FIT Africa
FIT AfricaTechnologies Ltd

Legal

Privacy Policy

Effective date: 1 June 2025  ·  Last updated: 1 June 2025

FIT Africa Technologies Ltd (“FIT Africa”, “we”, “our”, or “us”) operates the FIT Africa coaching platform, accessible at fitafrica.tech and associated subdomains (the “Platform”). This Privacy Policy explains what personal information we collect, how we use it, when we may share it, and how you can exercise your rights. By using the Platform, you agree to the practices described in this policy.

1. Who We Are

FIT Africa Technologies Ltd is a technology company operating the FIT Africa coaching platform. We provide tools for personal trainers, sports coaches, and enterprise wellness programmes to manage clients, deliver fitness content, and track health progress.

Our platform serves three main user groups: Coaches (personal trainers and coaching professionals who create accounts and manage clients), Clients (individuals who access the platform through a coach invitation), and Enterprise Administrators (organisations that manage multiple coaches and client populations through the enterprise dashboard).

For privacy enquiries, you can contact us at: privacy@fitafrica.tech

2. Information We Collect

We collect information you provide directly, information generated through your use of the Platform, and limited technical information from your device.

Account and Profile Information

  • Coaches: full name, email address, password (stored as a salted hash), business name, business description, specialty areas, and profile photo.
  • Clients: full name, email address, date of birth, gender, phone number, address, emergency contact details, and profile photo — as entered during account setup or intake.
  • Enterprise administrators: full name, email address, organisation name, and role within the enterprise.

Health and Fitness Data

  • Weight entries and body composition measurements (waist circumference, body fat percentage) logged by clients over time.
  • Fitness goals, goal start values, target values, and current progress.
  • Daily check-in records including mood, energy levels, sleep quality, and free-text notes.
  • Workout assignment and completion records, including difficulty ratings and client feedback on sessions.
  • Health notes and intake information provided by clients or entered by coaches.

This data is sensitive. It is used solely to power the coaching relationship and is never sold or used for advertising profiling.

Coaching Content and Communications

  • Workout programmes, exercise libraries, and coaching content created and uploaded by coaches.
  • Messages exchanged between coaches and clients through the in-app messaging system.
  • Session notes and coach observations recorded against client profiles.
  • Uploaded media files, including profile photos and business logos.

Usage and Technical Data

  • Log data including IP address, browser type, device type, operating system, pages visited, and session timestamps.
  • Application error logs and diagnostic data used to identify and resolve technical issues.
  • Cookies and session tokens used to maintain your authenticated session.

3. How We Use Your Information

We use the information we collect to operate and improve the Platform. Specifically:

  • Create and manage your account, authenticate your identity, and keep your session secure.
  • Enable coaches to manage their clients, build and assign programmes, and deliver coaching services.
  • Allow clients to access their personalised workout plans, log progress, and communicate with their coach.
  • Generate progress reports, statistics, and goal tracking visualisations within the Platform.
  • Send transactional emails such as account invitations, session reminders, and security verification codes.
  • Provide enterprise administrators with aggregated analytics and oversight of their coaching programmes.
  • Detect and prevent fraudulent access, abuse, or security incidents.
  • Respond to support requests and resolve account issues.
  • Comply with legal obligations applicable to FIT Africa as a data controller.

We do not use your personal data for advertising purposes, and we do not sell your data to third parties.

4. Legal Basis for Processing

We process your personal data on the following legal grounds:

  • Contract performance: processing your data is necessary to provide the services you signed up for.
  • Legitimate interests: operating and improving the Platform, preventing fraud, and maintaining security.
  • Legal obligation: complying with applicable data protection and regulatory requirements.
  • Consent: where we ask for your explicit consent for a specific processing purpose, such as marketing communications.

5. Data Sharing and Disclosure

We do not sell, rent, or trade personal information. We may share information in limited circumstances:

Service Providers

We use trusted third-party service providers to help operate the Platform. These include:

  • Cloud infrastructure and database hosting providers (data is stored in secure, access-controlled environments).
  • Email delivery services used to send transactional and notification emails.
  • Payment processors (for subscription billing where applicable — card data is handled entirely by the payment processor and never stored on our servers).
  • Content delivery networks and file storage providers used to serve media and uploaded content.

Service providers are contractually bound to process data only as instructed by FIT Africa and to maintain appropriate security standards.

Enterprise Relationships

If you are a client assigned to a coach through an enterprise programme, relevant profile information and progress data may be visible to the enterprise administrator responsible for that programme.

Legal Requirements

We may disclose personal information if required to do so by law, court order, or regulatory authority, or where we reasonably believe disclosure is necessary to protect our rights, your safety, or the safety of others.

Business Transfers

If FIT Africa is involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction. We will notify affected users in such an event.

6. Data Storage and Security

Personal data is stored on secure servers with appropriate technical and organisational safeguards, including:

  • Encrypted data storage and encrypted connections (HTTPS/TLS) across all Platform endpoints.
  • Access controls and role-based permissions limiting data access to authorised personnel and users only.
  • Hashed password storage — your password is never stored in plain text.
  • Regular security reviews and monitoring of infrastructure for vulnerabilities.
  • Session tokens with expiry to limit exposure from inactive or compromised sessions.

No method of transmission or storage is 100% secure. If you believe your account has been compromised, please contact us immediately at privacy@fitafrica.tech.

7. Data Retention

We retain your personal data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations and resolve disputes.

  • Active account data is retained for as long as the account remains open.
  • Following account deletion, personal data is purged from our systems within 30 days, except where retention is required by law.
  • Backup data may persist for up to 90 days after deletion before being fully removed from backup systems.
  • Anonymised or aggregated data that cannot identify an individual may be retained indefinitely for analytical purposes.

8. Cookies

The Platform uses cookies and similar technologies primarily for authentication and session management. Specifically:

  • Session cookies that authenticate your login and keep you signed in during a session.
  • Preference cookies that remember settings such as your selected display theme.
  • The Platform does not currently use third-party advertising or tracking cookies.

Most browsers allow you to manage or disable cookies through their settings. Disabling authentication cookies will prevent you from logging in.

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Correction: request correction of inaccurate or incomplete data.
  • Deletion: request deletion of your personal data (see Section 10 below).
  • Portability: request your data in a structured, machine-readable format where technically feasible.
  • Objection: object to certain types of processing, including direct marketing.
  • Withdrawal of consent: where processing is based on consent, withdraw it at any time.

To exercise these rights, contact us at privacy@fitafrica.tech. We will respond within 30 days. We may need to verify your identity before fulfilling a request.

10. Account and Data Deletion

You can request deletion of your account and associated personal data at any time. For coach and client accounts, an in-app account deletion feature is available in your account settings. The process requires you to:

  • Confirm your identity by entering your registered email address.
  • Receive a verification code sent to that email address.
  • Enter the code to confirm the deletion request.

Account deletion is permanent and irreversible. All personal data, client records, programme content, and coaching history associated with your account will be removed. For a step-by-step guide, see our Data Deletion page.

If you are unable to access your account, you can submit a deletion request directly by emailing privacy@fitafrica.tech.

11. Children's Privacy

The Platform is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, please contact us at privacy@fitafrica.tech and we will take prompt action to remove it.

12. International Data Transfers

FIT Africa operates with infrastructure that may involve data being processed or stored in multiple countries. Where data is transferred internationally, we take appropriate measures to ensure the transfer is lawful and that the recipient provides an adequate level of data protection. If you have questions about where your data is stored or transferred, contact us at privacy@fitafrica.tech.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. When we make material changes, we will update the effective date shown at the top of this page and, where appropriate, notify users by email or via an in-app notice. Continued use of the Platform after changes are published constitutes acceptance of the revised policy.

14. Contact Us

For privacy-related questions, data requests, or concerns:

FIT Africa Technologies Ltd

Privacy & Data Team

Email: privacy@fitafrica.tech