Privacy Notice

FitPuli Privacy Notice

For FitPuli, it is of utmost importance to protect the personal data of the visitors of the FitPuli websites and of the users of the FitPuli Services, and to guarantee their privacy rights. In this notice, we have summarized our personal data processing activities and the steps we have taken to ensure the protection of personal data. This privacy notice applies to data processing relating to the FitPuli Services and the websites of FitPuli (including www.FitPuli.hu; www.fitpuli.com; www.fitpuli.de and www.fitpuli.at) (together: the “FitPuli Site”).

This notice does not apply to any third-party applications or software integrated with the Services (“Third-Party Services”), or to the privacy practices of any other third-party products, services or businesses.

Unless defines otherwise, capitalized terms in this notice shall have the same meaning as in the Terms of Use.
1. What type of personal data do we process?
a) Data collected in relation to the Service
• Information necessary for registration: Name, email address, gender, data of birth, password and nickname.
• Activity data: Activity data generated in connection with the use of the FitPuli Services and by devices connected to the Services (smart watch or smart band), such as the number of steps taken, floors, active minutes, data relating to sleep, mood data.
• Health data: Health data provided in relation to the use of the Services and data generated by devices connected to the Services (smart watch or smart band), such as weight, height, waist measurement, blood pressure, blood sugar, pulse, quality of vision, quality of hearing, smoking habit, coffee- and alcohol consumption, medical history, medical history in the family, medication used on a regular basis, sensitivity to medication and other allergies.
• Information on whether you are entitled to use the FitPuli Services: If you use the FitPuli Services as a supplementary service to the Private MedNext corporate health insurance product of UNION Vienna Insurance Group Zrt. (“Union”), Union will share certain data with FitPuli in order to enable your registration to the Services. Such data include your corporate email address and the time period during which you are entitled to use the FitPuli Services. We use this information to assist your registration so that you can use the FitPuli Services, if you decide to do so.
If FitPuli is in a contractual relationship with your employer directly and your registration is based on an invitation from your employer, the above data will be provided to FitPuli directly by your employer.
• Log data: As most websites and services, our servers automatically collect certain information regarding our users’ interactions with the FitPuli Site and Services. This information includes internet protocol (IP) addresses of the users’ device, as well as information about their browser, the page visited and the time of access.
b) Information collected on the FitPuli Site
• Cookie information: When you access websites and services, we use cookies and other information gathering technologies for a variety of purposes. These technologies may provide us with personal data, information about devices and networks you utilize to access our website, and other information regarding your interactions. For detailed information about the use of cookies, please read our Cookie Notice.
• Contact data: Information provided through the „Contact Us” form on the FitPuli Site.
2. What is the legal basis of our data processing?
We collect and process information about you only where we have legal bases for doing so under applicable laws. This means we collect and use your information only where:
• It is necessary in order to provide you the Services, including to set up and maintain an account for you, to provide customer support;
• It satisfies a legitimate interest (which is not overridden by your data protection interests), such as for research and development, and to protect our legal rights and interests;
• You give us consent to do so for a specific purpose;
• It is needed to comply with a legal obligation.
Health data

As a user, you may provide certain health information about yourself in the FitPuli app, such as information about your blood pressure, blood sugar, smoking habit, coffee- and alcohol consumption, medication used on a regular basis, or allergies. Before providing such data, FitPuli will ask for your explicit consent in accordance with article 9(2) of the GDPR. Until you do not consent to the processing, you will not be able to add such data. You may withdraw your consent anytime. If you decide not to provide any health data or you withdraw your consent, you may still use the Services, but certain functions will not be available. FitPuli can provide feedback on your health conditions and assess the relevant data only to the extent it possible based on the data provided.

If you so decide, you may add certain devices (smart watch or smart band) and share with the Services that data collected by such devices. You may change your settings regarding your devices anytime. You can learn more here.
3. Why do we process your data?

Purpose Legal basis
Services: In principle, we use personal data collected in relation to the FitPuli Services, i.e. for the provision and maintenance of the services, to establish a user account and to enable users to track the status of their health. ·        Provision of the services;

·        Explicit consent

Communication: We will send you information regarding the Services, such as administrative messages, to your email address provided to us. Please be aware that you cannot opt out of receiving certain service messages from us, including necessary security alerts and legal notices. ·        Provision of the services;

·        Consent

Handling errors and complaints: To handle customer and user complaints, we may use technical information that we may connect to registration data if needed. Provision of the services
Marketing: Upon your consent, we may use your email address to send you marketing communications. In order to understand how our online marketing and email campaigns perform, we collect and analyse information. ·        Legitimate interest;

·        Consent

Product development: We use analytics software to allow us to better understand the behaviour of our users to grow our business. This software records information, such as how often our Services are used, and the events that occur while using the Services. We use this aggregated information to identify usage patterns and trends. Legitimate interest
Protecting our legitimate business interests and legal rights: Where required by law or where we believe it is necessary to protect our legal rights, interests and the interests of others, we use information about you in connection with legal claims, compliance, regulatory, and audit functions, and disclosures in connection with the acquisition, merger or sale of our business. ·        Legitimate interest;

·        Compliance with laws

Other: We may also process your data for any other purposes for which we obtain your consent where necessary or otherwise in accordance applicable law and this policy.  
  1. How do you use your personal data while using the Services?

The goal of the Service is to enable Users to track the status of their health and to maintain and improve their health conditions. FitPuli can provide feedback on your health conditions and assess the relevant data only to the extent the relevant data provided makes it possible.

  1. Who is responsible for data processing?

The Services are provided FitPuli Kft. (registered seat: 9024 Győr, Katód utca 6. I/3., Hungary, registration number: Cg. 08-09-029303) (“FitPuli”). FitPuli acts as a controller when processing your data. Accordingly, FitPuli is responsible for compliance with applicable data protection laws.

In any case, certain activities of FitPuli are outsourced to third parties (processors), they may also use your personal data when acting on behalf of FitPuli. You can find more details about our processors under section 6.

If you use the FitPuli Services as a supplementary service to the Private Med Next corporate health insurance product of Union, then Union will process certain data about you to enable your registration with FitPuli and will share such data with FitPuli – as a data processor – as set out in section 1. In relation to such data, the ultimate decisions will be made by Union. Neither your employer, nor Union will have any access to the health data processed within the framework of the Services.

  1. Do we share data with third parties?

We never sell your personal data to third parties. However, in certain cases we need to share your personal data with others. In any case, we will share your personal data only in accordance with applicable laws and this notice, and in the following cases:

  • Legal compliance: We may transmit personal data if the applicable legal provisions so require, or when such action is necessary to comply with any laws, e.g. with criminal authorities if we are required to cooperate for such purposes. We may also need to share personal data for the protection of our rights and interests, to protect your safety or the safety of others or to investigate fraud, in accordance with the applicable laws.
  • Third-party service providers: In certain cases, we use third party data providers. For example, we may outsource billing and payment transactions to third parties, data hosting, sending emails, website development and hosting, as well as certain marketing activities. Our data processors always undertake to use the personal data shared only in relation to their services provided to FitPuli. Currently, we use the following providers in connection with the provision of our Services:
Service provider Seat Data location Service
FireBase (Google LLC) 1600 Mountain view, Amphiteathre Parkway, California, USA EU Data hosting, analytics
Sendgrid (Twilio Inc) 375 Beale Street Suite 300 San Francisco, CA 94105, USA US Sending automated emails
Gmail (Google LLC) 1600 Mountain view, Amphiteathre Parkway, California, USA US Sending emails
Lokalise Inc 3500 South DuPont Highway, Suite BZ-101, Dover, DE 19901, USA US Localisation and translation system
  • Mail address: 1530 Budapest, Pf. 5
    Telephone: +36-1-391-1400
    Fax: +36-1-391-1410
    Email: [email protected]
    Website: http://www.naih.hu

    A list of contact details for the EU data protection authorities is available here.

    10. Any further questions?
    If you have any further questions in relation to the processing of your data, please contact [email protected].

    We have also appointed a data protection officer, whom you can contact:
    Name: József Oláh
    Email: [email protected]
    Address: 9024 Győr, Katód utca 6. I/3., Hungary

    uthority (Nemzeti Adatvédelmi és Információbiztonság Hatóság in Hungarian):

Mail address: 1530 Budapest, Pf. 5
Telephone: +36-1-391-1400
Fax: +36-1-391-1410
Email: [email protected]
Website: http://www.naih.hu

A list of contact details for the EU data protection authorities is available here.

10. Any further questions?
If you have any further questions in relation to the processing of your data, please contact [email protected].

We have also appointed a data protection officer, whom you can contact:
Name: József Oláh
Email: [email protected]
Address: 9024 Győr, Katód utca 6. I/3., Hungary