will be reviewed every three years or sooner if there are changes in legislation.