Legal / 2 September 2026

Privacy Notice

Effective 1 June 2025. PROTEQTPLUS LTD is the controller for personal data described in this notice. This notice explains what we collect, why we use it, who receives it, how long we keep it and your rights.

1. Controller

PROTEQTPLUS LTD, company number 16226856, registered office Flat 2, 33 Tyldesley Road, Blackpool, England, FY1 5DH, is the data controller for the member, prospect and website information described below. Contact us at hello@ironlogicfitness.com, call 020 3584 3839, or use our contact form.

2. Information we collect

  • Identity and contact details, including name, email, telephone number, address and account identifiers.
  • Membership details, including package, start date, access status, bookings, cancellations, support requests and complaints.
  • Payment and arrears data, including Stripe customer and subscription identifiers, invoices, payment status, Direct Debit mandate status, failed payment reasons, chargebacks, refunds, outstanding balances, reminder history and debt recovery notes.
  • Operational and safety information, including incident reports, access logs, CCTV where used, and health or accessibility information where needed for safety or service reasons.
  • Technical and security information, including device, browser, IP address, cookies, fraud-prevention and troubleshooting logs.

3. Why we use personal data and lawful bases

  • Contract: to set up and manage memberships, provide services, process payments, handle cancellations, refunds, support and recurring billing.
  • Legitimate interests: to run and improve the business, prevent fraud, secure the website and facilities, respond to enquiries, keep service records, manage complaints, recover unpaid debts and share necessary information with recovery partners where appropriate.
  • Legal obligation: to comply with accounting, tax, consumer, company, health and safety, court, regulatory and data protection obligations.
  • Consent: for optional marketing or optional health/accessibility information where consent is the appropriate basis.

If we process special-category health data, we will identify both an Article 6 lawful basis and an additional special-category condition before doing so.

4. Debt recovery and third-party sharing

If your account is overdue, we may share necessary personal information with debt collection agencies, tracing agents, payment recovery providers, solicitors, courts, enforcement agents, insurers and professional advisers. Information shared may include your name, contact details, membership details, invoice and payment history, amount outstanding, correspondence, dispute notes and evidence needed to verify or recover the debt.

The purpose is to recover sums due, resolve disputes, prevent fraud, establish or defend legal claims, and comply with legal obligations. We will share only what is reasonably necessary for the recovery or legal purpose. If a debt is assigned, transferred or sold where lawful, the new debt owner or recovery provider may contact you directly and process your data for that purpose.

5. Payment providers

Stripe and banking providers process payments, Direct Debit mandates, invoices, refunds, disputes and fraud checks. Their own privacy information may also apply when you use their checkout or payment services. Our application is not designed to store full card numbers or full bank-account credentials.

6. Health information

Health information is special-category data. Do not provide it unless needed for safety, accessibility, incident handling or a specific service. We do not use health information for debt recovery unless it is directly relevant to a dispute, vulnerability support request, legal claim or safety record and it is lawful and necessary to do so.

7. Retention

We keep information only for as long as reasonably necessary for membership administration, accounting, tax, legal, insurance, complaint, safety and debt recovery purposes. Membership, payment and contract records may be kept for up to six years after the relationship ends where needed for legal claims, accounting or debt recovery. Certain records may be kept for longer if required by law or if a dispute, debt, safeguarding, accident, fraud or legal claim is ongoing.

8. Your rights

Depending on the circumstances, UK data protection law may give you rights of access, rectification, erasure, restriction, data portability and objection, as well as rights relating to consent and certain automated decisions. These rights are not absolute. For example, we may need to keep certain information to comply with law, manage a contract, defend legal claims, investigate disputes or recover unpaid sums.

9. Marketing, cookies and security

We do not treat creation of a membership account as permission for unrelated electronic marketing. Where marketing consent is required, it is requested separately. See our Cookie Policy for cookie information. We use technical and organisational measures designed to protect personal data, including authenticated areas, access controls and provider checks. No system can be guaranteed completely secure.

10. International transfers

Some technology providers may process information outside the UK. Where UK data protection law requires transfer safeguards, we use an approved transfer mechanism or another lawful basis and assess supplementary protections where appropriate.

11. Requests and complaints

For a privacy request, email hello@ironlogicfitness.com, call 020 3584 3839, use our contact form, or write to our registered office. You also have the right to complain to the UK Information Commissioner's Office. Contacting us first does not remove that right.

12. Changes

We update this notice when our processing, providers or legal obligations materially change. The review date at the top identifies the current version.