WITHU HOLDINGS LIMITED (we) are committed to protecting your personal data and respecting your privacy. We know that users of apps are becoming increasingly concerned about what happens to their data. We have invested a significant amount of time and money to ensure that the amount of personal data we collect and store is at a minimum.
This policy (together with our end-user licence agreement as set out at https://withutraining.com/eula.html (EULA) and any additional terms of use incorporated by reference into the EULA, together, our Terms of Use) applies to your use of WITHU mobile application software (App) hosted on either the Google Play Store or the Apple App Store (each an App Store), once you have downloaded or streamed a copy of the App onto your mobile telephone or handheld device (Device).
This policy also applies where you contact us either directly or through our Website or through links on other websites or social media.
This policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. This App is not intended for children under the age of 17. Please read the following carefully to understand our practices regarding your personal data and how we will treat it.
WITHU HOLDINGS LIMITED is the controller and is responsible for your personal data (collectively referred to as “WithU”, “we”, “us” or “our” in this policy).
We have appointed a data privacy manager. If you have any questions about this privacy policy, please contact them using the details set out below.
Our full details are:
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues or other competent supervisory authority of an EU member state if the App is downloaded outside the UK. For further information please visit https://ico.org.uk/make-a-complaint/.
We keep our privacy policy under regular review.
This version was last updated on 10 May 2024. It may change and if it does, the new version will be posted on this page and, where appropriate, notified to you when you next start the App and, if we choose, by email. The new policy may be displayed on-screen and you may be required to read and accept the new version to continue your use of the App.
It is important that any personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during our relationship with you. The App may not function properly if some of the information you have provided us is wrong.
Our Website may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. Please note that these websites and any services that may be accessible through them have their own privacy policies and that we do not accept any responsibility or liability for these policies or for any personal data that may be collected through these websites or services, such as Contact and Location Data. Please check these policies before you submit any personal data to these websites or use these services.
When you download the App and agree to our Terms of Use, your mobile device is allocated a unique identification code (Unique Code), which is the basis on which we manage user accounts. All interactions by you (or any other user of the App on your Device) with the App are recorded by reference to the Unique Code. Depending on how you download the app and the type of device you are using, we may also have access to a unique code associated with your device, (IDFA, IDFV, AAID, IP & Android ID (collectively the “IDFA”)).
In order to use the App you will be required to create an account, to do this, you will be required to provide an email address (Login Data). We will be able to link your email address with the Unique Code, and therefore your account activity with you. This does mean that if you change your device, or access the App across multiple devices the use history and preferences would carry across the devices. If you choose to login using an existing social media account we will obtain that information indirectly from the relevant operator.
We may require limited additional personal data about you if you access the app through a download link provided via a partner company or your employer (see below on Contact Data).
When you use our App we will primarily identify you through your WithU account, although there is likely to be personal information also associated with your account. We will collect and store all interactions with the App on your device (Usage Data). Your Device will also store Usage Data in a cache along with your preferences in order to make your user experience as effective as possible. We will also collect and store such Usage Data on our systems to analyse your use, and the functionality of the App. If the Unique Code is associated with any personal data all of the Usage Data will be personal data.
For users who gain access to the app through a partner- or employer-linked website or service (such as membership of a gym, or employee rewards programme), you may be asked to supply your name and email address (Contact Data) so we can send you the download link. Some partners or employers may provide this information automatically to us via a generated link in addition to a unique code that identifies you as a user on the partner or employer system. In such a case we will retain the Contact Data for as long as you remain on the partner or employer system or as long as you remain a WithU user. In this case, we will be able to associate your contact information with your Unique Code.
Alternatively, the partner or employer may provide you access to the App via a portal. In this case, you will be allocated a unique ID (the “Partner ID”) by WithU, which will be associated with your use of the App as well as your association with the partner or employer. You will still be required to create a login with an email address.
You may provide additional information such as demographic data (for example, your age and gender) and personal data (for example, your age, weight, fitness level, location) (Profile Data) when you use the App to make your experience with the App more effective. You may also choose to provide additional data (Health Data) such as heart rate, by connecting third-party peripheral devices (such as a heart rate monitor) to your device. In all such cases, the App will provide you with more meaningful data and feedback, but it will operate perfectly well without such data. It is a matter of personal choice if you wish to provide the additional information.
If you contact us via the App, on our Website, or directly by email, you may choose to provide us with contact details such as your name and email address (Communication Data) as well as those of other people, for example if you are purchasing the App as a gift. We cannot connect these details with your Unique Code unless you also provide us with the Unique Code. We will only use the details to communicate with you and with the recipient of the gift, as appropriate, and if necessary, to identify and fix problems associated with your use of the App.
We will also collect information to identify what type of Device you are using (Device Data). This will be linked to your Unique Code, and will enable us to optimise the operation of the App.
We may also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific App feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.
By using the App you consent to our anonymising your data, and using the anonymised data for our purposes.
We will collect and process the following data about you:
We will only use your personal data when the law allows us to do so. Most commonly we will use your personal data in the following circumstances:
PURPOSES FOR WHICH YOUR DATA WILL BE USED
Purpose/activity: To create an account with us via a login
Type of data: You will provide us with your name and an email address
Lawful basis for processing: Your consent
Purpose/activity: To send you a link to download the App
Type of data: You may have to supply us with your name and email address on a web-based form.
Lawful basis for processing: Your consent
Purpose/activity: To send you a link to download the App where your access to it is a benefit provided by your employer.
Type of data: Your employer may provide us with your name and work email address.
Lawful basis for processing: Fulfilment of a contract with your employer.
Purpose/activity: To install the App, manage payments and register you as a new App user
Type of data: This process is managed by the operator of the App Store. We do not have any visibility of or access to any of your personal data processed in this way. If you subsequently use a login to access the App, we will be able to link your app, and any Usage Data with you using your Login Data.
Lawful basis for processing: Your consent
Purpose/activity: To track your app installation source
Type of data: We may have access to your IDFA in addition to other data, which may allow us to attach certain attributes to your membership.
Lawful basis for processing: Your consent
Purpose/activity: To track your use of the App and provide you with feedback about your usage.
Type of data:
Profile Data
Usage Data
Health Data
Lawful basis for processing: To perform a contract we have with you;
Consent
Purpose/activity: Partner campaigns
Type of data: We may occasionally partner with brands and send you relevant offers. If you have a login or we otherwise have your email address, we will contact you via your email address. In certain circumstances, we may also send information to the device you have logged in to. If you do not have a login, we will send this information to your Device according to your Unique Code.
Lawful basis for processing: Your consent
Purpose/activity: To manage our relationship with you including notifying you of changes to the App, new features, features that you may not have used or been aware of, usage data and statistics and changes to our Terms of Use
Type of data: If you have a login or we otherwise have your email address, we will contact you via your email address. In certain circumstances, we may also send information to the device you have logged in to. If you do not have a login, we will send this information to your Device according to your Unique Code.
Lawful basis for processing: We will do this in order to be able to perform a contract with you
In some cases, it will be necessary for our legitimate interests (to keep records updated and to analyse how customers use our products/ Services)
In other cases, it will be necessary to comply with legal obligations (to inform you of any changes to our terms and conditions)
Purpose/activity: To remind you when your subscription is coming to an end, or to prompt you to renew or upgrade your subscription, for example, if it has expired, or if you cease to be associated with the partner organisation or employer through which you originally obtained your subscription.
Type of data: If you have a login or we otherwise have your email address, we will contact you via your email address. In certain circumstances, we also may send information to the device you have logged in to. If you do not have a login, we will send this information to your Device according to your Unique Code.
Lawful basis for processing: Our legitimate interests (to market goods and services similar to those already supplied to you)
Purpose/activity: To enable you to complete a survey
Type of data: If you have a login, we may contact you via your email address or your device. If you do not have a login, we will interact with your Device on the basis of your Unique Code.
Lawful basis for processing: Your consent;
Performance of a contract with you;
Necessary for our legitimate interests (to analyse how customers use our products/Services and to develop them and grow our business)
Purpose/activity: To respond to enquiries and other communications you direct to us including through our Website
Type of data: Communication data
Lawful basis for processing: Your consent
Purpose/activity: To identify, diagnose and fix any problems you may have with using the App
Type of data: In most cases we will be able to do this on the basis of your Unique Code. If you do provide us with additional information, or your Unique Code is associated with any Login Data or Contact Data we will process that information in addition
Lawful basis for processing: To perform a contract with you (to remedy issues)
Your consent (additional communications data)
Purpose/activity: To administer and protect our business and this App including troubleshooting, data analysis and system testing
Type of data: Normally we would not require any personal data to do this.
Lawful basis for processing: Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security)
Purpose/activity: To provide partner businesses and employers and named third parties with access to data about their campaign/promotion and/or how users associated with them are using the App
Type of data: Anonymised Usage Data.
Lawful basis for processing: Performance of a contract
Purpose/activity: To provide partner businesses or employers with information about your subscription to the App (where your subscription is derived from your relationship with such a partner business or employer)
Type of data: Contact Data
Lawful basis for processing: To enable them to fulfil their legal obligations in relation to employment and tax;
Our legitimate interests (to ensure we can invoice them appropriately).
Purpose/activity: To provide partner businesses, employers and named third parties with information about your use of the App (where your subscription is derived from your relationship with such a partner business or employer). This may be for the purposes of ensuring you are appropriately rewarded for your use of the App, or for other purposes defined by the relevant recipient.
Type of data: Usage Data
Lawful basis for processing: Consent – you will need to specifically consent to any such personal data being shared with a partner business or your employer or other relevant third party. If the partner business or employer or third party wishes to share such data with third parties, you will need to provide additional specific consent to that within the app.
Purpose/activity: To manage, and if relevant, to terminate your account, where your account is related to your employment or a partner organisation.
Type of data: Your work email address, or your Partner ID
Lawful basis for processing: To fulfil a contract with your employer or a partner organisation.
Purpose/activity: To depersonalise any data, in order to continue to be able to use the data for our internal business purposes, and for marketing, and fundraising purposes.
Type of data: Usage Data, Profile Data, Health Data
Lawful basis for processing: Consent, to the depersonalisation;
Legitimate interests, to continue to use such depersonalised data for analysing and refining our products and services, and for marketing and fundraising purposes.
We use cookies and/or other tracking technologies to distinguish you from other users of the App and to remember your preferences and your progress and past usage of the App. This helps us to provide you with a good experience when you use the App and also allows us to improve the App. Your Device will create a store of Usage Data, Profile Data and Social Profile Data as part of its core functionality.
When you consent to providing us with your personal data, we will also ask you for your consent to share your personal data with the third parties set out below for the purposes set out in the list below:
Some of our external third parties are based outside the UK so their processing of your personal data will involve a transfer of data outside the UK.
Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
All information you provide to us is stored on our secure servers.
Once we have received your information, we will use strict procedures and security features to try to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way.
We will collect and store personal data on your Device using application data caches and other technology.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator when we are legally required to do so.
If we do hold any of your personal data, including Login Data, we will retain your personal data for a period of up to 3 years after you have stopped using the App or the login, save in the case of Contact Data, which we will hold only for as long as you remain on the partner or employer system or as long as you remain a WithU user. The Usage Data that is not linked with any of your personal data (and is therefore anonymous) will remain on our systems, and we will continue to use it to develop our App and understand the use of it by subscribers. You agree that we have the right to depersonalise any data for these purposes. In some circumstances you can ask us to delete your data: see Your Legal Rights below for further information.
In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
In the event that you do not use the App for a period of three years then we will treat the account as expired and your personal data may be deleted.
Under certain circumstances you have the following rights under data protection laws in relation to your personal data.
You can exercise any of these rights at any time by contacting us at dpo@withutraining.com
LAWFUL BASIS
You have the right to:
If you consider that our processing of your personal information infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. If you would like more information on these rights, please visit https://ico.org.uk/for-the-public/.