How we follow the GDPR
Last updated 23 July 2026
The General Data Protection Regulation is EU law that gives you real control over information about you, and puts the burden on organisations to earn and keep your trust. We are based in Malta and serve people across the EU, so it applies to us in full. This page explains what that means in practice — not as a legal recital, but as a description of how we actually work.
The seven principles, and what we do about each
Article 5 sets out seven principles that govern all processing. We are required not only to follow them but to be able to demonstrate that we do.
1. Lawfulness, fairness and transparency
Every piece of data we hold has a named lawful basis, listed row by row in our privacy notice. Nothing is collected for a reason we have not told you.
2. Purpose limitation
We use data for the purpose we collected it for. Your attendance record plans class timetables; it does not become a marketing list. If we ever wanted to use something for a genuinely new purpose, we would tell you first — and where that purpose relies on consent, ask you again rather than assume.
3. Data minimisation
We collect what the job needs and stop there. Our cookie consent log is the clearest example: it records the choice, the date and a random id, and deliberately stores no IP address and no browser fingerprint, because proving consent does not require identifying the person who gave it.
4. Accuracy
Staff can correct any member record on request, and you can ask us to fix something at any time. Where we correct data, we correct it everywhere it appears.
5. Storage limitation
Nothing is kept indefinitely "just in case". Every category has a stated retention period in the privacy notice, and data is deleted when it expires. Where a law requires us to keep something longer — accounting records, mainly — we say so rather than quietly holding on to it.
6. Integrity and confidentiality
Names, emails, phone numbers, addresses and dates of birth are encrypted in the database itself, so the stored data is unreadable without the key. Access to the staff dashboard is invite-only, sessions live in cookies JavaScript cannot read, every state-changing action is protected against cross-site request forgery, and login endpoints are rate-limited against brute force.
7. Accountability
We keep the records that let us prove the above: an append-only log of cookie-consent decisions, and a tracked queue of every data request with the date it arrived, who handled it, what was done and when it closed.
Your eight rights
These belong to you by law. Exercising them is free, we will never charge you or treat you differently for it, and we answer within one month. If a request is unusually complex we may extend that by up to two further months — and if we do, we will tell you why before the first month is up.
The right to be informed
Articles 13–14To know what we collect, why, on what legal basis, who we share it with and how long we keep it — which is what the privacy notice and this page are for.
The right of access
Article 15To get confirmation that we hold data about you, a copy of it, and an explanation of how it is used.
Make this request →The right to rectification
Article 16To have inaccurate data corrected and incomplete data completed, without undue delay.
Make this request →The right to erasure
Article 17To have your data deleted — the "right to be forgotten". We must comply unless a law requires us to keep something, such as accounting records.
Make this request →The right to restrict processing
Article 18To have us keep your data but stop using it, for example while a dispute about its accuracy is resolved.
Make this request →The right to data portability
Article 20To receive the data you gave us in a structured, machine-readable format, and to have it sent to another provider where technically feasible.
Make this request →The right to object
Article 21To object to processing based on our legitimate interests, and — absolutely, with no balancing test — to object to direct marketing at any time.
Make this request →Rights around automated decisions
Article 22Not to be subject to decisions made purely by automated means that significantly affect you, and to be told when that happens. We make no such decisions and do no profiling.
How we treat consent
Where we rely on consent — cookies, and permission to contact you — it has to be a real choice, so:
- It is opt-in. Nothing is pre-ticked, and silence never counts as agreement.
- It is specific. Each purpose is asked about separately, never bundled into a single "I agree".
- It is informed. We say who, what, why and for how long before you decide.
- It is freely given. Declining does not reduce your access to the site or the studio.
- It is as easy to withdraw as to give. One link in the footer, no explanation required, effective immediately.
- It is recorded. We keep evidence of what was agreed and when, because the law puts the burden of proof on us.
Automated decisions and profiling
We make none. No automated system decides anything that affects you, and we do not build behavioural profiles. The statistics we keep — how busy the studio gets by hour and weekday — exist to plan staffing and class times, and are read as aggregates.
Sending data outside the EU
Your data is hosted in the EU. The one routine exception is staff who choose to sign in with a Google account, where Google processes that sign-in under its standard contractual clauses — the transfer mechanism the European Commission approves for exactly this. No member data is transferred outside the EEA.
If something goes wrong
If a breach occurs that is likely to risk your rights and freedoms, we will report it to the Office of the Information and Data Protection Commissioner (IDPC) within 72 hours of becoming aware of it, and tell you directly without undue delay if the risk to you is high. We would rather tell you about a problem than have you find out some other way.
Keeping this current
We review our processing, this page and the privacy notice at least once every 12 months, and immediately whenever we change what we collect or who we share it with. The last review date is at the top of each page.
Questions, or a complaint
Ask us anything at team@chicphysiquestudio.com, or submit a formal request. If you are not satisfied with how we have handled it, you can complain to Office of the Information and Data Protection Commissioner (IDPC) at any time — you do not have to come to us first, though we would appreciate the chance to put things right.
