Legal documents
Privacy notice
Last updated: 22 September 2026 · version 2026-09-draft
This notice (art. 13 of Regulation (EU) 2016/679, “GDPR”) explains how the personal data of FITROOM users are processed. FITROOM is the app the studio uses to rent its room by the hour to professionals.
1. Data controller
The data controller is the studio that runs the room, shown below. For any question about your data, or to exercise your rights, write to the email address shown.
The app is developed and hosted by a technical provider that processes the data on the studio's behalf, as a processor (art. 28 GDPR).
- Company name
- Fitroom Studio S.r.l.
- Registered office
- Via Giuseppe Mazzini 48, 20123 Milano (MI), Italia
- info@fitroom.example
- Certified email (PEC)
- fitroomstudio@pec.example
- Data Protection Officer (DPO)
- [to be provided by the owner]
Note: the company name, registered office, VAT number, contacts and data controller above are invented placeholders, shown so the page can be reviewed. They are not the studio's real details and will be replaced with the ones the owner provides before publication.
2. Who this notice is for
This notice covers:
- the professionals (personal trainers, nutritionists, osteopaths and others) who sign up, apply and book the room;
- visitors of the public pages of the site.
FITROOM does not collect data about the professionals' clients: bookings hold no client names and no free notes about them. Please do not enter your clients' data in the app, for example in a cancellation reason.
3. Which data we process
- Contact and profile data: name, email address, phone, type of profession, VAT number (optional) and billing name, if any.
- Sign-in and security data: the one-time sign-in codes sent by email (stored hashed, valid for 10 minutes), sign-in sessions with IP address and browser type, the preferred language.
- Booking data: room, dates and times, status, reschedules, cancellations with their reason if given, and the history of changes.
- Payment data: amounts, status, refunds and Stripe transaction references. You enter card details on Stripe's payment page: they never reach the app's servers.
- Communications: the service emails we send you (sign-in codes, outcome of your application, confirmations, reschedules, cancellations, refunds, reminders).
- Push notifications, only if you turn them on: the technical address your browser gives us to reach it, the two keys we encrypt the message with, and the browser's name so we can tell your devices apart. They are used only to deliver reminders, and you delete them by turning notifications off.
We do not process health data or other special categories of data. The public pages use no analytics or profiling tools.
4. Why we process them and on which legal basis
- Creating and running your account, reviewing your application and letting you book, pay, reschedule and cancel: performance of a contract and pre-contractual steps (art. 6(1)(b) GDPR).
- Sending you the service emails about your account and bookings: performance of a contract (art. 6(1)(b) GDPR).
- Keeping the accounts, producing the monthly statement and meeting tax obligations: legal obligation (art. 6(1)(c) GDPR).
- Protecting the account and the service (sign-in sessions, history of booking changes, abuse prevention): the controller's legitimate interest in security (art. 6(1)(f) GDPR).
We do not use your data for marketing and we do not sell it.
5. Required data
Name, email and phone are needed to apply and to book: without them we cannot handle your request. The VAT number is optional.
6. How long we keep them
- Account and profile data: for as long as you work with the studio. After the account is closed they are deleted or anonymised, except those in the next point.
- Payments, refunds, paid bookings and statements: for the period required by tax and accounting law.
- Sign-in codes: valid for 10 minutes.
- Sign-in sessions: they expire 7 days after the last renewal.
- Push notification subscriptions: for as long as you keep them on. We delete them when you turn them off, and at the first send the push service refuses because the subscription no longer exists.
The exact retention periods will be stated in the final version of this notice.
7. Who receives the data
- The owner and the authorised staff of the studio, to handle applications, bookings and payments.
- The technical provider that develops and runs the app, as a processor.
- The service providers the app uses, as sub-processors: Vercel (app hosting, with functions in the Frankfurt region), Neon (database, Frankfurt), Stripe (payments and refunds), Resend (email delivery, from the EU region in Ireland).
- Authorities and the studio's advisers, for example its accountant, when the law requires it.
The data are not disclosed to the public.
8. Transfers outside the European Union
The database and the app are hosted in the European Union. Some providers are US companies or process part of the data in the United States: Stripe (payment processing), Resend (account data and delivery logs) and Vercel (platform operations). These transfers rely on the EU-US Data Privacy Framework, for certified companies, or on the standard contractual clauses adopted by the European Commission.
9. Your rights
At any time you can ask to:
- access your data and receive a copy;
- correct or update them (you can also change your name, type of profession, phone and VAT number yourself on the Profile page);
- erase them, within the limits of the retention obligations;
- restrict their processing or object to processing based on legitimate interest;
- receive them in a structured, machine-readable format (portability).
To do so, write to the controller's email address shown in section 1. You also have the right to lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it).
10. Automated decisions
We make no decisions based solely on automated processing and we do no profiling. Applications are approved by the studio owner.
11. Changes to this notice
If this notice changes, we publish the new version on this page: the date at the top shows the last update.