Skip to content

Privacy Policy

This privacy policy explains what Personal Data this Website collects, why it collects it and what rights the User has. It covers visitors to the Website and anyone who writes to the Controller through the contact form; gym membership has its own privacy notice, provided at the gym.

Summary

This Website collects little Personal Data, and only for the purposes described in this document. In short:

  • Data collected automatically: Usage Data, processed by Vercel Inc. to host the Website and for aggregate visit statistics.
  • Data provided by the User: the data entered in the contact form, processed by Vercel Inc. and Aruba S.p.A. to reply to the request.
  • Third-party content: the Google Maps map, loaded only if the User asks for it.

Data Controller

The Controller is the company that runs the gym and this Website. Users can contact the Controller at the details below with any question about the processing of their Data or to exercise the rights described in this document.

Zenfit Diano S.S.D.
Via Diano Calderina, 18013 Diano Marina (IM), Italy
VAT no. 01824260085
info@zenfitdiano.it
+39 0183 086296

Types of Data collected

Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Website.

In the contact form, name, email and message are required: without this Data the Controller could not reply. Phone number, experience level and activity of interest are optional, and Users are free not to provide them without any effect on the reply.

The Controller asks Users not to include health data in the form, such as injuries, medical conditions or medical certificates: if relevant to choosing the right class, it is best discussed in person at the gym.

Among the Personal Data collected by this Website, either independently or through third parties, are:

  • Usage Data;
  • name, email address and message text;
  • phone number, experience level and activity of interest, if provided;
  • third-party Tracking Tools, only if the User loads the Google map.

Methods of processing

The Controller takes appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of Personal Data.

Processing is carried out using IT and telematic tools, following procedures strictly related to the purposes indicated. In addition to the Controller, the Data may be accessed by the gym staff who handle enquiries, by whoever maintains the Website and by the technical service providers listed in this document, appointed as Data Processors under Article 28 GDPR.

The Data is not sold or published, is not used to send marketing communications and is not subject to profiling or to automated decision-making under Article 22 GDPR.

Place of processing

The Data is processed at the Controller's premises and wherever the Data Processors are located. The Controller's mailbox is hosted by Aruba S.p.A. in Italy; the Website, however, runs on the infrastructure of Vercel Inc., a US company, so Usage Data, statistics and the content of the form while it is being sent may also be processed in the United States.

Transfers to the United States rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework, in which Vercel participates, and on the standard contractual clauses in its data processing agreement.

If the User loads the map, Google may also process the Data outside the European Union, with the safeguards described in its own privacy policy.

Retention period

Personal Data is kept for as long as required by the purposes for which it was collected, and longer only where required by law or needed to protect the Controller's rights. At the end of the retention period it is deleted.

In particular:

  • messages received through the form stay in the Controller's mailbox for as long as needed to handle the request, and no longer than two years after the last exchange; the Website keeps no copy;
  • if the User joins the gym, from then on the privacy notice provided at the gym applies;
  • Usage Data recorded by Vercel can be viewed by the Controller for one day at most, while Vercel may keep it longer for the security of its infrastructure;
  • the IP address used to limit form submissions stays in the server's memory for ten minutes, without being written to disk;
  • the code that tells visits apart in the statistics is deleted after 24 hours.

Purposes and legal bases

The User's Data is collected for the following purposes, each with its own legal basis:

  • replying to enquiries and confirming receipt: steps taken at the User's request before entering into a contract, where the enquiry concerns membership, classes or prices (Article 6(1)(b) GDPR), and the Controller's legitimate interest in replying in other cases (Article 6(1)(f));
  • running the Website, keeping it secure and blocking spam: the Controller's legitimate interest in the security of the service (Article 6(1)(f) GDPR);
  • counting visits in aggregate: the Controller's legitimate interest in improving the Website (Article 6(1)(f) GDPR); these statistics meet the conditions under which the Italian Data Protection Authority's guidelines of 10 June 2021 treat them like technical tools, and therefore do not require consent;
  • displaying the Google map: the User's consent (Article 6(1)(a) GDPR and Article 122 of the Italian Privacy Code), given by pressing the button that loads it;
  • complying with legal obligations or requests from the authorities (Article 6(1)(c) GDPR) and, where necessary, protecting the Controller's rights (Article 6(1)(f)).

Contact management and messaging

The contact form sends the message to the Controller's mailbox and, right after, sends an automatic confirmation to the User's address, in the language the User was browsing in. The privacy checkbox records that this document has been read and is not consent to marketing communications.

To block automated submissions, the form contains a hidden field and measures the time between opening the page and sending; the server also limits how many messages can be sent from the same IP address within ten minutes.

Users who contact the Controller by email, phone or WhatsApp provide their contact details, which are used only to reply. On WhatsApp, WhatsApp's own privacy policy also applies, since it runs the service.

  • Companies: Vercel Inc. (form submission) and Aruba S.p.A. (email)
  • Place of processing: United States and Italy
  • Personal Data processed: name, email, phone number, experience level, activity of interest and message text

Hosting and infrastructure

This service hosts the files and Data that allow this Website to run. With every request, Vercel receives and records some Usage Data, such as IP address, date and time, requested page, browser and operating system, to run the Website and protect it from abuse and attacks.

  • Company: Vercel Inc.
  • Place of processing: United States
  • Personal Data processed: Usage Data

Statistics

To know how many visits the Website receives and which pages are read most, the Controller uses Vercel Web Analytics, which sets no Cookies and stores nothing on the User's device. For each page view it records the page address, the referring site, browser and operating system, device type, approximate location (country, region and city, derived from the IP address) and the time.

Visits are told apart by a code computed from the request and deleted after 24 hours; the IP address is not stored with this data, and the Controller only sees aggregate totals.

  • Company: Vercel Inc.
  • Place of processing: United States
  • Personal Data processed: Usage Data

Displaying content from external platforms

The Contact page shows a Google Maps map, which loads only when the User presses 'Show the map': until then, the browser does not contact Google. Once loaded, Google receives the IP address, browser data and interactions with the map, and may use its own Cookies.

Pressing the button counts as consent, which is not stored: on the next visit the map is off again. Google Ireland Limited processes this Data as an independent controller, under its own privacy policy.

  • Company: Google Ireland Limited
  • Place of processing: Ireland
  • Personal Data processed: Usage Data and Tracking Tools

Cookie Policy

This Website does not use Cookies: it stores only two pieces of technical information in the browser, and loads third-party content only when the User asks for the map. The WhatsApp, Instagram and Facebook buttons are plain links; by following them the User leaves the Website and that platform's privacy policy applies.

To find out more, the User can consult the Cookie Policy.

Rights of the User

Within the limits set by law, the User has the right to:

  • withdraw consent at any time, for processing based on it;
  • object to the processing of their Data where it is based on the Controller's legitimate interest, on grounds relating to their particular situation;
  • access their Data and receive a copy of it;
  • verify and seek rectification of their Data;
  • restrict the processing of their Data;
  • have their Data erased;
  • receive their Data in a structured, machine-readable format, or have it transferred to another controller, where processing is based on consent or a contract;
  • lodge a complaint with the Italian Data Protection Authority, or with the authority of the EU country where they live, work or where the breach took place, or take legal action.

How to exercise these rights

Requests can be sent to the Controller at the email address given in this document. Requests are free of charge and the Controller replies within one month; for complex requests this may be extended by two months, in which case the User is informed within the first. If there are doubts about the requester's identity, the Controller may ask only for the information needed to confirm it.

The statistics do not make it possible to identify the User, so the Controller cannot pick out the User's visits from the others (Article 11 GDPR); anyone who prefers not to be counted can disable JavaScript for this Website in their browser settings. Any Cookies set by Google can be deleted in the same settings.

Additional information about processing

Personal Data may be used by the Controller in legal proceedings, or in the steps leading to them, to defend against abuse of this Website. The Controller may also be required to disclose the Data upon request of public authorities.

More information about the processing of Personal Data can be requested from the Controller at any time, using the contact details given in this document.

Changes to this privacy policy

The Controller may change this privacy policy at any time, giving notice on this page; the date of the latest update is shown at the bottom. Where changes affect processing based on consent, the Controller will collect consent again if necessary. Previous versions can be requested from the Controller.

Definitions and legal references

This document is drawn up under Article 13 of Regulation (EU) 2016/679 (GDPR) and concerns this Website only. In the text, the following terms have this meaning:

  • Personal Data (or Data): any information that, directly or indirectly, identifies or makes identifiable a natural person.
  • Usage Data: information collected automatically while browsing, such as IP address, date and time of the request, page visited, referring page, browser, operating system and device type.
  • User: the natural person who uses this Website and to whom the Personal Data refers.
  • Data Controller (or Controller): the company named in the 'Data Controller' section, which determines the purposes and means of processing.
  • Data Processor (or Processor): anyone who processes Personal Data on behalf of the Controller.
  • Tracking Tool: any technology, such as Cookies, browser storage or unique identifiers, that makes it possible to store or read information on the User's device.
  • This Website: the zenfitdiano.it website, through which the Data described in this document is collected.

Latest update: 22 September 2026