iDFitness Privacy policy
iDFitness Privacy Policy
Last updated: 31/07/2026
This Privacy Policy explains how K1 Berkshire Ltd, trading as iDFitness (“iDFitness”, “we”, “us”, “our”), collects, uses, and protects your personal data when you become a member, use our facilities, visit our website, or interact with us. It should be read alongside our Terms of Service and Code of Conduct, which reference this policy and form part of your membership agreement.
We are committed to handling your personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
K1 Berkshire Ltd, trading as iDFitness, is the “data controller” responsible for your personal data.
Contact details:
- Email: hello@id.fitness
- Address: [iDFitness site address]
- Data protection queries: hello@id.fitness (marked “Data Protection”)
We have not appointed a formal Data Protection Officer, but the above contact handles all data protection queries and requests.
2. What Personal Data We Collect
Depending on how you interact with us, we may collect:
| Category | Examples |
|---|---|
| Identity data | Name, date of birth, emergency contact details |
| Contact data | Address, email address, phone number |
| Membership data | Membership type, start date, payment history, attendance/booking records, class history |
| Health data (special category) | Information provided in your health declaration (Section 2 of the Terms of Service), medical certificates supporting exceptional cancellation or pauses, fitness assessment results |
| Financial data | Payment card or bank details (processed via our payment provider — we do not store full card details ourselves), billing address |
| Images and video | Photos or video taken at the gym, in classes, or at events, where consented to under Section 18 of the Terms of Service |
| Communications data | Emails, messages, or call records between you and iDFitness, including complaints (Section 19 of the Terms of Service) and WhatsApp/Facebook group interactions |
| Technical/usage data | Website usage data, cookies, IP address, device/browser type (see our Cookie Policy, if applicable) |
| Marketing preferences | Your choices about receiving marketing communications from us |
We do not knowingly collect personal data from children under 16 directly; where under-18 membership involves a parent/guardian (Section 2 of the Terms of Service), we collect the necessary consent and contact details from the parent/guardian.
3. How We Collect Your Data
- Directly from you: when you sign up for membership, complete a health declaration, book a class, make a payment, contact us, or interact with our social media/WhatsApp groups.
- Automatically: through our website, booking system, and access control systems (e.g. gym entry).
- From third parties: our payment processor (confirming successful payment), and, where applicable, referral partners or corporate wellness scheme administrators (with your knowledge).
4. Why We Use Your Data and Our Legal Basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Setting up and managing your membership | Identity, contact, membership, financial data | Performance of a contract (your membership agreement) |
| Assessing whether it’s safe for you to train, and responding to exceptional cancellation/pause requests | Health data | Explicit consent (Article 9(2)(a) UK GDPR) |
| Processing payments and pursuing unpaid fees | Financial, membership data | Performance of a contract; legitimate interests (recovering debts owed to us) |
| Operating classes, bookings, and facility access | Membership, booking data | Performance of a contract |
| Enforcing our Terms of Service and Code of Conduct, including suspension/termination decisions | Identity, membership, communications data | Legitimate interests (protecting our members, staff, and business); legal obligation where relevant |
| Taking and using photos/video for promotional purposes | Images/video | Consent (separate from membership sign-up, per Section 18.2 of the Terms of Service) |
| Sending you service updates (e.g. price changes, closure notices, terms updates) | Contact data | Legal obligation / necessary for performance of contract |
| Sending you marketing communications (offers, newsletters, events) | Contact data, marketing preferences | Consent, or legitimate interests for existing members (with an opt-out in every communication) |
| Improving our website and services | Technical/usage data | Legitimate interests / consent (cookies) |
| Complying with our legal and regulatory obligations (e.g. tax, health & safety) | Financial, identity, health data | Legal obligation |
Where we rely on consent (health data, images, and marketing), you can withdraw that consent at any time by contacting hello@id.fitness, without affecting the lawfulness of processing before withdrawal. As noted in the Terms of Service, withdrawing consent to health data processing may limit our ability to safely provide certain services (e.g. personal training).
5. Who We Share Your Data With
We do not sell your personal data. We share it only where necessary, with:
- Payment processors (e.g. our card/direct debit provider) to process membership payments.
- Debt collection agencies, where a membership payment remains unpaid, in line with Section 9 of the Terms of Service.
- IT and software providers who support our booking system, website, and email/CRM systems (e.g. our marketing platform), acting as data processors under contract.
- Instructors and coaching staff, on a need-to-know basis, to deliver safe and appropriate training.
- Corporate wellness partners, only where you access iDFitness via a corporate scheme and only to the extent needed to confirm your eligibility.
- Regulators, law enforcement, or legal advisors, where required by law or to establish, exercise, or defend legal claims.
- A buyer or successor, if iDFitness’s business is sold, merged, or restructured, or in the event of closure as described in Section 13 of the Terms of Service, in which case your data would transfer subject to equivalent protections.
All third-party processors are contractually required to protect your data and use it only for the purposes we specify.
6. International Transfers
Where any of our service providers store or process data outside the UK, we ensure an appropriate safeguard is in place, such as the UK’s International Data Transfer Addendum, adequacy regulations, or Standard Contractual Clauses, before any transfer takes place.
7. How Long We Keep Your Data
| Data type | Retention period |
|---|---|
| Membership and payment records | Duration of membership plus 6 years (for tax/accounting purposes) |
| Health declarations and medical certificates | Duration of membership plus 2 years, or longer if needed to defend a legal claim |
| Images/video (promotional) | Until consent is withdrawn, or up to 3 years from last use, whichever is sooner |
| CCTV footage (if applicable on premises) | Typically 30 days, unless needed for an investigation |
| Marketing communication preferences and history | Until you unsubscribe or object, plus a record of your preference to demonstrate compliance |
| Complaints records | 3 years from resolution |
We securely delete or anonymise personal data once it is no longer needed for the purpose it was collected, save where we are required by law to retain it for longer.
8. Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data (“right to be forgotten”), where applicable;
- Restrict processing in certain circumstances;
- Object to processing based on legitimate interests or for direct marketing;
- Data portability, where processing is based on consent or contract and carried out by automated means;
- Withdraw consent at any time, where we rely on consent (health data, images, marketing);
- Not be subject to solely automated decision-making that produces legal or similarly significant effects on you (we do not currently use automated decision-making of this kind).
To exercise any of these rights, contact hello@id.fitness. We will respond within one month, as required by law (this may be extended by a further two months for complex requests, and we will tell you if this applies).
You also have the right to lodge a complaint with the UK’s data protection regulator, the Information Commissioner’s Office (ICO), at ico.org.uk or by calling 0303 123 1113, if you believe we have not handled your data properly. We would appreciate the opportunity to address your concern directly first — see our Complaints process in Section 19 of the Terms of Service.
9. Keeping Your Data Secure
We use appropriate technical and organisational measures to protect your personal data, including restricted staff access to health and payment data, secure storage of physical records (e.g. medical certificates), and secure, access-controlled digital systems for our booking, payment, and marketing platforms. We do not store full payment card details ourselves.
10. Cookies and Website Data
Our website may use cookies and similar technologies to operate correctly, remember your preferences, and understand how visitors use our site. Where required, we will ask for your consent before setting non-essential cookies, and you can manage your preferences via your browser settings or any cookie banner presented on our site.
11. Marketing Communications
If you’ve opted in (or, as an existing member, not opted out), we may contact you with news, offers, classes, and events by email, SMS, or WhatsApp. You can opt out at any time by using the “unsubscribe” link in our emails, replying “STOP”, or emailing hello@id.fitness. Opting out of marketing does not affect essential service communications about your membership (e.g. payment reminders, closure notices).
12. Children’s Data
Where a member is under 18, we collect the minimum necessary data with parental/guardian consent, as described in Section 2 of the Terms of Service. Parents/guardians can exercise data rights on behalf of their child by contacting hello@id.fitness.
13. Changes to This Policy
We may update this Privacy Policy from time to time, for example to reflect changes in the law or our services. We will notify members of material changes in the same way as changes to the Terms of Service (see Section 12 of the Terms of Service), and the “last updated” date at the top of this page will always reflect the current version.
14. Related Documents
This Privacy Policy should be read together with:
- iDFitness Terms of Service — sets out your membership contract, including how we handle health declarations (Section 2), liability (Section 3), image and video consent (Section 18), and data protection generally (Section 16).
- iDFitness Code of Conduct — sets out expected behaviour, including safe use of the images/video provisions (Sections 7 and 8) and how to raise a concern (Section 10).
15. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, contact us at hello@id.fitness.