Introduction:
This Privacy Policy explains what personal data FitmeClub (represented by Anastasia Polenok, a sole proprietor registered in Odessa, Ukraine) collects and processes when providing services, and how this data is used and protected. We take user privacy seriously and comply with Ukrainian legislation on personal data protection. By using our website and services, the User agrees to the terms of this Privacy Policy. If you do not agree to these terms, please refrain from using FitmeClub.
Data collected about users:
- Registration details: When creating an account, we request personal information necessary to provide services: first and last name, email address, and password. This information is needed for user identification, communication, and access to your personal account. In some cases, additional information (such as a contact phone number) may be required to support or validate payments. We ask that you provide accurate information and keep it up to date.
- Payment details: When paying for a subscription, the User enters their bank card details on a secure payment page. FitmeClub does not receive or store your full bank card details (number, CVV code) on its servers. This data is processed by a third-party certified payment provider that complies with PCI DSS security standards. Our service only receives payment status information and may obtain a token (unique identifier) for the transaction or card, which does not reveal sensitive card details. The token can be used to identify your card when automatically renewing your subscription, but does not itself contain payment details. You have the right to disable autopayments at any time, after which the saved card token will be deactivated for new charges.
- Technical and analytical information: When using the site, some technical data is collected: device IP address, browser type, operating system, access time, and address of requested pages. This data is collected automatically using cookies and similar technologies. They help analyze the service's performance, ensure security (for example, by identifying suspicious activity), and improve the user experience. You can learn more about the use of cookies and their storage settings in the relevant section of the Policy (see below).
- Training data: As part of your use of the service, we may collect information about your actions on the platform: purchased programs, subscription start and end dates, video viewing statistics (e.g., which videos you watched, course progress). This data is used to provide service functionality (for example, to remember your training progress) and improve content.
- Special categories of data: FitmeClub does not request or process sensitive personal data (such as health data, medical indicators, information about racial or ethnic origin, political views, religious beliefs, etc.) unless you choose to provide us with such information. We strongly recommend that you do not post any medical information or other sensitive data in your profile or messages on the platform that is not required for participation in the training program.
Purposes of personal data processing:
We collect and use users' personal information only for specified and legitimate purposes, including:
- Provision of services: Your registration and subscription information is needed to create an account, authenticate you on the site, and provide access to purchased training materials. Processing personal data allows us to fulfill our obligations under the contract (to provide you with the training services you paid for).
- Payment processing:: Payment data (to the extent available to the Company) is used to process your transactions, confirm payments, and activate subscriptions. For example, we record the fact of payment, the date, and the amount of the payment to provide or extend access to materials. If auto-renewal is enabled, we will initiate recurring transactions through your payment provider using your card token.
- Communication with the user: Email and/or phone may be used to send important notifications related to the use of the service. This includes: an email with your login details after payment, notifications about a subscription about to end or successful renewal, notifications about changes to the terms of service or privacy policy, and customer support responses to your inquiries. Your contact information may also be used to send you service news or special offers from FitmeClub, but only if you have given your express consent (for example, by subscribing to the newsletter). You can always unsubscribe from marketing communications by using the unsubscribe link in the email or by changing your settings in your personal account.
- Personalization and service improvement: Analytics data (cookies, usage statistics) help us understand what content is most interesting to users and how they interact with the platform. This is necessary to improve content and functionality – for example, we can recommend new programs based on those you've already completed, improve site navigation, and optimize page loading speed. In some cases, we may process your data to make personalized recommendations (for example, recommending suitable workouts based on what you've previously viewed), but such recommendations are generated automatically, and you always decide whether to follow them or not.
- Ensuring security and compliance with the law: We may use personal data to prevent fraud and other illegal activities on the platform. For example, IP addresses and technical data can help identify multiple registrations or unauthorized access. If we suspect a violation of the User Agreement or an attempt to defraud (including bypassing regional restrictions), we may use the relevant data to investigate the incident and to protect our legitimate interests. In addition, we process data where this is necessary to comply with legal requirements or respond to legitimate requests from government authorities. Personal data may be disclosed to competent authorities without the user's consent only in cases and according to the procedure expressly provided by law (for example, by court order or official request from law enforcement agencies).
Cookies and similar technologies:
- What is a cookie: Cookie – These are small text files that our website may store on your browser or device when you visit. They help us recognize you on return visits, save your user preferences, and perform a number of functions (such as authorization, traffic analysis, etc.).
- How we use them: FitmeClub uses cookies to: (a) store information about your session (for example, so that you remain logged in without having to re-enter your password each time); (b) remember settings, such as the interface language; (c) collect anonymous statistics about website usage (which pages are visited, how long you spend on the site, etc.), which allows us to improve content and navigation. We may also use third-party cookies from analytics services (such as Google Analytics) for aggregated traffic analysis, but these services do not receive information that personally identifies you.
- Technical limitations: One User may be limited to simultaneous use of an account on a certain number of devices (for example, simultaneous viewing of a video on no more than 2 devices). Attempts to simultaneously log in from multiple devices or suspicious activity (for example, simultaneous access under the same login from different geographic regions) may be considered a violation. In such cases, the Company reserves the right to temporarily block access and request identity verification. Continued suspicious activity after a warning may result in immediate termination of access to the content without a refund.
- Cookie management: You have the option to disable the saving of cookies at any time by changing your browser settings (usually you can prevent your browser from accepting new cookies, delete existing cookies, or set up notifications about sending cookies). Please note that disabling cookies may result in some FitmeClub features becoming unavailable or not functioning properly (for example, the site may 'forget' your login or preferences). For more information on how to manage cookies, please refer to your browser's Help section. By continuing to use our site without changing your cookie settings, you agree to our use of these files.
Transfer of data to third parties:
- Платежные сервисы: Для обработки платежей за подписку мы привлекаем сторонний платежный шлюз (провайдера). Ему передаются необходимые данные транзакции: сумма, валюта, а также платежные реквизиты, введенные вами на защищенной странице. Эти провайдеры действуют в качестве самостоятельных контролеров данных в части выполнения платежей, соблюдают стандарты безопасности и конфиденциальности. Мы передаем им только ту информацию, которая необходима для проведения оплаты или возврата (при исключительных обстоятельствах, например, двойном списании).
- Email-рассылки и хостинг: Мы можем использовать сторонние сервисы для отправки электронных писем (например, сервис рассылок) или для хостинга нашего веб-сайта. Такие сервисы могут обрабатывать ваш адрес электронной почты, имя или другие данные от нашего имени, строго в том объеме, который нужен для выполнения своих функций (рассылка уведомлений, обеспечение работы сайта). С ними заключены договоренности о конфиденциальности, и они не вправе использовать ваши данные в иных целях.
- Analytics: As mentioned above, we may integrate web analytics tools on the site (such as Google Analytics and similar services). These tools collect de-identified data about your interactions with the site (such as pages viewed, time on site, and navigation paths) and process it on their own servers. We use this data in aggregate to analyze trends. Google Analytics, for example, operates under its own privacy policy and does not provide us with personally identifiable information about users. You can opt out of Google Analytics by installing a blocking plug-in in your browser.
- Disclosure Required by Law: The Company may disclose a user’s personal data to third parties in cases expressly provided for by law. For example, if we receive a legally binding request from a court, law-enforcement agency, or tax authority to provide certain data, we are obliged to furnish the requested information. In each such case, we will verify the legality of the request and disclose only the minimum amount of data necessary to comply with the law. Your data may also be disclosed in the context of legal proceedings if you are a party to a dispute and the data on our service serves as evidence, or to protect the Company’s rights and property in legal proceedings (in accordance with applicable law).
- Business Combination: In the unlikely event of a FitmeClub corporate reorganization (for example, a merger, acquisition, or sale of the company), users’ personal data may be transferred to the successor entity or new owner along with other assets. In such a case, we will require the new party to adhere to this Privacy Policy with respect to your data, and you will be notified of the change in control of your personal data and may stop using the service if you so choose.
Protection of Personal Data
We implement appropriate organizational and technical measures to protect your personal data against unauthorized access, alteration, loss, or destruction. These measures include: restricting employee access to data (access is granted only to authorized personnel who need it to perform their duties), using secure connections (HTTPS, encryption of data in transit), hosting data on secured servers with restricted access, regularly updating software, and monitoring for vulnerabilities. We also adhere to a strict confidentiality policy regarding your data: under no circumstances are users’ personal data publicly disclosed or sold to third parties. The confidentiality of users’ personal data is guaranteed, except where disclosure is voluntarily made by the user (e.g., in comments or reviews) or is required by law. Please note that no method of data transmission over the Internet or method of electronic storage is 100% secure; therefore, we cannot absolutely guarantee that data will never be subject to unauthorized access. However, we continuously improve our security practices to minimize these risks as much as possible.
Data Retention:
We store users’ personal data only for as long as necessary for the purposes for which it was collected or for the period required by law. For example, information about your accounts and subscriptions is retained while you maintain an active account with the FitmeClub. When an account is deleted at the user’s request (or in the event of prolonged inactivity), we delete or anonymize the associated personal data, except for data that we are required to retain longer to fulfill legal obligations. Thus, payment-related financial information may be kept in accounting records for, for example, three years (or for another period as required by applicable tax and accounting laws) even after the account is deactivated. All information is retained no longer than necessary for the provision of services or other processing purposes, after which it is securely deleted or anonymized. When the retention period expires, the Company either irreversibly deletes personal data or anonymizes it in such a way that the user can no longer be identified.
User rights in relation to personal data:
In accordance with personal data protection legislation, you have a number of rights in relation to the information you provide to us:
- Right of access: You have the right to request confirmation as to whether we process your personal data, as well as to clarify which specific data we store, for what purposes, and how it is processed. Much of this information is available to you directly in your account (e.g., your profile details and payment history). To obtain a full report, you may send us an official request via our support email, specifying the subject of your request.
- Right to rectification: If you discover that any of your personal information is out of date, inaccurate, or incomplete, you can correct it at any time. Much of this information (such as your name and contact email) can be edited independently in your account profile. If the required information cannot be edited through the interface, please contact support – we will make the necessary changes.
- Right to Erasure (“Right to be Forgotten”): You have the right to request the deletion of your personal data processed by FitmeClub. This can be exercised by submitting an account deletion request. Please note that complete deletion may not be possible in all cases—for example, we cannot delete information that we are legally required to retain (see the Data Retention section). However, your login credentials, profile content, and other information not subject to mandatory retention will be deleted. After your request is fulfilled, you will lose access to the service, and your account cannot be restored.
- Right to Withdraw Consent: Where the processing of your data is based on consent (e.g., receiving marketing communications), you may withdraw your consent at any time. This will not affect the lawfulness of processing carried out before the withdrawal. You can unsubscribe from marketing emails via the link in the message or by adjusting the relevant checkbox in your account settings. If we implement on-site cookie consent or other additional consents, you will also be able to withdraw them through the settings.
- Right to Restrict Processing: You may request that we temporarily suspend the processing of your data (other than storage) in cases provided by law – for example, if you dispute the accuracy of the data or object to its processing – for a period allowing us to verify the accuracy of the information or our grounds for doing so.
- Right to object: You have the right to object to the processing of certain types of data where there are lawful grounds to do so. In particular, you may prohibit the processing of your data for direct marketing purposes. Where we process data on the basis of our legitimate interests, you may object, in which case we will cease such processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
- Right to data portability: In certain cases, you have the right to receive the personal data you have provided to us in a structured, commonly used, electronic format and to transmit it to another service provider. In practice, given the relatively small volume of personal data in the FitmeClub, this need may not arise; however, we are prepared to consider such a request.
- You can contact us using the details provided at the end of this Privacy Policy to exercise your rights. We may ask you to verify your identity (to ensure the request is made by the data subject) and to clarify the details of your request. We will respond within the time limits established by law (usually within 30 calendar days). Please note that certain rights may be limited by law—for example, we may refuse to delete data that we are legally required to retain, or decline manifestly excessive or repetitive requests.
International Data Transfers:
As our Company is registered in Ukraine, your personal data are primarily stored and processed in Ukraine. We do not transfer your personal data to countries that do not provide an adequate level of data protection, except when engaging third-party services mentioned above (e.g., email delivery or analytics tools that may be located outside Ukraine). In such cases, we implement safeguards for the transfer—such as relying on Standard Contractual Clauses or other mechanisms provided by law. By using the FitmeClub, you understand and agree that your data may be processed both in your country and in Ukraine. If you are located in the European Economic Area (EEA) or another jurisdiction with data-transfer requirements, we will ensure that any such transfers comply with the applicable legal requirements.
Privacy of minors:
The FitmeClub service is not intended for individuals under 18 years of age, and we do not knowingly collect personal data from children. If we become aware that a child’s personal data has been provided to us without parental consent, we will take steps to delete that information. Parents and legal guardians are encouraged to monitor their children’s use of the internet and our services. If you believe a child may have provided us with personal data, please contact our support team and we will promptly remove the relevant records. Please note that users under 18 are prohibited from registering and from using FitmeClub’s paid services in accordance with our Terms of Use.
Changes to the privacy policy:
We may update this Privacy Policy from time to time due to changes in our service or legal requirements. In the event of material changes (for example, expanding the categories of data collected or the ways information is used), we will clearly notify users—by means of a prominent notice on the website or via email—and, where required by law, request renewed consent. The current version of the Policy is always available on our website at the bottom of the homepage (the “Privacy Policy” section). The date of the last update is indicated at the beginning of the document. We encourage you to review the Policy periodically to stay informed about how we protect your data. Your continued use of the service after the updated Policy is published constitutes acceptance of the changes.
Contacts:
For any questions related to this Privacy Policy or our use of your personal data, you can contact us: Data Controller: Sole Proprietor Polenok Anastasiia (FitmeClub). We will do our best to respond to any requests or complaints regarding personal data. If you are not satisfied with our response, you have the right to lodge a complaint with the competent data protection authority in your jurisdiction. For Ukraine, this is the Ukrainian Parliament Commissioner for Human Rights (Ombudsperson), which serves as the supervisory authority for personal data.
Thank you for trusting FitmeClub. We value your privacy and are committed to protecting it. By using our service, you help us become better – and together, we create a safe and comfortable space for online training!