Last updated: 20 March 2026
Welcome to Lotus Pilates. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, and safeguard your data when you use our services at lotuspilates.co.uk.
Data Controller: Lotus Pilates is the data controller responsible for your personal information. For any questions about this policy or your data, please contact us at info@lotuspilates.co.uk.
We collect the following categories of personal data:
We collect health-related information through our Physical Activity Readiness Questionnaire (PAR-Q). This includes:
This is classified as "special category data" under UK GDPR and is collected with your explicit consent via digital signature before you can book your first class.
Under UK GDPR, we process your personal data based on the following lawful bases:
We process your identity, contact, and transaction data (name, email, booking history) for the performance of a contract to provide you with Pilates class bookings and related services. This includes managing your account, processing bookings, and communicating about your classes.
Health data (PAR-Q information) is processed strictly under your explicit consent. Before booking your first class, you must complete and digitally sign the PAR-Q health questionnaire. By providing your digital signature, you are giving explicit consent for us to process your health information for the purpose of ensuring your safety during physical activities and tailoring instruction to your needs.
You have the right to withdraw this consent at any time by contacting us. However, please note that we may need to retain certain health information for safety and legal reasons while you remain an active member.
We use trusted third-party service providers to securely process and store your data. These processors are bound by strict data protection agreements and only process your data as instructed by us:
We do not sell, rent, or share your personal data with any other third parties for marketing purposes.
We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy:
You can request deletion of your account and associated data at any time by contacting us at info@lotuspilates.co.uk. We will process your request in accordance with UK GDPR requirements, though some data may need to be retained for legal or safety reasons.
As a data subject under UK GDPR, you have the following rights:
To exercise any of these rights, please contact us at info@lotuspilates.co.uk. We will respond to your request within one month.
If you are not satisfied with how we handle your data protection rights, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection supervisory authority.
We take the security of your personal information seriously. We use industry-standard security measures, including encryption and secure data storage, to protect your data from unauthorized access, disclosure, alteration, or destruction. Your health information is stored securely and is only accessible to authorized personnel who need it to ensure your safety during classes.
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at info@lotuspilates.co.uk.