FitGang od sedaj naprej uporabljate z mobilno aplikacijo (SMS-i ne delujejo več).

Privacy policy


Based on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR), and the Personal Data Protection Act (Official Gazette of the Republic of Slovenia, No. 163/22; hereinafter: ZVOP-2), the Director of FGANG d.o.o. adopts the following:

PRIVACY POLICY AND PERSONAL DATA PROTECTION RULEBOOK

 

Article 1 (Content and Purpose of the Rulebook)

(1) This rulebook defines the rules for the processing of personal data and the organizational, technical, and logical-technical procedures and measures for protecting personal data within FGANG d.o.o. The purpose of this rulebook is to ensure lawful processing of personal data and prevent unauthorized destruction, modification, loss, or processing of data.

(2) Employees and external collaborators who process and use personal data in the course of their work must be familiar with personal data protection legislation, sector-specific regulations, and the content of this rulebook.

Article 2 (General Provisions)

(1) The controller of personal data is FGANG d.o.o., Celovška cesta 291, 1000 Ljubljana, company registration number: 6649254000.

(2) The terms used in this rulebook have the same meaning as in the General Data Protection Regulation.

Article 3 (Personal Data)

(1) Personal data means any information relating to an identified or identifiable natural person or user, regardless of the form in which it is recorded.

(2) The controller processes and stores personal data of users of the FitGang mobile application that are necessary for providing services, security, and system management.

(3) The following categories of personal data are processed:

a) Identification data:

-        first name,

-        last name,

-        geographical region of residence,

-        date of birth,

-        telephone number,

-        e-mail address – identification data for coupon usage,

-        FitGang ID / unique 6-digit code (unique_code) – central identifier for registration and usage,

-        profile photo (optional, stored on the server/S3).

b) Company and usage rights data:

-        company name,

-        usage rights,

-        record of changes,

-        account deactivation (is_active), cancellation of registration, possible account deletion request upon user demand.

c) Access and security data:

-        application login data,

-        active tokens,

-        devices for push notifications (user_devices: token, platform, user agent), e.g.: login data, session/access tokens, and registered devices.

-        activities within the application – reservations, credit usage, provider visits, integrations, push notifications,

-        user consents.

d) Administration and notification data:

-        transactional notifications (reservation, payment, credit balance) – usually without special consent,

-        marketing notifications/newsletters — require consent upon registration.

e) Data obtained through the use of our services
We collect information about the services you use and how you use them. This includes:

-        device data (platform, user agent, push token),

-        log data and search queries,

-        local storage (secure storage for login tokens).

f) Payment data

For transactions with credit or debit cards, we do not store card data ourselves. Such data is collected by our external payment service providers specializing in secure online card transaction processing: Stripe Checkout for card top-ups (additional purchases). Session IDs/payment statuses are stored, not card numbers. For companies: company invoices are kept separately from employee card payments.

Data collected during login into the FitGang user account is treated by the controller as personal data. The controller processes personal data on servers in different countries around the world, including outside the country of your residence, specifically: AWS (EU) for files/profile images, Hetzner Online GmbH (Germany) for database and server hosting, Stripe (USA) for card payments, Firebase/Google for push notifications.

Article 4 (Legal Basis)

(1) In accordance with Article 6 of the General Data Protection Regulation, the legal basis for the processing of personal data is the consent of the user of the FitGang mobile application. The user must consent to the processing of their personal data for the purposes specified in Article 1 of this rulebook. Furthermore, the processing of personal data is necessary for the provision of services used by employees of the company to which the data relates.

Article 5 (Purpose of Data Collection)

(1) The controller uses the collected data for:

-        providing, maintaining, and improving FitGang services,

-        developing new tools, products, and services,

-        informing users about upgrades, improvements, and changes to services,

-        providing customized content,

-        improving the security of services and users,

-        detecting and resolving errors,

-        conducting data and system analytics and research for service improvement.

(2) The data may be used across all services requiring a FitGang user account. When contacting the controller, the controller may keep records of communication to assist in resolving issues.

(3) Data collected through cookies and similar technologies is used to improve user experience and service quality.

(4) For the use of data for other purposes, the controller shall obtain prior consent.

Article 6 (Processing)

(1) Personal data may only be processed for specified and lawful purposes and may not be processed in a manner incompatible with those purposes.

(2) Processing means any operation or set of operations performed on personal data or sets of personal data, whether by automated means or not, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

Article 7 (Retention Period of Personal Data)

(1) Users’ personal data shall be processed and stored only for as long as necessary for the purposes of using the FitGang mobile application or for other purposes for which the data was collected.

(2) When the purpose of processing ceases, the data shall be routinely deleted or anonymized in accordance with legal regulations.

Article 8 (Disclosure of Personal Data)

(1) The controller discloses personal data to other natural or legal persons or public sector bodies only upon request, which must include:

-        information about the applicant submitting the request (for a natural person: full name and permanent or temporary residence address; for a sole proprietor, self-employed individual, or legal entity: the name or company name, address or registered office, and registration number), as well as the signature of the applicant or authorized person;

-        the legal basis for obtaining the requested personal data;

-        the purpose of the processing of personal data or the reasons demonstrating the necessity and appropriateness of the personal data for achieving the purpose of obtaining them;

-        the subject matter and reference number or other identification of the case in connection with which the personal data is required, including the indication of the authority or other entity handling the matter;

-        the categories of personal data to be disclosed;

-        the form and method of obtaining the requested personal data.

(2) Personal data shall be disclosed to public sector bodies free of charge.


(3) Unless otherwise provided by law, the controller shall provide the requested personal data no later than 15 days after receiving a complete request or shall notify the applicant in writing within this period of the reasons why the requested data will not be disclosed. The controller and request submitter may agree to extend the deadline mentioned in the previous sentence.

(4) If the controller fails to act in accordance with the previous paragraph, the request shall be deemed rejected.



Article 9 (Rights of the Individual)

(1) Individuals whose personal data is processed have the right to:

-        access to data,

-        rectification and deletion (“right to be forgotten”),

-        restriction of processing (except for data necessary for service provision),

-        objection,

-        data portability.

(2) These rights are exercised by request via e-mail to podpora@fitgang.io or by sending a request to the controller’s business address: FGANG d.o.o., Celovška cesta 291, 1000 Ljubljana.

Article 10 (Measures for the Protection of Personal Data)

(1) The controller implements measures to protect data against unauthorized access, modification, disclosure, or destruction.

Among other things:

-        SSL encryption is used,

-        data collection and storage practices are regularly reviewed,

-        access to personal data is restricted to employees, contractors, and agents who require it for their work.

The obligation to protect data also applies after the closure of the FitGang user account.

(2) Protection of premises, data carriers, hardware and software, and personal data is implemented through technical and organizational procedures and measures in accordance with this rulebook. These procedures and measures:

-        protect premises, equipment, and system software, protect application software used for the processing of personal data,

-        prevent unauthorized or unregistered access to premises, hardware, and software, as well as accidental or intentional unauthorized destruction, alteration, or loss of personal data,

-        prevent unauthorized access to, processing, use, and disclosure of personal data, including transmission via telecommunications means and other forms of personal data processing,

-        enable the secure storage and transfer of personal data,

-        enable the determination of when specific personal data was entered into a personal data filing system, used, or otherwise processed, and by whom,

-        enable the determination of to whom, when, on what legal basis, and for what purpose specific personal data was disclosed.



Article 11 (Protection of Premises, Data Carriers, Hardware and Software)

(1) Premises where FGANG d.o.o. operates and where data carriers containing personal data, hardware, and software are located must be protected with organizational and technical measures preventing unauthorized access.

(2) Access to protected premises is permitted only during company working hours and outside these hours only with authorization from the responsible person.

(3) After work is completed, cabinets and desks containing personal data carriers must be locked. Computers and other hardware must be switched off and protected with appropriate physical or software locks. Keys are kept in a location determined by the person responsible. Keeping keys in locks is not permitted.

(4) Cabinets, desks, and other furniture containing personal data carriers outside protected premises must also be locked.

(5) Persons not employed by the company may enter protected premises only with the knowledge of the person responsible.

Article 12 (Deletion of Data)

(1) Documents kept in paper form containing personal data shall be destroyed in a manner preventing the reading of destroyed data. Auxiliary materials (e.g. templates, calculations and charts, sketches, draft or failed printouts, etc.) shall also be destroyed in the same manner.

(2) Electronic data carriers (optical media, hard drives, USB drives, magnetic tapes, floppy disks, etc.) containing personal data  shall be destroyed in a manner preventing partial or complete restoration of deleted personal data.

(3) Disposal of documents and electronic data carriers in waste bins is prohibited; they must be transferred to a secure destruction location.


Article 13 (Notification)

(1) Users of the FitGang mobile application must immediately notify the responsible person of unauthorized destruction, misuse, or damage to personal data.

(2) If the person responsible determines a personal data breach likely to endanger the rights and freedoms of individuals, the Information Commissioner of the Republic of Slovenia must be notified.

Article 14 (Responsibility for the Implementation of Procedures and Measures)

(1) Anyone processing personal data obtained or accessed in the course of their work must implement the procedures and measures set out in this rulebook and protect the data even after termination of employment or contractual relationship.

Article 15 (Responsible Person)

(1) The person responsible for implementing the procedures and measures for protecting personal data determined by this rulebook is the Director of FGANG d.o.o.

Article 16 (Entry into Force)

(1) This rulebook enters into force on the date of adoption.

Date of adoption: 1 June 2026