FitManager Privacy Policy
Effective date: 10 August 2026 (previous version 3 August 2026) Applies to: FitManager web and mobile apps Data controller: newfrom (주식회사 뉴프롬) Controlling version: For users in the Republic of Korea, the Korean version of this Policy is the controlling text. For users outside the Republic of Korea, this English version is the controlling text. Region-specific information: Section 22 sets out the legal bases on which the Company processes personal information. Section 23 applies to users in the European Economic Area and the United Kingdom. Section 24 applies to users in the United States.
newfrom (주식회사 뉴프롬, the “Company”) complies with applicable law in order to protect users’ personal information while providing the FitManager service (the “Service”). This Privacy Policy explains what personal information the Company processes and for what purposes, how it protects that information, and what rights users may exercise.
1. Scope
This Policy applies to personal information processed through the FitManager website, the service introduction site, mobile apps, web views, and APIs provided by the Company.
This Policy also applies where a person who has not created an account submits an enquiry through the support page of the service introduction site. In that case the enquirer may hold no account, and the Company processes personal information only to the extent needed to reply to the enquiry.
The controller of your personal information is newfrom Co., Ltd. (주식회사 뉴프롬), whose details are in Section 19.
The Company operates the Service from the Republic of Korea and offers it internationally. It processes personal information on the basis of the personal information protection laws of the Republic of Korea and, where they apply to you, the laws of your own region. Section 22 states the legal basis for each purpose. Section 23 covers the European Economic Area and the United Kingdom. Section 24 covers the United States.
External sites and app stores linked from the Service are governed by the privacy policies of the respective operators.
2. Purposes of Processing
The Company processes personal information for the following purposes.
- Registration, login, identification, and account management
- Email verification, password reset, and account security
- Connection requests, invite-code connections, and connection status management between trainers and member users
- Creation, assignment, performance, logging, and history review of workout programs
- Trainer feedback, member feedback, and management of attachments
- Management of workout programs and workout logs in solo mode
- Creation of organizations, management of member invitations, join requests, and roles, and management of organization-owned materials
- Verification of the existence of business (fitness center) organizations, review of business registration certificates, and prevention of duplicate registration
- Trainer approval review and provision of public trainer profiles
- Consultation, trial, and conversion management of prospect records by trainers
- Management of the exercise library, custom exercises, equipment catalogue, and media such as images and videos
- Delivery of push notifications, email notifications, and service announcements, and management of notification preferences
- Display of screens, wording, and content in the language selected by the user
- App version checks and update guidance
- Customer enquiries, reports, dispute handling, prevention of misuse, and processing of use restrictions and objections
- Receiving support enquiries regardless of account status, verifying the enquirer before showing an enquiry, posting replies, and notifying the enquirer
- Ensuring service stability, incident response, and security log analysis
- Processing account closure requests and confirming that deletion has been carried out
- Statistics, service quality improvement, development of workout analysis algorithms, and model training based on anonymised workout data
3. Categories of Personal Information Processed
The Company processes the following information to the extent necessary to provide the Service.
| Category | Items |
|---|---|
| Account information | Email address, password hash, display name, role (trainer/member/administrator), account status, email verification status, language preference, authentication generation value, sign-up and update timestamps |
| Profile information | Profile photo or image key, trainer biography, affiliation, professional title, specialties, trainer approval status, member invite code |
| Organization information | Organization name, organization type (personal/business), operating status with the reason, handler, and time of change, and the requesting creator |
| Organization identity information | Business registration number, country, business address (province/city/detail), postal code |
| Organization submitted documents | Copy of the business registration certificate, original file name, MIME type, file size, stored object key, uploading user, upload and review timestamps, review result, rejection reason |
| Organization membership information | Organization membership and role (owner/manager/trainer), membership status, invitation and join request history and outcomes, organization-specific trainer profile overrides |
| Trainer-member connection information | Trainer ID, member ID, organization, connection status, initiating party, connection creation and change timestamps |
| Prospect record information | Name, mobile number, email address, consultation/trial/conversion notes, status, next contact date, archiving time and reason |
| Workout program information | Program title, description, author, assigned member, program type, week, session, exercises, planned repetitions, loads, rest intervals, and notes per set |
| Workout log information | Workout session, performing member, start and completion times, set completion status, actual repetitions, actual loads, recorded values such as duration and distance, workout notes |
| Feedback information | Author, recipient or related member, feedback body, linked session, program, or exercise, read status, creation time |
| Media information | Uploaded images, videos, and files, original file name, MIME type, file size, stored object key, uploading user, upload time, description, whether people are included and the time consent was confirmed |
| Push notification information | Per-installation device identifier, FCM registration token, platform (iOS/Android/web), device display name, per-category notification preferences and change history, delivery and receipt logs, failure reasons, badge state |
| Service announcement information | Announcement audience eligibility, announcement delivery history |
| Email delivery information | Recipient email address, request time, and request IP used to enforce resend limits for email verification and password reset, and delivery history |
| Enquiry information | Reply email address, the hash of the lookup password, reference number, enquiry subject and body, operator reply body, the environment the enquirer chose to tell us (iPhone/Android/PC), IP address at submission, processing status and the times of submission, latest activity, and closure |
| Enquiry lookup attempt information | Email address and request IP used to attempt an enquiry lookup, whether it succeeded, and the attempt time |
| App environment information | App platform and app version, update guidance display history |
| Service usage and security information | Access timestamps, request logs, IP address, User-Agent, error logs, authentication token issuance and expiry information |
| Operational records | Processing history for account status changes, trainer approval changes, and similar actions by service administrators, including the reason, handler, and time |
| Account closure records | Internal identifier of the closed account, role, applied policy version, request, anonymisation, and cleanup completion timestamps, processing status and retry information |
The Company does not collect unique identifiers designated by law, such as resident registration numbers, passport numbers, or driver’s licence numbers.
4. How Personal Information Is Collected
The Company collects personal information in the following ways.
- Information that users enter or submit directly during registration, profile creation, organization registration, program creation, workout logging, feedback writing, file upload, and enquiries
- Information that trainers enter about prospect records for consultation and trial management
- Access logs, error logs, authentication token information, and app version information that are generated and collected automatically while the Service is used
- Device tokens required for push delivery, collected when a user grants notification permission in the app
5. Sensitive and Health-Related Information
The Company is not a medical institution and does not collect medical information for the purpose of diagnosing or treating illness.
What the Company does not collect. The Service does not connect to Apple Health, Google Health Connect, or any other health platform on your device, and does not read data from them. It has no field for body weight, body fat, heart rate, blood pressure, body mass index, or any comparable body metric, and does not ask for your date of birth or your sex.
Workout records. The values the Service stores are measurements of what you did in training: repetitions, the load lifted, duration, distance, pace, rest intervals, and rate of perceived exertion. These describe training performance rather than the state of your health, and the Company does not treat them as health data or use them to infer anything about your health.
Where health information can appear. The Service has free-text fields for session notes, set notes, and feedback messages, and it lets you attach photographs and videos. Trainers can also record consultation notes about a prospective member. The enquiry body on the support page is a free-text field as well. If what you or your trainer writes or uploads describes pain, injury, symptoms, pregnancy, medication, or a physical limitation, that entry reveals information about health and the Company treats it accordingly. Section 22 states the legal basis for each of these.
An enquiry is a channel for questions about using the Service, so there is no need to describe your health or your body in one. The Company advises against entering sensitive information on the enquiry form.
The Company processes such information only to the extent necessary for workout management and the provision of feedback, and does not use it for advertising or for profiling users.
You decide what to enter. None of these fields is required in order to hold an account, and you may delete what you have entered at any time or close your account, which deletes it as described in Section 7. Where you are connected to a trainer, what you enter becomes visible to that trainer as described in Section 10.
Users should take care not to upload, or write in an enquiry, unnecessary or sensitive information such as medical certificates, diagnosis names, treatment records, resident registration numbers, or other people’s photographs or videos. Trainers must keep member users’ health-related information and consultation records confidential, and must not use them for purposes other than the Service or disclose them to third parties.
6. Personal Information of Children Under 14
The Service is available only to persons who meet the minimum age set out in Article 4 of the Terms of Service: 16 in the European Economic Area unless the applicable member state has set a lower age, which may be as low as 13; 13 in the United Kingdom; 14 in the Republic of Korea; and 13 elsewhere. The Company does not knowingly collect personal information from anyone below that age, and does not verify age at registration.
If the Company becomes aware that a user is below the applicable age, it will verify whether any consent required by the applicable law has been obtained, restrict use of the Service, or delete the account and the related personal information. If you become aware that personal information of a person below the applicable age has been collected, please notify the contact in Section 19 and the Company will verify and delete it without delay.
7. Retention and Use Periods
The Company retains personal information until the purpose of processing is achieved, and destroys it without delay once the purpose is achieved or the user closes their account. However, where retention is required by law or necessary for handling disputes, preventing misuse, or maintaining the consistency of the Service, the Company may retain information for the periods set out below.
| Information | Retention period |
|---|---|
| Account information | Until a closure request. Once closure is accepted, identifying information such as email address, display name, password, and profile image is removed or replaced with substitute values without delay. The account record itself is retained in a form in which the individual cannot be identified, in order to maintain referential consistency of the remaining records |
| Member users’ workout programs, workout sessions, set logs, and feedback | Until the user deletes them or closes their account. Deleted without delay when a member user closes their account |
| Trainers’ profiles, unassigned programs, and prospect record information | Until the trainer deletes them or closes their account. Deleted without delay when a trainer closes their account |
| Programs assigned to members and in progress | Retained even if the trainer closes their account, in order to preserve the member user’s workout logs; author information is displayed in a form in which the author cannot be identified |
| Prospect record information | Destroyed one year after the trainer deletes or archives it. Deleted immediately when the trainer closes their account |
| Organization information and organization identity information | Until the organization is terminated |
| Organization submitted documents | Until the organization is terminated. Copies of business registration certificates are destroyed without delay when the organization is terminated, while the review outcome record is retained. Backups may retain the data for up to 30 days |
| Media files and metadata | Until the related workout log, feedback, or exercise is deleted or the account is closed. On closure, stored files are queued for deletion and removed in sequence, with automatic retries on transient failure. Backups may retain the data for up to 30 days |
| Push device tokens and notification preferences | Until the user logs out, unregisters the device, deletes the app, opts out, or the token is invalidated. Deleted immediately on account closure |
| Push and announcement delivery logs | Retained to confirm delivery results and handle redelivery; the user’s receipt logs are deleted immediately on account closure |
| Email verification and password reset tokens | Verification tokens for 24 hours after issuance; password reset tokens for one hour after issuance or until used. Deleted immediately on account closure |
| Email delivery and request history | Retained to enforce resend limits and prevent abuse; history for the email address is deleted immediately on account closure |
| Enquiry information | Destroyed one year after the enquiry’s latest activity (submission or most recent post). Enquiries are not linked to an account, so they are retained for this period regardless of whether an account is closed. If a user with an account closes it, enquiries they submitted are not deleted immediately, and the enquiry content does not include account identifiers. May persist in backups for up to 30 days |
| Enquiry lookup attempt information | Retained to prevent brute-force attempts against the enquiry lookup password; deleted together with the enquiry when it is destroyed |
| Operational records (account status and trainer approval changes) | Retained to verify operational history; deleted immediately when the affected user closes their account |
| Consent records | The version, language, and time of the documents you agreed to. Retained while the account exists in order to demonstrate that consent was given, and deleted immediately on account closure |
| Account closure records | Retained to confirm that deletion has been carried out. Contains only the internal identifier and processing timestamps and status, and does not contain identifying information such as email address or name |
| Anonymised workout data | Where stored separately in a form in which individuals cannot be re-identified, until the purposes of statistics, quality improvement, development of workout analysis algorithms, and model training are achieved |
| Access and security logs | Three months, for security, incident response, and prevention of misuse |
| Dispute and rights infringement records | Three years where necessary to handle related disputes, reports, or legal claims |
| Backup data | Deleted in sequence within a maximum of 30 days according to the backup cycle |
| Records retained under applicable law | The period prescribed by the relevant law |
Login sessions apply an expiry policy of 24 hours for access tokens and 14 days for refresh tokens. Where an event that affects account security occurs, such as a password change or account closure, existing sessions are invalidated at once.
Account closure cannot be reversed, and the Company does not provide a procedure to cancel closure or restore data.
8. Use of Anonymised Data for Analysis and Training
After account closure or a deletion request, the Company destroys or anonymises the original personal information and identifiable workout logs. Structured workout data from which user identifiers and linking keys have been removed so that individuals cannot be re-identified may be retained in a separate analytical store.
Anonymised workout data may be used for statistics, service quality improvement, development of workout analysis algorithms, and model training. Free-text notes, feedback bodies, photographs, videos, and files, which carry a high risk of re-identification, are excluded from the separate storage used for anonymised analysis.
The Service does not currently carry out fully automated decision-making or profiling that has a material effect on users’ rights or obligations.
9. Provision to Third Parties
In principle, the Company does not provide users’ personal information to third parties. It may do so exceptionally in the following cases.
- Where the user has given prior consent
- Where there is a specific provision of law, or an investigative authority, court, or administrative agency makes a request in accordance with lawful procedure
- Where it is necessary to prevent an imminent danger to life, body, or property
The Company does not sell personal information or provide it to third parties for advertising purposes.
10. Information Sharing Between Users
Where a trainer and a member user are connected within the Service, this is information sharing between users for the purpose of providing the Service, and is not provision to a third party.
- A member user’s workout logs, program performance history, feedback, and attached media are displayed to the connected trainer.
- Programs, feedback, and public profiles created by a trainer are displayed to the connected member user.
- Organization owners and organization administrators may view organization members and organization-owned materials to the extent necessary for operating the organization.
- Organization identity information, such as the detailed business address and business registration number, is not disclosed to member users.
- A member user may end a connection so that the trainer can no longer access new records.
11. Delegation of Processing
The Company delegates part of its personal information processing to external service providers in order to provide the Service reliably.
| Processor | Delegated work | Items processed |
|---|---|---|
| Amazon Web Services, Inc. | Server hosting, database operation, infrastructure security log management | Service data, access and security logs |
| Amazon Web Services, Inc. (S3) | Storage of images, videos, and files | Media files, object keys, metadata |
| Google LLC (Firebase Cloud Messaging) | Delivery of app push notifications | Device identifiers, push tokens, notification preferences, notification titles and bodies, deep links |
| Zoho Corporation | Email delivery for email verification, password reset, enquiry receipt and reply notices, and similar purposes | Email addresses, verification and reset link information, enquiry reference numbers |
The Company does not use separate behavioural analytics tools or advertising identifier based tracking tools.
The Company manages personal information protection, prohibition of use for other purposes, restrictions on sub-delegation, security measures, and retention and destruction through contracts or terms with its processors, and discloses any change of delegated work or processor through this Policy.
Apple App Store and Google Play are independent operators responsible for app distribution and installation and are not processors of the Company. Device and account information that those operators process under their own policies is governed by their respective privacy policies.
12. Transfer of Personal Information Abroad
The Company operates its servers, database, and file storage in the Amazon Web Services Seoul region, so the Service data itself is stored within the Republic of Korea. However, certain information is transferred abroad in the course of email delivery and push notification delivery, as set out below.
| Transferee | Country | Items transferred | Purpose | Time and method of transfer | Retention and use period | Contact |
|---|---|---|---|---|---|---|
| Zoho Corporation | United States | Email address, verification and reset link information, enquiry reference numbers | Email delivery for email verification, password reset, enquiry receipt and reply notices, and similar purposes | Transmitted over the network when an email needs to be sent | Until the purpose is achieved or use of the Service ends | privacy@zohocorp.com |
| Google LLC | United States | Device identifier, push token, notification preferences, notification title and body, deep link | Delivery of app push notifications | Transmitted over the network when a notification needs to be sent | Until the purpose is achieved, the token is deleted, or use of the Service ends | https://support.google.com/policies/troubleshooter/7575787 |
Users may refuse the transfer of their personal information abroad. Transfers for push notifications stop if notification delivery is turned off in the app or device settings, and the rest of the Service remains available. Transfers for email delivery are required for email verification at registration and for password reset, so refusing them means that account verification and password reset cannot be used, which restricts registration for and use of the Service.
If you use the Service from outside the Republic of Korea, the information you enter is transmitted to and stored on the Company’s infrastructure in the Republic of Korea. For users in the European Economic Area and the United Kingdom, this transfer is covered by the adequacy decisions that the European Commission and the United Kingdom have adopted for the Republic of Korea, which recognise that Korean law provides an essentially equivalent level of protection. No separate transfer contract is therefore required for that transfer.
The Company will update this Policy, and give separate notice where necessary, if the transferee, the country of transfer, or the method of processing changes.
13. Destruction Procedure and Method
- The Company destroys personal information without delay once the retention period has elapsed or the purpose of processing has been achieved.
- Electronic files are deleted or de-identified so that they cannot be recovered, and any paper documents are shredded or incinerated.
- Files held in storage are queued for deletion and removed in sequence, with automatic retries where a transient failure occurs.
- Backup data is stored separately from operational data and is deleted in sequence within a maximum of 30 days once the backup retention cycle has passed.
- Information that must be retained by law is stored separately and is not used for any other purpose.
14. Rights of Data Subjects and How to Exercise Them
Users may exercise the following rights in relation to their own personal information at any time.
- Request for access
- Request for correction where there is an error
- Request for deletion
- Request to suspend processing
- Withdrawal of consent and request for account closure
- Refusal of transfer of personal information abroad
Rights may be exercised through the settings screens in the Service, by email, or in writing. Many items, including name, profile, language preference, notification preferences, trainer connections, and account closure, can be reviewed and changed directly by the user in the Service settings.
The Company acts without delay in accordance with applicable law after verifying the requester’s identity, and replies with the outcome using the method by which the request was made. A request may be limited where retention is required by other laws, where it is necessary for handling a dispute, or where it risks infringing the rights and freedoms of other users; in such cases the Company will explain the reason.
Where rights are exercised through a legal guardian or an authorised representative, the Company may require documentation confirming the authorisation.
Where the law of a user’s country of residence grants additional rights beyond those listed above, such as data portability, restriction of processing, or objection to automated processing, the user may request the exercise of those rights using the contact in Section 19.
15. Prospect Record Information Entered by Trainers
Where a trainer enters prospect record information, the trainer must inform the person concerned that their name, contact details, consultation notes, and similar information are stored in FitManager for consultation and member conversion management, and must obtain any necessary consent.
The Company stores and processes such information in order to provide the trainer’s consultation, trial, and conversion management features, and destroys it one year after the trainer deletes or archives it. Where a trainer closes their account, the prospect record information entered by that trainer is deleted immediately.
A person recorded as a prospect may request access, correction, or deletion using the contact in Section 19.
16. Automatically Collected Information and Data Stored on the Device
The Service does not use cookies for advertising or behavioural analytics. However, it stores the following information in the user’s browser or in-app storage in order to maintain login, ensure security, retain screen settings, and deliver notifications.
| Stored item | Purpose | Retention period |
|---|---|---|
| Access token and refresh token | Maintaining the login state and authentication | Until logout, account closure, or token expiry |
| Active organization identifier | Retaining the current working organization for trainers who belong to several organizations | Until changed or the user logs out |
| Language preference | Displaying screens in the selected language | Until changed or storage is cleared |
| App installation identifier and notification registration state | Per-device push delivery and prevention of duplicate registration | Until the app is deleted, the device is unregistered, or storage is cleared |
| Notification guidance acknowledgement | Preventing the one-time guidance screen from being shown repeatedly | Until storage is cleared |
Users can remove this information by clearing browser storage or deleting the app. Doing so resets the login state and screen settings.
Access timestamps, IP addresses, User-Agent strings, and request and error logs are recorded automatically on the server while the Service is used, and are used only for security and incident response.
17. App Device Permissions
The mobile app uses the following device permissions. All of them are optional; if a user does not grant a permission, the user may still use the rest of the Service other than the corresponding feature.
| Permission | Type | Purpose |
|---|---|---|
| Notifications | Optional | Receiving push notifications such as connection requests, new programs, feedback, organization processing, and service announcements |
| Camera | Optional | Taking photographs or videos to attach to workout logs and feedback |
| Microphone | Optional | Recording sound together with video when a video is taken |
When a user attaches a photograph, video, or file from their device, the app receives only the items the user selects through the picker provided by the operating system, and does not access the device storage as a whole.
Users may revoke a granted permission at any time in their device settings.
18. Security Measures
The Company applies the following measures to protect personal information.
- HTTPS encryption for all communication between the web and app clients and the server
- One-way hashing of stored passwords
- JWT-based authentication with expiry times for access and refresh tokens, and invalidation of all existing sessions on password change or account closure
- Role-based access control and separation of service administrator privileges
- Data isolation per organization and restriction of access to workout logs according to trainer-member connections
- Storage of media files in a non-public store and issuance of signed URLs with a limited validity period
- Deactivation of an existing push token when a token conflict occurs
- Expiry times for email verification and password reset tokens, and limits on the number of delivery requests
- Minimisation of access privileges to the database, storage, and servers
- Monitoring of access and error logs and operation of incident response procedures
- Separate management of production secrets, certificates, and API keys
- Recording of the handler, reason, and time for key operational actions such as account status changes
If a personal information breach occurs or the Company becomes aware that one has occurred, the Company will notify users and report to the relevant authorities in accordance with applicable law, and will take measures to prevent the spread of harm and to analyse the cause.
19. Privacy Officer and Contact
Enquiries about the processing of personal information, requests for access, correction, deletion, or suspension of processing, complaints, and requests for remedy may be sent to the following contact details.
- Data controller: newfrom Co., Ltd. (주식회사 뉴프롬)
- Representative: Chanseok Hong (홍찬석)
- Business registration number: 215-87-38206
- Privacy officer: Chanseok Hong (홍찬석), Director
- Department: Personal Information Protection
- Email: help@newfrom.net
- Address: 10, Seonyu-ro 9-gil, Yeongdeungpo-gu, Seoul, Republic of Korea
- Hours: Email enquiries accepted at all times; replies are sent in order on business days
20. Remedies for Infringement of Rights
Users may contact the following organisations for advice on personal information infringement or for dispute resolution.
- Personal Information Infringement Report Centre: 118 (within Korea) / https://privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972 / https://www.kopico.go.kr
- Supreme Prosecutors’ Office Cybercrime Investigation Division: 1301 (within Korea)
- Korean National Police Agency Cyber Bureau: 182 (within Korea)
- Privacy portal: https://www.privacy.go.kr
21. Changes to this Privacy Policy
The Company will amend this Privacy Policy where there is a change in applicable law, the Service, the categories processed, processors, transfers abroad, retention periods, or privacy officer details.
Material changes will be announced at least seven days before they take effect through a Service screen, email, in-app notification, or another reasonable method. Where a change is unfavourable to users, or where the law requires a longer period, that period will apply.
The Company maintains a record of amendments together with effective dates so that previous versions can be identified.
22. Legal Bases for Processing
Where data protection law requires the Company to have a legal basis for processing your personal information, it relies on the bases below. The purposes are those listed in Section 2.
| Processing | Legal basis |
|---|---|
| Creating and managing your account, email verification, password reset | Performance of the contract between you and the Company (the Terms of Service) |
| Connecting trainers and members, creating and assigning programs, recording workouts, exchanging feedback, managing organizations and their materials | Performance of the contract |
| Verifying the identity of business organizations and reviewing business registration certificates | Performance of the contract, and compliance with a legal obligation where the applicable law requires the Company to confirm who is operating as a business |
| Workout records: repetitions, load lifted, duration, distance, pace, rest intervals, rate of perceived exertion, and the sessions in which they were recorded | Performance of the contract. As explained in Section 5, these are measurements of training performance and are not treated as data concerning health |
| Free-text notes, feedback messages, photographs, and videos, to the extent that what you write or upload reveals pain, injury, symptoms, pregnancy, medication, or a physical limitation | Your explicit consent, which you give by choosing to write or upload that content after agreeing to this Policy at registration. You may withdraw it at any time by deleting the entry or closing your account, which does not affect processing carried out before withdrawal. Entries that do not reveal such information are processed for the performance of the contract |
| Push notifications and device tokens | Your consent, given when you allow notifications on your device. You may withdraw it in the app or in your device settings |
| Service announcements, security notices, and notices about changes to the Terms or this Policy | Performance of the contract, and the Company’s legitimate interest in keeping users informed about the service they use |
| Security, incident response, abuse prevention, access and error logs, limits on email requests | The Company’s legitimate interest in keeping the Service and its users secure, balanced against your interest in not being monitored beyond what security requires |
| Handling enquiries, reports, disputes, use restrictions, and objections | Performance of the contract, the Company’s legitimate interest in defending legal claims, and compliance with a legal obligation where an authority requires it |
| Support enquiries submitted by people who do not hold an account, including the reply email address, the lookup password hash, the enquiry content, and the submission IP | The Company’s legitimate interest in answering people who contact it about the Service, balanced against their interest in not having more retained than a reply requires. There is no contract with an enquirer who holds no account, so the Company does not rely on performance of a contract here. The lookup password hash, submission IP, and lookup attempt records rest on the Company’s legitimate interest in ensuring that only the person who submitted an enquiry can read it and in preventing abuse of the enquiry form |
| Retaining records for the periods in Section 7 | Compliance with a legal obligation, and the Company’s legitimate interest in defending legal claims |
| App version checks and update guidance | Performance of the contract, and the Company’s legitimate interest in keeping supported versions secure |
| Statistics and model training using anonymised data | Not applicable. Once data is anonymised it is no longer personal information. The anonymisation itself rests on the Company’s legitimate interest in improving the Service |
Where the Company relies on legitimate interests, you may object under Section 23. Where it relies on consent, you may withdraw it at any time without affecting processing carried out before you withdrew it.
23. Additional Information for Users in the European Economic Area and the United Kingdom
This Section applies to you if you are in the European Economic Area or the United Kingdom.
Controller. newfrom Co., Ltd. (주식회사 뉴프롬), whose details are in Section 19, decides why and how your personal information is processed.
Representative. Article 27 of the GDPR and of the UK GDPR requires a controller outside those territories to designate a representative there.
| Territory | Representative |
|---|---|
| European Economic Area | Not yet designated. Until a representative is appointed, contact the Company at help@newfrom.net |
| United Kingdom | Not yet designated. Until a representative is appointed, contact the Company at help@newfrom.net |
Your rights. In addition to the rights in Section 14, you have the following rights, which you may exercise by writing to help@newfrom.net.
| Right | What it means |
|---|---|
| Access | Obtain confirmation of whether your personal information is processed and a copy of it |
| Rectification | Have inaccurate information corrected and incomplete information completed |
| Erasure | Have your information deleted where it is no longer necessary, where you withdraw consent, or where you object and there is no overriding ground to keep it |
| Restriction | Have processing limited while a dispute about accuracy or a legitimate interest is resolved |
| Portability | Receive the information you provided in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible |
| Objection | Object at any time to processing based on legitimate interests, on grounds relating to your situation |
| Withdrawal of consent | Withdraw consent at any time, without affecting processing carried out before the withdrawal |
| Not to be subject to automated decisions | The Company does not make decisions about you by automated means alone that produce legal or similarly significant effects |
The Company answers requests within one month. Where a request is complex or you have made several, the Company may extend that period by two further months and will tell you why within the first month. Exercising these rights is free unless a request is manifestly unfounded or excessive.
Complaints. You may lodge a complaint with the data protection authority of the member state where you live or work, or where you believe an infringement occurred. In the United Kingdom this is the Information Commissioner’s Office, https://ico.org.uk. A list of authorities in the European Economic Area is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
International transfers. Section 12 explains where your information goes. Transfers to the Republic of Korea are covered by the adequacy decisions described in that Section. For transfers to Zoho Corporation and Google LLC in the United States, the safeguard relied on is the set of standard contractual clauses approved by the European Commission, together with the United Kingdom addendum, contained in the data processing terms of each provider. You may obtain information about the safeguard applied to a particular transfer by writing to help@newfrom.net.
Retention. Section 7 states how long each category is kept. Where no period is stated, the Company keeps information only for as long as the purpose in Section 22 requires, and then deletes or anonymises it.
24. Additional Information for Users in the United States
This Section applies to you if you are located in the United States.
Consumer health data. Information you enter about your body, your symptoms, your training, and photographs or videos of yourself is consumer health data under the laws of some states, including the Washington My Health My Data Act and Nevada Senate Bill 370.
| Question | Answer |
|---|---|
| What consumer health data is collected | Free-text session notes, set notes, and feedback messages, photographs and videos you upload, and consultation notes a trainer records, to the extent that they describe pain, injury, symptoms, pregnancy, medication, or a physical limitation. Workout measurements such as repetitions, load, duration, distance, and perceived exertion describe training performance rather than health status, and the Service holds no body metric such as weight, body fat, or heart rate and does not read data from any health platform on your device |
| How it is collected | You enter it, or a trainer connected to you enters it on your behalf as described in Section 4 |
| Why it is collected | To provide workout planning, logging, and feedback, as described in Section 2 |
| Who it is shared with | The trainer you are connected to, and the organization administrators of that trainer’s organization, as described in Section 10. It is also stored by the Company’s hosting and storage processor listed in Section 11 |
| Whether it is sold | No. The Company does not sell consumer health data and does not offer it in exchange for anything of value |
| How to withdraw consent | Delete the information in the app, end your connection with a trainer, or close your account, which deletes it as described in Section 7. You may also write to help@newfrom.net |
| How to have it deleted | Close your account under Section 7, which deletes it, or write to help@newfrom.net. The Company will confirm deletion and will tell its processors to delete it |
| Who to contact | help@newfrom.net. Section 19 has the Company’s full details |
The Company does not use consumer health data for advertising, does not use it to infer characteristics unrelated to the Service, and does not geofence any healthcare facility.
State privacy rights. Depending on the state in which you live, you may have the right to know what personal information is collected and how it is used, to obtain a copy, to correct it, to have it deleted, and to be free from discrimination for exercising these rights. Write to help@newfrom.net to exercise them. The Company will verify your identity through the email address on your account before acting.
No sale or sharing. The Company does not sell personal information and does not share it for cross-context behavioural advertising. It has not done so in the preceding twelve months.
Children. The Company does not knowingly collect personal information from children under 13, as described in Section 6.
Addenda
This Privacy Policy is the first version and takes effect on 3 August 2026.
Amendment of 10 August 2026
The following was amended when the enquiry desk opened on the support page of the service introduction site. Notice is given seven days before the effective date, as required by Section 21.
- Section 1: the scope now covers the service introduction site and enquirers who hold no account.
- Section 2: receiving support enquiries regardless of account status, verifying the enquirer, and posting replies were added to the purposes.
- Section 3:
Enquiry informationandEnquiry lookup attempt informationwere added to the categories processed. - Section 5: it is now stated that the enquiry body is a free-text field and that users are advised not to enter sensitive information there.
- Section 7: the retention period for enquiry information (one year from the latest activity) was added, together with the fact that it is retained regardless of account closure.
- Sections 11 and 12: enquiry receipt and reply notices were added to the delegated email delivery work.
- Section 22: a legal basis was added for enquiries from people who hold no account, since performance of a contract does not apply to them.