THEKoR
Train Recover Institute The Keyholder Events Members Apply

Legal

Consumer Health Data Privacy Policy

Last updated: June 16, 2026

On this page

Introduction & Scope What Is Consumer Health Data Categories & Sources Purposes of Collection Who We Share With How We Obtain Consent Your Health Data Rights Exercising Your Rights Right to Appeal Data Security Privacy Contact Effective Date

1. Introduction & Scope

This Consumer Health Data Privacy Policy ("Health Data Policy") describes how The KoR SRQ ("The KoR," "we," "us," or "our") collects, uses, shares, and protects consumer health data, and the rights you have regarding that data. We have adopted this Health Data Policy in the spirit of, and to align with, emerging consumer health data privacy laws — including Washington's My Health My Data Act and similar laws in other states — even where such laws may not directly apply to us.

This Health Data Policy supplements, and should be read together with, our general Privacy Policy. To the extent this Health Data Policy conflicts with our general Privacy Policy with respect to consumer health data, this Health Data Policy controls.

2. What We Mean by "Consumer Health Data"

For purposes of this Health Data Policy, "consumer health data" means personal information that is linked or reasonably linkable to you and that identifies your past, present, or future physical or mental health status, or that you share with us in connection with your wellness and recovery. In the context of The KoR, this may include:

  • Fitness and physical activity information, including training sessions and participation in strength and conditioning programs;
  • Recovery activity, including your use of our cold plunges, our sauna, and contrast and recovery therapy;
  • Wellness, fitness, and performance goals you share with us;
  • Body, health, or condition-related information you choose to share, such as injuries, limitations, or health considerations relevant to your training or recovery; and
  • Any assessment, measurement, or program-related information collected through The KoR Performance Institute (KoRPI).

3. Categories of Consumer Health Data We Collect and Our Sources

We collect consumer health data from the following sources:

  • Directly from you — through our website forms (such as Schedule a Tour, Apply for Membership, and Book Recovery), during consultations and assessments, and in the course of your communications with our staff;
  • Through your use of our facilities and services — including check-ins, bookings, and session records relating to training, cold plunge, sauna, and recovery; and
  • Through our membership and booking platform — where your account, bookings, and usage history are maintained.
We collect only the consumer health data that is reasonably necessary to provide and improve our services. We do not require you to share more health-related information than is necessary for the service you request.

4. Purposes for Collecting and Using Consumer Health Data

We collect and use consumer health data only for purposes you would reasonably expect, including to:

  • Provide, personalize, and administer your training, recovery, and membership services;
  • Schedule and manage recovery sessions, cold plunge and sauna use, and classes;
  • Tailor programs and recommendations to your stated goals and considerations;
  • Communicate with you about your sessions, bookings, and account;
  • Promote safety and respond appropriately to health considerations you share with us; and
  • Comply with our legal obligations and protect the rights and safety of our members, guests, and staff.

5. Who We Share Consumer Health Data With

We share consumer health data only with service providers (sometimes called processors) who perform services on our behalf and are contractually limited to using the data only for those services. These include:

  • GymMaster — our membership management, booking, and access-control platform;
  • Constant Contact — our email marketing platform;
  • Resend — our transactional email delivery provider;
  • Google Analytics — our website analytics provider; and
  • Netlify — our website hosting provider.

We may also disclose consumer health data when required by law or to protect the rights, property, or safety of our members, guests, staff, or others, and in connection with a business transfer as described in our general Privacy Policy.

We do not sell your consumer health data, and we do not share it with third parties for their own independent marketing or advertising purposes. We will not collect, use, or share consumer health data for any purpose materially different from those described here without first obtaining your consent.

6. How We Obtain Consent

We collect consumer health data only with your consent or as necessary to provide a service you have requested. When you voluntarily provide health-related information through our forms or to our staff, or when you book and use our recovery services, you consent to our collection and use of that information for the purposes described in this Health Data Policy. Where required by law, we will obtain your separate, affirmative consent before collecting or sharing consumer health data for any purpose not described here. You may withdraw your consent at any time as described below.

7. Your Rights Regarding Consumer Health Data

Subject to applicable law, you have the following rights with respect to your consumer health data:

  • Right to access: You may request confirmation of whether we are collecting, sharing, or selling your consumer health data, and request access to that data, including a list of the categories of third parties and service providers with whom we have shared it.
  • Right to delete: You may request that we delete your consumer health data, subject to limited exceptions such as legal recordkeeping obligations.
  • Right to withdraw consent: You may withdraw your consent to our collection, use, or sharing of your consumer health data at any time. Withdrawing consent may limit our ability to provide certain services.
  • Right to appeal: If we decline to act on your request, you may appeal that decision (see Section 9).

8. How to Exercise Your Rights and Our Response Timeline

To exercise any of these rights, contact us using the information in Section 11. We will take reasonable steps to verify your identity before responding, which may require you to provide information sufficient to confirm that you are the person to whom the consumer health data relates.

We will respond to your request within 45 days of receipt. If reasonably necessary, we may extend that period by an additional 45 days, in which case we will notify you of the extension and the reason for it within the initial 45-day period. There is no charge to exercise these rights, although we may decline or charge a reasonable fee for requests that are manifestly unfounded, excessive, or repetitive, to the extent permitted by law.

9. Right to Appeal

If we decline to take action on your request, we will inform you of the reason. You may appeal our decision by contacting us using the information in Section 11 and stating that you wish to appeal. We will respond to your appeal in writing within 45 days, explaining the actions taken or not taken in response and the reasons for our decision.

10. Data Security for Consumer Health Data

We maintain reasonable administrative, technical, and physical safeguards designed to protect consumer health data against unauthorized access, use, alteration, and disclosure. We limit access to consumer health data to staff and service providers who need it to perform their duties, and we rely on reputable platforms that maintain their own security measures. No system can be guaranteed to be completely secure, but we are committed to handling your consumer health data responsibly and in accordance with this Health Data Policy.

11. Designated Privacy Contact

For all matters relating to consumer health data, including to exercise your rights or file an appeal, please contact our designated privacy contact:

The KoR SRQ — Privacy Contact
1955 Upper Beechwood Ave
Sarasota, FL 34231
Phone: (941) 744-6043
Email: info@thekorsrq.com

12. Effective Date

This Consumer Health Data Privacy Policy is effective as of June 16, 2026. We may update it from time to time; when we do, we will revise the "Last updated" date at the top of this page. Your continued use of our Site and services after any update constitutes your acknowledgment of the revised Health Data Policy.

THEKoR

Sarasota's private gym, cold plunge and sauna club. Train hard. Recover harder. Belong.

Explore
Private GymCold PlungeSaunaPerformance InstituteThe Keyholder
Get Started
Schedule a TourApply for MembershipBook RecoveryMember Login
Visit
Mon–Fri 6–11a · 3–7p
Sat 8–11a
Sun 8–11a (soon)
(941) 744-6043

1955 Upper Beechwood Ave
Sarasota, FL 34231

© 2026 The KoR SRQ · Sarasota, FL · Privacy · Terms · Health Data Privacy
InstagramFacebookTikTokX