top of page

THE CHAPEL CLUB

 

Privacy Notice

 

Last updated: September 2026

 

1. General

 

1.1 The Chapel -- Expert Personal Training, is the trading name of Alex Minors Limited (company number 05741243) ("The Chapel" "we", "us" or "our"). The Chapel takes the privacy of your information very seriously. Our Privacy Notice is designed to tell you about our practices regarding the collection, use and disclosure of personal information which may be provided to us via our website or member portal app, collected in person or collected through other means such as an online form, email, or telephone.

 

1.2 This notice applies to personal data provided by our customers and clients, whether they are an ongoing client for our services or otherwise. In this notice "you" refers to any individual whose personal data we hold or process (other than our staff and contractors).

 

1.3 In this notice references to the "Services" are references to any services provided by us which relate to any personal data held or processed by us, including our member portal app.

 

1.4 This notice is governed by the Data Protection Act 2018 and by the retained UK law version of the EU General Data Protection Regulation as incorporated into UK law under the European Union (Withdrawal) Act 2018 ("UK GDPR"), and any other applicable data or privacy legislation.

 

1.5 This notice may be updated from time to time. Changes to this notice are effective when they are posted on our website.

 

2. Basis on which we process personal data

 

2.1 Personal data we hold about you will be processed either because:

 

2.1.1 in the case of data relating to your fitness or health, you have consented to our holding and using that data (and you will be asked to sign a consent form in relation to this data);

 

2.1.2 the processing is necessary in pursuit of a "legitimate interest" --- a legitimate interest in this context means a valid interest we have or a third party has in processing your personal data which is not overridden by your interests in data privacy and security;

 

2.1.3 you have consented to the processing for the specific purposes described in this notice;

 

2.1.4 the processing is necessary in order for us to comply with our obligations under a contract between you and us.

 

3. Personal data we collect

 

3.1 We may collect and process the following personal data about you:

 

3.1.1 Contact information such as names, email addresses, phone numbers, addresses ("Contact Information"). We process this on the basis of the performance of our contract with you and our legitimate interest in providing our services.

 

3.1.2 Information relating to your health and fitness ("Health and Fitness Information"), including responses to our Physical Activity Readiness Questionnaire (PAR-Q), body composition measurements, and training history. We process this on the basis of your explicit consent under UK GDPR Article 9.

 

3.1.3 A record of any correspondence or communication between you and us ("Communication Information"). We process this on the basis of the performance of our contract with you and our legitimate interest in providing our services.

 

3.1.4 Marketing information in order to provide information about our services, including names, email addresses, phone numbers, and addresses ("Marketing Information"). We process this on the basis of your consent or our legitimate interests in communicating with you about our services.

 

3.1.5 Financial information completed in our payment mandate form, including bank account information, sort code and account number ("Financial Information"). We process this with the legitimate interest of collecting fees in line with our terms and conditions. We do not store full account numbers --- these are passed directly to our payment processing partner.

 

3.1.6 Information relating to your use of our services, including frequency of visits, session history, and preferences ("Usage Information"). We process this with the legitimate interest of better understanding our clients' habits to enhance our service offering.

 

3.1.7 Data from wearable devices (such as Whoop, Apple Health, or Garmin), including heart rate variability, sleep data, recovery scores, and activity data ("Wearables Data"), where you choose to connect such a device to our member portal. We process this on the basis of your explicit consent and solely for the purpose of informing your training programme.

 

3.2 We also utilise CCTV --- please see section 5 for further information.

 

3.3 We will collect information either from you directly or from a third party. If we obtain your personal data from a third party your privacy rights under this notice are not affected.

 

3.4 We will not collect any sensitive personal data (other than information relating to your health and fitness) without your prior explicit consent.

 

4. Data Retention

 

4.1 Our current data retention policy is to delete or destroy the personal data we hold about you in accordance with the following:

 

Category of personal data — Length of retention

 

Records relevant for tax purposes — 8 years from the end of the tax year to which the records relate

 

Personal data processed in relation to a contract between you and us — 7 years from either the end of the contract or the date you last used our services or placed an order with us

 

Personal data held on marketing or business development records — 3 years from the last date on which you have interacted with us

 

4.2 For any category of personal data not specifically defined in this notice, the required retention period will be deemed to be 7 years from the date of receipt by us of that data or (if later) the end of the relevant contract, arrangement or interaction.

 

4.3 The retention periods stated in this notice can be prolonged or shortened as required (for example, in the event that legal proceedings apply to the data).

 

4.4 We review the personal data we hold on a regular basis to ensure it remains relevant and accurate. If we discover data we hold is no longer necessary or accurate, we will take reasonable steps to correct or delete it.

 

5. CCTV

 

5.1 We utilise CCTV for the legitimate interest of protecting the safety of our staff and service users, as well as to collect evidence if required for criminal or other legal proceedings. CCTV is in use in the grounds of the property, within the reception and fitness areas, but not in the changing rooms or other sensitive areas.

 

5.2 Our employees, contractors and other third parties are able to review footage as required. By utilising our facilities, you provide consent to your image being recorded and reviewed, as proportionate and necessary for our legitimate interests.

 

5.3 Our CCTV is processed in accordance with the Data Protection Act 2018. We register our CCTV with the Information Commissioner's Office annually.

 

6. Sharing your information

 

6.1 We do not disclose any personal data you provide to any third parties other than as follows:

 

6.1.1 GoCardless Ltd --- our direct debit payment processing partner. Payment mandates are currently arranged directly with GoCardless outside of our member portal. Where financial information is passed to GoCardless (directly or via future portal integration), GoCardless acts as a data processor under a Data Processing Agreement and maintains its own privacy policy at gocardless.com.

 

6.1.2 Lovable Labs, Inc. and Google LLC --- Lovable operates the AI Gateway that powers the support chatbot within our member portal; the underlying AI model is provided by Google (Gemini). Where you use the chat feature, your member profile data (including relevant health and training data) is processed via this Gateway to generate personalised responses. Lovable and Google act as data processors under Data Processing Agreements and do not use this data to train their models. Data is processed in the United States under Standard Contractual Clauses approved for UK transfers.

 

6.1.2a In addition to the chat feature above, we use the same AI Gateway (Lovable / Google, as described in 6.1.2) to generate summaries of your health and fitness information for your trainer's reference, based on your PAR-Q/health screening responses. This helps your trainer quickly understand relevant health context ahead of your sessions. We process this on the basis of your explicit consent under UK GDPR Article 9, the same basis on which we collect your Health and Fitness Information under 3.1.2. This data is subject to the same international transfer safeguards described in 12.1.1.

 

6.1.3 Resend Inc --- our transactional email platform, used to send booking confirmations, session reminders, and other communications. Resend acts as a data processor under a Data Processing Agreement.

 

6.1.4 Self-employed staff (e.g. personal trainers) --- we may disclose relevant personal data to enable them to provide services to you.

 

6.1.5 Supabase, Inc. --- our database, authentication, and file storage provider, hosted in the EEA (Frankfurt, Germany) as described in Section 8. Lovable Labs, Inc. --- our application hosting, deployment, and development platform provider. Both act as data processors under Data Processing Agreements. We may also engage other IT technical support providers, website and app developers, and marketing service providers who may have access to personal data in the course of providing services to us.

 

6.1.6 Where we are under a duty to disclose or share your personal data to comply with any legal obligation (for example, if required to do so by a court order or for the purposes of prevention of fraud or other crime).

 

6.1.7 In order to enforce any terms and conditions or agreements for our services that may apply.

 

6.1.8 As part of a sale of some or all of our business and assets to any third party or as part of any business restructuring or reorganisation, taking steps to ensure your privacy rights continue to be protected.

 

6.1.9 Browser and device push notification services (including Google Firebase Cloud Messaging, Apple, Mozilla, and Microsoft, depending on your device and browser) --- where you enable push notifications, your device's push notification endpoint and relevant notification content (such as session times or message alerts) is passed through these services to deliver notifications to your device. These providers act as data processors in facilitating delivery.

 

6.1.10 Google Fonts --- our website and portal load typefaces from Google's font service, which receives your IP address and browser user-agent when pages load. This is a minor, standard web functionality transfer.

 

6.2 Other than as set out above, we shall not disclose any of your personal information unless you give us permission to do so.

 

7. Email and Other Communications

 

7.1 If you are a current or former client we may from time to time contact you about your bookings, programme, and account. We may also contact you with information about our services if you have expressly consented to receive such communications.

 

7.2 When we send email and other electronic communications we will comply with applicable regulations including the Privacy and Electronic Communications Regulations 2003. You will have an opportunity to opt out of receiving marketing communications from us.

 

7.3 Transactional communications (such as booking confirmations, session reminders, and health questionnaire renewal notices) do not require your opt-in as they are necessary for the delivery of our services.

 

8. Security

 

8.1 We will take all reasonable steps to ensure that appropriate technical and organisational measures are carried out in order to safeguard the information we collect from you and protect against unlawful access and accidental loss or damage. These measures include:

 

8.1.1 protecting our servers by both hardware and software firewalls;

 

8.1.2 locating our data processing storage facilities in secure locations within the European Economic Area;

 

8.1.3 encrypting all data stored on our servers using industry-standard encryption methods;

 

8.1.4 ensuring that all communication with our servers is encrypted through Secure Sockets Layer (SSL);

 

8.1.5 implementing Row Level Security on our database to ensure each member can only access their own data;

 

8.1.6 when necessary, disposing of or deleting your data securely;

 

8.1.7 regularly backing up and encrypting all data we hold.

 

8.2 We will ensure that our staff are aware of their privacy and data security obligations.

 

8.3 Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of data transmitted to us via email or our website.

 

9. Your privacy rights

 

9.1 UK GDPR gives you the following rights in respect of personal data we hold about you:

 

The right to be informed — You have a right to know about our personal data protection and data processing activities, details of which are contained in this notice.

 

The right of access — You can make what is known as a Subject Access Request ("SAR") to request information about the personal data we hold about you (free of charge, save for reasonable expenses for repeat requests). If you wish to make a SAR please contact us as described below.

 

The right to correction — Please inform us if information we hold about you is incomplete or inaccurate in any way and we will update our records as soon as possible, but in any event within one month. We will take reasonable steps to communicate the change to any third parties to whom we have passed the same information.

 

The right to erasure (the 'right to be forgotten') — Please notify us if you no longer wish us to hold personal data about you. Unless we have reasonable grounds to refuse the erasure, on receipt of such a request we will securely delete the personal data in question within one month. We will communicate the erasure to any third parties to whom we have passed the same information.

 

The right to restrict processing — You can request that we no longer process your personal data in certain ways, whilst not requiring us to delete the same data.

 

The right to data portability — You have the right to receive copies of personal data we hold about you in a commonly used and easily storable format. You may also request that we transfer your personal data directly to a third party (where technically possible).

The right to object — Unless we have overriding legitimate grounds for such processing, you may object to us using your personal data if you feel your fundamental rights and freedoms are impacted. You may also object if we use your personal data for direct marketing purposes or for research or statistical purposes.

 

Right to withdraw consent — If we are relying on your consent as the basis on which we are processing your personal data, you have the right to withdraw your consent at any time.

 

9.2 All Subject Access Requests and other requests or notifications in respect of your above rights must be sent to us in writing to the contact details set out below.

 

9.3 We will endeavour to comply with such requests as soon as possible but in any event within one month of receipt.

 

10. Data Breaches

 

10.1 If personal data we hold about you is subject to a breach or unauthorised disclosure or access, we will report this to the Information Commissioner's Office (ICO) where required by law.

 

10.2 If a breach is likely to result in a risk to your data rights and freedoms, we will notify you as soon as possible.

 

11. Other Websites

 

11.1 Our services may contain links and references to other websites. Please be aware that this notice does not apply to those websites.

 

11.2 We cannot be responsible for the privacy policies and practices of sites that are not operated by us, even if you access them via our services.

 

12. Transferring your information outside the UK/EEA

 

12.1 We will not transfer your personal data in a systematic way outside of the UK or EEA ("European Area") but there may be circumstances in which certain personal information is transferred outside the European Area, in particular:

 

12.1.1 Where you use our AI chatbot feature, or where AI is used to generate training summaries for our team (see 6.1.2a), your data is processed by Lovable Labs, Inc. and Google LLC in the United States. This transfer is made under Standard Contractual Clauses approved for UK international transfers, and each acts as a data processor under a Data Processing Agreement.

 

12.1.2 If you use our services while you are outside the European Area, your information may be transferred outside the European Area in order to provide you with our services.

 

12.1.3 From time to time your information may be stored in devices used by our staff outside the European Area (staff are subject to our data security policies).

 

12.2 If we transfer your information outside of the European Area we will provide appropriate safeguards and we will be responsible for ensuring your privacy rights continue to be protected as outlined in this notice.

 

13. Notification of changes

 

We will post details of any changes to this notice on our website to help ensure you are always aware of the information we collect, how we use it, and in what circumstances we share it with other parties.

 

14. Contact us

 

If at any time you would like to contact us with your views about our privacy practices, or with any enquiry or complaint relating to your personal information or how it is handled, you can do so via the following email address: alex@thechapel.club.

 

The Chapel · Chapel Street · Berkhamsted · HP4 2EA

 

If we are unable to resolve any issues you may have or you would like to make a further complaint, you can contact the Information Commissioner's Office by visiting http://www.ico.org.uk/ for further assistance.

bottom of page