Legal / 12 August 2026
Privacy Notice
PROTEQTPLUS LTD is the controller for personal data described in this notice. This notice explains what we collect, why we use it, who receives it, how long we keep it and your rights.
1. Controller
PROTEQTPLUS LTD, company number 16226856, registered office 128 City Road, London, United Kingdom, EC1V 2NX, is the data controller for the member, prospect and website information described below. Our customer contact email is hello@ironlogicfitness.com and our telephone number is 020 3584 3839.
2. Information we collect
- Account information such as email address, authentication identifiers and account status.
- Membership information such as plan, membership status, billing period, cancellation status and service history.
- Payment metadata supplied by a payment processor where online payment is used, such as customer, subscription or invoice identifiers, payment status, amount and currency. Our application is not designed to store full payment-card numbers.
- Service, complaint and support information you provide when contacting us.
- Technical and security information reasonably needed to operate, secure and troubleshoot the website.
- Cookie or local-storage choices described in our Cookie Policy.
- Health or medical information only where a specific service or safety process reasonably requires it and an appropriate lawful basis and special-category condition apply.
3. Why we use personal data and lawful bases
- Contract: to create and administer accounts, provide memberships, handle plan changes and cancellations, and support agreed payment arrangements.
- Legal obligation: where records or disclosures are required by tax, accounting, consumer, corporate or data-protection law.
- Legitimate interests: to secure systems, prevent fraud and abuse, maintain reliability, handle routine enquiries and improve operations where those interests are not overridden by your rights.
- Consent: where consent is the appropriate basis, including optional direct marketing or non-essential cookies. Consent can be withdrawn without affecting earlier lawful processing.
If we process special-category health data, we will identify both an Article 6 lawful basis and an additional special-category condition before doing so.
4. Who receives data
We use service providers where needed to run the service. Core application providers include Supabase for database and authentication infrastructure and Lovable-hosted infrastructure for application deployment and development. Where online card payment is enabled, a specialist payment provider such as Stripe may process payment and billing information. Providers act under their applicable legal roles and contractual arrangements. We may also disclose information where required by law, to protect legal rights, or in connection with a legitimate corporate transaction subject to appropriate safeguards.
5. International transfers
Some technology providers may process information outside the UK. Where UK data-protection law requires transfer safeguards, we use an approved transfer mechanism or another lawful basis and assess supplementary protections where appropriate.
6. Retention
We keep personal data only for as long as reasonably necessary for the purpose collected, including membership administration, resolving disputes, security, tax and accounting records, and legal claims. Retention depends on the record type rather than one blanket period, subject to legal or evidential requirements.
7. Your rights
Depending on the circumstances, UK data-protection law may give you rights of access, rectification, erasure, restriction, data portability and objection, as well as rights relating to consent and certain automated decisions. Some rights have legal conditions or exemptions, and we may need to verify identity before acting on a request.
8. Marketing
We do not treat creation of a membership account as permission for unrelated electronic marketing. Where marketing consent is required, it is requested separately. Electronic marketing messages will include an appropriate way to opt out, and valid objections to direct marketing will be respected.
9. Security
We use technical and organisational measures designed to protect personal data, including authenticated areas and access controls. Where online card payment is enabled, card processing is handled through a specialist payment provider rather than by storing full card numbers in our application. No online system can be guaranteed absolutely secure; personal-data breaches are assessed and handled under applicable notification duties.
10. Children
The standard online membership flow is intended for adults. If a junior service is introduced, it will use age-appropriate information and any parent or guardian process required for that service.
11. Requests and complaints
For a privacy request, email hello@ironlogicfitness.com, call 020 3584 3839, use our contact form, or write to our registered office. You also have the right to complain to the UK Information Commissioner's Office. Contacting us first does not remove that right.
12. Changes
We update this notice when our processing, providers or legal obligations materially change. The review date at the top identifies the current version.