THE CHAPEL GYM Privacy Policy
Privacy Notice
Who we are
The Chapel Gym CIO is a registered charity providing gym, wellbeing, housing support and recovery-related services in Corby.
The Chapel Gym CIO
Elizabeth Street
Corby
NN17 1TU
Registered charity number: 1185403
ICO registration number: ZA787071
The Chapel Gym CIO is the data controller for the personal information covered by this notice, except where we explain otherwise.
Our Data Protection Lead is Sam Hearsum.
For questions about your personal information or to exercise your data protection rights, contact:
What information we collect
The information we collect depends on your relationship with us and the services you use. It may include:
- your name, address, telephone number, email address and date of birth;
- membership and account information;
- attendance and gym access information;
- payment and transaction information;
- bank account number and sort code where required for Direct Debit administration;
- emergency contact information;
- information you provide when contacting us or completing a form;
- information about young people participating in our Youth Fitness Project, including information supplied by a parent, guardian or referrer;
- vehicle and parking information where relevant;
- CCTV images;
- information relating to employees, applicants and volunteers; and
- health or other sensitive information where it is genuinely necessary for us to provide a service safely or meet our responsibilities.
We try to collect only the information we actually need.
Gym membership and health information
We use members' personal information to administer memberships, provide access to the gym, manage member accounts, communicate about membership and services, collect payments, and operate the gym safely and effectively.
Our membership system is ClubManager.
Where you provide health information relevant to using the gym safely, we will only record or retain information where there is a genuine need to do so. We do not aim to collect or retain unnecessary medical information.
Where information from a PAR-Q or similar health declaration genuinely needs to be retained, it may be recorded or securely uploaded to your membership record. Unnecessary source documents are securely destroyed or deleted once the necessary information has been dealt with.
Depending on the particular processing, our legal grounds may include performing our contract with you, complying with legal obligations, and our legitimate interests in administering and operating the gym safely. Where we process health information or other special category information, we also identify an appropriate additional condition under data protection law.
Payments and Direct Debits
We process payment and transaction information to collect membership fees and other payments, administer accounts and maintain appropriate financial records.
We use third-party payment providers including GoCardless, Stripe and Zettle (a PayPal service). Depending on how you pay, these providers may process information such as your name and contact details, bank or payment-card details, transaction information and information needed to process and protect the payment.
These payment providers may have their own responsibilities under data protection law and provide their own privacy information.
For Direct Debits, The Chapel Gym also holds the account holder's sort code and bank account number within ClubManager. Access is limited to authorised staff who require it for membership and payment administration.
Young people
Some of our activities involve young people, including the Youth Fitness Project.
We may process information such as the young person's name, date of birth, contact details, parent or guardian information, referral information and information relevant to their participation, safety and support.
We recognise that children's personal information requires particular care. We limit access to those who need the information and aim to explain our use of information in language appropriate to the young person and the circumstances.
Where information is supplied by a parent, guardian, school, professional or other referrer rather than directly by the young person, we will handle it in accordance with our data protection and safeguarding responsibilities.
CCTV
CCTV operates at The Chapel Gym for security, safety and the prevention and investigation of incidents.
The system records video images. It does not intentionally record audio.
CCTV footage is normally overwritten after approximately 30 days. Relevant footage may be retained for longer where necessary to investigate an incident, deal with a safeguarding matter, respond to an insurance or legal issue, or assist law enforcement.
Access to CCTV is restricted to authorised people. Footage may be disclosed to organisations such as the police, insurers or safeguarding bodies where there is a lawful and appropriate reason to do so.
Website enquiries
If you contact us through our website or by email, we use the information you provide to respond to your enquiry.
Routine enquiries remain within our organisational email system and are deleted when they are no longer needed.
If your enquiry results in you joining a service or concerns a matter that needs to be formally recorded—for example a safeguarding issue—the relevant information may instead become part of the appropriate service or organisational record.
Chapel Homes and Hope into Action
The Chapel Gym operates Chapel Homes as a franchise of Hope into Action UK.
Chapel Homes processes information needed to assess applications, provide accommodation and support tenants. This can include sensitive information about health, support needs and personal circumstances.
Certain information is shared with Hope into Action UK under our franchise arrangements. For the Shared Data specified in that agreement, The Chapel Gym and Hope into Action UK act as separate data controllers, each responsible for its own use of the information.
People using Chapel Homes are provided with more specific privacy information about how their information is used and shared.
Chapel Recovery
The Chapel Gym operates Chapel Recovery, a lived-experience recovery organisation providing peer support, one-to-one recovery support, group sessions, counselling and referrals/signposting.
Because of the nature of the service, Chapel Recovery may need to process particularly sensitive information, including information about recovery, substance use and physical or mental health.
Access to this information is restricted and it is handled with particular care. People using Chapel Recovery will be provided with more specific privacy information about the use of their information.
Safeguarding
The Parochial Church Council of St John the Baptist Church with the Epiphany is responsible for safeguarding at The Chapel Gym.
Where a safeguarding concern arises, relevant information may be shared with the Parish Safeguarding Officer and, where necessary, other safeguarding or statutory organisations.
We only share information that is relevant and necessary and do not rely on consent where another lawful safeguarding basis requires or permits us to use or disclose information.
Employees and volunteers
We process information about employees, job applicants and volunteers for recruitment, employment, payroll, volunteer management, training, safeguarding and related administrative purposes.
Information may be shared with organisations such as our payroll provider, HMRC, pension providers, safeguarding organisations and other professional or statutory bodies where necessary.
How we use your information
Depending on your relationship with us, we may use personal information to:
- provide and administer our services;
- manage gym memberships and accounts;
- process payments;
- communicate with you;
- provide support;
- manage referrals and participation in projects;
- keep people safe and meet safeguarding responsibilities;
- manage employees and volunteers;
- prevent and investigate incidents;
- maintain financial and organisational records;
- meet legal, regulatory and contractual obligations; and
- establish, exercise or defend legal claims.
Under UK data protection law, we must have a lawful basis for each use of personal information. Depending on the circumstances, we may rely on contract, legal obligation, legitimate interests, consent, vital interests or another basis provided by law.
Where we process special category information, such as health information, we must also satisfy an additional legal condition.
We do not use consent simply because information is sensitive where another legal basis is more appropriate.
Who we share information with
We do not sell your personal information.
Where necessary and lawful, information may be shared with organisations that help us operate our services or meet our responsibilities. These may include:
- ClubManager;
- GoCardless;
- Stripe;
- Zettle/PayPal;
- our IT and cloud-service providers, including Google Workspace;
- Hope into Action UK in connection with Chapel Homes;
- the Parochial Church Council and safeguarding personnel;
- payroll and professional service providers;
- referral and support organisations;
- healthcare, counselling or support services where appropriate;
- local authorities and other statutory bodies;
- insurers and professional advisers; and
- the police or other law-enforcement bodies where appropriate.
We require organisations processing information on our behalf to protect it appropriately.
How long we keep information
We keep personal information only for as long as it is reasonably required for the purpose for which we collected it, including any legal, safeguarding, accounting, contractual or insurance requirements.
Different records therefore have different retention periods.
For example, CCTV is normally overwritten after approximately 30 days unless footage needs to be preserved for a particular matter.
When information is no longer required, it is securely deleted, destroyed or anonymised.
We maintain and review our retention arrangements as part of our data protection procedures.
Keeping your information secure
We use organisational and technical measures appropriate to the information we hold.
These include restricting access according to people's roles, individual user accounts, secure organisational Google Workspace accounts and Shared Drives, locked storage for appropriate paper records, access controls and other security measures.
Staff and volunteers must only access personal information where they need it for their role.
Information stored or accessed outside the UK
Some of the organisations and technology providers we use may store or access information outside the UK.
Where personal information is transferred internationally, we will ensure that the transfer is permitted under UK data protection law and that appropriate safeguards are used where required.
Marketing
We do not currently carry out routine electronic marketing.
If we use our systems to send promotional communications in future, we will only do so where permitted by data protection and electronic marketing law. Where consent is required, you will be able to withdraw it and opt out of future marketing.
This does not prevent us sending necessary service communications, such as messages concerning your membership or a service you are using.
COOKIES
We and our trusted partners use cookies and other technologies in our related services, including when you visit our Site or access our services.
A "cookie" is a small piece of information that a website assign to your device while you are viewing a website. Cookies are very helpful and can be used for various different purposes. These purposes include allowing you to navigate between pages efficiently, enable automatic activation of certain features, remembering your preferences and making the interaction between you and our Services quicker and easier. Cookies are also used to help ensure that the advertisements you see are relevant to you and your interests and to compile statistical data on your use of our Services.
The Site uses the following types of cookies:
a. 'session cookies' which are stored only temporarily during a browsing session in order to allow normal use of the system and are deleted from your device when the browser is closed;
b. 'persistent cookies ' which are read only by the Site, saved on your computer for a fixed period and are not deleted when the browser is closed. Such cookies are used where we need to know who you are for repeat visits, for example to allow us to store your preferences for the next sign-in;
c. 'third party cookies' which are set by other online services who run content on the page you are viewing, for example by third party analytics companies who monitor and analyze our web access.
Cookies do not contain any information that personally identifies you, but Personal Information that we store about you may be linked, by us, to the information stored in and obtained from cookies. You may remove the cookies by following the instructions of your device preferences; however, if you choose to disable cookies, some features of our Site may not operate properly and your online experience may be limited.
We also use a tool called “Google Analytics” to collect information about your use of the Site. Google Analytics collects information such as how often users access the Site, what pages they visit when they do so, etc. We use the information we get from Google Analytics only to improve our Site and services. Google Analytics collects the IP address assigned to you on the date you visit sites, rather than your name or other identifying information. We do not combine the information collected through the use of Google Analytics with personally identifiable information. Google’s ability to use and share information collected by Google Analytics about your visits to this Site is restricted by the Google Analytics Terms of Use and the Google Privacy Policy .
Your rights
Depending on the circumstances and the legal basis we rely upon, you may have the right to:
- ask for a copy of personal information we hold about you;
- ask us to correct inaccurate or incomplete information;
- ask us to delete your information;
- ask us to restrict how we use your information;
- object to certain uses of your information;
- receive certain information in a portable format; and
- withdraw consent where we rely on your consent.
These rights are not absolute and different rights apply in different circumstances.
You have the right to object to processing based on our legitimate interests. You also have an absolute right to object to the use of your personal information for direct marketing.
To exercise a data protection right, contact:
Sam Hearsum, Data Protection Lead
We may need to confirm your identity before releasing personal information.
Complaints
If you have concerns about how we use your personal information, please contact our Data Protection Lead first so that we have an opportunity to investigate:
You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator.
Information Commissioner's Office
Changes to this notice
We may update this Privacy Notice when our services, systems or legal obligations change.
Last Modified October 2026
