This policy was last updated on 23rd of July, 2020.
Triyoga is committed to complying with the General Data Protection Regulation and the Data Protection Act 2018. Looking after the personal information you share with us is very important, and we want you to be confident that your personal data is kept safely and securely and to understand how we use it to offer you a better and more personalised experience.
We have published this notice to help you understand:
- how and why triyoga collect information from you
- who triyoga share your information with, why and on what basis
- what your rights are
triyoga Limited is the data controller of the information you provide. triyoga Limited is a company registered in England and Wales with registered number 03842172.
Should you have any questions about this policy please write to us at firstname.lastname@example.org
Definitions and Interpretation
In this Policy, the following terms shall have the following meanings:
Online channels: http://triyoga.co.uk, the triyoga App, the triyoga Mind Body booking portal at https://clients.mindbodyonline.com/classic/home?studioid=1991Offline channels: our triyoga studios
|“Our Site”||Refers to http://triyoga.co.uk|
|“Account”||means a triyoga or Mind Body account required to access and/or use certain areas and features of Our Locations|
|“Personal Data”||means any and all data that relates to an identifiable person who can be directly or indirectly identified from that data. In this case, it means personal data that you give to Us via any of Our Locations. This definition shall, where applicable, incorporate the definitions provided in the EU Regulation 2016/679 – the General Data Protection Regulation (“GDPR”);|
|“We, Us ,Our”||means triyoga (UK) Limited, registered in England under company number 03842172, whose registered address is Unit 4, 122a Gloucester Avenue, London, England, NW1 8HX.|
When do we collect your personal data?
- When you create an account at any of Our Locations
- When you purchase a product at any of Our Locations or apply for concession pricing which requires proof of age, job seekers, student or disabled status.
- When you book a service at any of Our Locations or ask to be added to a waiting list for a service
- When you visit our centres to attend a class
- When you redeem a gift card at any of Our Locations
- When you engage with us on social media
- When you download or install one of our apps
- When you contact us by any means with queries, complaints, send us your CV for a job application or complete an application form for one of our workshops or teacher trainings
- When you enter prize draws or competitions
- When you choose to complete any feedback requests or surveys we send you
- When you’ve given a third party permission to share with us the information they hold about you
- When you use our studios which may have CCTV systems operated for the security of both customers and Partners. These systems may record your image during your visit
What data do we collect and how do we use it?
Depending upon your use of Our Locations, We may collect some or all of the following personal and non-personal data
Data Protection says that we are allowed to collect and use your personal data only where we have a proper reason to do so. The law says we must have one or more of these reasons:
- Contract – your personal information is processed in order to fulfil a contractual arrangement e.g. to place an order or book a class.
- Consent – where you agree to us using your information in this way e.g. for storing your payment card details.
- Legitimate Interests – this means the interests of triyoga in managing our business to allow us to provide you with the best products and service in the most secure and appropriate way
- Legal Obligation – where there is statutory or other legal requirement to share the information e.g. when we have to share your information for law enforcement purposes.
|What we store||Our Reasons (Legal Basis)||What we use the data for|
|Name, date of birth, email, telephone number, For your security, we’ll also keep an encrypted record of your login password.||Fulfilling a contract||We need this information as a minimum in order to process your orders and bookings|
|Email, address and telephone number||Consent (email only)||Supplying you with email Marketing communications that you have opted into to keep you informed of special offers, promotions and new events.|
|Legitimate Interests||1) Reminders and Schedule Changes: Notifying you of changes to classes that you’ve already booked such as cancellations, teacher substitutes, style changes or waitlist changes.
2) Enhancements to our services: Such as changes to pricing and schedules or new services
3) Satisfaction surveys: In order to improve our service to you we’ll send you a short satisfaction survey after the sooner of your third visit or 30 days after your first visit. We’ll also send you a short satisfaction survey if you cancel a membership with us. These emails are sent by a third party called Listen360 and you can opt-out of these emails at any time by clicking the unsubscribe link at the bottom of any email from Listen360.
We may also contact you to discuss feedback or complaints.
|Fulfilling a contract||Sending you payment invoices by email|
|Date of Birth||Legitimate interest||For health and safety reasons under 14s cannot practice yoga, (unless in a child specific class), Between the ages of 14 and 16 you can practice if accompanied by an adult|
How you heard about triyoga
|Legitimate interest||Personalising and tailoring your experience with triyoga. Developing products and services, that attract and retain customers. Improving customer interaction with our sites.|
|Preferred triyoga location||Legitimate interest||To personalise your experience when using our online Locations|
|Your photo||Legitimate interest||This helps us ensure that your pre-paid class passes are not being used fraudulently by someone else|
|Payment card number, expiry date and billing address||Consent (we will only store these details if you ask us to)|
|If you purchase one of our services or make a booking: your purchased / booked services, receipts||Fulfilling a contract||We also use information about services bought and volumes, to help us with planning, demand forecasting, management information and research|
|Time and date of your check-ins for any bookings||Legitimate interests||To help us with planning and handling our customer contact efficiently and effectively|
|Details of your interactions with us through Our Locations. For example, we collect notes from our conversations with you, details of any complaints or comments you make, and how and when you contact us.||Legitimate interests||Keeping our records up to date, handling our customer contact efficiently and effectively|
|Health information and emergency contact (we only request this when you take part in a equipment pilates class)||Legitimate interests||To enable us to assess your suitability for the services and safeguard your health|
|Details of your visits to our websites or apps, including IP address, web browser and version, operating system, and which website referred you to ours.||Legitimate interests||Improving customer experience and interaction with our sites.|
Third party services and how we share your data
We contract with third parties to supply products and services to you on Our behalf. In some cases, the third parties may require access to some or all of your data. Where any of your data is required for such a purpose, We will take all reasonable steps to ensure that your data will be handled safely, securely, and in accordance with your rights, Our obligations, and the obligations of the third party under the law. In certain circumstances, We may be legally required to share certain data held by Us, which may include your personal data, for example, where We are involved in legal proceedings, where We are complying with legal requirements, a court order, or a governmental authority.
We use the following third party data processors who are based outside the EU, but who are protected by the Privacy Shield, which allows them to store EU data on US soil with the GDPR.
MINDBODY Online, California USA – we use MindBody online for web scheduling, registration, order processing and online payments
Loyal Snap, New York City USA – with your consent you may be contacted with reminders about your account and special offers
Listen360, Georgia USA – following your first visit to triyoga you may be contacted via email to provide feedback on your experience. You can opt-out of these emails at any time by clicking the unsubscribe link at the bottom of every email
Google, California USA – We may compile statistics about the use of Our Locations using Google Analytics including data on traffic, usage patterns, user numbers, sales, and other information. All such data will be anonymised and will not include any personally identifying data, or any anonymised data that can be combined with other data and used to identify you. We may from time to time share such data with third parties such as prospective investors, affiliates, partners, and advertisers. Data will only be shared and used within the bounds of the law
MailChimp – We use MailChimp to send communications and store your sign-up/opt-in data for all promotional emails. Your data is stored safely and securely and will not be shared with any third party directly from MailChimp. You can opt-out of these emails at any time by clicking the unsubscribe link at the bottom of every email
Where do we store your data?
Your data will be stored in the UK and all MINDBODY Online data for its triyoga platform, and data with third party service providers, Loyal Snap, MailChimp and Listen360 are stored in the US, protected by the Privacy Shield that allows MINDBODY Online, Loyal Snap, MailChimp and Listen360 to store EU data on US soil with the GDPR.
How long we keep your information
If we collect your personal information, the length of time we retain it is determined by a number of factors including the purpose for which we use that information and our obligations under other laws.
We may need your personal information to establish, bring or defend legal claims. For this purpose, we will always retain your personal information for 7 years after the date it is no longer needed by us for any of the purposes listed under ‘What data do we collect and how do we use it’.
- the law requires us to hold your personal information for a longer period, or delete it sooner;
- you exercise your right to have the information erased (where it applies) and we do not need to hold it in connection with any of the reasons permitted or required under the law;
- we bring or defend a legal claim or other proceedings during the period we retain your personal information, in which case we will retain your personal information until those proceedings have concluded and no further appeals are possible; or
- in limited cases, existing or future law or a court or regulator requires us to keep your personal information for a longer or shorter period.
In-centre live streamed classes and workshops
You have the following rights under the GDPR, which this Policy and Our use of personal data have been designed to uphold:
right to access – You have the right to request information about the personal data we hold on you at any time.
right to portability – Whenever We process your personal data, by automated means based on your consent or based on an agreement, you have the right to get a copy of your data transferred to you or to another party. This only includes the personal data you have submitted to us.
right to rectification – You have the right to request rectification of your personal data if the information is incorrect, including the right to have incomplete personal data completed. If you have triyoga or Mind Body account you can edit your personal data under your account and membership pages.
right to erasure – You have the right to erase any personal data processed by Us at any time except for the following situations:
- you have an ongoing matter with Customer Service
- you have an unsettled debt with Us, regardless of the payment method
- if you are suspected or have misused our services within the last four years
- your debt has been sold to a third party within the last three years or one year for deceased customers
- if you have made any purchase, we will keep your personal data in connection to your transaction for book-keeping purposes
- we bring or defend a legal claim or other proceedings during the period we retain your personal information, in which case we will retain your personal information until those proceedings have concluded and no further appeals are possible
- in limited cases, existing or future law or a court or regulator requires us to keep your personal information for a longer or shorter period.
Your right to object to processing based on legitimate interest
You have the right to object to processing of your personal data that is based on Our legitimate interest. We will not continue to process the personal data unless we can demonstrate legitimate grounds for the process which overrides your interest and rights or due to legal claims.
If you have any cause for complaint about Our use of your personal data, please contact Us at email@example.com in the first instance in order that we can investigate thoroughly. Should you find the response unsatisfactory, you also have the right to lodge a complaint with the UK’s supervisory authority, the Information Commissioner’s Office, by calling 0303 123 1113.
For further information about your rights, please contact the Information Commissioner’s Office or your local Citizens Advice Bureau.
By continuing to browse our site, you consent to our placing cookies on your computer (unless you have chosen to disable them via your browser). Certain features of Our Site depend on Cookies to function. Cookie Law deems these Cookies to be “strictly necessary”. Your consent will not be sought to place these Cookies. You may still block these Cookies by changing your internet browser’s settings but please be aware that Our Site may not work properly if you do so.
The following first party Cookies may be placed on your computer or device:
|Name of Cookie||Purpose||Strictly Necessary|
|ARRAffinity||This cookie makes triyoga.co.uk pages load more quickly. In technical terms it’s used to distribute traffic to the website on several servers in order to optimise response times.||yes|
|csrftoken||This cookie helps protect Us against a CSRF attack. A CSRF vulnerability allows a malicious party to force you a logged-in user to perform an malicious actions without you consent or knowledge.||yes|
|_ga, _gat, _gid||These cookies enable the function of Google Analytics. This software helps us collect and analyse visitor information such as browser usage, new visitor numbers, response to marketing activity and shopping times. That information helps us to improve the website and your shopping experience, and to make our marketing campaigns relevant.
The data stored by these cookies can be seen only by the relevant teams at triyoga and Google and never shows any confidential information.
|wfvt_#||This cookie remembers your submitted data when you comment on a blog post. The purpose is to auto-populate form fields for subsequent comments, in order to save you time.||no|
Third party Cookies may be placed on your computer or device by the following companies however these are not within our control:
- Doubleclick is used for placing adverts and marketing on third party websites
- Youtube is used to provide video social media and content
You can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. If you’d like to learn more about cookies in general and how to manage them please visit aboutcookies.org.
Our Policy on “Do Not Track” Signals under the California Online Protection Act (CalOPPA)
We do not support Do Not Track (“DNT”). Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked. You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.
Our Policy on The Brazillian LGPD (Lei Geral de Proteção de Dados)
The Brazillian LGPD (Lei Geral de Proteção de Dados) is a new data privacy law that will apply to businesses (both inside and outside Brazil) that process the personal data of users located in Brazil. The new law is expected to go into effect on 16th August 2020, but ongoing discussions in the Brazilian government may result in a change to the effective date. The LGPD terms will be incorporated into our existing data protection terms, so no action is required to accept the LGPD terms where the existing data protection terms already form part of your account.
Our Service does not address anyone under the age of 18 (“Children”).
We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your Child has provided us with Personal Data, please contact us via firstname.lastname@example.org. If we become aware that we have collected Personal Data from children without verification of parental consent, we will take steps to remove that information from all our servers. For all our Children’s online and in-centre classes we require parental booking. Our Children’s classes will not be live streamed or recorded.
Information about triyoga
Our Locations are owned and operated by triyoga, a limited company registered in England under company number 03842172, whose registered address is Unit 4, 122a Gloucester Avenue, London, England, NW1 8HX.