GDPR Policy
Introduction
At Enfinify Holding LLC, we are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR). This policy applies to users within the European Economic Area (EEA) and explains how we collect, process, store, and protect personal data through Endomondo.com, the Enfit app, online coaching services, and eCommerce operations (physical and digital products).
By using our services, you acknowledge that we may process your personal data in accordance with this policy.
1. Data We Collect
We collect personal data to provide and improve our fitness, coaching, and eCommerce services. The types of data we collect include:
Personal Information:
- Name, email, phone number (for account registration, purchases, and coaching sessions).
- Billing and shipping addresses (for product orders and deliveries).
Account & Fitness Data:
- Workout history, preferences, and progress (for Enfit and online coaching).
- User-generated content, such as reviews, testimonials, or fitness logs.
Payment Information:
- Payment details (processed securely through third-party gateways like Stripe or PayPal).
Technical Data:
- IP address, browser type, device ID (for analytics and security).
- Cookies and tracking technologies (see our Cookie Policy for details).
2. How We Use Your Data
We process personal data for the following purposes:
- Providing Services: To deliver coaching programs, fitness tracking, and product purchases.
- Order Fulfillment: To process, ship, and deliver physical products or digital content.
- User Support: To respond to inquiries and provide assistance.
- Marketing & Promotions: To send personalized offers (with user consent).
- Analytics & Improvements: To enhance our platforms and optimize user experience.
- Legal Compliance: To meet tax, regulatory, and fraud prevention requirements.
3. Legal Basis for Processing Data
Under GDPR, we only process personal data when we have a legal basis, such as:
- User Consent: When users opt-in to marketing emails or agree to cookies.
- Contractual Necessity: To fulfill purchases, coaching agreements, or app usage.
- Legal Obligation: To comply with tax laws, fraud prevention, or GDPR requirements.
- Legitimate Interest: To improve services while balancing user rights and freedoms.
4. Data Sharing & Third Parties
We do not sell personal data. However, we may share information with:
- Payment Processors (e.g., Stripe, PayPal) to handle transactions securely.
- Shipping & Logistics Providers to deliver purchased products.
- Online Call & Scheduling Apps (e.g., Zoom, Google Meet, Calendly) for coaching sessions.
- Messaging Platforms (e.g., WhatsApp) for customer interactions.
- Analytics & Advertising Providers (e.g., Google Analytics, Raptive) for website insights.
- Legal Authorities if required by law.
All third-party partners are GDPR-compliant and handle data securely.
5. Your Rights Under GDPR
Users in the EEA have the following data protection rights:
🔹 Right to Access: Request a copy of the personal data we hold.
🔹 Right to Rectification: Correct any inaccurate or incomplete data.
🔹 Right to Erasure (“Right to be Forgotten”): Request deletion of your data.
🔹 Right to Restrict Processing: Limit how we use your data.
🔹 Right to Data Portability: Receive your data in a machine-readable format.
🔹 Right to Object: Opt out of direct marketing or data processing based on legitimate interests.
🔹 Right to Withdraw Consent: Revoke consent for data collection at any time.
To exercise your rights, contact us at [email protected]
6. Data Retention & Security
We retain personal data only as long as necessary for service delivery, legal compliance, or user requests. We use encryption, secure servers, and access controls to protect your data.
- Account Data: Retained as long as the account is active.
- Purchase Data: Retained for tax and legal purposes.
- Coaching Data: Retained for continued service and progress tracking.
- Marketing Data: Retained until you opt out.
Users can request deletion of their data at any time.
7. International Data Transfers
As a US-based company, we may process personal data outside the EEA. When we do, we ensure GDPR-compliant data transfer safeguards, such as:
- Standard Contractual Clauses (SCCs)
- Data Processing Agreements (DPAs) with third-party vendors
- Encryption & Security Measures
8. Updates to This GDPR Policy
We may update this policy periodically to reflect regulatory changes or service updates. Users should review this page regularly for the latest version.
9. Contact Us
For any GDPR-related requests or concerns, contact us at:
Email: [email protected]
Contact Page: https://www.endomondo.com/contact
If you believe your rights have been violated, you may also file a complaint with your local Data Protection Authority (DPA).