Tämä tietosuojaseloste on saatavilla vain englanniksi. Ristiriitatilanteessa englanninkielinen versio on ensisijainen. (This policy is available in English only. In the event of any conflict, the English version prevails.)
Privacy Policy
Last updated: 27 August 2026
Document version: 2026-08-27
1. Introduction and scope
This Privacy Policy explains how LSTT Solutions Oy ('LostFit', 'we', 'us', 'our') collects and processes personal data when you:
- visit or interact with our websites, including lostfit.fi and any other domains we control (the 'Websites');
- purchase subscriptions or other products or services from us as a trainer or other business customer (the 'Trainer Services');
- use our web application as a trainer or other coaching professional (the 'Trainer App'); or
- use our mobile application as an end user or client of a trainer (the 'Client App').
Together, the Websites, Trainer Services, Trainer App and Client App are referred to as the 'Services'.
This Privacy Policy is intended to meet the requirements of the EU General Data Protection Regulation (GDPR) and applicable national data protection laws.
2. Data controller and contact details
Unless otherwise stated in this Privacy Policy, the data controller responsible for the processing of your personal data is:
LSTT Solutions Oy Business ID (Y-tunnus): 3585888-3 Registered address: Takkulantie 320, 21270 Nousiainen, Finland Website: https://lostfit.fi
For privacy questions or to exercise your rights, you can contact us at:
Email: gdpr@lsttsolutions.fi
LSTT Solutions Oy has not appointed a statutory Data Protection Officer (DPO) under GDPR. We have assessed our processing activities against the criteria in GDPR Article 37(1)(c) — which requires a DPO when core activities involve large-scale processing of special categories of data — and have determined that our current scale of processing does not meet the mandatory threshold. We will review this assessment as the number of trainers and clients on the platform grows.
All data protection and privacy-related matters are handled via the contact details above.
We may update this contact information from time to time on our Websites.
3. Roles: controller, processor and trainers
Our role under data protection law depends on the context of the processing:
- For Website visitors, newsletter subscribers, and prospective customers, we act as an independent data controller.
- For trainers and other paying customers using the Trainer Services and Trainer App, we act as a data controller for their account, billing and usage data.
- For end users and clients whose data is entered into the Trainer App or Client App by a trainer or by the client themselves (for example, workouts, body measurements, and nutrition information), the trainer is generally the data controller and LostFit acts as a data processor, processing personal data on behalf of the trainer.
When we act as a processor for trainers, our processing is governed by a data processing agreement that forms part of our contract with the trainer. Trainers are responsible for providing their own privacy information to their clients and for choosing the appropriate legal basis under GDPR for their processing of client data.
In some situations we may also act as an independent controller, for example where we process limited personal data to protect our own systems, comply with legal obligations, or improve the security and quality of the Services.
When LostFit acts as a data processor for trainers, the processing is governed by a data processing agreement in accordance with GDPR Article 28. The data processing agreement forms part of the contractual terms with trainers and includes provisions on:
- Security measures and confidentiality obligations;
- Sub-processor engagement and approval;
- Assistance with data subject rights requests;
- Data breach notification procedures;
- Audit rights and compliance verification;
- Data deletion or return upon termination.
The data processing agreement forms part of the Trainer Terms of Service and is accepted by the trainer at onboarding; a copy is available to existing and prospective trainer customers on request.
4. Categories of personal data we process
The exact data we process depends on which parts of the Services you use.
4.1 Website visitors and marketing contacts
When you visit our Websites or interact with our marketing materials, we may process:
- Basic identifiers and contact details: name, email address, phone number, company name, role, and your communication with us (for example when you fill out a contact form or subscribe to a newsletter);
- Technical and usage data: IP address, device and browser type, operating system, language settings, referring URLs, pages viewed, time and date of visits, and similar diagnostic and usage information;
- Cookie and tracking data: data collected via cookies or similar technologies used for essential functions and, on our marketing website (lostfit.fi), analytics to understand how visitors interact with our site; and
- Marketing preferences: your choices regarding receiving marketing communications from us.
4.2 Trainers and other business customers
If you register for and use the Trainer Services and Trainer App as a trainer or other business customer, we may process:
- Account data: name, email address, phone number, login credentials, language, time zone, and role within your organisation;
- Business information: company name, business ID, billing address, VAT number, subscription plan, payment status, and contract details;
- Payment and billing data: details necessary to process payments and manage invoices (for example, transaction identifiers, payment method type, partial card details or IBAN as provided by our payment service provider). Full payment data is processed by our payment service provider and not stored by us in plain form;
- Usage data: login times, device information, features used, actions taken in the Trainer App (for example, program creation, client management, messaging);
- Support data: information you provide when you contact us for support, such as logs, screenshots, or descriptions of issues;
- Marketing preferences and communication history.
- Technical security and access data: when you log in to the Trainer App, we collect device type, device manufacturer and model, operating system name and version, app version and build number, device memory, login timestamp, local IP address of your device, your public IP address, and an approximate location (city, region, and country) derived from that IP address. This data is used for security monitoring, fraud prevention, and troubleshooting, and you can view your own login history (including failed login attempts) at any time in the app's account settings.
4.3 End users and clients (Client App and client profiles)
When end users and clients use the Client App or when trainers record information about their clients, we may process, on behalf of trainers and sometimes as controller for limited purposes:
- Basic profile data: name, email address, phone number, login credentials, preferred language, time zone;
- Demographic data provided by the trainer or client (for example, age range or date of birth as required by the trainer);
- Training and activity data: training programs, exercises, sets and repetitions, training logs, completion status, goals and progress information, and communication between trainer and client within the Services;
- Body composition and measurement data: weight, body fat percentage, body measurements, photos, and other physical data the trainer or client chooses to record;
- Nutrition and lifestyle data (where enabled): meal logs, calorie and macronutrient targets, dietary preferences or restrictions, allergies, and similar data; and
- Technical and usage data relating to the use of the Client App (as described above for Website visitors).
- Technical security and access data: when you log in to the Client App, we collect device type, device manufacturer and model, operating system name and version, app version and build number, device memory, login timestamp, local IP address of your device, your public IP address, and an approximate location (city, region, and country) derived from that IP address. This data is used for security monitoring, fraud prevention, and troubleshooting, and you can view your own login history (including failed login attempts) at any time in the app's account settings. It is not shared with your Trainer.
Some of this information (for example, certain body measurements, weight tracking, injury notes, and dietary restrictions or allergies) may qualify as special categories of personal data under GDPR, such as health data. Section 6 below explains how we handle such data.
We do not require trainers or clients to upload special categories of data. Any such data is provided voluntarily and only to the extent necessary to deliver the requested training services.
5. Purposes and legal bases for processing
We process personal data only when we have a valid legal basis under GDPR. The main purposes and legal bases are:
5.1 Provision of the Services and contract performance
We process personal data to:
- create and manage user accounts for trainers and clients;
- provide, operate and maintain the Trainer App and Client App;
- provide customer support and respond to requests;
- process payments, manage subscriptions and billing;
- communicate service-related information, such as changes to functionality, security notices or important service updates.
Legal bases:
- performance of a contract (GDPR Article 6(1)(b)) where we have a direct contractual relationship with you, such as trainers using our Services; and
- where end users and clients access the Client App, processing that is necessary to provide and secure the technical operation of the Services, based on our legitimate interests (GDPR Article 6(1)(f)), while the trainer remains responsible for determining the lawful basis for the processing of client data as controller.
5.2 Acting as data processor for trainers
When we process client data on behalf of trainers, we do so:
- to provide the platform and features that trainers use to deliver services to their own clients;
- to store, display and process training, body measurement and nutrition data entered by trainers or clients; and
- to provide related support, security and maintenance.
When acting as a processor, LostFit does not hold an independent legal basis under GDPR Article 6 for client personal data — the lawful basis is held by the trainer as data controller. Processing is carried out under documented instructions from the trainer pursuant to GDPR Article 28 and the Data Processing Agreement that forms part of the Trainer Terms of Service. Trainers are responsible for identifying the lawful basis under Article 6 for their own processing of client data, and for obtaining any necessary consents — including explicit consent under Article 9(2) for health data.
5.3 Analytics, service improvement and security
We may process personal data to:
- monitor and analyse usage of the Services to understand how the Services are used and to improve usability and performance;
- maintain the security and stability of our infrastructure, including logging, monitoring, troubleshooting, and preventing misuse or fraud;
- generate anonymised or aggregated statistics for business intelligence, research, benchmarking, and industry reporting, and publish or commercially use the resulting insights, provided that individuals cannot be identified from such data and no trainer, organisation, or client is identified as the source without their consent (Trainer Terms of Service Section 6.5).
Legal basis:
- our legitimate interests (GDPR article 6(1)(f)) in improving and securing the Services; and
- your consent (GDPR article 6(1)(a)) for analytics that involve storing information on, or reading information from, your device. We do not rely on legitimate interest for that step, and analytics do not run until you have consented.
We have assessed that these legitimate interests outweigh data subjects' privacy interests because: processing is limited to pseudonymous or aggregated data; security monitoring is something users would reasonably expect; and data subjects retain the right to object.
5.4 Marketing communications
We may process personal data to:
- send trainers or prospective customers newsletters, product updates, event invitations or other marketing communications by email or other electronic means;
- measure and improve the effectiveness of our marketing campaigns; and
- identify a trainer or their organisation as a LostFit customer, and use their trading name and logo for that purpose, in our marketing materials, on our website, and in customer lists (Trainer Terms of Service Section 6.8). Where a trainer operates as a sole trader under their own name, that name is personal data; the trainer may opt out of this use at any time by contacting us at the address in section 2, and we will stop it within 30 days.
Legal bases:
- your consent (GDPR article 6(1)(a)) where required by law, for example when you subscribe to a newsletter; and
- our legitimate interests (GDPR article 6(1)(f)) in promoting our Services to existing customers, where permitted by law (soft opt-in), provided you have not opted out.
We have assessed that these legitimate interests outweigh data subjects' interests because: we contact only existing business relationships; communications are relevant and infrequent; opt-out is easy and always honoured; and we do not contact people who have not had a prior relationship with us.
You can withdraw your consent or object to direct marketing at any time (see section 10 below). If you opt out, we will stop sending you marketing communications but may still send essential service messages.
5.5 Compliance with legal obligations and protection of rights
We may process personal data where necessary to:
- comply with legal obligations (for example, accounting, tax and consumer protection laws);
- respond to lawful requests from public authorities;
- establish, exercise or defend legal claims; and
- protect the rights, property or safety of LostFit, our users or others.
Legal bases:
- compliance with legal obligations (GDPR article 6(1)(c)); and
- our legitimate interests (GDPR article 6(1)(f)) in protecting our business and defending legal claims.
We have assessed that these legitimate interests outweigh data subjects' interests, as processing is strictly limited to specific circumstances involving active or threatened legal claims, regulatory investigations, or safety concerns.
5.6 AI Add-On features
The AI Add-On is not yet available. No AI feature is enabled for any trainer or client, and no personal data is currently sent to any AI service. This section describes how the feature will work when it is switched on, so that the commitments below are on record in advance.
What will be sent. Before any data leaves our systems, direct identifiers are removed: no name, email address, phone number, postal address, photograph, or free-text note is transmitted. What is transmitted is body measurements, weight history, goals, and per-exercise progression relating to a single client. Where the nutrition and meal-planning capability is used, dietary preferences, restrictions, allergies, and intolerances are also transmitted. Allergy and dietary-restriction data is health data under Article 9, and is treated as special category data throughout.
That data will remain personal data. We describe it as pseudonymised, not anonymised. Because we keep the ability to link the data back to the client it came from, it stays within the scope of the GDPR and we will treat it accordingly — it is not outside data protection law merely because the name has been removed.
Who will process it. We will name the AI inference provider or providers in the sub-processor table in section 8.0, and in Appendix B of the Data Processing Agreement, together with their processing location and the transfer mechanism relied on, before the AI Add-On is enabled for anyone. Any provider we engage will process the data solely on our instructions and will be contractually prohibited from using it to train its own models. Trainers who hold a Data Processing Agreement with us will receive 15 days' advance notice of the addition, as set out in section 8.0.
Content generated by AI will be labelled as AI-assisted where it is shown in the Services, in accordance with Article 50 of Regulation (EU) 2024/1689 (the EU AI Act). Every AI suggestion is reviewed by the Trainer before it reaches a client (see section 11.1).
Legal basis: where LostFit acts as processor for a Trainer, the Trainer determines the lawful basis and, for health data, the Article 9(2) condition — in practice the client's explicit consent. Where LostFit acts as controller in relation to the operation of the feature itself, performance of the AI Add-On contract with the Trainer (GDPR Article 6(1)(b)).
5.7 AI model training (trainer content)
If you are a Trainer, we use the non-personal elements of your Content — workout programme structures, exercise templates, training plan progressions, and periodisation approaches — in anonymised or aggregated form to train, evaluate, and improve our AI models, in accordance with Section 6.6 of the Trainer Terms of Service. We may make the resulting models available commercially, including as a paid service or API. This does not involve disclosing your Content to anyone.
This use is limited to programme and template material. We do not use client personal data, client health data, measurements, progress photos, or messages to train AI models.
Because programme structures and templates in this anonymised form are not personal data, this particular processing falls outside the GDPR. To the extent any personal data is nevertheless involved, we rely on our legitimate interests (GDPR Article 6(1)(f)) in developing and improving our products, and you may object under Article 21.
Independently of data protection law, you may opt out of the AI training licence at any time in the LostFit web application, under Settings → Privacy (Asetukset → Tietosuoja), or by contacting us at the address in section 2. The setting applies to the Content you created; where several trainers work under one organisation, each controls their own. An opt-out applies going forward: we stop using your Content in later training runs and remove it from our training datasets, but models already trained cannot be separated back into the individual contributions that produced them.
6. Special categories of personal data (health and similar data)
Certain data that may be processed through the Services, such as body measurements, weight tracking, information about injuries, dietary restrictions or allergies, may constitute special categories of personal data under GDPR, in particular health data.
We do not require you to provide such data. To the extent that such data is processed through the Services:
- for trainers and their clients, the primary responsibility for determining the lawful basis for processing health data lies with the trainer as controller;
- where LostFit processes such data on behalf of trainers, we do so as a data processor in accordance with our data processing agreement; and
- where LostFit processes such data as a controller (for example, if we provide certain features directly to end users in the future), we will rely on your explicit consent (GDPR article 9(2)(a)) or another applicable exception under article 9.
Trainers should ensure that they obtain explicit consent from their clients for the processing of any health data and that they clearly explain the purposes of processing and the retention periods.
Health and fitness data processed through LostFit is not sold to third parties. It is not used for advertising, insurance eligibility determination, credit scoring, employment assessment, or for any purpose beyond those stated in this policy. Trainers are bound by equivalent restrictions in the Data Processing Agreement.
Progress photos and messages. Progress photos are visible to the client and their trainer only. They are not used in marketing, are not used to train AI models, and are not disclosed to any third party beyond the storage provider that hosts them. Messages between a trainer and their client are not monitored, read, or moderated by LostFit in the ordinary course. LostFit staff access either category only where it is necessary to operate or secure the Services, to investigate a report of abuse or a safety concern made under Section 5.3 of the Client Terms of Service, or to comply with a legal obligation. Such access is limited to authorised personnel, is logged, and is covered by the confidentiality obligations in section 12.
You may withdraw your consent to the processing of special category data at any time via the relevant settings in the Services or by contacting us. If you withdraw consent, we may no longer be able to provide certain features that depend on that data.
7. Cookies and similar technologies
The LostFit Trainer App and Client App use cookies and similar technologies that are strictly necessary for their operation and security, such as session management and authentication. These essential cookies do not require user consent under applicable ePrivacy legislation.
In addition, the Trainer App asks you once, when you first sign in, whether we may collect usage analytics. If you agree, we store an identifier in your browser and record which pages and features you use, so that we can see how the product is actually used and improve it. If you decline, we collect nothing. Your answer is stored on your account rather than in your browser, so it follows you across devices and we do not have to ask again, and you can change it at any time from your settings.
Usage analytics never include your clients' personal data. We do not record anything you type into forms, and we do not collect names, measurements, or health information. You are identified to our analytics provider only by your internal user ID — never by name, email address, or phone number.
The Client App asks the same question, once, when you first sign in. If you agree, we record which screens you open and when you open and close the app, and we store an identifier in the app on your device so that repeat use can be recognised. If you decline, nothing is collected and nothing is stored for this purpose. We do not record your training logs, measurements, nutrition entries, messages, or anything you type. Location is not derived from your IP address for analytics purposes. As in the Trainer App, your answer is stored on your account rather than on the device, so it follows you across devices and reinstalls, and you can change it at any time under Profile → Privacy. Declining does not limit any feature of the app.
Our public marketing website (lostfit.fi) uses PostHog analytics to understand how visitors interact with the site. Because PostHog stores an identifier in your browser, we ask for your consent before it is placed, and nothing is stored on or read from your device until you have answered. Until you answer, and also if you decline, we store nothing on your device and your visit is counted only through a temporary server-side value that is rotated and discarded daily. The Website also sets one strictly necessary functional cookie to remember your language preference, and records your analytics choice so we do not ask again. All of this is set out in full in our Cookie Policy, where you can also change your choice at any time.
We do not use cookies for advertising, cross-site tracking, or behavioural marketing.
We do not rely on legitimate interest as a basis for storing information on, or reading information from, your device. Where consent is required under applicable ePrivacy legislation, we ask for it and we honour your answer.
8. Recipients of personal data
We only share personal data with third parties when necessary for the purposes described in this Privacy Policy, when required by law, or when you have given your consent.
8.0 Sub-processors
We use the following sub-processors (service providers) who may process personal data on our behalf. All sub-processors are bound by GDPR-compliant data processing agreements.
| Service provider | Purpose | Processing location |
|---|---|---|
| Supabase Inc. | Database, authentication, and file storage | EU (eu-north-1) |
| Cloudflare, Inc. | Bot protection (Cloudflare Turnstile) on sign-up, login, password-reset and account-deletion forms. Receives your IP address, user-agent and browser signals when a form is protected | EU + US, global edge network (EU-US DPF certified; EU Standard Contractual Clauses) |
| Vercel Inc. | Application hosting and content delivery for the Trainer App and Website | EU (arn1, Stockholm) + US (EU Standard Contractual Clauses) |
| Stripe Payments Europe, Limited | Payment processing and subscription management | EU + US (EU-US DPF certified) |
| Resend Inc. | Transactional email delivery | EU (Ireland, eu-west-1) |
| Functional Software Inc. (Sentry) | Error monitoring and crash reporting | EU (Sentry EU region) |
| PostHog Inc. | Usage analytics for the marketing website and, where you have consented, the Trainer and Client Apps | EU (PostHog EU Cloud, Frankfurt) |
| OneSignal Inc. | Push notification delivery | EU (Netherlands) + US (EU-US DPF certified) |
No AI inference provider is engaged at present, because the AI Add-On is not enabled (see section 5.6). One will be added to this table, with its processing location and transfer mechanism, before that feature is switched on.
Stripe is an exception to the description above. It processes payment data on our instructions, but it is also an independent controller of that data for fraud prevention, anti-money laundering, identity verification and regulatory compliance — obligations it must meet in its own right as a licensed payment institution, and which it determines itself rather than on our behalf. For those purposes, Stripe's own privacy policy applies alongside ours.
We will update this list when we add, change, or remove sub-processors. Trainers who have a Data Processing Agreement with us are entitled to 15 days’ advance notice before we add a new sub-processor. Where a change is required urgently to maintain the security, availability or continuity of the Service, we may make it sooner and will inform them without undue delay; their right to object is unaffected.
In addition to the above, we may share personal data with:
- Professional advisers: such as lawyers, accountants, auditors or consultants, where necessary for the provision of their services to us;
- Public authorities: where required by law or to protect our legal rights.
We do not sell personal data.
8.1 Payments and financial data
We use Stripe to process and manage payments. When you make a payment through our Services, we share your payment information with Stripe to process the transaction, comply with applicable law, and prevent fraud. For information on how Stripe processes personal data, see stripe.com/privacy.
8.2 Links to third-party websites
The Services may contain links to external websites operated by third parties, such as trainer websites, social media platforms, or partner services. We are not responsible for the privacy practices or content of these third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.
We do not sell personal data in the sense of data protection or consumer privacy laws.
9. International data transfers
LostFit stores and processes personal data within the European Union. Our database, authentication, file storage, email delivery, error monitoring, and analytics services are all hosted in the EU.
Transfers of personal data outside the EU occur only in connection with the sub-processors named below. Stripe, LLC processes payment data, and OneSignal Inc. processes push notification data, in the United States. Both are certified under the EU-US Data Privacy Framework (DPF), which the European Commission has recognised as providing adequate protection for personal data transferred from the EU to the United States (adequacy decision July 2023). Their DPF certifications are publicly verifiable at dataprivacyframework.gov. Vercel Inc., which hosts the Trainer App and the Website, is a United States company; transfers to Vercel are governed by the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914). Cloudflare, Inc. provides bot protection on our sign-up, login, password-reset and account-deletion forms; because it operates a global edge network, the IP address and browser signals it receives may be processed outside the EU. Cloudflare is certified under the EU-US Data Privacy Framework, and transfers are additionally governed by the Standard Contractual Clauses incorporated in its data processing addendum.
The AI Add-On is not enabled and no data is transferred for AI inference at present. If the provider we engage for that feature processes data outside the EU, we will update this section and the sub-processor table in section 8.0 with the safeguards relied on before the feature is switched on, as stated in section 5.6.
If we add a sub-processor that processes data outside the EU, we will update this section and the sub-processor list in section 8.0, and will ensure that appropriate safeguards (such as Standard Contractual Clauses) are in place before any transfer occurs.
10. Retention of personal data
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy or as required by law. The full internal retention schedule is set out in our Retention Policy document. The periods below summarise the main categories.
Trainer data:
- Trainer account and profile data: retained for the duration of the subscription and for 3 years after account closure, to cover the limitation period for potential contractual claims.
- Trainer billing and invoice records: retained for 6 years from the end of the fiscal year in which the last relevant transaction occurred (and 10 years for statutory financial statements and ledgers), as required by the Finnish Accounting Act.
- Trainer-created content (workout programs, exercise templates, nutrition plan templates): retained until account closure. Following account closure, trainers have 30 days to request an export of their content, which we provide within 30 days of the request. We permanently delete trainer-created content 30 days after account closure.
- Trainer support and communications: retained for 3 years from the date the ticket or conversation is closed.
- Login and security logs: anonymised (actor identity, IP address, and derived location removed) 90 days after creation; the anonymised record is then retained for security-monitoring purposes.
Client and end-user data:
- Client profile data (name, contact details, goals): retained while the coaching relationship is active and for 3 years after the last active date, unless the trainer instructs earlier deletion.
- Client health and body measurement data (measurements, body composition, fitness scores, workout logs, nutrition logs, questionnaire responses relating to health): retained while the coaching relationship is active. We permanently delete this data 30 days after the coaching relationship ends (last active date or trainer account closure, whichever is earlier). This is special category data under GDPR and we apply the strictest retention standard.
- Client progress photos and body images: retained while the coaching relationship is active. We permanently delete progress photos 30 days after the coaching relationship ends.
- Chat and messaging data: retained while the coaching relationship is active and for 1 year after the last active date, then deleted.
- Login and security logs: anonymised (actor identity, IP address, and derived location removed) 90 days after creation; the anonymised record is then retained for security-monitoring purposes.
The coaching relationship is considered active while the trainer's account is in an active state and the client has not been permanently archived or deleted by the trainer. "Last active date" means the most recent login or data interaction by either the coach or the client.
Marketing data:
- Contact details used for marketing are retained until you withdraw your consent or object to marketing, or for 2 years of inactivity, whichever is earlier. We retain only a minimal record of your preference after that to prevent re-contact.
Consent records:
We retain records of consents you have given (for example, consent to health data processing or to specific features) for 3 years after the consent period ends, so that we can demonstrate that processing was lawful.
Where no specific retention period is stated, we determine the appropriate period by considering the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it and whether we can achieve those purposes in other ways, and applicable legal requirements.
When personal data is no longer required, we will either delete it securely or irreversibly anonymise it so that it can no longer be associated with an identifiable individual.
11. Your rights under GDPR
Subject to applicable law and certain limitations, you have the following rights in relation to your personal data:
- Right of access: to obtain confirmation as to whether we process personal data about you and, if so, to receive a copy of that data and information about the processing.
- Right to rectification: to have inaccurate or incomplete personal data corrected.
- Right to erasure ('right to be forgotten'): to request deletion of your personal data in certain circumstances, for example where it is no longer necessary for the purposes for which it was collected or where you have withdrawn consent and there is no other legal basis for processing.
- Right to restriction of processing: to request that we restrict processing of your personal data in certain circumstances.
- Right to data portability: to receive personal data that you have provided to us in a structured, commonly used and machine-readable format and to transmit that data to another controller, where processing is based on consent or contract and carried out by automated means.
- Right to object: to object to processing based on our legitimate interests, including profiling, on grounds relating to your particular situation. You also have the right to object at any time to the processing of your personal data for direct marketing purposes.
- Right to withdraw consent: where processing is based on your consent, you may withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
You can exercise your rights by contacting us using the contact details in section 2. We may need to verify your identity before acting on your request and may be unable to fulfil a request where we are legally required to retain data or where other exemptions apply.
If your request concerns training, nutrition, measurement or programme data entered by you or your trainer in the Services, direct it first to your trainer, who is the controller of that data; we assist trainers in fulfilling such requests where required by our contract and by law. For your account itself — login and security history, app diagnostics, analytics and push-notification settings — LostFit is the controller and you can contact us directly using the contact details in section 2.
11.1 Automated processing
LostFit does not make solely automated decisions that produce legal effects or similarly significant effects for individuals within the meaning of GDPR Article 22.
The AI Add-On available to Trainers uses automated processing to generate workout plan suggestions and client progress summaries. These suggestions are tools for Trainers — every plan is reviewed and delivered by the Trainer as part of their professional service. No AI-generated content is applied to a client's programme without the Trainer's review and decision. The outcome is therefore not a "solely automated" decision within the meaning of Article 22.
The logic involved is as follows. The inputs are the client's recorded body measurements and weight history, their stated goals and targets, and their logged workout history including per-exercise weight and volume progression. A large language model is prompted with that data to produce suggested exercises, sets, repetitions and loading, or a narrative progress summary. The significance and consequences for the client are limited by design: the output is a draft shown only to the Trainer, who decides whether to use, change, or discard it. Nothing is scored, ranked, or decided about the client automatically, and no output affects the client's access to any service.
Analytics we generate about platform usage are aggregated or pseudonymous and do not produce individualised automated decisions about users.
11.2 Complaints to the supervisory authority
If you believe that our processing of your personal data violates data protection law, you have the right to lodge a complaint with your local supervisory authority. In Finland, the supervisory authority is:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
- Website: tietosuoja.fi
- Postal address: Tietosuojavaltuutetun toimisto, PL 800, 00531 Helsinki (visiting address: Lintulahdenkuja 4, 00530 Helsinki)
- Email: tietosuoja@om.fi
Complaints specifically about cookies or other storage of information on your device are supervised in Finland by a different authority — the Finnish Transport and Communications Agency (Traficom) and its National Cyber Security Centre, under section 205 of the Act on Electronic Communications Services (917/2014):
Traficom / Kyberturvallisuuskeskus
- Website: kyberturvallisuuskeskus.fi
We encourage you to contact us first so that we can try to resolve your concerns.
12. Security of processing
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include, as appropriate:
- restricting access to personal data to authorised personnel and service providers who need it to perform their tasks and are bound by confidentiality obligations;
- using secure server environments, encryption in transit and at rest where appropriate, and access controls for our systems;
- maintaining backup and recovery procedures and monitoring for unusual activity;
- regularly reviewing our security practices and updating them in light of technological developments and risk assessments.
However, no method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect personal data, we cannot guarantee absolute security.
In the event of a personal data breach, LostFit will assess the risk to affected individuals and, where required by GDPR Articles 33 and 34, notify the relevant supervisory authority and affected users without undue delay.
13. Children and age restrictions
Our Services are not directed to children under 16 years of age. We do not knowingly collect personal data from children under 16.
If you are under 16, you may not create an account or use the Services. Clients aged 16 or older may use the Services and consent to the processing of their personal data on their own behalf; no separate parental or guardian consent is required for the digital service (the Finnish statutory age for consent to information society services is 13 under the Data Protection Act (1050/2018) §5, and LostFit applies a more conservative minimum of 16).
Trainers who provide services to clients under 18 years of age remain responsible for complying with any professional, safety, or legal obligations that apply to providing fitness services to minors in their jurisdiction, and for providing appropriate information to clients (and, where their own professional rules require it, to a parent or guardian).
If we become aware that we have collected personal data from a child under 16 without appropriate consent or legal basis, we will take steps to delete such data as soon as reasonably practicable. If you believe that we may have collected personal data from or about a child without proper authorisation, please contact us immediately using the details in section 2.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example to reflect changes in our Services, in our processing activities, or in applicable law. We will publish the updated version on our Websites and indicate the date of the latest revision at the top of the document.
If we make material changes, we may also notify you by email or through the Services. Your continued use of the Services after the effective date of the updated Privacy Policy will constitute your acknowledgement of the changes.
15. How to contact us
If you have any questions, concerns or requests relating to this Privacy Policy or to our processing of your personal data, please contact us at:
LSTT Solutions Oy Email: gdpr@lsttsolutions.fi Postal address: Takkulantie 320, 21270 Nousiainen, Finland
Please include sufficient information for us to identify you and understand your request, and we will respond as required by applicable law.