Back to sign in

Privacy policy

How we collect, use, protect and delete your personal and health information, under the Protection of Personal Information Act 4 of 2013 (POPIA).

Last updated 20 Aug 2026

Who is responsible for your information

Day Traning Co. is the responsible party for the personal information processed in this app, as defined in the Protection of Personal Information Act 4 of 2013 (POPIA).

Questions, objections and requests about your information go to privacy@studio.example. You may also complain to the Information Regulator (South Africa) — inforeg@justice.gov.za.

What we collect

We collect only what is needed to train you safely:

  • Personal details — name, date of birth, sex, contact number, email, occupation.
  • Emergency contact — name, relationship and contact number.
  • Health information — PAR-Q answers, medical history, injuries, joint pain, physical limitations, medication, allergies and hospitalisation history.
  • Assessment data — measurements, body composition, blood pressure, resting heart rate, posture, flexibility, strength and cardiovascular test results.
  • Training data — your programmes, completed workouts, feedback, weekly check-ins and any pain reported.
  • Progress photographs, only if you consent to them.
  • Messages between you and your trainer, and your trainer's private notes about your training.
  • Account data — your email address and a hashed password. We never store your password itself.

Why we process it, and on what basis

Personal and training information is processed to perform our agreement with you: to onboard you, assess you, write your programme and track your progress.

Health information is special personal information under POPIA s26. We process it only on your explicit consent, recorded in this app, and only to screen you for exercise and to write and adjust your programme.

We do not use your information for automated decision-making about you, and we do not sell it.

Medical clearance

This app is not a medical device and does not diagnose anything. A flagged PAR-Q answer, a blood-pressure reading or a test rating is information for your trainer to act on — it is never a medical opinion, and the system never records you as medically cleared.

Only your trainer can record that clearance is required and that clearance was received, and that record reflects a decision made by a healthcare professional, not by this app.

Who can see your information

Access is role-based. Your trainer can see only the clients assigned to them. You can see only your own record.

Assessment results and measurements appear in your portal only when your trainer has enabled sharing on your profile. Progress photographs are private to your trainer unless they are explicitly shared with you.

Trainer notes are private working notes and are not shown in the client portal. They still form part of your record and are included in a request for access.

We do not share your information with third parties, and we do not transfer it outside South Africa.

How it is protected

Passwords are hashed with bcrypt and never stored in readable form. Sessions are signed, time-limited, HTTP-only cookies.

In production the app is served over HTTPS, so information is encrypted in transit. The database and uploaded images are held on access-restricted storage.

Backups are taken on a regular schedule, are held for no longer than the retention periods below, and are protected to the same standard as the live database.

Every route and action that touches client data goes through a server-side access check, so a client can never reach another client's record by changing a link.

How long we keep it

We keep your information only as long as it serves the purpose it was collected for, then delete it. The periods are set out in the retention table below.

If you ask us to delete your record, we do so unless we are required by law to keep it.

Your rights under POPIA

You have the right to:

  • Ask what information we hold about you and get a copy of it — your trainer can export your full record as CSV, and your portal shows it on screen.
  • Have information corrected or completed if it is wrong or out of date.
  • Object to processing, and ask us to delete or destroy your record.
  • Withdraw your consent at any time. Withdrawing consent to health information means we can no longer screen you or write you a programme, so training has to stop.
  • Complain to the Information Regulator if you believe your information has been mishandled.

Changes to this policy

This policy was last updated on 2026-08-20 and is version 1.0. Your consent is recorded against the version you agreed to. If we make a material change, we will ask you to consent again rather than assume your old consent still applies.

Data-retention policy

How long each part of your record is kept

InformationKept forWhy
Health information (PAR-Q, medical history, injuries, medication)5 years after the last training sessionRetained as a record of the screening the programme was based on.
Assessment results and measurements5 years after the last training sessionNeeded to interpret reassessments against a client's own history.
Programmes and workout history5 years after the last training sessionRecord of the training prescribed and completed.
Progress photographsDeleted on request, otherwise 2 years after the last sessionHeld only while consent to photographs stands.
Messages and trainer notes2 years after the last training sessionRecord of advice given.
Account and contact detailsUntil the account is deletedNeeded to give the client access to their own record.

Contact

Requests, objections and complaints

Responsible party
Day Traning Co.
Information Officer
The studio owner
Email
privacy@studio.example
Regulator
Information Regulator (South Africa) — inforeg@justice.gov.za