Privacy Policy
Last updated: 15 July 2026
1. Introduction and scope
This Privacy Policy explains how LSTT Solutions Oy ('LostFit', 'we', 'us', 'our') collects and processes personal data when you:
- visit or interact with our websites, including lostfit.fi and any other domains we control (the 'Websites');
- purchase subscriptions or other products or services from us as a trainer or other business customer (the 'Trainer Services');
- use our web application as a trainer or other coaching professional (the 'Trainer App'); or
- use our mobile application as an end user or client of a trainer (the 'Client App').
Together, the Websites, Trainer Services, Trainer App and Client App are referred to as the 'Services'.
This Privacy Policy is intended to meet the requirements of the EU General Data Protection Regulation (GDPR) and applicable national data protection laws.
2. Data controller and contact details
Unless otherwise stated in this Privacy Policy, the data controller responsible for the processing of your personal data is:
LSTT Solutions Oy
Business ID (Y-tunnus): 3585888-3
Registered address: Samottikuja 3 C 244, 20250 Turku, Finland
Website: https://lostfit.fi
For privacy questions or to exercise your rights, you can contact us at:
Email: gdpr@lsttsolutions.fi
LSTT Solutions Oy has not appointed a statutory Data Protection Officer (DPO) under GDPR. We have assessed our processing activities against the criteria in GDPR Article 37(1)(c) — which requires a DPO when core activities involve large-scale processing of special categories of data — and have determined that our current scale of processing does not meet the mandatory threshold. We will review this assessment as the number of trainers and clients on the platform grows.
All data protection and privacy-related matters are handled via the contact details above.
We may update this contact information from time to time on our Websites.
3. Roles: controller, processor and trainers
Our role under data protection law depends on the context of the processing:
- For Website visitors, newsletter subscribers, and prospective customers, we act as an independent data controller.
- For trainers and other paying customers using the Trainer Services and Trainer App, we act as a data controller for their account, billing and usage data.
- For end users and clients whose data is entered into the Trainer App or Client App by a trainer or by the client themselves (for example, workouts, body measurements, and nutrition information), the trainer is generally the data controller and LostFit acts as a data processor, processing personal data on behalf of the trainer.
When we act as a processor for trainers, our processing is governed by a data processing agreement that forms part of our contract with the trainer. Trainers are responsible for providing their own privacy information to their clients and for choosing the appropriate legal basis under GDPR for their processing of client data.
In some situations we may also act as an independent controller, for example where we process limited personal data to protect our own systems, comply with legal obligations, or improve the security and quality of the Services.
When LostFit acts as a data processor for trainers, the processing is governed by a data processing agreement in accordance with GDPR Article 28. The data processing agreement forms part of the contractual terms with trainers and includes provisions on:
- Security measures and confidentiality obligations;
- Sub-processor engagement and approval;
- Assistance with data subject rights requests;
- Data breach notification procedures;
- Audit rights and compliance verification;
- Data deletion or return upon termination.
The data processing agreement is available upon request to existing and prospective trainer customers.
4. Categories of personal data we process
The exact data we process depends on which parts of the Services you use.
4.1 Website visitors and marketing contacts
When you visit our Websites or interact with our marketing materials, we may process:
- Basic identifiers and contact details: name, email address, phone number, company name, role, and your communication with us (for example when you fill out a contact form or subscribe to a newsletter);
- Technical and usage data: IP address, device and browser type, operating system, language settings, referring URLs, pages viewed, time and date of visits, and similar diagnostic and usage information;
- Cookie and tracking data: data collected via cookies or similar technologies used for essential functions and, on our marketing website (lostfit.fi), analytics to understand how visitors interact with our site; and
- Marketing preferences: your choices regarding receiving marketing communications from us.
4.2 Trainers and other business customers
If you register for and use the Trainer Services and Trainer App as a trainer or other business customer, we may process:
- Account data: name, email address, phone number, login credentials, language, time zone, and role within your organisation;
- Business information: company name, business ID, billing address, VAT number, subscription plan, payment status, and contract details;
- Payment and billing data: details necessary to process payments and manage invoices (for example, transaction identifiers, payment method type, partial card details or IBAN as provided by our payment service provider). Full payment data is processed by our payment service provider and not stored by us in plain form;
- Usage data: login times, device information, features used, actions taken in the Trainer App (for example, program creation, client management, messaging);
- Support data: information you provide when you contact us for support, such as logs, screenshots, or descriptions of issues;
- Marketing preferences and communication history.
- Technical security and access data: when you log in to the Trainer App, we collect device type, device manufacturer and model, operating system name and version, app version and build number, device memory, login timestamp, local IP address of your device, and your public IP address. This data is used for security monitoring, fraud prevention, and troubleshooting.
4.3 End users and clients (Client App and client profiles)
When end users and clients use the Client App or when trainers record information about their clients, we may process, on behalf of trainers and sometimes as controller for limited purposes:
- Basic profile data: name, email address, phone number, login credentials, preferred language, time zone;
- Demographic data provided by the trainer or client (for example, age range or date of birth as required by the trainer);
- Training and activity data: training programs, exercises, sets and repetitions, training logs, completion status, goals and progress information, and communication between trainer and client within the Services;
- Body composition and measurement data: weight, body fat percentage, body measurements, photos, and other physical data the trainer or client chooses to record;
- Nutrition and lifestyle data (where enabled): meal logs, calorie and macronutrient targets, dietary preferences or restrictions, allergies, and similar data; and
- Technical and usage data relating to the use of the Client App (as described above for Website visitors).
- Technical security and access data: when you log in to the Client App, we collect device type, device manufacturer and model, operating system name and version, app version and build number, device memory, login timestamp, local IP address of your device, and your public IP address. This data is used for security monitoring, fraud prevention, and troubleshooting. It is not shared with your Trainer.
Some of this information (for example, certain body measurements, weight tracking, injury notes, and dietary restrictions or allergies) may qualify as special categories of personal data under GDPR, such as health data. Section 6 below explains how we handle such data.
We do not require trainers or clients to upload special categories of data. Any such data is provided voluntarily and only to the extent necessary to deliver the requested training services.
5. Purposes and legal bases for processing
We process personal data only when we have a valid legal basis under GDPR. The main purposes and legal bases are:
5.1 Provision of the Services and contract performance
We process personal data to:
- create and manage user accounts for trainers and clients;
- provide, operate and maintain the Trainer App and Client App;
- provide customer support and respond to requests;
- process payments, manage subscriptions and billing;
- communicate service-related information, such as changes to functionality, security notices or important service updates.
Legal bases:
- performance of a contract (GDPR Article 6(1)(b)) where we have a direct contractual relationship with you, such as trainers using our Services; and
- where end users and clients access the Client App, processing that is necessary to provide and secure the technical operation of the Services, based on our legitimate interests (GDPR Article 6(1)(f)), while the trainer remains responsible for determining the lawful basis for the processing of client data as controller.
5.2 Acting as data processor for trainers
When we process client data on behalf of trainers, we do so:
- to provide the platform and features that trainers use to deliver services to their own clients;
- to store, display and process training, body measurement and nutrition data entered by trainers or clients; and
- to provide related support, security and maintenance.
When acting as a processor, LostFit does not hold an independent legal basis under GDPR Article 6 for client personal data — the lawful basis is held by the trainer as data controller. Processing is carried out under documented instructions from the trainer pursuant to GDPR Article 28 and the Data Processing Agreement that forms part of the Trainer Terms of Service. Trainers are responsible for identifying the lawful basis under Article 6 for their own processing of client data, and for obtaining any necessary consents — including explicit consent under Article 9(2) for health data.
5.3 Analytics, service improvement and security
We may process personal data to:
- monitor and analyse usage of the Services to understand how the Services are used and to improve usability and performance;
- maintain the security and stability of our infrastructure, including logging, monitoring, troubleshooting, and preventing misuse or fraud;
- generate anonymised or aggregated statistics for business intelligence, provided that individuals cannot be identified from such data.
Legal basis:
- our legitimate interests (GDPR article 6(1)(f)) in improving and securing the Services. Where we use non-essential cookies or similar technologies, we rely on your consent in accordance with applicable ePrivacy rules.
We have assessed that these legitimate interests outweigh data subjects' privacy interests because: processing is limited to pseudonymous or aggregated data; security monitoring is something users would reasonably expect; and data subjects retain the right to object.
5.4 Marketing communications
We may process personal data to:
- send trainers or prospective customers newsletters, product updates, event invitations or other marketing communications by email or other electronic means;
- measure and improve the effectiveness of our marketing campaigns.
Legal bases:
- your consent (GDPR article 6(1)(a)) where required by law, for example when you subscribe to a newsletter; and
- our legitimate interests (GDPR article 6(1)(f)) in promoting our Services to existing customers, where permitted by law (soft opt-in), provided you have not opted out.
We have assessed that these legitimate interests outweigh data subjects' interests because: we contact only existing business relationships; communications are relevant and infrequent; opt-out is easy and always honoured; and we do not contact people who have not had a prior relationship with us.
You can withdraw your consent or object to direct marketing at any time (see section 10 below). If you opt out, we will stop sending you marketing communications but may still send essential service messages.
5.5 Compliance with legal obligations and protection of rights
We may process personal data where necessary to:
- comply with legal obligations (for example, accounting, tax and consumer protection laws);
- respond to lawful requests from public authorities;
- establish, exercise or defend legal claims; and
- protect the rights, property or safety of LostFit, our users or others.
Legal bases:
- compliance with legal obligations (GDPR article 6(1)(c)); and
- our legitimate interests (GDPR article 6(1)(f)) in protecting our business and defending legal claims.
We have assessed that these legitimate interests outweigh data subjects' interests, as processing is strictly limited to specific circumstances involving active or threatened legal claims, regulatory investigations, or safety concerns.
5.6 AI Add-On features
If you or your Trainer use the AI Add-On, we process anonymised training and progress data to generate AI-assisted workout suggestions. No personally identifiable information is transmitted to any AI inference service — data is anonymised before submission.
Legal basis: performance of the AI Add-On contract (GDPR Article 6(1)(b)).
We will update this section with the name of the AI inference provider before the AI Add-On is made available to users.
5.7 AI model improvement (trainer content)
If you are a Trainer, we may use non-personal elements of your Content — such as workout programme structures and exercise templates — in anonymised or aggregated form to train and improve LostFit's AI features, in accordance with Section 6.6 of the Trainer Terms of Service. You may opt out at any time by contacting us at the address in section 2.
Legal basis: performance of contract (GDPR Article 6(1)(b)) as disclosed in the Trainer Terms of Service; or our legitimate interests (GDPR Article 6(1)(f)) where the opt-out mechanism applies.
6. Special categories of personal data (health and similar data)
Certain data that may be processed through the Services, such as body measurements, weight tracking, information about injuries, dietary restrictions or allergies, may constitute special categories of personal data under GDPR, in particular health data.
We do not require you to provide such data. To the extent that such data is processed through the Services:
- for trainers and their clients, the primary responsibility for determining the lawful basis for processing health data lies with the trainer as controller;
- where LostFit processes such data on behalf of trainers, we do so as a data processor in accordance with our data processing agreement; and
- where LostFit processes such data as a controller (for example, if we provide certain features directly to end users in the future), we will rely on your explicit consent (GDPR article 9(2)(a)) or another applicable exception under article 9.
Trainers should ensure that they obtain explicit consent from their clients for the processing of any health data and that they clearly explain the purposes of processing and the retention periods.
Health and fitness data processed through LostFit is not sold to third parties. It is not used for advertising, insurance eligibility determination, credit scoring, employment assessment, or for any purpose beyond those stated in this policy. Trainers are bound by equivalent restrictions in the Data Processing Agreement.
You may withdraw your consent to the processing of special category data at any time via the relevant settings in the Services or by contacting us. If you withdraw consent, we may no longer be able to provide certain features that depend on that data.
7. Cookies and similar technologies
The LostFit Trainer App and Client App use only cookies and similar technologies that are strictly necessary for their operation and security, such as session management and authentication. These essential cookies do not require user consent under applicable ePrivacy legislation.
Our public marketing website (lostfit.fi) uses self-hosted analytics (Umami) to understand how visitors interact with the site. This analytics tool is configured without tracking cookies and does not store persistent identifiers in your browser. The Website also sets one strictly necessary functional cookie, described in our Cookie Policy, to remember your language preference.
We do not use cookies for advertising, cross-site tracking, or behavioural marketing.
If we introduce non-essential cookies in the future, we will provide clear information and obtain consent where required by law before placing such cookies.
8. Recipients of personal data
We only share personal data with third parties when necessary for the purposes described in this Privacy Policy, when required by law, or when you have given your consent.
8.0 Sub-processors
We use the following sub-processors (service providers) who may process personal data on our behalf. All sub-processors are bound by GDPR-compliant data processing agreements.
| Service provider | Purpose | Processing location |
|---|---|---|
| Supabase Inc. | Database, authentication, and file storage | EU (eu-north-1) |
| Stripe LLC / Stripe Payments Europe Ltd | Payment processing and subscription management | EU + US (EU-US DPF certified) |
| Resend Inc. | Transactional email delivery | EU (Ireland, eu-west-1) |
| Functional Software Inc. (Sentry) | Error monitoring and crash reporting | EU (Sentry EU region) |
| PostHog Inc. | Usage analytics for Trainer and Client Apps (when deployed) | EU Cloud |
| OneSignal Inc. | Push notification delivery | EU (Netherlands) + US (EU-US DPF certified) |
Our marketing website uses Umami Analytics, which is self-hosted on our own infrastructure and does not involve a third-party sub-processor relationship.
We will update this list when we add, change, or remove sub-processors. Trainers who have a Data Processing Agreement with us are entitled to 30 days' advance notice before we add a new sub-processor.
In addition to the above, we may share personal data with:
- Professional advisers: such as lawyers, accountants, auditors or consultants, where necessary for the provision of their services to us;
- Public authorities: where required by law or to protect our legal rights.
We do not sell personal data.
8.1 Payments and financial data
We use Stripe to process and manage payments. When you make a payment through our Services, we share your payment information with Stripe to process the transaction, comply with applicable law, and prevent fraud. For information on how Stripe processes personal data, see stripe.com/privacy.
8.2 Links to third-party websites
The Services may contain links to external websites operated by third parties, such as trainer websites, social media platforms, or partner services. We are not responsible for the privacy practices or content of these third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.
We do not sell personal data in the sense of data protection or consumer privacy laws.
9. International data transfers
LostFit stores and processes personal data within the European Union. Our database, authentication, file storage, email delivery, error monitoring, and analytics services are all hosted in the EU.
The only transfer of personal data outside the EU occurs in connection with Stripe, LLC, which processes payment data in the United States. Stripe, LLC is certified under the EU-US Data Privacy Framework (DPF), which the European Commission has recognised as providing adequate protection for personal data transferred from the EU to the United States (adequacy decision July 2023). Stripe's DPF certification is publicly verifiable at dataprivacyframework.gov.
If we add a sub-processor that processes data outside the EU, we will update this section and the sub-processor list in section 8.0, and will ensure that appropriate safeguards (such as Standard Contractual Clauses) are in place before any transfer occurs.
10. Retention of personal data
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy or as required by law. The full internal retention schedule is set out in our Retention Policy document. The periods below summarise the main categories.
Trainer data:
- Trainer account and profile data: retained for the duration of the subscription and for 3 years after account closure, to cover the limitation period for potential contractual claims.
- Trainer billing and invoice records: retained for 6 years from the end of the fiscal year in which the last relevant transaction occurred, as required by applicable accounting legislation.
- Trainer-created content (workout programs, exercise templates, nutrition plan templates): retained until account closure. Following account closure, trainers have 30 days to export their content. We permanently delete trainer-created content 30 days after account closure.
- Trainer support and communications: retained for 3 years from the date the ticket or conversation is closed.
- Login and security logs: anonymised (actor identity and IP address removed) 90 days after creation; the anonymised record is then retained for security-monitoring purposes.
Client and end-user data:
- Client profile data (name, contact details, goals): retained while the coaching relationship is active and for 3 years after the last active date, unless the trainer instructs earlier deletion.
- Client health and body measurement data (measurements, body composition, fitness scores, workout logs, nutrition logs, questionnaire responses relating to health): retained while the coaching relationship is active. We permanently delete this data 30 days after the coaching relationship ends (last active date or trainer account closure, whichever is earlier). This is special category data under GDPR and we apply the strictest retention standard.
- Client progress photos and body images: retained while the coaching relationship is active. We permanently delete progress photos 30 days after the coaching relationship ends.
- Chat and messaging data: retained while the coaching relationship is active and for 1 year after the last active date, then deleted.
- Login and security logs: anonymised (actor identity and IP address removed) 90 days after creation; the anonymised record is then retained for security-monitoring purposes.
The coaching relationship is considered active while the trainer's account is in an active state and the client has not been permanently archived or deleted by the trainer. "Last active date" means the most recent login or data interaction by either the coach or the client.
Marketing data:
- Contact details used for marketing are retained until you withdraw your consent or object to marketing, or for 2 years of inactivity, whichever is earlier. We retain only a minimal record of your preference after that to prevent re-contact.
Consent records:
We retain records of consents you have given (for example, consent to health data processing or to specific features) for 3 years after the consent period ends, so that we can demonstrate that processing was lawful.
Where no specific retention period is stated, we determine the appropriate period by considering the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it and whether we can achieve those purposes in other ways, and applicable legal requirements.
When personal data is no longer required, we will either delete it securely or irreversibly anonymise it so that it can no longer be associated with an identifiable individual.
11. Your rights under GDPR
Subject to applicable law and certain limitations, you have the following rights in relation to your personal data:
- Right of access: to obtain confirmation as to whether we process personal data about you and, if so, to receive a copy of that data and information about the processing.
- Right to rectification: to have inaccurate or incomplete personal data corrected.
- Right to erasure ('right to be forgotten'): to request deletion of your personal data in certain circumstances, for example where it is no longer necessary for the purposes for which it was collected or where you have withdrawn consent and there is no other legal basis for processing.
- Right to restriction of processing: to request that we restrict processing of your personal data in certain circumstances.
- Right to data portability: to receive personal data that you have provided to us in a structured, commonly used and machine-readable format and to transmit that data to another controller, where processing is based on consent or contract and carried out by automated means.
- Right to object: to object to processing based on our legitimate interests, including profiling, on grounds relating to your particular situation. You also have the right to object at any time to the processing of your personal data for direct marketing purposes.
- Right to withdraw consent: where processing is based on your consent, you may withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
You can exercise your rights by contacting us using the contact details in section 2. We may need to verify your identity before acting on your request and may be unable to fulfil a request where we are legally required to retain data or where other exemptions apply.
If you are an end user or client whose data is processed by a trainer via the Services, you should usually direct your request first to your trainer, who is the controller of your data. We will assist trainers in fulfilling such requests where required by our contract and by law.
11.1 Automated processing
LostFit does not make solely automated decisions that produce legal effects or similarly significant effects for individuals within the meaning of GDPR Article 22.
The AI Add-On available to Trainers uses automated processing to generate workout plan suggestions. These suggestions are tools for Trainers — every plan is reviewed and delivered by the Trainer as part of their professional service. No AI-generated content is applied to a client's programme without the Trainer's review and decision. The outcome is therefore not a "solely automated" decision within the meaning of Article 22.
Analytics we generate about platform usage are aggregated or pseudonymous and do not produce individualised automated decisions about users.
11.2 Complaints to the supervisory authority
If you believe that our processing of your personal data violates data protection law, you have the right to lodge a complaint with your local supervisory authority. In Finland, the supervisory authority is:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
Website: tietosuoja.fi
Postal address: Tietosuojavaltuutetun toimisto, Ratapihantie 9, 6. krs, FI-00520 Helsinki
Email: tietosuoja@om.fi
We encourage you to contact us first so that we can try to resolve your concerns.
12. Security of processing
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include, as appropriate:
- restricting access to personal data to authorised personnel and service providers who need it to perform their tasks and are bound by confidentiality obligations;
- using secure server environments, encryption in transit and at rest where appropriate, and access controls for our systems;
- maintaining backup and recovery procedures and monitoring for unusual activity;
- regularly reviewing our security practices and updating them in light of technological developments and risk assessments.
However, no method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect personal data, we cannot guarantee absolute security.
In the event of a personal data breach, LostFit will assess the risk to affected individuals and, where required by GDPR Articles 33 and 34, notify the relevant supervisory authority and affected users without undue delay.
13. Children and age restrictions
Our Services are not directed to children under 16 years of age. We do not knowingly collect personal data from children under 16.
If you are under 16, you may not create an account or use the Services. Trainers may work with clients between 16 and 18 years of age; in such cases, the Trainer is responsible for ensuring that the client's parent or legal guardian has been informed and has consented before the account is created and personal data is processed.
Trainers who provide services to clients under 18 years of age are responsible for:
- obtaining parental or guardian consent where required before processing personal data of minors;
- ensuring compliance with applicable laws regarding the processing of minors' data;
- providing appropriate privacy information to parents or guardians.
If we become aware that we have collected personal data from a child under 16 without appropriate consent or legal basis, we will take steps to delete such data as soon as reasonably practicable. If you believe that we may have collected personal data from or about a child without proper authorisation, please contact us immediately using the details in section 2.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example to reflect changes in our Services, in our processing activities, or in applicable law. We will publish the updated version on our Websites and indicate the date of the latest revision at the top of the document.
If we make material changes, we may also notify you by email or through the Services. Your continued use of the Services after the effective date of the updated Privacy Policy will constitute your acknowledgement of the changes.
15. How to contact us
If you have any questions, concerns or requests relating to this Privacy Policy or to our processing of your personal data, please contact us at:
LSTT Solutions Oy
Email: gdpr@lsttsolutions.fi
Postal address: Samottikuja 3 C 244, 20250 Turku, Finland
Please include sufficient information for us to identify you and understand your request, and we will respond as required by applicable law.