← Back to legal documents
Leggi la versione italiana

Version 1.0 — in effect from 2026-08-12

Courtesy translation. In the event of any discrepancy, the Italian version prevails.

PRIVACY NOTICE — FITLOOP APP (USERS)

pursuant to Articles 13 and 14 of Regulation (EU) 2016/679

Version 1.0 — last updated 12 August 2026

By means of this document (the "Notice"), the Controller, as defined below, wishes to inform you, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "GDPR"), of the purposes and manner of the processing of your personal data carried out in connection with the FitLoop mobile application (the "App") and the services connected to it, as well as of the rights that the GDPR grants you.

This Notice is also provided pursuant to Article 14 of the GDPR with reference to personal data that is not collected directly from you, such as data generated by the platform's systems on the basis of the information you provide (for example, the body measurements and the three-dimensional avatar derived from photographs) and any data received from Partner Gyms within the shared scope referred to in Article 9 below. This Notice entirely supersedes any previous version.

1. Controller, contact details and Data Protection Officer (DPO)

The Controller is Fit & Social S.r.l. Unipersonale, with registered office at Viale Risorgimento 19/A, 25060 Cellatica (BS), tax code and VAT number 04041980980, registration number with the Brescia Companies Register 04041980980, SDI recipient code USAL8PV, acting through its pro tempore legal representative Mr Nicola Finazzi (the "Controller").

For any matter relating to the processing of your personal data, to receive any information relating to this Notice, and to exercise the rights referred to in Article 12 below, you may contact the Controller:

  • by ordinary mail: Fit & Social S.r.l. Unipersonale, Viale Risorgimento 19/A, 25060 Cellatica (BS);
  • by sending an email to: info@fitloop.net;
  • by sending a certified email message to the PEC address: fitandsocial@pec.it;
  • through the dedicated "Privacy" section available within the App.

Data Protection Officer ("DPO"): external DPO — [•]. The Controller will appoint as DPO an external professional or organisation, independent and free from conflicts of interest pursuant to Article 38(6) of the GDPR; the DPO's contact details will be communicated to the Garante per la protezione dei dati personali pursuant to Article 37(7) of the GDPR and, once the appointment has been finalised, published in this Notice and in the App.

The Controller, including through the structures designated for that purpose, will take charge of your request and provide you with a response without undue delay and, in any event, within thirty days of receipt of the request, pursuant to Article 12 of the GDPR. That period may be extended by two months, if necessary, taking into account the complexity and number of requests; in that case, the Controller will inform you of the extension and of the reasons for it within thirty days of receipt of the request. Where the Controller has reasonable doubts concerning the identity of the natural person making the request, it may request further information necessary to confirm the data subject's identity.

2. What personal data we process

For the purposes indicated in this Notice, the Controller processes the following categories of personal data:

a) Personal identification, contact and login details: first name, last name, date of birth, tax code, email address, telephone number and any further contact details you provide; App authentication credentials (username and password) and temporary verification codes (OTP) sent by SMS or email for the purposes of authentication and confirmation of certain operations. Your tax code is requested during registration and is processed in order to verify the truthfulness of the declared date of birth, to protect minors (see Article 10): where the declared age is under 15 years, registration cannot be completed.

b) Photographs uploaded to create the Avatar: one or more photographs of the body (and possibly of the face) taken or uploaded by you through the App. The photographs are used exclusively to process your body measurements and your three-dimensional avatar and are deleted immediately after processing: the Controller does not retain them. The following are derived from the photographs: (i) the body measurements (thirteen body circumferences and further anthropometric parameters); (ii) the 3D avatar representing your figure. Such derived data, being capable of revealing information about your physical condition, are treated by the Controller, on a precautionary basis, as health data pursuant to Article 9 of the GDPR. They do not, however, constitute biometric data within the meaning of Article 4(14) of the GDPR, as they are not processed for the purpose of uniquely identifying you.

c) Data from the initial questionnaire: the answers you provide to the questionnaire presented when activating the personalised services, concerning sporting history, any medical conditions and injuries, dietary habits, sleep and lifestyle. This is data belonging to special categories (health data) within the meaning of Article 9 of the GDPR, processed exclusively upon your explicit consent.

d) Loop usage data: the information recorded as part of the App's paths ("Loops"): training sessions performed, nutrition logged, supplementation taken, rest and recovery. As they relate to your physical condition, such data are treated as health data within the meaning of Article 9 of the GDPR.

e) Conversations with the Loop Coach AI: the messages you exchange with the App's virtual assistant, which may contain health data, as well as any further content you freely enter into the conversation.

f) Payment data: purchases of subscriptions and services are made outside the app stores, on the Controller's web store accessible via a link from the App, with payments processed by the payment service provider Stripe; the app stores (Apple App Store, Google Play) are involved solely in the distribution of the App (downloads and updates). The Controller receives confirmation of the outcome of transactions and the data necessary for the accounting management of orders, but does not retain payment card numbers.

g) Technical and App usage data: device model, operating system version, technical identifiers, IP address, application logs, error reports (crash reports) and App usage events (analytics); the latter are collected subject to your consent choice, where required (see Article 5).

h) Session recordings (session replay): recordings of the navigation screens within the App, activated exclusively upon your prior consent and with content masking, as described in Article 5 below.

i) Geolocation data: the location of your device, processed exclusively for the nearby-gym search function and only upon prior grant of the relevant system permission, revocable at any time from the device settings.

j) Content posted in the social feed: text, images and other content you voluntarily post in the App's social areas, visible to other users according to the available visibility settings.

k) Referral programme data: your personal invitation code, and the number and activation status of users invited using your code.

l) Credits and wallet: the balance and transaction history of in-app credits accrued (for example through the referral programme) and used within the App.

3. Purposes of the processing, legal bases and retention periods

The Controller processes your personal data for the purposes, on the legal bases, and for the retention periods indicated in the table below.

Purpose of the processingLegal basisRetention period
Creation and management of the account; provision of the App's features and of the requested services (including the Premium Subscription)Performance of the contract (Article 6(1)(b) GDPR)Duration of the account; thereafter, up to 10 years where necessary to comply with civil-law obligations and to protect the Controller's rights (Article 2946 of the Italian Civil Code)
Verification of the truthfulness of the declared date of birth by means of the tax code, with blocking of registration for persons under 15 years of age (protection of minors — see Article 10)Performance of the contract (Article 6(1)(b) GDPR) and obligation to protect minors (Article 6(1)(c) GDPR, in relation to Article 2-quinquies of Legislative Decree No. 196/2003 and to Law No. 132/2025)Duration of the account
Processing of the 3D avatar and body measurements from photographs; generation of personalised programmes (Loops)Explicit consent (Article 9(2)(a) GDPR), revocable at any timePhotographs: deleted immediately after processing. Body measurements: for the duration of the account. Replaced avatar files: 90 days from the new scan
Collection and analysis of the initial questionnaire on health and lifestyleExplicit consent (Article 9(2)(a) GDPR), revocable at any timeFor the duration of the account, unless consent is withdrawn
Personalised coaching through the Loop Coach AI (including the human safety review of the questionnaire answers — see Article 4)Explicit consent (Article 9(2)(a) GDPR) for health data; performance of the contract (Article 6(1)(b) GDPR) for the remaining components of the serviceConversations: for the duration of the account, unless consent is withdrawn or earlier deletion occurs
Security of the App and of the systems, prevention of fraud and abuseLegitimate interest of the Controller (Article 6(1)(f) GDPR)Security logs: 12 months from collection, save for ongoing incident investigations
Product analytics and session recordings (session replay) — see Article 5Consent (Article 6(1)(a) GDPR), revocable at any time in-appSession recordings: 30 days. Analytics events: 24 months, in pseudonymised form, thereafter deletion or irreversible anonymisation
Direct marketing (sending of the Controller's promotional communications by email and push notifications) — adult users onlyConsent (Article 6(1)(a) GDPR)Until consent is withdrawn
Profiling for marketing purposes (analysis of your preferences and of your use of the App to personalise offers, content and promotional communications) — adult users onlyConsent (Article 6(1)(a) GDPR), distinct and separate from consent to direct marketingUntil consent is withdrawn
Service communications (operational and security notices, and notices of changes to the service)Performance of the contract (Article 6(1)(b) GDPR)Duration of the account
Compliance with legal obligations (accounting, tax, responding to requests from the authorities)Legal obligation (Article 6(1)(c) GDPR)10 years
Management of orders placed on the marketplace (supplements)Performance of the contract (Article 6(1)(b) GDPR)Time necessary to fulfil the order; accounting records: 10 years
Management of the referral programme and crediting of creditsPerformance of the contract (Article 6(1)(b) GDPR); legitimate interest (Article 6(1)(f) GDPR) for the prevention of abuseDuration of the account
Publication of content in the social feedPerformance of the contract (Article 6(1)(b) GDPR)Until removed by you or until the account is closed
Search for nearby gyms by means of geolocationConsent given by means of the system permission (Article 6(1)(a) GDPR)Location processed in real time and not retained

Withdrawal of consent does not affect the lawfulness of processing based on consent given before its withdrawal. Once the periods indicated above have elapsed, personal data are deleted or irreversibly anonymised, unless their further retention is necessary to comply with a legal obligation or to establish, exercise or defend a legal claim.

4. Artificial intelligence systems

The personalised programmes (Loops) and the coaching service (Loop Coach AI) are generated using artificial intelligence models provided by Anthropic PBC (Claude API) and, in the event that the main provider is unavailable, using models run directly on the Controller's own infrastructure (a backup solution, known as a "fallback"), with no transmission of data to third parties.

In accordance with the transparency obligations set out in Article 50 of Regulation (EU) 2024/1689 (the "AI Act"), the Controller informs you that: (i) by interacting with the Loop Coach AI you are interacting with an artificial intelligence system and not with a human operator; (ii) the programmes, plans and suggestions provided by the App are content generated by artificial intelligence systems and are indicated as such in the interface; (iii) the images and synthetic content generated or processed by artificial intelligence and shareable outside the App — such as the three-dimensional avatar and the "Share Card" images — are marked as artificially generated or manipulated, including by means of machine-readable marking affixed by the platform.

The data transmitted to the AI service provider are minimised and pseudonymised: they do not include your name or your contact details. Pursuant to the data processing agreement (DPA) entered into with the provider, the data transmitted are not used by the provider to train its own models.

The generation of personalised programmes involves profiling and automated processing of your data within the meaning of Article 22 of the GDPR, necessary for the performance of the contract and, for health data, based on your explicit consent. You have, in any event, the right to obtain human intervention from the Controller, to express your point of view, and to contest the decision, by contacting the details indicated in Article 1. The human review mechanism for your safety (the "Medical Gate"), described further below in this Article, constitutes a measure of human oversight over the automated processing, which reinforces this right to human intervention.

The initial questionnaire and the conversations with the Loop Coach AI are monitored by safety protocols that identify risk signals ("red flags") and trigger automatic blocks — including the protocols dedicated to eating disorders (DCA) — suspending the generation of potentially detrimental content and inviting the user to consult a healthcare professional. The programmes and suggestions generated by the App do not, in any case, constitute medical, healthcare or nutritional advice.

Human review for your safety (the "Medical Gate"). Where the answers you provide to the questionnaire — when activating the personalised services or upon a subsequent update — reveal conditions relevant to your safety (for example, certain medical conditions, ongoing drug therapies, pregnancy or breastfeeding), the automatic generation of the nutrition and supplementation plans is temporarily suspended and a review is triggered by authorised personnel of the Controller, instructed pursuant to Article 29 of the GDPR and bound by confidentiality obligations; the Training and Rest Loops remain regularly available. The review is taken up within 48 working hours and the outcome is communicated to you through the App: unblocking of the generation, possibly with precautionary adjustments; the proposal of a dedicated path with a qualified professional, the terms of which are communicated to you before you decide whether to take part; or, where the service cannot be safely provided to you, a refund in accordance with the arrangements indicated in the App's contractual terms. Pending the review, the Loop Coach AI does not provide advice on nutrition or supplementation, while the functions relating to training and rest remain available.

The review takes place exclusively within the Controller's organisation and does not involve the disclosure of your data to any new recipient external to those indicated in Article 6. For accountability purposes (Article 5(2) GDPR), the Controller retains the records of the review (rules triggered, outcome and related timing) for the duration of the account and for a further period of 24 months, save for further retention in the event of litigation. The internal assessments underlying the review are not communicated to you: you receive only a clear and neutral explanation of the outcome; the suspension and the review do not, in any case, constitute a medical assessment, a diagnosis, or a judgment on your state of health.

5. Analytics and session recordings (PostHog)

For the purposes of product analysis and improvement, the Controller makes use of the PostHog platform, hosted exclusively within the European Union (Frankfurt, Germany).

The analytics and session recording (session replay) tools are disabled by default and are activated only upon your specific consent, distinct from the other consents, which you may withdraw at any time through the App's preferences section, with immediate effect.

Session recordings are made with masking of inputs and text; screens displaying health data (questionnaire, body measurements, avatar, conversations with the Loop Coach AI) are excluded from recording or masked entirely, so that the recordings do not contain health data. The collection of the IP address for analytics purposes is disabled.

Session recordings are retained for 30 days. PostHog acts as a processor pursuant to Article 28 of the GDPR.

6. Recipients of personal data and processors (Article 28 GDPR)

In order to pursue the purposes referred to in Article 3, your personal data may be disclosed to the following categories of recipients, each within the limits of what is necessary for the performance of their respective tasks.

RecipientPrivacy roleActivity and place of processing
Amazon Web Services (AWS)Processor under Article 28 GDPRHosting of infrastructure and data — EU region (Ireland)
Anthropic PBCProcessor under Article 28 GDPRArtificial intelligence services (Loop generation, coaching) — USA (see Article 7)
StripeProcessor under Article 28 GDPRPayment services for purchases made on the Controller's web store; the Controller does not retain card numbers (see Article 7)
BrevoProcessor under Article 28 GDPRSending of transactional and marketing emails — EU
Google / FirebaseProcessor under Article 28 GDPRAnalytics, push notifications, crash reporting (Crashlytics), remote configuration (see Article 7)
SentryProcessor under Article 28 GDPRCrash reporting and error diagnostics (see Article 7)
PostHogProcessor under Article 28 GDPRProduct analytics and session replay — EU (Frankfurt) (see Article 5)
BranchProcessor under Article 28 GDPRDeep linking for the referral programme — when activated (see Article 7)
Apple / Google (app stores)Independent controllersDistribution of the App (downloads and updates) under their respective terms; purchases of subscriptions and services take place outside the stores, on the Controller's web store (Stripe payments)
Partner GymsJoint controllers under Article 26 GDPRLimited to the shared scope, when you purchase or activate gym services through the App or share programmes, measurements or your avatar with trainers — see Article 9
Third-party supplement manufacturer (indicated on the product page and at checkout) and appointed couriersIndependent controllersFulfilment, shipping and delivery of marketplace orders
Consultants and professional advisers of the Controller; public authoritiesProcessors under Article 28, or independent controllers, depending on the caseAdministrative, accounting, tax and legal matters; responding to requests from authorities empowered by law

Your personal data are not disclosed to the public at large. The updated list of processors appointed by the Controller is available upon request at the contact details indicated in Article 1. The data may also be processed by the Controller's staff, duly authorised and instructed pursuant to Article 29 of the GDPR.

7. Transfers of personal data to third countries

The Controller favours providers that process data within the European Union (in particular: AWS — Ireland; PostHog — Frankfurt; Brevo — EU). Where the pursuit of the purposes referred to in Article 3 entails the transfer of personal data to third countries — in particular to the United States, with reference to Anthropic, Stripe, Google, Sentry and Branch — the transfer takes place:

  • on the basis of an adequacy decision of the European Commission pursuant to Article 45 of the GDPR (the EU-U.S. Data Privacy Framework, for certified providers); or
  • on the basis of the Standard Contractual Clauses approved by the European Commission pursuant to Article 46(2)(c) of the GDPR, supplemented, where necessary, by additional technical and organisational measures.

With specific reference to Anthropic PBC, the transfer is governed by the Standard Contractual Clauses included in the data processing agreement entered into with the provider (Anthropic is not certified under the EU-U.S. Data Privacy Framework).

A copy of the safeguards adopted for the transfers may be requested at the Controller's contact details indicated in Article 1.

8. Nature of the provision of data and consequences of refusal

The provision of the data necessary for the conclusion and performance of the contract (personal identification data — including the tax code, required to verify age for the protection of minors —, contact details and credentials) is mandatory: without it, it is not possible to create the account or provide the App's services.

Explicit consent to the processing of health data (photographs and derived data, questionnaire, Loop data, coaching) is required exclusively for the use of the personalised functions: without such consent, the App cannot provide the core personalised functions (processing of the avatar and measurements, generation of personalised Loops, coaching), without prejudice to the possibility of using any functions that do not require such data.

Consent for the purposes of direct marketing, profiling for marketing purposes, analytics, and session recording (session replay) is always optional: the failure to give it, or its withdrawal, does not affect the use of the App in any way. Consents are collected in a granular and separate manner — (i) processing of data relating to health and physical characteristics; (ii) direct marketing; (iii) profiling for marketing purposes; (iv) analytics and session replay — and may be given, refused and withdrawn individually, at any time, through the App's preferences section. Each consent may be withdrawn at any time, as easily as it was given, without prejudice to the lawfulness of the processing carried out before its withdrawal. Consents for the purposes of direct marketing and profiling for marketing purposes are not offered to minor users: such processing is reserved to adult users and is not, in any case, activated for users between 15 and 17 years of age (see Article 10).

9. Joint controllership with Partner Gyms (Article 26 GDPR)

Where you purchase, through the App, products or services of a gym taking part in the FitLoop network (the "Partner Gym"), or activate the sharing of your programmes, measurements or avatar with the Partner Gym's trainers, the Controller and the Partner Gym process the personal data falling within that shared scope as joint controllers pursuant to Article 26 of the GDPR.

The shared scope includes, in particular: (i) the personal identification data and subscription status necessary for the provision of the Partner Gym's services purchased or activated through the App; (ii) the programmes, measurements and avatar that you have chosen to share with the trainers; (iii) any joint marketing initiatives, exclusively upon your consent; (iv) data relating to control of access to the facility. Any other processing remains within the exclusive controllership of each party.

The essential content of the joint-controllership arrangement is made available to data subjects upon request. The point of contact designated for data subjects is Fit & Social S.r.l. Unipersonale, at the contact details indicated in Article 1. Your right to exercise the rights referred to in Article 12 in respect of, and against, each joint controller remains unaffected.

10. Minors

The App is reserved to persons who have reached 15 years of age. The registration procedure requires the declaration of your date of birth: where the declared age is under 15 years, the App is entirely blocked and registration cannot be completed. The truthfulness of the declared date of birth is further verified by means of the tax code requested during registration, which incorporates the date of birth (see Article 2, letter a). The Controller does not knowingly process the personal data of persons under 15 years of age: should it become aware of any such processing, it will promptly delete the data. Any reports may be sent to info@fitloop.net.

The age threshold thus identified is consistent with the applicable regulatory framework: Article 2-quinquies of Legislative Decree No. 196 of 30 June 2003 recognises the capacity of a minor who has reached the age of fourteen to validly give consent to the processing of their personal data in relation to the direct offer of information society services; Law No. 132 of 23 September 2025, on artificial intelligence, makes access by minors under fourteen years of age to artificial intelligence systems subject to the consent of the person exercising parental responsibility, and allows minors who have reached the age of fourteen to give their own consent autonomously, provided that the information relating to the use of such systems is easily accessible and comprehensible. Since the App is reserved to persons who have reached 15 years of age, both thresholds are met.

To protect users between 15 and 17 years of age, the Controller applies the following enhanced measures:

  • age verification (age assurance): declaration of the date of birth during registration; complete blocking of the App and impossibility of completing registration where the declared age is under 15 years; verification of the truthfulness of the declared date of birth by means of the tax code requested during registration;
  • age-appropriate language: the information and notices provided through the App — including those relating to the artificial intelligence systems (see Article 4) — are drafted in clear, simple language that is comprehensible also for users between 15 and 17 years of age;
  • enhanced safety protocols for adolescents: the protocols for identifying risk signals ("red flags") and those dedicated to eating disorders (DCA), described in Article 4, apply more precautionary thresholds to minor users, block content promoting aggressive caloric restriction, and direct the user towards qualified support resources;
  • purchases: purchases of subscriptions and services are made outside the app stores, on the Controller's web store accessible via a link from the App, with payments processed by Stripe on the terms set by it (including the rules applicable to payments made by minors); spending commitments made by minor users require the authorisation of the person exercising parental responsibility;
  • exclusion of marketing and profiling: consents for the purposes of direct marketing and profiling for marketing purposes are not offered to minor users, and the related processing is not, in any case, activated in respect of them (see Articles 3 and 8).

11. Manner of processing and security measures (Article 32 GDPR)

The processing of your personal data is carried out by electronic and IT means, using logics strictly related to the purposes indicated and, in any event, in a manner that ensures the security, integrity and confidentiality of the data.

The Controller adopts appropriate technical and organisational measures pursuant to Article 32 of the GDPR, including: encryption of data in transit and at rest; access control based on the principle of least privilege; pseudonymisation, where appropriate; periodic backups; and procedures for managing and notifying personal data breaches. Processing is carried out by persons authorised and instructed by the Controller, or by processors appointed pursuant to Article 28 of the GDPR.

Any unlocking of the App by means of local biometric authentication (Face ID or fingerprint) is processed exclusively on your device by the Apple or Google operating systems: the related data are never transmitted to, or processed by, the Controller; the Controller receives only the positive or negative outcome of the authentication.

12. Rights of the data subject (Articles 15-22 GDPR)

In relation to the processing described in this Notice, as a data subject you may, on the terms provided for by the GDPR, exercise the rights set out in Articles 15 to 22 of the GDPR and, in particular, the following rights:

  • right of access (Article 15): the right to obtain confirmation as to whether or not processing of personal data concerning you is being carried out and, if so, to obtain access to your personal data — including a copy of it — and disclosure of, among other things, the following information: a) the purposes of the processing; b) the categories of personal data processed; c) the recipients to whom the data have been or will be disclosed; d) the retention period for the data, or the criteria used to determine it; e) the existence of the rights to rectification, erasure, restriction and objection; f) the right to lodge a complaint with a supervisory authority; g) the source of the data, where they were not collected from the data subject; h) the existence of automated decision-making, including profiling, and meaningful information about the logic used;
  • right to rectification (Article 16): the right to obtain the rectification of inaccurate personal data concerning you and/or the completion of incomplete personal data;
  • right to erasure (right to be forgotten, Article 17): the right to obtain the erasure of personal data concerning you, where: a) the data are no longer necessary for the purposes for which they were collected or otherwise processed; b) you have withdrawn your consent and there is no other legal ground for the processing; c) you have successfully objected to the processing; d) the data have been unlawfully processed; e) the data must be erased for compliance with a legal obligation; f) the data have been collected in relation to the offer of information society services referred to in Article 8(1) of the GDPR. The right to erasure does not apply to the extent that the processing is necessary for compliance with a legal obligation, for the performance of a task carried out in the public interest, or for the establishment, exercise or defence of legal claims;
  • right to restriction of processing (Article 18): the right to obtain the restriction of processing, where: a) you contest the accuracy of the personal data, for the period necessary to verify it; b) the processing is unlawful and you oppose the erasure of the data, requesting instead that its use be restricted; c) the Controller no longer needs the data, but you require them for the establishment, exercise or defence of legal claims; d) you have objected to the processing pursuant to Article 21(1) of the GDPR, pending verification as to whether the Controller's legitimate grounds override your own;
  • right to data portability (Article 20): the right to receive, in a structured, commonly used and machine-readable format, the personal data concerning you that you have provided to the Controller, processed by automated means on the basis of consent or of the contract, and the right to transmit that data to another controller without hindrance, as well as, where technically feasible, to have it transmitted directly from one controller to another. The export of your Loop data is also available free of charge, upon request submitted by means of an in-app ticket, in PDF and CSV formats, without prejudice to the provisions of Article 20 of the GDPR;
  • right to object (Article 21): the right to object at any time, on grounds relating to your particular situation, to the processing of personal data based on the Controller's legitimate interest. In the case of processing for direct marketing purposes, you may object at any time and without needing to provide any reason: in that case, the data will no longer be processed for that purpose;
  • right to withdraw consent (Article 7(3)): the right to withdraw, at any time, any consent given, as easily as it was given, directly from the App or by contacting the Controller, without prejudice to the lawfulness of the processing based on consent given before its withdrawal;
  • right not to be subject to a decision based solely on automated processing (Article 22): the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, except in the cases provided for in Article 22(2) of the GDPR; in the cases where this is permitted, you nonetheless have the right to obtain human intervention, to express your point of view, and to contest the decision, as set out in Article 4 of this Notice.

The above rights may be exercised against the Controller by contacting the details indicated in Article 1 above. The exercise of your rights as a data subject is free of charge pursuant to Article 12 of the GDPR; however, in the case of manifestly unfounded or excessive requests, including because of their repetitive character, the Controller may charge you a reasonable fee, taking into account the administrative costs of handling your request, or may refuse to act on the request.

Should you consider that the processing of your personal data infringes the GDPR, you also have the right to lodge a complaint with the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the supervisory authority of the Member State of your habitual residence, place of work, or of the place where the alleged infringement occurred, without prejudice to any other administrative or judicial remedy.

13. Data of deceased persons (Article 2-terdecies of Legislative Decree No. 196/2003)

Pursuant to Article 2-terdecies of Legislative Decree No. 196 of 30 June 2003 (the "Italian Data Protection Code"), the rights referred to in Articles 15 to 22 of the GDPR relating to the personal data of deceased persons may be exercised by a person having an interest of their own, or acting to protect the data subject as their agent, or for family reasons deserving of protection. The relevant requests may be submitted at the contact details indicated in Article 1, together with documentation suitable to prove the identity and standing of the person making the request.

The exercise of such rights is not permitted in the cases provided for by law or where — since these are information society services — the data subject has expressly prohibited it by a written statement submitted to, or communicated to, the Controller. You may therefore send the Controller, at any time, at the contact details indicated in Article 1, a written statement prohibiting, in whole or in part, the exercise of such rights after your death: the intention to prohibit must be unambiguous and must be specific, freely given and informed; the prohibition may relate to the exercise of only some of the rights and may be withdrawn or amended at any time. The prohibition may not, in any case, have effects detrimental to the exercise, by third parties, of the property rights arising from the data subject's death, nor to the right to defend one's own interests in legal proceedings.

14. Amendments to this Notice

The Controller reserves the right to amend or update this Notice, including as a result of the evolution of the services offered and of applicable law. Material amendments will be notified through the App before they take effect and, where required by the nature of the amendment, your consent will be collected again. Each version of the Notice is identified by a version number and date; the current version is always available within the App and on the Controller's website.

Possible transfer of controllership. The Controller may transfer to Sportechlabs Software S.r.l. the controllership of the processing described in this Notice, without this entailing any change to the purposes, legal bases and retention periods indicated, or to the rights granted to data subjects. You will receive advance notice of the transfer through the App or by email.

The App is not currently integrated with wearable devices or third-party health platforms: any future integrations with wearable devices will be the subject of a supplementary notice and specific consent before their activation.

Termini e condizioniInformativa privacy