FysioBoost brand mark

Privacy

Privacy statement

This statement explains which personal data FysioBoost processes, why we process it, what an employer can and cannot see, and which choices and rights you have.

Version
1.0
Effective date
1 August 2026
Last updated
1 August 2026
Contents

Do you have a privacy question or want to exercise a right?

info@fysioboost.nl

1. Who is responsible?

FysioBoost, located at Weteringlaan 161, 5032 XZ Tilburg, the Netherlands, is responsible for the processing described in this statement. FysioBoost is registered with the Dutch Chamber of Commerce under number 95150714 and has VAT identification number NL867021147B01.

You can contact us about general matters, privacy questions and requests at info@fysioboost.nl. In this statement, ‘we’ and ‘us’ refer to FysioBoost.

2. Who does this statement apply to?

This statement applies to dashboard and mobile-app users, employees and other participants invited by an organization, organization administrators, website visitors and anyone who contacts us.

It also applies when you use scans, wearables, tasks, rewards, AI features, group reports or notifications. Where consent is required, we request it separately and specifically; this statement is not consent.

3. FysioBoost and your organization

FysioBoost generally acts as an independent controller for accounts, personal scans, scores, tasks, wearable data, personal AI summaries, security, support, notifications, leaderboards, rewards and the preparation of protected group reports.

Your employer or inviting organization is independently responsible for deciding to offer FysioBoost, inviting participants, managing roles and licences, employee communications and the lawful use of group reports.

Where FysioBoost processes specific data only on an organization’s documented instructions, the parties record their respective roles in a data processing agreement.

  • Participation in health features must be genuinely voluntary.
  • Your employer cannot access individual answers, health data, personal scores, wearable readings or personal AI summaries.
  • FysioBoost must not be used for individual evaluation, monitoring, selection, disciplinary measures or other employment decisions.

4. Which personal data do we process?

4.1 Account and profile data

We may process your name, email address, user ID, authentication provider, account status, registration and verification dates, last login, language, profile photo, role, organization, department, invitation data and pseudonymised registration markers. Passwords are handled by our authentication service; we do not see your original password.

  • Depending on the features used: age or date of birth, sex, height, weight, BMI, body-fat percentage and muscle mass.
  • Preferences, selected wearable source and settings for notifications, AI, marketing and leaderboards.

4.2 Scans and questionnaires

Scans may cover movement, physical comfort and complaints, mental health, stress, sleep, nutrition, personal development, social vitality, smoking, lifestyle barriers and current vitality.

  • Data about BMI, cardiovascular conditions, cancer, diabetes, asthma or COPD, osteoarthritis, rheumatism and neurological conditions.
  • Possible religious or philosophical beliefs, free text and calculated category, vitality and progress scores.
  • Health data and religious or philosophical beliefs are special-category data and receive additional protection.

4.3 Wearable and health data

With your permission and depending on your device, we may process steps, distance, active minutes, exercise time, active calories, floors climbed, heart rate, resting heart rate, heart-rate variability, oxygen saturation, sleep, temperature, weight and body measurements.

  • Daily, weekly and monthly totals, source device, manufacturer, model, technical device ID and synchronization status.
  • Battery and connection status of a FysioBoost Band.
  • The app requests access only to data types needed for a feature you enable.

4.4 Use, derived insights and communications

We may calculate category and vitality scores, trends, task suggestions, recommendations, points, ranks, participation indicators, AI summaries and aggregated organization trends.

We also process assigned and completed tasks, progress, coins and XP, reward choices and delivery status, support requests, service messages and communication preferences.

4.5 Technical and security data

We may process IP address, browser, operating system, device and app version, session data, request and login times, limited error and security logs, push token, installation ID, platform, timezone and consent history.

We seek to keep names, email addresses, health values, tokens and other sensitive content out of technical logs.

5. Where do we obtain data?

FysioBoost currently does not write health data back to Apple Health.

  • Directly from you.
  • From your employer or organization, such as your invitation, department and role.
  • From Google if you use Google Sign-In.
  • From Apple Health or Android Health Connect after you grant access.
  • From a connected FysioBoost Band or another supported wearable.
  • Through operation and security of the website, app and dashboard.
  • From partners that deliver a reward you selected.

6. Purposes and legal bases

6.1 Account and service

We process account, profile and usage data to create and secure your account, authenticate you, determine your organization and role, display results and progress and provide support. Legal basis: performance of a contract or steps requested before entering into a contract.

6.2 Health features

We process special-category data for scans, personal scores, tasks, insights, wearable views, trends and inclusion in sufficiently large group aggregates only after prior, specific and explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR.

Without consent, we do not process those data for these purposes and the relevant features will be unavailable. Refusal must not cause adverse employment consequences.

6.3 AI and group reports

Personal AI summaries require separate explicit consent. We also request separate consent for group statistics while the source data remain personal data. Reports are shown only for at least ten valid participants, and stricter suppression rules may apply.

6.4 Security, service, marketing and rewards

For security, abuse and fraud prevention, troubleshooting and legal protection, we rely on our legitimate interests and, where applicable, legal obligations. Necessary service messages support performance of the contract or reliable service delivery.

We send marketing email only with consent unless a limited statutory exception applies. For a selected reward, we process necessary delivery data to fulfil your request and prevent fraud.

6.5 Legal obligations

We may process data to meet legal duties or lawful orders, investigate fraud or offences and establish, exercise or defend legal claims.

7. What can your employer see?

Authorized administrators may see limited administrative information for account and licence management, such as name, email, department, role, invitation status and whether a licence seat is used. They must not infer health information from it.

An organization can receive only group-level insights, such as average vitality and category scores, distributions, movement, activity, sleep, recovery, participation, progress and organization or department trends.

  • A reporting group contains at least ten valid participants.
  • Names, emails, user IDs, individual answers and individual scores are not shown.
  • Free text is not displayed directly to employers.
  • Small or potentially identifiable departments and breakdowns are suppressed.
  • An employer must not combine reports with other information to identify people or make individual employment decisions.

Aggregated does not automatically mean anonymous

Reports are designed to prevent individual recognition. Source data held by FysioBoost remain personal data while they can be linked to a user. We call data anonymous only when identification is reasonably and permanently impossible.

8. Artificial intelligence

FysioBoost uses Google Gemini for certain personal and organizational summaries. Personal AI may process selected scores, answers, filtered free text, tasks, progress, points, wearable data and scan availability.

Before sending data, we seek to remove direct identifiers such as name, email, user ID, organization ID, IP address, phone numbers, links and access tokens. Health values may still be special-category data. Organization AI uses only group data that meets minimum group size and suppression requirements.

  • AI output may be inaccurate, incomplete or inappropriate.
  • AI does not diagnose and is not medical, legal or employment advice.
  • AI does not independently make decisions with legal or similarly significant effects.
  • A personal AI summary is not shared with your employer.
  • You can disable personal AI; no new summaries are generated until you consent again.

9. Apple Health, Health Connect and wearables

9.1 Apple Health

On iOS, FysioBoost may request read permission per data type for steps, sleep, exercise time, active energy, heart rate, resting heart rate, oxygen saturation, heart-rate variability and temperature. You control and withdraw these permissions in iOS. HealthKit data is not used for advertising or data trading.

9.2 Health Connect

On Android, FysioBoost may read similar data through Health Connect. You manage permissions in Android. Health Connect data is not used for advertising, creditworthiness, insurance decisions, fitness for employment or sale to data brokers.

9.3 FysioBoost Band and other wearables

The app uses Bluetooth to find, connect to and read available measurements from a band. Technical device IDs are stored securely for synchronization. The technical connection may use an SDK from the hardware supplier.

Measurements may be inaccurate, delayed, duplicated, incomplete or unavailable and are not intended for medical diagnosis.

10. Camera, photos and local storage

The camera may scan a registration or pairing QR code; the camera image is not stored as a photo. A selected profile photo is kept in protected storage and accessed through temporary secure links.

Sessions and local wearable IDs are stored using protected operating-system storage where possible. Logging out clears local caches and temporary data. Server data is removed after account deletion or a valid deletion request, subject to legal exceptions. The web version may use browser storage for sessions.

11. Who receives data?

We do not sell personal or health data. We share only data needed for the services below and enter into data protection agreements where required.

Recipient categories, purposes and possible data
RecipientPurposePossible data
SupabaseDatabase, authentication, storage and server functionsAccount, scan, health, consent and technical data
Vercel and Vercel AnalyticsHosting, performance and privacy-oriented visitor analyticsWeb requests and limited technical data
Google Gemini and Google Sign-InAI summaries and optional sign-inFiltered AI input or authentication and account data
Apple Health and Health ConnectHealth source selected by youOnly data types for which you grant access
FysioBoost Band hardware supplierTechnical wearable SDKTechnical device and measurement data to the extent processed by the SDK
Expo, Apple APNs and Google FCMPush notificationsPush token, platform and general message content
Resend, EmailJS and email/hosting providerVerification, service, website and other emailName, email, message content and delivery status
hCaptchaBot and abuse protectionIP, browser, interaction and security data
TremendousDelivery of a selected digital rewardName, email, value and reward data
Professional advisers and competent authoritiesLegal, security or statutory purposesOnly data that are necessary or lawfully required

Additional information

The Supabase production database is in the eu-west-1 Ireland region. According to Vercel, Vercel Analytics does not use cookies for its analytics tool. hCaptcha uses interaction and device characteristics to identify bots. Expo forwards push messages to Apple or Google.

A reward partner may retain delivery data longer due to financial and legal duties. A FysioBoost Band may contain components or software from an external hardware supplier; FysioBoost remains your contact for processing within our service.

12. Transfers outside the EEA

Some suppliers or subprocessors may be located in the United States or other countries outside the European Economic Area. Where required, we use an adequacy decision, the EU-US Data Privacy Framework where valid and applicable, European Commission standard contractual clauses and supplementary technical or organizational safeguards.

You can ask info@fysioboost.nl about safeguards that apply to a specific transfer.

13. How long do we retain data?

We retain personal data no longer than necessary for its purpose unless a legal obligation or claim requires longer retention. For active accounts, completed scans, results, trends and current AI summaries are retained as needed to provide personal history and the service.

Retention periods and criteria by data category
DataRetention period or criterion
Hashed registration attempts and expired one-time invitations30 days
Revoked push tokens30 days
Completed notification logs90 days
Incomplete progress scans30 days
Raw health measurements7 days after a usable daily total exists
Hourly health totals90 days after a usable daily total exists
Completed synchronization logs30 days
Individual activity days400 days
Weekly/monthly totals, scans, results and AI summariesFor the active account and as needed for personal history; AI until replacement or deletion
Account and profile dataFor the active account, followed by up to 30 days for closure
Consent and email historyAs needed for evidence, service, security or applicable limitation periods
Financial administration7 years or another legally required period
Managed database backupsUp to 30 days in the normal backup cycle
Tremendous dataUnder Tremendous’ legal and contractual retention periods

After account or contract deletion

Active personal data linked to an account is deleted within 30 days unless an exception applies. Temporary copies may remain in protected backups until the backup cycle ends and are not actively used.

After an organization is removed, organization statistics may remain only if demonstrably and irreversibly anonymised; otherwise they are deleted.

14. Security

We use appropriate technical and organizational safeguards. No system is risk-free; if an incident occurs, we comply with applicable notification and information duties.

  • Encrypted connections, role-based access and row-level database security.
  • Tenant isolation, protected file storage and secure storage for sessions and device IDs.
  • Limited technical logs, hashed registration markers and minimised AI input.
  • A minimum employer group of ten and additional suppression where identification is a risk.
  • Deletion of raw health measurements after processing, monitoring, backups and updates.

15. Your privacy rights

Where applicable, you can request access, correction, deletion, restriction, portability, object to legitimate-interest processing, obtain information about recipients and transfers and request human intervention in relevant automated decision-making.

Send requests to info@fysioboost.nl. We may request information to verify your identity and generally respond within one month. The statutory period may be extended for a complex request; we will tell you within the first month.

A request may be restricted where necessary to protect others’ rights, meet legal duties, preserve security or handle legal claims. We explain any restriction.

16. Withdrawing consent

You can withdraw consent through settings or at info@fysioboost.nl as easily as you gave it. Withdrawal is not retroactive but stops new processing for that purpose.

Withdrawal may stop new AI summaries, scans, health measurements and inclusion in new employer aggregates and may disable related features. You may also request deletion of previously collected data unless a legal exception applies.

17. Automated processing

FysioBoost automatically calculates scores, trends, tasks and recommendations. AI may summarize text and suggest actions. We do not use this to make independent decisions with legal or similarly significant effects. Employers must not use outputs for individual employment decisions.

18. Minors

FysioBoost is primarily intended for participants in a work setting and is not specifically directed at children. An organization wishing to invite a person under 16 must consult FysioBoost first so parental authorization and the employment context can be assessed. For participants aged 16 or 17, we assess in advance whether the intended use and consent flow are appropriate.

19. Complaints

Please first send a complaint to info@fysioboost.nl. You may also complain to the Dutch Data Protection Authority, PO Box 93374, 2509 AJ The Hague, the Netherlands.

20. Changes

We may update this statement when our services, suppliers or the law change. We announce material changes in advance through the app, dashboard or email. A new purpose that requires consent starts only after separate consent is obtained. The current version is always available on our website and in the app.

Back to top