General Terms and Conditions (GTC)
Privacy Policy for the App "Satisfit Fitness at Home"
1. Basic Information & Contact Details
- Name and Address of the Controller: Hubertina Thewissen, ALNISAID NV, Burgemeester Kenisstraat 1, 2910 Essen, Belgium
- Contact Details: Email: info@alnisaid.com, Tel.: +32 3 670 0120
- Data Protection Officer: A data protection officer has not been appointed as it is not legally required.
2. What data is processed?
We process the following data to ensure and improve the functionality of the "Satisfit Fitness at Home" app (com.satisfit.chatapp), hereinafter referred to as the "App":
- Master Data (Account Information):
- System-generated: Upon first use, a random user ID and a temporary user and chat name are created to allow the use of the app without immediate disclosure of personal data.
- Voluntary Information: You can later voluntarily provide or change the following data in your profile:
- Email address
- A user and chat name of your choice
- Your real name (optional)
- A profile picture (optional)
- A securely encrypted password
- Usage Data / Technical Data:
- IP address
- Device information (e.g., device type, operating system and version)
- App version
- Times and duration of app usage
- Interactions within the app (e.g., features used)
- CometChat authentication token
- Google Advertising ID (AD_ID) on Android devices. This can be used for measuring the success of advertising campaigns and for technical purposes in delivering push notifications.
- Content, Fitness & Health Data (Particularly sensitive):
- Your answers from the initial questionnaire (gender, age, height, weight, fitness goals, dietary habits, etc.).
- Chat messages and shared media that you send and receive via the chat function.
- Activities and body data logged by you.
- Uploaded photos or videos (e.g., as a profile picture or in chat).
- Device Access (only with your explicit permission):
- Camera: To take photos or videos for your profile picture or the chat.
- Photo Library / Gallery: To select existing images or videos for your profile or chat.
- Microphone: For future audio and video call functions in the chat.
- Push Notifications: To send you notifications about new messages or other relevant events.
- Location Data:
- The app does not currently request GPS location data. Should this feature be introduced in the future (e.g., for tracking running routes), we will ask for your separate and explicit consent.
3. Purpose and Legal Basis of Processing
We process your data for the following purposes and on the basis of the following legal grounds:
- For the provision of app services (Performance of a contract, Art. 6(1)(b) GDPR): The processing of your master, content, fitness, and health data is necessary to provide you with the core functions of the app, such as creating training plans, keeping a nutrition diary, and using the chat function. The processing of in-app purchases is also part of the performance of this contract.
- Based on your consent (Art. 6(1)(a) & Art. 9(2)(a) GDPR):
- We obtain your explicit consent for the processing of particularly sensitive health data (e.g., from the questionnaire).
- We ask for your express permission for access to the camera, photo library, microphone, and for push notifications.
- We also obtain your consent for the analysis of user behavior with Google Firebase Analytics (see section 4).
- You can withdraw any of these consents at any time with future effect.
- To ensure stability and security (Legitimate interest, Art. 6(1)(f) GDPR): We analyze technical usage data and crash reports to fix errors, ensure app stability, and prevent misuse. Our legitimate interest is to offer a technically flawless and secure service.
- For marketing and advertising (Consent, Art. 6(1)(a) GDPR): To measure the effectiveness of our advertising measures on third-party platforms (like Google or social media) and to promote our app, we process pseudonymized data such as your advertising ID with your consent.
4. Integrated Third-Party Providers & Data Recipients
We work with specialized service providers to operate the app securely and reliably:
- Hosting Provider: Our servers and databases are hosted by Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). The server location is Germany. Your data is therefore stored exclusively within the European Union.
- Chat Service Provider: The chat functionality is provided by CometChat (USA). We transmit your user ID, chat name, and profile picture to CometChat for this purpose. The content of your chats is also routed through their servers.
- Analytics & App Performance (Google Firebase): We use various services from Google Firebase (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, USA) to improve and monitor our app:
- Firebase Analytics: This service helps us understand how users interact with the app (e.g., which features are most popular). For this, pseudonymized usage data (e.g., device IDs) is collected and transmitted to Google. This only happens with your consent.
- Firebase Crashlytics: To improve the stability of our app, we use Crashlytics to receive real-time crash reports. Information about the device status at the time of the crash is collected.
- Firebase Cloud Messaging (FCM): We use this service to send push notifications to your device.
- Subscription Management (RevenueCat): To manage in-app purchases and subscriptions, we use the service RevenueCat (RevenueCat, Inc., USA). RevenueCat provides us with anonymized purchase information (e.g., whether a subscription is active), but does not process any sensitive payment data itself. The actual payment processing is handled exclusively by the respective app stores (Apple App Store or Google Play Store). We do not get access to your credit card or bank details.
- Marketing Service Providers: To attract new users to our app, we run advertisements on external platforms. To measure the success of these campaigns ("conversion tracking"), data may be transmitted to these platforms:
- Google Ads & Social Media Platforms (e.g., Meta/Facebook/Instagram): If you become aware of our app through an advertisement and install it, your pseudonymized advertising ID (Google Advertising ID or Apple's ID for Advertisers) may be reported back to the respective platform. This is solely for the purpose of measuring and attributing the success of our advertising campaign. We do not create personal user profiles for advertising purposes within our app.
Data is only transferred to countries outside the EU (like the USA) if an adequate level of data protection is ensured, e.g., through the use of EU Standard Contractual Clauses.
5. Storage Duration
Your account and fitness data will be stored as long as your account with us exists. You can request the deletion of your personal data at any time. To do so, you can either use our dedicated deletion page at https://satisfit.com/delete-user.php or send an informal email with your deletion request to the email address mentioned in section 1 (info@alnisaid.com). After receiving and reviewing your request, your data will be permanently removed from our active systems within 90 days. Anonymized usage statistics may be retained for analytical purposes for a longer period.
6. User Rights
You have the right to:
- Access your data processed by us.
- Rectification of incorrect data.
- Erasure of your data.
- Restriction of processing.
- Data portability (receive your data in a machine-readable format).
- Object to the processing.
- Withdraw your consent.
- Lodge a complaint with a data protection supervisory authority.
To exercise your rights, please contact us via the email address mentioned in section 1.
7. Miscellaneous
- Data Security: We protect your data through modern encryption technologies (SSL/TLS) during transmission and storage.
- Push Notifications: You can deactivate the receipt of push notifications at any time in your smartphone's settings for the app.
- App Store Information: The data protection information we provide in the Apple App Store and Google Play Store is part of this declaration.
- Changes to this Privacy Policy: We reserve the right to adapt this privacy policy so that it always complies with the current legal requirements or to implement changes to our services in the privacy policy. In the event of significant changes, we will inform you within the app or by email. The new privacy policy will then apply to your next visit.