FeaturesPricingTestimonials
LoginFree trial
FeaturesPricingTestimonialsLoginFree trial

Privacy Policy

Version 1.2 — Effective August 1, 2026 — GDPR (EU 2016/679)

FitDesk (Société par Actions Simplifiée (SAS), RCS Montpellier 104 196 233, 118 Rue des Roselières, 34970 Lattes, France) is committed to protecting your personal data in accordance with the GDPR and the French Data Protection Act. This policy covers the website, the Android mobile application and all related services.

Article 1 — Data Controller

FitDesk, Société par Actions Simplifiée (SAS), RCS Montpellier 104 196 233, 118 Rue des Roselières, 34970 Lattes, France.

Contact: contact@fitdesk.io

Article 2 — Scope and roles

This policy applies to the data processed by FitDesk acting as data controller, that is, the data of Platform users, whatever their profile: coach, athlete, organisation manager or administrator.

Where a coach enters information about their own clients or prospects into the Platform, the coach alone determines the purposes and means of that processing: the coach is the data controller for it, and FitDesk acts as a technical service provider on their behalf.

Article 3 — Categories of data collected

  • Identification data: last name, first name, email address, telephone number, preferred language.
  • Account and authentication data: credentials, password hash (never stored in clear text), passwordless authentication keys ("passkeys"), sign-in history.
  • Professional data (coaches): trading name, specialty, country of practice, organisation details.
  • Sports activity data: programmes, sessions, exercises, loads, performances, personal records and progress indicators.
  • Health and well-being data (athletes): declared medical conditions and allergies, well-being reports (sleep, energy, stress, mood, motivation, muscle soreness, pain areas, digestive comfort, hydration, food cravings and, where applicable, menstrual cycle tracking), session reports and meal reports.
  • Nutrition data: meal plans, meals, intake and related tracking.
  • Communication data: messages exchanged through the Platform's messaging service (one-to-one conversations, group conversations and support exchanges).
  • Exchanges with the conversational assistant: content of the conversations held with the "Milo" assistant (see Article 7).
  • Billing data (coaches): billing details and subscription history. Payment instrument data is processed by our payment provider and is never stored by FitDesk.
  • Technical and log data: IP address, browser and device type, pages viewed, service call logs and email delivery logs.

Article 4 — Source of the data

Data is in principle collected directly from you. Some data may be entered by an authorised third party: a coach inviting an athlete, or a manager attaching a member to their organisation.

As part of its outreach to sports professionals, FitDesk may also process business contact details obtained indirectly from publicly available sources. Data subjects are informed at first contact, may object to this processing at any time, and are provided with an immediate unsubscribe link in every message.

Article 5 — Purposes and legal bases

  • Provision and operation of the service: performance of the contract (Art. 6(1)(b) GDPR).
  • Sports tracking and coaching support: performance of the contract (Art. 6(1)(b)).
  • Processing of health and well-being data: explicit consent (Art. 9(2)(a)). This information is optional and consent may be withdrawn at any time.
  • Subscription management and billing: performance of the contract and legal obligations (Art. 6(1)(b)/(c)).
  • Security, fraud prevention and logging: legitimate interest (Art. 6(1)(f)).
  • Improvement and monitoring of the service: legitimate interest (Art. 6(1)(f)).
  • Service-related communications: legitimate interest (Art. 6(1)(f)).
  • Outreach to professionals: legitimate interest (Art. 6(1)(f)), with a permanent right to object.
  • Legal and accounting obligations: legal obligation (Art. 6(1)(c)).

Article 6 — Recipients and processors

Your data is accessible to your coach (for your sports tracking), to authorised members of your organisation (see Article 8), to authorised FitDesk staff and to the competent authorities where required by law.

FitDesk uses the following processors:

  • OVH SAS: hosting of the Platform and of the data — France (Roubaix).
  • Stripe: payment processing and billing — United States.
  • OpenAI: supply of the language models used by the conversational assistant — United States (see Article 7).
  • OVH SAS: delivery of the emails sent by the Platform, transactional and informational messages — France (Roubaix).

FitDesk does not sell or rent your personal data. No data is transferred for advertising purposes.

Article 7 — The "Milo" conversational assistant

The Platform provides a conversational assistant based on language models supplied by OpenAI, a company established in the United States. It is used to suggest meals, compose exercises and answer support requests.

FitDesk does not automatically send the assistant any data from your record. Neither your health record, nor your allergies, nor your well-being reports, nor your performances are disclosed to it. Only the content you type into the conversation yourself, the history of that conversation and, for support requests, extracts from our knowledge base are transmitted.

Every message is subject to an automated compliance check before processing. Conversations are stored for twenty-four hours after the last exchange and are then automatically deleted. Technical logs never record the content of messages.

Content produced by the assistant consists of suggestions intended to be reviewed and validated by a professional. It does not constitute medical advice, a prescription, or personalised dietary advice.

Article 8 — Sharing within an organisation

Where you are attached to an organisation (club, gym, professional structure), some of your data is accessible to other members of that organisation:

  • the manager has access to the directory of its members and to attachment information. The directory exposes no health or sports-tracking data;
  • a coach who is a member of the organisation may access the tracking record of an athlete of the same organisation, including their health information, in order to ensure continuity of support, even where there is no direct contractual relationship between them;
  • members may be brought together in group conversations, in which their identity is visible to the other participants.

The end of the attachment terminates these accesses for the future.

Article 9 — Transfers outside the European Union

Hosting of the Platform and storage of the data take place in France. Two processing operations involve a transfer to the United States: payment processing by Stripe, and the use of OpenAI language models for the conversational assistant.

These transfers are governed by the standard contractual clauses adopted by the European Commission, in accordance with Article 46 GDPR, supplemented where appropriate by suitable additional measures. No other transfer outside the EU is carried out.

Article 10 — Retention periods

  • Account and related data: for as long as the account is in use.
  • After account closure: 3 years, then deletion or anonymisation.
  • Billing data: 10 years (accounting obligation).
  • Browsing logs: 30 days.
  • Technical service call logs and email delivery logs: 12 months.
  • Conversations with the assistant: 24 hours after the last exchange.
  • Evidence of acceptance of contractual documents: duration of the contractual relationship and 5 years thereafter.

Article 11 — Security

FitDesk implements: encryption of data in transit (HTTPS/TLS), storage of passwords as cryptographic hashes, segregation of components and restricted access to production environments, logging of access and sensitive operations, anonymisation of IP addresses in browsing logs (geographic precision limited to the country), regular backups.

Article 12 — Mobile application

The FitDesk mobile application is distributed on Google Play. It requires only Internet access, which is necessary for the service to work.

It embeds no third-party analytics tool, no advertising tracker and no advertising identifier. It does not access your location, your camera, your contacts or your microphone. The data processed through the application is the same as that processed through the website.

Article 13 — Cookies and trackers

FitDesk uses no third-party cookies, no analytics tools and no advertising pixels.

Only mechanisms strictly necessary for the operation of the service are used: keeping you signed in during the session and remembering your language preference. Such mechanisms are exempt from consent within the meaning of the French data protection authority's recommendation of 17 September 2020; no cookie banner is required.

Article 14 — Automated processing and profiling

In accordance with Article 13(2)(f) GDPR, the Platform carries out the following automated processing:

  • the conversational assistant described in Article 7, which produces suggestions subject to validation by a professional;
  • the automatic sending of follow-up messages triggered by your activity (extended absence of connection, unvalidated session, sign-up anniversary);
  • an automated compliance check of the messages sent to the assistant.

No decision producing legal effects concerning you, or similarly significantly affecting you, is taken solely on the basis of automated processing within the meaning of Article 22 GDPR.

Article 15 — Your rights

  • Access — obtain a copy of your data.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion, subject to legal retention obligations.
  • Restriction — restrict certain processing.
  • Objection — object to processing based on legitimate interest, in particular outreach.
  • Portability — receive your data in a structured format.
  • Withdrawal of consent — at any time, in particular for health data.

To exercise these rights: contact@fitdesk.io. Response within one month. You may also lodge a complaint with the French data protection authority (CNIL) at www.cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.

Article 16 — Updates

This policy may be updated to reflect changes in the service or in applicable law; the effective date appears in the header. In the event of a substantial change, users are informed by any appropriate means.

Article 17 — Governing law

This Privacy Policy is governed by French law. Any dispute relating to its interpretation or performance falls within the jurisdiction of the French courts.

Back to home