fitliftly ← Back to home

fitliftly — Privacy Policy

Effective from: 19 July 2026

1. Data Controller

The controller of personal data is:

Stelix holding s.r.o.
Company ID (IČO): 01443909, VAT ID (DIČ): CZ01443909
Registered seat: Ke stadionu 1953, 272 01 Kladno, Czech Republic
E-mail: info@stelixholding.cz

(hereinafter the "Controller" or "we")

In accordance with Art. 37 GDPR, the Controller has not appointed a Data Protection Officer (DPO), as it is not a public authority and its core activity does not consist of large-scale systematic monitoring of data subjects nor large-scale processing of special categories of data. The above contact e-mail will, however, fully address any data protection enquiries.

2. Who This Policy Applies To

This Policy applies to:

  • registered Users of the fitliftly application (all roles: user, trainer, venue, partner);
  • Visitors of the website fitliftly.com without registration;
  • persons who contact the Controller via e-mail or through the in-app feedback widget.

3. Categories of Personal Data Processed

3.1 Identification and contact data

  • first name and surname
  • username
  • e-mail address
  • phone number (optional)
  • address (street, city, postal code — optional, used i.a. for invoicing)
  • date of birth (optional)
  • gender (optional)

3.2 Profile data

  • profile picture (avatar)
  • biography and other optional profile details
  • privacy settings (public, friends, private)
  • language and timezone

3.3 Social account data

If you sign in via Google, Apple or Facebook, we obtain from the identity provider:

  • the user identifier with that provider
  • the e-mail address
  • the name (and possibly avatar)

3.4 Service usage data (operational)

  • records of workouts created, completed and cancelled
  • venue entry records (QR check-in/check-out)
  • statistics (volume, streaks, XP, level)
  • badges, challenges, leaderboards
  • friend list, follow relationships, followed venues
  • chat messages, polymorphic comments, reactions
  • uploaded photos of workouts and venues
  • sport pass records (card type, number, validity)

3.5 Payment and invoicing data

  • records of credit wallet transactions
  • invoices (number, IČO/DIČ, billing address) — for trainer/venue/partner roles
  • payment card details are not stored in the App — card payments are processed via the Stripe gateway, which is an independent data controller; the App records only the amount, variable symbol and top-up status

3.6 Technical data

  • IP address
  • device type, operating system, browser version
  • last-seen timestamp
  • cookies and similar technologies (see Art. 8)
  • push notification token

3.7 Health data — special category of personal data (Art. 9 GDPR)

If you grant explicit consent to the Health Sync feature, the App synchronises data from Apple HealthKit (iOS) or Google Health Connect (Android), in particular:

  • activity (steps, energy expenditure, distance)
  • heart rate
  • sleep data
  • body metrics (weight, height — if shared)

This data falls under special categories of personal data per Art. 9 GDPR and we process it solely on the basis of your explicit consent. You may withdraw consent at any time in the App settings or at the device system level; after withdrawal we no longer synchronise the data and existing records can be deleted on request.

3.8 Feedback data

When you use the feedback widget, we store the message text, a screenshot of the current screen, the page URL and the browser type. This data is transferred via webhook to our internal issue tracking system (GitLab).

3.9 Publicly available data about venues

Our directory also lists venues that do not yet have a manager on fitliftly. Their details (name, address, location, and where available contact and opening hours) come from public sources, in particular OpenStreetMap (© OpenStreetMap contributors, ODbL licence). We process them on the basis of our legitimate interest (Art. 6(1)(f) GDPR) — maintaining a directory of venues. If you are a venue operator, you may request to take over management, to correct, or to remove the data directly at the given venue in the app or at info@stelixholding.cz, and you may object to the processing at any time.

4. Processing Purposes, Legal Bases and Retention

Purpose Legal basis (GDPR Art. 6/9) Data categories Retention
Creation and management of the User Account, authentication performance of contract (Art. 6(1)(b)); after account deletion legitimate interest (Art. 6(1)(f)) — defence of legal claims 3.1, 3.2, 3.3 duration of the account + 3 years after deletion (limitation period for claims)
Provision of the Service (social network, booking, check-in, statistics) performance of contract 3.4 duration of the account
Chat messages (conversations and message content) performance of contract (Art. 6(1)(b)) 3.4 duration of the account; deleted messages and messages of a deleted account are permanently removed within 30 days
Payment processing and tax document issuance legal obligation (Art. 6(1)(c)) — Accounting Act, VAT Act 3.5 10 years from the end of the accounting period
Service security, fraud prevention, debugging legitimate interest (Art. 6(1)(f)) 3.4, 3.6, 3.8 logs 6 months, security incidents 3 years
Marketing communication (newsletter, news) consent (Art. 6(1)(a)) 3.1 until consent withdrawn or 3 years from last interaction
Health Sync — synchronisation of health data explicit consent (Art. 9(2)(a)) 3.7 until consent withdrawn or account deleted
Feedback / error reporting legitimate interest 3.8 until resolution + 6 months
Push notifications (bookings, social activity) performance of contract device token while the device is active

5. Recipients of Personal Data (Processors)

We share your data only to the necessary extent with the categories of recipients listed below. We have data processing agreements (DPAs) in place with all of them in accordance with Art. 28 GDPR.

Processor Purpose Location Transfer outside EU
Hetzner Online GmbHHosting (servers, database, backups)Germanyno
Stripe Payments Europe, Ltd.Payment gateway (card payments, payee onboarding)Ireland / EU; partial processing in the USA under Standard Contractual Clauses and the EU-U.S. Data Privacy Frameworklimited (see left column)
Cloudflare, Inc.CDN, DDoS protection, TurnstileUSA / globalyes — DPF / SCC
Google LLCGoogle Sign-In, Health Connect (Android)USAyes — DPF / SCC
Apple Inc.Sign in with Apple, HealthKit (iOS)USAyes — DPF / SCC
Meta Platforms Ireland Ltd.Facebook LoginIreland / USAyes — DPF / SCC
PostHog EU B.V.Product analytics and session replay — pseudonymised, with input masking and sensitive content excludedEU (Frankfurt data centre)no
Functional Software, Inc. (Sentry)Application error trackingEU data residency (Germany); parent company USAlimited — DPF / SCC
DeepL SEMachine translation of exercise descriptions (no User identifiers)Germanyno
GitLab Inc.Internal issue tracking system (feedback widget)USAyes — SCC
OpenStreetMap Foundation / Mapy.cz a.s.Geocoding of venue addresses (not user addresses)EU / UKno personal data transfer (only POI addresses)
Accounting and tax advisorAccountingCzech Republicno

We do not sell your personal data to third parties for marketing purposes.

6. Transfers to Third Countries

Some of the services listed above (Google, Apple, Meta, Cloudflare, GitLab, Sentry) operate as part of global infrastructures. Sentry and PostHog data is stored in EU data centres; for Sentry, the US parent company may have limited access. When transferring personal data outside the European Economic Area we rely on:

  • EU-US Data Privacy Framework (DPF) — for the United States with certified recipients;
  • Standard Contractual Clauses (SCCs) adopted by the European Commission — for other cases;
  • supplementary organisational and technical measures (encryption, pseudonymisation) where relevant.

7. Your Rights as a Data Subject

Under the GDPR you have the following rights:

  • Right of access (Art. 15) — to obtain information about what data we process about you.
  • Right to rectification (Art. 16) — to correct inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten", Art. 17) — to request deletion of data when no longer needed or upon withdrawal of consent. This also covers manual deletion of health data.
  • Right to restriction of processing (Art. 18).
  • Right to data portability (Art. 20) — to receive your data in a machine-readable format (JSON/CSV).
  • Right to object (Art. 21) — to processing based on legitimate interest or for direct marketing purposes.
  • Right to withdraw consent (Art. 7(3)) — at any time, with effect for the future (in particular for marketing and Health Sync).
  • Right not to be subject to automated decision-making (Art. 22) — the App does not perform automated decision-making with legal effects.

How to exercise your rights

Rights can be exercised:

  • in the App under "Privacy & Data" (export, deletion, withdrawal of consents);
  • by e-mail to info@stelixholding.cz.

We handle requests free of charge within 30 days of receipt (the period may be extended by an additional 2 months for complex cases, with notice to the data subject).

8. Cookies and Similar Technologies

8.1 Strictly necessary (no consent required)

  • session cookie (fitliftly_session, XSRF-TOKEN) — authentication and CSRF protection
  • language preference (locale)
  • role preference (active_role_context)
  • App localStorage (remembered UI settings, such as venue chat visibility)

8.2 Application usage analytics

To understand how the App is used we rely on PostHog, operated exclusively in the EU (Frankfurt data centre). It is configured to store no cookies or other identifiers on your device — which is why no cookie-banner consent is required. The processing covers:

  • usage measurement (page views, clicks, performance metrics);
  • session replay — a visual recording of navigation through the App used to improve usability; all form inputs are masked and sensitive blocks (chat messages, health data, credit balances, benefit-card numbers) are excluded from the recording entirely;
  • for logged-in users, matching under a pseudonymous numeric identifier (no name or e-mail).

The legal basis is our legitimate interest in improving the Service (Art. 6(1)(f) GDPR). You may object to this processing at any time using the contacts in Section 7.

8.3 Marketing (with consent)

Currently not used. If deployed in the future, we will request your consent via a cookie banner.

Cookie consent can be updated at any time in the settings.

9. Security of Personal Data

We implement in particular the following technical and organisational measures:

  • transport encryption (TLS 1.2+, HTTPS);
  • password hashing (bcrypt);
  • restricted access to the production database (administrators only);
  • regular backups (daily incremental, weekly full);
  • network segmentation (PostgreSQL and Redis are not exposed to the internet);
  • security headers (HSTS, X-Frame-Options, etc.);
  • protection against automated attacks (Cloudflare Turnstile, honeypot);
  • regular operating system and library updates;
  • access monitoring.

In the event of a security breach with risk to the rights of data subjects, we will notify you in accordance with Art. 33 and 34 GDPR.

10. Children

The App is not intended for children under 15 and independent registration in this age group is prohibited. Where the App is used by a person aged 15–18, we recommend obtaining consent from a legal guardian. If we discover that we have collected data from a child without the necessary consent, we will delete the data immediately.

11. Changes to the Privacy Policy

This Policy may be updated from time to time. We will inform Users of material changes via e-mail and/or via in-App notification at least 30 days before the change takes effect. The current version is always available at fitliftly.com/privacy.

12. Complaint to the Supervisory Authority

If you believe that your personal data is being processed in breach of the GDPR, you have the right to lodge a complaint with the supervisory authority:

Office for Personal Data Protection (ÚOOÚ)
Pplk. Sochora 27
170 00 Prague 7, Czech Republic
uoou.gov.cz

13. Contact

For any questions regarding the protection of personal data, please contact us:

Stelix holding s.r.o.
Ke stadionu 1953, 272 01 Kladno, Czech Republic
Company ID (IČO): 01443909
E-mail: info@stelixholding.cz
fitliftly

The all-in-one platform connecting athletes, trainers and venues.

fitliftly is running as a pilot — open to everyone from autumn 2026.

CSEN

Product

  • Features
  • For business
  • Mobile app
  • Log in

Company

  • Stelix holding s.r.o.
  • Reg. No. 01443909 · VAT CZ01443909
  • Ke stadionu 1953, 272 01 Kladno, Czechia
  • info@fitliftly.com

Legal

  • Privacy policy
  • Terms & conditions
  • Out-of-court dispute resolution (ČOI)

© 2026 Stelix holding s.r.o. All rights reserved.

Made with love in Czechia