Privacy Policy (09/2026)
1. Controller
The controller under the GDPR is: Michèl Fois, FIT VIII, Friedrichstraße 71, 61476 Kronberg im Taunus, Germany, phone 06173 5061347, mail@fitviii.com.
2. Scope
This policy applies to the website fitviii.com and to the FIT VIII app (iOS and Android). It explains the nature, scope and purpose of the processing of personal data and your rights.
3. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing. You may withdraw any consent given at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority; ours is the Hessian Commissioner for Data Protection and Freedom of Information.
4. Processing for performance of the contract (membership & training)
To establish and carry out the training or coaching agreement, we process master data (name, address, contact details, date of birth), contract and booking data, and payment data. The legal basis is Art. 6(1)(b) GDPR (contract). Accounting-relevant data is retained for up to ten years due to statutory retention obligations (Art. 6(1)(c) GDPR, § 147 AO, § 257 HGB).
5. Health data (InBody analysis, health questionnaire)
As part of the Professional Check-Up and ongoing support, we process health data (e.g. body composition from the InBody analysis, information from the health questionnaire). This is a special category of personal data and is processed solely on the basis of your explicit consent under Art. 9(2)(a) GDPR, which you may withdraw at any time with effect for the future.
6. Service providers engaged (processors)
We use carefully selected service providers, with each of whom a data processing agreement under Art. 28 GDPR is in place:
-
Website hosting – Wix: The website is hosted by Wix.com Ltd. (Israel; server locations including the USA/EU). Usage and connection data (including IP address) is processed to provide and secure the website. Legal basis: Art. 6(1)(f) GDPR.
-
Booking, member management & app – Virtuagym: Through Virtuagym B.V. (Netherlands/EU) we manage memberships, appointments/bookings and training plans; Virtuagym also provides the app we use. Master, contract, booking and training data as well as app usage and device data are processed. Legal basis: Art. 6(1)(b) GDPR.
-
Payment processing – Mollie: SEPA direct debit payments are processed via Mollie B.V. (Netherlands/EU). Name, bank details (IBAN) and transaction data are processed. Legal basis: Art. 6(1)(b) GDPR.
-
Body analysis – InBody: Body analysis is carried out using devices and software from InBody Co., Ltd. Readings are processed on the InBody device/PC and in the InBody cloud and then transferred to Virtuagym. Legal basis: Art. 9(2)(a) GDPR (consent). An EU adequacy decision exists for South Korea.
-
File storage & administration – Microsoft OneDrive: For administrative purposes we store documents in Microsoft OneDrive (Microsoft Ireland Operations Ltd.). Where health data is stored there, this is based on your consent (Art. 9(2)(a) GDPR). Otherwise the legal basis is Art. 6(1)(b) and (f) GDPR.
-
Communication – WhatsApp, email, phone: For support and scheduling we use, among others, WhatsApp (Meta Platforms Ireland Ltd.) as well as email and phone. Legal basis: Art. 6(1)(b) and (f) GDPR or your consent.
7. The app we use (Virtuagym)
For booking and training management we use the app provided by Virtuagym B.V.; we only adjust its visual design (e.g. colours). The provision, operation and publication of the app in the Apple App Store and on Google Play are carried out by Virtuagym as the app provider. When you use the app, Virtuagym processes access, usage and device data; with regard to the member and training data relating to FIT VIII, Virtuagym acts on our behalf (Art. 28 GDPR). You receive push notifications only with your consent, which you can withdraw at any time in your device settings. Virtuagym provides supplementary information on app- and store-related processing in its own privacy notices.
8. Cookies
The website uses technically necessary cookies from our hosting provider Wix that are required for operation and security. We do not use marketing or tracking cookies or analytics services.
9. International data transfers
Where data is processed outside the EU/EEA (including the USA via Wix, WhatsApp, Apple, Google, Microsoft), this is done on the basis of appropriate safeguards, in particular EU standard contractual clauses or — where applicable — the EU-US Data Privacy Framework. Adequacy decisions by the EU Commission exist for Israel and South Korea.
10. Retention
We process personal data only for as long as necessary for the respective purposes. Contract and accounting data is retained until statutory retention periods expire (up to ten years), health data until the end of support or until consent is withdrawn, and contact enquiries until they have been dealt with.
11. Data security & minors
We take appropriate technical and organisational measures to protect your data. Our services are not directed at minors below the legally required age; we do not knowingly collect data from children without the consent of a guardian.
12. Updates
The version published on the website applies. We will provide notice of material changes in an appropriate manner.
