This privacy policy applies between you, the User of this Website, and Peaceful Suites Ltd (“Peaceful Suites”, “we”, “us” or “our”), the owner and provider of this Website. We take the privacy of your information seriously, and this policy explains how we collect, use, share and protect the personal data of Users in connection with your use of www.peacefulsuites.com (the “Website”) and our related services.
Please read this policy carefully. If you do not agree with any part of it, please do not use the Website.
In this policy, the following definitions apply:
Unless the context requires otherwise, the singular includes the plural and vice versa, “including” means “including without limitation”, and headings are for convenience only and do not affect interpretation.
This policy applies only to the actions of Peaceful Suites and Users in respect of this Website. It does not extend to any third-party websites that can be accessed from this Website, including any social media platforms we may link to. We are not responsible for the privacy practices of any third-party websites.
For the purposes of the Data Protection Laws, Peaceful Suites is the “data controller” in respect of the personal data described in this policy – meaning we determine the purposes for which, and the manner in which, your Data is processed.
We may collect the following categories of Data, which may include personal data, from you:
Health data is a “special category” of personal data under the Data Protection Laws. We only collect this where you choose to provide it, and we rely on your explicit consent to process it, for the purpose of planning classes and sessions safely and appropriately for you.
We collect Data directly from you, for example:
When you access the Website, we automatically collect certain Data, including your IP address, and the date, time and frequency with which you access the Website, together with information about how you use and interact with its content. We also collect Data automatically via cookies, in line with your cookie settings – see Part B below for full details.
We use your Data where it is necessary to provide you with the best possible service and experience, including for internal record-keeping and the improvement of our products and services. The table below sets out our main purposes for processing and the legal basis we rely on under the Data Protection Laws.
Purpose | Legal basis |
Booking and managing a class, session or subscription | Performance of a contract with you |
Responding to enquiries and providing customer support | Legitimate interests – running our business effectively |
Processing payments and subscriptions | Performance of a contract; legal obligation (accounting/tax) |
Recording injuries or known health issues to plan classes safely | Explicit consent (special category data) |
Sending marketing communications | Consent (or legitimate interests for existing customers, with an opt-out) |
Website analytics and improving our services | Consent (cookies) and legitimate interests |
Preventing fraud and keeping our systems secure | Legal obligation and legitimate interests |
Where we rely on legitimate interests, you have the right to object in certain circumstances – see “Your Rights” below. Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
We will not use your Data for any purpose incompatible with the purposes set out above without notifying you and, where required, obtaining your consent.
We do not sell your personal data. We may share your Data with the following categories of recipient, for the reasons set out below. Where a third party processes Data on our behalf, we have appropriate contracts in place requiring them to protect your Data in line with the Data Protection Laws.
Recipient | Reason for sharing | Retention by recipient |
Our staff, contractors and professional advisers | Class timetabling and assessing general levels of fitness | For as long as necessary to deliver the service, or as advised by our professional advisers |
Fitness/progress-tracking software provider (data processor) | Tracking members’ progress and fitness against a software application | For the duration of your membership plus the retention period set out below |
Payment service provider (data processor) | Processing and managing payments for subscription plans | In line with the payment provider’s own retention obligations and applicable financial regulation |
Regulators, law enforcement or courts | Where we are required to do so by law or to protect our legal rights | As required by the relevant legal obligation |
We may also disclose your Data as required by law, to protect our legal rights, or in connection with a sale or restructuring of our business – see “Changes of Business Ownership” below.
Your Data is primarily stored and processed within the UK and the European Economic Area (EEA). If any of our third-party service providers are located outside the UK or EEA, we will ensure an appropriate safeguard is in place before transferring your Data, such as the UK International Data Transfer Agreement, EU Standard Contractual Clauses, or reliance on a jurisdiction benefiting from an adequacy decision. You can request further details of the safeguards we use by contacting us using the details below.
We use appropriate technical and organisational measures to safeguard your Data, including:
We are certified to SOC 2, a recognised security and data-management standard. Technical and organisational measures also include procedures for identifying and responding to any suspected data breach. If you suspect any misuse, loss or unauthorised access to your Data, please contact us immediately – see “Contact Us” below. Where required by law, we will notify the Information Commissioner’s Office and affected individuals of any personal data breach that poses a risk to their rights and freedoms, without undue delay.
For further guidance on protecting your information and devices against fraud, identity theft and other online risks, visit
We only keep your Data for as long as necessary to fulfil the purposes set out in this policy, or as required or permitted by law. Typical retention periods are set out below; these may vary depending on your individual circumstances.
Category of Data | Typical retention period | Reason |
Account and contact details | Duration of membership plus 6 years | Contractual necessity and limitation periods for legal claims |
Health and injury information | Duration of membership plus 2 years, or as required for insurance purposes | Safety, insurance and legitimate interests |
Payment and transaction records | 6 years from the end of the relevant tax year | UK tax and accounting legislation |
Marketing preferences | Until you unsubscribe or withdraw consent, then suppressed to record your choice | Consent / legitimate interests |
Website analytics data (cookies) | Up to 26 months | Consent |
Even after Data is deleted from our live systems, it may persist for a limited period on secure backup or archival media, retained only for legal, tax or regulatory purposes.
Subject to certain exemptions, you have the following rights in relation to your Data under the Data Protection Laws:
Right | What it means |
Right to be informed | To know how and why we use your personal data — set out in this policy. |
Right of access | To request a copy of the personal data we hold about you. |
Right to rectification | To have inaccurate or incomplete data corrected. |
Right to erasure | To request deletion of your data in certain circumstances (‘right to be forgotten’). |
Right to restrict processing | To limit how we use your data in certain circumstances. |
Right to data portability | To receive your data in a portable format, or have it transferred to another provider. |
Right to object | To object to processing based on legitimate interests, or to direct marketing. |
Rights re: automated decisions | To not be subject to solely automated decision-making that produces legal or similarly significant effects, without human involvement. |
Where we provide access to your information, we will not charge a fee unless your request is manifestly unfounded, excessive or repetitive. We may need to request specific information from you to help confirm your identity before responding. We aim to respond to all legitimate requests within one month; if a request is particularly complex, or you have made multiple requests, it may take longer, and we will keep you informed.
To exercise any of these rights, or to withdraw consent where consent is our legal basis for processing, please contact us using the details in “Contact Us” below.
If you are unhappy with how we have handled your Data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues:
We would, however, appreciate the opportunity to address your concerns directly before you approach the ICO, so please contact us first.
Our services are intended for adults. We do not knowingly collect personal data from children under 13 without the consent of a parent or guardian. If a class or service is offered to minors, we will collect only the Data necessary to deliver that service, and require verifiable parental or guardian consent before doing so. If you believe we have inadvertently collected Data from a child without appropriate consent, please contact us so that we can delete it.
We do not currently use your Data to make decisions by automated means that produce legal or similarly significant effects on you. If this changes, we will update this policy and, where required, obtain your consent.
Where you have consented to receive marketing communications from us, you may opt out at any time by using the “unsubscribe” link in any marketing e-mail, or by contacting us directly using the details below. Opting out of marketing communications does not affect service-related communications, such as booking confirmations or account notices, which we may still need to send you.
This Website may, from time to time, contain links to other websites. We have no control over, and are not responsible for, the content or privacy practices of those websites. This policy does not extend to your use of any third-party website, and we recommend you read the privacy policy of any website before using it.
Peaceful Suites may, from time to time, expand, restructure or sell all or part of its business. Where Data is relevant to any part of the business so transferred, it will transfer along with that part, and the new owner will be permitted to use the Data for the purposes for which it was originally supplied, subject to this policy or an equivalent successor policy. We may also disclose Data to a prospective purchaser as part of that process, subject to appropriate confidentiality protections. In all cases, we will take reasonable steps to ensure your privacy continues to be protected.
We may update this policy from time to time, as we consider necessary, or as required by law. Any changes will be posted on the Website, and, where the changes are material, we will take reasonable steps to notify you directly (for example, by e-mail). Your continued use of the Website following any changes will constitute your acceptance of the updated policy.
If you have any questions about this policy, wish to exercise any of your rights, or want to report a suspected data breach, please contact us at: