Privacy policy
What onTrainer does with personal data, whose data it is, and how to get at it. Written for coaches, clients and visitors, who are not in the same position.
Previous versions
- No previous versions. This is the first one in force.
1Two different roles, and why it matters
In plain language
For your own account, we decide how your data is used. For your clients' data, your coach decides and we only act on their instructions.
onTrainer sits in two different positions depending on whose data is involved, and your rights are exercised differently in each.
| Whose data | Who is the controller | Where to go |
|---|---|---|
| A coach's own account | onTrainer | Use this policy and contact our data protection officer. |
| A client's records, programs, check-ins and health data | The coach who invited them | Ask that coach. onTrainer processes it only on their instructions, under the data processing agreement. |
| A visitor to this website | onTrainer | Use this policy and the cookie choices page. |
If you are a client and you are not sure who your coach is, the invitation you accepted names them, and their name appears in your app.
2Who to contact
You can also complain to a supervisory authority. In Romania that is the National Supervisory Authority for Personal Data Processing. If you live elsewhere in the EU, you may complain to the authority where you live.
3What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Identity and contact | Name, email address, the language you use | You, when you sign up or are invited |
| Workspace | Practice name, tier, and your booking rules: how late a client may cancel, and whether a missed session spends the credit | You |
| Coaching records | Programs, assignments, sessions, bookings, credit balances, check-in answers | You and your clients |
| Intake and medical flags | Answers to the intake forms a coach sets, and any flags derived from them | The client, on the coach's form |
| Health data | Heart rate, sleep, workouts and similar series | Apple Health or Health Connect, only after the client turns it on |
| Payment | Subscription status, tier, interval, and an identifier from our payment provider | Stripe. We never receive card numbers. |
| Technical | IP address, device and browser, timestamps, error logs | Automatically, when you use the service |
| Consent records | What was consented to, when, and against which version of the form | Automatically, when consent is given or withdrawn |
4Why we use it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing the workspace and the apps you subscribed to | Performance of a contract |
| Taking payment and managing the subscription | Performance of a contract |
| Keeping the service secure, and investigating abuse | Legitimate interests: keeping the service and its accounts secure, and stopping abuse of it |
| Understanding which pages of this website are read | Consent, through the cookie choices page |
| Synchronising and showing health data | Explicit consent, Article 9(2)(a) |
| Meeting our legal and accounting obligations | Legal obligation |
5Health and medical data
In plain language
It is off until a client turns it on, it can be turned off at any moment, and turning it off stops the flow immediately.
Health and medical information is what the GDPR calls special category data: the kinds of personal data it treats as the most sensitive, which may be used only on a short list of narrow grounds. The ground relied on here is the client's own explicit consent. The rule is Article 9 of the GDPR, and it is why this section exists at all.
- Synchronisation is off by default and starts only when the client gives explicit, separate consent in their own app.
- Consent is recorded with a timestamp and the version of the form it was given against.
- A client can withdraw consent at any time, in their app, without asking their coach. Withdrawal stops the flow of new data immediately.
- Risk flags and alerts derived from health data are informational prompts for the coach. They are not automated decisions producing legal effects.
- When a coach leaves the Online Coach tier, health history collected under it is permanently deleted, including derived flags and alert history. Affected clients are notified.
6Who else touches your data
We use a small number of processors. Each is bound by contract to act only on our instructions.
A current list of sub-processors, and how we tell you when it changes, is in the data processing agreement.
7Where your data is stored
Client records and health data are stored in the European Union. Each workspace is isolated from every other one at the database level, so one coach cannot reach another coach's data.
Where a processor operates outside the EU, the transfer relies on an adequacy decision or on standard contractual clauses.
8How long we keep it
| What | How long |
|---|---|
| Health data | Until consent is withdrawn, the client is removed, or the coach leaves the Online Coach tier, whichever is first |
| Payment and accounting records | As long as tax law requires |
9Your rights
In plain language
You can get a copy of your data, correct it, delete it, or take it elsewhere. Most of it you can do yourself, in the product.
| Right | How to use it |
|---|---|
| Access a copy | Export from your workspace, or ask us |
| Correct something wrong | Edit it in the product, or ask us |
| Delete your data | Request deletion in the product. Some records are kept where the law requires it. |
| Take it elsewhere | Export produces a machine-readable file |
| Withdraw consent | Turn health sync off in the app, or change your cookie choices |
| Object or restrict | Write to the data protection officer |
We answer within one month. If a request is complex we may extend that, and we will tell you why.
10Cookies
This website uses cookies that are necessary for it to work, and optional ones that tell us which pages are read. Optional cookies are off until you accept them, and declining leaves the site fully usable.
Your choice is recorded and can be changed at any time from Cookie choices in the footer.
11Changes to this policy
We keep every version of this policy, dated. When we make a material change we tell you before it takes effect. The version in force is named at the top of this page.