As the European Union's GDPR regulations are coming into effect on May 25, 2018, we have collected tips and responsibilities for the gym owners.
Tips and responsibilities
- As a gym owner you are the controller of the data. It means you are responsible of the data you collect and save to WODconnect.
- Collect only data that is necessary for your business and use the data only for purposes which you have informed beforehand.
- Storing the data is limited in time. Therefore we have removed the “Old members” section from the gym owner view.
- Be transparent and document what data and why you are collecting from your customers.
- You have to be able to prove that you have done everything you could to follow the GDPR regulations, for instance with a data protection diary.
The rights of the registered
- Your clients have the right to receive transparent and up to date information from the data controller.
- Your clients have the right to get their personal data for free by asking without a delay and in generally supported form (CSV, JSON, XML). WODconnect collects users’ workout data and hands over the data as a CSV-file if requested via email.
- Your clients have the right to correct the mistakes of the personal data.
- Your clients have the right to get their information removed completely. However, some laws, for instance the accounting act, might override the data protection regulations.
- Your clients have the right to resist direct marketing messages and know how they can remove themselves from any contact list. Every email that is sent from WODconnect includes an unsubscribe link and users are also able to change their email preferences from their settings page.
- Your clients have the right to resist any kind of profiling.
- Your clients have the right to stay out of any automatic decision making process when it might have significant effects. Profiling and automatic decision making processes need to be informed to the clients.
Conclusion
Generally there is no need to worry if you act honestly and according to good principles. Just remember to keep your clients' data private and fulfill their requests without a delay. In the overlapping situations, resolve the prioritization order of the laws. And if you feel uncertain about anything, you can always send us a message.