// Legal

Privacy
Policy

Last updated: May 7, 2026

1. Who We Are

This website, roxzone.training, is operated by Pedro, Jorge, Paulo & Rogério, Lda, a company registered in Portugal with NIPC PT516657151, trading under the brand name RoxZone.

We are the data controller responsible for your personal data as defined under the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection laws.

For any privacy-related questions or requests, contact us at: info@roxzone.training


2. Scope and Applicable Law

This Privacy Policy applies to all visitors and users of roxzone.training regardless of their location. Depending on where you are based, additional rights and protections may apply:


3. What Data We Collect and Why

a) Contact and enquiry forms

When you submit a contact form or apply for 1:1 coaching, we collect your name, email address and the content of your message. We use this data solely to respond to your enquiry.

Legal basis: legitimate interest (GDPR Art. 6(1)(f)).

b) Email newsletter and lead magnets

When you subscribe to receive training guides or marketing communications, we collect your name and email address. We use Mailchimp to manage and deliver these communications. You can unsubscribe at any time via the link in any email.

Legal basis: consent (GDPR Art. 6(1)(a)).

c) Analytics

We use Google Analytics to understand how visitors use our website. This tool collects anonymised data about your device, browser, approximate location and behaviour on the site via cookies.

Legal basis: consent (GDPR Art. 6(1)(a)).

d) Marketing and advertising

We use Meta Pixel (Facebook/Instagram) to measure the effectiveness of our advertising campaigns and to show relevant ads to people who have visited our site.

Legal basis: consent (GDPR Art. 6(1)(a)).

e) Coaching programme

If you enrol in our 1:1 coaching programme, we may collect additional information including fitness data, training history, performance metrics and health-related information you choose to share. This data is special category data under GDPR Art. 9 and is used exclusively to deliver your coaching programme. We process this data only with your explicit consent.

Legal basis: explicit consent (GDPR Art. 9(2)(a)) and contract performance (GDPR Art. 6(1)(b)).

f) Technical and usage data

When you visit our website, we automatically collect certain technical information including your IP address (anonymised), browser type, operating system, referring URLs and pages visited. This data is used for security, performance monitoring and fraud prevention.

Legal basis: legitimate interest (GDPR Art. 6(1)(f)).


4. Payments

We do not process payments directly on this website. All purchases and subscription management are handled externally by Strivee. Please refer to Strivee's own privacy policy for information on how they handle your payment and personal data. We do not store or have access to your payment card information at any time.


5. Cookies

We use the following types of cookies:

You can manage your cookie preferences at any time via our cookie consent banner. You may also control cookies through your browser settings, though disabling certain cookies may affect website functionality.


6. Third-Party Services and Data Processors

We share data with the following third-party processors under Data Processing Agreements (DPAs):

ServicePurposeLocationPrivacy Policy
Mailchimp (Intuit)Email marketingUSAmailchimp.com/legal/privacy
Google AnalyticsWebsite analyticsUSApolicies.google.com/privacy
Meta PlatformsAdvertisingUSAfacebook.com/privacy/policy
StriveeTraining plan delivery and paymentsStrivee's policy
VercelWebsite hosting and infrastructureUSAvercel.com/legal/privacy-policy
ResendTransactional email deliveryUSAresend.com/legal/privacy-policy

We do not sell your personal data to any third party under any circumstances.


7. International Data Transfers

Some of our third-party processors transfer and process your data outside the European Economic Area, including to the United States. Where such transfers occur, we ensure appropriate safeguards are in place, including:

You may request a copy of the relevant transfer safeguards by contacting us at info@roxzone.training.


8. Data Retention

Data TypeRetention Period
Contact form submissions12 months after last contact
Email subscribersUntil unsubscribe or deletion request
Coaching programme data24 months after programme end
Health and fitness data24 months after programme end
Analytics data26 months (Google Analytics default)
Technical / server logs90 days
Financial records10 years (Portuguese legal requirement)

After the applicable retention period, data is securely deleted or anonymised.


9. Your Rights

EU / EEA Residents (GDPR)

UK Residents (UK GDPR)

All rights above apply. Complaints may be lodged with the Information Commissioner's Office (ICO) at ico.org.uk.

California Residents (CCPA/CPRA)

We do not sell personal information as defined under the CCPA.

Brazilian Residents (LGPD)

All rights equivalent to GDPR apply under the LGPD, including rights of access, correction, anonymisation, portability, deletion and information about sharing.

Australian Residents

You have the right to access and correct your personal information under the Australian Privacy Principles. Complaints may be lodged with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

To exercise any of your rights, contact us at info@roxzone.training. We will respond within 30 days (or within the timeframe required by your local law).


10. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These measures include:

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by applicable law.


11. Children's Privacy

Our services are intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us immediately at info@roxzone.training and we will delete that data promptly.


12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal requirements. The date at the top of this page reflects the most recent revision. For material changes, we will notify active subscribers by email. Continued use of the website after any changes constitutes acknowledgement of the updated policy.


13. Contact and Complaints

For any questions, requests or complaints regarding this Privacy Policy or the way we handle your personal data:

Pedro, Jorge, Paulo & Rogério, Lda
Trading as RoxZone
NIPC: PT516657151
Email: info@roxzone.training
Website: roxzone.training

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. For Portugal and EU residents, this is the CNPD — Comissão Nacional de Proteção de Dados at cnpd.pt.

Legal notice: This Privacy Policy was drafted to reflect GDPR, UK GDPR, CCPA/CPRA, LGPD and Australian Privacy Principles requirements. It should be reviewed by a qualified data protection lawyer before publication, particularly regarding the processing of health and fitness data under GDPR Article 9.

We use cookies to analyse site traffic and personalise our marketing. See our Cookie Policy for details.