Your Gym Privacy Policy
Last Updated: June 2026
YOURGYM LYTHAM LTD
Privacy Notice Addendum – Facial Recognition Access Control and Attendance Analytics
Effective Date: June 2026
This notice explains how YOURGYM LYTHAM LTD uses facial recognition technology and attendance analytics as part of its membership services.
This notice should be read alongside the main YourGym Privacy Policy.
1. WHO WE ARE
YOURGYM LYTHAM LTD is the Data Controller responsible for your personal information.
Registered Office:
Unit 8 St Georges Court
St Georges Park
Kirkham
Preston
Lancashire
PR4 2EF
For questions relating to this notice, please contact the gym directly.
2. WHAT INFORMATION WE COLLECT
As part of our membership services we may collect:
Membership Information
• Name
• Email address
• Telephone number
• Membership number
• Membership status
Access Control Information
• Profile photograph
• Entry and exit records
• Access events
• Attendance history
Membership Activity Information
• Class attendance records
• Purchase history
• Membership usage information
Biometric Information
Where you choose to use facial recognition access, facial biometric templates are generated and used by authorised access control systems to verify your identity.
3. WHY WE USE THIS INFORMATION
We use your information to:
• Verify your identity.
• Control access to gym facilities.
• Prevent unauthorised access.
• Prevent membership sharing.
• Protect members and staff.
• Maintain attendance records.
• Support emergency occupancy management.
• Improve operational planning.
• Improve member experience.
• Support member engagement and retention activities.
4. FACIAL RECOGNITION
Facial recognition is available as an optional method of accessing the gym.
If you choose to use facial recognition:
• You will be asked to provide a profile photograph.
• A facial biometric template will be generated by authorised access control systems.
• The template will be used solely for authentication and access control purposes.
Facial biometric information is not used for:
• Marketing.
• Advertising.
• Sale to third parties.
• Behavioural profiling using facial characteristics.
5. ATTENDANCE ANALYTICS
We analyse attendance and membership activity information to:
• Understand facility usage.
• Improve services.
• Identify members who may benefit from additional support.
• Improve member engagement.
• Improve retention and member outcomes.
Examples may include identifying members who have not attended recently so that support, guidance or assistance can be offered.
Attendance analytics are generated using attendance records and membership information and are not generated using facial biometric templates.
No solely automated decisions producing legal or similarly significant effects are made using attendance analytics.
6. OUR LAWFUL BASIS
We process personal data under the following lawful bases:
Article 6(1)(f) UK GDPR – Legitimate Interests
Our legitimate interests include:
• Protecting members and staff.
• Securing our facilities.
• Preventing fraud.
• Preventing membership misuse.
• Improving our services.
Biometric Processing
Where facial recognition is used, we rely on your explicit consent under Article 9(2)(a) UK GDPR.
You may withdraw your consent at any time.
7. ALTERNATIVE ACCESS METHODS
You are not required to use facial recognition.
Alternative access methods are available, including:
• QR code access.
• Membership card access.
• Staff assistance where required.
Withdrawal of consent will not affect your ability to access the facility.
8. HOW LONG WE KEEP INFORMATION
Profile photographs are retained while your membership remains active and only for as long as reasonably necessary.
Facial biometric templates are deleted within 30 days of:
• Membership termination.
• Withdrawal of consent.
• Removal from facial recognition enrolment.
Attendance records are normally retained for 12 months unless a longer retention period is required for legal, insurance or security purposes.
9. WHO WE SHARE INFORMATION WITH
We may share information with:
• Authorised staff.
• Service providers acting on our behalf.
• Technology providers supporting gym operations.
• Law enforcement agencies where required by law.
• Payment processing providers responsible for collecting and administering membership payments.
We do not sell personal information to third parties.
10. INTERNATIONAL TRANSFERS
Your information is hosted within the United Kingdom.
We do not routinely transfer your information outside the United Kingdom.
Should this change in future, appropriate safeguards will be implemented in accordance with UK GDPR requirements.
11. YOUR RIGHTS
You have the right to:
• Access your information.
• Correct inaccurate information.
• Request deletion where applicable.
• Restrict processing where applicable.
• Object to processing where applicable.
• Withdraw consent for facial recognition.
To exercise these rights, please contact the gym directly.
12. COMPLAINTS
If you have concerns about how your personal information is being used, you may contact YOURGYM LYTHAM LTD using our data protection complaints procedure.
We will investigate your complaint and respond within a reasonable period.
You also have the right to complain to the Information Commissioner's Office (ICO):
13. CHANGES TO THIS NOTICE
We may update this notice from time to time to reflect changes in our services, technology or legal obligations.
The latest version will always be available through our membership platform and on request.
1. Who We Are
Your Gym UK (“we”, “us”, “our”) operates www.yourgymfitness.co.uk and is responsible for how we collect and use your information as a data controller under UK data protection law.
2. Information We Collect
a) Personal Information You Provide
We may collect personal data you voluntarily give us, including:
Name, email, phone number
Address and postcode
Date of birth
Payment details (where applicable; processed securely by third-party providers)
Health or fitness information (only if you choose to provide it)
b) Information Collected Automatically
When you use our website, we may automatically collect:
IP addresses
Browser and device data
Analytics and usage information (e.g., pages visited)
Cookie identifiers
This information helps us improve your experience and understand how the site is used.
3. How We Use Your Information
We use your information to:
Provide and manage your membership or enquiries
Process payments and send confirmations
Improve our website and services
Communicate news, updates, offers (where you have opted in)
Comply with legal obligations
We will only use your personal data where we have a lawful basis to do so, such as your consent, performance of a contract with you, legal obligations, or our legitimate interests.
4. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to collect device information. Cookies help personalise your experience and support analytics.
You can manage your cookie preferences through your browser settings or through the cookie banner on our site, allowing you to accept or reject non-essential cookies.
5. Sharing Your Information
We may share your personal data with:
Trusted service providers (for payments, hosting, email communications)
Law enforcement or regulators when required by law
We do not sell or rent your personal information to third parties.
6. International Data Transfers
If any third-party service we use processes your data outside the UK, we ensure appropriate safeguards are in place to protect your information as required by law.
7. Data Retention
We keep your personal data only for as long as necessary to fulfil the purposes outlined in this policy, including legal, tax, or reporting requirements. After that, your information will be securely deleted or anonymised.
8. Your Rights
Under UK data protection law, you have rights including:
Access to your personal data
Correction of inaccurate data
Deletion of your personal data
Restriction or objection to processing
Withdrawal of consent at any time
To exercise your rights, contact: memberships@yourgymfitness.co.uk.
You also have the right to complain to the UK Information Commissioner’s Office (ICO) if you believe your data is not being handled properly.
9. Security
We take reasonable steps to protect your personal information from loss, misuse, and unauthorised access. However, no website or internet transmission is completely secure.
10. Children
Our services are not designed for people under 16. If we learn we have collected data from someone under 16 without verification, we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with a new Last Updated date. Please review this page regularly for updates.