Privacy Policy

 

Privacy policy of Fitvise s.r.o.

version 2.0.

 

Fitvise s.r.o.

Company ID No: 17628946

with its registered office at Emy Destinové 411, 252 25 Jinočany

registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File No. 374178

e-mail: info@fitvise.cz

telephone: +420 777 775 277

(hereinafter referred to as the “Controller”)

 

I. Introductory provisions

  1. This Privacy Policy (hereinafter referred to as the “Policy”) is a general document containing, in particular, basic information about the circumstances in which the personal data of the data subjects specified below is processed, including the purposes, scope and methods of processing such personal data, the rights of the data subjects in relation to such processing and the methods by which those rights may be exercised.
  2. The processing of personal data is governed by applicable legislation, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC, also referred to as the General Data Protection Regulation or the “GDPR”. In the case of users from the United Kingdom, the processing is also governed by the applicable UK GDPR and the Privacy and Electronic Communications Regulations, referred to as the “PECR”.

II. Controller of personal data

  1. The controller of personal data is Fitvise s.r.o., Company ID No. 17628946, with its registered office at Emy Destinové 411, 252 25 Jinočany, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File No. 374178. The Controller is also the operator of the Fitvise mobile application (hereinafter referred to as the “App”) and the website available at www.fitvise.cz (hereinafter referred to as the “Website”).
  1. The Controller determines the purposes and means of processing personal data and carries out such processing.
  1. The protection of the personal data of users of the Fitvise App and visitors to the Website is a priority for the Controller. For this reason, the Controller hereby informs users of the Fitvise App and visitors to the Website what data is collected, processed and used and for what purposes.
  1. Where necessary, data subjects may contact the Controller by telephone at +420 777 775 277 or by email at info@fitvise.cz.
  1. The Controller declares that it complies with all statutory obligations required under applicable and effective legislation and that all personal data voluntarily provided by a data subject to the Controller will be processed only on the basis of a valid legal ground, in particular the Controller’s legitimate interests, performance of contractual obligations, compliance with legal obligations or consent granted by the data subject.
  1. The Controller further declares that, in accordance with Article 13 of the GDPR, it fulfils its information obligation before the processing of personal data begins.
  1. When processing personal data, the Controller proceeds in a manner that ensures that the rights of data subjects are not adversely affected and takes care to protect data subjects against unauthorised interference with their privacy.
  1. The Controller undertakes to enable data subjects to exercise their rights under the GDPR and related legislation and to support data subjects in exercising those rights.

III. Data subjects, purposes, scope, retention periods and legal grounds for processing

A. CUSTOMERS

The Controller processes the personal data of data subjects for the following purposes, to the following extent, on the following legal grounds and for the following periods:

a. Purpose: Provision of services to data subjects in accordance with the agreement for the provision of digital content, including conclusion of the agreement for the provision of digital content, provision of access to and use of the Fitvise App, optimisation of services enabling personal fitness coaches to manage their clients and their progress, maintain records about them, schedule training sessions and set nutrition and training plans, or enabling individuals to register for sessions with their coach, as well as other related services and the handling of complaints.

Scope of data: First name, surname, email address, telephone number, age, gender, postal address, billing address where applicable, Company ID No. where applicable and registered office where applicable.

Legal ground: Processing is necessary for the performance of the agreement.

Retention period: For the period necessary for the performance of the agreement and for the duration of applicable limitation periods.

 

b. Purpose: Provision of personalised services in the Fitvise App, including monitoring progress, creating training and nutrition plans, recording sessions and similar activities, enabling data subjects to record information about their weight, body fat percentage and body measurements, and to view training and nutrition plans created by their coaches, as well as the potential evaluation and presentation of the data subject’s progress within the App.

Scope of data: Sensitive data concerning the User’s health, in particular weight, body measurements, including height, body fat percentage, waist circumference, hip circumference and similar measurements, and photographs.

Legal ground: Consent.

Retention period: Until consent is withdrawn or, where consent is not withdrawn, until termination of the agreement.

 

c. Purpose: Administration of the User Account.

Scope of data: First name, surname, email address, postal address and telephone number.

Legal ground: Consent.

Retention period: From registration until the User Account is deleted by the data subject or deleted by the Controller due to inactivity of the data subject, but no earlier than two years after the data subject’s last login to the User Account.

 

d. Purpose: Accounting and tax purposes and compliance with archiving obligations.

Scope of data: First name, surname and address.

Legal ground: Processing is necessary for compliance with legal obligations imposed on the Controller by law.

Retention period: For the necessary period of ten years, unless applicable legislation requires a longer retention period.

 

e. Purpose: Sending commercial communications for marketing and advertising purposes.

Scope of data: First name, surname and email address.

Legal ground: Consent.

Retention period: For a necessary and proportionate period, but no longer than until consent is withdrawn.

 

f. Purpose: Sending unsolicited commercial communications.

Scope of data: First name, surname and email address.

Legal ground: Legitimate interest consisting in direct marketing.

Retention period: For a necessary and proportionate period.

 

B. VISITORS TO THE WEBSITE

The Controller’s online presentation operated on the Website specified above uses cookies that serve to improve the quality of the services offered and ensure a more effective and user-friendly design of the Website. The Controller processes cookies in relation to visitors to the Website. More information about the processing of cookies on the Website is available in the cookie banner.

 

Cookies are text files containing small amounts of information that are downloaded to the mobile telephone, computer or other device of a visitor to the Website when the Website is visited. Each time the Website is subsequently visited, the cookies are sent back to the Website or to another website that recognises them. In simple terms, cookies enable the Website to store information about visits to the Website.

 

The Website uses different categories of cookies for different purposes. Strictly necessary cookies are required for the basic functioning of the Website. The Controller cannot ensure the basic functioning of the Website without these cookies. Most cookies are session cookies, which are automatically deleted after the visitor leaves the Website. For users from the United Kingdom, consent to cookies is governed by the UK GDPR and the PECR.

 

The Controller may process strictly necessary cookies without the consent of the Website visitor. The Controller may process all other cookies only with the consent of the Website visitor, which may be withdrawn or refused at any time in the cookie settings. However, withdrawal or refusal of consent may affect the use and browsing of the Website.

 

C. PERSONS CONTACTING THE CONTROLLER

The Controller processes the personal data of persons who contact the Controller by email or telephone for the following purposes, to the following extent, on the following legal grounds and for the following periods:

a. Purpose: Responding to enquiries submitted by the person making the enquiry.

Scope of data: First name, surname, email address and telephone number.

Legal ground: Legitimate interest in providing a response.

Retention period: For the period strictly necessary to respond to the enquiry.

 

IV. Voluntary provision of personal data

  1. The data subject provides their personal data to the Controller voluntarily. The Controller processes only personal data voluntarily provided to it by the data subject when using or registering for the Fitvise App, visiting the Website, communicating by email or during an in-person meeting.
  1. Failure to provide personal data may affect the Controller’s ability to enter into an agreement or provide the data subject with services that depend on the necessary availability of information about the data subject, including personal data.

V. Right to withdraw consent

Where the processing of personal data is based on the consent of the data subject, the data subject may withdraw their consent to processing at any time by sending an email to info@fitvise.cz, using the link included in a commercial communication or using the relevant option in the Fitvise App. Withdrawal of consent does not affect the processing of personal data carried out by the Controller on another legal basis, in particular for the purpose of performing the agreement or providing a service. Nor does it affect the lawfulness of processing based on consent before its withdrawal.

 

VI. Processors of personal data

A. Disclosure of personal data to coaches

  1. Within the Fitvise App, a User acting as a client may be matched with a User acting as a personal coach. In such a case, selected coaches are granted access to the personal data of their clients to the extent necessary for the provision of training, nutrition and related services through the Fitvise App.
  1. The personal data made available may include, in particular, the client’s first name, surname, age, gender, contact details, body measurements, weight, health information, progress information and shared photographs, exclusively for the purpose of providing services that form part of the functionality of the Fitvise App.
  1. The coach is contractually obliged to maintain confidentiality regarding all personal data to which the coach obtains access through the App and must not disclose or transfer such data to any third party. The coach is authorised to use the client’s personal data only within the Fitvise App and exclusively for the purpose of providing services to the client.
  1. The Controller ensures that all access by coaches to client data takes place securely and in accordance with the technical and organisational measures for the protection of personal data specified in this Policy.
  1. The client is informed of the possibility that their data may be disclosed to a coach when the cooperation is established within the App and may terminate such connection at any time. When the connection is terminated, and no later than upon termination of the agreement, the coach’s access to the client’s personal data is disabled.

B. Transfer of personal data to other third parties

    1. Processors of personal data:
  • social network service provider – Meta Platforms Ireland Limited
  • analytics and cloud service providers – Google Ireland Limited and Google LLC
  • information system provider – Asseco Solutions, a.s. (HELIOS)
  • mobile deep linking, analytics and attribution tool provider – Branch Metrics, Inc.
  • hosting service providers – Google Ireland Limited and Google LLC
  • email service provider
  • providers of services processing cookies – Google Ireland Limited, Google LLC and Meta Platforms
    1. Please note that, due to changes in the providers of certain services, it is not possible to list all current and future processors of personal data by name. The Controller may also decide in the future to use additional applications or processors in order to improve the quality of the services provided and its business processes. The above list of processors may therefore change over time.
    1. The personal data of data subjects is not transferred to third parties for the purpose of displaying advertisements. Advertising displayed in the App is provided exclusively by the Controller’s business partners without personal data of data subjects being made available to them.
    1. In the future, as part of an expansion of the App’s functionalities, the Controller may cooperate with business partners to whom certain data necessary for the use of a specific function may be transferred, such as default macronutrient settings within a meal plan. The data subject will be informed in advance of any such expansion of functionality and will be given the opportunity to consent to the transfer of data.

C. Transfers of personal data to countries outside the EU

Personal data may be transferred to Apple Inc., Google LLC and Branch Metrics, Inc., also known as Branch.io, in the United States of America. Such transfers are based on an adequacy decision of the European Commission under the EU–U.S. Data Privacy Framework, where that mechanism is applicable, or on standard contractual clauses approved by the European Commission pursuant to Article 46 of the GDPR.

 

D. Disclosure and transfer of personal data without the consent of the data subject

  1. In cases stipulated by law, the Controller is entitled or required to transfer or disclose personal data to law enforcement authorities or other public authorities.
  1. Personal data may only be transferred, disclosed, used and processed to the extent necessary.

VII. Use of analytics tools

  1. The Controller declares that its Website may use services provided by GOOGLE Inc. consisting of the collection of reports concerning the activities of visitors to the Website, in order to provide the Controller with more detailed information about the use of the Website and enable the Controller to take this information into account when improving the accessibility of the Website. If a visitor to the Website does not wish such information to be collected, the collection may be prevented by installing the Browser Software Plugin. Google Analytics can be disabled at: https://tools.google.com/dlpage/gaoptout. 
  1. The App uses Google Analytics to analyse the use of the App and improve its functionalities. This tool collects anonymised information such as the type of device, operating system, IP address in anonymised form, time spent in the App and the manner in which the User interacts with individual screens. This data is not used to identify any particular person and is processed by Google Ireland Limited in accordance with its privacy policy available at: https://policies.google.com/privacy. The processing is based on the legitimate interest of the App operator in improving the App’s functionalities and user experience.

VIII. Rights of data subjects and methods of exercising them 

The data subject has the following rights:

a) Right of access to personal data

The data subject has the right to obtain confirmation from the Controller as to whether personal data concerning them is or is not being processed and, where such personal data is being processed, the right to obtain access to the personal data and the following information:

    1. the purposes of processing the personal data;
    2. the categories of personal data concerned;
    3. the recipients or categories of recipients to whom the personal data has been or will be disclosed;
    4. the envisaged period for which the personal data will be stored or, where it is not possible to determine that period, the criteria used to determine it;
    5. the existence of the right to request that the Controller rectify or erase personal data concerning the data subject, restrict its processing or the right to object to such processing;
    6. the right to lodge a complaint with a supervisory authority;
    7. any available information as to the source of the personal data, where the data was not obtained from the data subject.

The data subject also has the right to request a copy of the personal data being processed by the Controller, provided that this does not adversely affect the rights and freedoms of other persons. For additional copies requested by the data subject, the Controller may charge a reasonable fee based on administrative costs. Where the data subject submits a request electronically, the information shall be provided in a commonly used electronic form unless the data subject requests another method.

 

b) Right to rectification

The data subject has the right to have the Controller rectify inaccurate personal data concerning them without undue delay. Taking into account the purposes of processing, the data subject also has the right to have incomplete personal data completed, including by providing a supplementary statement.

 

c) Right to erasure (right to „be forgotten“)

The data subject has the right to have the Controller erase personal data concerning them without undue delay, and the Controller is obliged to erase the personal data without undue delay where one of the following grounds applies:

  1. the personal data is no longer necessary for the purposes for which it was collected or otherwise processed
  2. the data subject withdraws the consent on which the processing was based and there is no other legal ground for the processing
  3. the data subject raises a justified objection to the processing of the personal data
  4. the personal data has been processed unlawfully
  5. the personal data must be erased in order to comply with a legal obligation under European Union law or the law of the Czech Republic
  6. the personal data was collected in connection with an offer of information society services on the basis of consent granted by a child

d) Right to restriction of processing

The data subject has the right to have the Controller restrict processing in any of the following cases:

  1. the data subject contests the accuracy of the personal data, for a period enabling the Controller to verify the accuracy of the personal data
  2. the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of its use instead
  3. the Controller no longer needs the personal data for the purposes of processing, but the data subject requires it for the establishment, exercise or defence of legal claims

e) Right to data portability

The data subject has the right to receive the personal data concerning them that they have provided to the Controller in a structured, commonly used and machine-readable format and has the right to transmit such data to another controller without hindrance from the Controller, where:

 

  1. the processing is based on consent to the processing of personal data or concerns the processing of personal data for the purpose of entering into and performing an agreement with the data subject;
  2. the processing is carried out by automated means.

When exercising the right to data portability, the data subject has the right to have the personal data transmitted directly by the Controller to another controller, where technically feasible. The exercise of the right to data portability must not adversely affect the rights and freedoms of other persons.

 

f) Right to object 

The data subject has the right to object to the processing of personal data. Where the data subject raises a justified objection to processing for direct marketing or profiling purposes, the personal data will no longer be processed for those purposes.

 

The objection will be assessed and the Controller will subsequently inform the data subject whether the objection has been upheld and the Controller will cease processing the data, or whether the objection was unfounded and the processing will continue. Processing will be restricted until the objection has been resolved.

 

g) Right not to be subject to automated decision-making, including profiling 

The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, meaning any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to the data subject, where such a decision produces legal effects concerning the data subject or similarly significantly affects them.

 

This right does not apply where the automated decision is necessary for entering into or performing an agreement between the data subject and the Controller or is based on the data subject’s explicit consent. In such cases, however, the data subject has the right to obtain human intervention in the automated decision-making process by the Controller, the right to express their point of view and the right to contest the automated decision.

 

h) Right to lodge a complaint with a supervisory authority 

The data subject has the right to lodge a complaint regarding the Controller’s processing of their personal data with the supervisory authority. In the Czech Republic, the supervisory authority is the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7.

 

IX. Final Provisions 

This Policy is effective from July 30, 2026.

In Jinočany on July 30, 2026.

 

Fitvise s.r.o.
Ing. Karolína Kamenická, Managing Director