Club documents

PRIVACY POLICY AND PERSONAL DATA PROCESSING STREKOZA FITNESS

Version as of 7 October 2026

This is an English translation provided for convenience. The official version of the Policy is in Ukrainian; if the texts differ, the Ukrainian version prevails. Read the Ukrainian original.

1. General provisions

1.1. This Privacy and Personal Data Processing Policy (the “Policy”) sets out how personal data of clients, prospective clients, website visitors and other individuals who interact with STREKOZA FITNESS is collected, used, stored, protected and otherwise processed.

1.2. Services at each STREKOZA FITNESS fitness club are provided by the business entity assigned to that Club, which is the controller of the Client’s personal data within the respective legal relationship:

STREKOZA FITNESS fitness club (Kyivskyi district) 65113, Odesa, 11-Z Kniazia Yaroslava Mudroho Ave SPORTSERVIS ODYN LLC, EDRPOU code 36501322.

STREKOZA FITNESS fitness club (Peresypskyi district) 65025, Odesa, 37H Vladyslava Buvalkina St SERVIS SPORT LLC, EDRPOU code 36502572.

1.3. For the purposes of this Policy, the “Controller” means the respective business entity that provides services to the Client at a specific Club.

1.4. Personal data is processed in accordance with the Constitution of Ukraine, the Law of Ukraine “On Personal Data Protection”, other legislation of Ukraine, the Public Offer, the STREKOZA FITNESS Visiting Rules and this Policy.

2. Categories of personal data

2.1. Depending on the nature of the interaction, the Controller may process:

— identification data: full name, date of birth/age and other data needed to identify the Client;

— contact data: phone number, email;

— data on the contract, the chosen plan/membership, its validity period, freezes, bookings and visits;

— payment and settlement information to the extent needed to account for payments and refunds;

— a photo of the Client taken by a Club employee when the membership is first issued, to create the Client’s internal profile and for visual identification;

— technical data of the website/other electronic services, if such data is actually collected;

— video surveillance footage, if video surveillance is carried out at the Club.

2.2. STREKOZA FITNESS does not scan or automatically recognize Clients’ faces and does not create biometric templates (vectors) from photos for automated unique identification.

2.3. The ordinary photo of the Client stored in their internal profile and used by staff for visual identification is not used by STREKOZA FITNESS as a biometric template.

2.4. The personal data processed must be adequate, relevant and not excessive in relation to the defined purpose of processing.

3. Purpose and legal grounds for processing

3.1. Personal data may be processed to conclude and perform the contract; create and maintain the Client’s profile; grant access to the Club; identify the Client; prevent the transfer of a personal membership/access device to third parties; record visits; book classes; account for payments and refunds; send service notifications; ensure safety; handle requests; comply with accounting, tax and other legislation; and protect rights and legitimate interests.

3.2. Depending on the specific operation, the legal ground is the conclusion and performance of a transaction, the consent of the data subject where consent is required, a requirement of law or another ground provided for by Article 11 of the Law of Ukraine “On Personal Data Protection”.

3.3. Marketing messages, where the law requires consent, are sent on the basis of the Client’s separate expression of will. Opting out of marketing messages does not affect the service notifications needed to perform the contract.

4. Photographing the Client when issuing a membership

4.1. When a membership is first issued, a Club employee takes a photo of the Client. The photo is added to the Client’s internal profile.

4.2. The purpose of taking and further processing the photo is the visual identification of the Client by Club staff, confirming personal use of the membership/access device and preventing its transfer to third parties.

4.3. The photo is not used for automated facial recognition, creating a biometric template, profiling the Client or making automated decisions about them.

4.4. Being photographed for internal identification does not mean the Client consents to the publication or use of their image in advertising, on social media, on the website or in other public materials.

4.5. A photo or other image of the Client is used for advertising, marketing or other public purposes only on a separate proper legal ground and, where the law requires it, with the Client’s separate consent.

5. Video surveillance

5.1. Video surveillance may be carried out at the Club for the safety of people, the protection of property and access control, in compliance with the law.

5.2. Appropriate notices are placed where video surveillance is carried out.

5.3. Video surveillance is not carried out in showers, toilets and other places where a person reasonably expects a higher level of privacy.

6. Recipients and processors of personal data

6.1. Only employees and other authorized persons who need access to perform their job or contractual duties have access to personal data.

6.2. Data may be transferred to providers of IT systems, hosting, CRM and access control systems, payment providers, accountants and other counterparties only to the extent necessary and where there is a lawful ground.

6.3. Personal data is transferred to public authorities in the cases and in the manner provided for by law.

6.4. Cross-border transfer of personal data, if it actually takes place, is carried out in accordance with the legislation of Ukraine.

7. Retention periods

7.1. Personal data is kept no longer than necessary for the lawful purpose of its processing, unless a longer period is set by law or is necessary to defend legal claims.

7.2. The Client’s photo in the internal profile is kept for as long as needed to identify the Client in connection with using the Club’s services; once that purpose ends, it is deleted unless there is another lawful ground for keeping it.

7.3. After the set period expires, personal data is deleted, destroyed or anonymized unless there is a lawful ground for further processing.

8. Rights of the data subject

8.1. The Client has the rights provided for by Article 8 of the Law of Ukraine “On Personal Data Protection”, in particular the right to know the sources of collection and the location of their personal data, the purpose of processing and the location of the Controller; to receive information on the conditions of access to personal data; to submit, in cases provided for by law, reasoned demands objecting to processing or requesting the change or destruction of data; to withdraw consent where processing is based on consent; and to apply to the Ukrainian Parliament Commissioner for Human Rights or to a court.

8.2. Requests concerning personal data may be submitted to the respective service provider at the Club reception or in another way it has officially designated.

8.3. To protect personal data, the Controller may reasonably require confirmation of the applicant’s identity.

9. Personal data protection

9.1. The Controller applies organizational and technical measures to prevent accidental loss, unlawful access, alteration, disclosure or destruction of personal data.

9.2. Employees and engaged persons have access to personal data only within the scope of their necessary powers and must keep it confidential.

10. Informing the Client and confirming acknowledgment

10.1. Before personal data processing begins, the Client is given the information required by law about the Controller, the composition and content of the personal data, the purpose of its collection and processing, the legal grounds, the persons to whom the data may be transferred and the Client’s rights.

10.2. The Client’s acknowledgment of this Policy and of the information about being photographed at first registration may be confirmed by the Club Member Application Form, an electronic confirmation or another method that properly records such acknowledgment.

10.3. Confirming acknowledgment of this Policy is not consent to the advertising use of the Client’s photos/videos or to receiving marketing messages, where the law requires separate consent for that action.

11. Changes to the Policy

11.1. The Controller may update the Policy due to changes in legislation, technology or the actual processes of personal data processing.

11.2. The current version of the Policy is brought to Clients’ attention by publishing it on the official STREKOZA FITNESS website, at the Club reception and/or in another accessible way.

11.3. If the purpose or method of processing changes in such a way that the law requires separate consent or another legal ground, the relevant actions are taken only after those requirements are met.

12. Contact details of the personal data controllers:

SPORTSERVIS ODYN LLC, EDRPOU code 36501322 65113, Odesa, 11-Z Kniazia Yaroslava Mudroho Ave

SERVIS SPORT LLC, EDRPOU code 36502572 65025, Odesa, 37H Vladyslava Buvalkina St

Official website: strekoza.ua

Questions about this document? Call 067 558 33 09 or 067 483 08 79, or come to the reception: 11z Kniazia Yaroslava Mudroho Ave or 37h Vladyslava Buvalkina St, Odesa.
Book a class

Call us

Choose a club and a number: on a phone the call starts right away.

Tairova Club

11z Kniazia Yaroslava Mudroho Ave

Kotovskoho Club

37h Vladyslava Buvalkina St