Data controller
The data controller is IMG S.A. with its registered office in Gdansk, ul. Obroncow Wybrzeza 9/4, NIP: 7010264454, hereinafter referred to as the Company.
Providing any personal data is voluntary, but it is necessary to achieve the purpose for which the data is provided or to take actions connected with that purpose.
Scope of processed data
The Controller processes the following Customer data:
- surname and given names,
- email address,
- phone number,
- activity related to individual projects,
- activity related to the use of individual services,
- personal data or information that we are required to collect under applicable laws, recommendations or guidelines,
- payment amount and date, data provided by your bank or payment operator, and the payment method used.
Where children participate in a service, the data of both children and their parents is processed. The Controller also processes the email address, phone number and name of a newsletter recipient. For employees, the set of processed data results from employment regulations.
Legal bases and purposes
Under Article 6 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), the basis for processing personal data by the Controller is the user’s consent, a legal obligation and performance of a contract.
The purposes of data processing are:
- sale of Services and products included in the offer (Article 6(1)(b) GDPR),
- proper performance of agreements concluded with IMG S.A. (Article 6(1)(b) GDPR),
- delivery of informational and advertising mailings to which the user has consented (Article 6(1)(a) GDPR),
- activity related to sport and a healthy lifestyle,
- ongoing informational, educational and advertising communication with recipients,
- ensuring the health safety of customers and employees, including by collecting data on training frequency, weight, exercises performed and other aspects of training and the training process, analysing those data and preparing reports to provide the highest quality services,
- analysis, service improvements, automation of business processes, and preparation of statistics and reports using artificial intelligence based tools (Article 6(1)(a) GDPR).
Access to data and external entities
All members of the Company’s team have access to personal data. Access to particular categories of persons is separated by technical permission limits for shared drives or folders. Documents are similarly protected physically in locked cabinets.
The list of external entities that have access to personal data is kept in the Company’s documentation. Each of those entities publishes its privacy policy on its own website.
Those entities guarantee compliance with the GDPR or with standards analogous to the GDPR in the field of personal data protection, and the Controller’s use of their technologies when processing personal data is lawful. Data processing agreements have been concluded with those entities, usually in the form of updates to their terms.
The Controller will not sell or transfer Customers’ personal data to entities other than those indicated in the documentation.
The user acknowledges that personal data may be transferred to authorised state authorities in connection with proceedings conducted by them, at their request and after the prerequisites confirming the necessity of obtaining such data from us have been met.
User rights
The user has the following rights:
- Right to withdraw consent - withdrawing consent may prevent further use of services that the Controller may lawfully provide only on the basis of consent. Withdrawal of consent does not make processing performed before withdrawal unlawful.
- Right to object to the use of data - if the Controller processes data on the basis of a legitimate interest, the user may object to such use. If the objection is justified and the Controller has no other legal basis for processing, the data covered by the objection will be deleted.
- Right to erasure (“right to be forgotten”) - at the user’s request, the Controller will delete data where consent has been withdrawn, a justified objection to marketing or statistical use has been raised, processing is unlawful, or the data is no longer necessary for the purposes for which it was collected or processed.
- Right to restriction of processing - where the accuracy of data, lawfulness or necessity of processing is contested, or where an objection has been lodged.
- Right of access - the Controller will confirm whether personal data is processed. The user may obtain a copy of the data, access to the data and the information contained in this Policy and other requested information.
- Right to rectification - at the request of the User or Customer, the Controller will correct inaccurate data and supplement incomplete data.
- Right to data portability - at the request of the user or Customer, the Controller will send personal data in a PDF file or another agreed format to the requester or directly to another controller indicated by them.
The user also has the right to lodge a complaint with the President of the Personal Data Protection Office.
The Controller enables the exercise of these rights by email to hello@fitipass.com, with a clear subject line indicating which right the user wishes to exercise. The Controller will fulfil the request within 30 days of receiving the message.
Data retention
The data retention period will not be shorter than required by applicable law, including accounting, tax, pension and social insurance regulations.
- Newsletter recipient data will be stored until a deletion request is submitted.
- Customer data will be stored until the limitation period for related claims expires.
The Company undertakes to destroy temporary documents containing personal data, such as participant lists for a specific event or class, and to ensure proper data circulation and minimisation in line with the procedures recorded in the Register of Processing Activities.
Data security
The Controller applies technical and organisational measures ensuring protection of processed personal data appropriate to the risks and categories of protected data, in particular protecting data against disclosure to unauthorised persons, removal by an unauthorised person, processing in breach of applicable regulations, and alteration, loss, damage or destruction.
The Controller informs that it has not appointed a Data Protection Officer (DPO) and independently performs duties connected with personal data processing.