Legal

Privacy Policy.

Last updated: 24 June 2026

This privacy policy explains how Charlie Johns (trading as Charlie Johns Personal Training, "CJPT", "I", "me") collects, uses, and protects information about you when you visit cjpt.ie or become a coaching client.

I take your privacy seriously and only collect the information I genuinely need to provide my services. I don't sell your data. I don't share it with anyone except the service providers listed below, who help me run the business.

01

Who's responsible for your data.

The data controller is Charlie Johns, trading as Charlie Johns Personal Training (CJPT). I'm a sole trader based in Cork, Ireland, and I'm solely responsible for how your data is collected, used, and stored.

If you have any questions about your data or how it's handled, my contact details are at the bottom of this page. I'll respond to any data-related query within 7 working days.

02

What information I collect.

I collect information in two main contexts: when you visit the website, and when you become a coaching client.

From website visitors

If you only visit the website and don't get in touch or book anything, the only data I collect is anonymous analytics data via Google Analytics 4. This includes pages viewed, time on site, approximate geographic location (country/region level only — IP addresses are anonymised), browser type, and device type. No personal information is collected unless you actively give it to me. Analytics only runs if you've accepted cookies.

From clients and prospective clients

If you book a free consultation, sign up to a service, or contact me directly, I collect:

  • Identification data: name, email address, phone number
  • Health and training data: information you provide in the initial health questionnaire and ongoing client check-ins (training history, injuries, goals, lifestyle factors, etc.)
  • Body composition data: weight (if you choose to share it) and progress photos (only if you choose to send them — these are never required)
  • Payment data: processed entirely by Stripe — I never see or store your card details, only confirmation that a payment was successful
  • Communications: the messages you send me via email, WhatsApp, Slack, or Instagram DM
03

Why I collect it.

Under GDPR I'm required to have a lawful basis for processing your data. Mine are:

  • Contract: I need your name, contact details, and health information to provide the coaching service you've signed up for. This is the basis for most client data.
  • Legitimate interest: to respond to enquiries, run the business effectively, and improve the website through analytics.
  • Consent: for marketing communications, use of client photos or testimonials in marketing, and for non-essential cookies (Google Analytics).
  • Legal obligation: to keep financial records as required by Irish tax law.

You can withdraw consent at any time by emailing me.

04

Who I share your data with.

I share data only with the following service providers, who help me run the business. Each has been assessed for GDPR compliance:

Stripe
Purpose: Payment processing
Data shared: Name, email, card data (handled directly by Stripe — I never see it)
Calendly
Purpose: Booking the free consultation
Data shared: Name, email, phone number, your selected time slot
Google Workspace (Gmail, Forms, Sheets)
Purpose: Email, health questionnaire delivery, client management
Data shared: All client identification and health data
Slack
Purpose: The private client community
Data shared: Name, email
Google Analytics 4
Purpose: Website analytics
Data shared: Anonymous browsing data only
Vercel
Purpose: Website hosting
Data shared: Anonymous server logs
Meta (Instagram)
Purpose: Only if you contact me via Instagram DM
Data shared: Whatever you share in the DM

All processors above are GDPR-compliant. Some (Stripe, Google, Vercel, Meta) are based in or transfer data to the US under Standard Contractual Clauses approved by the European Commission, as permitted under GDPR.

I don't sell your data. I don't share it with advertisers or third parties beyond the processors listed above.

05

How long I keep your data.

  • Client identification and health data: for the duration of our coaching relationship, plus 6 years afterwards to meet Irish tax record-keeping requirements. After 6 years it's deleted.
  • Financial records: 6 years, as required by Irish tax law.
  • Marketing data: until you unsubscribe or ask to be deleted.
  • Analytics data: Google Analytics retains anonymous data for 14 months by default.
  • Email correspondence: typically 2 years, unless required longer for ongoing client matters.
06

Progress photos and testimonials.

These need special mention because they're optional and require explicit consent:

  • Progress photos are never required. You decide whether to send them, how often, and what they show. They're stored in Google Drive linked to your client file and only seen by me.
  • Testimonials and client photos in marketing (e.g. Instagram, the website) are only ever used with your explicit, written consent, given separately. I'll always ask before publishing anything that identifies you. You can withdraw consent at any time and I'll remove the content.
07

Your rights under GDPR.

You have the following rights regarding your data. To exercise any of them, email charlie@cjpt.ie.

Right to access

Request a copy of the data I hold about you.

Right to rectification

Ask me to correct anything that's wrong.

Right to erasure

Also known as the 'right to be forgotten'. Ask me to delete your data, subject to legal retention obligations (e.g. tax records).

Right to restrict processing

Ask me to stop using your data in certain ways.

Right to data portability

Request your data in a format you can take elsewhere.

Right to object

To specific uses of your data (e.g. marketing).

Right to withdraw consent

For anything you previously consented to.

I'll respond to any request within 30 days, usually faster.

You also have the right to complain to the Data Protection Commission (the Irish data protection authority) if you're unhappy with how I handle your data.

08

Cookies.

The website uses cookies in two categories:

  • Essential cookies: required for basic site functionality (e.g. remembering your cookie consent choice). These don't track you.
  • Analytics cookies (Google Analytics 4): track anonymous usage of the site. These only run after you've explicitly accepted cookies via the banner.

For full details, see the Cookie Policy.

09

Data security.

I take reasonable steps to protect your data:

  • All client data is stored in services with industry-standard encryption (Google Workspace, Stripe, Slack, etc.)
  • Strong unique passwords with two-factor authentication on all relevant accounts
  • Only I have access to your data — no other CJPT staff exist at this time
  • The website uses HTTPS encryption

No system is 100% secure. If a data breach occurs that affects you, I'll notify you and the Data Protection Commission within 72 hours, as required by GDPR.

10

Changes to this policy.

If I make material changes to this policy, I'll notify existing clients by email and update the "last updated" date at the top. Minor changes (typo fixes, clarifications) won't trigger a notification.

If you have any questions about this policy or anything in it, email me at charlie@cjpt.ie. I'm happy to explain anything.

Contact

Get in touch about your data.

For any data-related question, request, or complaint, you can reach me at:

Email: charlie@cjpt.ie

Phone: 087 690 7886

Postal address: 154 South Douglas Road, Cork, T12 EH0F

See Also

The other legal bits.