Privacy
Policy
Your privacy matters deeply — especially given the sensitive health data our platform handles. Here’s exactly what we collect, why, and how you control it.
Who We Are
XHealthBlend (“we,” “us,” or “our”) operates the fitness platform available at xhealthblend.com and any associated applications (the “Platform”). We act as the data controller for personal data collected directly from users.
In coach-client or gym-member relationships, the coach or gym may also act as a data controller or processor for their clients’/members’ data. In such cases, coaches and gyms are independently responsible for ensuring a valid legal basis to process that data.
For privacy-related questions, contact us at privacy@xhealthblend.com.
Data We Collect
Data you provide directly
| Category | Examples | Who provides it |
|---|---|---|
| Account data | Name, email, password, profile photo, user role | All users |
| Body & health metrics | Weight, height, body fat %, waist, hips, chest, and other measurements | Trainees |
| Nutrition data | Meal logs, calorie intake, macros, food preferences, dietary restrictions | Trainees |
| Fitness data | Workout history, exercises, sets, reps, weights, training notes | Trainees |
| Goals & assessments | Fitness goals, health history voluntarily shared, initial assessments | Trainees |
| Professional data | Certifications, specializations, client lists, custom programs | Coaches |
| Business data | Gym name, address, member lists, trainer assignments | Gyms & clubs |
| Payment data | Billing name, card details (processed by payment provider — not stored by us) | Paying subscribers |
| Communications | Support messages, feedback, emails to us | All users |
Data collected automatically
- Usage data: Pages visited, features used, session duration, interaction patterns
- Device data: Device type, OS, browser type, screen resolution, language settings
- Connection data: IP address, approximate location (country/city), time zone, referring URL
- Log data: Server access times, error logs, security-related events
Data we do not collect
We do not collect genetic data, biometric identifiers, or health data beyond what you voluntarily enter. We do not access your camera, microphone, or precise location beyond features you explicitly activate.
How We Use Your Data
| Purpose | Description |
|---|---|
| Providing the Platform | Operating all features including workout logging, nutrition tracking, dashboards, and management tools |
| Account management | Creating and managing your account, authenticating identity, and enabling role-based access |
| Personalization | Tailoring your experience and customizing dashboards based on your role and preferences |
| Progress tracking | Generating charts, reports, and insights based on health and fitness data you enter |
| Billing & subscriptions | Processing subscription payments, managing billing cycles, and sending invoices |
| Customer support | Responding to queries, resolving issues, improving support quality |
| Security & fraud prevention | Detecting, preventing, and responding to unauthorized access and abuse |
| Legal compliance | Meeting obligations under applicable laws, regulations, and court orders |
| Platform improvement | Analyzing aggregated, anonymized usage patterns — never using identifiable health data |
| Communications | Sending service notifications, security alerts, and — with your consent — newsletters |
Legal Basis for Processing
For users in the EU, EEA, or UK, we process your personal data under the following GDPR legal bases:
Contract performance
Processing necessary to provide the services you signed up for — account creation, Platform features, subscription management.
Explicit consent
For processing special category health data, we rely on your explicit consent given when you voluntarily enter such data. You may withdraw this consent at any time without affecting prior lawful processing.
Legitimate interests
For fraud prevention, Platform security, and anonymized analytics — where our interests do not override your rights and freedoms.
Legal obligation
Where processing is required to comply with applicable laws, regulations, or legal process.
Health & Sensitive Data
How we protect your health data
- All health data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Internal access restricted on a strict need-to-know basis
- Never used for advertising, profiling, or sold to any third party
- Never combined with external data sources to build behavioral profiles
- Aggregated data used for Platform improvement is fully anonymized
Coach access to trainee health data
When a trainee connects with a coach, the coach gains access to data the trainee has chosen to share. This is:
- Initiated voluntarily by the trainee through the Platform’s connection feature
- Limited to data categories necessary for the coaching relationship
- Revocable at any time by the trainee via disconnecting from the coach in the Platform
Gym access to member data
Gym account holders and authorized trainers may access member data within the gym-member relationship. Gyms are independently responsible for ensuring appropriate legal consent from members.
Data Sharing & Third Parties
Payment processors
We share billing information with our payment processor solely to process subscription payments. Your full card details are never stored on XHealthBlend servers. Processors are PCI-DSS compliant.
Hosting & infrastructure providers
Third-party hosting providers store and serve our Platform under data processing agreements that prohibit them from using your data for any other purpose. We select providers with appropriate security certifications (ISO 27001 or SOC 2).
Analytics & monitoring
We may use limited, privacy-preserving analytics tools configured to minimize data collection. We do not use tools that build individual behavioral profiles or share identifiable data with advertising networks.
Legal disclosures
We may disclose your data if required by law, court order, or governmental authority. We will notify you where legally permitted to do so.
Business transfers
In the event of a merger or acquisition, your data may be transferred. We will notify you via email before your data becomes subject to a different privacy policy, with the option to delete your account.
Cookies & Tracking
We use cookies and similar technologies to operate the Platform. Our cookie usage is minimal and privacy-first. Full details are available in our Cookie Policy at xhealthblend.com/cookies.
Essential cookies only by default
By default, we set only the cookies strictly necessary for the Platform to function — session authentication, security tokens, and preference storage. No advertising or tracking cookies are ever placed without explicit consent.
Data Storage & Security
Where your data is stored
Your data is stored on servers provided by third-party hosting providers. We use established providers maintaining high security and compliance standards. Data may be stored in data centers located outside your country — see Section 9 for safeguards.
Security measures
- Encryption in transit: TLS 1.2 or higher for all data transmission
- Encryption at rest: AES-256 for stored personal and health data
- Access controls: Role-based access limits internal access on a need-to-know basis
- Authentication: Strong password requirements and two-factor authentication support
- Monitoring: Active monitoring for suspicious activity and unauthorized access attempts
- Regular audits: Periodic security reviews to identify and address vulnerabilities
Data breach response
In the event of a breach, we will notify the relevant supervisory authority within 72 hours where required by GDPR, and notify affected users without undue delay if there is high risk to their rights. Report security concerns to security@xhealthblend.com.
International Data Transfers
As a global platform, your data may be transferred to countries outside your residence — including those with different data protection standards. We ensure appropriate safeguards are always in place:
- Standard Contractual Clauses (SCCs): For EU/EEA transfers to third countries
- Adequacy decisions: Transfers to countries with EC-recognized adequate protection
- Data Processing Agreements: Contractual obligations with all hosting and service providers
Data Retention
| Data category | Retention period |
|---|---|
| Active account data | Duration of account + 30 days after deletion request (for data export) |
| Health & fitness data | Duration of account. Deleted within 30 days of account termination |
| Nutrition & dietary logs | Duration of account. Deleted within 30 days of account termination |
| Payment & billing records | 7 years from transaction date (financial & tax regulation requirements) |
| Support communications | 3 years from date of interaction |
| Security & audit logs | 12 months |
| Anonymized analytics data | Indefinitely (cannot be linked to any individual) |
Your Rights
We honor the following rights for all users globally, not just those in regulated jurisdictions:
Right to access
Request a copy of all personal data we hold about you, including health and fitness records.
Right to rectification
Correct any inaccurate or incomplete personal data we hold at any time.
Right to erasure
Request deletion of your personal data, subject to legal retention requirements.
Right to portability
Receive your data in a structured, machine-readable format to transfer elsewhere.
Right to restrict processing
Ask us to limit how we use your data while a dispute or review is in progress.
Right to object
Object to processing based on legitimate interests, including profiling.
Withdraw consent
Withdraw consent for health data processing at any time without affecting prior processing.
Right not to be profiled
Object to automated decision-making or profiling that significantly affects you.
How to exercise your rights
Contact us at privacy@xhealthblend.com. We will respond within 30 days. We may verify your identity before processing your request.
California residents (CCPA)
Submit requests with subject line “CCPA Request” to privacy@xhealthblend.com. We do not sell personal information.
EU/UK residents (GDPR & UK GDPR)
You have the right to lodge complaints with your local supervisory authority. EU: edpb.europa.eu. UK: ico.org.uk.
Brazilian residents (LGPD)
Contact us at privacy@xhealthblend.com to exercise rights under the LGPD.
Children’s Privacy
XHealthBlend is not directed at children under 13, and we do not knowingly collect personal data from them. Users between 13–17 may only use the Platform with verifiable parental or guardian consent.
If you believe we have inadvertently collected data from a child under 13, contact us immediately at privacy@xhealthblend.com and we will promptly delete that data.
Changes to This Policy
When we make material changes, we will: send an email notification to your account address, display a prominent Platform notice for at least 30 days, update the “Last updated” date, and — where required by law — seek fresh consent for new health data processing.
For changes materially affecting health data processing, we will provide at least 30 days’ advance notice and obtain your explicit consent before new processing begins.
Privacy questions
or requests?
We aim to respond to all privacy-related requests within 30 days.