1. Introduction

Vitalfit UK (website: https://www.vitalfit.uk) values your trust and is committed to protecting your personal data. We are a UK-based fitness company specialised in Electro-Muscle Stimulation (EMS) training. Please read this Privacy Policy carefully. By using our services—including website forms, bookings, and Lead Ads—you consent to this policy under the UK General Data Protection Regulation and Data Protection Act 2018 .

2. Data Collected

Data Storage Location

We operate on UK-based servers, and our hosting provider ensures GDPR-compliant processing.

Registration & Booking Data

When registering or booking, we collect:

  • Name, email, phone number, and any profile info you provide.

  • This is used to manage bookings, send reminders, and process your EMS session.

Contact Form & Lead Ads Data

Information submitted via website forms or Lead Ads is stored securely and used solely for:

  • Booking management

  • Lead follow-up

  • Optional marketing offers

We do not sell or share personal data except as needed for service delivery (e.g. scheduling systems, WhatsApp)

Cookies & Analytics

We use essential cookies for session functionality and Google Analytics for anonymous usage reports. No personal data is stored in analytics. You can disable cookies via your browser settings .

3. How We Use Your Data

We process your personal data to:

  • Confirm and manage EMS bookings

  • Provide coaching and customer support

  • Send appointment reminders, updates and occasional offers (only if opted-in)

  • Improve our services and user experience

Legal bases: consent, performance of contract (bookings), legitimate interests (service improvement)

4. Who Has Access to Your Data

Your information is accessed only by:

  • Vitalfit UK staff for bookings and support

  • Service providers (e.g., booking platforms, WhatsApp) under GDPR-compliant agreements
    We do not share your personal data beyond these uses unless required by law

5. Data Retention

We only keep your data as long as necessary:

  • Booking and form data: up to 2 years

  • Marketing data: retained until you unsubscribe

  • Analytics: anonymised after 26 months

Paper forms and notes are securely destroyed when no longer needed.

6. Security Measures

We use SSL encryption for data transmission and restrict access to those who need it. In case of a breach, we follow UK GDPR protocols and notify affected individuals within 72 hours

7. Your Rights

Under UK GDPR you have the right to:

  • Access, correct or delete your personal data

  • Object to processing or request restriction

  • Data portability

  • Withdraw consent

  • Lodge a complaint with the ICO (Information Commissioner’s Office)

Contact us via email at privacy@vitalfit.uk, and we’ll respond promptly

8. Security Measures
We use the SSL/HTTPS protocol throughout our site. This encrypts our user communications with the servers so that personally identifiable information is not captured/hijacked by third parties without authorization. In case of a data breach, system administrators will immediately take all needed steps to ensure system integrity, will contact affected users and will attempt to reset passwords if needed.
9. Your Data Rights
General Rights

If you have a registered account on this website or have left comments, you can request an exported file of the personal data we retain, including any additional data you have provided to us.

You can also request that we erase any of the personal data we have stored. This does not include any data we are obliged to keep for administrative, legal, or security purposes. In short, we cannot erase data that is vital to you being an active customer (i.e. basic account information like an email address).
If you wish that all of your data is erased, we will no longer be able to offer any support or other product-related services to you.

GDPR Rights

Your privacy is critically important to us. Going forward with the GDPR we aim to support the GDPR standard. ThemeRex permits residents of the European Union to use its Service. Therefore, it is the intent of ThemeRex to comply with the European General Data Protection Regulation. For more details please see here: EU GDPR Information Portal.

10. Third Party Websites

ThemeREX may post links to third party websites on this website. These third party websites are not screened for privacy or security compliance by ThemeRex, and you release us from any liability for the conduct of these third party websites.
All social media sharing links, either displayed as text links or social media icons do not connect you to any of the associated third parties unless you explicitly click on them.

Please be aware that this Privacy Policy, and any other policies in place, in addition to any amendments, does not create rights enforceable by third parties or require disclosure of any personal information relating to members of the Service or Site. ThemeRex bears no responsibility for the information collected or used by any advertiser or third party website. Please review the privacy policy and terms of service for each site you visit through third party links.

11. Release of Your Data for Legal Purposes

At times it may become necessary or desirable to ThemeRex, for legal purposes, to release your information in response to a request from a government agency or a private litigant. You agree that we may disclose your information to a third party where we believe, in good faith, that it is desirable to do so for the purposes of a civil action, criminal investigation, or other legal matter. In the event that we receive a subpoena affecting your privacy, we may elect to notify you to give you an opportunity to file a motion to quash the subpoena, or we may attempt to quash it ourselves, but we are not obligated to do either. We may also proactively report you, and release your information to, third parties where we believe that it is prudent to do so for legal reasons, such as our belief that you have engaged in fraudulent activities. You release us from any damages that may arise from or relate to the release of your information to a request from law enforcement agencies or private litigants.

Any passing on of personal data for legal purposes will only be done in compliance with laws of the country you reside in.