WithU MOBILE APPLICATION AND WEBSITE PRIVACY POLICY

WITHU HOLDINGS LIMITED (we) are committed to protecting your personal data and respecting your privacy. We know that users of apps are becoming increasingly concerned about what happens to their data. We have invested a significant amount of time and money to ensure that the amount of personal data we collect and store is at a minimum.

INTRODUCTION

This policy (together with our end-user licence agreement as set out at https://withutraining.com/eula.html (EULA) and any additional terms of use incorporated by reference into the EULA, together, our Terms of Use) applies to your use of WITHU mobile application software (App) hosted on either the Google Play Store or the Apple app store (each an App Store), once you have downloaded or streamed a copy of the App onto your mobile telephone or handheld device (Device).

This policy also applies where you contact us either directly or through our Website or through links on other websites or social media.

This policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. This App is not intended for children under the age of 17. Please read the following carefully to understand our practices regarding your personal data and how we will treat it.

IMPORTANT INFORMATION AND WHO WE ARE

WITHU HOLDINGS LIMITED is the controller and is responsible for your personal data (collectively referred to as “Withu”, “we”, “us” or “our” in this policy).

We have appointed a data privacy manager. If you have any questions about this privacy policy, please contact them using the details set out below.

Contact details

Our full details are:

  • Full name of legal entity: WithU Holdings Limited
  • Email address: dpo@withutraining.com
  • Postal address: WITHU HOLDINGS LIMITED, The Carriage House, Mill Street, Maidstone, ME15 6YE
  • Website address: https://withutraining.com (Website)

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues or other competent supervisory authority of an EU member state if the App is downloaded outside the UK. For further information please visit https://ico.org.uk/make-a-complaint/.

Changes to the privacy policy and your duty to inform us of changes

We keep our privacy policy under regular review.

This version was last updated on 10 May 2024. It may change and if it does, the new version will be posted on this page and, where appropriate, notified to you when you next start the App and, if we choose, by email. The new policy may be displayed on-screen and you may be required to read and accept the new version to continue your use of the App.

It is important that any personal data we hold about you is accurate and current.  Please keep us informed if your personal data changes during our relationship with you.  The App may not function properly if some of the information you have provided us is wrong.

Third party links

Our Website may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. Please note that these websites and any services that may be accessible through them have their own privacy policies and that we do not accept any responsibility or liability for these policies or for any personal data that may be collected through these websites or services, such as Contact and Location Data. Please check these policies before you submit any personal data to these websites or use these services.

THE DATA WE COLLECT ABOUT YOU

When you download the App and agree to our Terms of Use, your mobile device is allocated a unique identification code (Unique Code), which is the basis on which we manage user accounts. All interactions by you (or any other user of the App on your Device) with the App are recorded by reference to the Unique Code. Depending on how you download the app and the type of device you are using, we may also have access to a unique code associated with your device, (IDFA, IDFV , AAID , IP & Android ID (collectively the “IDFA”)).

In order to use the App you will be required to create an account, to do this, you will be required to provide an email address (Login Data). We will be able to link your email address with the Unique Code, and therefore your account activity with you. This does mean that if you change your device, or access the App across multiple devices the use history and preferences would carry across the devices.  If you choose to login using an existing social media account we will obtain that information indirectly from the relevant operator.

We may require limited additional personal data about you if you access the app through a download link provided via a partner company or your employer (see below on Contact Data).

When you use our App we will primarily identify you through your WithU account, although there is likely to be personal information also associated with your account. We will collect and store all interactions with the App on your device (Usage Data). Your Device will also store Usage Data in a cache along with your preferences in order to make your user experience as effective as possible. We will also collect and store such Usage Data on our systems to analyse your use, and the functionality of the App. If the Unique Code is associated with any personal data all of the Usage Data will be personal data.

For users who gain access to the app through a partner- or employer-linked website or service (such as membership of a gym, or employee rewards programme), you may be asked to supply your name and email address (Contact Data) so we can send you the download link. Some partners or employers may provide this information automatically to us via a generated link in addition to a unique code that identifies you as a user on the partner or employer system. In such a case we will retain the Contact Data for as long as you remain on the partner or employer system or as long as you remain a WithU user. In this case, we will be able to associate your contact information with your Unique Code.

Alternatively, the partner or employer may provide you access to the App via a portal. In this case, you will be allocated a unique ID (the “Partner ID”) by WithU, which will be associated with your use of the App as well as your association with the partner or employer. You will still be required to create a login with an email address.

You may provide additional information such as demographic data (for example, your age and gender) and personal data (for example, your age, weight, fitness level, location) (Profile Data) when you use the App to make your experience with the App more effective.  You may also choose to provide additional data (Health Data) such as heart rate, by connecting third party peripheral devices (such as a heart rate monitor) to your device.  In all such cases, the App will provide you with more meaningful data and feedback, but it will operate perfectly well without such data.  It is a matter of personal choice if you wish to provide the additional information.

If you contact us via the App, on our Website, or directly by email, you may choose to provide us with contact details such as your name and email address (Communication Data) as well as those of other people, for example if you are purchasing the App as a gift. We cannot connect these details with your Unique Code unless you also provide us with the Unique Code. We will only use the details to communicate with you and with the recipient of the gift, as appropriate, and if necessary, to identify and fix problems associated with your use of the App.

We will also collect information to identify what type of Device you are using (Device Data). This will be linked to your Unique Code, and will enable us to optimise the operation of the App.

We may also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific App feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.

By using the App you consent to our anonymising your data, and using the anonymised data for our purposes.

HOW IS YOUR PERSONAL DATA COLLECTED?

We will collect and process the following data about you:

  • Information you give us directly. This is information you consent to giving us about you by corresponding with us (for example, by email or chat or using our helpdesk) or by filling in your contact details on a web-based form, so we can send you a link to the App. It includes information you provide when you share information on our social media pages and when you report a problem with the App.
  • Information provided by your employer or a partner company. This will be information that can be used to personally identify you such as your e-mail and/or a unique ID
  • Information you provide through the App. This is information you provide about yourself, including fitness level, and personal characteristics in order to make your use of the App more effective.
  • Health Data – Information you provide to us by linking a third party device to your use of the App, such as a heart rate monitor.
  • Device Data. Your Device has an electronic signature which will notify us of its characteristics. This may include a device specific advertising identifier (IDFA,IDFV,AAID,IP & Android ID)
  • Usage Data. We will collect, store and process all interactions that take place with the App on your Device, and on our servers, which may include both the data we collect through your use of the App, and also Health Data collected through a third party device linked to the App.
  • Survey and Feedback Data. You may choose to respond to surveys and feedback requests on the App. We will collect store and process any information you provide us.

HOW WE USE YOUR PERSONAL DATA

We will only use your personal data when the law allows us to do so. Most commonly we will use your personal data in the following circumstances:

  • Where you have consented before the processing.
  • Where we need to perform a contract we are about to enter or have entered with you.
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
  • Where we need to comply with a legal or regulatory obligation.

PURPOSES FOR WHICH YOUR DATA WILL BE USED

Purpose/activity Type of data Lawful basis for processing
To create an account with us via a login You will provide us with your name and an email address Your consent
To send you a link to download the App You may have to supply us with your name and email address on a web-based form. Your consent
To send you a link to download the App where your access to it is a benefit provided by your employer. Your employer may provide us with your name and work email address. Fulfilment of a contract with your employer.
To install the App, manage payments and register you as a new App user This process is managed by the operator of the App Store. We do not have any visibility of or access to any of your personal data processed in this way. If you subsequently use a login to access the App, we will be able to link your app, and any Usage Data with you using your Login Data. Your consent
To track your app installation source We may have access to your IDFA in addition to other data, which may allow us to attach certain attributes to your membership. Your consent
To track your use of the App and provide you with feedback about your usage. Profile Data

Usage Data

Health Data

To perform a contract we have with you;

Consent

Partner campaigns We may occasionally partner with brands and send you relevant offers. If you have a login or we otherwise have your email address, we will contact you via your email address. In certain circumstances, we may also send information to the device you have logged in to.If you do not have a login, we will send this information to your Device according to your Unique Code. Your consent
To manage our relationship with you including notifying you of changes to the App, new features, features that you may not have used or been aware of, usage data and statistics and changes to our Terms of Use If you have a login or we otherwise have your email address, we will contact you via your email address. In certain circumstances, we may also send information to the device you have logged in to.If you do not have a login, we will send this information to your Device according to your Unique Code. We will do this in order to be able to perform a contract with you  In some cases, it will be necessary for our legitimate interests (to keep records updated and to analyse how customers use our products/ Services)In other cases, it will be necessary to comply with legal obligations (to inform you of any changes to our terms and conditions)
To remind you when your subscription is coming to an end, or to prompt you to renew or upgrade your subscription, for example, if it has expired, or if you cease to be associated with the partner organisation or employer through which you originally obtained your subscription. If you have a login or we otherwise have your email address, we will contact you via your email address. In certain circumstances, we also may send information to the device you have logged in to.If you do not have a login, we will send this information to your Device according to your Unique Code. Our legitimate interests (to market goods and services similar to those already supplied to you)
To enable you to complete a survey If you have a login, we may contact you via your email address or your device.If you do not have a login, we will interact with your Device on the basis of your Unique Code. Your consent; 

Performance of a contract with you; 

Necessary for our legitimate interests (to analyse how customers use our products/Services and to develop them and grow our business)

To respond to enquiries and other communications you direct to us including through our Website Communication data Your consent
To identify, diagnose and fix any problems you may have with using the App In most cases we will be able to do this on the basis of your Unique Code. If you do provide us with additional information, or your Unique Code is associated with any Login Data or Contact Data we will process that information in addition To perform a contract with you (to remedy issues)Your consent (additional communications data)
To administer and protect our business and this App including troubleshooting, data analysis and system testing Normally we would not require any personal data to do this. Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security)
To provide partner businesses and employers and named third parties with access to data about their campaign/promotion and/or how users associated with them are using the App Anonymised Usage Data. Performance of a contract
To provide partner businesses or employers with information about your subscription to the App (where your subscription is derived from your relationship with such a partner business or employer) Contact Data To enable them to fulfil their legal obligations in relation to employment and tax;

Our legitimate interests (to ensure we can invoice them appropriately).

To provide partner businesses, employers and named third parties with information about your use of the App (where your subscription is derived from your relationship with such a partner business or employer). This may be for the purposes of ensuring you are appropriately rewarded for your use of the App, or for other purposes defined by the relevant recipient. Usage Data Consent – you will need to specifically consent to any such personal data being shared with a partner business or your employer or other relevant third party. If the partner business or employer or third party wishes to share such data with third parties, you will need to provide additional specific consent to that within the app.
To manage, and if relevant, to terminate your account, where your account is related to your employment or a partner organisation. Your work email address, or your Partner ID To fulfil a contract with your employer or a partner organisation.
To depersonalise any data, in order to continue to be able to use the data for our internal business purposes, and for marketing, and fundraising purposes. Usage Data, Profile Data, Health Data Consent, to the depersonalisation;

Legitimate interests, to continue to use such depersonalised data for analysing and refining our products and services, and for marketing and fundraising purposes.

COOKIES

We use cookies and/or other tracking technologies to distinguish you from other users of the App and to remember your preferences and your progress and past usage of the App. This helps us to provide you with a good experience when you use the App and also allows us to improve the App. Your Device will create a store of Usage Data, Profile Data and Social Profile Data as part of its core functionality.  

DISCLOSURES OF YOUR PERSONAL DATA

When you consent to providing us with your personal data, we will also ask you for your consent to share your personal data with the third parties set out below for the purposes set out in the list below:

  • Third parties to whom we have outsourced some aspects of the App and the associated services, such as the helpdesk, hosting of the App, warehousing of data and marketing activities. For details on our providers please contact us at dpo@withutraining.com
  • Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy policy;
  • Subject to your specific consent, the partner business or employer through which you have obtained your subscription to the App, for the purposes of: (a) where relevant, ensuring they are able to comply with their tax and regulatory obligations; (b) ensuring you are appropriately rewarded for your use of the App; and (c) such other purposes that will be clearly identified in the consent request.

After you place an order on our Website you will need to make payment for the goods or services you have ordered. In order to process your payment we use Stripe, a third party payment processor.

In most cases, the payment process will be managed by the relevant app store subscription service.  If you access the app through a portal, your payment will be processed by Stripe, who collect, use and process your information, including payment information, in accordance with their privacy policies. You can access their privacy policy via the following link: https://stripe.com/gb/privacy

Stripe’s services in Europe are provided by a Stripe affiliate—Stripe Payments Europe Limited (“Stripe Payments Europe”)—an entity located in Ireland. In providing Stripe Services, Stripe Payments Europe transfers personal data to Stripe, Inc. in the US.

For further information about the safeguards used when your information is transferred outside the European Economic Area, see International Transfers below.

WithU does not have any access to payment information, so we do not collect or store it.  

INTERNATIONAL TRANSFERS

Some of our external third parties are based outside the UK so their processing of your personal data will involve a transfer of data outside the UK.

Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  • We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see European Commission: Adequacy of the protection of personal data in non-EU countries.; or
  • Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see European Commission: Model contracts for the transfer of personal data to third countries; or
  • Where we use providers based in the US, we may transfer data to them if they are part of the Data Privacy Framework which requires them to provide similar protection to personal data shared between Europe and the US. For further details, see https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/eu-us-data-transfers_en.
  • Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.

DATA SECURITY

All information you provide to us is stored on our secure servers.

Once we have received your information, we will use strict procedures and security features to try to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way.

We will collect and store personal data on your Device using application data caches and other technology.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator when we are legally required to do so.

DATA RETENTION

If we do hold any of your personal data, including Login Data, we will retain your personal data for a period of up to 3 years after you have stopped using the App or the login, save in the case of Contact Data, which we will hold only for as long as you remain on the partner or employer system or as long as you remain a WithU user. The Usage Data that is not linked with any of your personal data (and is therefore anonymous) will remain on our systems, and we will continue to use it to develop our App and understand the use of it by subscribers. You agree that we have the right to depersonalise any data for these purposes.  In some circumstances you can ask us to delete your data: see Your legal rights below for further information.

In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

In the event that you do not use the App for a period of three years then we will treat the account as expired and your personal data may be deleted.

YOUR LEGAL RIGHTS

Under certain circumstances you have the following rights under data protection laws in relation to your personal data.

You can exercise any of these rights at any time by contacting us at dpo@withutraining.com

GLOSSARY

LAWFUL BASIS Consent means processing your personal data where you have signified your agreement by a statement or clear opt-in to processing for a specific purpose. Consent will only be valid if it is a freely given, specific, informed and unambiguous indication of what you want. You can withdraw your consent at any time by contacting us.

Legitimate Interest means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.

Performance of Contract means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.

Comply with a legal obligation means processing your personal data where it is necessary for compliance with a legal obligation that we are subject to.

YOUR LEGAL RIGHTS

You have the right to:

  • Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
  • Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
  • Object to the processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
  • Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:

(a) if you want us to establish the data’s accuracy;

(b) where our use of the data is unlawful but you do not want us to erase it;

(c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or

(d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

  • Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
  • Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

If you consider that our processing of your personal information infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. If you would like more information on these rights, please visit https://ico.org.uk/for-the-public/.