Privacy Policy

What Elite Pilates Club holds about you, why we hold it, who else touches it, how long we keep it and what you can make us do with it. Written to comply with the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission.

Last updated

Who controls your information

Elite Pilates Club is the Personal Information Controller for everything described here: we decide what is collected and what is done with it. The registered business behind the trading name, its registration number and its registered office are set out on the legal index.

Trading as
Elite Pilates Club
Registered name
To be confirmed
Registration no.
To be confirmed
Registered office
To be confirmed
Email
contact@theelitepilatesclub.com

Your Data Protection Officer

We have designated a Data Protection Officer, as the Data Privacy Act requires. They are accountable for how this policy is applied, and they are the person to write to about anything on this page — a question, a request to see your record, a correction, an objection or a complaint.

Data Protection Officer
To be confirmed
Email
contact@theelitepilatesclub.com
Subject line
Data privacy request
In person
Ask at reception at either studio and they will route it

We answer within fifteen working days, and sooner where we can.

What we collect

Grouped by what it is actually for.

Your account

  • Name, email address and mobile number.
  • Date of birth — we need it to know whether a parent or guardian has to sign.
  • Your home studio, and your profile photograph if you upload one.
  • The name and number of an emergency contact. That is somebody else’s personal information: please make sure they know you have given it to us.
  • For members under 18, the name and number of the parent or guardian who consented.
  • Your password is handled by our authentication provider and stored only as a cryptographic hash. Nobody at the studio can see it, and we cannot recover it for you — we can only send you a reset link.

What you do with us

  • Classes booked, waitlists joined, attendance, late cancellations and no-shows, at which studio and with which coach level.
  • Credits bought and spent, their expiry dates, packages, memberships, billing cycles and any freeze.
  • Points earned and redeemed, and your referral code and its uses, where those programmes are running.
  • Your video-library viewing progress, where the library is available to you.

Payments

  • Amounts, currency, the method you chose, whether it settled, the gateway’s reference, the numbered receipt we issued, and any refund.
  • Never your card number.Card details are entered on the payment gateway’s own page and never reach our systems.

What you have told us you want

  • Whether you want studio news and offers by email.
  • Whether you are in or out of the points programme.
  • Whether you consent to photography and video in the studio, and when you gave or withdrew that consent.
  • The date you accepted the waiver, and which version of it.

Messages we send you

  • The transactional emails we have queued and sent to you — booking confirmations, reminders, receipts, renewal and credit-expiry notices — with their subject and content, so both of us can see what was actually sent.

Device and usage information

  • Aggregate, cookieless measurement of which pages are visited and how quickly they load (see Cookie Policy). This is not tied to your account.
  • Ordinary server and security logs kept by our hosting and database providers, which include IP addresses and request metadata.

Sensitive personal information

Some of what we hold is sensitive personal information as the Data Privacy Act defines it, and it is treated with the extra care the law demands. We are calling it out separately rather than burying it in the list above, because that is the whole point of the category.

  • Health and medical information from the Liability Waiver & Consent Form. The form asks five questions and you answer them yourself: injuries or medical conditions that may affect your participation; scoliosis or any other spinal condition; whether you are undergoing therapy such as physiotherapy or chiropractic care; whether you are pregnant, and how many months along; and whether you have recently given birth, and how long ago. Where you answer yes, you tell us more in your own words.
  • Anything else you want your coach to know, in the free-text medical notes on your profile.
  • Whether a doctor’s consent is on file for you, and when it was recorded. We record that it exists; we do not need to keep the letter itself.
  • Your date of birth, because age is itself sensitive personal information under the Act.

Health answers are visible to teaching and reception staff who need them to keep you safe in the room, and to nobody else. They are not used for marketing, are never sold, and are not shared with anyone outside the studio except our infrastructure providers, who hold the database the answers sit in and do not read it.

How we collect it

  • From you. When you create an account, complete onboarding, sign the waiver, book, buy, update your profile, or write to us.
  • From staff, on your behalf.When reception books you in, takes a payment at the desk, marks you present or absent, or records that your doctor’s consent has arrived.
  • Automatically, from your use of the site. The strictly necessary cookies that keep you signed in, and — only if you accept analytics — cookieless page and performance measurement.
  • From our payment gateway. The result of a payment you made, and its reference.

What we use it for

  • To give you an account, and to run it: bookings, waitlists, credits, memberships and receipts.
  • To teach you safely — which is what the health answers are for, and nothing else.
  • To take payment, issue numbered receipts and process refunds.
  • To send you the emails the service itself requires: confirmations, reminders, receipts, renewal and expiry notices. These are not marketing and you cannot opt out of them while you hold an account.
  • To run the points and referral programmes, where they are switched on.
  • To send you studio news and offers — only if you have asked for them.
  • To keep the books the Bureau of Internal Revenue requires us to keep.
  • To keep the site and the accounts on it secure, and to investigate misuse.
  • To understand, in aggregate, which pages are used and how fast the site is, so we can make it better.
  • To establish, exercise or defend a legal claim, if one is ever made.

The lawful criteria we rely on

Processing personal information needs a criterion under section 12 of the Act. Processing sensitive personal information needs one of the narrower criteria in section 13. Here is which applies to what.

Ordinary personal information — section 12

  • Necessary for a contract with you (§12(b)) — your account, bookings, credits, memberships, payments, receipts and the transactional email that goes with them.
  • Necessary for compliance with a legal obligation (§12(c)) — financial records and receipts kept for tax and accounting.
  • Legitimate interests (§12(f)) — security, fraud and abuse prevention, and aggregate measurement of how the site performs. We rely on this only where your rights do not override it, which is why the analytics are cookieless and never tied to your account.
  • Consent (§12(a)) — marketing email, analytics measurement, and photography or video of you in the studio.

Sensitive personal information — section 13

  • Your consent, given before the processing (§13(a)).This is the criterion the waiver answers rely on. You give it when you complete the Liability Waiver & Consent Form, having been told what the answers are for. It is specific, it is freely given, and — as the next section says — you can take it back.
  • Protection of your life and health (§13(b)) — where a condition you have declared matters to what happens in the room, and you are not in a position to consent at that moment.
  • Establishment, exercise or defence of legal claims (§13(f)) — the sole reason we keep the waiver and its answers on file after you stop training with us.

Where we rely on consent you can withdraw it, and withdrawing it is as easy as giving it was. Withdrawal is not retrospective: it stops future processing and does not undo what was lawfully done before.

  • Health answers.Tell the Data Protection Officer you are withdrawing consent and we will stop processing them. Be aware of the consequence: without current health answers, and without a doctor’s consent where the studio requires one, we may not be able to let you take a class. That is a safety rule, not a penalty.
  • Marketing email. Turn it off under My account → Profile, or use the unsubscribe link on any marketing email. Booking and payment emails carry on — they are part of the service, not marketing.
  • Photography and video. Withdraw it under My account → Profile at any time.
  • Points programme. Leave it from your account. Points already earned stay on the account.
  • Analytics. Change your choice from Cookie settings in the site footer — see the Cookie Policy.

Who else processes it

We do not sell your personal information and we do not share it for anyone else’s marketing. It is disclosed only to the service providers below, who process it on our written instructions and for no purpose of their own, and to the people listed at the end.

WhoWhat they doWhat they get
SupabaseThe database, sign-in and file storage behind the siteEverything in your account, including the waiver answers, and your profile photograph
VercelHosting and content delivery, plus cookieless page and performance measurementRequest and security logs including IP address; aggregate page and performance data not tied to your account
XenditTaking online payments and issuing refunds, on its own hosted checkout pageYour name, email, the amount and what you are buying — and the card or wallet details you type on its page, which never reach us
ResendDelivering our transactional emailYour email address and the content of the message we send you
Google FontsServing a web font — only where the studio has chosen a Google font for the site; otherwise no request is made at allYour IP address and browser, as part of the font request your browser makes

We may also disclose personal information:

  • to our professional advisers — accountants, auditors and lawyers — under a duty of confidence;
  • where a court, a regulator or the law requires it, including a lawful order of the National Privacy Commission or the Bureau of Internal Revenue;
  • to emergency services or a medical professional, if you are hurt in the studio and it is needed to help you;
  • to a buyer, if the business is ever sold or reorganised — with the same protections carried across, and notice to you.

Processing outside the Philippines

Some of the providers above run their infrastructure outside the Philippines, so your information is processed abroad. Under section 21 of the Act, transferring it does not transfer our responsibility for it: we remain accountable for information we hand to a third party, including one overseas.

Before any of it leaves, we require:

  • a written data processing agreement limiting the provider to our instructions;
  • a commitment to a standard of protection comparable to the Act’s;
  • encryption in transit, and at rest where the provider offers it;
  • an obligation to tell us promptly about any security incident affecting our data.

How long we keep it

We keep personal information only as long as the purpose it was collected for lasts, plus any period the law requires. In practice:

  • Your account, bookings and credit history — while your account is open, and for two years after your last activity, so a member who comes back finds their history where they left it.
  • Payment records, receipts and refunds — ten years, because these are accounting records and the Bureau of Internal Revenue requires books of account and their supporting documents to be preserved for that long. This is the one category we cannot delete on request.
  • The waiver, the health answers and the doctor’s-consent record — for as long as you train with us, and for five years after your last session. That is the window in which a claim arising out of a session could still be brought, and the waiver is the document that answers it. After that they are destroyed.
  • Marketing and consent preferences — until you change them, and then a record of the change, so we can show we honoured it.
  • Transactional email we sent you — while your account is open.
  • Server and security logs — for the short retention windows our hosting and database providers operate.
  • Aggregate analytics — indefinitely, because by then it identifies nobody.

How we protect it

Section 20 of the Act requires organisational, physical and technical measures proportionate to the risk. Ours include:

  • Row-level security in the database. Your session can only read your own rows — the rule is enforced by the database itself, not by the application asking nicely.
  • Encryption in transit across the whole site, and at rest at our database and storage provider.
  • Passwords we never see. They are hashed by the authentication provider; there is nothing in our systems to steal.
  • Card details we never receive.They are typed on the payment gateway’s page, not ours.
  • Private files served through short-lived signed links rather than public URLs, so a profile photograph is not sitting on an address anyone can guess.
  • Staff access limited to what the job needs, with health answers visible only to teaching and reception staff, and administrative keys held server-side only.
  • Two-step confirmation before anything is destroyed, with the request and its outcome written to an audit trail.

No system is perfect. If a breach ever puts you at real risk of serious harm, we will notify you and the National Privacy Commission within the period the Act and the NPC’s issuances require.

Your rights under RA 10173

The Data Privacy Act gives you the following rights over your information. They are yours whether or not you are a member, and exercising them is free.

  1. To be informed — that your information is being processed, and of what, why, by whom and for how long. This page is how we do it.
  2. To object — to processing, including direct marketing and any automated processing. Where we rely on your consent, objecting withdraws it.
  3. To access — to be given a copy of what we hold about you, the purposes, the recipients, and how it was obtained.
  4. To rectification — to have anything inaccurate or incomplete corrected, and to have the correction passed to anyone we shared it with.
  5. To erasure or blocking — to have your information suspended, withdrawn, blocked, removed or destroyed where it is incomplete, outdated, false, unlawfully obtained, or no longer needed for the purpose it was collected for.
  6. To damages — to be indemnified for damage sustained through inaccurate, incomplete, outdated, false or unlawfully obtained use of your information.
  7. To data portability — to obtain a copy of the information you gave us in an electronic, structured, commonly used format, and to move it elsewhere.
  8. To lodge a complaint — with us first, and with the National Privacy Commission if we do not put it right.

Your lawful heirs and assigns may exercise the rights of access and correction after your death or incapacity, as the Act provides.

How to exercise them

Some of these you can do yourself, right now. The rest go to the Data Protection Officer.

  • Access and portability. Signed in, open /api/member/exportand your browser downloads a structured JSON file of your whole record — profile, bookings, credits, memberships, payments and receipts, points, referrals, consents, health answers and the emails we sent you. It is generated live and is nobody else’s but yours.
  • Rectification. Correct your own details, health answers and emergency contact under My account → Profile. For anything you cannot edit — a booking record, a receipt — write to the Data Protection Officer and we will correct it or tell you why we cannot.
  • Objection and withdrawal of consent. Marketing email, photography consent and the points programme are switches in your account; analytics is Cookie settings in the footer. See the section on consent above.
  • Erasure or blocking. Write to the Data Protection Officer. Erasure here means your record is anonymised: your name, email, phone, date of birth, health answers, emergency contact and profile photograph are destroyed, and the financial rows we are legally required to keep survive with nothing in them that identifies you. We confirm before anything is destroyed, and the request and its outcome are logged. It cannot be undone.
  • To be informed, and to damages. Write to the Data Protection Officer.

We may ask you to confirm your identity before acting — usually by asking you to make the request from the email address on your account. That is a protection for you, not an obstacle.

Automated decisions and profiling

We do not make any decision about you by automated means alone, and we do not profile you. Nothing here scores you, ranks you or decides anything about your membership without a person involved.

Two things that might look like it, described plainly. If you answer yes to a health question, your account shows a note recommending a private session rather than a group class — that is a fixed rule applied to your own answer, it is a recommendation, and it never blocks a booking. And when a class you book could be paid for by more than one credit, we automatically spend the one closest to expiring, so the least possible value is lost. Neither has any legal or similarly significant effect on you.

Children and young people

The site and the account are meant for people aged 18 and over. Under-18s can train with us with a parent or guardian’s consent; the guardian is named on the account, accepts the terms and the waiver, and can exercise every right on this page on the young person’s behalf.

We do not knowingly collect information from a child without that consent, and we do not send marketing to anyone we know to be under 18. If you believe we hold a child’s information without proper consent, tell the Data Protection Officer and we will destroy it.

Cookies and this website

Cookies and browser storage have their own document, because they deserve a real list rather than a paragraph. It names every cookie and storage key this site sets, what each is for and how long it lasts, and it explains how to change your analytics choice.

Read the Cookie Policy. The short version: the only things that cannot be switched off are what keeps you signed in and what remembers your cookie choice, and the site sets no advertising or cross-site tracking cookies at all.

Changes to this policy

We update this policy when what we do changes, or when the law or an NPC issuance requires it. The current version is always at this address, with the date it took effect at the top of the page.

For a change that materially affects how we use your information, we will tell you by email to the address on your account or by a notice on the site before it takes effect — and where the change needs your consent, we will ask for it rather than assume it.

Complaints and the NPC

Tell us first. Write to the Data Protection Officer at contact@theelitepilatesclub.com and we will investigate and reply. Most complaints are a record somebody cannot see or a preference that did not save, and both are quicker to fix than to escalate.

If you are not satisfied with how we handled it, you have the right to complain to the National Privacy Commission, which regulates us.

Regulator
National Privacy Commission
Address
5th Floor, Delegation Building, PICC Complex, Vicente Sotto Street, Pasay City, Metro Manila 1307
Email
info@privacy.gov.ph · complaints@privacy.gov.ph
Website
privacy.gov.ph