Privacy Policies

Last updated: August 12, 2026

1. IDENTITY OF THE DATA CONTROLLER

In compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (GDPR), and Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), users are informed that the personal data collected through this website will be processed by:

Data Controller: Ian David Field
Tax ID (CIF/NIF): X9294106J
Address: Av. De Los Covachos, 2, 30870 Mazarrón, Murcia
Email: cdafitness@hotmail.co.uk
Telephone: +34 634 30 40 87
Website: https://cdaftiness.es

Hereinafter referred to as the “Controller“.

2. PURPOSE OF THE PROCESSING

The personal data provided by users will be processed for the following purposes:

a) Handling Inquiries

Managing requests for information, inquiries, questions, or communications made through contact forms, email, telephone, or other communication channels available on the website.

b) Customer Management

Managing the contracting of sports services, membership registrations, activity bookings, group classes, personal training sessions, and any other services offered by the gym.

c) Administrative, Tax, and Accounting Management

Managing invoicing, collections, payments, incidents, and compliance with legal obligations arising from the contractual relationship.

d) Sending Commercial Communications

Sending information about promotions, events, updates, sports activities, and offers related to the gym’s services when prior consent has been obtained or when there is a contractual relationship that permits such communications.

e) Security and Fraud Prevention

Ensuring the security of the platform, detecting unauthorized access, and preventing fraudulent activities.

f) Statistical Analysis and Service Improvement

Analyzing the use of the website through analytics tools in order to improve the browsing experience and the services offered.

3. CATEGORIES OF DATA PROCESSED

The following categories of data may be processed:

  • First name and surname.
  • Identification document.
  • Postal address.
  • Email address.
  • Telephone number.
  • Website access and browsing data.
  • Billing information.
  • Banking details when necessary for payment management.
  • Information voluntarily provided by the user.

The user guarantees that the data provided is accurate, complete, and up to date.

4. LEGAL BASIS FOR PROCESSING

The legal grounds that legitimize the processing are as follows:

Consent of the Data Subject

When the user voluntarily contacts the gym, requests information, or agrees to receive commercial communications.

Performance of a Contract

When processing is necessary for the provision of contracted services or for the implementation of pre-contractual measures requested by the user.

Compliance with Legal Obligations

When necessary to comply with legal obligations in tax, labor, accounting, administrative, or consumer protection matters.

Legitimate Interest

To ensure website security, prevent fraud, improve our services, and carry out internal management activities.

5. DATA RETENTION PERIOD

Personal data will be retained:

  • For as long as a contractual relationship exists with the user.
  • Until the user requests its deletion.
  • For the periods required by applicable legal obligations.

Once these periods have expired, the data may remain blocked solely for the purpose of addressing potential legal liabilities.

6. DATA RECIPIENTS

As a general rule, data will not be disclosed to third parties except where required by law.

However, the following entities may have access to the data:

Financial Institutions

To manage collections, refunds, and transactions related to the contracted services.

Consultancy and Accounting Firms

For compliance with tax, labor, and accounting obligations.

Technology Service Providers

Providers offering web hosting, IT maintenance, email services, statistical analysis, and customer management services.

All of them operate under agreements that guarantee the confidentiality and security of the data.

7. PAYMENTS THROUGH STRIPE

To manage payments made through this website, we use the services of Stripe Payments Europe, Ltd.

When a user purchases services or pays any amount through the website, certain information necessary to process the payment may be communicated directly to Stripe.

The data that may be processed includes:

  • First name and surname.
  • Email address.
  • Billing information.
  • Transaction amount.
  • Data necessary for payment validation and security.

Stripe acts as an independent data controller with regard to the information used to process payment transactions.

You can obtain more information by consulting Stripe’s Privacy Policy:

https://stripe.com/privacy

8. GOOGLE ANALYTICS

This website uses Google Analytics, a web analytics service provided by Google Ireland Limited.

Google Analytics enables the collection of statistical information regarding the use of the website in order to improve the user experience and optimize the services offered.

The information collected may include:

  • Anonymized IP address where applicable.
  • Approximate location.
  • Device type.
  • Operating system.
  • Browser used.
  • Pages visited.
  • Time spent on the website.
  • Interactions carried out on the website.

Google Analytics will only be activated after the user’s explicit acceptance through the corresponding cookie management system.

You may consult Google’s Privacy Policy at:

https://policies.google.com/privacy

9. INTERNATIONAL DATA TRANSFERS

Some providers used by the Controller may process information outside the European Economic Area (EEA).

In particular:

  • Google Analytics.
  • Stripe.
  • Other auxiliary technological services that may be used in the future.

Where international data transfers occur, they will be carried out with the safeguards required by the GDPR, including:

  • Adequacy decisions approved by the European Commission.
  • Standard Contractual Clauses (SCCs).
  • Protection mechanisms recognized by applicable regulations.

10. DATA SUBJECT RIGHTS

Users may exercise the following rights at any time:

  • Right of access.
  • Right to rectification.
  • Right to erasure.
  • Right to object.
  • Right to restriction of processing.
  • Right to data portability.
  • Right to withdraw consent.
  • Right not to be subject to automated decision-making.

To exercise any of these rights, you may contact:

Email: dpo@cdafitness.es
Postal Address:  Av. De Los Covachos, 2, 30870 Mazarrón, Murcia

The request must be accompanied by documentation that allows verification of the applicant’s identity when necessary.

11. COMPLAINTS BEFORE THE SPANISH DATA PROTECTION AGENCY (AEPD)

If you believe that your rights have not been properly addressed, you may file a complaint with the competent supervisory authority:

Spanish Data Protection Agency (AEPD)

https://www.aepd.es

12. COMMERCIAL COMMUNICATIONS

Commercial communications sent by electronic means will only be carried out when:

  • The user has provided explicit consent.
  • There is a prior contractual relationship that permits it in accordance with Article 21 of the Spanish Information Society Services and Electronic Commerce Act (LSSI-CE).

The user may withdraw consent or unsubscribe at any time through the mechanisms provided in each communication or by contacting the Controller.

13. SECURITY MEASURES

The Controller applies appropriate technical and organizational measures to ensure the confidentiality, integrity, and availability of personal data, preventing its alteration, loss, unauthorized processing, or unauthorized access.

However, users should be aware that Internet security measures are not completely infallible.

14. MINORS

The services offered through this website are not directed at children under the age of 14.

If a minor provides personal data without the authorization of their parents or legal representatives, the Controller reserves the right to delete such data as soon as it becomes aware of this circumstance.

15. SOCIAL MEDIA

The gym may maintain corporate profiles on social networks such as Instagram, Facebook, TikTok, LinkedIn, or similar platforms.

Users’ interactions with these profiles shall be subject to these conditions and to the specific privacy policies of each platform.

16. COOKIES

This website uses both first-party and third-party cookies to improve the user experience and obtain browsing statistics.

All information regarding the use of cookies is available in the corresponding Cookie Policy.

17. CHANGES TO THE PRIVACY POLICY

The Controller reserves the right to modify this Privacy Policy in order to adapt it to legal, judicial, or technical developments.

Any modifications will be published on this same page, indicating the date of the latest update.

18. CONTACT

For any inquiries related to the protection of personal data, you may contact:

CDA FITNESS GYM
Address: Av. De Los Covachos, 2, 30870 Mazarrón, Murcia
Email: cdafitness@hotmail.co.uk
Telephone: +34 634 30 40 87
Website: https://cdaftiness.es

19. GOVERNING LAW AND JURISDICTION

This Privacy Policy shall be governed by and construed in accordance with the laws of Spain.

Any dispute arising from the interpretation, application, validity, or enforcement of this Privacy Policy shall be subject to the courts and tribunals competent under applicable Spanish legislation.

Nothing in this clause shall limit or affect any rights granted to consumers under mandatory consumer protection laws. In particular, consumers shall retain any jurisdictional rights recognized by applicable consumer protection regulations.

Translate
Scroll to Top