top of page

Privacy Policy

Last updated: August 2026

This Privacy Policy explains how Lagree Sant Cugat ("we") collects, uses, stores and protects your personal data when you visit our website lagreesantcugat.com ("the Site"), book classes online, interact with our content or contact us through digital channels. We comply with Regulation (EU) 2016/679 (General Data Protection Regulation, "RGPD") and the Spanish Organic Law 3/2018 on Data Protection and Guarantee of Digital Rights (LOPDGDD).

1. Data controller

Lagree Sant Cugat Address: Avenida de Catalunya, 15, Sant Cugat del Vallès, Catalonia, Spain.

Email: admin@lagreesantcugat.com

Telephone: +34 634 91 74 82

Our contact person for privacy matters is: same as above

You can contact us at any time about this policy or your personal data using the contact details above.

2. Personal data we collect

We collect and process the following categories of personal data through our website:

2.1 Data you provide us directly:

Category

Identification data

Contact details

Account details

Health and physical data

Payment details

Communication data

Comments and feedback data

Examples

Full name, date of birth

Email, phone number, postal address

Username, password (encrypted)

Injuries, medical conditions, pregnancy, physical limitations

Billing name, transaction records

Messages, emails, form submissions sent to us

Comments, survey responses, testimonials

When are they collected?

Registration, reservation, submission of waiver form

Contact forms, newsletter subscription, reservation

Creating a member account on the booking platform

Waiver form, pre-class registration, instructor notes

Online class or membership purchases

Contact form, email inquiries, direct messages (DM) on social networks

Feedback forms, Google reviews, surveys

2.2 Data collected automatically:

Category

Technical/connection data

Usage data

Geolocation data (approximate)

Cookie identifiers

Examples

IP address, browser type, device type, operating system, screen resolution

Pages visited, time on page, click paths, referral source, session duration

Country, region, city (derived from IP)

Unique cookie IDs stored in your browser

How are they collected?

Server logs, cookies, analytics tools

Cookies, Wix Analytics, third-party analytics tools

Analysis tools

All cookies set by the Site (see Section 8)

2.3 Data from third party sources:

We may receive limited data from platforms through which you interact with us:

  • Google Business Profile : Reviews, ratings, and any information you publish publicly

  • Instagram/Facebook : Public profile data when you tag us, send us messages or comment on our posts

  • Class booking platform (e.g. bsport, Glofox): Class history, attendance, package status synced with our admin panel

3. Special category data (Article 9 RGPD)

We process information about your physical health, injuries and medical conditions as part of our monitoring obligation to provide safe fitness instruction. This constitutes special category data under Article 9 of the GDPR and is processed with your explicit consent.

We process this data only to:

  • Assess whether you can safely participate in specific classes

  • Modify exercises or hardware configuration to accommodate your needs

  • Respond appropriately in case of emergency

  • Fulfilling our duty of care as a fitness provider

You may withdraw this consent at any time. However, withdrawal may mean that we will not allow you to continue participating in classes until you provide updated health information or medical clearance.

4. Purposes and legitimate basis of processing

Purpose

Class booking and membership management

Safe instruction and injury prevention

Customer service and communication

Newsletter and marketing (email)

Social media marketing (paid and organic)

Website analysis and improvement

Cookie-based personalization

Accounting and tax compliance

Legal protection and liability management

Recruitment (when we are looking for staff)

What do we do with your data?

Process reservations, manage packages, monitor attendance

Using health data to adapt exercises, prevent injuries

Respond to inquiries, send confirmations and reservation reminders

Send promotional offers, class announcements, studio news

Run targeted ads, share user-tagged content

Monitor visitor behavior to improve site UX and content

Remember preferences, saved classes, language settings

Issue invoices, retain financial records

Retain signed disclaimers, incident reports

Process job applications submitted via the Site

Legitimate Basis (GDPR)

Art. 6(1)(b) — Performance of contract

Art. 9(2)(a) — Explicit consent

Art. 6(1)(b) — Performance of contract

Art. 6(1)(a) — Consent (withdrawable at any time)

Art. 6(1)(a) — Consent

Art. 6(1)(f) — Legitimate interest

Art. 6(1)(a) — Consent (via cookie banner)

Art. 6(1)(c) — Legal obligation

Art. 6(1)(f) — Legitimate interest

Art. 6(1)(b) — Steps prior to the contract / Art. 6(1)(a) — Consent

5. Data Sharing — Who receives your data

We do not sell your personal data. We only share it with the following recipients:

5.1 Service providers acting as processors:

Supplier

Wix.com Ltd.

[Booking platform, e.g. bsport]

[Payment processor, e.g. Stripe / Revolut]

Google LLC

Meta Platforms Ireland Ltd.

Email service provider (e.g. Wix Email, Mailchimp)

Accountant or tax advisor

Purpose

Website hosting, CMS, integrated analytics, contact forms

Class scheduling, reservations, package management

Payment processing for classes and memberships

Analytics, Google Business Profile, paid advertising (Google Ads)

Organic and paid Instagram/Facebook content

Newsletter distribution and campaign analytics

Invoicing, VAT, tax returns

Shared data

Technical/connection data, form submissions

Name, email, phone, attendance history

Billing name, transaction amount, card token (not full card numbers)

Aggregated/anonymized usage data; advertising engagement data

Public profile data (when you interact with us); aggregated ad performance

Name, email address, open/click data

Billing name, invoice amounts, tax-relevant data

5.2 Legal authorities:

We may disclose personal data to competent authorities (police, courts, tax agencies) where required by law, court order or to protect our legal rights.

5.3 Transfers to third countries:

Some of our providers (notably Wix.com and Google/Meta) may process data outside the EU/EEA, primarily in the United States. We ensure that these transfers are protected by:

  • Standard Contractual Clauses adopted by the European Commission (Art. 46 GDPR)

  • Supplier certification under the EU-US Data Privacy Framework (where applicable)

  • Additional safeguards such as pseudonymization or encryption

 

We will not transfer your data to a third country without appropriate safeguards in place. You can request a copy of the safeguards applied by contacting us at admin@lagreesantcugat.com .

6. Automated decision-making and profiling

We do not participate in automated preselections that produce legal effects or significantly similar consequences for you (Article 22 GDPR).

We use limited profiles to optimize marketing — for example, creating custom audiences on Instagram or Google Ads based on whether you have visited our site or booked classes. This does not make decisions about you individually; it groups users together for advertising purposes. You can opt out at any time through the platforms’ own advertising settings.

7. Data retention

Data Category

Website analytics and logs

Contact form submissions

Newsletter subscriber details

Member account and booking details

Signed disclaimers

Health/physical data

Payment and billing records

Job applications (when we are looking for staff)

Incident/injury reports

Social media interactions (DMs, comments)

Retention Period

14 months (rolling)

12 months since last interaction

Until cancelled + 3 years (proof of consent)

Membership duration + 4 years

Membership duration + 6 years

Membership duration; deleted on cancellation unless linked to an active incident/claim

6 years

12 months from application (unselected candidates)

6 years from the date of the incident

Duration of your publication/public message + 12 months of archiving

Foundation

Standard analysis practice; can be shortened upon request

Communication tracking window

GDPR Art. 5(2) accountability

Fiscal/accountant (General Tax Law)

Civil liability statute of limitations (Spain)

Purpose limitation; Art. 5(1)(e)

Spanish tax law

Pre-contract obligation period

Civil liability

Communication record

When the retention period expires, we securely delete or anonymize the data. Where deletion is not technically possible (e.g. automated backups), we restrict access until the next backup cycle completes deletion.

8. Cookies and tracking technologies

Our website uses cookies and similar technologies (pixels, web beacons, local storage). Below is the classification and control information.

8.1 Types of cookies we use:

Type

Strictly necessary

Preference cookies

Analytical cookies

Marketing cookies

Third-party cookies

Purpose

Enable basic site functionality (reservation, login, cart)

Remember language, saved classes, display preferences

Measure traffic, page views, user behavior

Provide targeted advertising on Instagram, Facebook, Google

Set for embedded content (Instagram feed, Google Maps, YouTube if embedded)

Examples

Session cookies, Wix security cookies, CSRF tokens

Wix language cookie, site preferences

Wix Analytics, Google Analytics (if enabled)

Meta Pixel, Google Ads tag, remarketing cookies

Instagram embeds, Google Maps, social sharing buttons

Duration

Session or up to 12 months

Up to 12 months

Up to 24 months

Up to 13 months

Established by the respective platform

8.2 Cookie consent:

Our website displays a cookie consent banner on your first visit. You can:

  • Accept all cookies — Full functionality and analytics/marketing enabled

  • Reject non-essential cookies — Only strictly necessary cookies are set; the site remains functional

  • Manage Preferences — Granular Switches by Category

  • Withdraw consent later — Via the Cookie Settings link in the footer of the website or by clearing your browser's cookies

 

Wix includes a built-in cookie consent banner — make sure it's enabled in your Wix dashboard under Settings → Cookie Consent.

8.3 Third-party tracking:

If we run paid advertising through Meta (Instagram/Facebook) or Google, these platforms set their own tracking pixels. These are governed by each platform's respective privacy policy:

  • Meta Privacy Policy: facebook.com/privacy/policy

  • Google Privacy Policy: policies.google.com/privacy

9. Instagram and social networks

We have an active presence on Instagram (@lagreesantcugat) and Google Business Profile. When:

  • Tags in a post or story — We may repost or reuse your content as user-generated content, attributing your handle. We process your public username and the content of your post. We remove any reposts within 48 hours of your request.

  • You send us a DM — We process the content of your message to respond to your inquiry. Messages are retained as described in Section 7.

  • Comments on our posts — Your comment is public and is governed by the Instagram platform policy.

  • You enter a giveaway or promotion — We may collect entries via Instagram comments/DMs and process usernames and any information required solely to administer the promotion.

For all processing on social networks, the legal basis is Art. 6(1)(a) (consent, given by your voluntary interaction) and Art. 6(1)(f) (legitimate interest in community engagement and marketing).

10. Data security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • TLS/SSL encryption for all data transmitted between your browser and our website

  • Passwords encrypted using industry standard hashing (via Wix and booking platform)

  • Access controls — Only authorized study personnel and contracted vendors may access personal data, and only on a known need-to-know basis

  • Secure payment processing — We never store full credit card numbers; all payment data is handled by PCI-DSS compliant providers

  • Regular software updates — Wix platform security patches applied automatically; booking platform updated according to provider schedule

  • Staff training — Instructors and administrative staff trained in data management and confidentiality

Despite these controls, no system can guarantee 100% security. In the event of a personal data breach that affects your rights and freedoms, we will notify the AEPD within 72 hours and the affected individuals without undue delay, as required by Articles 33 and 34 of the GDPR.

11. Your rights

Under the GDPR and Spanish law, you have the following rights:

Law

Access (Art. 15)

Rectification (Art. 16)

Erasure (Art. 17)

Limitation (Art. 18)

Portability (Art. 20)

Opposition (Art. 21)

Withdraw consent (Art. 7(3))

Complaint (Art. 77)

What does it mean?

Request a copy of all personal data we hold about you

Correct inaccurate or incomplete data

Request the deletion of your data, subject to legal retention exceptions

Request that we limit the processing of your data while an investigation is being conducted

Receive your data in a structured and machine-readable format and transfer it to another provider

Object to processing based on legitimate interests or for marketing

Withdraw consent for marketing, health data processing or photo/video use at any time

File a complaint with the Spanish Data Protection Agency (AEPD)

How to exercise your rights:

Send us an email to admin@lagreesantcugat.com with the subject "RGPD Request — [Your Name]". Include:

  1. Your full name

  2. The email address associated with your account (if applicable)

  3. What specific right do you want to exercise?

  4. Any details that help locate your data (class you attended, approximate date of interaction)

 

We will respond within one month (extendable by two more months for complex requests, according to Art. 12(3) GDPR). We will verify your identity before disclosing any personal data.

You also have the right to file a complaint with:

Spanish Data Protection Agency (AEPD) Calle Jorge Juan, 6, 28001 Madrid www.aepd.es Email: dpd@aepd.es

You can contact the AEPD before contacting us if you prefer.

12. Data of minors

Our website and services are not directed to children under the age of 14, except where a parent or guardian enrolls a minor in classes. In this case:

  • Parental consent is obtained for all processing of data related to the minor.

  • Health/physical data of minors are treated as special category data with explicit parental consent.

  • Minors' data is not used for marketing purposes without verified parental consent.

  • Parents can exercise all GDPR rights on behalf of their minor child

13. Links to third-party websites

Our website may contain links to external sites (Instagram, Google Business Profile, payment providers, class booking platform). This Privacy Policy applies only to our website. We are not responsible for the privacy practices of third-party sites and we encourage you to read their respective privacy policies.

14. Changes to this Privacy Policy

We may update this policy periodically to reflect changes in our practices, legal requirements, or service providers. Material changes will be communicated by:

  • A prominent notice on the homepage for at least 30 days

  • An email notification to active members (for material changes to data processing)

The "Last Updated" date at the top of this page indicates when the policy was last reviewed.

15. Contact

For any queries about these Terms and Conditions, you can contact us:

📧 Email: info@lagreesantcugat.com

📍 Location: Catalonia Avenue, 15

bottom of page