Version 1 · effective from 22.07.2026
GymMe Privacy Policy
Version: 1.0 · Effective date: 21 July 2026
The Polish-language version prevails. This English translation is for information only.
1. Controller and roles
- The controller of personal data relating to the user account and use of the GymMe platform (gymme.fitness) is Digital Solutions Tomasz Kłoś, Tax ID 8951902077, address ul. Piotrkowska 276A, 90-361 Łódź, contact: [email protected] (the "Operator" or "we").
- Dual role of the Operator. With respect to account data, authentication, subscription settlement, security and analytics, the Operator is the controller. With respect to the substantive Trainee data entered by a Trainer in the course of providing their service (plan content, notes, progress reports, health data), the Operator acts as a processor on the Trainer's behalf; the controller of that data is the Trainer (a sole proprietor).
2. What data we process and for what purpose
| Data category | Purpose | Legal basis |
|---|---|---|
| Email, username, password (hash) | account creation and operation, authentication | Art. 6(1)(b) GDPR (contract) |
| First name, last name, photo | user profile | Art. 6(1)(b) GDPR |
| Trainer business data (name, Tax ID, address) | public profile, legal requirements | Art. 6(1)(c) and (b) GDPR |
| Buyer data and purchase document | Trainer's sales documentation (processed on the Trainer's behalf) | legal obligation of the Trainer — Art. 6(1)(c) GDPR; GymMe as processor |
| Payment-attempt register (pseudonymous) | accountability, defence against claims — not a fiscal document | Art. 6(1)(f) GDPR (legitimate interest) |
| Technical data (IP address, logs, essential cookies) | security, service operation | Art. 6(1)(f) GDPR (legitimate interest) |
| Health data (injuries, limitations) | tailoring the training plan | Art. 9(2)(a) GDPR (explicit consent) — controller is the Trainer |
3. Analytics
For traffic analysis we use Plausible Analytics — a cookieless tool hosted in the European Union, which does not process personally identifiable data and does not perform cross-site tracking.
4. Recipients and processors
We use trusted providers that process data on our behalf (processors) or as independent controllers:
- Brevo (Sendinblue) — sending emails and SMS; processor; data processed within the EEA.
- Plausible Analytics — traffic analytics; processor; data in the EEA.
- Autopay — handling of Trainer subscription payments; independent controller for payment processing (service activated together with the subscription).
- Trainer — for Trainee data entered by the Trainer; independent controller (the Operator acts as a processor in that scope).
The current list of processors is available on request at [email protected].
5. Transfers outside the EEA
We aim to process data within the EEA. If any provider processes data outside the EEA, this takes place on the basis of appropriate safeguards (an adequacy decision, including the Data Privacy Framework, or standard contractual clauses).
6. Retention period
- Account data is stored for the lifetime of the account; after account deletion, operational data is anonymised or deleted.
- Buyer data and the purchase document are processed as a processor on the Trainer's behalf; their retention period follows the Trainer's tax obligations (as a rule, 5 years from the end of the tax year) — also after account deletion, on the basis of Art. 17(3)(b) GDPR. The fiscal obligation and the issuing of a receipt, invoice or bill rest with the Trainer; GymMe is not a fiscal cash register or an invoicing system (see the Terms). The payment-attempt register (pseudonymous party identifiers) is retained for our own purpose — accountability and defence against claims (Art. 6(1)(f) GDPR); it is not a fiscal document.
- Records of document acceptance (the fact, version, date) are retained for accountability and defence against claims; after account deletion we remove technical data from them (IP address, browser identifier) while retaining the pseudonymous fact of acceptance.
7. Rights of data subjects
You have the right of access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to withdraw consent at any time (without affecting the lawfulness of processing before withdrawal). You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO). For data processed by a Trainer (as controller), address your request to the relevant Trainer; we will help forward it.
Requests concerning data for which we are the controller should be sent to [email protected].
8. Cookies
We use only cookies that are essential for the operation of the service. Details are described in the Cookie Policy.
9. Changes to this policy
We may update this policy. The current version is always available on the Platform together with its effective date.