Legal
Privacy Policy
What personal data DanFit collects, why, and how gyms, their staff and their members can exercise their rights.
01 Who we are and what this policy covers
DanFit is gym management software operated by Wellness+, Tirana, Albania (“we”, “us”). This policy describes how we handle personal data when you visit danfit.io, create an account, use the Service, or when a gym that uses DanFit records information about you as a member.
We keep this policy as plain as we can. If anything is unclear, write to us at support@weplus.al.
02 Our role: controller or processor
DanFit is used by gyms, and gyms use it to manage their members. Because of this, we act in two different roles:
- As a data controller for the personal data of website visitors, of the people who create and use a gym account (owners, administrators, reception staff), and for billing and support data. We decide how and why this data is processed.
- As a data processor for the personal data that gyms enter about their members and staff. The gym is the data controller: it decides what data is collected and why, and it is your first point of contact if you are a member. We process that data only on the gym's instructions.
Where this policy says “member data”, it means data processed in the second role.
03 The data we collect
Data you give us when you create and use an account
- your name, email address and password (stored only as a secure hash), your role and preferred language;
- your gym's name, contact email, logo, currency and language;
- subscription and billing information: the plan you chose, its status and renewal dates, and the invoice and payment records provided by our payment provider. We never receive your full card number;
- support tickets and messages you send us, including any screenshots you attach;
- settings you configure, such as membership types, check-in devices and API keys (stored as a hash).
Member data entered by gyms
Depending on what the gym chooses to record, this may include a member's name, email address, phone number, gender, date of birth, postal address, identity document number, notes, profile photo and preferred language; membership subscriptions and payments; check-in history (date and time of each visit); documents signed electronically, including the drawn signature; and, if the gym has enabled the optional face recognition add-on, a facial template (see below). Members can also enter some of this data themselves through a gym's self-service registration portal.
Data collected automatically
- technical data such as your IP address, browser type, device and operating system, pages visited, and the date and time of requests, kept in server logs;
- error reports generated when something goes wrong in the application, which may include the identifier of the account concerned;
- cookies that are strictly necessary for the Service to work (see Cookies and similar technologies).
We do not collect data from third-party sources or build profiles for advertising.
04 Why we use personal data and on what legal basis
We use personal data for the following purposes and legal bases. The legal bases refer to the EU General Data Protection Regulation (“GDPR”), which applies to our customers and their members in the European Economic Area, and to the equivalent provisions of other applicable laws.
- To provide the Service — creating and managing accounts, storing your data, issuing wallet passes, recording check-ins, generating reports and sending transactional emails. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- To bill and collect payments and to keep the accounting records the law requires. Legal basis: performance of a contract and compliance with legal obligations (Art. 6(1)(b) and (c)).
- To keep the Service secure — authenticating users, preventing abuse and fraud, monitoring errors and diagnosing problems. Legal basis: our legitimate interest in running a secure and reliable service (Art. 6(1)(f)).
- To support you — answering your requests and tickets. Legal basis: performance of a contract and legitimate interest.
- To communicate about the Service — account, billing, security and product changes. Legal basis: performance of a contract and legitimate interest. We send marketing emails only with your consent, which you can withdraw at any time.
- To improve the Service — understanding how features are used, in aggregated form. Legal basis: legitimate interest.
- To comply with the law and to establish, exercise or defend legal claims.
Member data is processed only for the purposes determined by the gym, which is responsible for its legal basis.
05 Member data: our commitments as a processor
When we process member data on behalf of a gym, the following terms apply between us and the gym and form part of our Terms of Service. They are intended to meet the requirements of Art. 28 GDPR.
- We process member data only to provide the Service and on the gym's documented instructions, which include the settings and actions performed in the Service, unless the law requires otherwise.
- The gym is responsible for having a lawful basis, for informing its members and for obtaining any consent the law requires, including explicit consent for biometric data.
- We make sure the people who access member data are bound by confidentiality and only access it when needed for support or operations.
- We implement the security measures described in How we protect data.
- We use the sub-processors listed in Who we share data with and will inform the gym before adding or replacing a sub-processor, giving it the chance to object.
- We help the gym respond to requests from members exercising their rights, and we notify the gym without undue delay if we become aware of a personal data breach affecting member data.
- At the end of the Service we delete or return member data as described in How long we keep data, and we provide the information reasonably needed to demonstrate compliance.
If you are a gym member and want to access, correct or delete your data, please contact your gym. If you contact us directly, we will forward your request to the gym and assist as needed.
06 Face recognition and biometric data
Face recognition is an optional add-on that gyms can enable to let members check in without a phone or card. It works as follows:
- When a gym staff member enrols a member, or a member enrols themselves on the gym's self-service portal, a photo or camera capture is analysed in the browser to compute a facial template: a set of 128 numbers describing facial features. Only this template is sent to us; the image used for enrolment is not uploaded for recognition purposes.
- The template is stored in the member's record in our database and made available to the gym's registered check-in devices, which compare it locally in the browser with the face of the person in front of the camera.
- When a match is found, the device sends us only the identifier of the matched member so that the visit can be recorded. Camera images from the check-in device are not sent to us or stored by us.
Facial templates are biometric data and, under the GDPR, a special category of personal data. The gym, as controller, must obtain the member's explicit consent before enrolment and offer an alternative way to check in. We process templates exclusively to provide the check-in feature, never share them with anyone else, and delete them when the gym removes them, when the member is deleted, or when the gym's account is closed.
09 International transfers
Our servers are located in the European Union. Our team in Albania accesses data for support and operations, and some of our providers are based in the United States. When personal data protected by the GDPR is transferred outside the European Economic Area, we rely on appropriate safeguards: the European Commission's Standard Contractual Clauses and, for providers certified under it, the EU-U.S. Data Privacy Framework. You can ask us for more information about these safeguards.
10 How long we keep data
- Account and gym data: for as long as your account exists, and for 30 days after it is closed so that you can request a copy of your data. After that, it is deleted.
- Billing records: for as long as tax and accounting law requires (generally up to 10 years).
- Member data: for as long as the gym keeps it in the Service. When a gym deletes a member, the record is deactivated immediately and removed from the gym's views; it is permanently erased when the gym requests it or when the gym's account is closed. Facial templates are erased as described in Face recognition and biometric data.
- Support tickets: for as long as your account exists, so that we can follow up on previous issues.
- Server logs and error reports: for a limited period, normally no more than 90 days, unless needed to investigate a security incident.
- Backups: copies of the database are kept for disaster recovery and overwritten within 30 days.
11 How we protect data
We take reasonable technical and organisational measures to protect personal data against loss, misuse and unauthorised access, including:
- encryption of all traffic between your browser, your devices and our servers (HTTPS);
- passwords stored only as salted hashes; API keys stored as hashes; time-limited tokens for email verification and password reset;
- strict separation of each gym's data: users and devices can only reach the data of their own gym, and access is limited by role;
- check-in devices authenticated with one-time activation codes and revocable at any time;
- access to production systems restricted to authorised staff, and regular backups.
No system is completely secure. If we become aware of a breach affecting your data, we will notify you and, where required, the competent authority without undue delay.
12 Your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected and incomplete data completed;
- have your data erased, in the situations provided by law;
- restrict or object to certain processing, including processing based on our legitimate interests;
- receive the data you provided in a portable, machine-readable format;
- withdraw your consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
- lodge a complaint with a data protection authority — in the EEA, the authority of your country of residence; in Albania, the Commissioner for the Right to Information and Personal Data Protection.
To exercise these rights, email us at support@weplus.al. We may need to verify your identity before acting on a request, and we will respond within one month, extendable where the law allows. If you are a gym member, the quickest route is to contact your gym, which controls your data; we will assist it in responding.
Gym users can update their own name, email, password and language at any time in the Service's settings.
13 Children
DanFit accounts are for businesses and their staff, and we do not knowingly collect personal data from children through the website. Gyms may record data about members who are minors (for example junior memberships); in that case the gym is responsible for obtaining the consent of a parent or guardian where the law requires it.
14 Changes to this policy
We may update this policy from time to time. The date at the top of the page shows when it was last changed. If the changes are material, we will notify account holders by email or through the Service before they take effect.
15 Contact
For any question about this policy or about your personal data, contact us at support@weplus.al.
Wellness+Tirana, Albania
danfit.io