Privacy policy
This explains what we do with personal data — yours as a studio running on Fitnez Studios, yours as someone reading this site, and your members' when you put it into the platform. It is written to be read, not to be survived.
Who we are
Fitnez Studios is operated by PLACEHOLDER — registered legal entity name, company number PLACEHOLDER, registered at PLACEHOLDER. That entity is the data controller for everything described in sections 3 and 4.
PLACEHOLDER — name the EU/UK representative and the data protection officer here if either is required, with an address for each.
For anything in this policy, write to us at the email at the foot of this page or the one in section 16. We answer within one business day.
The two roles we play
We handle personal data in two quite different capacities, and which one applies changes who you should ask about what.
Where we are the processor, we act only on the studio's documented instructions. If you are a studio member asking about your own data, ask your studio first — they decide what is collected and how long it is kept.
Controller — for studio owners, staff, and anyone visiting this marketing site. We decide why and how that data is used, and this policy governs it.
Processor — for your members' data inside your account: their bookings and attendance, purchases and package credits, wallet balances, and the WhatsApp and email conversations you have with them. You decide; we process on your behalf.
What we collect when you visit this site
Nothing you have not typed, plus the technical minimum needed to serve a page and keep bots out.
Demo requests — what kind of studio you run, whether you have opened yet, what platform you are on today, whether you want a branded member app, roughly how big the operation is, and your name, work email, phone, and studio name.
Contact messages — your name, work email, phone, studio or company, the topic you pick, and what you write.
The AI assistant — the messages you send it, plus a short-lived visitor and conversation reference so a reply reaches the right window. See section 9.
Server logs — IP address, browser, and requested page, kept briefly to spot abuse and diagnose faults.
A bot check — Cloudflare Turnstile runs on both forms. It tells us “human” or “not”; it does not profile you or follow you around the web.
What we collect when you use the platform
Account and team data: the names, emails, and roles of the people you invite, whether an invitation is still pending, what permissions they hold, and the record of who changed what and when.
Configuration and content: your locations, training programs, classes and schedules, packages and prices, holiday calendar, invoice and tax settings, anything you upload to the media library, and the copy, images, and branding on your booking website.
Usage: which features get used and when, so we can support you and see what to build next.
Billing: your plan, billing interval, invoices, and payment status. Card numbers are handled by the payment provider — they never reach our servers and we never store them.
Data you bring with you: when we run a guided import from the platform you are leaving, the members, packages, schedules, and balances in that file land in your account. From that point they are covered by section 5, and the working copies of the import are deleted once you confirm it landed correctly.
Support: the emails and chats you send us, and our replies.
Your members' data
Everything a studio records about its members belongs to that studio. We store and process it to run the service, and for nothing else.
The platform also sends messages on the studio's behalf — booking confirmations, class reminders, waitlist promotions, birthday messages, and anything built from the email templates — using our email infrastructure and the studio's own connected WhatsApp number. The studio decides which of those go out and to whom.
We do not sell that data. We do not market to your members. We do not mine it to build a competing product, and we do not use it to train models.
PLACEHOLDER — link the data processing agreement and the current sub-processor list here once both exist.
In practice, a studio's account holds four kinds of member data:
Who they are — profile and contact details, the client groups you sort them into, and whether you have blocked them from booking.
What they book — bookings and cancellations, waitlist positions, the spot they picked, check-ins, no-shows, and entries in events and challenges.
What they pay — packages and remaining credits, validity dates, wallet balance and every credit and debit against it, transactions, invoices, and badges or rewards you grant.
What they say — WhatsApp conversations in the shared inbox, and the emails the platform sends them on your behalf.
Why we are allowed to use it
Under the GDPR, each use rests on one of these bases:
To perform our contract with you — running your account, taking payment, providing support.
Our legitimate interests — keeping the service secure, preventing abuse, understanding which features get used, and replying when you ask us something. Never in a way that overrides your rights.
Your consent — for marketing email you opted into, which you can withdraw with one click in any message.
Legal obligation — tax, accounting, and anything a court or regulator properly requires.
The assistant on this site
The chat widget answers questions about the product. What you type is sent to our servers to generate a reply, and we keep a short record of the exchange to improve the answers.
PLACEHOLDER — name the model provider, whether prompts leave our infrastructure, and confirm the no-training-on-your-data commitment in writing.
It is a sales assistant on a marketing site, so treat it as one: do not paste member records, card numbers, or anything confidential into it.
Sending data abroad
Some of our providers operate outside the country you are in. Where data leaves the EEA or the UK, we rely on an adequacy decision or on standard contractual clauses, with additional safeguards where they are needed.
PLACEHOLDER — list the countries data is processed in, and the mechanism relied on for each.
How long we keep it
We keep personal data only as long as it is doing a job, then delete it.
Account and member data — for as long as the account is open, then PLACEHOLDER days for you to export it, then deleted. There is no export fee and no lock-in.
Invoices and tax records — as long as accounting law requires, which is longer than we would otherwise keep them.
Demo requests and contact messages — PLACEHOLDER months, then deleted.
Server logs and chat sessions — days, not months.
Backups roll off on their own cycle, so deletion can take a little longer there than in the live system.
How we protect it
Traffic runs over TLS, data is encrypted at rest, and access inside the company is limited to the people whose job needs it.
In your own account, the controls are yours: sixty granular permission keys, custom roles, approvals that stop wallet credits, wallet debits, and package changes from happening without a named approver, and an activity trail showing who changed what and when. Use them — most incidents are a permission someone should not have had.
If a breach affects your data, we will tell you and the regulator within the time the law allows, with what we know and what we are doing about it.
Your rights
Wherever you are, and whatever the local law calls them, you can ask us to:
show you what we hold, and give you a copy in a portable format;
correct anything that is wrong;
delete it, where we do not have to keep it;
restrict or object to a particular use, including profiling;
withdraw consent you gave, without affecting what happened before you withdrew it.
If you are a studio member, not a studio
Your studio decides what is collected about you and why, so your request goes to them first — they hold the account, and they can answer it from inside the platform.
If you cannot reach them, write to us anyway. We will help them respond, and where we can act ourselves, we will.
Children
The platform is for businesses. Nobody under 16 should hold a Fitnez Studios account.
Studios do run classes and events for minors, and a parent or guardian books on their behalf. Getting consent for that, and setting the age limits on your training programs, is the studio's responsibility.
If you believe a child's data reached us without that consent, tell us and we will delete it.
Changes, and how to reach us
We update this policy as the product and the law change. The date at the top always reflects the current version, and for anything material we email the account owner before it takes effect.
Questions, requests, or complaints: use the email address at the foot of this page, the contact form, or the postal address in section 1.
If we have not resolved something to your satisfaction, you can complain to your local data protection authority — PLACEHOLDER, name ours and link it.
Want to know what we hold on you?
Ask, and we will tell you — or delete it. No form to fill in, no reason required.
Also worth reading: our terms & conditions · Prefer to see it working first? Book a demo.

