Privacy Policy

How AWSA collects, uses and protects your personal information, why we do not use analytics or ad trackers, and how to exercise your GDPR and CCPA/CPRA privacy rights.

This Privacy Policy explains how AWSA collects, uses, stores and protects your personal information when you visit awsa.net, contact us, subscribe to our newsletter or use our home-gym coaching services. We built our website to collect as little data as possible, and this page tells you exactly what we do with the information you choose to share with us and what rights you have over it.

event Last updated: October 2, 2026

1. Who We Are and How to Contact Us

AWSA ("AWSA", "we", "us" or "our") operates the website at https://awsa.net,, which offers home-gym education, free training tools and remote coaching. We do not operate a physical gym. Learn more on our About page.

For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, AWSA is the data controller of the personal information described in this policy. For the purposes of the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, "CCPA/CPRA"), AWSA is the business responsible for your personal information.

You can reach us in the following ways:

2. Information We Collect

We collect information you give us directly and limited technical data created when you visit. We do not buy data from brokers or combine your information with third-party sources.

2.1 Contact form

When you use the form on our Contact page, we collect your name, email address, phone number (optional), the service you are interested in, your preferred contact method, your message, and a record that you ticked the consent checkbox, with the date and time of submission.

2.2 Newsletter

If you subscribe, we collect only your email address and a record of when you subscribed.

2.3 Coaching and service intake information

If you purchase or enquire about one of our services, we may ask you to complete an intake questionnaire or share information during a video call. Depending on the service, this may include:

  • Age range, height, body weight, training history and fitness goals
  • Your space, equipment, budget and schedule
  • Dietary preferences and food intolerances (for nutrition planning)
  • Injuries, pain, medical conditions, medications, pregnancy or other health matters that may affect your training
  • Progress information you choose to send, such as workout logs, measurements or photos
info
Good to know: Information about your health, injuries, medical conditions or body is considered "special category data" under the GDPR and UK GDPR and "sensitive personal information" under the CCPA/CPRA. You are never required to share it. If you choose to provide it, we ask for your explicit consent and use it only to make your coaching safer and more relevant to you.

2.4 Billing information

When you buy a service, we keep records of your name, email address, the service purchased, the amount, the invoice number and the payment status. Payments are handled through an invoice or a secure payment link provided by our payment processor. We never see or store your full card number, security code or bank login details.

2.5 Technical information and server logs

Our hosting provider automatically records basic server logs when your browser requests a page, such as your IP address, date and time, page requested, browser type and referring page. These logs are used for security, troubleshooting and abuse prevention. We do not use them to profile visitors, and we run no analytics software.

2.6 Information stored in your browser

We store two small preference items in your browser's local storage. They stay on your device and are not sent to us. See Section 13.

3. How We Use Your Information

We use your personal information only for the purposes listed below:

  • To respond to your enquiries using your preferred contact method.
  • To deliver our services, including consultations, training programs, nutrition plans and ongoing coaching.
  • To tailor programs safely around injuries or health conditions you tell us about.
  • To send our newsletter, if you have subscribed.
  • To issue invoices and keep accounting records as required by law.
  • To keep our website secure and fix technical problems.
  • To comply with legal obligations and handle legal claims.

We do not use your information for automated decision-making, profiling or targeted advertising.

If you are in the European Economic Area (EEA) or the United Kingdom, we must have a legal basis for each way we use your personal information. The table below sets out our purposes, the data involved, the legal basis we rely on and how long we keep the data.

PurposeData usedLegal basisRetention
Responding to contact form and email enquiriesName, email, phone (optional), service of interest, preferred contact method, message, consent recordConsent (Art. 6(1)(a)) and steps prior to entering a contract (Art. 6(1)(b))Up to 12 months after our last communication if you do not become a client
Sending the newsletterEmail address, subscription recordConsent (Art. 6(1)(a))Until you unsubscribe; the opt-out record is kept so we do not email you again
Delivering coaching and other servicesContact details, goals, training history, equipment, schedule, progress informationPerformance of a contract (Art. 6(1)(b))Duration of the service plus 24 months
Using health and fitness information to tailor programsInjuries, medical conditions, medications, pregnancy, body measurements, photosExplicit consent (Art. 9(2)(a)) together with Art. 6(1)(b)Duration of the service plus 24 months, or earlier if you withdraw consent
Invoicing and accountingName, email, service purchased, amount, invoice and payment statusLegal obligation (Art. 6(1)(c))As long as required by tax and accounting law, typically 6 to 7 years
Website security and troubleshootingServer log data such as IP address, browser and request detailsLegitimate interests (Art. 6(1)(f)) in keeping the site secure and workingTypically up to 30 days, as set by our hosting provider
Remembering your cookie choice and tool preferencesLocal storage values on your deviceStrictly necessary or at your request; stored only on your deviceUntil you clear your browser storage
Legal claims and complianceAny relevant recordsLegitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c))For as long as needed to resolve the matter

Where we rely on legitimate interests, we have balanced our interests against your rights and concluded that the processing is limited, expected and low-risk. You can object to it at any time (see Section 10).

5. How Long We Keep Your Information

We keep personal information only as long as we need it for the purposes above. Our standard periods are set out in the table in Section 4. In short, enquiries that do not lead to a service are deleted within 12 months; client records, including health information, are kept for the length of your service plus 24 months (or deleted sooner if you withdraw consent for health data); financial records are kept as long as tax law requires; and server logs are typically kept for no more than 30 days. After you unsubscribe from the newsletter, we keep your email on a suppression list so we never email you again. When a retention period ends, we securely delete or anonymize the information.

6. How We Share Your Information

We do not sell, rent or trade your personal information. We share it only with a few trusted service providers, and only as far as they need it to work for us:

RecipientPurposeData shared
Website hosting providerHosting the website and generating security logsServer log data
Email and newsletter providerReceiving form submissions, sending replies and delivering the newsletterName, email address, message content, subscription status
Payment processorIssuing invoices and processing payments through secure payment linksName, email address, service and amount; the processor collects your payment details directly
Video call providerHosting consultation and coaching callsName, email address and anything you share during the call

These providers act as our processors (service providers under the CCPA/CPRA) and are contractually bound to protect your information and use it only on our instructions. The payment processor may also act as an independent controller for its own legal duties, such as fraud prevention.

We may also disclose information if required by law, to protect the rights or safety of AWSA or others, or as part of a business transfer, in which case we will tell you first.

info
Good to know: AWSA does not sell personal information and does not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not done so in the past 12 months. We also do not knowingly sell or share the personal information of anyone under 16.

7. International Data Transfers

Our service providers may process personal information in other countries, including the United States, the UK and the EEA, where data protection laws may differ from yours. When we transfer data out of the EEA or the UK, we rely on appropriate safeguards, such as adequacy decisions (including the EU-US Data Privacy Framework and its UK extension), Standard Contractual Clauses with the UK International Data Transfer Addendum, or other lawful mechanisms.

You can ask us for more information about the safeguards we use by emailing [email protected].

8. How We Protect Your Information

We use reasonable technical and organizational measures to protect your information, including:

  • HTTPS encryption for all website traffic;
  • A static website with self-hosted fonts and scripts, so no third parties receive visitor data by default;
  • Restricting access to client records, especially health information;
  • Strong passwords and multi-factor authentication on our business accounts; and
  • Never storing payment card data ourselves.

No system is completely secure. If a data breach is likely to put your rights at risk, we will notify you and the relevant authorities as required by law.

9. Your Rights Under the GDPR and UK GDPR

If you are in the EEA or the UK, you have the following rights over your personal information:

  • Right of access: ask for a copy of the personal information we hold about you.
  • Right to rectification: ask us to correct information that is inaccurate or incomplete.
  • Right to erasure: ask us to delete your information where we no longer have a valid reason to keep it.
  • Right to restrict processing: ask us to pause using your information in certain situations.
  • Right to data portability: receive the information you gave us in a machine-readable format, or have it sent to another organization.
  • Right to object: object to processing based on legitimate interests, and to direct marketing at any time.
  • Right to withdraw consent: withdraw consent, including explicit consent for health information, at any time, without affecting earlier processing.
  • Rights related to automated decision-making: we do not make decisions about you based solely on automated processing.

10. Your Rights Under the CCPA/CPRA

If you are a California resident, you have the following rights, subject to certain exceptions:

  • Right to know: request the categories and specific pieces of personal information we hold about you, its sources, our purposes and who we disclose it to.
  • Right to delete: request that we delete personal information we collected from you.
  • Right to correct: request that we correct inaccurate personal information.
  • Right to opt out of sale or sharing: we do not sell or share personal information, so there is nothing to opt out of.
  • Right to limit use of sensitive personal information: we use health information only to provide the services you request, a permitted purpose under the CCPA/CPRA.
  • Right to non-discrimination: we will not deny services, charge different prices or reduce quality because you exercised your rights.

In the past 12 months, we have collected the following categories of personal information as defined by the CCPA/CPRA: identifiers (such as name, email address, phone number and IP address); commercial information (services purchased); internet or network activity (server log data); and sensitive personal information (health information you voluntarily provide for coaching). The sources, purposes and recipients are described in Sections 2, 3 and 6 of this policy.

11. How to Exercise Your Rights

Email [email protected] or use our Contact page, telling us which right you want to exercise and the email address you used with us.

Verification

We must verify your identity before acting on a request, usually by asking you to confirm it from the email address we have on file. For sensitive information, we may ask for extra details that match our records, used only for verification.

Response times

  • GDPR and UK GDPR requests: we will respond within 30 days (one calendar month) of receiving your request. For complex or multiple requests, we may extend this by up to two further months, and we will tell you if we need to.
  • CCPA/CPRA requests: we will confirm receipt within 10 business days and respond within 45 days. If we need more time, we may extend this by a further 45 days and will let you know why.

Exercising your rights is free, though we may refuse or charge a reasonable fee for clearly unfounded or excessive requests.

Authorized agents

California residents may use an authorized agent. We will ask for written permission signed by you and may ask you to verify your identity directly, unless the agent holds a valid power of attorney. Others may also appoint someone to act for them with proof of authority.

12. Children's Privacy

Our website and services are intended for adults. Our website is not directed at children under 16, and our coaching services are available only to people aged 18 or over, as explained in our Terms of Service. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact [email protected] and we will delete it promptly.

13. Cookies and Local Storage

We do not set any HTTP cookies of our own, and no third-party cookies are set by default. We use browser local storage only for awsa_cookie_consent (your cookie banner choice) and awsa_tools_prefs (your training tool preferences, such as units and timer settings). Both remain until you clear your browser storage.

This information stays on your device and is not sent to us or anyone else. We do not use analytics, advertising cookies, tracking pixels or fingerprinting. For full details and instructions on how to clear this information, see our Cookie Policy.

14. Third-Party Content (YouTube Videos)

Some of our articles include YouTube videos. To protect your privacy, these videos are click-to-load and use YouTube's privacy-enhanced mode (youtube-nocookie.com). Nothing is loaded from YouTube until you click the play button. Before you click, YouTube receives no information about your visit.

Once you click play, YouTube may receive your IP address and device information and store data on your device, and YouTube's own terms and privacy policy apply. If you prefer not to share data with YouTube, do not load the video.

15. Do Not Track and Global Privacy Control

Some browsers send "Do Not Track" (DNT) or Global Privacy Control (GPC) signals. Because we do not track visitors, use analytics or advertising technologies, or sell or share personal information, our website already behaves the way these signals request. Where the law requires, we treat GPC as a valid opt-out request.

16. Changes to This Privacy Policy

We may update this policy to reflect changes in our services, providers or the law. We will update the "Last updated" date above and, for significant changes, take reasonable steps to tell you, such as by email if you are a client or subscriber.

17. Contact Us and Complaints

For questions or complaints about how we handle your information, please contact us first at [email protected] and we will do our best to resolve it.

You also have the right to lodge a complaint with a data protection supervisory authority:

  • In the UK: the Information Commissioner's Office (ICO).
  • In the EEA: the data protection authority in the country where you live, work or where you believe the issue occurred.
  • In California: the California Privacy Protection Agency or the California Attorney General.

For other questions about our website or services, you can reach us at [email protected] or through our Contact page. You may also find answers on our FAQ page.