Privacy Policy
Version 1.5 — Effective October 1, 2026 — GDPR (EU 2016/679)
FitDesk (Société par Actions Simplifiée (SAS), RCS Montpellier 104 196 233, 118 Rue des Roselières, 34970 Lattes, France) is committed to protecting your personal data in accordance with the GDPR and the French Data Protection Act. This policy covers the website, the Android mobile application and all related services.
Article 1 — Data Controller
FitDesk, Société par Actions Simplifiée (SAS), RCS Montpellier 104 196 233, 118 Rue des Roselières, 34970 Lattes, France.
Contact: contact@fitdesk.io
Article 2 — Scope and roles
This policy applies to the data processed by FitDesk acting as data controller, that is, the data of Platform users, whatever their profile: coach, athlete, organisation manager or administrator.
Where a coach enters information about their own clients or prospects into the Platform, the coach alone determines the purposes and means of that processing: the coach is the data controller for it, and FitDesk acts as a technical service provider on their behalf.
Article 3 — Categories of data collected
- Identification data: last name, first name, email address, telephone number, preferred language and, where applicable, profile picture.
- Account and authentication data: credentials, password hash (never stored in clear text), passwordless authentication keys ("passkeys"), session tokens, sign-in history.
- Professional data (coaches): trading name, specialty, country of practice, organisation details.
- Sports activity data: programmes, sessions, exercises, loads, performances, personal records and progress indicators.
- Health and well-being data (athletes): declared medical conditions and allergies, well-being reports (sleep, energy, stress, mood, motivation, muscle soreness, pain areas, digestive comfort, hydration, food cravings and, where applicable, menstrual cycle tracking), session reports and meal reports.
- Uploaded documents and files: the documents you upload to your library or send to another user (PDF, images, office documents, spreadsheets, text files), together with the information describing them: file name, type, size, digital fingerprint, upload date, uploader and sharing scope. These documents may contain health data, and the file name itself is treated as health data — which is why it appears neither in emails nor in the storage service's logs.
- Nutrition data: meal plans, meals, intake and related tracking.
- Communication data: messages exchanged through the Platform's messaging service (one-to-one conversations, group conversations and support exchanges).
- Exchanges with the conversational assistant: content of the conversations held with the "Milo" assistant (see Article 7).
- Billing data (coaches): billing details and subscription history. Payment instrument data is processed by our payment provider and is never stored by FitDesk.
- Acquisition channel: at registration, the channel through which you discovered us (a link from our showcase site, an email campaign, a search engine or a similar referral) along with, where applicable, a campaign identifier or the name of the site that referred your visit. This information is attached to your account and follows its fate, not that of browsing logs.
- Technical and log data: IP address, browser and device type, pages viewed, service call logs and email delivery logs.
Article 4 — Source of the data
Data is in principle collected directly from you. Some data may be entered by an authorised third party: a coach inviting an athlete, or a manager attaching a member to their organisation.
As part of its outreach to sports professionals, FitDesk may also process business contact details obtained indirectly from publicly available sources. Data subjects are informed at first contact, may object to this processing at any time, and are provided with an immediate unsubscribe link in every message.
Article 5 — Purposes and legal bases
- Provision and operation of the service: performance of the contract (Art. 6(1)(b) GDPR).
- Sports tracking and coaching support: performance of the contract (Art. 6(1)(b)).
- Processing of health and well-being data: explicit consent (Art. 9(2)(a)). This information is optional and consent may be withdrawn at any time.
- Exchange of documents between users (upload, sharing, sending to a coach, attachment): performance of the contract (Art. 6(1)(b)); where the document contains health data, explicit consent (Art. 9(2)(a)) — uploading is voluntary and the Platform can be used without it.
- Security of uploaded documents (antivirus scanning, format checking, logging of views): legitimate interest (Art. 6(1)(f)).
- Subscription management and billing: performance of the contract and legal obligations (Art. 6(1)(b)/(c)).
- Security, fraud prevention and logging: legitimate interest (Art. 6(1)(f)).
- Improvement and monitoring of the service: legitimate interest (Art. 6(1)(f)).
- Service-related communications: legitimate interest (Art. 6(1)(f)).
- Outreach to professionals: legitimate interest (Art. 6(1)(f)), with a permanent right to object.
- Legal and accounting obligations: legal obligation (Art. 6(1)(c)).
Article 6 — Recipients and processors
Your data is accessible to your coach (for your sports tracking), to authorised members of your organisation (see Article 8), to authorised FitDesk staff and to the competent authorities where required by law.
FitDesk uses the following processors:
- OVH SAS: hosting of the Platform and of the data — France (Roubaix).
- Stripe: payment processing and billing — United States.
- OpenAI: supply of the language models used by the conversational assistant — United States (see Article 7).
- OVH SAS: delivery of the emails sent by the Platform, transactional and informational messages — France (Roubaix).
- Google Ireland Limited: delivery of the notifications displayed by the Android mobile application (Firebase Cloud Messaging) — Ireland. This service receives your device's notification identifier together with the title and text of the notification, which contain no health data.
As regards the documents you upload, the recipient depends on the scope you choose: yourself only by default, people you name, all of your active relationships, or the members of your organisation. FitDesk's authorised staff access technically extends to these documents; it is logged on the same footing as any other reader's. No document is passed to a processor: antivirus scanning runs within our own infrastructure, on a component with no outbound access.
FitDesk does not sell or rent your personal data. No data is transferred for advertising purposes.
Article 7 — The "Milo" conversational assistant
The Platform provides a conversational assistant based on language models supplied by OpenAI, a company established in the United States. It is used to suggest meals, compose exercises and answer support requests.
FitDesk does not automatically send the assistant any data from your record. Neither your health record, nor your allergies, nor your well-being reports, nor your performances are disclosed to it. Only the content you type into the conversation yourself, the history of that conversation and, for support requests, extracts from our knowledge base are transmitted.
Every message is subject to an automated compliance check before processing. Conversations are stored for twenty-four hours after the last exchange and are then automatically deleted. Technical logs never record the content of messages.
Content produced by the assistant consists of suggestions intended to be reviewed and validated by a professional. It does not constitute medical advice, a prescription, or personalised dietary advice.
Article 8 — Sharing within an organisation
Where you are attached to an organisation (club, gym, professional structure), some of your data is accessible to other members of that organisation:
- the manager has access to the directory of its members and to attachment information. The directory exposes no health or sports-tracking data;
- a coach who is a member of the organisation may access the tracking record of an athlete of the same organisation, including their health information, in order to ensure continuity of support, even where there is no direct contractual relationship between them;
- members may be brought together in group conversations, in which their identity is visible to the other participants;
- a document may be circulated to all members, by the manager or by a coach who is a member. The manager cannot view members' personal documents: they administer the organisation's library, not individual libraries.
An athlete can never send a document to another athlete, nor a coach to another coach.
The end of the attachment terminates these accesses for the future.
Article 9 — Transfers outside the European Union
Hosting of the Platform and storage of the data take place in France. Three processing operations involve a transfer outside the European Union: payment processing by Stripe and the use of OpenAI language models, both in the United States, together with the delivery of mobile application notifications by Google, whose infrastructure may involve such a transfer.
These transfers are governed by the standard contractual clauses adopted by the European Commission, in accordance with Article 46 GDPR, supplemented where appropriate by suitable additional measures. No other transfer outside the EU is carried out.
Article 10 — Retention periods
- Account and related data: for as long as the account is in use.
- After account closure: 3 years, then deletion or anonymisation.
- Billing data: 10 years (accounting obligation).
- Browsing logs: 30 days.
- Technical service call logs and email delivery logs: 12 months.
- Conversations with the assistant: 24 hours after the last exchange.
- Device notification identifier: until you sign out on that device, uninstall the application, or the identifier is invalidated by the notification service.
- Uploaded documents and files: for as long as the account is in use. A deleted document is moved to the bin, where it remains restorable, then destroyed after a period of 30 days; moving it to the bin immediately closes any access granted. A document sent to a coach belongs to them from the moment it is handed over and is not deleted along with your account — you may, however, withdraw it while your account exists.
- Document access log: 12 months.
- Document notifications: 90 days.
- Evidence of acceptance of contractual documents: duration of the contractual relationship and 5 years thereafter.
Article 11 — Security
FitDesk implements: encryption of data in transit (HTTPS/TLS), storage of passwords as cryptographic hashes, segregation of components and restricted access to production environments, logging of access and sensitive operations, anonymisation of IP addresses in browsing logs (geographic precision limited to the country).
Uploaded documents are subject to measures of their own: systematic, blocking antivirus scanning before storage; format checking against the file's actual content rather than its extension; storage by a dedicated service, on a network with no outbound access whatsoever, which knows neither the file's original name nor the identity of its owner; no durable download link is ever issued, access rights being re-evaluated on every view; named logging of views, made available to the owner.
Article 12 — Mobile application
The FitDesk mobile application is distributed on Google Play. It requires Internet access, which is necessary for the service to work, and, if you accept it, permission to display notifications.
It embeds no third-party analytics tool, no advertising tracker and no advertising identifier. It does not access your location, your camera, your contacts or your microphone.
Notifications. The application may alert you to an event in your programme — for example, a new training programme assigned by your coach. Those notifications are delivered by Google's Firebase Cloud Messaging service (Article 6), whose technical module assigns your device a notification identifier that is sent to our servers.
They are optional: declining the permission, or withdrawing it in your phone's settings, has no effect on the rest of the service. The text of a notification never contains health data — it names the nature of the event and, where relevant, the person concerned, never the content, because a notification is displayed on a lock screen. Subject to that, the data processed through the application is the same as that processed through the website.
Article 13 — Cookies and trackers
FitDesk uses no third-party cookies, no analytics tools and no advertising pixels.
Only mechanisms strictly necessary for the operation of the service are used: keeping you signed in during the session and remembering your language preference. Such mechanisms are exempt from consent within the meaning of the French data protection authority's recommendation of 17 September 2020; no cookie banner is required.
Article 14 — Automated processing and profiling
In accordance with Article 13(2)(f) GDPR, the Platform carries out the following automated processing:
- the conversational assistant described in Article 7, which produces suggestions subject to validation by a professional;
- the automatic sending of follow-up messages triggered by your activity (extended absence of connection, unvalidated session, sign-up anniversary);
- an automated compliance check of the messages sent to the assistant.
No decision producing legal effects concerning you, or similarly significantly affecting you, is taken solely on the basis of automated processing within the meaning of Article 22 GDPR.
Article 15 — Your rights
- Access — obtain a copy of your data.
- Rectification — correct inaccurate data.
- Erasure — request deletion, subject to legal retention obligations.
- Restriction — restrict certain processing.
- Objection — object to processing based on legitimate interest, in particular outreach.
- Portability — receive your data in a structured format.
- Withdrawal of consent — at any time, in particular for health data.
As regards uploaded documents, the right of access is exercised directly from the Platform, which shows you your documents, those sent to you and — for each of the ones you have shared — the named, dated list of those who viewed them. The right to erasure is exercised there too, except for a document sent to a coach, which belongs to them and which you may only withdraw.
To exercise these rights: contact@fitdesk.io. Response within one month. You may also lodge a complaint with the French data protection authority (CNIL) at www.cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.
Article 16 — Updates
This policy may be updated to reflect changes in the service or in applicable law; the effective date appears in the header. In the event of a substantial change, users are informed by any appropriate means.
Article 17 — Governing law
This Privacy Policy is governed by French law. Any dispute relating to its interpretation or performance falls within the jurisdiction of the French courts.