YOUR INFORMATION

Privacy
Notice.

This notice explains how Change in Motion collects, uses, shares, protects and retains personal information.

Data controller: Temple Bruer Consulting Ltd, company number 13190792, trading as Change in Motion.
Registered address: The Dovecote, Temple Farm, Temple Bruer, Lincoln, LN5 0DG.
Privacy contact: hello@changeinmotionlabs.com

Our services are for adults aged 18 and over. Last updated: 5 September 2026.

1. When this notice applies

When you use our website, contact us, make a booking, complete screening or consent forms, attend an assessment, provide device data, receive a report, make a payment, or contact us about a complaint or incident.

2. Information we collect

Identity and contact details; booking, contract and payment records; health screening, symptoms, medication, pregnancy status where relevant, injuries and allergies; physiological, performance, gait, strength, hydration and body-composition data; reports, goals and recommendations; technical website data; correspondence, complaints and incident records. Stripe normally handles full payment-card details; we do not store them.

3. Where information comes from

Most information comes directly from you through Acuity, conversations, bookings, assessments and connected devices. Test data may come from SpiroFit, Wahoo, Wattbike, Train.Red, Runeasi, VALD, hDrop and the confirmed body-composition system. Information may also come from a person you authorise, Stripe, Microsoft 365, our website provider, emergency responders, insurers, advisers or regulators where necessary and lawful.

4. Why we use information

To respond to enquiries, arrange appointments, administer contracts, take payment, screen readiness, deliver testing safely, analyse results, prepare reports, provide agreed follow-up guidance, protect our systems, maintain accounts, and manage incidents, complaints, insurance matters and legal duties. Our Article 6 bases are normally contract, legal obligation and legitimate interests. Where health data is required, we generally rely on explicit consent under Article 9(2)(a).

5. What you must provide

Contact, booking and payment information is normally required to administer the contract. Relevant health screening and test data is required where objectively necessary to assess readiness and deliver the selected service. Without required information, we may be unable to accept a booking, may modify or stop a test, or may be unable to produce a reliable report. Marketing preferences, testimonials and promotional imagery are optional.

6. Who we share information with

We disclose only what is reasonably necessary. Recipients may include Acuity, Stripe, Microsoft 365, website hosting and IT-support providers; performance-device and cloud-platform providers; accountants, banks and advisers; approved reporting providers; insurers, emergency services, healthcare professionals or regulators where necessary and lawful. We do not sell personal information or permit suppliers to use identifiable health or performance data for their own advertising.

7. International transfers

Some technology providers or subprocessors may store or access information outside the UK. Where required, we use UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another lawful safeguard, with appropriate technical controls. Contact us for details of applicable safeguards.

8. How long we keep information

Unconverted enquiries: 12 months from last meaningful contact. Booking, terms and customer correspondence: seven years after the relationship ends. Health screening, consent, raw test data and reports: seven years from the last service, subject to necessity review and legal holds. Optional gait video: 90 days unless you agree to longer progress monitoring. Payment and tax records: six years from the relevant accounting period. Complaints, incidents and insurance matters: seven years after closure or longer while a claim remains. Website security logs: normally 30 days.

9. How we protect information

We use unique accounts, role-based access, multi-factor authentication where supported, device security, encryption where provided, minimum-data collection, restricted access to health data, supplier checks, managed backups, secure deletion and incident-response procedures. No system is risk-free. We will assess a personal-data breach and notify the ICO and affected people where the legal thresholds are met.

10. AI-assisted reporting

An approved artificial-intelligence service may assist with consolidating measurements or drafting parts of a performance report. We use the minimum information necessary, assess the provider and safeguards, and require competent human review before release. AI does not independently make legal or similarly significant decisions about participants.

11. Your rights

Depending on the circumstances, you may ask for access, correction, erasure, restriction or portability; object to legitimate-interest processing or direct marketing; withdraw consent; and request safeguards concerning automated decisions. Rights are not absolute. We may verify your identity or retain information where law or a valid exemption requires it. Withdrawing consent does not make earlier processing unlawful and may mean we cannot safely continue a service.

12. Cookies and external links

This website uses storage necessary to deliver and protect the service. We will request the required choice before introducing non-essential analytics or functional technologies. Third-party booking, payment and external sites have their own privacy information and control their own processing for the purposes they determine.

13. Questions and complaints

Email hello@changeinmotionlabs.com with privacy questions, rights requests or complaints. Tell us what happened, the information involved, what you would like us to do and how we can contact you. We will acknowledge a data-protection complaint within 30 days and respond without undue delay. You may also complain to the Information Commissioner’s Office.

ICO: ico.org.uk/make-a-complaint · 0303 123 1113