Atletafit is not open yet. Today this site does one thing: it takes your name and your email so we can tell you when it is. This notice covers that, and nothing more, because there is nothing more. We do not sell your details, and we do not add you to anything you did not ask for.
Atletafit is a coaching platform being built in the United Kingdom. We decide what happens to the personal data collected through this site, which under UK GDPR makes us the controller of it.
We are not incorporated yet, so there is no company number to give you. When that changes, this notice changes with it and the effective date at the top of the page moves.
For anything in this notice, including a request to see or delete what we hold, write to hello@atletafit.com. It reaches a person, not a queue.
This notice covers atletafit.com and the waitlist. It does not cover the Atletafit platform, because the platform is not open. Section 11 sets out what changes when it is.
When you join the waitlist:
Automatically, when anyone visits:
What we do not collect. No health data, no training or nutrition records, no client information, no card details. None of it exists yet and none of it passes through this site. There are no analytics, advertising or tracking cookies here either, which is why you were not asked to accept any. Section 07 has the detail.
Four purposes, and the basis in law we rely on for each. Nothing is collected for a purpose that is not on this list.
Withdrawing consent takes one email and we will not ask you why. It does not affect anything we did while the consent was live.
Running a website means a handful of other companies touch some of this. We keep the list short, and each one only does the job in its row.
We have described them by what they do rather than by name. UK GDPR asks for the recipients or the categories of recipients, and while we are this small the category carries what actually matters to you: what they can see, and where they are. If you want the specific companies, ask at hello@atletafit.com and we will tell you.
None of them may use your details for their own purposes. They act on our instructions, under a written contract. We do not sell your data, we do not share it with advertisers, and we do not train machine learning models on it.
Our providers are based in, or store data in, the United Kingdom, the European Economic Area and the United States.
Where personal data leaves the UK, we rely on one of the following, in this order of preference:
If you are in Australia: this is the disclosure Australian Privacy Principles 1.4 and 8 ask for. The countries named above are where your details are likely to be handled.
When you ask to be removed, you are removed from our records. Backups roll over on their own schedule, so a copy can survive there briefly before it is overwritten. It is not used for anything in the meantime.
There is no cookie banner on this site because there is nothing to consent to. We run no analytics, no advertising, and no tracking of any kind.
What is stored on your device, and why:
You have the right to:
Exercising any of them is free and takes one email to hello@atletafit.com. We will acknowledge quickly and answer in full within one month.
You can also complain to the Information Commissioner’s Office, at ico.org.uk/make-a-complaint, on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would rather you came to us first, but you are not required to.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as California law uses those terms. You can ask what we hold and ask us to delete it, at the same address. We will not give you a worse experience for asking.
Under the Australian Privacy Principles you can ask for access to your personal information and ask us to correct it. If you are unhappy with how we handle that, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Everything moves over TLS. Access to the signup list is limited to the people who need it. The strongest protection here is how little there is: no card numbers, no health information, no client records, nothing that would matter much to anyone who took it.
If there were a breach that put you at risk, we would tell you, and we would tell the ICO within 72 hours where the law requires it. For Australian residents, the Notifiable Data Breaches scheme applies and we would notify the OAIC on the same basis.
Atletafit is a tool for working coaches. This site is not aimed at children and we do not knowingly collect anything from anyone under 18. If you think we have, tell us and it will be deleted.
Today we are the controller of a short list of names and email addresses. When the platform opens, the relationship changes: what your clients share belongs to them, you become the controller of it, and we become your processor, acting on your instructions.
That brings things this notice does not yet need:
All of it will be published before any client data reaches us, and we will email the list when it is.
The version and effective date sit at the top of this page. If we change something that affects you, we will email everyone on the waitlist rather than quietly reposting the page and hoping you re-read it.
hello@atletafit.com, for privacy requests and everything else. We are not large enough to be required to appoint a Data Protection Officer under Article 37, and we have not appointed one, so that address reaches the person who actually decides these things.
Complaints go to the ICO in the UK, or the OAIC in Australia. Both are linked in section 08.