PRIVACY POLICY

Introduction

Essence Pilates is a limited liability company dedicated to guiding people back to themselves — through movement that is thoughtful, grounded, and alive.

We believe in the quiet power of consistent practice, the intelligence of the original method, and the beauty of meeting each person exactly where they are.

This work is rooted in presence and shaped by care. More than building strong bodies, we’re here to nurture confidence, clarity, and connection — both on and off the mat.

Essence Pilates is a boutique studio committed to the original principles of the Pilates method. Our philosophy is rooted in mindful movement, precision, and a deep connection between mind and body. In an intimate and welcoming environment, we guide clients through personalized programs that promote strength, balance, and lasting vitality.

In line with this mission, Essence Pilates is committed to safeguarding the personal data entrusted to us.

We ensure that all personal data is processed in compliance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons regarding the processing of personal data and the free movement of such data, repealing Directive 95/46/EC (“GDPR”), as well as any applicable national laws.

This privacy policy applies whenever you interact with our services, activities, publications, events, website visitors, donors…, etc. (This list is not exhaustive).

All data protection terms used throughout this policy have the meaning assigned to them in the General Data Protection Regulation (GDPR) unless a derogatory definition has been provided for them in the policy itself.

Please read this policy carefully to understand how we collect, use, and manage your personal data.


Article 1: Data Controller and Contact Information

The data controller responsible for your personal data and your point of contact for privacy-related queries is Essence Pilates. If you have any questions regarding this privacy policy, please contact us at:

Email Address:

hello@essencepilates.lu


Article 2: Purposes, Legal Basis, and Categories of Data Processed

We collect your personal information from various sources, including directly from you (e.g., through forms, correspondence, or conversations) and, where applicable, from third parties (e.g., public sources).

This is done to fulfill our obligations under applicable laws, provide our services effectively, and for other legitimate purposes. For example, we may collect personal data to comply with tax requirements, maintain accurate records, or meet regulatory obligations.

We process your personal data for the following purposes and based on the following legal bases under Article 6 of the GDPR:

Membership Administration (Performance of a contract that you are party or for pre-contractual measures): Name, address, email, and membership start date.

Class booking Management (Performance of a contract that you are party or for pre-contractual measures): Name, address, and email for communication.

Payment Processing e.g. (Performance of a contract): Name, contact details, bank/payment card information

Newsletter Distribution (Consent): Name and email for informing about the studio’s activities.

Client Feedback & T estimonials (Consent): Name, feedback/testimonial, and optionally a photo for promotional use to demonstrate progress and success, if agreed via release form.

We do not process personal data of individuals under 16 years of age without written consent from a parent or legal guardian.In exceptional cases, we may process sensitive personal data (e.g., health and safety information like previous injuries and relevant medical history that may affect participation in Pilates classes) strictly within the scope of our legitimate activities and with appropriate safeguards.

Explicit consent will be obtained for any other purposes. The consent can be withdrawn at any time without affecting the lawfulness of the processing carried out before withdrawal.

Cookie Policy

Essence Pilates only collects strictly necessary cookies that are essential for the functioning of our website. We do not collect non-essential cookies, such as those used for behavioral analysis or advertising.


Article 3: Recipients of Personal Data

We do not share your personal data with any third parties.

We commit to the following principles regarding data sharing:

We will not collect or share more data than is necessary for our legitimate activities and purposes.

We will not sell your data to third parties.

We will not use your data for purposes beyond those stated in this policy.

We do not transfer personal data outside the European Economic Area.


Article 4: Data Retention

We retain personal data for up to 1 year following specific events such as cancellation of membership.

Data processed for membership fee management is retained for 2 months after the closure of annual financial accounts. Data may be retained longer in case of legal or regulatory obligations or ongoing disputes.If you wish to request data deletion, please contact us using the contact details provided above.


Article 5: Newsletters

If you sign up to our newsletter, we will send you information about services and updates relating to our classes, events and other targeted communications. You may unsubscribe from our newsletters at any time by clicking the “unsubscribe” link at the bottom of our emails or send an email to (hello@essencepilates.lu)


Article 6: Your Rights

Under the GDPR, you have the right to:

Access Your Data: Obtain a copy of the personal data we hold about you (Article 15 GDPR).

Rectification: Request correction of inaccurate or incomplete data (Article 16 GDPR).

Objection: Object to data processing unless the processing is necessary for the performance of a task carried out in the public interest, or for the purposes of legitimate interests pursued by [insert company name] (Article 21 GDPR).

Erasure: Request deletion of your data (“right to be forgotten”) (Article 17 GDPR).

Data Portability: Receive your data in a structured, commonly used, and machine readable format (Article 20 GDPR).

Restriction: Request restriction of processing under certain conditions (Article 18 GDPR).

To exercise these rights, please contact us using the email or postal address provided above.


Article 7: Complaints

If you have concerns or complaints about the way we handle, process, or protect your data, please contact us in the first instance using the contact details provided above.

If you believe your data has been processed in violation of the GDPR, you may lodge a complaint with the relevant data protection authority. For more information, visit: https://cnpd.public.lu.