Privacy Policy

AnyBody Yoga CIC  – Last updated: 3rd August 2026

1.1 This Privacy Policy explains how AnyBody Yoga CIC (“we”, “us”, “our”), a Community Interest Company registered in England and Wales under company number 17266636, collects, uses, and protects personal data belonging to clients, prospective clients, and website visitors (“you”).

1.2 We are committed to processing personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Contact details

For any queries relating to this policy or the handling of your personal data, please contact us.

Scope

2.1 This policy applies to personal data collected in connection with our yoga classes, one-to-one sessions, and events.

2.2 Our website is an informational site only. It does not include a login area, membership portal, e-commerce function, or blog with public comments, and does not collect personal data directly through the website itself, other than via the third-party booking service described in Section 5.

Personal data we collect

We may collect and process the following categories of personal data:

3.1 Identity and contact data — name, email address, and telephone number, provided when you make a booking or contact us directly.

3.2 Booking data — details entered when booking a class, one-to-one session, or event via our third-party booking platform, Calendly.

3.3 Attendance records — where registers or sign-in sheets are used at classes or events.

3.4 Special category data — where you choose to share information relating to your health or physical condition that is relevant to your practice. This is provided voluntarily and is treated with additional care as described in Section 6 below.

How and why we use your data

We use personal data for the following purposes:

4.1 To process and manage bookings for classes, one-to-one sessions, and events.

4.2 To communicate with you regarding bookings, scheduling changes, or cancellations.

4.3 To respond to enquiries submitted to us.

4.4 To maintain accurate records for health and safety, insurance, and safeguarding purposes.

4.5 To comply with applicable legal and regulatory obligations.

4.6 Where you have separately opted in, to send you updates or marketing communications. You may withdraw this consent at any time.

Third party processors

5.1 We use Calendly, a third-party scheduling service, to manage bookings. When you book a session, the personal data you provide (name, email address, and any notes) is processed by Calendly on our behalf, in accordance with Calendly’s own privacy policy, available at calendly.com/privacy.

5.2 We do not sell, rent, or otherwise disclose your personal data to third parties for marketing purposes.

Special category data

6.1 Any information you share with us regarding your health is treated as special category data under Article 9 of the UK GDPR.

6.2 We only collect such data where you provide it voluntarily, and we use it solely to ensure that sessions are delivered safely and appropriately for your circumstances.

6.3 Access to this information is restricted to those directly involved in delivering your sessions.

Legal Basis for Processing

We process personal data on the following legal bases:

6.4 Contract (Article 6(1)(b)) — to provide the classes, sessions, or events booked.

6.5 Legitimate interests (Article 6(1)(f)) — to operate our organisation safely and effectively, including maintaining attendance records.

6.6 Consent (Article 6(1)(a) and, where applicable, Article 9(2)(a)) — for marketing communications and for the voluntary provision of health-related information.

6.7 Legal obligation (Article 6(1)(c)) — where retention of records is required by law, including for insurance purposes.

Data security

7.1 We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or disclosure.

7.2 Digital records are stored securely with access restricted to authorised individuals. Physical records, where used, are kept in a locked, access-controlled location.

7.3 Access to personal data is limited to individuals who require it in order to deliver our services.

Data retention

8.1 We retain personal data only for as long as necessary for the purposes set out in this policy:

(a) Booking and contact data is retained for the duration of the client relationship and for a reasonable period afterwards for record-keeping purposes.

(b) Health-related information is retained only for as long as necessary to support the safe delivery of sessions, and in accordance with any applicable insurance or safeguarding requirements.

(c) Financial records are retained for a minimum of six years, in accordance with statutory requirements.

Your rights

Under UK GDPR, you have the right to:

(a) request access to the personal data we hold about you; (b) request correction of inaccurate or incomplete data; (c) request erasure of your data, where applicable; (d) request restriction of processing; (e) object to processing carried out on the basis of legitimate interests; (f) request data portability, where technically feasible.

To exercise any of these rights, please contact us using the details in Section 2. You also have the right to lodge a complaint with the Information Commissioner’s Office (ico.org.uk) if you believe your data has not been handled in accordance with the law.

Changes to this policy

We may amend this policy from time to time to reflect changes in our practices or legal requirements. The current version will always be published on our website, together with its effective date.

Cookie policy

Overview

Our website is an informational site. It does not include a login area, membership portal, e-commerce function, or blog, and we do not use cookies to track visitor activity, build user profiles, or personalise content.

Cookies we use

2.1 Essential cookies — our website hosting platform may set cookies automatically to enable core site functionality. These do not collect or store personal information.

2.2 Third-party booking cookies — where you click through to book a session via Calendly, Calendly may set its own cookies as part of that process. These are controlled by Calendly and not by us. Further information is available in Calendly’s cookie policy at calendly.com/privacy.

Managing cookies

You may control or delete cookies at any time through your browser settings. Please note that disabling cookies may affect the functionality of third-party services, including Calendly.

Future changes

Should we introduce analytics or marketing cookies in future, this policy will be updated accordingly and, where required by law, your consent will be obtained in advance.