Privacy policy
Version 2026-10. Last updated: October 2026. The Romanian text prevails.
1. Who we are
The data controller is SC Fit and Fight Legion SRL, registered office Calea Aurel Vlaicu nr. 270, Arad, Romania, tax ID 50644849, trade register no. J2024027913004 (“the Club”). The Club runs the Fit & Fight Arad gym, the fit-and-fight.ro website and the Fit & Fight mobile app.
For any question or request about your data, write to gdpr@fit-and-fight.ro or to the registered office.
2. What data we process
Account and profile
- name (username), email address, password (stored only in hashed form), phone number (optional);
- preferred language, preferred location, notification preferences;
- the age group declared at sign-up (18+, 14–17, child under 14).
Membership and payments
- memberships (plan, period, entries left, state: paid up, overdue, suspended, terminated);
- payments (amount, date, method: cash or card at the front desk, who received it);
- the date and version of the signed membership contract, the date and reason of a termination request.
Activity at the gym
- class bookings, check-ins and no-shows;
- badges earned (for attendance, training streaks, or awarded by a coach);
- which Club announcements you have read in the app.
Consents
- acceptance of this policy (date and version);
- the image-use consent (YES/NO) with its history (date, source: paper contract or app);
- for minors: the parent's or guardian's name and phone and the date the signed parental agreement was received.
Technical data
- the device identifier for push notifications (Firebase Cloud Messaging token);
- server logs (IP address, date and time of the request), kept for security.
What we do NOT store in the platform: identity card number, home address and health declarations. These stay only on the signed paper contract kept at the Club's office.
3. Why we process it and on what legal basis
- Entering into and performing the membership contract (Art. 6(1)(b) GDPR): account, membership, bookings, check-in, payments, termination.
- Legal tax and accounting obligations (Art. 6(1)(c) GDPR): records of payments received.
- Legitimate interest (Art. 6(1)(f) GDPR): notifications about the schedule, cancellations and changes, Club announcements, badges, platform security. You can object at any time in Profile → Notifications.
- Consent (Art. 6(1)(a) GDPR): use of your image in promotional material. Optional and revocable at any time.
4. Minors
People aged 14 to 17 may create their own account. For children under 14 the account is created and used by a parent, who can manage several children from one login. In both cases the contract and the parental agreement are signed by a parent or guardian, and bookings are possible only once the front desk has recorded the parental agreement. A minor's image consent is given and withdrawn only by the parent. The Club does not publish a minor's full name, school or any other data that would allow locating them.
5. Who receives the data
We do not sell data. It is shared only with:
- Club staff (front desk, coaches, administrator), strictly for their work;
- the hosting provider of the platform server, as a processor;
- Google (Firebase Cloud Messaging), to deliver push notifications;
- Apple and Google, through the app stores you install the app from;
- the Club's accountant and public authorities, where the law requires it.
Some of these services (Google, Apple) may transfer data outside the European Economic Area, on the basis of the EU–US Data Privacy Framework adequacy decision or the European Commission's standard contractual clauses.
6. How long we keep data
- For the duration of the membership contract.
- After the last membership ends, for 3 more years (the general limitation period), after which personal data is anonymised automatically.
- Payment records are kept for 10 years, as accounting law requires, but no longer identify you once anonymised.
- After an image consent is withdrawn, the Club removes from its own channels, within 30 days, material in which you are easily recognisable.
7. Your rights
You have the right:
- of access and portability: in the app, Profile → “Download my data”, or on request;
- to rectification: name and phone in the app, everything else at the front desk;
- to erasure: in the app, Profile → “Delete account” (anonymised immediately), or on request;
- to restriction of processing and to object, on request or through the notification preferences;
- to withdraw consent for image use, in the app or in writing;
- to lodge a complaint with the Romanian supervisory authority ANSPDCP, www.dataprotection.ro.
We answer requests within one month.
8. Security
Access to data is limited by role; each member sees only their own data. Passwords are stored hashed and all traffic to the server is encrypted (HTTPS).
9. Changes
When this policy changes we announce it in the app (Announcements) and update the version above.