Privacy policy
Last updated: September 8, 2026
This policy describes the personal data NetFit actually collects today, how it is used, and your rights over that data. It is written to reflect what the product actually does, not what is planned for later. It will be updated before any new data-collection feature goes into production, particularly health data.
1. Data controller
The controller for the data described in this policy is NetFit [legal structure currently being incorporated, see legal notice]. For any question about your personal data: contact@netfitsn.com.
2. Scope
This policy covers two surfaces: (a) the netfitsn.com website (contact form, newsletter, waitlist), and (b) the NetFit software platform used by client gyms (staff accounts, member records entered by the gym). It does not cover features that have not yet been built, such as detailed health-data synchronization: those processing activities will trigger an update to this policy, and where applicable, prior authorization from the competent authority, before going live.
3. Data collected
- Via the site: name, email, phone, gym name, city, message (contact and demo forms); email only (newsletter, Coaches/Members waitlist).
- Via the platform, for a client gym's staff account: name, email, phone, role, password (hashed, never stored in plain text).
- Via the platform, for a member record entered by a client gym: name, phone, email (optional), subscription history, payment history, check-in history, photo (optional).
- Technical data: IP address and connection logs, for security purposes (fraud detection, abuse prevention).
4. Purposes of processing
- Responding to contact and demo requests.
- Sending the newsletter and product updates, only to those who consented.
- Providing the NetFit service to client gyms (member management, access control, billing).
- Ensuring platform security (fraud prevention, logging).
- Complying with our legal and accounting obligations.
5. Legal basis
Processing is based, depending on the case, on the performance of the subscription contract (data processed via the platform), consent (newsletter, waitlist), NetFit's legitimate interest (security, fraud prevention), or compliance with a legal obligation (billing).
6. NetFit's role versus the client gym's role
For a member's data entered by a client gym, the gym is the data controller: it decides what is collected and how it is used with respect to its member. NetFit acts as a data processor: we host and secure this data on the gym's behalf, without using it for our own purposes. Any question a member has about their data should first be directed to their gym; NetFit remains available for any technical question about how this data is hosted.
7. Data recipients
Data is accessible to authorized NetFit personnel, and to technical subprocessors strictly necessary for the service: OVH (hosting), Resend (transactional emails), and the mobile money payment provider used to bill client gyms. No data is sold to third parties or used for advertising purposes.
8. Retention period
Contact and newsletter data is kept until unsubscription, or for 3 years after the last contact if there is no response. Data for a tenant or member account is kept for the duration of the contractual relationship, then anonymized within 30 days after the contract effectively ends. Data required for our legal obligations, notably accounting (payments, invoices, check-in history), is kept separately for as long as those obligations require, unless a deletion request is processed under section 10.
9. Security
NetFit implements technical and organizational measures to protect your data: hashed passwords (never stored in plain text), encrypted connections, strict data isolation between each client gym, role-based access control. Our security posture is tracked methodically and documented internally, including regular audits.
10. Your rights
In accordance with Senegalese law No. 2008-12 on the protection of personal data, and, for individuals covered by the GDPR, the European regulation, you have the right to access, rectify, erase, object to, and port your data.
At this time, these requests are handled manually: write to contact@netfitsn.com stating your identity and the nature of your request, and we commit to responding within a reasonable timeframe. A self-service export and deletion mechanism within the platform is under construction and will progressively replace this manual process.
You also have the right to lodge a complaint with Senegal's Data Protection Commission (CDP), the competent supervisory authority.
11. Cookies
The netfitsn.com website only uses technical cookies strictly necessary for it to function (language preference, theme preference). No third-party analytics or advertising cookies are set at this time; this policy will be updated if that changes.
12. International transfers
Hosting the data (OVH) may involve processing outside Senegal, notably in France/Europe. NetFit ensures it uses a hosting provider offering recognized security guarantees for this type of transfer.
13. Minors
The platform may be used by a gym to manage minor members, under the gym's responsibility and, where applicable, with the consent of their legal guardian collected by the gym itself at sign-up.
14. Changes to this policy
This policy may be updated, notably as new platform features go into production. The last-updated date appears at the top of this page.