Legal
Last updated: July 2026
Data Controller
The Barn Fitness and Lifestyle Ltd (Company No. 16779715)
Yew Tree Dr, Weston-super-Mare, BS22 6DB
[email protected]Identity & contact: name, email, phone, address, DOB. Membership & usage: membership ID, check-ins, class bookings, communications. Payments: billing status, direct debit references (payment providers process card/DD details on our behalf). Health (special category): PAR-Q and health declarations for safe exercise. CCTV: images in publicly accessible areas for safety and crime prevention. Website/app: device identifiers, cookies, and analytics.
We process personal data only when we have a lawful basis under UK GDPR. Contract: to create and manage your membership and provide services. Legitimate interests: gym safety, fraud prevention, customer service, and minimal service analytics. Legal obligation: finance/tax records and health & safety incident records. Consent: marketing communications (opt-in) and explicit consent for special category health data — you may withdraw consent at any time. Vital interests: limited use in a medical emergency.
We may process health data (e.g., PAR-Q) to help you train safely. Our condition for processing is explicit consent (Article 9(2)(a)); we document this and give clear choice. Where consent is withdrawn, we may not be able to provide aspects of the service that depend on safety screening.
Membership platform (ClubRight) as our processor. Payment/Direct Debit provider(s) as our processor. Email/SMS provider for marketing or service notices. Professional advisers and insurers where necessary. Law enforcement and regulators only when legally required. We use contracts and due diligence with all processors.
If personal data is transferred outside the UK, we will use permitted mechanisms (e.g., UK adequacy, IDTA or UK Addendum to EU SCCs) and assess transfer risks before proceeding.
We keep personal data no longer than necessary for the stated purposes. Membership records: duration of membership. Health & safety incident/accident records: at least 3 years (longer where justified). Financial/tax records: minimum periods required by law (e.g., HMRC). We review retention regularly and securely delete or anonymise data when the period ends.
We use CCTV only for security and safety, display clear signage, control access to footage, and set short retention unless needed for an investigation. We register with the ICO and pay the data protection fee where required. Individuals may request copies of footage showing them, subject to lawful exemptions and redaction.
Under UK GDPR you have rights to: access, rectification, erasure, restriction, objection, data portability, and to withdraw consent. We respond within one calendar month (extendable to three for complex requests with notice). To exercise your rights, contact: [email protected]. If unresolved, you can complain to the ICO at www.ico.org.uk.
We implement appropriate technical and organisational measures including access controls, encryption, staff training, secure disposal, and least privilege access. We maintain a breach response plan and, where required, notify the ICO within 72 hours and affected individuals without undue delay.
We send marketing only with your opt-in consent — you can unsubscribe at any time. We use cookies and analytics on our site; you can manage preferences via our cookie banner.
We may update this Privacy Policy to reflect legal or operational changes and will notify members of material changes.