Last updated 9 September 2026
This privacy policy explains how TDM Gym collects, uses, shares and protects personal data when you visit our websites, apply for or use a gym membership, buy equipment, request a quote, join a mailing list, visit our premises or otherwise communicate with us. It also explains your rights under UK data protection law.
This policy is a privacy notice, not a contract. You do not consent to all processing simply by using our websites or services. We use personal data only where we have a lawful basis.
1 Who we are
TDM Gym is the controller responsible for the personal data described in this policy.
Postal address: TDM Gym, Azzurri House, Walsall Business Park, Aldridge, Walsall, WS9 0RB, United Kingdom
Email: contact@tdmgym.co.uk
Telephone: 0330 133 9438
Websites: TDM Gym website and TDM Gym equipment shop
2 Personal data we collect
Depending on your relationship with us, we may collect:
-
Identity and contact data, such as your name, date of birth or age confirmation, email address, telephone number, billing address, delivery address and emergency contact details where relevant.
-
Membership and application data, such as the information in an application, membership type, start and end dates, payment status, attendance or access records, communications and membership history.
-
Order and transaction data, such as products viewed or purchased, quotes, order history, delivery and installation information, returns, refunds and payment status. Card providers process full card details; we do not normally receive or retain the full card number.
-
Enquiry and communications data, including messages, call notes, support requests, reviews, feedback and social-media communications.
-
Health or accessibility information that you choose to provide, or that is required to manage a specific safety or accessibility request. This may be special category data and receives additional protection.
-
Premises and security data, where applicable, such as CCTV images, incident reports and access-control records. Signs at the premises provide additional information about CCTV use.
-
Technical and usage data, such as IP address, device and browser details, approximate location derived from IP address, referring page or campaign, pages viewed, interactions, timestamps, cookie identifiers and diagnostic or security logs.
-
Marketing and preference data, such as mailing-list subscriptions, interests, campaign engagement, unsubscribe choices and cookie preferences.
Please do not include unnecessary sensitive information in forms, messages, reviews or photographs. We do not ordinarily seek criminal offence data.
Where we obtain personal data
We usually obtain personal data directly from you through our websites, shop, membership application, in-person interactions, forms, email, telephone and social media. We may also receive data from:
-
a person or organisation acting for you;
-
e-commerce, website, hosting, analytics, communications and advertising providers;
-
payment, finance, fraud-prevention and identity-verification providers;
-
delivery, installation and logistics providers; and
-
public sources or referral platforms where appropriate and lawful.
3 How we use personal data and our lawful bases
The lawful bases that normally apply to our main processing activities are set out below.
|
Purpose |
Data used |
Lawful basis |
|
Respond to enquiries, quotes and membership applications |
Contact, application, product and communications data |
Steps at your request before a contract; legitimate interests for business enquiries |
|
Set up and administer memberships, day passes and access |
Identity, contact, membership, payment and access data |
Contract; legitimate interests when you act for an organisation |
|
Process orders, payments, delivery, installation, returns and refunds |
Identity, contact, order, transaction, payment and delivery data |
Contract; legal obligation |
|
Support customers and members; manage complaints, incidents and legal claims |
Contact, membership, transaction, communications, incident and relevant health data |
Contract; legal obligation; legitimate interests in service, safety and legal rights |
|
Address a health, safety or accessibility need |
Relevant health or accessibility data |
Contract or legitimate interests plus explicit consent for special category data; vital interests in an emergency |
|
Protect people, premises, equipment and systems; prevent fraud |
Identity, transaction, CCTV, access and technical data |
Legitimate interests in safety, security and fraud prevention; legal obligation where applicable |
|
Keep financial, tax and corporate records |
Identity, transaction, order, membership and payment data |
Legal obligation; legitimate interests in accurate business administration |
|
Operate, troubleshoot and improve websites and services |
Technical, usage, preference, survey and communications data |
Legitimate interests where consent is not required; consent for non-exempt technologies |
|
Send and measure direct marketing |
Contact, marketing preference and engagement data |
Consent, or legitimate interests where electronic marketing rules permit; consent for non-exempt tracking |
|
Plan or complete a business sale, purchase or reorganisation |
Relevant customer, member, supplier and transaction data |
Legitimate interests in managing the business, with appropriate safeguards |
Our legitimate interests include responding to enquiries, running and improving the gym and shop, maintaining appropriate records, protecting people and property, preventing fraud, securing systems, understanding service performance and protecting our legal rights. We balance those interests against your rights and reasonable expectations before relying on them.
For special category data, we also identify a condition under Article 9 of the UK GDPR. We will normally rely on explicit consent for health or accessibility information you voluntarily provide, and may rely on vital interests in an emergency where you cannot give consent.
If we need to use personal data for a new purpose that is not compatible with the original purpose, we will provide further information and identify a valid lawful basis before doing so.
4 Information you need to provide
You do not have to provide personal data merely to browse our websites. We need certain information to assess a membership application, administer a membership or pass, respond to an enquiry, process an order, deliver equipment, take or refund payment, and meet legal obligations. We will identify mandatory information. If you do not provide it, we may be unable to provide the requested service or complete a transaction.
5 Cookies and similar technologies
We use cookies and similar storage or access technologies, including local storage, pixels and tags.
-
Strictly necessary technologies may be used without consent where they are needed to transmit communications, provide a service you request, maintain security or remember privacy choices.
-
Limited analytics or functionality technologies may be used without consent only where a statutory exception applies and we meet its conditions, including clear information and a simple objection or opt-out mechanism where required.
-
Other analytics, advertising and tracking technologies are not used until you consent. You can refuse them without losing access to the core service and can change your choice through the website’s cookie settings.
Our cookie settings and Cookie Policy identify the technologies in use, their providers, purposes and durations.
6 Direct marketing
We may send marketing about equipment, gym memberships, events, services, promotions and related content where you have consented or where the existing-customer soft opt-in applies. The soft opt-in may apply when we obtained your details during negotiations for, or the sale of, our products or services, the marketing concerns similar products or services, and we offered a clear opt-out when collecting the details and in every message.
You can opt out at any time through the unsubscribe method in a message or by contacting us. We may retain a minimal suppression record so we continue to respect your choice. Messages needed to administer an application, membership, order, delivery, safety matter or policy change are service communications rather than marketing.
7 Who we share personal data with
Where necessary and lawful, recipients may include:
-
website, e-commerce, hosting, IT support, communications, email marketing, analytics and cybersecurity providers;
-
banks, card processors, finance providers and fraud-prevention services;
-
delivery, installation, storage and logistics partners;
-
membership administration, access-control, security and CCTV service providers;
-
professional advisers, auditors and insurers;
-
government bodies, regulators, courts, law-enforcement agencies and tax authorities where disclosure is required or permitted by law; and
-
a prospective buyer, seller or adviser involved in a genuine business transaction, subject to confidentiality and data-protection safeguards.
Processors acting for us must follow our documented instructions, keep personal data secure and use it only for the agreed services. Some recipients, including banks and finance providers, act as independent controllers and provide their own privacy information. We do not sell personal data.
8 International transfers
Some providers may process personal data outside the United Kingdom. Where a transfer is restricted under UK data protection law, we use a permitted mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, binding corporate rules or a permitted exception in limited circumstances. Where required, we assess whether protection is not materially lower than under UK law and apply supplementary measures.
Contact us for more information about the safeguards used for a particular transfer or how to obtain a copy, subject to lawful redactions.
9 How long we keep personal data
We retain personal data only for as long as needed for the purpose collected, including legal, tax, accounting, reporting, safety, fraud-prevention and dispute requirements. Our usual periods are:
|
Record |
Usual retention period |
|
Unsuccessful or withdrawn membership applications |
Usually up to 12 months after the decision or withdrawal |
|
Memberships, passes, orders, delivery and payment records |
Usually 6 years after the relationship or transaction ends, or longer where law or a live dispute requires |
|
Health and accessibility information |
For the relevant membership or request, then only as long as needed for safety, legal obligations or claims |
|
Enquiries that do not lead to a membership or order |
Up to 24 months after the last meaningful contact |
|
Complaints, incidents and data-rights correspondence |
Usually 6 years after closure, with identity evidence removed sooner where possible |
|
CCTV and routine access records |
CCTV usually up to 30 days and access logs usually up to 12 months, unless needed for an incident, investigation or claim |
|
Website security and diagnostic logs |
Usually up to 12 months, unless needed longer to investigate an incident |
|
Marketing records |
Until you opt out or the data is no longer accurate or needed; suppression records may be retained to honour an opt-out |
|
Cookies and similar identifiers |
For the period stated in the cookie settings or Cookie Policy |
10 Security and data breaches
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration or disclosure. Measures may include access controls, encryption where appropriate, secure backups, supplier checks, staff procedures and incident-response processes. Access is limited to people who need the information for their role. No system is completely secure, but we review safeguards in light of the data and risks involved.
If a personal data breach occurs, we will assess it and notify the Information Commissioner’s Office and affected people where UK law requires.
11 Your data protection rights
Depending on the circumstances and lawful basis, you may have the right to:
-
ask for access to your personal data and information about its use;
-
ask us to correct inaccurate or incomplete personal data;
-
ask us to delete personal data in certain circumstances;
-
ask us to restrict processing in certain circumstances;
-
receive personal data you provided in a structured, commonly used and machine-readable format, or ask us to send it to another controller, where portability applies;
-
object to processing based on legitimate interests, including related profiling;
-
withdraw consent at any time, without affecting processing carried out before withdrawal; and
-
ask for safeguards where a decision with legal or similarly significant effects is made solely by automated processing.
Your right to object: You have an absolute right to object at any time to direct marketing. You may also object to processing based on legitimate interests. We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
To exercise a right, contact us using the details below. We may request information needed to verify your identity and clarify the request. There is normally no fee. We will respond without undue delay and usually within one month, subject to lawful extensions or limitations.
12 Automated decision making
We do not make decisions about you based solely on automated processing, including profiling, that produce legal or similarly significant effects. Membership applications are reviewed by people. If this changes, we will update this policy and provide the information and safeguards required by law.
13 Children
Our services are intended for adults. We do not knowingly enter into memberships or equipment-purchase contracts with anyone under 18. If you believe a child has provided personal data to us, please contact us. We will investigate and delete the data where appropriate. If an online service becomes likely to be accessed by children, we will assess their needs and apply age-appropriate design and privacy safeguards.
14 Complaints
You can submit a data-protection complaint by emailing contact@tdmgym.co.uk or writing to our postal address. We will acknowledge the complaint within 30 days and, without undue delay, investigate, keep you informed where appropriate and tell you the outcome.
You may also complain to the Information Commissioner’s Office. Current complaint guidance and contact details are available at ICO complaint service or by telephone on 0303 123 1113. You do not have to contact us before approaching the ICO.
15 Third party links
Our websites may link to sites, services or social-media platforms operated by other organisations. Those organisations are responsible for their own privacy practices. Please read their privacy information before providing personal data.
16 Changes to this policy
We may update this policy when our services, data use or legal obligations change. The current version will be posted on our websites with a revised last-updated date. If a change is significant, we will take reasonable steps to bring it to your attention.
17 Contact us
For questions, rights requests or complaints about personal data, contact:
TDM Gym
Azzurri House
Walsall Business Park
Aldridge
Walsall
WS9 0RB
United Kingdom
Email: contact@tdmgym.co.uk
Telephone: 0330 133 9438
Instagram
Facebook
TikTok