Compliance

GDPR Guide for Customers

Practical data-protection guidance for gyms, studios and organisations using ClassControl.

Effective: 18 July 2026 Last reviewed: 18 July 2026 Version: 1.0

1. Understand your role

The customer will normally be the Controller deciding why and how member and staff data is used. Eatwell Tech Solutions will generally be a Processor providing ClassControl on the customer’s instructions.

2. Provide privacy information

Tell members what you collect, why, the lawful bases, recipients, retention, rights and complaint route when information is collected. Link to both your organisation’s privacy notice and the relevant ClassControl platform information.

3. PAR-Q and health data

Health information is special-category data. Before enabling PAR-Q, document an Article 6 lawful basis and a separate Article 9 condition. Collect only what is necessary, restrict access and define retention.

4. Manage permissions

  • Use individual accounts.
  • Assign the lowest role needed.
  • Review administrators and instructors regularly.
  • Remove access promptly when someone leaves.
  • Do not share exported PAR-Q information through insecure channels.

5. Retention and deletion

Create retention periods for accounts, bookings, attendance and PAR-Q records. Retention should reflect purpose, legal obligations and safety needs rather than keeping data indefinitely.

6. Individual rights

Maintain a process for access, correction, deletion, restriction, portability and objection requests. Verify identity before disclosure and keep a record of how requests were handled.

7. Incidents

Report suspected compromise promptly. Preserve evidence, reset affected credentials, revoke access and coordinate with Eatwell Tech Solutions where platform assistance is required.