Helthfit Privacy Policy

Effective date: [EFFECTIVE DATE]  ·  Last updated: [DATE]

This policy is a template. Before publishing, replace every [BRACKETED] placeholder with your real company details and have it reviewed by qualified privacy counsel for your jurisdictions (at minimum GDPR / UK GDPR and, if applicable, US state laws).

Helthfit ("we", "us") is operated by [COMPANY LEGAL NAME], [COMPANY ADDRESS]. This policy explains what personal data the Helthfit app and website collect, why, and the choices you have. Helthfit provides general wellbeing guidance and is not a medical device or a source of medical advice.

1. Data we collect

We do not use advertising identifiers, we do not sell personal data, and we do not share it with data brokers.

2. Why we use it (legal bases)

3. Third parties

4. Retention

Account and health data are kept until you delete your account. Care reports expire 30 days after creation. Security and audit logs are kept for [N months]. After deletion we remove your health data immediately and retain only a minimal tombstone record so the account cannot be re-created with the same identifier.

5. Your rights

You can access, correct, export, and delete your data:

Contact us for any privacy request at [PRIVACY EMAIL].

6. Security

Passwords are hashed with bcrypt. Sensitive fields (care-report contents, any stored health-platform credentials) are encrypted with AES-256-GCM. Data is transmitted over HTTPS. Access to production data is limited to authorised staff.

7. Children

Helthfit is not directed to children under 16 and you must be at least 16 (or the age of digital consent in your country) to create an account.

8. Changes

We will post any changes here and, for material changes, notify you in the app or by email before they take effect.

9. Contact

[COMPANY LEGAL NAME], [COMPANY ADDRESS] · [PRIVACY EMAIL]