Legal

Privacy policy

We explain what data we process when you use Planify.fit as a trainer, gym or end client, what we use it for and how to exercise your rights. No unnecessary small print.

Last updated: 28 July 2026 · Version 3.1
In short

We don't sell your data or your clients'. We host everything on servers in the European Union. Your clients' training and health data is yours: we process it solely on your behalf and under your instructions, and you can export or delete it at any time from your dashboard.

1. Who the controller is

Planify.fit ("we") is the controller of the data of people who visit this website and of account holders.

For the data a trainer or gym enters about their own clients, Planify.fit acts as a data processor: the trainer or gym is the controller and decides the purposes. This relationship is governed by the data-processing agreement included in the Terms.

2. What data we process

Account data

Name, email, encrypted password, optional phone, business name and country.

Billing data

Legal name, tax ID, billing address and payment history. Card details are processed by Stripe: they never reach our servers.

Content you create

Plans, exercises, notes, messages, files and videos you upload to the platform.

Your clients' data

Name, contact, goals, measurements, training loads and notes that you enter or that the client logs in their portal.

Technical data

IP address, device and browser type, access and error logs.

Product usage

Pages visited and features used, only if you accept analytics cookies.

3. What we use it for and the legal basis

Purpose Legal basis (Art. 6 GDPR)
Providing the service: creating plans, managing clients, the client portal, payments. Performance of the contract
Billing, accounting and tax obligations. Legal obligation
Technical support and service communications. Performance of the contract
Security, fraud prevention and backups. Legitimate interest
Usage analytics and product improvement. Consent
Newsletter and marketing communications. Consent

4. Health-related data

Body measurements, previous injuries or physical limitations may be considered special-category data (Art. 9 GDPR). They may only be processed with the data subject's explicit consent. If you are a trainer or gym, it is your responsibility to obtain that consent before entering this information; the platform includes a client onboarding flow with an explicit consent checkbox and a record of the date so you can demonstrate it.

5. Providers who access the data

We work with a small number of providers, all with a signed data-processing agreement:

Amazon Web ServicesHosting and backups — Ireland region (EU)
Stripe Payments EuropePayment processing and billing — Ireland (EU)
BrevoTransactional emails and newsletter — France (EU)
Plausible AnalyticsAggregated analytics with no personal identifiers — Germany (EU)

We may also disclose data to legal and tax advisers, and to authorities where there is a legal obligation. We do not share data with third parties for advertising purposes.

6. International transfers

Data is stored and processed within the European Economic Area. If, on an occasional basis, a support provider were to access it from outside the EEA, the transfer is covered by the European Commission's standard contractual clauses together with supplementary encryption and minimisation measures. You can request a copy of these safeguards by writing to info@planify.fit.

7. How long we keep it

  • Account data and content: while the account is active.
  • After cancellation: 30 days for recovery, then deletion or anonymisation.
  • Invoices and accounting data: 6 years, under commercial and tax obligations.
  • Access and security logs: 12 months.
  • Non-necessary cookies: 13 months maximum.

8. Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction of processing, portability and not to be subject to automated decisions, and withdraw your consent at any time without affecting the lawfulness of processing carried out beforehand.

Write to info@planify.fit stating the right you wish to exercise. We will respond within one month at most. If you are a client of a trainer or gym, please contact them first, as they are the controller of your data; we will forward your request if it reaches us directly.

If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (aepd.es).

9. Cookies

We use necessary cookies for the session, security and payment, which do not require consent. Analytics and marketing cookies are only set if you accept them in the notice shown on your first visit. You can change your decision at any time from the "Cookies" link in the footer.

CategoryPurposeDuration
NecessarySession, security, paymentSession – 12 months
AnalyticsAggregated product usage13 months
MarketingCampaign measurement13 months

10. Security

We encrypt data in transit (TLS 1.3) and at rest (AES-256), apply role-based access control, optional two-step authentication, an audit log and daily encrypted backups. Should a security breach occur that poses a risk to your rights, we will notify you and report it to the authority within 72 hours.

11. Changes to this policy

If we change this policy we will let you know by email and within the app at least 15 days in advance where the change is substantial. The version in force will always be the one published on this page.

This English version is provided for convenience only. The binding version is the Spanish one; in the event of any discrepancy, the Spanish text prevails.

Read the Terms Back to home
© 2026 Planify.fit
Pricing FAQ Privacy Terms Cookies Status Contact