Privacy statement
Which data we process, what for and for how long, and what your rights are.
Effective from 1 October 2026.
How to read this statement
This statement explains what NForce IT, trading as Fit Relay, does with personal data. Fit Relay has two roles.
For this website, for the businesses that buy Fit Relay and for their contact persons, Fit Relay decides what happens with the data: we are the controller.
For the data a gym, studio or personal trainer puts into Fit Relay about its members and staff, including health data, the gym is the controller and Fit Relay processes the data on the gym's instructions, as a processor. If you train at a gym that uses Fit Relay, your gym's privacy statement applies to that data, and your questions about it go to your gym first. We help your gym answer them.
Who we are
NForce IT, trading as Fit Relay, the Netherlands, Chamber of Commerce 60066350, VAT NL002161960B51.
Send questions about privacy to privacy@fitrelay.app.
We have not appointed a data protection officer. Every privacy question reaches the owner directly, through the address above.
What we process as controller
For these processing activities we decide the purpose. Each one lists the data, what it is for and its legal basis (article 6 GDPR).
| Processing | Data | Purpose | Legal basis |
|---|---|---|---|
| Visiting fitrelay.app | The necessary cookies; technical data your browser sends (IP address, browser, the page) in the server logs | Showing the site, remembering your theme and language, security | Legitimate interest: a working, secure site |
| Statistics, only with your consent | Google Analytics cookies and the pages and actions you use; when signed in, your role (member, coach, manager) and your gym's short name. Never your name, e-mail address or anything from a check-in or other health data | Understanding how Fit Relay is used and improving it | Consent; you can withdraw it at any time |
| The contact form | Subject, business name, Chamber of Commerce number, your name, e-mail address, an optional phone number, your message | Answering you, and preparing a quote or agreement | Legitimate interest; steps at your request before an agreement |
| Signing up as a gym at fitrelay.app/start | The plan chosen, the company name, the Chamber of Commerce number, the VAT number, the invoice address and optionally the phone number, the gym's name, web address (and optionally its own domain) and address, your name and e-mail address, and your acceptance of the terms and the data processing agreement (who, which version, when) | Creating your organisation, having the subscription paid through Stripe and opening your account; showing that the terms were accepted | Contract: steps at your request to enter into and perform the agreement; legal obligation for the data processing agreement (art. 28 GDPR) |
| Bot protection (Google reCAPTCHA) on Fit Relay's sign-in, sign-up and contact form | Data reCAPTCHA collects in your browser to score whether you are a person; reCAPTCHA loads only once you use such a form | Keeping out automated abuse | Legitimate interest |
| A customer's organisation account | Name, e-mail address, the organisation and its Chamber of Commerce number, sign-in data and the two-step verification secret (stored encrypted) | Giving access, performing the agreement | Performance of the agreement |
| Billing the subscription | Organisation name, Chamber of Commerce number, invoice address and billing contact, the customer and invoice data in Stripe | Invoicing and collecting the subscription and its extras | Performance of the agreement; legal duty to keep records |
| Security of the platform | Every sign-in, wrong code, refused page, new role and changed password: an account id, the IP address and the reason | Detecting and investigating misuse | Legitimate interest: security |
| Service mail | Your e-mail address and name | Invitations and account mails | Performance of the agreement |
What we process as processor, for a gym
A gym uses Fit Relay to coach its members. For that, Fit Relay stores on the gym's behalf: the member's name, e-mail address, phone number if given, gym and coach; training and nutrition programmes; workout logs, meal logs and body measurements; daily check-ins (such as energy, sleep, soreness and weight) and reports of pain; messages between member and coach; appointments and bookings; contracts, payments and credits with the evidence of signing (time, IP address, browser, the accepted text); and, only when the member gives permission in the iOS app, day totals from Apple Health (steps, sleep, average heart rate, active energy, weight).
Much of this is data concerning health (article 9 GDPR). The gym decides why and on which basis it processes this data and is responsible for it. Fit Relay processes it only on the gym's instructions, under the data processing agreement in article 12 of our terms and conditions, and never for its own purposes.
A member can withdraw the Apple Health permission in the app at any time. What was synchronised before stays until the gym or the member has it deleted.
Who sees the data
Inside Fit Relay, a member's data is seen by the member, their coach (and a stand-in coach while one is set) and the people the gym gives access to.
Fit Relay's platform administrators see organisations, subscriptions and the people of each organisation (name, role, coach) to run the service, but not members' programmes, logs, check-ins or contracts.
The database separates every gym's data per row, so one gym can never read another's.
Recipients and sub-processors
Fit Relay runs on NForce IT's own servers in the Netherlands. We share personal data only with these parties, each bound by an agreement:
| Party | What for | Data |
|---|---|---|
| Stripe | Payments: iDEAL, card and SEPA direct debit, invoices for the subscription and for members' contracts | Name, e-mail address, payment details, amounts, the mandate |
| Google Workspace (Gmail) | Sending all of Fit Relay's mail and receiving the contact form | E-mail address, name, the content of the mail |
| Google reCAPTCHA | Bot protection on Fit Relay's sign-in, sign-up and contact form; not on a gym's own pages | Data reCAPTCHA collects in the browser |
| Google Analytics 4, only after consent | Statistics | Cookie id, pages, actions, role and gym short name |
| Apple Push Notification service | Push notifications to the iOS app, when the member allows them | A device token and the notification text |
Payment details (card, IBAN) are entered on Stripe's pages; Fit Relay does not store them. We do not sell personal data. We give data to authorities only when the law obliges us to.
Transfers outside Europe
Fit Relay's servers are in the Netherlands. Google, Stripe and Apple are groups with parent companies in the United States, so personal data may be transferred to the United States when they process it.
Those transfers rely on the EU–US Data Privacy Framework where the recipient is certified under it, and otherwise on the European Commission's standard contractual clauses. Ask for a copy of the safeguards at privacy@fitrelay.app.
How long we keep data
| Data | Kept for |
|---|---|
| Session cookie frp-token | 7 days, or until you sign out |
| Theme, language and cookie-choice cookies | 1 year |
| Technical server logs | 14 days |
| Security log (sign-ins, refused pages) | 90 days |
| Audit trail of changes in Fit Relay | As long as it is needed as evidence of who changed what, and at the latest until the data it concerns is deleted |
| Read in-app notifications | 90 days |
| Invitation links | 24 hours, then they no longer work |
| Contact-form messages | 12 months after the last contact, unless an agreement follows |
| A sign-up that is not paid | After 24 hours, or after 14 days while an iDEAL or SEPA payment is still clearing: we then delete your account and your acceptance. The company name and Chamber of Commerce number stay in the audit trail, which cannot be changed |
| Acceptance of the terms and the data processing agreement | As long as the agreement runs, and 5 years after that (the statutory limitation period) |
| Organisation account and contacts | As long as the agreement runs, and afterwards as long as the organisation's data is in Fit Relay |
| Invoices and payment records | 7 years (statutory duty) |
| Google Analytics data | 14 months |
| Data we process for a gym | Until the gym deletes it or asks us to delete or return it, also after the agreement ends |
When an account is deleted, the data linked to it is deleted with it, except what the law obliges us to keep.
Your rights
You have the right to access your personal data, to have it corrected or deleted, to restrict its processing, to object to processing based on legitimate interest, and to receive data you gave us in a structured, machine-readable form.
You can do the last yourself: under Settings you download all your own data as a file.
Send your request to privacy@fitrelay.app. We answer within one month and may ask you to prove who you are. If your request is about data your gym holds in Fit Relay, we pass it to your gym, which decides on it, and we help your gym carry it out.
If you think we handle your data wrongly, you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl). We would appreciate hearing from you first.
Withdrawing consent
Where we rely on your consent, you can withdraw it at any time, without it affecting what happened before. Statistics and advertising: Cookie settings at the bottom of every page. Apple Health: in the Fit Relay app and in the iOS Health settings. Anything else: privacy@fitrelay.app.
Automated decisions
Fit Relay takes no decisions about you based solely on automated processing that have legal or similarly significant effects, and it does not profile you. Fit Relay contains no artificial intelligence that decides about members.
Two automatic security checks exist: reCAPTCHA scores whether a sign-in, sign-up or contact message comes from a person, and a request with a very low score is refused (you can then reach us by e-mail); and after too many wrong passwords or codes, signing in is blocked for fifteen minutes.
Security
Every account signs in with a password and a second step (a code from an authenticator app). Connections are encrypted (HTTPS). The database separates each gym's data per row, the servers accept connections only from the network's edge, and every sign-in and refused access is logged.
If a breach still happens, we inform the gyms concerned and, where the law requires it, the Autoriteit Persoonsgegevens.
Changes
We may change this statement when Fit Relay changes. The date at the top shows the current version; we inform customers of important changes by e-mail.