Data Protection Policy
Last updated: 30 September 2026
Purpose and scope
This policy explains how Julie Driver, trading as Julie Driver Pilates, manages personal information in accordance with the UK GDPR, Data Protection Act 2018 and related law. It applies to information handled through the website, enquiries, bookings, teaching, teacher training, workshops, qualifications, marketing and business administration.
Responsibilities
Julie Driver is responsible for data-protection compliance and can be contacted at julie@juliedriverpilates.com or 07966 232779. No Data Protection Officer has been appointed because the business does not currently carry out processing that legally requires one. Anyone working for or on behalf of the business must follow this policy, keep information confidential, use it only for authorised purposes and report concerns promptly.
Principles and lawful use
Personal information must be processed lawfully, fairly and transparently; collected for specified purposes; limited to what is necessary; accurate; kept only as long as required; and protected against unauthorised access, loss or damage. Before processing begins, the purpose, lawful basis and any additional condition required for special-category information such as health data must be identified.
Collection, retention and rights
Only information reasonably required for the relevant service or legal obligation will be collected. Records are reviewed and securely deleted or anonymised when no longer needed, using the retention periods described in the Privacy Policy and any applicable awarding-body requirements. Requests to access, correct, erase, restrict, object to or receive personal information must be sent promptly to Julie Driver and handled within the statutory period.
Security and suppliers
Reasonable technical and organisational controls are used, including appropriate access restrictions, secure accounts, strong authentication where available, software updates, backups and confidential disposal. Suppliers must be assessed and bound by appropriate data-processing terms. Only the minimum necessary information may be shared with Wix, payment, communications, course or awarding-organisation providers and other authorised recipients. International transfers require an applicable UK adequacy regulation or approved safeguard.
Breaches
Any suspected loss, disclosure, cyber incident or unauthorised access must be reported immediately to Julie Driver. The incident will be contained, documented and assessed. The ICO will be notified within 72 hours where required, and affected people will be informed without undue delay where the risk is high.
Training, review and contact
People handling personal information must receive guidance appropriate to their role. This policy and related processing activities will be reviewed regularly and after significant legal, operational or security changes. Questions or concerns should be sent to julie@juliedriverpilates.com.
