Last updated 23 May 2018
1. WHO ARE WE
This website ("Site") is operated by NuBeginnings Wellness Limited, a company registered in England and Wales under registration number 09884636 ("NuBeginnings", "we", "us" and/or "our"). Our registered address is 9 Glebe Street, London W42BD. You can contact us as indicated under the "Contact" section below. The data controller responsible for your personal data is The NuBeginnings company with whom you contract as a customer, member or membership applicant ("NuBeginnings", "we", "us" and/or "our").
3. PERSONAL DATA WE COLLECT
We collect the following personal data about you:
- Application: The personal details you provide when submitting a membership application. This includes your name, address, e-mail address; phone number; gender and date of birth; country; health information about yourself; information about your lifestyle and other information that you elect to provide to support your application. We also collect information about your debit/credit card and bank account information provided by you to our payment service providers, that we require for the purpose of processing your membership application (and administering your membership). For further details please also refer to the section below headed "Payment Information".
- Other Information: Personal details you choose to give when corresponding with us by phoneor e-mail, participating in user/customer/member surveys or otherwise visiting and interacting with this Site or any other websites we operate, and personal data that you provide to us when you visit one of our consultants or premises. We can also combine personal data that youprovide to us with other information we collect about you only with your permission from third party consultants such as personal trainers, nutritionists or doctors.
4. AUTOMATICALLY COLLECTED PERSONAL DATA
- Data: When you visit our Site, our servers record information ("log data"), including information that your browser automatically sends whenever you visit the Site. This log data includes your Internet Protocol ("IP") address (from which we understand the country you are connecting from at the time you visit the Site), browser type and settings, the date and time of your request.
5. HOW WE USE YOUR PERSONAL DATA
We use your personal data in the following ways:
- To acknowledge, confirm and deal with your application for services (and where necessary put you on our waiting list). Such use of your data is necessary in order to implement your request.
- Where you are a client, provide you with the requested services, administer your account and contact you regarding your use of the services. Such use is necessary to respond to or implement your request and for the performance of the contract between you and us.
- To complete and fulfill your programme, for example, to send your test packages, interpret your results and then contact you with the results and recommendations. Such use is necessary for the performance of the contract between you and us.
- To contact you in connection with user/customer/member surveys and use any information you
choose to submit in response, provided that you gave us your consent to being contacted in this
way at the time you provided us with the personal data.
- Your information will be used as necessary for certain legitimate business interests, which
include the following:
- where we are asked to deal with any enquiries or complaints you make.
- to administer our Site, to better understand how visitors interact with our websites and ensure that our Site is presented in the most effective manner for you and for your computer/device.
- to conduct analytics to inform our marketing strategy and enable us to enhance and personalise the experience we offer to our members and our communications, including by creating customer or member profiles to enable personalised direct marketing communications.
- to provide postal communications which we think will be of interest to you.
- if you ask us to delete your data or to be removed from our marketing lists and we are required to fulfil your request, to keep basic data to identify you and prevent further unwanted processing.
- we may anonymise, aggregate and de-identify the data that we collect and use such anonymised, aggregated and de-identified data for our own internal business purposes, including statistical and market research purposes, for example to analyse patterns among groups of people, and conducting research on demographics, interests and behavior.
- for internal business/technical operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes and as part of our efforts to keep our Site, network and information systems secure.
- to (a) comply with legal obligations, (b) respond to requests from competent authorities; (c) enforce our NuBeginnings Rules; (d) protect our operations; (e) protect our rights, safety or property, and/or that of our affiliated businesses, you or others; and (f) enforcing or defending legal rights, or preventing damage.
6. DISCLOSURE OF YOUR INFORMATION
We will never share your personal data with third parties unless required to do so by law.
7. PAYMENT INFORMATION
Any credit/debit card payments and other payments you make through our Site will be processed by our third-party payment providers and the payment data you submit will be securely stored and encrypted by our payment service providers using up to date industry standards. Please note that we do not ourselves directly process or store the debit/credit card data that you submit.
We may arrange that card or payment data you submit in support of an application or subscription fee is stored for the purpose of processing your application, initiating your program plan and collecting your subscription fees if your initial application is successful.
You may choose to opt out of us holding your card or payment data.
8. PERSONAL DATA TRANSFERS
Your personal data will be transferred to and stored in countries other than the country in which the information was originally collected, including the United States and other destinations outside the European Economic Area ("EEA"), to our service providers and affiliated businesses for the purposes described above.
Please note that the countries concerned may not provide the same legal standards for protection of your personal data that you have in the United Kingdom or EEA. Where we transfer your personal data to countries outside of the EEA we will take all steps to ensure that your personal data will continue to be protected. We will implement appropriate safeguards for the transfer of personal data to our service providers in accordance with the applicable law, such as relying on our service providers’ Privacy Shield certification or implementing standard contractual clauses for data transfers. We have implemented data transfer agreements pursuant to applicable data protection law in order to implement appropriate safeguards for the transfer of personal data to any companies in countries outside the EEA. If you would like to receive more information on the safeguards that we implement, including copies of relevant data transfer contracts, please contact us as indicated below.
Where we have given you (or where you have chosen) a password or log-in which enables you to access certain restricted parts of our Site, you are responsible for doing everything you reasonably can to keep these details secret. You must not share your password or log-in details with anyone else.
Unfortunately, the transmission of information over the internet or public communications networks can never be completely secure. We will take appropriate technical and organisational security measures to protect the personal data that you submit to us against unauthorised/unlawful access or loss, destruction or damage, although we cannot 100% guarantee the security of personal data that you provide to us online.
10. YOUR DATA PROTECTION RIGHTS
To determine the appropriate retention period for your personal data, we consider the amount, nature, and sensitivity of the personal data, the purposes for which we process your personal data, applicable legal requirements or operational retention needs, and whether we can achieve those purposes through other means.
Upon expiry of the applicable retention period we will securely destroy your personal data in accordance with applicable laws and regulations. In some circumstances we may anonymise your personal data so that it can no longer be associated with you, in which case it is no longer personal data.
11. YOUR PERSONAL DATA PROTECTION RIGHTS
Certain applicable data protection laws give you specific rights in relation to your personal data. In particular, if the processing of your personal data is subject to the GDPR, you have the following rights in relation to your personal data:
- Right of access: If you ask us, we will confirm whether we are processing your personal data and, if so, provide you with a copy of that personal data along with certain other details such as the purpose of the data processing. If you require additional copies, we may need to charge a reasonable fee.
- Right to rectification: If your personal data is inaccurate or incomplete, you are entitled to ask that we correct or complete it. If we shared your personal data with others, we will tell them about the correction where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your personal data so you can contact them directly.
- Right to restrict processing: You may ask us to restrict or ‘block’ the processing of your personal data in certain circumstances, such as where you contest the accuracy of the personal data or object to us processing it. We will tell you before we lift any restriction on processing. If we shared your personal data with others, we will tell them about the restriction where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your personal data so you can contact them directly.
- Right to data portability: You have the right to obtain your personal data from us that you consented to give us or that was provided to us as necessary in connection with our contract with you. We will provide you with your personal data in a structured, commonly used and machinereadable format. You may reuse it elsewhere.
- Right to object: You may ask us at any time to stop processing your personal data, and we will do so: o If we are relying on a legitimate interest to process your personal data -- unless we demonstrate compelling legitimate grounds for the processing or o If we are processing your personal data for direct marketing.
- Right to withdraw consent: If we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing of your data before we received notice that you wished to withdraw your consent.
- Right to lodge a complaint with the data protection authority: If you have a concern about our privacy practices, including the way we handled your personal data, you can report it to the UK data protection authority (the Information Commissioner’s Office or ICO), or, as the case may be, any other competent data protection authority of an EU member state that is authorised to hear those concerns (you may find EU Data Protection Authorities’ contact information here).
If you wish to exercise any of these rights please contact us as described in the "Contact" section below. We may also need to ask you for further information to verify your identity before we can respond to any request.