Download PDF

Privacy Policy

1. What Does This Privacy Policy Mean?

This Privacy Policy (hereinafter in the text – the Privacy Policy) not only defines the terms that must be observed by all visitors of the website lemongym.ee (hereinafter in the text – the Website), users of the Lemon Gym mobile application downloadable from iTunes and Google Play (hereinafter in the text – the Application), recipients of the services of Lemon Gym OÜ (hereinafter in the text – Lemon Gym), persons who have engaged in active online activities on Lemon Gym social media accounts, persons who have agreed to receive Lemon Gym marketing materials, persons participating in Lemon Gym events, Lemon Gym clients (hereinafter in the text – the Clients), but also sets out the main rules for the processing of Personal Data which the Clients must follow.

A Client shall be deemed to have familiarized themselves with and agreed to comply with the Privacy Policy if the Client visits the Website, downloads the Application, purchases a service, visits Lemon Gym social media accounts, agrees to receive Lemon Gym direct marketing notifications, contacts Lemon Gym in connection with applying for a job, or visits Lemon Gym events. If the Client does not agree with any provision of the Privacy Policy, the Client loses the right to visit the Website, use the Application, use any services provided by Lemon Gym, contact Lemon Gym in connection with applying for a job, or engage in active activities on Lemon Gym social media accounts.


2. About Lemon Gym

Lemon Gym OÜ, registry code 14091160, legal address Mustakivi tee 17, 13912 Tallinn, Estonia. Contact for obtaining information: info@lemongym.ee.


3. What Are Personal Data?

Personal Data means any information collected by Lemon Gym about a Client that may be used to identify the Client and that is stored electronically or otherwise.

Personal Data includes any information (including the Client’s first name, last name, address, IP address) that Lemon Gym collects about Clients under this Privacy Policy, based on the Client’s separate consent or agreement, for a purpose defined by Lemon Gym.

Such data also includes publicly available personal information about Clients that Lemon Gym accesses when the Client contacts Lemon Gym via social media or engages in active activities on Lemon Gym social media accounts.


4. How Lemon Gym Collects and Uses Clients’ Personal Data

Lemon Gym needs Clients’ Personal Data, which may be collected in the ways described below.

In this Privacy Policy, we set out what should be taken into account when the company collects personal data about:

  • persons who use Lemon Gym services or purchase products sold by Lemon Gym;
  • persons who agree to receive Lemon Gym marketing materials;
  • persons who have contacted Lemon Gym;
  • Website visitors;
  • persons who use the Application;
  • users of social media tools who, in any way, contact Lemon Gym through Lemon Gym social media accounts or participate there through active activities;
  • persons who participate in Lemon Gym events;
  • job applicants.

Processing of Personal Data for the Provision of Services

Purpose of processingPersonal Data processedRetention periodLegal basis
Conclusion of a contract, sale and provision of servicesFirst name, last name, e-mail address, date of birth, place of residence (address), phone number, purchase-related information (purchase date, description of service, price, discount granted). Parents’ (if the service recipient is a minor) first name, last name, date of birth, place of residence, e-mail address, phone number. These data are mandatory; if not provided, we cannot provide services to you.Documents confirming the conclusion of contracts are retained for 10 years from the date of termination of the contract. Client account data are retained for 5 years from the Client’s last login to the client account or the Client’s last purchase date.Performance of a contract.
Provision of services when using the ApplicationE-mail address, session ID, first name, last name5 years from the Client’s last loginPerformance of a contract (as applicable).
Identification of Clients for the purpose of granting access to Lemon Gym sports clubsFirst name, last name, e-mail address, date of birth, place of residence (address), phone number, identity document (presented only if the person does not agree to be identifiable in another way)For the validity period of the membershipConclusion/performance of the contract.
Client’s (from 18 years) fingerprint data, person’s photo (if fingerprint is not provided)Consent.

5. Direct Marketing

Purpose of processingPersonal Data processedRetention periodLegal basis
Sending offers, newsletters and announcements to clients and other interested persons by e-mailFirst name, last name, e-mail address (mandatory data without which we cannot send direct marketing messages to you)While you are an active Client of Lemon Gym and for two years after the end of the contractBy purchasing Membership you become our client; therefore, based on the Electronic Communications Act (ERĮ) Article 81, Part 2, we have the right to send newsletters to the e-mail address provided by you regarding purchased goods and services. Please note that if you object, you can unsubscribe at any time by clicking the unsubscribe button at the bottom of each newsletter.
Organising lotteries and gamesPhotos, video material; if necessary for participation, the winner’s residential addressUntil the winner is determined and for 1 year after winningConsent (GDPR Article 6(1)(a)).

We send persons who have provided their contact details and expressed a wish to receive information about goods and/or services offered by Lemon Gym, by electronic means of communication (e-mail, SMS), offers regarding the provision of Lemon Gym services or sale of goods, newsletters and other advertising material, invitations to sales campaigns, requests for feedback on services provided, and information about Lemon Gym sports club news and the procedure for providing services.

For direct marketing purposes, Lemon Gym processes the following personal data: first name, last name, e-mail address (mandatory data without which we cannot send you direct marketing notifications); data confirming the right to participate in promotional campaigns; data regarding promotional campaign conditions confirming eligibility; documents fulfilling the promotional campaign conditions (mandatory for participation in campaigns); address, gender, marital status, workplace, number of children (non-mandatory data).

If you are our Client and do not opt out of Lemon Gym direct marketing notifications, we will send you, based on our legitimate interest, e-mail notifications about goods or services similar to the services already provided to you or goods already sold to you.

You have the right at any time to opt out of receiving direct marketing notifications by contacting us via e-mail: info@lemongym.ee.

If you are 14 years old, you may provide consent yourself to receive direct marketing notifications; however, if you are not yet 14 years old, we will request your parents’ consent. In such case, we ask you to provide your parents’ or guardians’ first name, last name and e-mail address, to whom we will send a request regarding such consent. Lemon Gym processes the Personal Data listed in this clause for 1 (one) year after receiving consent and then deletes such data.

For direct marketing purposes, your data are transferred to the following companies belonging to the same group:

Business nameDataLegal basisRetention periodData Protection Specialist and contact details
Lemon Gym OÜClient’s first name, last name, e-mail addressConsent1 year from receiving consentinfo@lemongym.ee

Your e-mail address is transferred to the social media networks “Facebook” and “LinkedIn” so that you may see Lemon Gym advertising.


6. Contacting Us

The Website provides several ways to contact Lemon Gym. We receive all notifications, review them and provide responses. To contact us via the Website, please provide your first name, last name, e-mail address, phone number, the Lemon Gym sports club you visit, and the content of your message.

If you contact us by e-mail, we process the following data: your first name, last name, e-mail address, and correspondence between us.

Such data are processed for the purpose of preparing to perform the contract or responding to your questions. If you do not provide your contact details, it is not possible to contact you.

Please note that the Website may use e-mail tracking or blocking software, and you must ensure that the messages you send do not contain unlawful content.

Correspondence is retained for 1 (one) year from receipt of the notification, except where other retention periods are specified in this Privacy Policy or by law.

All Personal Data you provide when communicating with us is used only for the purposes described above and for reviewing notifications and managing communication flows. We undertake not to use your personal data in any publications, without your explicit consent, in a manner that would allow your identity to be determined.

Please note that we may contact you by mail, e-mail or telephone. Please notify us of any changes to your personal data.


7. Website Visitors

You may register on the Website and create a personal account if you are at least 18 years old. All information you provide to Lemon Gym when becoming a registered Client is recorded and retained with your consent, in accordance with the terms of the Privacy Policy. If we reasonably find that you have violated any provision of this Privacy Policy, we have the right to block your Client account at any time. If you know or suspect that a third party has learned your username or password, you must notify us as soon as possible by e-mail: info@lemongym.ee.


8. Cookies

A cookie is a small text and number file that we store in your web browser or on your computer’s hard drive with your consent. We use different cookies for different purposes. Cookies also help us distinguish you from other Website users, thereby ensuring a more pleasant user experience and enabling us to improve the Website.

Most browsers allow you to reject all cookies. However, some browsers allow you to reject only third-party cookies. You may use these options, but please note that blocking all cookies will negatively affect the use of the Website and, without cookies, you may not be able to use all services of the Website.

We use the following cookies; a detailed list is available HERE:

Strictly necessary cookies

These cookies are necessary for the Website to function. The legal basis for processing data via such cookies is the performance of the contract when visiting the Website and ensuring the quality and security of visits by Lemon Gym. These may include cookies that enable the Client to log in to an account on the Website and access protected areas of the Website, use the shopping cart function, or other services.

Analytical cookies

These cookies allow Lemon Gym to recognize and count Website visitors and to track how visitors move around the Website. This helps Lemon Gym improve the Website’s operation and ensure that users can easily find what they are looking for. The legal basis for processing data collected by these cookies is the Clients’ consent.

Functional cookies

These cookies are used to recognize Clients when they return to the Website, so that Lemon Gym can tailor the presented content to Clients’ needs and remember information relevant to Clients. The legal basis for processing data collected by these cookies is the Clients’ consent.


Third-Party Services

Each time a Client visits the Website, third-party software “Google Analytics” is used on behalf of and in the legitimate interests of Lemon Gym, and information is collected about how Clients use the Website; for example, Clients’ activities on the Website are recorded and visitor behavior patterns are determined. This service is used to determine how many people visit the Website and which parts they are interested in. The collected information helps explain how the Website works and how Lemon Gym could improve it. Lemon Gym does not identify Clients’ identities and does not allow the “Google Analytics” program to do so.


Social Media

All information you provide to us via social media (including use of the “Like” and “Follow” functions and other communications) is controlled by the administrator of the social network.

The Website contains links to our social media accounts. Currently we have the following social media accounts:

We recommend reading the privacy policies of the third parties (see the links in brackets above) and contacting the service providers directly if you have any questions about how they use your personal data.


Participation in Lemon Gym Events

With your consent, we use your first name, last name, information about participation in Lemon Gym events, and photos from Lemon Gym events for informing about Lemon Gym events. We ensure that the use of such photos does not infringe your honor and dignity. With your consent, your photos may be published on Lemon Gym social media accounts and on the Website.

Media representatives may publish your photos only in compliance with legal requirements applicable to them; however, Lemon Gym is not responsible for the actions of media representatives.

Photos are published and retained for 3 years after the event takes place, unless other exceptions are provided by law.


Processing of Personal Data When Applying for a Job

When applying for a job, we collect and process, for the purpose of selecting employees and with your consent as a job applicant, your CV and/or motivation letter and/or other information provided by you that you submit to us or to the recruitment company.

If you do not submit your CV and/or motivation letter, we cannot assess your suitability for the offered position.

If you do not provide us with your consent to process your personal data, we are obliged to delete and/or destroy your personal data within 5 (five) business days.


Disclosure of Data

We may disclose information about you to our employees, managers, intermediaries, service providers or subcontractors if this is reasonably necessary for the purposes described in this Privacy Policy.

Among other things, we use the customer data management web service and system PerfectGym provided by Perfect Gym Solutions S.A. when concluding an Agreement with you, providing Services to you, processing your personal data, and sending you direct marketing notifications. The controllers of Clients’ personal data processed in the PerfectGym system are we and Perfect Gym Solutions S.A. independently. The terms of service and data protection terms of PerfectGym are available at: https://www.perfectgym.com/en/terms.

In addition, we may disclose information about you:

  • if we are required to do so by law;
  • to protect our rights or interests (including transferring your data to third parties for the purpose of collecting debts from you);
  • if we intend to sell the company’s business or part of its assets, disclosing your personal data to a potential buyer of the business or such part;
  • if we sell the company’s business or its main asset to third parties.

Your Personal Data will not be transferred to a third country and/or an international organization.

Except as provided in this Privacy Policy, we do not provide your personal data to third parties.

The list of recipients or categories of recipients described in this Privacy Policy may change; therefore, if you wish to be informed about changes to the recipients of your personal data, please notify us by e-mail at info@lemongym.ee, indicating in the text of the letter: “I wish to receive information about changes to the recipients of my personal data, first name, last name.”


Third-Party Materials and Third-Party Websites

Our Website and Application may contain third-party advertisements. Such third parties are solely responsible for the content of such advertisements and are obliged to ensure compliance with applicable laws.

You may visit third-party websites at your own risk. We assume no direct or indirect liability for the content on such websites, the accuracy of information, opinions expressed, or the quality of goods and services offered.

Our informational materials may contain information sourced from third-party websites. Materials obtained from a third-party website will be marked accordingly, and may include a reference to the original website. We assume no liability for data obtained from a third-party website and presented as a reference in informational material intended for you, nor for the personal data used by such third parties.


Security of Your Personal Data

Your personal data are processed in accordance with the requirements of the General Data Protection Regulation, the Estonian Personal Data Protection Act, and other relevant legislation. When processing your personal data, we implement appropriate technical and organizational measures that ensure protection of personal data against accidental or unlawful destruction, alteration, disclosure, or other unlawful processing.


Your Rights

In this section, we provide information about your rights in relation to our processing of your personal data and also about when you may exercise these rights. If you wish to receive more information about your rights or to exercise them, please contact us by e-mail: info@lemongym.ee.

Lemon Gym shall provide you, without undue delay and at the latest within 1 (one) month from receipt of the request, with information on the actions taken in response to your request regarding the exercise of your rights. Taking into account the complexity of the request and the number of requests received, this period may be extended by a further 2 (two) months. In such case, we will inform you within 1 (one) month from receipt of the request about such extension and the reasons for it. Lemon Gym refuses to fulfill your rights only in cases provided for by law.

Right to Withdraw Consent

If you have given us explicit consent for the processing of your personal data, you may withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Right of Access to Your Personal Data

We want you to understand how we use your personal data and to avoid any inconvenience in this regard. You may contact us at any time to ask whether we process personal data relating to you. If we store or otherwise use your personal data, you have the right to access them. To do so, submit a written request by e-mail to info@lemongym.ee and confirm your identity.

Right to Request More Information

We understand that it is very difficult to describe all possible ways of collecting and using personal data. We strive to provide the clearest and most comprehensive information possible and undertake to update this Privacy Policy when data processing activities change. If you still have questions about the use of your personal data, we will gladly answer them and provide any additional information we can disclose. If you have specific questions or did not understand the information provided, please contact us.

Additional Rights

Below we provide information about additional rights you may exercise in accordance with the procedure described below.

  • You have the right to request correction of any inaccurate data. In such case, we may ask you to confirm the corrected information.
  • You have the right to request deletion of your personal data. Please note that we can fulfill such a request only if:
    • your Personal Data are not necessary for the purposes for which they were originally collected (for example, we need your personal data to respond to your messages);
    • laws prohibit us from collecting, storing or using Personal Data;
    • your personal data are not necessary due to a legal obligation or for the establishment, exercise or defense of legal claims, for example in court proceedings.
  • You have the right to request restriction of processing of your personal data and/or to object to the processing of personal data concerning you:
    • for the period necessary for us to verify the accuracy of your personal data if you dispute the accuracy of the data;
    • if our collection, storage or use of your personal data is unlawful, but you decide not to request deletion;
    • if we no longer need your personal data, but you need them to establish, exercise or defend legal claims;
    • for the period necessary to determine whether we have overriding legal grounds for further processing of your personal data, if you have exercised your right to object to processing.
  • With your consent or for the purposes of concluding a contract, you have the right to data portability. When exercising this right, we will provide, at your request, a copy of the data you have provided.
  • You have the right to object to our use of your personal data:
    • where we use such data to pursue our legitimate interests but do not have overriding legal grounds to continue processing; or
    • at any time when we use your personal data for sending newsletters or for direct marketing purposes. In such case, the data will no longer be used for those purposes, but may be used for other lawful purposes.

Complaints

If you believe that your rights as a data subject have been and/or may be violated, please contact us immediately at info@lemongym.ee. We ensure that as soon as we receive your complaint, we will contact you within a reasonable time and inform you of the progress of the investigation and subsequently of the outcome.

If you are not satisfied with the outcome, you may submit a complaint to the supervisory authority – the national data protection inspectorate, i.e. in Estonia the Data Protection Inspectorate (www.aki.ee).


Liability

You are responsible for keeping your password and the confidentiality of the data you submit, and for other actions (data transfer, submitted orders, etc.) carried out on our Website and/or in the Application while logged in with your credentials. You must not disclose your password to third parties. If a third party uses the services provided on our Website and/or Application while logged in with your credentials, we will consider that you are the person logged in. If you lose your login details, you must notify us immediately by mail, telephone, fax or e-mail.

You are responsible for ensuring that the data you provide to us are accurate, correct and complete. If your data change, you must notify us immediately by updating the relevant data in the registration form, or if the data are not shown in the registration form, by notifying us by e-mail. We are not liable in any way for damage you suffer due to providing incorrect or incomplete personal data or failing to notify us of changes to your data.


Changes to the Privacy Policy

We may update or amend this Privacy Policy at any time. The updated or amended Privacy Policy enters into force from the moment it is published on our Website and/or in the Application. You should periodically check and ensure that the current version of the Privacy Policy is suitable for you.

When updating the Privacy Policy, we will notify you of material changes by publishing them on the Website and/or in the Application(s). If you log in to the Website and/or the Application after such notice is published, you agree to the new requirements indicated in the update.


Cookie List

Cookie namePurposeTime of creationValidity periodType of cookie (strictly necessary, analytical, functional)Data used
showRegistrationFormwhether to display the registration form / popup to the Clientupon Client’s visit to the Website1 daysession ID
__cfduidthe “__cfduid” cookie is set by the CloudFlare service to ensure trusted web traffic. It does not correspond to any user name in the web application. The cookie also does not store any personally identifiable informationupon Client’s visit to the Website1 year
doubleclick.net / test_cookieto check whether the user’s web browser supports cookiesupon Client’s visit to the Website15 min
paysera.lt / PHPSESSIDfor session identificationupon Client’s visit to the Website1 daysession ID
onesignal.comto check whether the user has agreed to receive browser notifications (push notifications)upon Client’s visit to the Website
facebook.com / actto optimize Website speedupon Client’s visit to the Websiteuntil end of session
facebook.com / c_userto check whether the user is logged inupon Client’s visit to the Website30 daysuser ID
facebook.com / datrto track user behaviorupon Client’s visit to the Website2 years
facebook.com / frfor advertising purposesupon Client’s visit to the Website2 years
facebook.com / luto check the Client’s registration statusupon Client’s visit to the Website2 years
facebook.com / presencea cookie for the “Facebook” network enabling “Facebook” chat featuresupon Client’s visit to the Websiteuntil end of session
facebook.com / sba cookie for the “Facebook” network enabling advertising displayupon Client’s visit to the Website2 years
facebook.com / xsan analytical cookie of the “Facebook” network identifying the user, application or websiteupon Client’s visit to the Website60 days