FitFormiq Fitness Assistant

FitFormiq Privacy and Cookies Policy

Version 3.2, effective from 7 August 2026

1. Who processes data and in what role

  1. The controller of data relating to the website, enquiries, B2B agreements, billing, Trainer Accounts, security, support and the Operator’s own analytics is Quanmedia Sp. z o.o., ul. Żwirki 17, 90-539 Łódź, Poland, KRS 0000539599, NIP 7272794495, email: kontakt@fitformiq.com, hereinafter the „Operator”.
  2. The controller of Client data, plans, measurements, health information, communications and purchases from the Trainer is the relevant Trainer. The Trainer’s details should be visible in the invitation, Account or offer.
  3. For data entrusted by the Trainer, the Operator acts as a processor under the Data Processing Agreement. Exceptionally, the Operator is a separate controller of limited technical and evidentiary data where such data is needed to secure the Platform, prevent abuse, handle legal notices or defend claims.
  4. The Operator does not determine the legal basis, scope or purpose of the Trainer’s training and dietary programmes. Questions about such data and the exercise of rights should first be directed by the Client to the Client’s Trainer. The Operator assists the Trainer and, where necessary, forwards the request to the Trainer.

2. What data we process

  1. Enquiries and contact: first name, last name, email address, telephone number, role, company, message content and correspondence.
  2. Trainers and their teams: identification and business details, NIP, address, Account and login details, roles, Package, payments, invoices, settings, support history and history of document acceptances.
  3. Clients, on the Trainer’s instructions: contact and profile details, plans, tasks, activities, schedules, measurements, photographs, nutritional data, progress, health information, purchases and Content entered into the Platform.
  4. Technical data: IP address, device and session identifiers, operating system, browser, application version, timestamps, security logs, error diagnostics and cookie or localStorage settings.
  5. Store and payments: order identifier, amount, status, Product and seller and purchaser details. As a rule, complete payment instrument data is processed by the payment provider rather than by the Operator.
  6. Legal notices: details of the person submitting the notice, the Content identified, justification, evidence, decision and correspondence.
  7. Data originates directly from the user, the Trainer, authorised persons within the Trainer’s organisation, the device and logs, or the payment provider.

3. Purposes, legal bases and periods

  1. Conclusion and performance of an agreement, Account activation, support and billing: Article 6(1)(b) GDPR, for the duration of the agreement and settlement handling. Evidence of acceptance of documents (Terms, Privacy Policy, Data Processing Agreement) and contractual data is kept for the duration of the agreement and, after it ends, until claims become time-barred, for no longer than 10 years.
  2. Invoices, taxes, accounting and obligations towards authorities: Article 6(1)(c) GDPR, for the period required by law, up to ten years from the end of the relevant year.
  3. Security, prevention of abuse, technical statistics, establishment and defence of claims and service improvement: Article 6(1)(f) GDPR, until the purpose ceases or an effective objection is made. Security logs are kept for up to 18 months, and data relating to claims until they become time-barred, for no longer than 10 years.
  4. B2B Verification (confirming business status and the professional purpose of the purchase): Article 6(1)(b), (c) and (f) GDPR. Data from failed or incomplete verifications is kept for up to 18 months to handle retries, prevent abuse and defend claims.
  5. Contact before conclusion of an agreement: Article 6(1)(b) or (f) GDPR, until the discussions end and then for a maximum of 12 months unless an agreement or claim arises.
  6. The Operator’s own marketing: Article 6(1)(f) GDPR and, for electronic communications channels, the additional consent required under electronic communications law, until an objection is made or consent is withdrawn.
  7. Website analytics: Article 6(1)(a) GDPR and consent to access the device, until consent is withdrawn and no longer than the lifespan of the relevant identifier.
  8. Handling notices of unlawful Content and orders from authorities: Article 6(1)(c) and (f) GDPR, for the duration of the proceedings and then for up to three years or longer if required by law.
  9. Client data entrusted by the Trainer: for the duration of the Trainer’s agreement and in accordance with the Trainer’s documented instructions, followed by the export and deletion period described in the Terms and the ordinary cycle for secure deletion of backups (up to 30 days).
  10. Health data is processed solely on the Trainer’s instructions. The Trainer is responsible for complying with Articles 6 and 9 GDPR, in particular for obtaining explicit consent where it constitutes the legal basis for processing.
  11. Providing data required for an Account, agreement or payment is necessary to perform the service. Other data is voluntary, but failure to provide some of it may restrict features.

4. Recipients and transfers

  1. Data may be received by the Operator’s authorised employees and contractors and by providers of hosting, email, support, monitoring, backups, accounting, legal services and IT infrastructure, only to the extent necessary.
  2. The current list of key processors acting on the Operator’s behalf includes: Quanmedia Sp. z o.o. — hosting and infrastructure (Poland, EEA); PayPro S.A. (Przelewy24) — payment handling (Poland); Resend, Inc. — delivery of transactional email (United States, transfer based on Standard Contractual Clauses). The list may be updated; information about changes is available at kontakt@fitformiq.com.
  3. Przelewy24 and other payment providers process data as separate controllers under their own documents. The selling Trainer also receives transaction data.
  4. Google Ireland Limited may receive data relating to Google Analytics only after analytics consent. If the website retrieves fonts from Google servers, Google may receive the IP address and technical connection data.
  5. Data may be disclosed to public authorities where required by law.
  6. Service data is, as a rule, hosted within the European Economic Area. Where a provider processes data outside the EEA, the Operator applies the required transfer mechanism, in particular an adequacy decision, Standard Contractual Clauses and supplementary safeguards. Information about the safeguard may be obtained at kontakt@fitformiq.com.

5. Rights

  1. Depending on the legal basis and the controller’s role, a data subject has the right of access, to a copy, rectification, erasure, restriction, portability, objection and withdrawal of consent without affecting the lawfulness of processing carried out before its withdrawal.
  2. A request concerning data handled by the Operator may be sent to kontakt@fitformiq.com. The Operator may verify the requester’s identity.
  3. For data managed by the Trainer, the Trainer should be contacted. A request received by the Operator will be forwarded to the relevant Trainer if the Trainer can be identified.
  4. A complaint may be lodged with the President of the Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland, uodo.gov.pl.
  5. The Operator does not make decisions concerning users that produce legal effects based solely on automated processing. Ordinary anti-fraud safeguards may temporarily suspend an action pending verification.

6. Cookies and localStorage

  1. Necessary mechanisms store the session, security, language choice, theme and cookie decision. They are required for the service requested by the user and do not require consent.
  2. Google Analytics 4 may use the _ga and _ga_<ID> identifiers to measure visits, devices and traffic sources. They are activated only after consent. The standard maximum lifespan is two years but may be shortened through settings.
  3. Rejecting analytics does not restrict basic features. Consent can be changed at any time through the „Cookie settings” link in the footer. Withdrawal applies prospectively.
  4. The user may also delete and block cookies in the browser settings. Blocking necessary mechanisms may prevent login or the storage of settings.

7. Security and minors

  1. The Operator applies measures appropriate to the risk, in particular encryption in transit, password hashing, roles and access controls, backups, updates, event logging and incident response procedures.
  2. No system can provide a complete guarantee of security. The user should use a strong, unique password and an up-to-date device and should not submit unnecessary data.
  3. The Platform is not directed independently at children. A minor’s Account is created only in a relationship with the Trainer and after the Trainer has ensured the required consent or other legal basis.

8. Google service integrations

  1. A Trainer may voluntarily connect their Google account to the Platform so that appointments and classes scheduled in FitFormiq appear in their Google Calendar and stay in sync with it. The integration is optional and is not a condition of using the Platform.
  2. Once consent is granted, the Operator uses only the https://www.googleapis.com/auth/calendar.events scope, that is, access to calendar events. The Operator creates, updates and deletes only those events that correspond to bookings created in FitFormiq. The Operator does not request access to managing calendars themselves.
  3. FitFormiq's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
  4. Data obtained from Google APIs is not used to serve advertising or build advertising profiles, is not sold or shared with data brokers, and is not transferred to third parties beyond what is necessary to provide the service, required by law, or covered by the user's explicit consent.
  5. People acting on the Operator's behalf do not read the content of data obtained from Google APIs, except where the user explicitly requests it as part of support, where it is necessary for security reasons, or where the law requires it.
  6. The Google account connection can be disconnected at any time from the Calendar view in the Platform, or revoked directly in Google account settings. After disconnection the Operator stops using access tokens and deletes them from its systems. Events previously created in Google Calendar remain at the user's disposal and are not deleted automatically.
  7. A Trainer may also provide the identifier of their Google Maps business listing in order to import publicly available reviews onto their website. In that case the Operator retrieves only public data made available by Google and gains no access to the Trainer's account.
  8. Google Analytics and Google Fonts are described in sections 4 and 6 respectively. They do not rely on the account connection described in this section.

9. Changes and contact

  1. The Policy may be updated as the law, providers or features change. Material changes are communicated through the Platform or by email.
  2. Privacy contact: kontakt@fitformiq.com.