Legal
Document Ref: DPRIV-DOC-01-1 · Version 1 · June 2024
Hi! We're CloudFit.
We create bespoke health journeys by blending cutting-edge AI with expert personal training insights to elevate your wellness, productivity and morale through plans that understand and adapt to your needs.
This is where we let you know how we use your data and protect your privacy. Our Privacy Notice is 'layered' so you can either read it in full or use the table below to jump to a specific section.
Contents
Section 1
If you visit our website, sign up to our waiting list, or are a user of the CloudFit app provided as a benefit by your employer, then this policy applies to you.
If you are interested in how your employer uses your data, you should check their Employee Privacy Notice (sometimes called a 'Privacy Policy') but we will let you know what data we get from them to provide you with the app and how we use it.
Section 2
If you use our CloudFit app, or provide us with information to contact you about our hyper-personalised bespoke health journeys, then we act as the 'data controller.'
We take our responsibility to protect the data in our custody seriously. A key part of that is providing you with transparent information that empowers you to make choices about your data and privacy.
We're as fed up as you about terms and conditions with thousands of words so have done our best to make this clear and concise whilst giving you all the information you need and required by law.
So, before we dive in, a key requirement:
You can contact us using this form if you have any questions.
Section 3
Section 4
We collect your data from your employer, from you and from third party applications. We group the different categories of personal data by type so that you can understand what data we collect.
| Type of Personal Data | Categories | Source |
|---|---|---|
| Basic Personal Details | Name, Date of Birth | You |
| Contact Information | Email Address | Your Employer |
| CloudFit Account Information | Username, Password | You |
| Consents & System Preferences | Records of your Consent, Contact & Notification Preferences | You |
| Physical Measurements | Height, Weight, Body Mass Index (BMI) | You |
| Lifestyle Information | Routine, Coaching Preferences | You |
| Fitness Information | Exercise Experience, Exercise Routine, Exercise Preferences | You |
| Health Information | Injury Information, Medical Diagnoses (e.g. COPD), Respiratory Performance, Doctor's Exercise Advice, Apple Health Data | You, Apple Health |
Section 5
We collect your personal data at different points on your journey with us. This starts by receiving your email address from your employer once you have confirmed to them you wish to use CloudFit. We use this to contact you to get you set up.
| When | We Collect | And Use It To |
|---|---|---|
| Your employer confirms your interest | Contact Information | Get in touch with you to join us |
| You complete onboarding forms | Basic Personal Details, Consents & System Preferences, Physical Measurements, Lifestyle Information, Fitness Information, Health Information | Get you onboarded to CloudFit; Enter into our contract with you through our terms and conditions |
| Your activity is updating Apple Health | Physical Measurements, Lifestyle Information, Fitness Information, Health Information | Understand your activity, health and fitness; Provide you with tailored adaptive wellness plans |
| You meet with our high-performance coaches | Basic Personal Details, Physical Measurements, Lifestyle Information, Fitness Information, Health Information | Understand your activity, health and fitness; Provide you with elite-level high-performance coaching advice and guidance; Provide you with tailored adaptive wellness plans |
| During your ongoing use of the CloudFit app | Contact Information, Basic Personal Details, Consents & System Preferences, Physical Measurements, Lifestyle Information, Fitness Information, Health Information | Keep your information up to date; Provide you with the CloudFit product and services; Assess and improve CloudFit product and services; Analyse your health data using our proprietary AI applications; Operate your account; Update you about our products and services; Comply with our legal obligations |
Section 6
We only process your personal data for specific purposes and when we have a lawful basis to do so, in line with data protection law.
Where it is necessary to use your personal data to enter into a contract with you at your request or to carry out our obligations under a contract with you.
Where you have given us your consent after reading this privacy notice and having been informed of the specific reasons that we will use your data for that require your consent.
Where it is necessary to use your personal data and we have a valid reason to do so that doesn't outweigh your rights and interests.
Where it is necessary for us to comply with a law or, where they have the force of law or are mandated by a regulator, official standards or guidelines.
If you have any concerns about how we use your data or want to understand more about our lawful bases, please get in touch with us by using this form.
Section 7
We use other organisations that are specialists and leaders in what they do. This means that we can focus on making CloudFit the best product it can be for you. When we do this, it may be necessary for these organisations to process your personal data on our behalf.
| Type | Examples | Purposes |
|---|---|---|
| Health Apps | Apple Health | Collecting health data to inform our analysis and recommendations |
| Cloud Storage / Processing | Amazon Web Services (AWS) | Storing your data used to provide you with insights |
| Large Language Model (LLM) Providers | OpenAI | Analysing your data to understand your health, fitness and preferences. Developing tailored adaptive health and wellness plans and recommendations based on your profile. |
| Productivity & Collaboration Tools | Microsoft 365 Office Suite | Operating our business and storing business documentation; Dealing with issues you raise |
| Communication Tools | MS Teams, Slack, Discord | Communicating internally to operate our business |
| Product Development Tools | Linear | Building the CloudFit app to continually expand and improve the products and services we provide you with |
When using third party organisations, we ensure:
Section 8
Where it is necessary to transfer personal data internationally, we opt in to the use of UK and Europe Data Storage regions so that your data is kept within GDPR-protected territories. Where necessary to transfer personal data further afield we apply other controls to protect your data.
These controls include signing contracts with organisations that facilitate these transfers and process personal data outside the UK and Europe and conducting impact assessments when doing so, if required.
For more information on how we protect your personal data when transferring it internationally, you can contact us using this form.
Section 9
We will retain your Personal Data for as long as you maintain an account or as otherwise necessary to provide you CloudFit products and services. We will also retain your Personal Data as necessary to comply with our legal obligations, resolve disputes, and enforce our terms and conditions, legal agreements and policies.
Where we no longer need to process your Personal Data for the purposes set out in this Privacy Policy, we will delete your Personal Data from our systems.
We will also retain usage data for internal analysis and performance purposes. Usage data is generally retained for a shorter period, except when this data is used to strengthen the security or to improve the functionality of CloudFit, or we are legally obligated to retain this data for longer time periods.
Section 10
Where we are processing your personal data based on your consent, you can contact us to withdraw your consent and we will dispose of your personal data. We will tell you where we are unable to continue providing you with CloudFit products or services when you make your request so you understand how this will affect your use of CloudFit.
We will also delete your Personal Data upon your direction to delete your account save where we are legally obligated to retain this data for longer.
Section 11
We take the security of your personal data seriously and are committed to protecting your personal information. To ensure this, we have implemented a variety of appropriate technical and organisational measures, including:
By implementing these technical and organisational measures, we aim to ensure the safety and confidentiality of your personal data. If you have any concerns about the security of your data, please contact us.
Section 12
You can make the following choices in relation to your personal data:
You can choose not to provide us with personal data.
You can update your cookie preferences.
You can choose whether we use your data for marketing.
Section 13
Under data protection law, you have rights. You don't usually need to pay a fee to exercise your rights. If you make a request, we have one calendar month to respond to you.
To exercise any of your rights, you can contact us using this form.
You have the right to receive transparent privacy information about how your personal data is processed so that you can make informed choices about your data and privacy.
You have the right to ask us for copies of your personal data.
You have the right to ask us to rectify personal data you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
You have the right to ask us to erase, restrict or object to the processing of your personal data in certain circumstances.
You have the right to ask that we transfer the personal data you gave us to another organisation, or to you, in certain circumstances.
When we use consent as our lawful basis you have the right to withdraw your consent.
Where your personal data is subject to "automated decision-making" that affects your legal rights or other similar rights, you have the right to have that reviewed by a member of our team.
We do not expect any automated processing at CloudFit to have such effects but we are always happy to review any requests you make relating to this right.
Section 14
You can make a complaint relating to your privacy.
If you have any concerns about our use of your personal data, you can make a complaint to us and contact our Data Protection Officer (DPO) by using this form.
If you remain unhappy with how we've used your data after filing a complaint with us, you can also complain to the Information Commissioner's Office (ICO).
The ICO can be contacted at: