Effective Date: 1st August 2025


1. Introduction

N7 Fitness & Recovery CIC (“N7”, “we”, “us”, or “our”) is committed to protecting the privacy and personal data of our members, visitors, and users (“you”). This Privacy Policy outlines how we collect, use, store, and protect your information in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable laws.

N7 Fitness & Recovery CIC is a Community Interest Company (CIC) specialising in supporting men’s mental and physical health through fitness, recovery programs, and related services. Our registered office is located at 238A Stanley Rd, Kirkdale, Liverpool L5 7QP.


2. Data Controller

For the purposes of the UK GDPR, the Data Controller is:

N7 Fitness & Recovery CIC

Attn: Sean Pownell (Founder)

Email: sean@n7fr.org

Address: 238A Stanley Rd, Kirkdale, Liverpool L5 7QP

We determine the purposes and means of processing your personal data.


3. What Personal Data We Collect

We collect and process the following categories of personal data:

  • Identification Data: Full name, date of birth, gender, photo (optional).
  • Contact Data: Email address, telephone number, postal address.
  • Health Data: Any relevant physical or mental health information provided voluntarily or via referral.
  • Emergency Contact Data: Name, relationship, and phone number of your emergency contact.
  • Membership & Activity Data: Membership details, attendance logs, fitness class participation, personal goals.
  • Referral Data: Information provided by third parties such as the NHS or healthcare professionals, which may include special category data (e.g., health conditions) and contact information.
  • Payment Data: While we do not store card or banking information directly, we process payments via third-party providers (Stripe and PayPal), who may collect billing and payment details.

4. Legal Basis for Processing

We process your personal data on one or more of the following lawful bases:

  • Consent: Where you have given clear consent for us to process your data.
  • Contractual Obligation: To fulfil our obligations under your membership agreement.
  • Legal Obligation: To comply with applicable laws and regulations.
  • Vital Interests: In cases of emergency, including contacting your nominated emergency contact.
  • Legitimate Interests: For purposes necessary to operate our services and improve member experience.
  • Public Task: Where data is shared by NHS or a healthcare professional as part of a referral, and we process it in the public interest in the area of public health or provision of care.

5. How We Use Your Information

We use your personal data for the following purposes:

  • To manage your membership and provide access to our services.
  • To communicate important updates, class schedules, and wellbeing resources.
  • To ensure the safety and wellbeing of members, including contacting emergency services or emergency contacts when necessary.
  • To manage bookings, attendance, and participation in classes or support groups.
  • To process payments securely via third-party processors.
  • To support members referred by the NHS or other healthcare bodies and deliver fitness and wellbeing programs.
  • To comply with our legal obligations and respond to legal requests.

6. Emergency Contact Disclosure

In the event of a medical or mental health emergency, we may contact your provided emergency contact. In doing so, we may disclose limited personal information, including confirmation that you are present at our facility and a brief explanation of the nature of the emergency, only if necessary to protect your vital interests.


7. NHS and Third-Party Referrals

If you are referred to N7 by the NHS or another healthcare provider, we may receive personal data about you directly from the referring party. This may include:

  • Name, contact details, and relevant health or wellbeing information.
  • Reason for referral and goals related to your health or recovery.

Such data is processed under the lawful basis of public task and/or explicit consent, and is used solely to provide you with appropriate support and services. This information is treated as highly confidential and managed in accordance with this Privacy Policy.


8. Sharing Your Information

We may share your information with:

  • Payment Providers: Stripe and PayPal, who are responsible for processing your payments. They are independent data controllers for certain payment-related information.
  • Emergency Services: If required for your safety.
  • Third-party Service Providers: Such as email communication tools, booking platforms, or cloud storage services, bound by confidentiality and data processing agreements.
  • Referring Healthcare Providers: If necessary for coordinated support.
  • Regulatory or Law Enforcement Authorities: When legally required.

9. Data Processors

Our data processors, including Stripe and PayPal, only process data on our behalf in accordance with our instructions and under strict contractual terms.


10. Data Retention

We will retain your personal data only for as long as necessary for the purposes set out in this Privacy Policy or as required by law. Typically:

  • Membership records: 6 years after termination.
  • Emergency contact and referral information: Deleted immediately upon termination unless another lawful basis applies.
  • Payment records: Retained in accordance with legal and financial obligations.

11. Data Security

We implement appropriate technical and organisational measures to protect your data, including encryption, secure servers, and access controls. Only authorised personnel have access to your data.


12. Your Rights Under GDPR

Under the UK GDPR, you have the following rights:

  • Right to Access: Request access to your personal data.
  • Right to Rectification: Request corrections to inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your data (subject to legal exceptions).
  • Right to Restrict Processing: Limit how we process your data.
  • Right to Data Portability: Receive your data in a structured, commonly used format.
  • Right to Object: Object to certain types of processing.
  • Right to Withdraw Consent: Where applicable.

To exercise these rights, contact us at support@n7fr.org.


13. Cookies and Tracking

Our website may use cookies and similar technologies to enhance your browsing experience. A separate Cookie Policy governs their use.


14. International Transfers

We do not knowingly transfer personal data outside of the UK. If required, we will ensure appropriate safeguards are in place in accordance with the UK GDPR.


15. Changes to This Policy

We reserve the right to update this Privacy Policy from time to time. The most recent version will always be available on our website with the effective date clearly shown.


16. Contacting Us

If you have questions about this Privacy Policy or how we handle your data, please contact:

N7 Fitness & Recovery CIC

Attn: Sean Pownell

Email: info@n7fr.org

Address: 238A Stanley Rd, Kirkdale, Liverpool L5 7QP