Fitrobit V2 — Enterprise Mobile Application Privacy Policy & Data Processing Disclosure
Last updated: June 19, 2026
- Version:
- 2.0.1
- Effective Date:
- June 19, 2026
- Contact:
- info@fitrobit.com
- Classification:
- Public / Global Member Distribution
- Author:
- Fitrobit Legal, Compliance & Data Protection Office
This Privacy Policy governs the processing of personal data within the Fitrobit V2 Mobile Application ("the Application"), an enterprise-grade multi-tenant software-as-a-service (SaaS) platform built and operated by Fitrobit ("Fitrobit", "we", "us", or "our"). This document outlines our corporate commitment to data protection, transparency, and architectural security for individual gym members ("Members", "Users", or "you").
1. Regulatory Framework & Scope of Application
This policy establishes our operational standards globally and regionally. While Fitrobit operates as an infrastructure provider, our data architecture aligns with modern international frameworks for data processing, including principles of data minimization, purpose limitation, and storage limitation. This policy governs all processing streams initiated when a Member initializes, logs into, or uploads data through the Application interface.
2. Definitional Roles: Data Controller vs. Data Processor
To ensure compliance with global data laws, the legal relationship regarding data management is structured under strict definitions: (a) Data Controller: The specific fitness studio, commercial gym facility, franchise, or corporate fitness center with which you hold an active membership or training contract (the 'Gym Client') acts as the sole Data Controller. The Gym Client establishes the lawful basis for processing, retains legal ownership of your data, and maintains exclusive authority over its modification, retrieval, and deletion. (b) Data Processor: Fitrobit acts strictly as the Data Processor. We provide the cloud infrastructure, database pipelines, and application interfaces requested by the Data Controller to fulfill their service contract with you. Fitrobit does not sell, monetize, or utilize your data for independent corporate objectives.
3. Tenant Architecture and Dynamic Brand Manifestation
The Application uses an advanced multi-tenant delivery model. Upon successful entry of your authentication credentials, the underlying system identifies your tenant allocation profile. It instantly pulls configurations that dynamically rebrand the interface layout, colors, logos, icons, and visual assets to match your Gym Client's enterprise identity. You acknowledge that this dynamic 'white-labeling' is a presentation-layer feature; the underlying software engine, data routing mechanics, and security boundaries remain under the centralized infrastructure management of Fitrobit.
4. Data Inventory & Granular Categories of Processing
We process specific data points on behalf of the Data Controller to operate the Application effectively. These include: (a) Core Identity & Authentication Elements: Full legal name, email address, telephone contact number, unique system-generated UUIDs, and cryptographically hashed passwords. (b) Biometric & Anthropometric Progression Data: Body weight, specialized localized physical dimensions (e.g., chest, waist, hips, arms, thighs), and target mass metrics. (c) Daily Lifestyle & Bio-Metric Targets: Trainer-assigned and user-logged sleep duration (hours), fluid hydration volumes (milliliters/liters), caloric intakes, macronutrient distribution values (proteins, carbohydrates, fats), and physical activity/step targets. (d) Media Assets: High-resolution progress photographs uploaded directly by the User to visually track muscular and physical composition over time. (e) Attendance & Hardware Integration Logs: Facility entry timestamps, class check-ins, and activity logs generated through local physical hardware integration (including QR systems or local biometric access readers). (f) Booking & Scheduling Records: Real-time reservation records for classes, personal training slots, and waitlists.
5. Inter-Platform Visibility & Trainer Collaboration Paradigm
Fitrobit V2 functions as a collaborative fitness optimization ecosystem. A core feature is providing real-time, actionable insights to your trainers. Therefore, you explicitly acknowledge and consent to the absolute visibility of your logged data: any metric, nutrition tracker, lifestyle log, completion checkmark, or progress photograph you input into the Application will be immediately visible to the administrative personnel, gym managers, and assigned Personal Trainers of your Gym Client. This data is displayed natively within their web dashboards to help them monitor compliance and adjust your fitness plans. It is accessible without requiring secondary authorization or individual password prompts from you.
6. Information Security Architecture & Storage Standards
Fitrobit implements strong physical, administrative, and technical safeguards designed to protect information from loss, misuse, or unauthorized modification: (a) Hosting Environment: The entire platform infrastructure is deployed within secure, high-availability data centers managed by Amazon Web Services (AWS). (b) Database Layer: Data is organized and stored in an enterprise MongoDB cluster utilizing access controls and network isolation protocols. (c) Cryptographic Protections: All user passwords undergo modern cryptographic hashing before being written to persistent storage. (d) Authentication Warning (Absence of MFA): Please note that this version of the Application relies on single-factor password authentication and does not support Multi-Factor Authentication (MFA). Account security depends heavily on your password strength. You assume full risk for unauthorized access resulting from weak or compromised passwords.
7. Data Retention Cycles and Account Erasure Rights
Because data ownership belongs to the Gym Client, Fitrobit stores your data according to the timeline chosen by your gym. If your gym membership expires or is canceled, your historical data remains in our system until the Gym Client requests a database cleanup. To delete your account or permanently erase your personal records, you must submit a formal request to your gym's management team. Fitrobit will execute these data deletion tasks within standard engineering timelines once we receive an authorized command from the Gym Client.
Contact us
If you have any questions about this Privacy Policy or how your data is processed, please contact the Fitrobit Legal, Compliance & Data Protection Office.
- info@fitrobit.com
- +94 707 444 404
- Fitrobit (Pvt) LtdRuhunukala Mawatha
Colombo, Sri Lanka