Privacy & Data Retention Policy
Introduction
Everybody Health & Leisure is committed to ensuring that you and your family’s personal information is protected when you are using our services. This Privacy Policy relates to our use of any personal information we collect from you via the following services:
- The Everybody Health & Leisure website – everybody.org.uk
- Social Media
- Any personal information you provide to us by phone, SMS, email, in letters and other correspondence and in person.
References to we, our or us in this privacy notice are to Everybody Health & Leisure (Oakwood Corporate Services, 3rd Floor, 1 Ashley Road, Altrincham, Cheshire, WA14 2DT; Company Number – 08685939; Registered Charity Number – 1156084).Everybody Health & Leisure is registered as a Data Controller under the Data Protection Act. Certificate of registration number – ZA060894.
This Privacy Policy explains the following:
- What information we may collect and why we collect it;
- How we will use information we collect about you;
- When we may use your details to contact you;
- Whether we will disclose your details to anyone else;
- Your choices regarding the personal information you provide to us;
- The use of cookies on the Everybody Health & Leisure website and how you can reject cookies.
Everybody Health & Leisure is committed to safeguarding your personal information. Whenever you provide such information, we are legally obliged to use your information in line with all applicable laws concerning the protection of personal information, including the Data Protection Act 2018 (these laws are referred to collectively in this Privacy and Cookies Policy as the “data protection laws”).
We have appointed a Data Protection Officer to oversee our compliance with data protection laws. They can be contacted by emailing [email protected]. Our director with the overall responsibility for data protection compliance in our organisation is Kerry Shea. She can be contacted by emailing [email protected].
If you require this policy in an alternative format, please email [email protected].
Policy Updates
This policy updates, amalgamates and replaces version 2026.2 of the Privacy Policy, version 5 of the Everybody Data Retention Policy, version 2024.1 of the Financial Retention Policy and version V3 04.22 of the Access to Personnel Records Policy. Changes include updates to retention responsibilities and procedures and removal of references to Everybody @ Home & the US Privacy Shield.
Definitions
CRM – Customer Relationship Management
EEA – European Economic Area
Everybody – Accepted shorthand for Everybody Health & Leisure
GDPR – General Data Protection Regulation
HR – Human Resources
ICO – Information Commissioners Office
IDTA – UK International Data Transfer Agreement
PECR – Privacy & Electronic Communications (EC) Directive Regulations
Related Policies & Documents
You may want, or need, to refer to other Everybody policies and guidance including:
- CCTV Policy
- Chat Function Policy
- Cyber Security Policy
- Photography Policy
- Use of Artificial Intelligence Policy
Who Are We?
Everybody Health & Leisure is a registered charity and a company limited by guarantee (Registered Charity No. 1156084; Company No. 08685939). Established in May 2014 (as Everybody Sports & Recreation), Everybody Health & Leisure delivers leisure services and public health initiatives.
Your Rights as a Data Subject
You have the following rights in relation to your personal information:
- The right to be informed about how your personal information is being used;
- The right to access the personal information we hold about you;
- The right to request the correction of inaccurate personal information we hold about you;
- The right to request the erasure of your personal information in certain limited circumstances;
- The right to restrict processing of your personal information where certain requirements are met;
- The right to object to the processing of your personal information;
- The right to request that we transfer elements of your data either to you or another service provider; and
- The right to object to certain automated decision-making processes using your personal information.
You should note that some of these rights, for example the right to require us to transfer your data to another service provider or the right to object to automated decision making, may not apply as they have specific requirements and exemptions which apply to them and they may not apply to personal information recorded and stored by us. For example, we do not use automated decision making in relation to your personal data. However, some have no conditions attached, so your right to withdraw consent or object to processing for direct marketing are absolute rights.
Whilst this privacy notice sets out a general summary of your legal rights in respect of personal information, this is a very complex area of law. More information about your legal rights can be found on the Information Commissioner’s website at https://ico.org.uk/for-the-public
To exercise any of the above rights, or if you have any questions relating to your rights, please contact us by emailing [email protected]
If you are unhappy with the way we are using your personal information, you can also complain to the UK Information Commissioner’s Office or your local data protection regulator. We are here to help and encourage you to contact us to resolve your complaint first.
Consent
Giving Consent to Everybody Health & Leisure will only be undertaken where the individuals have:
- A genuine choice and level of control over how your data is used;
- The right to only opt-in to give consent with no pre-ticked or implied consent options;
- Individuals are made fully aware of what they are consenting to;
- The right to withdraw consent at any time by speaking to a member of staff or emailing [email protected]; and,
- The right to know the purpose of collecting and processing your data.
There is the need for Everybody Health & Leisure to collect and process personal data without consent in the fulfilment of its duties and obligations to you, where appropriate. (For example: Personal and banking information will be required to process direct debit payments for membership fee collections). Should Everybody Health & Leisure partner with a payments collection company to enable the collection of these payments this provider will, as a business necessity, have access to customers’ personal information.
Everybody Health & Leisure will hold a copy of your consenting action in relation to who consented, when and how you were told. This information will be kept by Everybody Health & Leisure as long as is deemed appropriate.
Retention
The duration for which we retain your personal information will differ depending on the type of information and the reason why we collected it from you. However, in some cases personal information may be retained on a long-term basis: for example, personal information that we need to retain for legal purposes will normally be retained in accordance with usual commercial practice and regulatory requirements. Retention is based on:
- Legal obligation
- Contractual necessity
- Evidence & accountability
- Legitimate interests
Where multiple retention requirements apply, the longest period will be used.
Wherever possible data is stored electronically, is accessed via a secure network by authorised staff using encrypted or secure passwords. The level of data
accessible is managed by user authentication and preferences and accessing this data is controlled based on data type and job role need requirements.
Physical data is stored in locked cabinets or rooms with controlled access.
We will ensure that deletion is secure and an anonymised process.
It is important to ensure that the personal information we hold about you is accurate and up-to-date, and you should let us know if anything changes, for example if you change your phone number or email address. Changes can me made when visiting one of our sites, at the reception desk, or by emailing [email protected].
See Appendix 1 for relevant retention periods.
Employee Personal Information
We also collect personal information from our employees and from job applicants (human resource data) in connection with administration of our human resources programs and functions.
These programs and functions include but are not limited to; job applications and hiring programs, compensation and benefit programs, performance, review and development processes, training, access to our facilities and computer networks, employee profiles, employee directories, human resource recordkeeping, emergency contact details and other employment related purposes.
It is the policy of Everybody Health & Leisure to keep all past and present employee information private from disclosure to third-parties. There are certain business-related exceptions, and they are:
- To comply with local, regional, national contractual legislation requests
- Inquiries from third-parties with a signed authorisation from the employee to release the information, except in situations where limited verbal verifications are acceptable (see below).
- Third-parties with which Everybody Health & Leisure has contractual agreements to assist in administration of company sponsored benefits.
Prospective employers, government agencies, financial institutions, and residential property managers routinely contact Everybody Health & Leisure requesting information on a former or current employee’s work history and salary. All such requests of this type shall be referred to and completed on a confidential basis by the People Solutions team or payroll department. For written verification of employment requests, information will be provided on the form only when it is accompanied by an employee’s signed authorisation to release information. The form will be returned directly to the requesting party and filed as part of the payroll department’s confidential records.
Management Access to Personnel Records
Managers can access personnel records for their own employees, and can request the file via the HR Team. If the manager needs to retain the record it will be
stored in a secure location and returned to HR within 72 hours.
Formal Disclosure of Employee Information
We may receive requests for information about you from solicitors, tribunals, insurance and finance companies or directly from yourself. We’ll only share information if we have written evidence that you’ve given permission, or if they have a legal right to see it
References
By law, we’re not obliged to disclose outgoing references, but we will disclose a copy to you on request.
We’ll disclose a reference provided by another organisation if your referee was clearly made aware that their information may be shared with you on request. If it
was supplied ‘in confidence’ it will be shared at our discretion.
Safeguarding
Our Safeguarding Policy sets out the processes that must be followed during Safeguarding reports & incidents.
Safeguarding information relating to concerns and incidents must never be routinely deleted without expert review.
Marketing
We like to tell customers about other services we offer. When customers are joining a programme or signing up for a membership, we will ask if we can market
to them.
We are committed to ensuring that all marketing communications are lawful, fair, transparent and limited to what is necessary. We do not sell personal data and
only use it to support our services and charitable objectives.
We will also ask how they would like to be contacted.
At the end of their membership their data will be retained in line with this Policy.
Marketing data is retained for as long as consent is valid or up to 24 months from the last interaction or activity, whichever occurs sooner, unless required for legal purposes.
Within all electronic communications, there will be the option to directly unsubscribe or email [email protected] where they will also be
able to request a change to their preferences.
Campaign Monitor
We use Campaign Monitor for our email marketing.
This provider acts as a data processor on our behalf under contractual agreements compliant with UK GDPR (Article 28).
Personal data may include your name, email address, membership status and communication preferences. Data may be collected via:
- Membership and CRM systems (including XN Leisure)
- Website sign-up forms
- Event registrations and outreach activities
Marketing data is synchronised between systems to ensure that any unsubscribe or deletion request is consistently applied.
Data within Campaign Monitor is deleted or anonymised in accordance with the retention periods outlined, or sooner where consent is withdrawn.
Where data is transferred outside the UK or EEA (for example via third-party providers) we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or the UK International Data Transfer Agreement (IDTA).
Textanywhere
We use Textanywhere for SMS messaging.
Service-related messages (e.g. booking confirmations, membership updates) are sent as part of your contract with us.
Marketing messages via SMS will only be sent where you have provided consent or where permitted under PECR.
Textanywhere acts as a data processor on our behalf. Data is retained for the retention period outlined, to fulfil the purposes above and is removed in
accordance with our contractual arrangements.
The service collects customer data as part of the membership agreement and will be used as a form of membership related contact.
There is an option to opt out from the communication including in the text body.
Textanywhere will remove Everybody content and/or any archived data within 12 months after account cancellation.
Website – Security, Cookies, IP Addresses, Aggregate Information & Hyperlinks
The Everybody Health & Leisure website (www.everybody.org.uk) is a key communication tool for us. We take interaction with our website and the safety of our users very seriously.
Cookies are a technology that can be used to help personalise your use of a website. A cookie is an element of information that a website can send to your
browser, which may then store it on your system. We use a cookie consent mechanism which allows you to accept or reject non-essential cookies before they are placed on your device. You can update your preferences at any time. To enable Everybody to assess the effectiveness and usefulness of this Site, and to give you the best user experience, we collect and store information on pages viewed by you, your domain names and similar information. Some cookies may collect information that can be linked to an individual when combined with other data and are therefore treated as personal data.
Our Site makes use of anonymous cookies for the purposes of:
- Completion and support of Site activity
- Site and system administration
- Research and development
- Anonymous user analysis, user profiling, and decision-making.
We may use limited profiling (such as website usage patterns) to improve our website and communications. This does not result in automated decisions that have legal or similarly significant effects. We use Google Analytics to understand how visitors use our website. This involves the use of cookies and is subject to your consent.
An Internet Protocol (“IP”) address is associated with your computer’s connection to the internet. Everybody Health & Leisure may use your IP address to help diagnose problems with Everybody Health & Leisure server, to administer the Site and to maintain contact with you as you navigate through the Site. Your computer’s IP address also may be used to provide you with information based upon your navigation through the Site.
Aggregate information is used to measure the visitors’ interest in, and use of, various areas of the Site and the various programs that Everybody Health & Leisure administers. Everybody Health & Leisure will rely upon aggregate information, which is information that does not identify you, such as statistical and navigational information. With this aggregate information, Everybody Health & Leisure may undertake statistical and other summary analyses of the visitors’ behaviours and characteristics. Although Everybody Health & Leisure may share this aggregate information with third-parties, none of this information will allow anyone to identify you, or to determine anything else personal about you.
The Everybody Health & Leisure website contains hyperlinks to websites owned and operated by third-parties. These third-party websites have their own privacy policies, and are also likely to use cookies, and we therefore urge you to review them. They will govern the use of personal information you submit when visiting these websites, which may also be collected by cookies. We do not accept any responsibility or liability for the privacy practices of such third-party websites and your use of such websites is at your own risk.
The security of your personal information is important to us. We follow generally accepted best practice industry standards to protect the personal information submitted to us, both during transmission and once we receive it.
We use all reasonable measures to safeguard personally identifiable information, which measures are appropriate to the type of information maintained and follows applicable laws regarding safeguarding any such information under our control. In addition, in some areas of our Sites, we use encryption technology to enhance information privacy and help prevent loss, misuse, or alteration of the information under our control. We also employ industry-standard measures and processes for detecting and responding to inappropriate attempts to breach our systems.
No method of transmission over the Internet, or method of electronic storage, can be 100% secure. Therefore, we cannot guarantee the absolute security of your information. The Internet by its nature is a public forum, and Everybody Health & Leisure encourages you to use caution when disclosing information online. Often, you are in the best situation to protect yourself online. You are responsible for protecting your username and password from third-party access, and for selecting passwords that are secure.
If you have any concerns that your Everybody Health & Leisure account could have been compromised e.g. someone could have discovered your password, please get in touch straight away.
Some third-party providers may set cookies or process personal data on our behalf.
Where data is transferred outside the UK or EEA, appropriate safeguards such as Standard Contractual Clauses or the UK International Data Transfer Agreement are in place.
Our third-party systems include:
- Coursepro
- Eequ
- Leisure Hub
- MyFitApp
- Referall
- Stripe
- Ticket Tailor
- Totara
Third-Party Systems
Within our facilities, we have developed partnerships with companies that offer services to our users. To access these services, users may have to disclose personal data. All systems are totally optional.
All partners have been carefully selected and the way they use data has been scrutinised. We take steps to ensure providers implement appropriate data
protection measures. We are not responsible for the privacy practices of third party websites. We recommend reviewing their privacy policies before providing
personal information.
Some providers act as data processors on our behalf, while others act as independent data controllers. Where providers act as independent data processors,
we have appropriate contracts in place. Where they act as controllers, their own privacy policies apply.
The relevant privacy policy for each organisation is available as follows:
- Boditrax – https://www.boditrax.com/privacy
- CoursePro – https://www.fitronics.com/Privacy/
- Eequ – https://help.eequ.org/en/articles/221003-eequ-privacy-policy
- eGym – https://www.egym.com/datenschutz
- Google Analytics – https://policies.google.com/technologies/partner-sites
- Gravity – https://www.gravityforms.com/privacy/
- Healum (Everybody Wellness App) – https://www.healum.com/privacypolicy/
- iTrent – https://mhrglobal.com/uk/en/privacy-policy
- MyFitApp- https://www.myfitapp.com/privacy/
- Myzone – http://myzone.org/privacy/
- Netpulse – https://us.egym.com/en-us/privacy
- Referall – https://www.refer-all.net/privacy-policy
- Stripe – https://stripe.com/gb/privacy
- SwimTag – https://www.swimtag.net/legals.xhtml#privacyPolicy
- Technogym – https://www.technogym.com/gb/privacy-policy/
- Totara – https://www.totara.com/privacy-policy/
- Ticket Tailor – https://www.tickettailor.com/legal/privacy-policy
- XN Leisure – https://xnleisure.com/wpcontent/uploads/2025/07/Jonas_Privacy_Policy_post_Brexit_Jan_2021-1.pdf
Everybody App
The Everybody App is provided via MyFitApp and enables users to make and manage bookings, view centre information including timetables, browse memberships, refer a friend and view their membership card.
The app collects and processes limited health and fitness data only as necessary to provide core fitness and activity-tracking functionality. Subject to user consent, this may include workout and activity information such as activity type, duration, distance, time, calories burned, step counts, and activity status obtained from system health platforms, including Google Health Connect on Android and Apple Health on iOS. This data is used solely for displaying activity history, generating fitness insights, enabling in-app challenges, and supporting app functionality. Health and fitness data is not used for advertising, marketing, or profiling, is not sold or shared with third parties, and access permissions may be reviewed or revoked at any time through device settings. The app does not collect or process sensitive health or medical information.
Everybody Wellness App
Everybody Wellness App (Healum Ltd) is an AI powered patient management platform used to support personalised care and remote monitoring. Where utilised, Healum acts primarily as data processor processing personal data strictly on thedocumented instructions of the data controller.
Healum stores and processes personal data within the UK and applies appropriate technical and organisational measures to ensure data security and confidentiality, including secure cloud hosting, role-based access controls, and compliance with NHS Data Security and Protection Toolkit requirements.
At the end of any contractual arrangement, Healum will securely destroy personal data in accordance with Everybody Health & Leisure’s instructions.
CoursePro
Coursepro is a standalone system to hold customer details for swimming lessons. We collect personal details such as name, gender, email address, address, phone number, payment information and any other necessary account details. Medical information and learning processing information may also be stored on the account for the sole reason of allowing us to personalise our service where possible. Full access to this data is held on a permission level basis with MFA enabled. Lower levels of access to more basic information are password protected and only visible to the relevant staff member at the relevant time. Data is held during the time as a live customer and for 6 months after.
Social Media and Online Engagement other than the Everybody Website
We use a variety of online engagement tools and social media options to communicate and interact with customers, potential customers, employees and potential employees. These sites and applications include popular social networking and media sites, open-source software communities and more. To better engage the public in ongoing dialog, we use certain third-party platforms including, but not limited to, Facebook, Twitter and LinkedIn. Third-Party Websites and Applications (TPWA) are Web-based technologies that are not exclusively operated or controlled by Everybody Health & Leisure.
When interacting with the Everybody Health & Leisure presence on those websites, you may reveal certain personal information to Everybody Health & Leisure or to third-parties. Other than when used by Everybody Health & Leisure employees for the purpose of responding to a specific message or request, Everybody Health & Leisure will not use, share, or retain your personal information. The individual privacy policy for each organisation is available at:
- Facebook – http://www.facebook.com/policy.php
- Instagram – https://about.instagram.com/safety/privacy
- LinkedIn – https://www.linkedin.com/legal/privacy-policy
- TikTok – www.tiktok.com/legal/privacy-policy
- X – https://x.com/en/privacy
- YouTube – https://www.youtube.com/intl/en_be/howyoutubeworks/privacy/
We rely on our legitimate interests to manage and respond to enquiries and engage with our community via social media. Where required, we will obtain consent for specific marketing activities. For certain activities (such as page analytics and insights), we may act as joint controllers with the social media platform provider.
This may include your username, profile information, comments, direct messages, and other content you choose to share.
We retain social media interactions only for as long as necessary to respond to your enquiry or manage our relationship with you, and in line with our overall data
retention policy.
We recommend that you do not share sensitive personal information (such as health information or safeguarding concerns) via social media channels. You can control how your data is used through your social media account settings and may contact us directly to exercise your data protection rights.
Compliance, Monitoring & Enforcement
Everybody Health & Leisure adheres to the European Union Data Protection (95/46/EC) and e-Privacy (2002/58/ED) Directives, the Data Protection Act 2018 and the General Data Protection Regulations.
We do, for legitimate business reasons, transfer minimal data outside the EU and all/any company in the US will be required to adhere to the GDPR principles and have signed up to the US Privacy Shield.
We regularly review our compliance with our Privacy Policy. We also adhere to several self-regulatory frameworks in addition to complying with applicable law. If we receive formal written complaints, we will follow up with the person making the complaint. We work with the appropriate regulatory authorities to resolve any complaints that cannot be resolved directly.
Accessing and Updating Your Personal Information
It is important to ensure that the personal information we hold about you is accurate and up-to-date, and you should let us know if anything changes, for example if you change your phone number or email address.
If you have provided us with your personal information, you have the right to inspect the information stored by us for accuracy or may request that the information be removed from our records. We will make all reasonable efforts to comply with such requests except where it would require a disproportionate effort (for example developing a new system or changing an existing practice).
We will require that you verify your identity before we act on a request to edit or remove your information.
Requests to update or any requests regarding your personal data held by Everybody Health & Leisure can be made by emailing [email protected]
Data Breach Notification
In the unlikely event of a data breach, we will ensure that we follow all ICO (Information Commissioner’s Office) notification timelines.
If a breach poses a high-risk to your rights and freedoms, we will promptly notify you explaining:
- What happened and what data was affected
- The potential impact and the steps taken to reduce risk
- What you can do (e.g. change passwords, monitor accounts)
- How to contact us – [email protected]
Monitoring & Review
This policy will be reviewed every two years as a minimum or more often in light of legal or best practice changes.
