Privacy Policy – William Finneran Personal Training

Last Updated: 08/12/2025

William Finneran Personal Training ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable laws.

1. Data Controller

Business Name: William Finneran Personal Training
Email: williamfinneranpt@gmail.com
Location: Chiswick & Kew, London, UK

We act as the data controller for the personal data we collect.

2. Personal Data We Collect

We may collect and process the following categories of personal data:

a) Identity & Contact Data

  • Full name

  • Email address

  • Phone number

  • Address (if required for billing)

b) Health & Fitness Data (Special Category Data)

  • Medical history and injuries (as disclosed by you)

  • Fitness assessments, progress data, measurements, and training history

c) Financial Data

  • Payment status and transaction records (payments are processed securely via third-party providers; we do not store full card details)

d) Technical & Usage Data

  • IP address

  • Browser type and device information

  • Website usage and interaction data

3. How We Use Your Data

We use your personal data to:

  • Provide and manage personal training, coaching, and online services

  • Create safe and effective training programmes

  • Communicate with you regarding sessions, subscriptions, updates, and enquiries

  • Process payments and manage subscriptions

  • Improve our website and services

  • Comply with legal and regulatory obligations

4. Legal Basis for Processing

Under UK GDPR, we rely on the following lawful bases:

  • Contract: To provide training and coaching services

  • Consent: For health data and marketing communications

  • Legitimate Interests: To operate and improve our business

  • Legal Obligation: For accounting and regulatory compliance

You may withdraw consent at any time.

5. Special Category (Health) Data

Health and fitness data is collected only where necessary and with your explicit consent. This information is used solely to deliver safe and appropriate training services and is handled with enhanced security measures.

6. Data Sharing

We may share personal data with trusted third parties, including:

  • Payment processors (e.g. Stripe, PayPal)

  • Website hosting, booking, and coaching platforms

  • Professional advisers or authorities where legally required

All third parties are required to process your data securely and lawfully.

7. Data Retention

We retain personal data only for as long as necessary:

  • Client records: up to 7 years after last engagement (for legal and insurance purposes)

  • Marketing data: until consent is withdrawn

8. Data Security

We implement appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, or disclosure.

9. Your Rights

You have the right to:

  • Access your personal data

  • Request correction or erasure

  • Restrict or object to processing

  • Data portability

  • Withdraw consent at any time

  • Lodge a complaint with the Information Commissioner’s Office (ICO)

ICO website: https://ico.org.uk

10. International Transfers

We do not intentionally transfer personal data outside the UK. Where third-party tools involve international processing, appropriate safeguards are in place.

11. Updates to This Policy

We may update this Privacy Policy from time to time. The latest version will always be available on our website.