Home
    About
    Personal Training
    Pricing
    Client Stories
    FAQs
    Contact

    Legal

    Privacy Policy

    This policy explains what personal information Eternal Fitness collects, why, how it's used, who it's shared with, and the rights you have over it under UK GDPR and the Data Protection Act 2018.

    Last updated
    7 August 2026
    Data controller
    Esther Fair, trading as Eternal Fitness
    Based in
    Worthing, West Sussex
    01

    Who we are

    Eternal Fitness is a private, one-to-one personal training business operated by Esther Fair as a sole trader, based in Worthing, West Sussex. Esther is the data controller responsible for your personal information — the person who decides why and how it is used. The exact studio address is shared only with clients at the point of booking, to keep a private, single-occupant training space secure; general correspondence should go to the email address above.

    We don't have a formal Data Protection Officer — the law doesn't require one at this scale — but Esther is personally responsible for how your data is handled and is who to contact with any question or concern.

    02

    What information do we collect?

    Information you give us directly

    • Enquiries and messages. When you use the contact form, your name, email address, phone number (if given), and the content of your message.
    • Booking a free consultation. The "Book a Free Consultation" button on this site takes you to our Microsoft Bookings calendar, hosted by Microsoft, to choose a time. Booking there means you're giving your name, email, phone number, and any notes directly to that booking system — see who we share your information with below for how that works.
    • Becoming a client. If you go ahead with training, we collect the details needed to deliver the service safely and keep proper records: your name, contact details, emergency contact, health/PAR-Q information (see below), signed agreements and consent forms, session notes, and training programme data.
    • Client portal. If you're given access to the client portal, we hold your login details, session history, exercise logs, and any documents shared through it.

    Information collected automatically

    The public website itself doesn't run any analytics or advertising trackers, so beyond standard web server/hosting logs (kept briefly for security and abuse prevention, not used to build a profile of you) we don't automatically collect browsing data about visitors to the public pages. The staff hub and client portal — both password-protected — use essential session cookies to keep you logged in; see our Cookie Policy for the full, accurate list.

    What we don't collect

    We don't take payment directly through this website, so we don't collect or store card numbers or other payment instrument details ourselves. Payment for training is arranged directly with Esther.

    03

    Health information (special category data)

    Before your first session, we ask you to complete a PAR-Q (Physical Activity Readiness Questionnaire) covering things like diagnosed medical conditions, medications, implanted medical devices, and recent surgeries or hospital admissions. Under UK GDPR this counts as "special category data" — information about your health — which the law treats with extra care.

    We only collect this because it's genuinely necessary: without knowing about a condition, medication, or recent surgery, a session could be programmed unsafely. We ask for your explicit consent to hold and use this information for that purpose when you complete the form, and it is only ever used to plan and adapt your training safely — never for marketing, never sold, and never shared beyond what's described in this policy.

    If your PAR-Q answers indicate that medical clearance is needed before training can begin, we'll ask you to get a signed letter from your GP or relevant consultant, and no session will go ahead until that's received.

    04

    Our lawful basis for using your information

    UK GDPR requires us to have a valid legal reason ("lawful basis") for every use of your personal information. Depending on the situation, we rely on:

    • Contract. Where we need your information to provide the training service you've booked — e.g. contact details, scheduling, session records.
    • Consent. Especially for health/PAR-Q information (see above), and for anything else where we ask you directly and you can withdraw that consent at any time without it affecting other services.
    • Legitimate interests. For things like responding to a general enquiry, keeping basic records for insurance purposes, and the day-to-day administration of running the business — always balanced against your right to privacy.
    • Legal obligation. Where we're required to keep or disclose information — for example, financial records for HMRC.
    05

    How do we use your information?

    • Delivering training safely. Programming, adapting, and running your sessions around your goals and health information.
    • Communicating with you. Replying to enquiries, session scheduling, and — for clients — progress updates and reminders.
    • AI-assisted drafting. Some client progress-update emails and training plans are drafted with the help of an AI writing assistant, using relevant session/programme context, before Esther reviews and sends them herself. See who we share your information with for the processor involved.
    • Record-keeping and insurance. Signed agreements, consent forms, and health records are kept as evidence of what was agreed and disclosed, which also protects you.
    • Testimonials. We only ever use your name or words as a testimonial with your specific, separate consent — never PAR-Q or health information.
    • Running the business. Invoicing, basic bookkeeping, and administration.

    We don't use your information for automated decision-making or profiling that produces legal or similarly significant effects on you.

    06

    Who do we share your information with?

    We don't sell your information, and we don't share it for third-party marketing. We do use a small number of trusted service providers ("processors") to run the business — each only processes data on our instructions, for the purpose stated:

    WhoWhat forWhat they see
    Microsoft (Bookings)Scheduling free consultationsName, email, phone, and any notes you enter when booking — collected directly by Microsoft once you leave our site; their own privacy notice applies to that data
    Our email providerSending booking confirmations, enquiry replies, and client update emailsYour email address and the content of the email being sent
    Our hosting providerRunning the website and securely storing client records in our databaseWhatever is stored in your client record, hosted on infrastructure we control
    AI writing assistant (via OpenRouter)Helping draft client progress-update emails and training plans, which Esther always reviews before sendingRelevant session/programme context for the client the draft is being written for — never your PAR-Q answers
    TrainerizeHistoric client records from before we moved to our current systemTraining history for clients who were with us before the migration; no longer actively used for new data

    We may also disclose information where we're legally required to — for example, in response to a court order — or to protect someone's vital interests in a genuine emergency.

    07

    International transfers

    Some of the service providers above may process data outside the UK (for example, the AI assistant provider). Where that happens, we rely on the safeguards built into those providers' own terms (such as the UK's International Data Transfer Agreement or the EU Standard Contractual Clauses, as applicable) to keep your information protected to UK standards wherever it's processed.

    08

    Do we use cookies and other tracking technologies?

    The public website doesn't use any advertising or analytics cookies. The staff hub and client portal use a small number of essential cookies to keep you securely signed in. The full, accurate list is in our Cookie Policy.

    09

    How long do we keep your information?

    We only keep information for as long as we actually need it:

    • General enquiries that don't become bookings. Deleted or anonymised after around 12 months of inactivity.
    • Client records — contracts, invoices, financial records. Kept for at least 6 years after the end of the relationship, to meet HMRC record-keeping requirements.
    • PAR-Q, health information, and signed consent/agreement forms. Kept for the duration of our training relationship and for a further period afterwards — in line with standard professional-indemnity insurance guidance for the fitness industry — in case a question about what was disclosed or agreed ever needs to be answered.
    • Client portal data (session logs, exercise history). Kept while you remain an active client, and for a reasonable period afterwards in case you return to training with us.

    When there's no longer a good reason to keep it, we delete or anonymise it, except where we're required by law to keep it longer.

    10

    How do we keep your information safe?

    We use appropriate technical and organisational measures to protect your information — including encrypted connections (HTTPS) across the site, access to client records and the staff hub restricted to authenticated logins, and health information handled with particular care given its sensitivity. No system connected to the internet can be guaranteed 100% secure, but we take reasonable, proportionate steps for a business of our size to protect what we hold.

    11

    Children's information

    Eternal Fitness's services are provided to adults. We don't knowingly collect personal information from children. If you believe a child's information has been provided to us, please contact us at esther.fair@eternal-fitness.co.uk and we'll remove it.

    12

    What are your privacy rights?

    Under UK GDPR, you have the right to:

    • Access a copy of the personal information we hold about you.
    • Rectification — ask us to correct anything inaccurate or incomplete.
    • Erasure — ask us to delete your information, where there's no legal reason for us to keep it.
    • Restriction — ask us to limit how we use your information in certain circumstances.
    • Portability — receive certain information in a portable format, or ask us to transfer it to another provider.
    • Object — object to processing based on legitimate interests.
    • Withdraw consent at any time, where we're relying on consent — this won't affect anything already done before you withdrew it.

    To exercise any of these, just get in touch — we'll respond within one month. There's no charge for a reasonable request.

    If you're not happy with our response

    You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk or on 0303 123 1113. We'd always appreciate the chance to put things right directly first, but that right stands either way.

    13

    Do we make updates to this policy?

    We'll update this policy if the way we handle your information changes, or to stay in line with the law. The "Last updated" date at the top shows when it was last revised. If we make a significant change, we'll make that clear on this page rather than relying on you checking back.

    14

    How can you contact us about this policy?

    For anything to do with your personal information — a question, a request to see or delete your data, or a concern — contact Esther Fair directly at esther.fair@eternal-fitness.co.uk.

    Want a copy of what we hold?

    Ask and I will send it. If you would rather have the conversation on the phone than in writing, that is fine too.