PRIVACY POLICY
Gymnastics Growth Limited ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store and protect personal data when you visit our websites (including nickruddock.com, gymnasticsos.com, gymnasticsid.com, gymnasticsleaders.com, gymnasticscongress.com and gymnasticswebinar.com, together with any associated subdomains), register for or claim a GymnasticsID®, download resources, register for webinars, purchase standalone digital products, purchase or access Gymnastics Growth® Academy ("GGA"), Gymnastics Leaders ("GL") or GymnasticsOS®, join our launch lists or waiting lists, use our web or mobile platform, or otherwise engage with us as an individual or as part of a club or organisation. References to "Programme" in this Policy mean any paid product or membership we provide, including Gymnastics Growth Academy, Gymnastics Leaders, GymnasticsOS and any standalone digital product. Where Membership Terms apply, the definition in those terms takes precedence. This Policy is issued in accordance with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.
WHO WE ARE
Gymnastics Growth Limited is a company incorporated in England & Wales with company number 13031738 and registered office at Third Floor, 207 Regent Street, London, W1B 3HH. ICO registration: ZB248126. Contact email: support@gymnasticsos.com. GymnasticsOS, GymnasticsID and Gymnastics Growth are registered trade marks owned by Nick Ruddock and used by Gymnastics Growth Limited under licence. For the purposes of data protection law, we may act as either Data Controller or Data Processor depending on how you engage with our services.
OUR PLATFORM AND SITES
GymnasticsOS is our umbrella platform, operated by Gymnastics Growth Limited, under which our paid content, courses and memberships sit, including Gymnastics Growth Academy ("GGA"), Gymnastics Leaders ("GL") and the GymnasticsOS platform itself. A GymnasticsID is the free, personal account you create to register for and access GymnasticsOS: a unique handle tied to a single email address that belongs to you. nickruddock.com is our personal-brand and content site, and our other sites (such as gymnasticscongress.com and gymnasticswebinar.com) support our events, webinars and related activities.
You must be aged 16 or over to claim a GymnasticsID, and registration is open internationally in any territory where we make it available. Where a member is under 18, some parts of the platform behave differently for them; see MEMBERS AGED 16 AND 17 below.
Where you purchase or access GGA, GL or other products, the applicable Membership Terms or Terms of Sale also apply. This Policy explains what we do with the personal data you provide across all of the above.
WHEN WE ACT AS DATA CONTROLLER
We act as Data Controller where we determine the purposes and means of processing personal data. This includes GymnasticsID registration, GGA memberships (single-user licences), direct purchases by individuals, lead magnet downloads, webinar registrations, marketing communications, certification issuance, platform analytics used to improve our services, billing and subscription management, launch list and waiting list signups, and responding to enquiries.
We are also the Data Controller for the way we run and protect the platform itself, whoever is paying for it. That includes our own analytics, the security monitoring described under KEEPING YOUR ACCOUNT SECURE, the administrative record described under RECORDS WE KEEP ABOUT YOUR ACCOUNT, and any decision to restrict or lock an account. A club cannot instruct us to do those things and cannot instruct us to stop, because they are how we keep the service safe for everybody on it.
In these circumstances we are responsible for complying with UK GDPR in relation to that processing.
WHEN WE ACT AS DATA PROCESSOR (ORGANISATIONAL LICENCES)
Where a Member Club purchases a Gymnastics Leaders or Gymnastics Growth Academy organisational licence and uses the platform to manage or monitor authorised users, we may process personal data on behalf of that Member Club. In such cases, the Member Club is the Data Controller and Gymnastics Growth Limited acts as Data Processor. Processing in this context is governed by the Data Processing Addendum forming part of the Membership Agreement. A Member Club can obtain a copy of that Addendum at any time by asking us at support@gymnasticsos.com. We process such personal data only on documented instructions from the Member Club and do not use it for our own independent purposes.
Your GymnasticsID itself remains your own account. It belongs to you rather than to any club, it continues to exist if you stop working with that club, and we act as Data Controller in respect of it.
Both roles may apply to the same person at the same time. If you are a coach at a member club and you also pay for your own Academy membership, we are the Processor for what you do as part of that club's account, and the Controller for your GymnasticsID, your own membership, and everything described in the paragraph above. Your club sees the first. It does not see the second.
CATEGORIES OF PERSONAL DATA
Depending on how you interact with us, we may collect:
Identity and Contact Data, including name, date of birth, email address, country of residence, telephone number, job title, club or organisation name, billing address and any profile photograph you upload.
Account and Platform Data, including your GymnasticsID handle, username, programme access history, certification status, CPD tracking records, engagement metrics, login activity, usage data, and the time you were last active on the platform.
Content You Create, including notes, entries, files and documents you upload or store in the platform, and anything you add to your own profile. Where you enter information into a club's own records as part of your work for that club, that content belongs to the club's account rather than to your personal one, and we handle it as Processor for them.
Message Content, including direct messages, club channel messages and group conversations, together with who is in a conversation and when messages were sent.
Connection and Visibility Data, including your connection requests and the people you are connected to, the club or organisation you are linked to, and your own visibility settings.
Safety Records, including reports you make about another member, reports another member makes about you, records of accounts you have blocked or that have blocked you, and the outcome of anything we act on.
Financial Data, including transaction history, subscription status and your billing status, being an internal marker of whether your account is paid, in arrears, on a legacy arrangement or complimentary. Card details and bank account details are handled by our payment providers and are not stored by us; where you pay by Direct Debit, your mandate is held by our Direct Debit provider.
Marketing and Lead Data, including lead magnet registrations, webinar registrations, launch list and waiting list signups, referral codes and referral activity, online exercise submissions, email engagement data, SMS engagement data and marketing preferences.
Technical Data, including IP address, device type, browser type, time zone, cookie identifiers and website usage data.
We do not intentionally collect special category data. We do not collect special category data for our own purposes.
Where you are linked to a club, information you record about that club's gymnasts in the course of your work is handled by us on the club's behalf rather than for ourselves, and the club is the controller of it.
The platform is not a medical, safeguarding, disciplinary or incident record system, and our Terms of Use ask you not to use it as one. Outside the ordinary run of coaching, please do not put health, medical or other sensitive information about anyone into free-text fields, messages or uploaded files.
You must not upload photographs, video or audio recordings of children to the platform at all. Our Terms of Use explain why, and what happens if you do.
HOW WE COLLECT DATA
We collect personal data when you claim a GymnasticsID, register for or purchase a Programme, download a free resource, complete an online exercise, are enrolled by a Member Club as an authorised user, join one of our launch lists or waiting lists, use our platform, interact with our website through cookies and analytics technologies, book a call with us, or engage with us through CRM, booking and email systems used to manage enquiries and marketing.
JOINING A CLUB
A club can invite you to join its account by giving you a club code, or by inviting you by email. When you use that code or accept that invitation, we create a link between your GymnasticsID and that club, and that link is what lets the club see you on its staff list and include you in its records. You can see which club you are linked to at any time, and either you or the club can end the link.
Where a club holds an organisational licence, everyone on its staff list is given access to the content included in that licence. That access exists because of the club's payment rather than a purchase of your own, and if the club's subscription ends, or your link to the club ends, that access ends with it. Your use of that content produces the same records as any other member's, and those records sit with your GymnasticsID.
HOW OTHER MEMBERS SEE YOU
Some of your information is visible to other members of the platform.
You can be found by other members in Network, the part of the platform where coaches and clubs find and connect with each other. Before you have accepted a connection, another member can see your name, your handle, your About description and the club you are linked to. The rest of your GymnasticsID stays private until you accept a connection request from them.
There is one exception. Where you are linked to a club, your co-workers at that club can see your GymnasticsID without sending a connection request. They can also see when you were last active on the platform. If you are unlinked from a club, that access ends.
You control your own visibility settings within the platform, and you can decline or withdraw a connection at any time. We process this information to deliver the platform to you under Contract, and to keep the directory useful and safe under Legitimate Interests.
MESSAGING
The platform lets members message each other directly, in club channels and in group conversations. We process the content of those messages in order to deliver the messaging service, and we use a specialist messaging provider to do so under a data processing agreement.
We do not read your messages routinely, and we do not use their content for marketing or to train AI models. We may access message content where it is necessary to investigate a report or a safety concern, to comply with a legal obligation, or to resolve a technical fault you have asked us to fix.
Messages between an under-18 and an adult are treated differently. See MEMBERS AGED 16 AND 17 below.
If you delete your account, the messages you have sent remain visible to the people you sent them to, shown as coming from a deleted member rather than from you by name. This is so that the other party retains their own record of the conversation, and so that a conversation subject to a safeguarding report cannot be removed by closing an account.
SAFETY, BLOCKING AND REPORTING
You can block another member, and you can report a member or a message to us.
Where you block someone, we record that block and apply it across the platform, including with our messaging provider. Where you report someone, we record the report, what you told us, and what we did about it.
A report you make about another member is information about them, and a report made about you is information about you. We retain both. We may not be able to show you the full content of a report made about you where doing so would identify the person who made it or would prejudice an investigation.
We process this information under Legitimate Interests, specifically our interest and yours in a platform that is safe for coaches and for young people.
If you report a specific message, we take a copy of that message and of a few messages either side of it, at the moment you report it. We do this because a message can be deleted by the person who sent it, and the more serious the message the more likely that is. The copy is made by our systems from our messaging provider, not from your device, and we store the text, who sent it, when it was sent, and a fingerprint that lets us show the copy has not been altered since. We record which message you reported and which were kept only as context.
We take a few messages either side because a single line lifted out of an exchange can read either way, and a decision made on one line is a decision made on half the facts. We do not take the wider conversation and we do not take your message history.
Where a message had a file attached, we record what the file was - its name, type and size - and a link to it. We do not take our own copy of the file. If it needs to be looked at, a member of our staff opens it deliberately, and that is recorded in the same way as reading the message.
If you report a person rather than a particular message, we take no copy of any conversation at all. There is nothing you have identified for us to look at, and we do not go looking.
A member of our staff may read what was captured in order to decide what to do about the report. Only the small number of people who run the platform can do this. Every time one of them opens a reported message we record who opened it and when, and they cannot edit or remove that record. If that record cannot be written, the message is not shown to them.
We keep a log of the steps we take on a report - for example that we restricted an account while we looked into it, that we spoke to someone, that we lifted the restriction, and how the report was closed. Each step records who took it and when, and we keep it whether the report was upheld or dismissed, because a decision that nothing happened needs the same trail as a decision that something did.
We do not read your messages for any other reason. We do not read them to improve the product, to train anything, or out of curiosity, and there is no way for us to browse conversations that have not been reported.
We are still setting how long we keep this material, and we record the date everything was captured so that a retention period can be applied to it once set. If you want to know what we hold about you, you can ask us.
KEEPING YOUR ACCOUNT SECURE, the administrative record described under RECORDS WE KEEP ABOUT YOUR ACCOUNT, and any decision to restrict or lock an account. A club cannot instruct us to do those things and cannot instruct us to stop, because they are how we keep the service safe for everybody on it.
In these circumstances we are responsible for complying with UK GDPR in relation to that processing.
WHEN WE ACT AS DATA PROCESSOR (ORGANISATIONAL LICENCES)
Where a Member Club purchases a Gymnastics Leaders or Gymnastics Growth Academy organisational licence and uses the platform to manage or monitor authorised users, we may process personal data on behalf of that Member Club. In such cases, the Member Club is the Data Controller and Gymnastics Growth Limited acts as Data Processor. Processing in this context is governed by the Data Processing Addendum forming part of the Membership Agreement. A Member Club can obtain a copy of that Addendum at any time by asking us at support@gymnasticsos.com. We process such personal data only on documented instructions from the Member Club and do not use it for our own independent purposes.
Your GymnasticsID itself remains your own account. It belongs to you rather than to any club, it continues to exist if you stop working with that club, and we act as Data Controller in respect of it.
Both roles may apply to the same person at the same time. If you are a coach at a member club and you also pay for your own Academy membership, we are the Processor for what you do as part of that club's account, and the Controller for your GymnasticsID, your own membership, and everything described in the paragraph above. Your club sees the first. It does not see the second.
CATEGORIES OF PERSONAL DATA
Depending on how you interact with us, we may collect:
Identity and Contact Data, including name, date of birth, email address, country of residence, telephone number, job title, club or organisation name, billing address and any profile photograph you upload.
Account and Platform Data, including your GymnasticsID handle, username, programme access history, certification status, CPD tracking records, engagement metrics, login activity, usage data, and the time you were last active on the platform.
Content You Create, including notes, entries, files and documents you upload or store in the platform, and anything you add to your own profile. Where you enter information into a club's own records as part of your work for that club, that content belongs to the club's account rather than to your personal one, and we handle it as Processor for them.
Message Content, including direct messages, club channel messages and group conversations, together with who is in a conversation and when messages were sent.
Connection and Visibility Data, including your connection requests and the people you are connected to, the club or organisation you are linked to, and your own visibility settings.
Safety Records, including reports you make about another member, reports another member makes about you, records of accounts you have blocked or that have blocked you, and the outcome of anything we act on.
Financial Data, including transaction history, subscription status and your billing status, being an internal marker of whether your account is paid, in arrears, on a legacy arrangement or complimentary. Card details and bank account details are handled by our payment providers and are not stored by us; where you pay by Direct Debit, your mandate is held by our Direct Debit provider.
Marketing and Lead Data, including lead magnet registrations, webinar registrations, launch list and waiting list signups, referral codes and referral activity, online exercise submissions, email engagement data, SMS engagement data and marketing preferences.
Technical Data, including IP address, device type, browser type, time zone, cookie identifiers and website usage data.
We do not intentionally collect special category data. We do not collect special category data for our own purposes.
Where you are linked to a club, information you record about that club's gymnasts in the course of your work is handled by us on the club's behalf rather than for ourselves, and the club is the controller of it.
The platform is not a medical, safeguarding, disciplinary or incident record system, and our Terms of Use ask you not to use it as one. Outside the ordinary run of coaching, please do not put health, medical or other sensitive information about anyone into free-text fields, messages or uploaded files.
You must not upload photographs, video or audio recordings of children to the platform at all. Our Terms of Use explain why, and what happens if you do.
HOW WE COLLECT DATA
We collect personal data when you claim a GymnasticsID, register for or purchase a Programme, download a free resource, complete an online exercise, are enrolled by a Member Club as an authorised user, join one of our launch lists or waiting lists, use our platform, interact with our website through cookies and analytics technologies, book a call with us, or engage with us through CRM, booking and email systems used to manage enquiries and marketing.
JOINING A CLUB
A club can invite you to join its account by giving you a club code, or by inviting you by email. When you use that code or accept that invitation, we create a link between your GymnasticsID and that club, and that link is what lets the club see you on its staff list and include you in its records. You can see which club you are linked to at any time, and either you or the club can end the link.
Where a club holds an organisational licence, everyone on its staff list is given access to the content included in that licence. That access exists because of the club's payment rather than a purchase of your own, and if the club's subscription ends, or your link to the club ends, that access ends with it. Your use of that content produces the same records as any other member's, and those records sit with your GymnasticsID.
HOW OTHER MEMBERS SEE YOU
Some of your information is visible to other members of the platform.
You can be found by other members in Network, the part of the platform where coaches and clubs find and connect with each other. Before you have accepted a connection, another member can see your name, your handle, your About description and the club you are linked to. The rest of your GymnasticsID stays private until you accept a connection request from them.
There is one exception. Where you are linked to a club, your co-workers at that club can see your GymnasticsID without sending a connection request. They can also see when you were last active on the platform. If you are unlinked from a club, that access ends.
You control your own visibility settings within the platform, and you can decline or withdraw a connection at any time. We process this information to deliver the platform to you under Contract, and to keep the directory useful and safe under Legitimate Interests.
MESSAGING
The platform lets members message each other directly, in club channels and in group conversations. We process the content of those messages in order to deliver the messaging service, and we use a specialist messaging provider to do so under a data processing agreement.
We do not read your messages routinely, and we do not use their content for marketing or to train AI models. We may access message content where it is necessary to investigate a report or a safety concern, to comply with a legal obligation, or to resolve a technical fault you have asked us to fix.
Messages between an under-18 and an adult are treated differently. See MEMBERS AGED 16 AND 17 below.
If you delete your account, the messages you have sent remain visible to the people you sent them to, shown as coming from a deleted member rather than from you by name. This is so that the other party retains their own record of the conversation, and so that a conversation subject to a safeguarding report cannot be removed by closing an account.
SAFETY, BLOCKING AND REPORTING
You can block another member, and you can report a member or a message to us.
Where you block someone, we record that block and apply it across the platform, including with our messaging provider. Where you report someone, we record the report, what you told us, and what we did about it.
A report you make about another member is information about them, and a report made about you is information about you. We retain both. We may not be able to show you the full content of a report made about you where doing so would identify the person who made it or would prejudice an investigation.
We process this information under Legitimate Interests, specifically our interest and yours in a platform that is safe for coaches and for young people.
When you report someone from a conversation, we take a copy of that conversation at the moment you report it. We do this because a message can be deleted by the person who sent it, and the more serious the message the more likely that is. The copy is taken by our systems from our messaging provider, not from your device, and we store the text of each message, who sent it, when it was sent, and a fingerprint that lets us show the copy has not been altered since.
We take the recent part of the conversation rather than a single message, because a single line taken out of an exchange can read either way. We do not take the whole history of your conversations.
A member of our staff may read that copy, and the surrounding conversation, in order to decide what to do about the report. Only the small number of people who run the platform can do this. Every time one of them opens a reported conversation we record who opened it and when, and that record cannot be edited or removed by them.
We keep a log of the steps we take on a report - for example that we restricted an account while we looked into it, that we spoke to someone, that we lifted the restriction, and how the report was closed. Each step records who took it and when. We keep this whether the report was upheld or dismissed, because a decision that nothing happened needs the same trail as a decision that something did.
We do not read your messages for any other reason. We do not read them to improve the product, to train anything, or out of curiosity, and there is no way for us to browse conversations that have not been reported.
KEEPING YOUR ACCOUNT SECURE
We keep a record of the devices you sign in from and of your sign-in events, including time, approximate location derived from your IP address, and the device and browser used. We use this to identify accounts that are being shared or that have been taken over.
We look for a small number of specific patterns: sign-ins from an unusually high number of different devices over a short period, sign-ins from two countries so far apart that one person could not have travelled between them in the time, and several sign-ins from different places at the same time. These checks are automated and refer an account for review by a member of our staff. No account is restricted automatically as a result of them.
Where we believe an account is being shared against our terms, has been taken over, or is being used to harm someone, we may restrict it or lock it. A restricted account keeps its data and loses some access; a locked account cannot be used until the matter is resolved. Neither is the same as cancelling or deleting an account, and in both cases you can contact us at support@gymnasticsos.com to ask why and to ask us to review it. We rely on Legitimate Interests for this monitoring, being our interest in protecting members, young people and the service from misuse.
CHECKING WHAT IS PUBLISHED ON THE PLATFORM
We check content published on the platform, being your profile, your handle, your About description and any club page you control, for material our Acceptable Use Policy does not permit, such as links and calls to action selling to other members. This applies to content other members can see. We do not scan the content of your messages for this purpose.
RECORDS WE KEEP ABOUT YOUR ACCOUNT
When someone at Gymnastics Growth Limited changes something about your account, such as your membership status, tier, billing arrangement or access, we record what was changed, when, and who changed it. This history is retained permanently and is not edited or removed. It is visible to our staff and not to other members or to your club.
We produce analytics about how the platform is used, including how many members are active, where they are located, and which content is used. Our staff can see this both in aggregate and, where necessary to support you or investigate a problem, as an individual record of your own activity.
MEMBERS AGED 16 AND 17
You must be aged 16 or over to claim a GymnasticsID. We ask for your date of birth when you register and ask you to confirm it, and your age determines how some parts of the platform behave for you.
In the United Kingdom, a person aged 13 or over can give their own consent to use an online service. We therefore do not require parental consent for a member aged 16 or 17. A parent or guardian with a question about a young person's account can contact us at support@gymnasticsos.com.
Where a member is under 18, they cannot exchange private one-to-one messages with an adult member. A conversation between an under-18 and an adult must include a chaperone: a responsible adult aged 18 or over who joins the conversation and can see everything written in it. Everyone in the conversation can see that it is chaperoned and who the chaperone is. This applies whichever of them started the conversation and cannot be turned off.
Because your date of birth changes what the platform allows, you cannot change it yourself across your eighteenth birthday once your account exists. If your date of birth is recorded incorrectly, contact us and we will correct it.
We do not allow anyone under 16 to register. If we become aware that we hold personal data about someone under 16, we will delete it. If you believe someone under 16 has registered, please contact support@gymnasticsos.com.
IMPORTED LEGACY DATA AND ACCOUNT CONSOLIDATION
We hold historic purchase and account records that we are migrating from a previous system. As part of bringing your history into GymnasticsOS, we may link your GymnasticsID and email address to this imported legacy purchase data so that your past purchases appear in one place. You may also add and verify additional or previously used email addresses to your GymnasticsID in order to consolidate purchases made under different email addresses into a single account. We only link records where there is a reasonable match to you, and you can ask us to unlink or correct any record you believe has been associated with you in error.
MANAGING YOUR MEMBERSHIP
We cross-check memberships to find people who are paying twice for the same thing, for example paying for Academy separately when an organisational licence or a Gymnastics Leaders membership already includes it. Where we find one we will tell you, both in the platform and by contacting you, so that you can cancel whichever you no longer need. Cancelling it is your decision and your responsibility, and we are not obliged to refund payments already taken on a duplicate subscription. We do this under Legitimate Interests.
Where you ask to cancel, we record the request, its status and how it was resolved, so that it can be dealt with and evidenced later.
PURPOSES AND LAWFUL BASES
We process personal data only where lawful. We rely on Contract where processing is necessary to deliver GymnasticsID registration, Programme access, certifications, subscriptions, messaging and platform functionality; Legitimate Interests to operate and improve our services, consolidate your historic records, keep the platform and its members safe, monitor engagement, prevent misuse, analyse performance and communicate relevant offerings, balancing those interests against your rights; Consent where required for marketing emails, SMS messages or non-essential cookies (which may be withdrawn at any time); and Legal Obligation where processing is required for tax, accounting or regulatory compliance.
TEXT MESSAGES
We do not send marketing text messages.
Where you give us your mobile number, we may send you a text message to verify that the number is yours, or to send you a single-use code when you sign in or confirm a change to your account. These messages are necessary to protect your account rather than to promote anything, and standard message and data rates from your network may apply.
If we ever introduce marketing text messages, we will ask for your consent separately first, and you will be able to withdraw it at any time.
NOTICES WE SHOW YOU
Where there is a problem with the service, or planned maintenance, we may show a status message to everyone signed in. These notices are about the platform rather than about you, and showing one does not involve looking at your data.
CALLS WITH US
Where you book or join a call with us, including coaching calls, support calls, and discovery or sales calls, we may record it and use automated transcription services to produce a written record. Recording is disclosed in the booking confirmation and confirmed verbally at the start of the call.
We use those recordings and transcripts to follow up on the conversation, to keep our own record of what was discussed and agreed, and to improve our products and services. We also use AI tools to summarise transcripts and to build notes about you and your coaching, so that we hold a continuous record between conversations. Those notes form part of the record we hold about you, and you may ask to see them.
We do this under Legitimate Interests, being our interest in giving you continuous and informed support, balanced against your right to be informed and your right to object. You may object to this processing, and you may ask us to delete any recording, transcript or note, by emailing support@gymnasticsos.com.
AI ASSISTANCE TOOLS
We use AI-powered tools, including automated transcription services and large language model assistants, to draft notes, summarise meetings and support internal productivity.
Where these tools process documents or recordings containing personal data, we use business or enterprise accounts operating under a data processing agreement consistent with UK GDPR, configured so that our data is not used to train the provider's models. We do not put personal data into AI tools operating on consumer terms.
We do not use the content of member messages to train AI models.
ORGANISATIONAL REPORTING
Where a Member Club holds a Gymnastics Leaders or Gymnastics Growth Academy organisational licence, we may provide the club with reporting relating to its authorised users, including whether an account is active, when it was last used, participation in club content and certification status.
Reporting is limited to a member's activity as part of that club. It does not extend to a member's private messages, to their personal notes and content, or to their membership or purchases outside that club.
One item is broader in scope than club reporting. The time you were last active on the platform is a single figure for your whole account, not a per-club one, and it is visible to the other members of your club rather than only to a club administrator. It shows when you last used GymnasticsOS, not what you were doing. Reporting is provided for the internal professional development and performance management purposes of the Member Club, and authorised users acknowledge that such reporting forms part of the organisational licence structure.
KEY SERVICE PROVIDERS
We engage carefully-selected third-party sub-processors to deliver our services. For compliance and transparency, the following providers are named explicitly: Stripe (payment processing), GoCardless (Direct Debit collection), Twilio (SMS messaging) and Kit (email marketing). For all other sub-processors, including hosting and infrastructure, messaging, in-app media, analytics, scheduling and operational tooling, we share the categories of providers used (see DATA SHARING below). Each provider operates under a data processing agreement consistent with UK GDPR.
Where you are a member or customer and you wish to know which providers process your own personal data, you may make a written request to support@gymnasticsos.com. We will verify your identity before responding, and we will respond within the period required by law.
A request of this kind concerns the providers that handle your own personal data. It does not extend to suppliers who do not process it, or to information about how we run our business. Where a request is manifestly unfounded or excessive, including where it is repetitive, we may charge a reasonable fee or decline to act on it, as the law permits.
DATA SHARING
We share personal data only where necessary and with appropriate safeguards. This may include payment processors, direct debit and bank payment providers, hosting and database providers, cloud storage providers, messaging and chat infrastructure, video hosting and streaming providers, document and certificate generation providers, email marketing platforms, transactional email providers, SMS gateway providers, push notification providers, live-chat and customer-support platforms, video conferencing and meeting-transcription providers, scheduling platforms, CRM systems, webinar platforms, workflow automation tools, AI-assistance providers, analytics tools, error and performance monitoring providers, cookie consent management providers, accounting software and form and survey platforms.
Where we engage third-party processors, we ensure appropriate contractual safeguards are in place in accordance with UK GDPR. We may disclose personal data where required by law, in connection with legal proceedings, or in the event of business restructuring. We do not sell personal data.
INTERNATIONAL MEMBERS
Our members are in a number of countries, and the platform is available wherever we make it available.
We are established in the United Kingdom, so UK data protection law governs what we do with your personal data wherever you live. We apply the same standard to everyone: the rights set out under YOUR RIGHTS below are given to every member, not only to members in the United Kingdom.
Where the law of your own country gives you rights we have not described, those rights are not taken away by this Policy. Tell us what you would like to exercise and we will deal with it. Where you are a club or an organisation rather than an individual, you remain responsible for complying with the data protection law that applies to you, and our Club Data Processing Agreement says so.
INTERNATIONAL TRANSFERS
Some service providers may operate outside the United Kingdom. Where personal data is transferred internationally, we rely on appropriate safeguards including UK adequacy regulations, UK-approved Standard Contractual Clauses and additional contractual and technical safeguards where appropriate.
DATA RETENTION
We retain personal data only for as long as necessary for the purposes for which it was collected, including financial records for a minimum of six years, active membership data for the duration of your membership and two years afterwards, marketing and SMS data until you unsubscribe, and processor data (organisational licence accounts) in accordance with contractual arrangements. Recordings, transcripts and notes from calls are retained for as long as you remain a member or customer and for six years afterwards, in line with our other business records, because they form part of the history of our work with you.
Message content is retained for as long as the conversation exists.
Safety records, including blocks and reports, are retained for six years, including after an account is closed, because their purpose is to protect other members. Records of devices and sign-in events are retained for twelve months.
The time you were last active is current information only. It is overwritten rather than kept as a history.
A GymnasticsID without a membership. A GymnasticsID is free, and holding one does not require you to buy anything. Many people will use one only to reserve their handle, appear in Network and message other coaches, and that is a complete way to use it rather than an unfinished one. Where you hold a GymnasticsID with no membership attached, we keep your identity record, being your name, email address, chosen handle and registration details, for as long as your account exists, so that your handle stays reserved to you. You can delete your GymnasticsID at any time.
Retention after deletion. If you delete your account or ask us to erase your GymnasticsID, we retain a limited core record of your identity (such as name, email address and the fact an account existed) for six years afterwards. We keep this for legal, financial, tax, audit and dispute-resolution purposes, after which it is securely deleted or anonymised. We want you to know this before you register: deleting your account removes your active profile and stops ongoing processing, but a minimal record is retained for the period described above.
SECURITY
We implement appropriate technical and organisational measures proportionate to the risk, including secure hosting, encrypted connections, role-based access controls and restricted internal access. We do not use passwords. You sign in with a single-use code sent to your email address, so no password of yours is stored by us. While we take commercially reasonable steps to protect personal data, no system can guarantee absolute security.
If a personal data breach occurs, we will investigate it, and where the law requires it we will report it to the Information Commissioner's Office without undue delay and within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to your rights and freedoms, we will tell you directly and without undue delay, explaining what happened, what it means for you and what we are doing about it.
YOUR RIGHTS
Under UK GDPR you have the right to access your personal data, rectify inaccurate data, request erasure, restrict or object to processing, request data portability, withdraw consent (including marketing email, SMS or call-recording consent) and lodge a complaint with the Information Commissioner's Office (ICO). Requests may be made to support@gymnasticsos.com, and we will respond within one month. The ICO can be contacted at www.ico.org.uk.
COOKIES
We use cookies and similar technologies to operate our website, improve user experience, analyse traffic and support marketing activities. Strictly necessary cookies (including those needed to register and secure your GymnasticsID) are used without consent; all other categories are set only with your prior consent. You may control cookies through our cookie banner and settings, or your browser settings. See our Cookies Policy for full detail.
CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. The latest version will always be available on our website. Where a change materially affects how we use your personal data, we will tell you, and where the law requires it we will ask you to agree to the new version before you continue using the platform.