Chalet Coaching

PRIVACY POLICY

Last updated: 14 July 2026

1. Introduction

This Privacy Policy explains how CHALET AQUARIUS LTD collects, uses, stores, shares, and protects personal data when you access or use the Chalet Coaching website, create an Account, purchase Tokens, generate an AI Plan, request a Trainer-Created Course, communicate with us, or otherwise use our services.

The data controller responsible for the processing described in this Privacy Policy is:

CHALET AQUARIUS LTD

Company number: 15587263

Registered office: 20 Wenlock Road, London, England, N1 7GU

Email: info@chaletcoaching.co.uk

Phone: +44 7782 358363

In this Privacy Policy, “Chalet Coaching”, “Company”, “we”, “us”, and “our” refer to CHALET AQUARIUS LTD.

We process personal data in accordance with applicable data protection laws, including the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

Where the EU General Data Protection Regulation (“EU GDPR”) applies to particular processing activities, we will also process personal data in accordance with its applicable requirements.

The Service is intended for persons aged 18 and over.

2. Scope of This Privacy Policy

This Privacy Policy applies to personal data processed in connection with:

your Chalet Coaching Account;

the Chalet Coaching website and Dashboard;

AI-generated fitness Plans and Courses;

Trainer-Created Courses;

Token purchases and payment transactions;

customer support and other communications;

cookies and similar technologies;

technical operation, security, and improvement of the Service; and

other services expressly provided through Chalet Coaching.

This Privacy Policy does not govern independent third-party websites or services that operate under their own privacy policies.

3. Personal Data We Collect

The personal data we collect depends on how you use the Service.

3.1 Account and Identity Data

We may collect:

name;

email address;

telephone number;

Account identifiers;

username or profile information;

encrypted or securely protected authentication credentials;

preferred language;

preferred currency; and

other information associated with your Account.

3.2 Fitness, Physical, and Health-Related Data

To generate or personalise training content, we may collect information such as:

age;

gender, where requested;

height;

weight;

fitness level;

experience level;

training goals;

lifestyle information;

exercise preferences;

available equipment;

preferred training frequency;

physical limitations;

injuries;

mobility or exercise restrictions; and

other information you voluntarily provide that is relevant to the requested Course or Plan.

Some of this information may constitute data concerning health or other special category personal data under applicable data protection law.

We explain how we process this information in Section 7 below.

3.3 Trainer Request Data

Where you request a Trainer-Created Course, we may process:

the Trainer selected;

information submitted with your request;

your goals and preferences;

fitness and health-related inputs relevant to the request;

requested Course configuration;

communications or clarifications relating to the request;

request status;

delivery information; and

records relating to completion, cancellation, or support.

3.4 Transaction and Token Data

We may collect and retain transaction-related information such as:

Token purchases;

Token balances;

Tokens credited or deducted;

purchase amount;

transaction currency;

transaction date and time;

payment status;

refund status;

order and transaction references;

payment method type or card brand, where provided to us;

limited payment identifiers, such as the last four digits of a card, where supplied by the payment provider;

fraud or payment risk indicators; and

records required for accounting, tax, dispute, or compliance purposes.

Transaction Data does not mean that we store your complete payment card credentials.

3.5 Technical and Device Data

When you access or use the Service, we may automatically collect information such as:

IP address;

browser type and version;

device type;

operating system;

device or session identifiers;

approximate location derived from technical information;

language and time zone;

login and session information;

security logs;

error and diagnostic information; and

other technical information required to operate and secure the Service.

3.6 Usage Data

We may collect information about how you interact with the Service, including:

pages and features accessed;

Dashboard activity;

AI Plan generation activity;

Course requests;

downloads;

interactions with available Service features;

date and time of activity;

referral information;

support interactions; and

other information about the use and performance of the Service.

3.7 Communications and Support Data

When you contact us, we may process:

your contact details;

the content of your message;

attachments or screenshots you provide;

support history;

complaint information;

payment or delivery enquiries; and

other information necessary to respond to or resolve your request.

3.8 Cookie and Similar Technology Data

We may use cookies, local storage, session storage, and similar technologies to collect or store information relating to:

authentication;

Account sessions;

security;

language or currency preferences;

cookie preferences;

Service functionality;

support features; and

other purposes described in our Cookies Policy.

Non-essential technologies are used where the required consent has been obtained.

4. How We Collect Personal Data

We may collect personal data:

4.1 Directly From You

For example, when you:

create or update an Account;

purchase Tokens;

submit information for an AI Plan;

request a Trainer-Created Course;

communicate with a Trainer through available Service functionality;

contact customer support;

submit a complaint;

manage cookie preferences; or

otherwise provide information to us.

4.2 Automatically

Certain Technical, Usage, Cookie, and Security Data may be collected automatically when you access or interact with the Service.

4.3 From Service Providers and Other Third Parties

We may receive limited information from:

payment processors;

fraud-prevention and security providers;

hosting and infrastructure providers;

authentication providers;

communications and support providers; and

other service providers involved in operating the Service.

For example, a payment provider may inform us whether a payment was successful, declined, refunded, disputed, or subject to additional authentication.

5. How We Use Personal Data

We may process personal data to:

create and manage your Account;

authenticate Users and maintain Account security;

provide access to the Dashboard;

process Token purchases;

maintain Token balances and transaction records;

generate AI Plans;

prepare and deliver Trainer-Created Courses;

personalise fitness and training content;

communicate with you about your requests and purchases;

provide customer support;

investigate technical, delivery, payment, or Account issues;

process eligible refunds;

prevent fraud, abuse, and unauthorised activity;

maintain and improve the Service;

diagnose technical problems;

monitor security and performance;

comply with legal, tax, accounting, and regulatory obligations;

establish, exercise, or defend legal claims;

enforce our Terms and Conditions; and

send permitted Service or marketing communications.

We will not use personal data for a purpose that is incompatible with the purpose for which it was originally collected unless permitted or required by law.

6. Lawful Bases for Processing

Depending on the purpose and circumstances, we may rely on one or more of the following lawful bases.

6.1 Performance of a Contract

We may process personal data where necessary to:

create and administer your Account;

process purchases;

credit and deduct Tokens;

provide AI Plans;

process Trainer requests;

deliver Courses;

provide customer support relating to the Service; and

perform our contractual obligations.

6.2 Legal Obligation

We may process personal data where necessary to comply with legal obligations, including requirements relating to:

accounting;

taxation;

fraud prevention;

legal proceedings;

regulatory requirements; and

lawful requests from competent authorities.

6.3 Legitimate Interests

Where appropriate, we may process personal data where necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and interests.

These interests may include:

operating and improving the Service;

maintaining security;

preventing fraud and abuse;

protecting our legal rights;

managing complaints and disputes;

understanding how the Service is used; and

maintaining reliable business records.

Where required, we assess the relevant interests and the impact of the processing on individuals.

6.4 Consent

We may rely on your consent where required, including for:

certain cookies or similar technologies;

certain marketing communications;

processing certain health-related information where explicit consent is the appropriate special category condition; and

other optional processing activities for which consent is requested.

Where processing is based on consent, you may withdraw that consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

7. Health and Other Special Category Data

Certain information you provide for the creation or personalisation of a Course may constitute special category personal data, particularly data concerning your health.

This may include information about:

injuries;

physical limitations;

mobility restrictions;

health-related exercise restrictions; or

other information revealing aspects of your physical health.

Where we process health-related special category data for personalised plan generation or related Service functionality, we will identify both:

an appropriate lawful basis for processing under applicable data protection law; and

an applicable condition for processing special category data.

Where appropriate, we rely on your explicit consent to process health-related information that you voluntarily provide for the purpose of:

generating or personalising a fitness Plan;

preparing a Trainer-Created Course;

adapting training content to disclosed restrictions;

supporting the relevant Course request; and

providing related Service functionality.

You are not required to provide more health-related information than is reasonably necessary for the relevant feature or request.

You should not provide medical records or other highly sensitive information unless specifically requested and reasonably necessary for the Service.

7.1 Withdrawal of Explicit Consent

You may withdraw explicit consent for future processing of consent-based health data by contacting us.

Withdrawal of consent may mean that we can no longer:

generate certain personalised content;

continue a Trainer-Created Course requiring that information; or

provide a feature that depends on the relevant data.

Withdrawal does not affect processing already carried out lawfully before the withdrawal.

We may still retain limited information where retention is required by law or necessary for the establishment, exercise, or defence of legal claims.

7.2 Not a Medical Service

Chalet Coaching is a fitness and training platform and does not provide medical diagnosis, medical treatment, emergency care, or healthcare services merely because health-related information is processed for fitness personalisation.

8. AI-Generated Plans and Automated Processing

The Service may use automated systems and artificial intelligence technologies to generate or assist in generating fitness content based on information provided by Users.

This may involve processing information such as:

selected training goals;

fitness level;

preferred training type;

available equipment;

training frequency;

physical limitations;

other Plan configuration inputs; and

relevant health-related information where provided.

The purpose of this processing is to generate, personalise, structure, or deliver the requested fitness content.

Where third-party technology providers support automated generation, we take reasonable steps to ensure that personal data is processed under appropriate contractual and data protection arrangements.

We seek to limit the personal data used for automated generation to information reasonably necessary for the relevant purpose.

AI-generated content may involve automated generation of fitness recommendations, but the Service is not intended to make decisions producing legal effects or similarly significant effects concerning you solely through automated processing.

Where applicable law gives you rights relating to certain automated decisions, those rights remain unaffected.

9. Trainers and Access to Personal Data

Where you request a Trainer-Created Course, the relevant Trainer may need access to information reasonably necessary to prepare or support the requested Course.

Depending on the request, this may include:

fitness goals;

experience level;

training preferences;

available equipment;

training frequency;

relevant physical limitations;

relevant health-related information voluntarily provided by you; and

communications or clarifications relating to the request.

Trainers should only receive or access information reasonably necessary for the relevant Service.

We do not intend to disclose unrelated payment card credentials or unnecessary Account information to Trainers.

Personal data made available in connection with Trainer-Created Courses must be handled in accordance with applicable contractual, confidentiality, and data protection requirements.

10. Payment Data and Card Security

Payments for Tokens and other eligible purchases are processed through third-party payment infrastructure.

10.1 Full Cardholder Data

Chalet Coaching does not store your full payment card details on its own servers.

In particular, we do not store your full payment card number or card security code such as CVV or CVC on Chalet Coaching servers.

Full payment card details required to authorise a card transaction are submitted to and handled through the relevant PCI DSS-compliant payment gateway or payment processing infrastructure.

The payment provider is responsible for processing the card payment within its payment environment and may process personal data in accordance with its own legal obligations and privacy terms.

10.2 Information We May Receive

Although we do not store full cardholder credentials, we may receive and retain limited information relating to a payment, including:

transaction reference;

payment status;

purchase amount;

currency;

date and time;

payment method or card brand;

limited card identifiers, such as the last four digits, where provided;

refund or dispute status; and

fraud, authentication, or risk-related transaction information.

This information may be used for:

confirming payment;

crediting Tokens;

maintaining transaction records;

processing refunds;

customer support;

accounting and tax purposes;

fraud prevention;

dispute management; and

compliance with legal obligations.

  1. 3-D Secure Authentication

Card payments may be subject to 3-D Secure or another authentication process where supported or required by the relevant payment provider, card scheme, or card issuer.

During a 3-D Secure process, you may be asked to complete an additional authentication step, for example through your bank or card issuer.

Authentication information and full card credentials are handled through the relevant payment and authentication infrastructure rather than being stored as full cardholder data on Chalet Coaching servers.

We may receive limited information about the result or status of the authentication process where necessary to process or record the transaction.

Use of 3-D Secure does not mean that every transaction will be approved. Final payment authorisation remains subject to the relevant payment provider and card issuer.

12. Who We Share Personal Data With

We may disclose personal data where reasonably necessary to the following categories of recipients.

12.1 Payment and Financial Service Providers

To:

process payments;

authenticate transactions;

process refunds;

prevent fraud;

manage payment disputes; and

maintain transaction records.

12.2 Hosting and Infrastructure Providers

To host, store, secure, maintain, and operate the Service.

12.3 Technology and Service Providers

This may include providers supporting:

Account functionality;

authentication;

automated Plan generation;

communications;

email delivery;

technical monitoring;

error logging;

security; and

other operational functions.

12.4 Trainers

Where necessary to fulfil a Trainer-Created Course request.

12.5 Customer Support and Communication Providers

For example, where a support or live-chat service is enabled in accordance with applicable consent requirements.

12.6 Professional Advisers

Including:

accountants;

auditors;

legal advisers;

insurers; and

other professional consultants.

12.7 Authorities and Other Parties Where Required

We may disclose personal data where reasonably necessary to:

comply with law;

respond to a lawful request from a competent authority;

enforce our legal rights;

protect Users or other persons;

prevent or investigate fraud or unlawful activity; or

establish, exercise, or defend legal claims.

12.8 Business Transfers

If all or part of our business is sold, reorganised, merged, or transferred, relevant personal data may be disclosed to professional advisers, potential purchasers, or successor organisations subject to appropriate confidentiality and data protection safeguards.

We do not sell personal data in the ordinary meaning of selling personal information for monetary consideration.

13. Service Providers Acting on Our Behalf

Where a service provider processes personal data on our behalf as a processor, we take reasonable steps to require appropriate contractual commitments concerning:

confidentiality;

security;

permitted processing purposes;

assistance with data protection obligations;

deletion or return of data where applicable; and

use of subprocessors.

Some third parties may act as independent controllers for particular processing activities, particularly where they determine their own legal purposes and obligations.

For example, a payment provider may process certain information independently to comply with payment, fraud-prevention, financial, or legal obligations.

14. International Data Transfers

Some service providers or technical infrastructure used in connection with the Service may be located outside the United Kingdom or may allow personal data to be accessed from another country.

Where a transfer of personal data is subject to international transfer restrictions, we will use an appropriate legal transfer mechanism where required.

Depending on the circumstances, this may include:

transfer to a country covered by applicable adequacy regulations or an adequacy decision;

the UK International Data Transfer Agreement;

the UK Addendum to the European Commission Standard Contractual Clauses;

European Commission Standard Contractual Clauses where the EU GDPR applies;

another legally recognised safeguard; or

an applicable statutory exception where lawful and appropriate.

Where required, we may also assess the circumstances and risks associated with the transfer and implement supplementary safeguards.

15. Data Retention

We retain personal data only for as long as reasonably necessary for:

the purposes for which it was collected;

providing and administering the Service;

maintaining Account and transaction records;

complying with legal, accounting, or tax obligations;

fraud prevention;

security;

handling complaints and disputes;

establishing, exercising, or defending legal claims; and

other legitimate and lawful business requirements.

Retention periods may vary depending on:

the type of data;

the purpose of processing;

the sensitivity of the information;

the status of your Account;

whether an order or dispute remains active;

legal requirements; and

applicable limitation periods.

Where personal data is no longer reasonably required, we may delete, anonymise, or otherwise securely dispose of it.

15.1 Account Data

Account information may be retained while your Account remains active and for an appropriate period after closure where necessary for legal, security, dispute, or record-keeping purposes.

15.2 Transaction Data

Certain payment, refund, accounting, and transaction records may need to be retained after Account closure in order to comply with legal obligations or manage disputes.

15.3 Health-Related Data

Health-related information will not be retained longer than reasonably necessary for the relevant purpose, subject to legal or claims-related retention requirements.

Because of its sensitive nature, we seek to limit the collection and retention of such information to what is reasonably necessary.

15.4 Backup Data

Deleted information may remain temporarily in secure backups until those backups are overwritten or deleted in accordance with applicable retention processes.

16. Data Security

We use reasonable technical and organisational measures designed to protect personal data against:

unauthorised access;

accidental or unlawful loss;

misuse;

alteration;

unauthorised disclosure; and

destruction.

Depending on the nature of the data and Service, measures may include:

access controls;

authentication controls;

secure communications;

restricted access to personal data;

logging and monitoring;

use of reputable infrastructure and payment providers;

data minimisation; and

internal or contractual confidentiality requirements.

Payment card processing is handled through PCI DSS-compliant payment infrastructure, and full payment card details are not stored on Chalet Coaching servers.

No online system or method of electronic storage can guarantee absolute security. Users are also responsible for protecting their Account credentials and devices.

If we become aware of a personal data breach, we will investigate and take appropriate action, including notification to competent authorities or affected individuals where required by applicable law.

17. Your Data Protection Rights

Depending on the applicable law and the circumstances of the processing, you may have the right to:

17.1 Right of Access

Request confirmation of whether we process your personal data and obtain access to personal data we hold about you.

17.2 Right to Rectification

Request correction of inaccurate personal data and completion of incomplete information.

17.3 Right to Erasure

Request deletion of personal data in circumstances where the law provides a right to erasure.

This right is not absolute. We may retain information where processing remains legally permitted or required.

17.4 Right to Restriction

Request restriction of processing in certain circumstances.

17.5 Right to Data Portability

Receive certain personal data in a structured, commonly used, and machine-readable format, and request transmission to another controller where the legal requirements for portability apply.

17.6 Right to Object

Object to certain processing based on legitimate interests and to processing for direct marketing purposes.

17.7 Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

17.8 Rights Relating to Certain Automated Decisions

Where applicable law provides rights concerning decisions based solely on automated processing that produce legal or similarly significant effects, you may exercise those rights in accordance with the applicable legal requirements.

18. Exercising Your Rights

To exercise a data protection right or submit a privacy request, contact:

Email: info@chaletcoaching.co.uk

Please describe your request clearly enough for us to identify the relevant information and respond appropriately.

We may request reasonable information to verify your identity before disclosing, deleting, or changing personal data.

This is intended to protect personal data against unauthorised access.

We will respond within the timeframe required by applicable law.

In certain circumstances, a request may be limited or refused where permitted by law. Where required, we will explain the relevant reason.

19. Account Closure and Personal Data

You may request closure of your Chalet Coaching Account as described in our Terms and Conditions.

Closing an Account does not necessarily result in immediate deletion of all personal data.

We may retain information where reasonably necessary for:

legal obligations;

accounting and tax records;

fraud prevention;

security;

unresolved transactions;

complaints or disputes;

legal claims; or

other lawful retention purposes.

Where no lawful purpose for continued retention remains, the relevant personal data will be deleted, anonymised, or otherwise securely disposed of.

20. Marketing Communications

Where we send direct marketing communications, we will do so in accordance with applicable law.

Where consent is required, we will request it before sending the relevant marketing communication.

You may opt out of marketing communications at any time by:

using the unsubscribe mechanism provided in the communication, where available; or

contacting us.

Opting out of marketing does not prevent us from sending non-marketing communications that are necessary to administer your Account, transactions, Courses, security, or support requests.

21. Cookies and Similar Technologies

We use cookies and similar technologies for purposes including:

Account login and authentication;

security;

session management;

language and currency preferences;

remembering cookie choices;

Service functionality; and

optional support or other features where consent is required.

Where non-essential cookies or similar technologies require consent, they will not be used until the relevant consent has been obtained.

You may manage available choices through the cookie settings provided on the Service.

Further information, including examples of cookies and their purposes, is provided in our Cookies Policy.

22. Jivo and Support Functionality

Where available, the Service may use Jivo or similar functionality to provide live chat or customer support.

Where such functionality uses non-essential cookies, storage, or similar technologies, it will be enabled in accordance with applicable consent requirements.

Information you voluntarily submit through a support service may be processed for the purpose of:

responding to your enquiry;

providing customer support;

maintaining support records; and

resolving Service-related issues.

The relevant provider may process limited technical or communication data to provide the support functionality.

23. Third-Party Links

The Service may contain links to third-party websites, applications, or services.

We do not control independent third parties and are not responsible for their privacy practices.

You should review the relevant privacy information before providing personal data directly to an independent third party.

24. Children

The Service is intended for persons aged 18 and over.

We do not knowingly offer Accounts or paid Services to children.

If we become aware that personal data has been collected from a person who is not eligible to use the Service, we may take reasonable steps to delete or restrict the relevant information, subject to applicable legal obligations.

25. Complaints

If you have a concern about how we process personal data, we encourage you to contact us first so that we can investigate and attempt to resolve the matter.

You also have the right to make a complaint to the UK Information Commissioner’s Office (ICO) where it is the competent supervisory authority.

If you live in another country, you may also have the right to contact another competent data protection authority.

Your right to complain to a supervisory authority is not affected by any attempt to resolve the issue directly with us.

26. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

changes to the Service;

new functionality or technologies;

changes to our processing activities;

changes to service providers;

changes in law or regulatory requirements; or

improvements in clarity.

The current version will be published with an updated revision date.

Where a change materially affects how personal data is processed, we will provide additional notice or obtain consent where required by law.

27. Contact Us

For questions about this Privacy Policy, your personal data, or your data protection rights, contact:

CHALET AQUARIUS LTD

Company number: 15587263

20 Wenlock Road

London, England

N1 7GU

Email: info@chaletcoaching.co.uk

Phone: +44 7782 358363

PRIVACY POLICY