Last updated: September 23, 2026
1. IDENTITY OF THE DATA CONTROLLER
In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), and any other applicable data protection legislation, users are informed that the personal data collected through this website shall be processed by:
Data Controller: Ian David Field
Tax ID (NIF): X9294106J
Address: Av. De Los Covachos, 2, 30870 Mazarrón, Murcia, Spain
Email: cdafitness@hotmail.co.uk
Telephone: +34 634 30 40 87
Website: https://cdafitness.es
Hereinafter referred to as the “Controller”.
2. PURPOSE OF THE PROCESSING
The personal data provided by users may be processed for the following purposes:
a) Handling Inquiries
Managing requests for information, questions, claims, communications, suggestions, incidents, and any contact made through forms, email, telephone, WhatsApp, social media platforms, or any communication channel made available by the Controller.
b) Customer and Membership Management
Managing registrations, memberships, class bookings, appointment scheduling, sports activities, personal training services, access management, account administration, and any services contracted by users.
c) Administrative, Tax, Accounting and Legal Management
Managing invoicing, accounting operations, tax obligations, payment processing, debt recovery, contract administration, legal compliance requirements, and any activities arising from the contractual relationship.
d) Commercial Communications
Sending information regarding events, promotions, sporting activities, services, offers, newsletters, updates, and commercial communications related to CDA Fitness services whenever the user has granted consent or where permitted under applicable legislation.
e) Security and Fraud Prevention
Protecting the security of facilities, information systems, users, employees, suppliers, and assets; investigating incidents; preventing unauthorized access; and detecting fraudulent, abusive, or unlawful activities.
f) Statistical Analysis and Service Improvement
Analyzing website usage, customer interactions, operational performance, and service quality in order to improve user experience and optimize business operations.
g) Customer Support Through WhatsApp and Internal WhatsApp Bot
The Controller provides customer support through WhatsApp, including an internal automated communication system (“WhatsApp Bot”).
The WhatsApp Bot is a proprietary tool developed, configured, and administered directly by the Controller and is used solely for customer service, operational management, and information assistance purposes.
The WhatsApp Bot does not operate as an independent decision-making system and is not managed by external customer service providers, marketing agencies, profiling companies, artificial intelligence providers acting on their own behalf, or data brokerage entities.
The WhatsApp Bot may be used for:
- Responding to questions and information requests.
- Scheduling appointments and class bookings.
- Managing memberships and subscriptions.
- Handling support requests and incidents.
- Sending information requested by users.
- Facilitating communication between users and authorized personnel.
- Improving operational efficiency.
Data processed through WhatsApp may include:
- Name and surname.
- Telephone number associated with the WhatsApp account.
- Information voluntarily provided in conversations.
- Membership-related information.
- Booking and appointment information.
- Customer support records.
The Controller does not carry out automated decision-making processes producing legal effects or similarly significant effects on users through the WhatsApp Bot.
Communications may be reviewed by authorized personnel where necessary for customer service management, quality control, fraud prevention, legal compliance, dispute management, system administration, or security purposes.
3. CATEGORIES OF DATA PROCESSED
The following categories of personal data may be processed:
- Name and surname.
- Identification document details where required.
- Postal address.
- Email address.
- Telephone number.
- WhatsApp telephone number.
- Website access and browsing information.
- Membership information.
- Billing information.
- Payment information.
- Banking details where required.
- Communications exchanged with the Controller.
- Customer support records.
- Messages exchanged through WhatsApp.
- Information voluntarily provided by users.
- Images captured by CCTV systems.
- Information relating to contracted services.
- Any other data necessary for the provision of services.
Users guarantee that all information provided is accurate, truthful, complete, and up to date.
4. LEGAL BASIS FOR PROCESSING
The processing of personal data is based on one or more of the following legal grounds:
Consent of the Data Subject
Where users voluntarily submit information, complete forms, subscribe to communications, or expressly consent to a specific processing activity.
Performance of a Contract
Where processing is necessary for the provision of services, management of memberships, execution of bookings, or implementation of pre-contractual measures requested by the user.
Compliance with Legal Obligations
Where processing is necessary to comply with obligations arising from tax, accounting, consumer protection, employment, security, administrative, or other applicable legislation.
Legitimate Interests
To ensure security, protect facilities, prevent fraud, improve services, manage customer relationships, protect assets, and administer internal business operations.
5. DATA RETENTION PERIOD
Personal data shall be retained:
- For as long as necessary to fulfill the purposes for which it was collected.
- For the duration of any contractual relationship.
- Until consent is withdrawn where processing is based on consent.
- For the periods required under applicable legislation.
- For the time necessary to address potential liabilities arising from the processing.
After expiration of the applicable retention periods, data shall be securely deleted or blocked where legally required.
6. DATA RECIPIENTS
Personal data will not generally be disclosed to third parties except where legally required or necessary for the provision of services.
Data may be accessed by:
Financial Institutions
For the processing of payments, refunds, direct debits, transfers, and other financial transactions.
Professional Advisors
Lawyers, accountants, auditors, tax consultants, compliance consultants, labor advisors, and similar professional service providers.
Technology Service Providers
Providers offering web hosting, cloud storage, communication systems, software platforms, cybersecurity services, IT support, analytics services, email services, maintenance services, and related technological infrastructure.
Such providers are contractually bound to comply with confidentiality obligations and applicable data protection legislation.
6.1 WHATSAPP COMMUNICATION SERVICES
Users communicating through WhatsApp acknowledge that communications may involve services provided by WhatsApp Ireland Limited and entities belonging to the Meta group.
The Controller operates an internally managed communication environment and WhatsApp Bot solely for customer service and operational management.
Personal data obtained through WhatsApp:
- Is not sold.
- Is not rented.
- Is not commercially exploited.
- Is not transferred for advertising purposes by the Controller.
- Is not used for behavioral profiling by the Controller.
Users should be aware that WhatsApp and Meta may independently process personal data under their own privacy policies.
Further information is available at:
7. PAYMENTS THROUGH STRIPE
Payments may be processed through Stripe Payments Europe, Ltd.
In order to process transactions, certain information may be communicated directly to Stripe, including:
- Name and surname.
- Email address.
- Billing information.
- Transaction details.
- Payment verification data.
- Security and anti-fraud information.
Stripe acts as an independent data controller regarding payment processing activities.
Privacy Policy:
8. GOOGLE ANALYTICS
This website may use Google Analytics, a web analytics service provided by Google Ireland Limited.
Google Analytics collects statistical information regarding website usage, including:
- Anonymized IP address where applicable.
- Approximate geographic location.
- Browser information.
- Operating system.
- Device information.
- Pages visited.
- Time spent on pages.
- Navigation paths.
- User interactions.
Google Analytics will only operate following the user’s consent where required by applicable legislation.
Privacy Policy:
9. INTERNATIONAL DATA TRANSFERS
Certain service providers used by the Controller may process information outside the European Economic Area (EEA).
Such providers may include:
- Stripe.
- Google.
- Meta / WhatsApp.
- Other technology providers where applicable.
Where international transfers occur, appropriate safeguards shall be implemented in accordance with GDPR requirements, including:
- Adequacy decisions.
- Standard Contractual Clauses (SCCs).
- Other approved transfer mechanisms.
10. DATA SUBJECT RIGHTS
Users may exercise the following rights:
- Right of access.
- Right to rectification.
- Right to erasure.
- Right to restriction of processing.
- Right to object.
- Right to data portability.
- Right to withdraw consent.
- Right not to be subject to automated decision-making.
Requests may be submitted via:
Email: dpo@cdafitness.es
Postal Address:
Av. De Los Covachos, 2
30870 Mazarrón, Murcia
Where requests relate to CCTV footage, users may be required to provide sufficient information to identify the relevant recording while protecting the rights and freedoms of third parties.
11. COMPLAINTS BEFORE THE SPANISH DATA PROTECTION AGENCY
If users believe their rights have not been properly addressed, they may lodge a complaint with:
Spanish Data Protection Agency (AEPD)
12. COMMERCIAL COMMUNICATIONS
Electronic commercial communications shall only be sent where:
- The user has granted valid consent.
- A prior contractual relationship exists and applicable legislation permits such communications.
Users may unsubscribe or withdraw consent at any time.
13. SECURITY MEASURES
The Controller implements appropriate technical and organizational security measures designed to ensure:
- Confidentiality.
- Integrity.
- Availability.
- Resilience of systems.
- Protection against unauthorized access.
- Protection against accidental or unlawful destruction, alteration, or loss.
Despite such measures, absolute security of Internet communications cannot be guaranteed.
14. MINORS
The services offered through this website are not directed to children under 14 years of age.
Where the Controller becomes aware that personal data belonging to a minor has been provided without appropriate authorization, appropriate measures shall be taken, including deletion where applicable.
15. VIDEO SURVEILLANCE
15.1 Video Surveillance Systems
For security, access control, protection of persons and property, loss prevention, incident investigation, and safeguarding of facilities, CDA Fitness operates CCTV systems within its premises.
The legal basis for such processing is the legitimate interest of the Controller pursuant to Article 6(1)(f) GDPR.
Purposes include:
- Protection of members and visitors.
- Protection of employees and suppliers.
- Prevention of theft and vandalism.
- Investigation of security incidents.
- Protection of facilities and assets.
- Defense of legal claims.
Recordings may be disclosed to:
- Law enforcement authorities.
- Courts and tribunals.
- Insurance providers.
- Legal representatives.
- Competent public authorities.
Recordings shall be retained only for legally permitted periods unless preservation is required for ongoing investigations or legal proceedings.
Appropriate technical and organizational security measures have been implemented to protect recorded images.
15.2 Separate Video Surveillance Privacy Notice
Additional information regarding CCTV processing activities is available through the specific Video Surveillance Privacy Notice displayed at the facilities and available upon request.
This notice forms part of the Controller’s overall data protection framework and complements the information contained herein.
16. COOKIES
This website uses first-party and third-party cookies to improve functionality, user experience, security, and statistical analysis.
Detailed information is provided in the Cookie Policy.
17. CHANGES TO THIS PRIVACY POLICY
The Controller reserves the right to modify this Privacy Policy to reflect legal, regulatory, judicial, technological, or operational developments.
Any modifications will be published on this page together with the updated revision date.
18. CONTACT
For any questions regarding data protection or this Privacy Policy, users may contact:
CDA FITNESS GYM
Ian David Field
Av. De Los Covachos, 2
30870 Mazarrón, Murcia
Email: cdafitness@hotmail.co.uk
Telephone: +34 634 30 40 87
Website: https://cdafitness.es
For matters specifically relating to the CCTV system, users may request the Video Surveillance Privacy Notice through the above contact channels.
19. GOVERNING LAW AND JURISDICTION
This Privacy Policy shall be governed by and construed in accordance with the laws of Spain.
Any dispute relating to the interpretation, validity, enforcement, or application of this Privacy Policy shall be submitted to the competent courts and tribunals in accordance with Spanish legislation.
Nothing contained in this clause shall limit any mandatory rights afforded to consumers under applicable consumer protection regulations.
