BodyFit’s Data Governance framework defines how we collect, store, use, and protect user data — ensuring accuracy, privacy, and lawful processing.
We collect only the data needed to provide our service: profile information, health screening, workout and nutrition logs, device data, and activity history. We do not collect data we do not use. Our Privacy Policy details exactly what we collect and why.
Accurate data drives accurate coaching. We provide tools for users to review and correct their data. Our data quality flags identify incomplete or inconsistent records. Connected device data is validated on sync. Users can report data errors via support tickets.
Data has a lifecycle: collection, use, retention, and deletion. Our Data Retention Policy defines how long different data types are kept. Users can request deletion at any time. Account deletion removes personal data within 30 days, with limited exceptions for legal or fraud-prevention purposes.
We process data on lawful bases under UK GDPR: consent, contract (providing the service), legitimate interests (fraud prevention, service improvement), and legal obligation. We document our processing activities and respect user rights. See our GDPR Rights page.
Privacy Governance
Privacy is foundational at BodyFit. Our Privacy Governance framework ensures user data is protected, user rights are respected, and privacy is built into everything we do.
Governance Overview
BodyFit’s governance framework defines how we make decisions, manage risk, and maintain the trust our users place in us. It spans AI, data, privacy, security, and ethics.
Data Retention
Compliance
BodyFit operates in compliance with applicable UK and international regulations governing data protection, AI, and digital health.