PRIVACY POLICY
Live Like an Athlete – PHI Performance Health Intention Oy
Last updated: 1.12.2025
PHI Performance Health Intention Oy (“we”, “our”, “us”), Business ID 2705817-3, located in Finland, provides the Live Like an Athlete mobile application (“App”). This Privacy Policy explains how we collect, use, store, protect, and process personal data when you or your child use our App.
Our App is available worldwide. All personal data is processed in compliance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
By using our App, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
PHI Performance Health Intention Oy
Business ID: 2705817-3
Finland
Email: asiakaspalvelu@phioy.com
We are the primary data controller for all personal data processed in the Live Like an Athlete App.
2. Third-Party Service Provider: Everfit (Whitelabel Platform)
The Live Like an Athlete App is built on the Everfit platform, which provides technical infrastructure, backend systems, data storage, and operational functionalities. PHI Performance Health Intention Oy is the data controller, while Everfit acts as our data processor.
Everfit processes personal data only for:
-
data hosting and storage
-
technical platform functionality
-
system performance and bug fixing
-
account synchronization
-
maintaining security
Everfit does NOT:
-
use data for advertising or marketing
-
sell or share data for independent purposes
-
access data beyond what is required for technical operation
All processing follows our instructions under a GDPR-compliant Data Processing Agreement (DPA), including EU Standard Contractual Clauses (SCCs) for international transfers.
3. Personal Data We Collect
3.1 Account Information (Parent or Guardian)
Accounts used for registration, subscription, and payments must be created by a parent or legal guardian.
We may collect:
-
Name
-
Email
-
Payment and subscription details (processed via third-party payment providers)
-
Country and region
-
Guardian’s consent for a child to use the App
3.2 Child User Information
A child (e.g., young athlete) may use the App under guardian supervision.
For child users, we may process:
-
Name or nickname
-
Age group or birth year
-
Training performance details
-
App usage data
-
Health and fitness data (only with guardian’s explicit consent)
We do not collect data from a child without:
-
The guardian creating the primary account, and
-
The guardian giving consent for the child to use the App.
3.3 Usage Data
-
App activity
-
Selected programs
-
Completed exercises
-
Device and technical data
3.4 Health and Fitness Data (Special Category Data)
Collected only with explicit consent (from the guardian for minors):
-
Training logs
-
Heart rate (if provided)
-
Fitness progress
-
Wellness, recovery, and lifestyle metrics
3.5 Communications
-
Support messages
-
Feedback or content submitted voluntarily
4. Purpose and Legal Basis for Processing
4.1 Operating the App
-
Delivering training, nutrition, and wellness programs
-
Personalizing content
Legal basis: Contract, legitimate interest
4.2 Health and Fitness Data
-
Providing progress insights
-
Enabling training guidance
Legal basis: Explicit consent (guardian consent for minors)
4.3 System Maintenance
-
Performance analytics
-
Bug fixing
Legal basis: Legitimate interest
4.4 Legal Obligations
-
Financial and accounting requirements
Legal basis: Legal obligation
5. Health Data Utilization
Our App collects and processes health-related information such as workout activity, exercise logs, heart rate, and other fitness metrics. This data is collected only with explicit consent (from a guardian in the case of minors) and is used exclusively to deliver core App features, including fitness tracking, progress insights, and cross-device synchronization.
We do not share your health data with any third parties, and we do not use this data for advertising or marketing purposes. All health information is stored securely and access is limited to authorized personnel only. We adhere to industry best practices to ensure data protection.
If you choose to delete your account, all associated personal and health-related data will be permanently deleted from our systems.
6. Account Deletion
You or your child’s guardian may request data deletion at any time.
Requests may be submitted through:
-
in-app settings
-
email or contact form
Include the subject “delete my account” and:
-
account holder’s full name
-
account holder’s email
We will use commercially reasonable efforts to honor your request.
We may retain:
-
legally required records
-
limited archived information required for legal or administrative reasons
Note: Messages or feedback submitted within the App may not be deleted.
7. Children’s Privacy and Use of the App by Minors
The App may be used by children, including young athletes, with parental or legal guardian consent.
To comply with GDPR:
-
A guardian must create the account and manage payment details.
-
A guardian must provide consent for the child to use the App.
-
A guardian may review, modify, or delete the child’s data at any time.
We do not knowingly collect personal information from children without guardian oversight.
8. Data Storage and Retention
Data is stored within the EU/EEA or by GDPR-compliant providers.
Retention:
-
Active account → data kept until deletion request
-
Health data → deleted permanently upon account deletion
-
Legal/financial data → retained per Finnish law (typically 6 years)
9. International Data Transfers
If data is transferred outside the EU/EEA (e.g., Everfit’s US-based infrastructure), we use:
-
Standard Contractual Clauses (SCCs)
-
Adequacy decisions
-
Other required GDPR safeguards
10. Data Sharing
We do not sell or rent data.
Data may be shared with:
-
Everfit (data processor)
-
secure hosting providers
-
analytics or system tools
-
payment processors (guardian accounts only)
All third parties comply with strict confidentiality and security obligations.
11. User Rights Under GDPR
Guardians and adult users have the right to:
-
access data
-
correct data
-
delete data
-
withdraw consent
-
restrict processing
-
data portability
-
object to certain processing
To exercise rights, contact: asiakaspalvelu@phioy.com
You may also contact the Finnish Data Protection Authority.
12. Cookies and Tracking Technologies
The App may use cookies or similar technologies for:
-
authentication
-
preferences
-
analytics
-
performance
You may disable cookies, but some features may not function properly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The latest version will always be published publicly with an updated “Last updated” date.
14. Contact Information
For privacy inquiries or rights requests:
PHI Performance Health Intention Oy
Business ID: 2705817-3
Finland
Email: asiakaspalvelu@phioy.com
