Document 02 of 04 · Effective 29 May 2026

PRIVACY POLICY.

Version  v1.0 Compliance  UK GDPR · Data Protection Act 2018 Regulator  Information Commissioner’s Office (ICO)
First-draft notice. This Privacy Policy is a working baseline drafted against the UK GDPR and the Data Protection Act 2018. It is not legal advice and is not a substitute for review by a UK-qualified solicitor or data-protection specialist before relying on it for a contested matter.

01Who we are (data controller)

The data controller is Julian Spiller, trading as Be The Change Fitness, a sole-trader fitness coach based in Wales, UK.

For all data-protection questions, requests, or complaints, contact: contact@bethechangefitness.co.uk.

You can also lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ICO), at ico.org.uk or by calling 0303 123 1113.

02What we collect

We only collect what we need to deliver the Services or to comply with a legal obligation. There are three broad categories.

Contact details

Health and fitness data

Special category data

Health and fitness data is treated as “special category data” under Article 9 UK GDPR. We process it on the basis of your explicit consent (given at sign-up) together with performance of the coaching contract. You can withdraw consent at any time — the consequence is we cannot continue delivering coaching that depends on it.

Payment data

03Lawful bases for processing

What we doLawful basis (UK GDPR Art. 6)Special-category basis (Art. 9, if applicable)
Deliver paid coaching Contract (Art. 6(1)(b)) Explicit consent (Art. 9(2)(a))
Send transactional emails (receipts, welcome pack, programme delivery) Contract (Art. 6(1)(b))
Send marketing emails (newsletter, free series, offers) Consent (Art. 6(1)(a)) — you opt in
Basic site analytics Legitimate interest (Art. 6(1)(f)) — understanding aggregate use
Comply with tax and accounting law (HMRC) Legal obligation (Art. 6(1)(c))
Defend or bring a legal claim Legitimate interest (Art. 6(1)(f)) Legal claims (Art. 9(2)(f))

04Who we share data with (processors)

We use trusted third-party processors. Each is bound by a data-processing agreement and processes data on our instructions only.

ProviderWhat they processRegion
StripePayments & receipts (card, recurring)Ireland / US (SCCs)
KlarnaPay-in-3 instalmentsEEA
Brevo (formerly Sendinblue)Transactional & marketing emailEU (France)
KahunasCoaching delivery (training plans, check-ins)UK / EU
NetlifyWebsite hosting & deliveryGlobal (US) — SCCs in place
CalendlyConsultation bookingUS (SCCs)
TypeformApplication & intake formsEU (Spain)
ManyChatInstagram DM automation — only if you opt in via a comment-to-DM flowUS (SCCs)
HMRCStatutory reporting where required by UK tax lawUK

We never sell your data. We do not run paid advertising trackers (such as the Meta Pixel) on this site at the time of writing.

05How long we keep your data

Data typeRetention period
Active client coaching data (programmes, check-ins, measurements)For the active term of coaching, then archived securely for up to 24 months in case of return or continuity.
Transactional and financial records (invoices, receipts, contracts)At least 6 years from the end of the relevant tax year — required by HMRC.
Marketing email list (newsletter, free series subscribers)Until you unsubscribe, then removed from active sending and held only in suppression for delivery compliance.
Application / consultation enquiries that did not convertUp to 12 months, then deleted.
Site analyticsAggregated, retained no longer than 26 months.

06Your rights

Under UK GDPR and the Data Protection Act 2018 you have the right to:

To exercise any of these, email contact@bethechangefitness.co.uk. We will respond within one calendar month, in line with UK GDPR.

07Cookies and analytics

We keep tracking minimal and deliberately avoid aggressive third-party advertising cookies.

If you do not consent to non-essential cookies, you can use private/incognito browsing or block cookies in your browser settings. Doing so will not affect your access to the free tools or coaching.

08Children

The Services are not directed at people under 18. You must be 18 or over to purchase coaching. The free tools and email series are written for adults; if you are under 18, please use them only with the involvement of a parent or guardian.

09International transfers

Some of our processors (Stripe, Netlify, Calendly, ManyChat) are headquartered in the United States. Where personal data is transferred outside the UK or EEA, the transfer is protected by the UK International Data Transfer Agreement (IDTA) or the European Commission’s Standard Contractual Clauses (SCCs), together with any additional safeguards required by the ICO’s guidance.

You can ask for a copy of the transfer mechanism in place for any specific provider by emailing the address above.

10Security

We apply appropriate technical and organisational measures:

11Changes to this Privacy Policy

We update this Policy when our processing changes, when a new processor is added, or when the law changes. The effective date at the top reflects the latest version. Material changes will be flagged to active clients by email at least 14 days in advance.

12Contact

Data-protection contact: contact@bethechangefitness.co.uk

Be The Change Fitness · Julian Spiller · Wales, UK