Privacy Policy

Privacy Policy

1. Introduction

This privacy policy tells you how the Craig’s Fitness use your personal data when you visit our website, interact with us, and buy our goods and services.

It also tells you about your privacy rights and how the law protects you.

It is important that you read this privacy policy, together with any other privacy policies we may provide, so that you are fully aware of how and why we are using your data.

If you have any questions, or would like to exercise your privacy rights, please follow the instructions in this privacy policy. See How to contact Craig’s Fitness about privacy below.

 2. Personal data which we collect about you

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We collect a variety of information about our wonderful customers (you!) and visitors to the website. This personal data falls into these categories:

Identity Data includes title, first name, last name, username or similar identifier and an encrypted version of your login/password. If you interact with us through social media, this may include your social media user name.

Contact Data includes billing address, delivery address, email address and telephone numbers.

Special Categories of Personal Data about you (this includes details about your health and medical data).

3. Data security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

4. Data retention

We will only keep your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they stop being customers for tax purposes.

We also make a promise to you that you can come back at any time in the future and re-print products you have ordered from us in the past. So, unless you actively delete this information, we keep it, so we can keep our promise to you.

In some circumstances you can ask us to delete your data; see Your legal rights below for further information.

In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.

5. Your legal rights

If the General Data Protection Regulation applies to you because you are in the European Union, you have rights under data protection laws in relation to your personal data:

  • The right to be informed – that’s an obligation on us to inform you how we use your personal data (and that’s what we’re doing that in this privacy policy);
  • The right of access – that’s a right to make what’s known as a ‘data subject access request’ for copy of the personal data we hold about you;
  • The right to rectification – that’s a right to make us correct personal data about you that may be incomplete or inaccurate;
  • The right to erasure – that’s also known as the ‘right to be forgotten’ where in certain circumstances you can ask us to delete the personal data we have about you (unless there’s an overriding legal reason we need to keep it);
  • The right to restrict processing – that’s a right for you in certain circumstances to ask us to suspend processing personal data;
  • The right to data portability – that’s a right for you to ask us for a copy of your personal data in a common format (for example, a .csv file);
  • The right to object – that’s a right for you to object to us processing your personal data (for example, if you object to us processing your data for direct marketing); and
  • Rights in relation to automated decision making and profiling – that’s a right you have for us to be transparent about any profiling we do, or any automated decision making.

These rights are subject to certain rules around when you can exercise them. You can see a lot more information on them, if you are interested, on the UK Information Commissioner’s Office website.

If you wish to exercise any of the rights set out above, please contact us (see How to contact Craig’s Fitness about privacy).

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

We have appointed a data privacy manager who is responsible for overseeing questions in relation to this privacy policy. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact the data privacy manager using the details in How to contact Craig’s Fitness about privacy below.

You have the right to make a complaint at any time to the Information Commissioner’s Office (“ICO”), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.

6. How to contact MOO about privacy

If you have any questions about this privacy policy, or would like to exercise any of your rights, please email us at craigsfitness121@gmail.com

7. Changes to this privacy policy

 The General Data Protection Regulation is new and the ICO is still issuing new bits of guidance about how businesses should follow it. So, you may see little updates to our privacy policy over the coming months. Be sure to check in and have read every now and then. Thank you.

Follow

Follow this blog

Get every new post delivered right to your inbox.

Email address