ECHELON - EU & UK Privacy Notice
Last updated [25/11/2020]
Thank you for choosing to be part of our community at Echelon Fitness UK Limited (“Echelon”, “we”, “us”, or “our”). We are committed to protecting personal data that concerns you, and your right to privacy.
Personal data is any information about you or relating to you from which we are able to identify you, or where you can be identified by other means available to us.
This Privacy Notice sets out the types of personal data we process, the purposes for which it is processed, and other information including your rights under the EU General Data Protection regulation (GDPR), the Data Protection Act 2018, and other applicable laws ("Data Protection Laws"). It applies to all personal data concerning individuals located in the UK or EU and processed in relation to:
In this Privacy Notice, when we say "the Services", we mean all or any of the above.
We hope you take some time to read this Privacy Notice carefully, or at least the summary information below. It is important and will help you make an informed decision about sharing your personal data with us.
Residents of California If you are a resident of California, State law allows you certain rights regarding your Personal Information. You can find out more by reading our California Privacy Notice, which complements the terms of this Privacy Notice, here [insert link, and ensure a reciprocal link from the CA Privacy Notice – SMR]
The following is a very short summary of the information contained in this Privacy Notice. It is provided for your ease of reference but is not intended to replace the full information which follows.
This can include your name, address and other identification details, location, IP address, data relating to your use of the Services, and data relating to your health.
We obtain personal data either directly from you, from you through your use of the Services, or from third parties where you provide them with personal data in connection with your use of the Services.
Where we process your information as a controller, it is for the purposes necessary for providing the Services, which may include of fulfilling a contract between us, compliance with our legal obligations, certain purposes that are required to further our legitimate business interests, or for any other purpose where we have your consent.
We only share information with your consent, to comply with laws, to provide you with the Services, to protect your rights, or to fulfil business obligations.
Some of your personal data will be transferred to the US for processing by our US affiliate. Your information will be kept secure and your rights and freedoms protected.
We only keep your personal data as long as you give your consent, or for as long as we have another lawful reason to process your personal data.
We protect your personal data through the application of various organisational and technical security measures.
You have a number of rights under the Data Protection Laws, including the right to access your personal data, to withdraw your consent, or to object to further processing.
Major updates to this Privacy Notice will be provided to you by email, through the mobile app, or by notice on the website. Minor updates will be made by updating this Privacy Notice online.
If you have any questions or concerns about our notice, or our practices with regards to your personal data, please contact us at CS@echelonfit.uk, or 88 Crawford Street, London, England, W1H 2EJ.
We may process data about your use of the Services ("Usage Data"). The Usage Data may include your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use and inferences gained from analyzing your data as far as they related to the Services. The source of the Usage Data is our analytics tracking system. This Usage Data may be processed for the purposes of analysing your use of the Services.
We may process your account data ("Account Data"). The Account Data may include your name and email address. The Account Data may be processed for the purposes of operating our website, providing the Services, ensuring the security of our website and services, maintaining back-ups of our databases and communicating with you.
We may process your information included in your personal profile on the Services ("Profile Data"). The Profile Data may include your name, address, telephone number, email address, profile pictures, gender, date of birth, relationship status, interests and hobbies, educational details and employment details. We may capture your visual image, likeness and voice recording (e.g., via photographs and/or video) if you visit our studios and/or showrooms, participate in live or web-based studio classes and/or call our member support or inside sales teams. We record and store member support and sales calls to train support and sales agents to help resolve member questions, for quality purposes and as required by law. Additionally, Echelon fitness equipment and Echelon applications may contain a camera, microphone and voice control features. These features are in use only when activated by you, for example, to take a user profile photo or to initiate or accept a video chat from another user. The profile data may be processed for the purposes of enabling and monitoring your use of our website and services.
We may process your personal data that is provided during the use of the Services ("Service Data"). The Service Data may be processed for the purposes of operating our website, providing the Services, ensuring the security of our website and services, maintaining back-ups of our databases and communicating with you.
We may process personal data that you post for publication on or through the Services ("Publication Data"). The Publication Data may be processed for the purposes of enabling such publication and administering the Services.
We may process personal data contained in any enquiry you submit to us regarding goods and/or Services ("Enquiry Data"). The Enquiry Data may be processed [for the purposes of offering, marketing and selling relevant goods and/or services to you.
We may process personal data relating to our customer relationships, including customer contact information ("Customer Relationship Data"). The Customer Relationship Data may include your name, your employer, your job title or role, your contact details, and information contained in communications between us and you or your employer. The Customer Relationship Data may be processed for the purposes of managing our relationships with customers, communicating with customers, keeping records of those communications and promoting our Products and Services to customers. In all cases this processing will be carried out in accordance with applicable law on electronic marketing.
We may process information relating to transactions, including purchases of goods and services, that you enter into with us and/or through the Services ("Transaction Data"). The Transaction Data may include your contact details, your card details and the transaction details. The Transaction Data may be processed for the purpose of supplying the purchased goods and services and keeping proper records of those transactions.
We may process information that you provide to us for the purpose of subscribing to our email notifications and/or newsletters ("Notification Data"). The Notification Data may be processed for the purposes of sending you the relevant notifications and/or newsletters.
We may process information contained in or relating to any communication that you send to us ("Correspondence Data"). The Correspondence Data may include the communication content and metadata associated with the communication. The Services will generate the metadata associated with communications made using the Services’ contact forms. The Correspondence Data may be processed for the purposes of communicating with you and record-keeping.
Some of the personal data you provide or generate when using the Echelon Fit app, for instance your height, weight, age and biometric data including your heartrate, which relate to your physical health and wellbeing, may fall under the special category for which the Data Protection laws require enhanced protection and the identification of a more specific lawful purpose ("Sensitive Data"). We will only process Sensitive Data with your explicit consent, and never for purposes to which you have not consented.
We may combine any of these categories of data in order to develop the Services.
Most of the personal data we process is provided to us directly by you, and some we obtain through your use of the Services. We also may obtain personal data concerning you from third parties including:
We use personal data for a variety of “Business Purposes” set out in this paragraph 9. We process your personal data for these purposes in reliance on our legitimate business interests, in order to enter into or perform a contract with you, with your consent (for Sensitive Data), and/or for compliance with our legal obligations.
In each case, the lawful basis for this processing is the fulfilment of a contract with you or the pursuance of our legitimate business interest and in some cases both apply. Where another specific lawful basis applies to a type of processing or class of personal data, for instance your consent, this is indicated below.
We use the information we collect or receive:
We may need to share your personal data with third parties in the following situations:
Where your data is shared with third party providers, we will ensure that suitable legal measures are in place to ensure confidentiality and security of personal data.
Our affiliate, Echelon Fitness Multimedia LLC operates the Echelon Fit app and various aspects of the Services that are provided on a global basis. Echelon Multimedia LLC is located and domiciled in the USA and so the bulk of the related processing activities are carried out in the USA. Consequently, personal data that concerns you will be routinely transferred to, stored in, and processed by us in, the USA.
We shall take all reasonable steps to protect the security and integrity of any personal data concerning you, and your rights and freedoms as a data subject, while your personal data is being processed overseas. All such transfers will be made subject to an approved transfer mechanism, which will include at least a Data Transfer Agreement incorporating the Standard Contractual Clauses approved by the EU Commission and the UK Parliament as providing sufficient safeguards for such transfers, and under which you have directly enforceable rights. A copy of the Data Transfer Agreement is available on request.
We will only keep your personal data for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law (such as tax, accounting or other legal requirements). In general, we will not keep your personal data for longer than 2 years after the termination of your account or stopping your use of the Services.
When we have no ongoing legitimate business need to process your personal data, we will either delete or anonymize it, or, if this is not possible (for example, because your personal data has been stored in backup archives), then we will securely store your personal data and isolate it from any further processing until deletion is possible.
We have implemented appropriate technical and organizational security measures designed to protect the security of any personal data we process. However, please also remember that we cannot guarantee that the internet itself is 100% secure. Although we will do our best to protect your personal data, transmission of personal data to and from the Services is at your own risk. You should only access the services within a secure environment.
If we are relying on your consent to process your personal data, you have the right to withdraw your consent at any time. Please note however that this will not affect the lawfulness of processing carried out before consent was withdrawn.
Under the Data Protection Laws you have certain specific rights relating to your personal data which are set out below.
Please note that not all these rights are absolute, and they do not apply in all circumstances. However, you are always welcome to contact us with any request relating to processing of your personal data and, even if we are not obliged by law to comply with your request, we will do everything reasonable to accommodate your wishes.
If you think we have not complied with the requirements of the law as it applies to your personal data, you have a right to lodge a complaint with any data protection supervisory authority. The Supervisory Authority in the UK is the Information Commissioner’s Office (ICO): firstname.lastname@example.org or 0303 123 1113 / +44 1625 545 700; www.ico.org.uk.
You can find details EU Supervisory Authorities here: https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm.
If you have questions or comments about your privacy rights, you may email us at CS@echelonfit.uk
We may update this privacy notice from time to time. The updated version will be indicated by an updated “Revised” date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes on the website or by sending you a notification through the mobile app. We encourage you to review this privacy notice frequently to be informed of how we are processing and protecting your personal data.
If you have questions or comments about this policy, you may email us at CS@echelonfit.uk or by post to:
Echelon Fit UK Ltd
88 Crawford Street
London W1H 2EJ
[Add Contact Details of Data Protection Officer, if appropriate SMR]