Effective Date: 22nd August 2025
Last Updated: 22nd August 2025
1. Introduction
Welcome to NK Boxing (“we”, “us”, “our”). We are committed to protecting and respecting the privacy of our users (“you”, “your”). This Privacy Policy explains what personal data we collect from you, why we collect it, how we use it, who we share it with, and what your rights are in relation to your data.
This policy applies to your use of our website nkboxing.com and the services we offer, including the booking of boxing coaching sessions.
For the purpose of the UK General Data Protection Regulation (UK GDPR), the data controller is:
-
Business/Controller Name: Nida Khalid
2. What Information We Collect About You
We may collect and process the following data about you:
a) Information You Give Us Directly:
-
Identity & Contact Data: Your full name, email address, and phone number when you book a session or contact us through our contact form.
-
Transaction Data: Details about payments to and from you and other details of sessions you have purchased from us.
-
Financial Data: We use third-party payment processors (Stripe, supporting Apple Pay and Google Pay) to handle payments. We do not store your full credit/debit card details on our servers. The payment processor provides us with a confirmation token and transaction details (e.g., last 4 digits of the card, expiry date).
-
Health & Safety Information (Special Category Data): Before your first session, we may ask you to complete a Physical Activity Readiness Questionnaire (PAR-Q) or provide information about your health, injuries, or any conditions relevant to participating safely in boxing. We will only collect this with your explicit consent.
b) Information We Collect Automatically:
-
Technical & Usage Data: When you visit our website, we automatically collect technical information about your device, IP address, browser type and version, time zone setting, operating system, and platform.
-
Behavioural Data: We collect information about your visit, including the pages you viewed, how you navigate our site, mouse movements, clicks, scrolls, and session duration. This is collected via services like Google Analytics and Microsoft Clarity. Microsoft Clarity may record your sessions on our website.
c) Information We Receive from Third Parties:
-
Payment Processors: We receive confirmation of your payment and transaction details from Stripe, Apple Pay, or Google Pay.
3. How and Why We Use Your Information (Legal Basis for Processing)
We will only use your personal data when the law allows us to. Most commonly, we will use your data in the following circumstances and on the following legal bases:
Purpose/Activity | Type of Data | Lawful Basis for Processing |
To register you as a new customer and book your session(s) | Identity, Contact, Transaction | Performance of a contract with you. |
To process your payment for sessions | Identity, Contact, Financial, Transaction | Performance of a contract with you. |
To manage our relationship with you (e.g., sending booking confirmations, reminders, and information about cancellations) | Identity, Contact, Transaction | Performance of a contract with you. |
To manage health and safety requirements for training | Health & Safety Information | Explicit Consent. This is special category data and requires your clear, affirmative consent. |
To respond to your enquiries or support requests | Identity, Contact | Our legitimate interest to respond to our customers and grow our business. |
To administer and protect our business and this website (including troubleshooting, data analysis, security) | Technical, Usage | Our legitimate interest for running our business, provision of administration and IT services, and network security. |
To use data analytics to improve our website, services, and user experience (using Google Analytics, Cloudflare Zaraz, Microsoft Clarity) | Technical, Usage, Behavioural | Your Consent, typically given via our cookie consent banner. |
To comply with our legal obligations (e.g., keeping financial records for tax purposes) | Identity, Contact, Transaction | To comply with a legal obligation. |
To send you marketing communications (if you have opted-in) | Identity, Contact | Your Consent. |
4. Who We Share Your Data With
We do not sell your personal data. We may share your data with trusted third-party service providers who help us operate our business:
-
Payment Processors: Stripe (and its integrated services Apple Pay and Google Pay) to securely process your payments. You can view their privacy policies on their respective websites.
-
Analytics & Website Monitoring Providers:
-
Google Analytics to understand how users interact with our website.
-
Microsoft Clarity to capture user interaction on our website, such as session recordings and heatmaps, to improve user experience.
-
Cloudflare Zaraz to manage and load third-party tools (like Analytics) on our website in a secure and privacy-conscious way.
-
-
Professional Advisers: Our accountants, lawyers, and insurers where necessary for professional advice or to comply with legal and contractual obligations.
-
Governmental Bodies: HM Revenue & Customs (HMRC), regulators, and other authorities who require reporting of processing activities in certain circumstances.
5. International Data Transfers
Some of our third-party service providers (such as Google, Microsoft, and Stripe) are based outside the UK. When we transfer your data to these providers, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
-
The country has been deemed to provide an adequate level of protection for personal data by the UK Government.
-
We use specific contracts approved for use in the UK which give personal data the same protection it has in the UK (such as the UK’s International Data Transfer Agreement or Addendum).
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the UK.
6. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to distinguish you from other users. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site. The services mentioned above (Google Analytics, Microsoft Clarity) use cookies to function.
When you first visit our website, you will be presented with a cookie banner asking for your consent to place non-essential cookies on your device. You can manage your preferences at any time.
7. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. We limit access to your personal data to those employees, agents, and other third parties who have a business need to know.
We have procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
8. Data Retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.
-
Customer & Transaction Data: We are required by UK law to keep basic information about our customers (including Contact, Identity, Financial, and Transaction Data) for six years after they cease being customers for tax purposes.
-
Health & Safety (PAR-Q) Data: Retained for the duration of you being an active client and for a reasonable period thereafter in case of any claims. We will securely delete this data if you do not proceed with sessions.
-
Analytics Data: This is typically anonymised or pseudonymised and may be kept for longer periods as determined by the settings within our analytics providers (e.g., Google Analytics).
9. Your Data Protection Rights
Under UK data protection law, you have rights including:
-
Right of access: You have the right to ask us for copies of your personal information.
-
Right to rectification: You have the right to ask us to rectify personal information you think is inaccurate.
-
Right to erasure (the “right to be forgotten”): You have the right to ask us to erase your personal information in certain circumstances.
-
Right to restriction of processing: You have the right to ask us to restrict the processing of your personal information in certain circumstances.
-
Right to object to processing: You have the right to object to the processing of your personal information in certain circumstances (e.g., for direct marketing).
-
Right to data portability: You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.
-
Right to withdraw consent: Where we are relying on consent to process your data, you can withdraw that consent at any time.
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you. Please contact us at [email protected] if you wish to make a request.
10. Children’s Privacy
Our services are aimed at women and girls. For any individual under the age of 16 wishing to book a session, we require the consent of a parent or legal guardian. We do not knowingly collect personal information from children under the age of 13 without parental consent. If we learn that we have collected such information without consent, we will take steps to delete it.
11. Refund Policy and Data
Our refund policy is that cancellations are only refunded if made more than 48 hours before the scheduled session. We will retain transaction data related to all bookings, including cancelled or non-refunded ones, for the retention periods specified in Section 8 to meet our legal and financial obligations.
12. Links to Other Websites
Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites.
13. Changes to This Privacy Policy
We may update this policy from time to time. The latest version will always be available on our website. We will notify you of any significant changes where we are required to do so.