How we collect, use and protect your personal information
1. Who We Are
Best Fit Dynamics Ltd ("Best Fit", "we", "us") operates the Best Fit platform - a behavioural insight tool that helps gyms and fitness organisations understand how to communicate with and support their members and teams more effectively.
We are registered in England and Wales, company number 16799190. Our registered office is 39 Newnham Street, Ely, Cambridgeshire, CB7 4PQ. You can reach us at privacy@bestfitdynamics.com.
2. Who This Policy Is For
This policy applies to:
- gym members and individual users who complete a Best Fit assessment or create an account through a participating gym;
- gym staff and coaches who use the platform to view team or member insights;
- visitors to our website at bestfitdynamics.com; and
- anyone who contacts us directly via email, support channels or social media.
If you are a gym operator or business interested in subscribing to Best Fit, your relationship with us is also governed by our Business Terms, which set out our data protection obligations to you as a business customer.
3. How Best Fit Works - and Why That Matters for Your Data
When you complete a Best Fit questionnaire, the platform analyses your answers and places you into one of eight behavioural profiles. That profile, along with practical engagement insights, is then available to you and - depending on how your gym has configured things - to authorised gym staff.
This is called profiling. Under UK data protection law (the UK GDPR), we are required to tell you clearly that this happens, explain the logic, and make sure it is used fairly. The important things to know are:
- your profile is based entirely on your own answers, not on any external data about you;
- it is not a medical or psychological diagnosis - it is an engagement and communication tool;
- no significant decision about you (such as refusing your membership) should ever be made solely on the basis of your profile; and
- you can ask to see your profile, have it corrected, or have your data deleted - see section 10.
4. What Data We Collect
| Type of data | What this includes | Where it comes from |
|---|---|---|
| Account information | Your name, email address, gym membership, account role | You or your gym when the account is created |
| Assessment responses | Your answers to the Best Fit questionnaire | You, when you complete the assessment |
| Your profile and insights | The behavioural archetype and engagement insights generated from your answers | Generated automatically by the platform from your responses |
| Technical data | IP address, browser and device type, session information | Collected automatically when you use the platform |
| Support data | Messages and information you send us when asking for help | You, when you contact support |
| Website interaction data | Pages visited, time on site, referral source (via cookies) | Collected automatically - see our Cookie Policy |
5. Why We Use Your Data and Our Legal Basis for Doing So
Under UK data protection law, we must have a legal reason ("lawful basis") for using your personal data. Here is what we use your data for and why we are allowed to.
| What we use your data for | Legal basis | More detail |
|---|---|---|
| Creating your account and letting you log in | Contract - necessary to provide the service | Without this we cannot give you access. |
| Running the assessment and generating your profile | Contract, or consent depending on your gym's setup | This is the core function of the service. |
| Sharing your profile with your gym's authorised staff | Legitimate interests of the gym and of Best Fit in delivering the contracted service | Your gym's privacy notice should also explain this. Sharing is limited to trained, authorised staff. |
| Answering support requests and resolving issues | Contract and legitimate interests | We keep support records to help resolve problems and to improve the service. |
| Keeping the platform secure | Legitimate interests | We use technical data to detect attacks, prevent fraud and protect all users. |
| Improving the product using anonymised data | Legitimate interests | We use aggregated, anonymised data - never identifiable profiles - to improve Best Fit and to produce industry insights. |
| Complying with legal obligations | Legal obligation | For example, financial records we are required to keep by law. |
6. Your Gym's Role and Our Role
When you use Best Fit through a gym, both your gym and Best Fit Dynamics have responsibilities for your data. Understanding this split helps you know who to contact if you have a question.
| Activity | Your gym's responsibility | Best Fit's responsibility |
|---|---|---|
| Deciding to use Best Fit and telling you about it | Your gym decides to subscribe and must inform you through their own privacy notice | We provide the tools and make the notices available |
| Storing and generating your profile from your answers | Your gym is the "data controller" - it decides the purpose | We are the "data processor" - we handle the data on the gym's instructions |
| Platform security, account management and support | Not responsible for our systems | We are solely responsible for platform security and our own systems |
| Decisions made using your profile (e.g. how you're communicated with) | Your gym decides how to use the insights - they are responsible for those decisions | We provide the tool only; we do not make decisions about you |
In short: if you have a question about how your gym is using your profile, contact your gym. If you have a question about your data on the Best Fit platform itself, contact us at privacy@bestfitdynamics.com.
7. Sharing Your Data With Others
We do not sell your personal data. We share it only in the following circumstances.
- With your gym and its authorised, trained staff - as described above.
- With our technology suppliers (hosting, email, support tools) who process data on our behalf under strict contractual data protection obligations. A list of our principal suppliers is available on request.
- With professional advisers (lawyers, accountants, insurers) where strictly necessary.
- With regulators or law enforcement where required by law or court order.
We will never share your individual, identified profile with any third party for advertising, marketing or commercial purposes without your explicit consent.
8. International Data Transfers
Some of our technology suppliers operate servers outside the United Kingdom. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place - typically the UK International Data Transfer Addendum or equivalent approved mechanisms - so that your data receives the same standard of protection as it does in the UK.
9. How Long We Keep Your Data
| Type of data | How long we keep it |
|---|---|
| Your account and profile | While your account is active, plus up to 12 months after it closes |
| Assessment responses and insights | Up to 24 months from your last use of the platform, unless your gym requests earlier deletion |
| Security and technical logs | Between 90 days and 12 months depending on the type |
| Support records | Up to 24 months from resolution |
| Financial and legal records | As required by law - typically 6 years |
10. Your Rights
Under UK data protection law, you have the following rights. You can exercise any of them by emailing privacy@bestfitdynamics.com. We will respond within one month.
| Your right | What it means in practice |
|---|---|
| Access | Ask for a copy of all the personal data we hold about you |
| Correction | Ask us to correct anything that is wrong or incomplete |
| Deletion | Ask us to delete your data (subject to any legal obligations we have to retain it) |
| Restriction | Ask us to pause using your data while a dispute is resolved |
| Objection | Object to certain uses of your data, particularly where we rely on legitimate interests |
| Portability | Receive your data in a common electronic format in certain circumstances |
| Withdraw consent | Where we asked for your consent, you can withdraw it at any time - this will not affect anything we did before you withdrew it |
| Human review | If you think a significant decision was made about you based solely on your automated profile, you can ask for a human to review it |
11. Cookies
We use cookies and similar technologies on our website and platform. Strictly necessary cookies (for login and security) are always active. For analytics cookies we ask for your consent through our cookie banner. You can manage your preferences at any time through the cookie settings on the site.
Our full Cookie Policy, including a list of all cookies in use, is available in the Cookie Policy on this site.
12. Research and Anonymised Insights
We may use anonymised, aggregated data - meaning data that cannot be linked back to any individual person - to improve the Best Fit platform, to conduct research about engagement and behaviour in the fitness industry, and to publish statistics and insights. This will never include your name, your profile, or anything that could identify you as an individual.
Where we use a case study or testimonial that identifies a specific person or gym, we will always obtain explicit written consent first.
13. Future Uses of the Platform
Best Fit is designed to be used across a range of contexts - not just gym membership, but also staff development, coaching team alignment, corporate wellness programmes and other fitness-related settings. Wherever it is used, the same principles apply: your profile is an engagement tool only, it must not be used as the sole basis for important decisions about you, and you always have the rights described in section 10.
If we introduce a new use of your data that is not described in this policy, we will update it and, where required by law, ask for your consent.
14. Complaints
If you are unhappy about how we have handled your data, please email us first at privacy@bestfitdynamics.com and we will do our best to resolve it quickly.
You also have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk or 0303 123 1113. We would always prefer to hear from you directly first, but you are not obliged to contact us before going to the ICO.
15. Changes to This Policy
We will update this policy if the law changes or if we change how we use your data. If changes are material, we will let you know via the platform or by email. The current version date is shown on the cover of this document.