PRIVACY BELEID VOOR KLANTEN EN WEBSITE
Laatste update 24 mei 2018
HDD Holding B.V. met e-mail adres info@hddgroup.com hierna te noemen Verwerkingsverantwoordelijke, verklaart het volgende:
Verwerkingsverantwoordelijke houdt zich aan de eisen die de Algemene Verordening Gegevensbescherming (AVG) stelt en gaat vertrouwelijk met haar klantgegevens om. Persoonlijke gegevens van klanten, sollicitanten, assessoren, instructeurs, trainers en bezoekers van onze websites en evenementen worden met de grootst mogelijke zorgvuldigheid behandeld en beveiligd.
HDD Holding vertegenwoordigt Les Mills B.V., FitCo B.V. en Studion B.V. op het gebied van privacy.
2. SUMMARY OF KEY POINTS
- Les Mills International Limited is the data controller for the personal information collected through our websites and apps (collectively, our “Digital Services”).
- We process information you provide to us, information collected automatically when you use our Digital Services, and information we receive from trusted third parties (such as payment providers, analytics and advertising partners, social media platforms, and Licensed Clubs).
- We use personal information to operate and improve our Digital Services, tailor your experience, process purchases, communicate with you, carry out analytics and optimisation, deliver relevant advertising (where permitted), comply with legal obligations and, if you are an Instructor, support and administer your role.
- We may send you marketing materials relating to our services which you can opt out of at any time.
- We share personal information with trusted service providers and business partners who help us operate our services. This includes payment processors, analytics and optimisation tools, customer support platforms, marketing and communications partners, and (where relevant) Licensed Clubs (as defined in Section 4 below). Some advertising and measurement tools we use may be considered “sharing” under the California Privacy Rights Act (“CPRA”), and you can control these settings via our cookie consent management platform.
- You have various privacy rights that you may exercise in relation to our use of your personal information. You may exercise these by contacting us through the communication methods set out in the Section 16 – Your Privacy Rights below.
In this Policy, “Instructor" means any person authorised to instruct Les Mills programs or who has entered into an instructor agreement (“Instructor Agreement”) with us, the Les Mills Companies or an authorised distributor.
3. WHO IS RESPONSIBLE FOR YOUR PERSONAL INFORMATION
OurDigital Services are controlled by Les Mills International Limited (“we”,“us”, “our”) whose registered office is at Level 2, 200Victoria Street West, Auckland 1010, New Zealand.
Some of our Digital Services, including Les Mills Connect, the Instructor and Clubportals, and associated apps, are supported on a day-to-day basis by Les Mills Companies in the territories in which they operate. While certain operational activities are carried out locally, overall control and governance of these Digital Services remain with us.
In this Policy, “Les Mills Companies” means all subsidiaries and affiliate companies from time to time owned by us, including:
- United Kingdom: Les Mills UK Fitness Limited operates the UK Les Mills Connect and Instructor and Club portals;
- United States: Les Mills United States Trading Inc. operates the US Les Mills Connect and Instructor and Club portals; and
- The Nordics: Les Mills Nordic AB operates the Nordic Les Mills Connect and Instructor and Club portals.
If you are using our Instructor or Club portals in these territories, Les Mills International Limited and the relevant Les Mills company in that territory act as joint data controllers for the aspects of the service where decisions about how your personal information is used are made jointly.
If you require a full list of entities comprising the Les Mills Companies, please contact us as described in Section 18 - Contact Us below.
4. INFORMATION WE COLLECT ABOUT YOU
We collect and process the following information about you:
Information you provide to us
This is information about you that you give us when you use our Digital Services, contact us by phone, SMS, instant messaging, email, social media or otherwise. It includes information you provide when you:
- register to use our site;
- subscribe to our service;
- search for a product;
- place an order on our site;
- participate in discussion boards or other social media functions on our site;
- enter a competition;
- report a problem with our site; and/or
- call us or we call you, which we may record with your consent.
The information you give us may include your name, address, location, date of birth, email address, phone number, financial information, such as payment card details or bank account details (for example, where you sign up for training or purchase releases), personal description and photographs, videos, images or comments.
If you are an Instructor, we will collect additional information about you in relation to your role including details of the classes and clubs you are affiliated with, purchasing history, payment information, event/training attendance, certification information and hours worked.
You must provide us with accurate information. If any of your details change, please inform us and we will update your personal information in line with our legal obligations.
Information we collect through your use of our services
When you visit or use our Digital Services, we may collect the following information:
- Technical information, including the IP address used to connect your computer or device to the Internet, your login information, browser type and version, time zone setting, anonymised location data, browser plug-in types and versions, operating system and platform;
- Usage information, including the full URL, clickstream to, through and from our site (including date and time), pages or products you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and browsing behaviour;
- Analytics information, including information about how you use and interact with our site or services, such as pages viewed, features used, time spent on pages, navigation paths, referring URLs, and aggregated usage patterns;
- Optimisation and testing information including information collected through A/B testing and similar methods to improve website functionality, performance, content, and user experience, such as variations displayed, interactions with those variations, and aggregated results;
- Location information, including approximate location data (such as city or region) may be used to provide location-based features, such as identifying nearby clubs or classes. Location information is used in real time and is not retained;
- Marketing and advertising information, including information about how you interact with our marketing and advertising, such as whether you open or click communications, view or engage with advertisements, or respond to promotional campaigns.
Information we receive from third parties
We may receive information about you from:
- Authorised partners, such as health and fitness clubs or other organisations authorised or licensed by Les Mills to deliver Les Mills programmes (“Licensed Clubs”), authorised distributors, or similar partners;
- Third party service providers that support our Digital Services, including payment processing, communications, analytics, advertising, personalisation, technical support, and single sign-on or social media integration; and
- Social media platforms, where you interact with us or connect your account (for example, Meta, Instagram or TikTok). The information we receive depends on your privacy settings with those platforms.
We combine this information with the information you provide us and the information we collect through your use of our Digital Services to operate, analyse, and improve our services.
5. HOW WE USE YOUR PERSONAL INFORMATION
We use the information we hold about you for the following purposes.
Consent
Where you have given us your consent, we process your personal information for the following purposes:
- Send you marketing communications and offers about health, fitness, our programs, and related opportunities (including by email or SMS), or allow authorised third parties to do so;
- Enable interactive features of our services when you choose to use them;
- Collect marketing or analytics cookies; and
- Allow you to share content via integrated social media features.
- Performance of a contract
- We process your personal information for purposes such as:
- Fulfil our contractual obligations and deliver the products and services you request;
- Respond to your queries and keep you informed about service updates;
- Enable account features, purchases, content access, and secure payment processing through trusted providers; and
- Supportinstructor-related services such as certification, event participation, and club affiliation.
Legal obligation
We process your personal information where necessary to comply with our legal or regulatory obligations (for example, responding to lawful requests, maintaining required records, or meeting financial reporting requirements).
Legitimate interests
We process your personal information for purposes such as:
- Administering and improving our websites and apps, including troubleshooting, analytics, testing, and optimisation;
- Personalising content and tailoring your experience across our services;
- Keeping our sites and services safe and secure;
- Measuring and improving the effectiveness of advertising and delivering relevant ads where permitted by applicable law, including through third-party tools;
- Making recommendations about products or services that may interest you;
- Conducting research, surveys, and statistical analysis to enhance our offerings;
- Supporting training, quality assurance, and customer service (including reviewing callrecordings);
- Enabling social sharing features and engagement on third-party platforms;
- Supporting location-based features (e.g., Find-a-Class) using real-time device location with your permission; and
- Tracking participation in competitions and promotions.
Whenever possible, we anonymise the data so that it cannot be connected to any individual person.
7. WHERE AND HOW WE TRANSFER, STORE, AND PROTECT YOUR PERSONAL INFORMATION
Individuals located in the European Union (“EU”) or European Economic Area (“EEA”) should be aware that their personal information may be transferred to, and processed in, countries outside the EU/EEA by us or by third parties acting on our behalf, including the Les Mills Companies and our service providers. For example, personal information may be transferred to New Zealand for the purposes described above.
Where personal information is transferred outside the EU/EEA to a country that has not been recognised as providing an adequate level of data protection, we implement appropriate safeguards in accordance with applicable data protection laws, such as entering into Standard Contractual Clauses approved by the European Commission under the European Union General Data Protection Regulation (Regulation (EU) 2016/679). We may also assess the risks associated with the transfer and apply supplementary technical, contractual, or organisational measures where appropriate to ensure an equivalent level of protection.
Where required under other data protection laws (including Brazil’s Lei Geral de Proteção de Dados (“LGPD”), we also implement appropriate contractual or other safeguards to protect personal information transferred internationally.
8. HOW LONG WE KEEP YOUR PERSONAL INFORMATION
We keep personal information only for as long as we need it to support our legitimate business purposes, meet our legal obligations, or fulfil the purposes for which it was collected. When the information is no longer required, we (or our third‑party service providers) securely delete it, anonymise it, or archive it.
We determine how long to retain personal information based on factors such as the type of data, the reason it was collected, our operational needs, legal and regulatory requirements, and any contractual commitments.
For details about how long your personal information may be stored and your rights, including your rights to erasure, please see Section 16 -Your Privacy Rights.
9. SECURITY OF YOUR PERSONAL INFORMATION
We store your personal information on secure servers and trusted third‑partyservices that process data on our behalf. Any payment transactions are encrypted using industry‑standard security protocols.
Once we receive your information, we implement a combination of physical, technical, and administrative safeguards to protect it. These include strict access controls, regular testing and updates of our security measures, and compliance with applicable data protection laws. Access to personal information is limited to employees who need it to perform their roles, and they receive training on confidentiality and data protection. We take disciplinary action where necessary to ensure these responsibilities are upheld.
If you use a password to access certain parts of our site, you are responsible for keeping this password confidential. Please do not share it with anyone.
While we take appropriate steps to safeguard your personal information, no method of transmitting data over the internet is completely secure. We cannot guarantee the security of information sent to our site, and any transmission is at your own risk.
11. LINKS TO OTHER WEBSITES AND SERVICES
Our digital platforms, newsletters, and other communications will, from time to time, contain links and/or banners that take you to other websites. We are not responsible for the reliability of the content or privacy practices of such other websites.
Our site may also contain social media features, such as the Facebook Like button. These features will collect your IP address, which page you are visiting on our site, and will set a cookie to enable the feature to function properly. Social media features and widgets are either hosted by a third party or hosted directly on our site. Your interactions with these features are also governed by the privacy policy of the company providing it.
12. PUBLIC FORUMS AND USER GENERATED CONTENT
We may provide you with chat features, instant messaging, message boards, community forums, and/or news groups through our Digital Services. Please remember that any information that you share on public areas of the platform will become public information and be accessible to the public. We do not intend (but reserve the right) to monitor, moderate, or screen the contents of user postings. We bear no responsibility for any such content, and you should be cautious when considering whether to disclose your personal information in the on the platform through public or private forums.
13. LES MILLS INSTRUCTORS
If you are a Les Mills Instructor, we process your personal information for the purposes described above, and we also process information relating to your role as an Instructor. These additional uses are set out below.
Consent
Where you choose to share your personal information with Licensed Clubs through our Digital Services, we and Licensed Club(s) may access, process, and use your personal information to:
- support and manage your relationship with the Licensed Club;
- purchase Les Mills releases on your behalf;
- purchase event tickets on your behalf;
- contact you or respond to your contact requests; and
- undertake any other activities that are legally required or lawfully permitted from time to time.
Performance of a contract
Where you provide us with personal information in your role as an Instructor, we process it where it is necessary to enter into and perform our Instructor Agreement with you. We use your information to:
- review, manage and administer all aspects of your role (including performance, assessment, and payment);
- provide access to our Digital Services as well as information about training, assessment, certification, events, and Les Mills releases;
- provide information about your certification, continuing education, assessment, and training to your Licensed Club(s);
- ensure that the Licensed Club(s) you are affiliated with are complying with their obligations to us;
- ensure that you are complying with the terms of your Instructor Agreement and the applicable digital platforms you use as part of your role, including any legal proceedings arising in relation to the same; and
- manage and monitor the performance of group fitness (including Instructor performance) at Licensed Clubs and analysing trends in group fitness performance in the fitness industry.
Public disclosure of Instructor information
If you are an Instructor, we may publish your name in newsletters or on our websites in connection with your role. We will only do this where we have your explicit consent or where applicable privacy laws otherwise permit us to do so.
14. LICENSED CLUBS
If you are a Licensed Club and provide us with personal information about Instructors, you warrant that you have all necessary rights and consents under applicable law to provide that information to us and permit its use in accordance with this Policy. You agree to indemnify, defend, and hold us harmless from and against any claims, costs, losses, liabilities, and damage arising out of or in connection with a breach of this warranty.
15. CHILDREN’S PRIVACY
We do not knowingly collect information from individuals under the age of 16, and our Digital Services are not directed to children under the age of 16. If we learn that we have collected personal information from a child under 16, we will delete that information in accordance with applicable laws. We encourage parents and guardians to take an active role in their children’s online activities and interests.
16. YOUR PRIVACY RIGHTS
You have certain rights in relation to your personal information. These rights vary depending on the laws that apply to you, but we aim to handle all personal information in a way that gives you meaningful choice and control. In some circumstances, and where permitted by law, you may be able to request changes to your personal information, ask us to delete it, or limit how we use it. Additional rights may apply if you are in certain jurisdictions, such as the European Union, California, or Brazil. These are explained in the sections below. If you have questions about your rights or how they apply to you, please contact us using the details in Section 18 - Contact Us.
When you exercise your privacy rights, we may ask you to provide enough information for us to verify your identity before we respond to your request.
Accessing your personal information
You have the right to request access to the personal information we hold about you, including information we have shared with other Les Mills Companies or with third‑party service providers and processors. This right may be limited in some circumstances, as permitted by applicable data protection laws.
If you wish to do so, please email your request to privacy@lesmills.com.
We aim to be as open as possible with you. However, there may be situations where we need to withhold certain information — for example, where it is commercially sensitive, legally privileged, relates to another individual, or could compromise the safety or security of our employees or customers. In these cases, we will withhold the information but will explain the reason why.
Controlling your marketing preferences
You have the right to ask us not to use your personal information for marketing purposes. We will usually inform you before collecting your data if we intend to use your data for such purposes or if we intend to disclose your information to any third party for such purposes.
You can exercise the right at any time by contacting us at privacy@lesmills.com or by using any other opt-out method that we provide in the communication, such as an 'unsubscribe' link in emails.
European Union
If data protection laws in the EU apply to you, you may have additional rights in relation to your personal information. These include the right to request details about: the purposes for which we process your data; the categories of personal data involved; the recipients or categories of recipients who may have received your data (including parties outside the Les Mills Companies); the source of the data if it was not provided directly by you; and the period for which the data will be stored.
In addition to the rights described above, you also have the right to:
- request the correction (rectification) of any personal data we hold about you that is inaccurate or incomplete;
- request the deletion of your personal data or the cessation of its processing, subject to certain legal exceptions;
- object to our processing of your personal information based on the legitimate interests described above. In some cases, we may be unable to stop processing, but if this applies, we will explain why;
- receive the personal information you have provided to us in a structured, commonly used and machine‑readable format, and to transmit that data to another controller (data portability); and
- lodge a complaint with the relevant data protection authority if you have concerns about how we process your personal information.
Californian Privacy Rights
If you are a resident of California, you have additional rights under the California Privacy Rights Act (“CPRA”).These rights apply to the personal information we collect through our websites, apps and services. This section explains those rights and how you can exercise them.
We do not sell personal information. Some of the advertising and measurement tools we use on our websites (for example, through Google, Meta, TikTok or other marketing platforms) may involve the disclosure of device or browsing information so that advertising can be personalised or measured. Under the CPRA, this type of activity may be considered “sharing” for cross-context behavioural advertising.
We manage these technologies through our cookie consent management platform (“CMP”), which allows you to control your cookie preferences, including opting out of marketing, preference and advertising cookies. You can update your cookie settings at any time through our CMP or by using the “Do Not Sell or Share My Personal Information” link.
If you are a resident of California, you have the right to:
- know the categories of personal information we collect, use, and disclose;
- access the personal information we hold about you;
- delete your personal information (subject to certain exceptions);
- correct inaccurate personal information we hold about you;
- opt-out of any “sale” or “sharing” of your personal information;
- limit the use of “sensitive” personal information, if collected (we do not use sensitive personal information about you in a way that requires this right to be offered); and
- be free from discrimination for exercising any of your privacy rights.
You may exercise your California privacy rights by contacting us using the details set out in Section 18- Contact Us or through any other request mechanisms we make available from time to time. We may need to verify your identity before responding to your request. You may also designate an authorised agent to make a request on your behalf, in accordance with applicable law.
Brazilian Privacy Rights
If you are located in Brazil, you have rights under Brazil’s data protection law, the Lei Geral de Proteção de Dados (“LGPD”).These rights apply to the personal information we collect through our sites. This section explains those rights and how you can exercise them.
Under the LGPD, you have the right to:
- confirm whether we process your personal data;
- access the personal data we hold about you;
- correct incomplete, inaccurate or outdated data;
- request anonymisation, blocking or deletion of unnecessary or excessive data, or data processed in non-compliance with the LGPD.
- Port your personal data to another service provider, where technically feasible;
- Request information about shared third parties, including the categories of recipients;
- Withdraw consent at any time, where we rely on your consent;
- Request a review of automated decisions that affect your interests (where applicable).
Weare a global business and may transfer your personal data to countries outside Brazil. When we do this, we take appropriate steps to protect your data, including entering into contractual safeguards consistent with LGPD requirements.
If you wish to exercise your LGPD rights or have any questions about how we process your personal information in Brazil, you can contact our Data Protection Officer (Encarregado)
17. CHANGES TO OUR POLICY
We will post any updates to this Policy on this page and notify you directly if the changes are material. The “Last Updated” date below will always reflect the most recent version.
18. CONTACT US
Questions, comments and requests regarding this Policy are welcomed and should beaddressed to privacy@lesmills.com.
Our address is 200 Victoria Street West, Auckland, New Zealand 1010.
19. DIFFERENCES BETWEEN VERSIONS
If there is an inconsistency between the English version of this Policy and the Swedish version of this Policy, the English version will take priority (unless your personal information was collected from you in the Nordics, in which case the Swedish version will take priority).
10. SOCIAL SIGN IN AND SOCIAL NETWORK FEATURES
You may be able to log in to our site using social sign-in services such as Facebook Connect. These services will authenticate your identity and provide you the option to share certain personal information with us such as your name and email address to pre-populate our sign-up form. Services like Facebook Connect give you the option to post information about your activities on this site to your profile page to share with others within your network.