Legal
Privacy Policy
Last updated: 2 August 2026
Template document — not legal advice. This policy ships with the FitSculpt Pro template as a starting point. Every [PLACEHOLDER] below has to be replaced with your own details, and the whole document reviewed against the services you actually run and the law that actually applies to you, before you put it online. Have a qualified professional check it. Publishing it unedited protects nobody.
1. Who is responsible for your data
This website is operated by [YOUR LEGAL ENTITY NAME], [REGISTERED ADDRESS], VAT/company number [NUMBER] ("we", "us"). We are the data controller for the personal data described here.
For anything to do with your data, write to [PRIVACY CONTACT EMAIL]. If you have appointed a Data Protection Officer, name them here — otherwise delete this sentence.
2. What we collect
We only hold what you hand us. Nothing on this site profiles you in the background.
- Consultation booking form: your name, email address and the training goal you select.
- Contact form: your name, email address, subject line and the message you write.
- Body metrics calculator: the height, weight, age and activity level you type in. These are processed entirely inside your browser to produce the number on screen. They are never transmitted to us, never stored, and are gone the moment you close the page.
- Theme preference: whether you chose the light or dark interface, kept in your browser's local storage.
- Server logs: our hosting provider may record IP address, browser user agent and requested URL for security and diagnostics. Check what [YOUR HOSTING PROVIDER] retains and for how long, and state it here.
3. Why we process it, and on what legal basis
Under the GDPR (Regulation (EU) 2016/679), our bases are:
- To answer you — replying to an enquiry or booking request. Basis: steps taken at your request prior to entering a contract, Art. 6(1)(b).
- To deliver coaching you have bought — performance of a contract, Art. 6(1)(b).
- To keep the site working and secure — our legitimate interest in a functioning, non-abused website, Art. 6(1)(f).
- To meet accounting and tax obligations — legal obligation, Art. 6(1)(c).
- Marketing email, if you ask for it — your consent, Art. 6(1)(a), withdrawable at any time.
If you send us health information in a free-text message, that is a special category of data under Art. 9. Please do not send more than you need to. Where we do handle it, we rely on your explicit consent under Art. 9(2)(a).
4. How long we keep it
- Enquiries that go nowhere: [E.G. 12 MONTHS].
- Client records: for the duration of the coaching relationship, then [E.G. 24 MONTHS].
- Invoices and accounting records: as long as tax law requires — commonly 10 years in Italy.
- Marketing consent: until you withdraw it.
5. Who else sees it
We do not sell your data and we do not trade it. It is shared only with suppliers who process it on our instructions under Art. 28 agreements — typically hosting, email delivery, and any scheduling or payment provider we use. List yours here: [YOUR PROCESSORS].
We also disclose data where the law compels us to.
6. Cookies, local storage and third-party services
This site sets no cookies — no analytics, no advertising, no tracking
pixels. The only thing written to your device is a single
localStorage entry recording your light/dark theme choice. It is a
technical preference, holds no identifier, never leaves your browser, and you can
clear it from your browser settings at any time.
Google Fonts. As shipped, this template loads its typefaces from Google's servers, which means your IP address reaches Google when a page opens. If you operate in the EU, self-host the fonts instead — it removes the transfer entirely and is the reason a German court found the CDN version unlawful in 2022. If you keep the CDN, say so here and cover it under international transfers below.
Add anything else you bolt on — analytics, a booking widget, a chat box, a pixel — with its purpose, provider and legal basis. Most of those do require a consent banner before they load.
7. Transfers outside the EEA
Where a supplier processes data outside the European Economic Area, that transfer rests on an adequacy decision or on Standard Contractual Clauses. Name the suppliers and the mechanism here: [TRANSFER DETAILS].
8. Your rights
Under Articles 15 to 22 of the GDPR you may ask us to:
- confirm what we hold and give you a copy of it;
- correct anything inaccurate or incomplete;
- erase it, where no legal ground for keeping it survives;
- restrict how we use it while a dispute is resolved;
- hand it to you, or to another provider, in a portable format;
- stop processing based on legitimate interest, on grounds relating to your situation;
- withdraw consent at any time, without affecting what was lawful beforehand.
Write to [PRIVACY CONTACT EMAIL]. We answer within one month. If our answer does not satisfy you, you can complain to your national supervisory authority — in Italy, the Garante per la protezione dei dati personali (opens in a new tab).
9. Children
This site is not aimed at anyone under 16 and we do not knowingly collect their data. If you believe a child has sent us personal data, tell us and we will delete it.
10. Security
We take reasonable technical and organisational measures to protect your data — encrypted transport, restricted access, suppliers chosen with care. No method of transmission over the internet is perfectly secure, and we cannot guarantee absolute security.
11. Changes to this policy
We may update this policy as the service or the law changes. The date at the top always reflects the current version. Material changes will be flagged on this page.
12. Contact
Questions about this policy or about your data: [PRIVACY CONTACT EMAIL], or write to [REGISTERED ADDRESS].
See also our Disclaimer and AI content notice, which covers the imagery, testimonials and results claims on this site.