Legal

Privacy policy

Last updated: 12 August 2026

This policy explains what personal data the Living Fit Malta platform collects, why it is collected, and what you can do about it. It applies to the Living Fit Malta website and training app.

The controller of your personal data is DG Ventures AB, a company registered in Sweden (registration number 559423-6761), registered address Mälarvägen 28, 165 72 Hässelby, Sweden ("we", "us"). You can reach us about anything in this policy at privacy@livingfitmalta.com.

Health data in one paragraph

Health and wearable data is never required to use the platform. We only process it if you switch it on yourself, and only on the basis of your explicit consent. You can withdraw that consent, disconnect any wearable, and delete the data at any time from your profile. This data is used to shape training suggestions only — it is not a medical device, not a diagnosis, and not a substitute for professional healthcare advice.

1. What we collect

We collect only what the platform needs to function:

  • Account data — email address, display name, password credentials handled by our authentication provider (we never see your password), and the roles attached to your account.
  • Training data — exercises, sets, reps, tempo, rated effort (RPE), session notes, programme assignments and your training history.
  • Optional body-composition data — weight, body-fat estimates and circumference measurements that you choose to enter.
  • Optional health and wearable data — for example heart-rate variability, resting heart rate, sleep duration and sleep stages, activity and readiness metrics imported from a wearable account you connect yourself.
  • Coaching and business records — if you train with a coach through the platform, your bookings, attendance, session packages and related notes.
  • Technical data — log, security and diagnostic data such as timestamps, error reports and coarse device information, used to keep the service working and secure.

We do not knowingly collect data from anyone under 16. If you believe a child has an account, contact us and we will delete it.

2. Why we use it, and our legal basis

  • To provide the platform (accounts, logging sessions, generating workouts, showing progress) — performance of our contract with you (GDPR Art. 6(1)(b)).
  • To process health, sleep, recovery and wearable data — your explicit consent (GDPR Art. 9(2)(a), together with Art. 6(1)(a)). If you do not consent, the platform still works; it simply uses your training history and self-reported inputs instead.
  • To keep the service secure and prevent abuse — our legitimate interests (GDPR Art. 6(1)(f)).
  • To answer enquiries you send us — our legitimate interests or steps taken at your request before entering a contract.
  • To meet legal and accounting obligations — compliance with a legal obligation (GDPR Art. 6(1)(c)).

We do not sell your personal data, we do not use it for advertising or profiling that produces legal effects for you, and we do not use your health data for automated decision-making of that kind.

3. Wearables and connected accounts

Connecting a wearable (for example an Oura account) is entirely optional and always initiated by you. When you connect one:

  • You authorise the provider directly; we receive only the metrics needed for readiness and recovery features.
  • Access tokens are stored encrypted on our backend and are not exposed to the browser or to other users.
  • You can disconnect at any time, which stops future syncing immediately.
  • Disconnecting can be combined with deletion of the imported data, on request or from your profile.
  • Your coach, if you have one, sees only the summary metrics you agree to share — never raw provider account access.

Oura. The wearable we currently support is the Oura Ring, provided by Oura Health Oy (Finland). If you connect it, we receive your sleep duration, sleep score, heart-rate variability, resting heart rate and basic account details. This is health data under Article 9 GDPR and is processed only on the basis of your explicit consent, given at Oura's own consent screen. Full detail — including how to disconnect and delete — is on our Oura integration page, and Oura's own handling is covered by Oura's privacy policy.

4. Who can see your data

  • You. Your training and health data belongs to your account and is protected by row-level access rules so other users cannot read it.
  • Your coach, if you have one. If you are linked to a coach on the platform, that coach can see your training records and the readiness summaries needed to programme your sessions.
  • Our processors. Infrastructure providers who host the database, authentication, storage and application servers on our behalf, under data-processing agreements and only on our instructions.
  • Authorities, where we are legally required to disclose data.

Where data is transferred outside the EU/EEA, we rely on adequacy decisions or the European Commission's standard contractual clauses.

5. How long we keep it

Account, training and measurement data is kept while your account is active. Health and wearable data is kept until you withdraw consent, disconnect the source or delete it, whichever comes first. After you delete your account we remove or irreversibly anonymise your personal data within 90 days, except where we must keep records longer for accounting, tax or legal-claims purposes. Backups age out on their own rolling schedule.

6. Your rights

Under the GDPR you can ask us to:

  • Give you access to the personal data we hold about you
  • Correct data that is wrong or incomplete
  • Delete your data (“right to be forgotten”)
  • Restrict or object to certain processing
  • Export your data in a portable, machine-readable format — the app also has a built-in export
  • Withdraw consent for health and wearable processing at any time, without affecting processing already carried out

Email privacy@livingfitmalta.com and we will respond within one month. If you are unhappy with how we handle it, you can complain to the Swedish Authority for Privacy Protection (IMY) or to the supervisory authority where you live — in Malta, the Information and Data Protection Commissioner (IDPC).

7. Security

We use encrypted connections, encrypted storage of provider credentials, per-user database access rules and role-restricted coach and admin functions. No online service can promise perfect security, but we design the platform so that a single compromised account cannot read other people's health data.

8. Cookies and local storage

We use strictly necessary cookies and browser storage to keep you signed in, remember your preferences, and allow the app to work offline. We do not use advertising cookies or third-party ad trackers.

9. Changes to this policy

We may update this policy as the platform changes. Material changes affecting health data will be notified in the app, and where the change requires it, we will ask for your consent again.

10. Contact

DG Ventures AB, Mälarvägen 28, 165 72 Hässelby, Sweden. Registration number 559423-6761. Privacy enquiries: privacy@livingfitmalta.com. See also our terms and conditions.