- About this Privacy Policy
This Privacy Policy explains how Raw Condition Ltd trading as Raw Gyms collects, uses, stores, shares and protects personal data. It applies to members, prospective members, day pass users, guests, visitors, corporate contacts, suppliers, website users, app users and people who contact us. Raw Gyms is the controller of your personal data for the purposes described in this Policy, unless we tell you otherwise. Our trading address is Unit 2 Burton Hall Road, Sandyford, Dublin 18. You can contact us about privacy matters at members@rawcondition.com or by writing to us at the above address. This Policy should be read together with our Terms and Conditions, Cookie Policy, CCTV notices, club rules, membership forms and any privacy information shown to you when you provide data.
- Personal data we collect
We may collect and use the following categories of personal data, depending on your relationship with Raw Gyms and the services you use.
| Category | Examples |
| Identity and contact data | Name, address, email address, phone number, date of birth, emergency contact where provided, company/corporate details where relevant. |
| Membership data | Membership type, home club, member ID, join date, renewal date, cancellation date, freeze details, access status, corporate membership eligibility. |
| Payment and billing data | Payment status, invoices, receipts, transaction history, direct debit or card payment references, arrears and refund records. Full card details are handled by payment processors where applicable. |
| App and access data | Raw Gym Plus app account, QR code/access credentials, swipe card records, access logs, class bookings and attendance. |
| Health and fitness safety data | PAR-Q or health questionnaire responses, injuries, fitness limitations, medical information relevant to safe exercise, pregnancy-related information where voluntarily disclosed, incident or accident health details. |
| CCTV and site visit data | Images/video captured by CCTV in public areas, entry/exit records, incident footage and visitor records. |
| Communications and complaints | Emails, letters, calls, face-to-face interaction notes, contact forms, complaints, feedback and survey responses. |
| Marketing and preferences | Marketing permissions, opt-outs, communication preferences, engagement with offers, website forms and lead source. |
| Website and cookie data | IP address, device information, browser type, cookie identifiers, pages visited, analytics and advertising preferences. |
| Photos and videos | Images or videos from events, classes, challenges, testimonials or marketing content where applicable. |
| Supplier/corporate contact data | Business contact name, role, email, phone, company, billing or account contact details. |
- How we collect personal data
We collect personal data directly from you when you join, use our website, download or use the Raw Gym Plus app, visit a club, book a class, complete a form, complete a PAR-Q or health questionnaire, make a payment, request a freeze or cancellation, contact us, respond to a survey or interact with us on social media. We may also receive personal data from payment processors, membership software providers, app providers, corporate membership partners, website/analytics providers, social media platforms, CCTV systems, insurers, legal advisers or other third parties where lawful and relevant.
- Lawful basis and processing-purpose table
We use personal data only where we have a lawful basis to do so. The table below summarises our main processing purposes, the data used, lawful basis, typical retention period and the types of processors or recipients involved.
| Purpose | Data used | Lawful basis | Typical retention | Processors / recipients |
| Create and manage membership | Identity, contact, membership and app/access data | Contract | Active membership plus up to 6 years for contract/dispute records | Membership software, Raw Gym Plus app provider, access-control provider |
| Provide gym access and classes | Member ID, QR code/swipe card, class bookings, access logs | Contract and legitimate interests | Access logs 12-24 months unless incident-related | App, booking and access-control providers |
| Process payments and billing | Payment status, invoices, direct debit/card references, arrears | Contract and legal obligation | Usually 6 years for accounting/tax records | Payment processors, banks/card providers, accounting systems, accountants |
| Recover unpaid fees | Contact details, arrears balance, payment history, communications | Legitimate interests | Up to 6 years after resolution/write-off | Payment processor, credit control provider, legal advisers where needed |
| Health/PAR-Q and fitness safety | Health questionnaires, injuries, exercise limitations, incident health data | Contract/legitimate interests/vital interests plus Article 9 condition such as explicit consent or legal claims | Active membership plus 12-24 months unless incident/claim-related | Authorised staff, app/form provider, membership system, insurers/legal advisers where needed |
| CCTV security and safety | CCTV images/video, incident footage | Legitimate interests | Routine footage up to 30 days; incident footage longer where necessary | CCTV/security provider, Gardaí, insurers, legal advisers where needed |
| Customer service and complaints | Communications, complaint records, account notes | Contract and legitimate interests | Routine queries 12-24 months; formal complaints up to 6 years | Email/CRM providers, legal advisers where needed |
| Operational communications | Email, phone, SMS, app notifications, account status | Contract and legitimate interests | Membership term plus relevant account period | Email/SMS/app providers |
| Marketing to members/prospects | Contact details, preferences, consent/opt-out status, engagement | Consent or legitimate interests/soft opt-in where permitted | Until opt-out; inactive leads reviewed after 24 months | Email/SMS platform, CRM, marketing agencies |
| Website analytics and cookies | Cookie IDs, IP/device data, site usage | Consent for non-essential cookies; legitimate interests for strictly necessary cookies | Cookie-specific periods, usually 6-26 months | Website host, analytics providers, cookie consent provider |
| Social media advertising/custom audiences | Hashed email/phone, engagement data | Consent preferred; otherwise legitimate interests only after assessment | Campaign period or until opt-out | Meta/Google/social platforms, marketing agencies |
| Photos/videos for marketing | Identifiable images/videos and consent records | Consent or other appropriate lawful basis | Until consent withdrawn or campaign/archive period ends | Website provider, marketing agency, social platforms |
| Legal compliance and rights requests | Relevant account, identity, communication and request records | Legal obligation and legitimate interests | Rights logs 12-24 months; legal/accounting records up to 6 years | Legal advisers, accountants, insurers, regulators |
- Legitimate interests summary
Where we rely on legitimate interests, we do so where necessary to operate and protect our gyms, manage customer relationships, improve our services, recover unpaid fees, prevent misuse of facilities, maintain safety and security through CCTV, manage complaints and incidents, protect our legal position and send relevant service or marketing communications where permitted. We balance these interests against your rights and expectations and provide opt-out rights where applicable.
- Health Data, PAR-Q and Fitness Safety Information
We may collect limited health and fitness safety information where necessary to help provide services safely, manage risk within our facilities, respond to incidents, or support you in using our gyms, classes and personal training services. This may include information you provide in a health questionnaire, PAR-Q, onboarding form, class waiver, personal training consultation, app profile, freeze request, incident report or direct communication with our team. Health data may include information about injuries, medical conditions, exercise limitations, pregnancy-related considerations where voluntarily disclosed, symptoms affecting safe exercise, emergency/incident information, personal training goals and support needs. We only ask for health information that is relevant to the service, safety assessment, incident, request or support being provided. Some basic fitness safety information may be required before you use certain services. Other health information, such as detailed injury history, body metrics, training goals or personal training notes, is optional unless genuinely needed for a specific service or safety reason. Health information is special-category personal data under GDPR. Where required, we identify both an Article 6 lawful basis and an Article 9 special-category condition, such as explicit consent, vital interests or legal claims depending on the circumstances. Access to health and fitness safety information is restricted to authorised team members who need it for their role. This may include club management, authorised reception/admin staff, personal trainers or instructors involved in delivering your service, and staff involved in managing an accident, incident, complaint, membership-support request or legal/insurance matter. We do not use health data for general marketing, advertising profiling or social media targeting. Where we rely on your explicit consent to process health information, you may withdraw that consent at any time. If you withdraw consent, we will stop processing the relevant health information unless we have another lawful reason to retain it, such as an accident record, insurance matter, legal claim, complaint or regulatory obligation. If the health information is necessary for a particular service, class, personal training programme or safety assessment, refusing or withdrawing consent may mean we cannot provide that service or may need to adjust how it is provided.
- CCTV
CCTV operates in public areas of our clubs, but not in changing areas. CCTV is used for safety, security, crime prevention, incident management, prevention and detection of anti-social behaviour, effective operation of the gym and protection of members, visitors, staff and property. Routine CCTV footage is normally retained for up to 30 days and then automatically overwritten or deleted. Where footage is required for an incident, complaint, insurance matter, legal claim, disciplinary issue, Garda request or investigation, the relevant footage may be retained for longer until the matter is resolved and any applicable retention period has expired. Access to CCTV footage is restricted to authorised personnel. Footage may be disclosed to An Garda Síochána, insurers, legal advisers, regulators or other parties where required or permitted by law.
- Photos, videos and social media
CCTV is separate from marketing photography and video. We do not treat joining Raw Gyms as automatic consent to use identifiable photos or videos of you for social media, advertising or marketing. We may occasionally take photos or videos at events, classes, challenges or club activities. Where you are identifiable and the content is used for marketing, advertising or social media, we will rely on separate consent or another appropriate lawful basis where permitted. You may withdraw consent for future use at any time. We will take reasonable steps to remove or stop using images or videos where practicable, but we may not be able to remove content already copied, shared or stored by third parties.
- Marketing communications
We may send you operational or service communications about your membership, payments, access, safety, opening hours, class changes, price changes, closures or important account matters. These are not marketing messages and may still be sent even if you opt out of marketing. We may send marketing communications about Raw Gyms news, offers, events, challenges or services where you have consented or where we are otherwise permitted to do so by law. You can opt out at any time by using the unsubscribe link, replying STOP or UNSUBSCRIBE where available, updating your preferences or contacting members@rawcondition.com. As a previous member, we may contact you about re-joining offers for up to 24 months after your membership ends, unless you opt out earlier or applicable law requires a different approach. If you have not purchased from us, we will only send electronic marketing where you have consented, except where we are responding directly to your query.
- Cookies and website tracking
We use strictly necessary cookies to operate our website. We only use analytics, advertising, personalisation and social media cookies where you have given consent through our cookie banner or cookie settings tool.
You can manage or withdraw cookie consent using the cookie settings tool on our website. More information is available in our Cookie Policy.
- Retention schedule
We do not keep personal data for longer than necessary. Different categories of data are kept for different periods depending on the purpose for which they were collected, our legal and accounting obligations, insurance requirements, contract-management needs, and whether a complaint, incident, payment dispute or legal claim may arise. When your membership ends, we deactivate your membership account and remove your access to our facilities. We do not delete all account data immediately, as some information must be retained for legitimate business, legal, accounting, insurance, complaint-handling, safety or dispute-resolution purposes. We delete or anonymise personal data when it is no longer required for those purposes.
| Type of data | Typical retention period |
| Membership account and contract records | Active membership plus up to 6 years |
| Payment, invoice and accounting records | Usually 6 years for tax/accounting purposes |
| Direct debit/payment mandate records | Active mandate plus up to 6 years |
| Cancellation, freeze and refund records | Up to 6 years after resolution |
| Routine access logs | 12-24 months unless linked to an incident |
| Class booking and attendance records | 12-24 months unless needed for complaint or incident |
| Health/PAR-Q information | While relevant to membership/safety, usually active membership plus 12-24 months, unless linked to an incident or claim |
| Accident and incident records | Usually up to 6 years, or longer where legally required or involving minors |
| Routine CCTV footage | Usually up to 30 days |
| CCTV linked to an incident | Retained until the incident, claim or investigation is resolved and any relevant retention period has expired |
| Routine enquiries | 6-12 months if you do not become a member |
| Formal complaints and disputes | Up to 6 years after resolution |
| Marketing preferences | Until you unsubscribe or opt out |
| Marketing consent records | For the duration of consent plus a reasonable period to evidence compliance |
| Suppression/opt-out records | Retained in minimal form to make sure we do not contact you again |
| Cookie consent records | Usually 6-12 months or until consent is refreshed |
| Website analytics | According to analytics settings, usually 14-26 months |
| Photo/video consent records | For as long as the image/video is used plus a reasonable evidence period |
Retention extension
Where a legal claim, complaint, investigation, insurance matter, payment dispute, safety issue or regulatory matter is ongoing, we may retain relevant records for longer until the matter is fully resolved and any applicable limitation period has expired.
- Sharing personal data
We do not sell your personal data. We may share personal data with trusted service providers and third parties where necessary for the purposes described in this Policy.
| Recipient/category | Purpose |
| Membership management and app providers | Managing membership accounts, app access, QR codes, bookings and club access. |
| Ashbourne Management or other direct debit/membership payment providers | Processing monthly direct debits and membership payments, where applicable. |
| Stripe or other card/payment processors | Processing initial payments, card payments, refunds and in-club purchases. |
| Banks/card providers | Payment processing, chargebacks and payment verification. |
| Accountants and finance systems | Accounting, audit, tax and financial reporting. |
| Email/SMS/CRM providers | Operational communications, service messages, marketing preferences and campaigns. |
| Website hosts, web developers and IT support | Hosting, maintaining and securing website, forms and systems. |
| Cookie, analytics and advertising providers | Website analytics, cookie consent management and advertising where consent/permissions apply. |
| Social media platforms | Social media content, custom audiences or advertising where permitted and transparent. |
| CCTV/security providers | Operation and maintenance of CCTV/security systems. |
| Insurers, legal advisers and credit control providers | Claims, legal advice, debt recovery, disputes and risk management. |
| Corporate membership partners/employers | Corporate membership administration where your membership is arranged through a corporate scheme. |
| Regulators, An Garda Síochána and public authorities | Where required or permitted by law, court order, regulatory request or safety/security need. |
- International transfers
Some of our service providers, app providers, website providers, analytics providers, marketing providers or social media platforms may process personal data outside the European Economic Area. Where this happens, we will ensure appropriate safeguards are in place, such as an adequacy decision, the EU Standard Contractual Clauses, the EU-US Data Privacy Framework where applicable, or another lawful transfer mechanism. You can contact us for more information about the safeguards used for international transfers.
- Security
We use appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These may include restricted access, passwords, access controls, staff confidentiality, secure systems, processor contracts, retention controls, secure deletion and staff training. Health data, incident records and CCTV are subject to additional access restrictions because of their sensitivity.
- Your rights
Subject to legal conditions and exemptions, you may have the following rights under data protection law: access to your personal data; correction of inaccurate data; deletion of data in certain circumstances; restriction of processing; objection to processing; data portability; withdrawal of consent where processing is based on consent; and the right not to be subject to certain automated decisions. To exercise your rights, contact members@rawcondition.com. We may need to verify your identity before responding. We will respond within the time required by law. You also have the right to lodge a complaint with the Data Protection Commission in Ireland if you are unhappy with how we handle your personal data. We encourage you to contact us first so we can try to resolve the issue.
- Children and younger members
The minimum age to join Raw Gyms is 17 with parental or guardian consent. Where we process data relating to younger members, we take additional care to ensure the data is appropriate, limited and handled securely. Parent or guardian details may be used where required for consent, safety, administration, billing or emergency contact purposes.
- Updates to this Policy
We may update this Privacy Policy from time to time. The latest version will be published on our website. Where changes are material, we will take reasonable steps to bring them to your attention.
- Contact
For questions about this Privacy Policy or your personal data, please contact Raw Gyms at members@rawcondition.com or write to Raw Condition Ltd trading as Raw Gyms, Unit 2 Burton Hall Road, Sandyford, Dublin 18.