Chic Physique
HomeClassesTrainersPrice ListFitness SolutionsBlogContact
Join now

How we follow the GDPR

Last updated 23 July 2026

The General Data Protection Regulation is EU law that gives you real control over information about you, and puts the burden on organisations to earn and keep your trust. We are based in Malta and serve people across the EU, so it applies to us in full. This page explains what that means in practice — not as a legal recital, but as a description of how we actually work.

The seven principles, and what we do about each

Article 5 sets out seven principles that govern all processing. We are required not only to follow them but to be able to demonstrate that we do.

1. Lawfulness, fairness and transparency

Every piece of data we hold has a named lawful basis, listed row by row in our privacy notice. Nothing is collected for a reason we have not told you.

2. Purpose limitation

We use data for the purpose we collected it for. Your attendance record plans class timetables; it does not become a marketing list. If we ever wanted to use something for a genuinely new purpose, we would tell you first — and where that purpose relies on consent, ask you again rather than assume.

3. Data minimisation

We collect what the job needs and stop there. Our cookie consent log is the clearest example: it records the choice, the date and a random id, and deliberately stores no IP address and no browser fingerprint, because proving consent does not require identifying the person who gave it.

4. Accuracy

Staff can correct any member record on request, and you can ask us to fix something at any time. Where we correct data, we correct it everywhere it appears.

5. Storage limitation

Nothing is kept indefinitely "just in case". Every category has a stated retention period in the privacy notice, and data is deleted when it expires. Where a law requires us to keep something longer — accounting records, mainly — we say so rather than quietly holding on to it.

6. Integrity and confidentiality

Names, emails, phone numbers, addresses and dates of birth are encrypted in the database itself, so the stored data is unreadable without the key. Access to the staff dashboard is invite-only, sessions live in cookies JavaScript cannot read, every state-changing action is protected against cross-site request forgery, and login endpoints are rate-limited against brute force.

7. Accountability

We keep the records that let us prove the above: an append-only log of cookie-consent decisions, and a tracked queue of every data request with the date it arrived, who handled it, what was done and when it closed.

Your eight rights

These belong to you by law. Exercising them is free, we will never charge you or treat you differently for it, and we answer within one month. If a request is unusually complex we may extend that by up to two further months — and if we do, we will tell you why before the first month is up.

The right to be informed

Articles 13–14

To know what we collect, why, on what legal basis, who we share it with and how long we keep it — which is what the privacy notice and this page are for.

The right of access

Article 15

To get confirmation that we hold data about you, a copy of it, and an explanation of how it is used.

Make this request →

The right to rectification

Article 16

To have inaccurate data corrected and incomplete data completed, without undue delay.

Make this request →

The right to erasure

Article 17

To have your data deleted — the "right to be forgotten". We must comply unless a law requires us to keep something, such as accounting records.

Make this request →

The right to restrict processing

Article 18

To have us keep your data but stop using it, for example while a dispute about its accuracy is resolved.

Make this request →

The right to data portability

Article 20

To receive the data you gave us in a structured, machine-readable format, and to have it sent to another provider where technically feasible.

Make this request →

The right to object

Article 21

To object to processing based on our legitimate interests, and — absolutely, with no balancing test — to object to direct marketing at any time.

Make this request →

Rights around automated decisions

Article 22

Not to be subject to decisions made purely by automated means that significantly affect you, and to be told when that happens. We make no such decisions and do no profiling.

How we treat consent

Where we rely on consent — cookies, and permission to contact you — it has to be a real choice, so:

  • It is opt-in. Nothing is pre-ticked, and silence never counts as agreement.
  • It is specific. Each purpose is asked about separately, never bundled into a single "I agree".
  • It is informed. We say who, what, why and for how long before you decide.
  • It is freely given. Declining does not reduce your access to the site or the studio.
  • It is as easy to withdraw as to give. One link in the footer, no explanation required, effective immediately.
  • It is recorded. We keep evidence of what was agreed and when, because the law puts the burden of proof on us.

Automated decisions and profiling

We make none. No automated system decides anything that affects you, and we do not build behavioural profiles. The statistics we keep — how busy the studio gets by hour and weekday — exist to plan staffing and class times, and are read as aggregates.

Sending data outside the EU

Your data is hosted in the EU. The one routine exception is staff who choose to sign in with a Google account, where Google processes that sign-in under its standard contractual clauses — the transfer mechanism the European Commission approves for exactly this. No member data is transferred outside the EEA.

If something goes wrong

If a breach occurs that is likely to risk your rights and freedoms, we will report it to the Office of the Information and Data Protection Commissioner (IDPC) within 72 hours of becoming aware of it, and tell you directly without undue delay if the risk to you is high. We would rather tell you about a problem than have you find out some other way.

Keeping this current

We review our processing, this page and the privacy notice at least once every 12 months, and immediately whenever we change what we collect or who we share it with. The last review date is at the top of each page.

Questions, or a complaint

Ask us anything at team@chicphysiquestudio.com, or submit a formal request. If you are not satisfied with how we have handled it, you can complain to Office of the Information and Data Protection Commissioner (IDPC) at any time — you do not have to come to us first, though we would appreciate the chance to put things right.

Chic Physique

Professional, effective training in a spotlessly clean studio.

Opening hours

Monday – Friday: 05:00 – 21:00
Saturday & Sunday: 06:00 – 12:00

Find us

ChicPhysique Studio
Hilltop Gardens, Triq L-Inkwina, Naxxar

Get in touch

00356 21383837
team@chicphysiquestudio.com

© Chic Physique Studio
PrivacyCookiesGDPRRequest your dataStaff login