מדיניות פרטיות
StudiU Privacy Policy
Effective date: 4 September 2026
Version: 1.3
StudiU is a platform for studios and personal trainers. It is operated by TA Fitness, also trading under the name StudiU (“StudiU”, “we”, “us” or “our”). This Privacy Policy explains how we handle personal data when you visit our website, contact us, request a demo, represent a customer studio, use a StudiU business account, or interact with StudiU in another context where we determine why and how your data is used.
StudiU also processes member and staff data on behalf of customer studios. In that situation, the studio is normally the data controller and StudiU is its processor. Section 3 explains this distinction.
1. Who we are
Controller: TA Fitness, also trading under the name StudiU
Legal form: Sole proprietorship registered in the Netherlands
KvK number: 62960652
Address: Eleanor Rooseveltlaan 106, 1183 CL Amstelveen, the Netherlands
Privacy contact: Tal Assa
Email: empower@nextlevelams.nl
We have not appointed a formal Data Protection Officer. Privacy requests and questions can be sent to the contact above.
2. Who this policy covers
This policy covers:
- visitors to the StudiU website;
- people who contact us or request a demo;
- owners, representatives, administrators and staff of customer studios;
- StudiU business-account users;
- support, billing and marketing contacts;
- parents, guardians and third-party payers whose own data is processed through StudiU;
- members to the extent StudiU independently determines a processing purpose.
NXT LVL Personal Training has its own member and staff privacy information. This policy is not a replacement for those notices.
3. When a studio controls member data
When a customer studio uses StudiU to manage its members or staff, that studio normally decides why the data is collected, which data is required, how long it is retained, and who may access it. The studio is the controller and StudiU processes the data under the studio's documented instructions and our Data Processing Agreement.
This may include:
- identity and contact details, address, date of birth and profile photo;
- guardian, emergency-contact and third-party-payer information;
- accounts, roles, permissions, authentication and security records;
- memberships, subscriptions, bookings, attendance and purchase history;
- invoices, payment status, IBAN and SEPA mandate information;
- messages, documents, waivers and trainer notes;
- optional health, injury, fitness, progress and body-measurement data;
- consent, preference and withdrawal records;
- optional adult-only AI interactions, suggestions and approval records;
- migration data supplied by the studio or its former system.
Members should first contact their own studio to exercise privacy rights or ask how their information is used. If a member contacts StudiU directly, we will normally forward the request securely to the responsible studio and assist it. We do not use an external studio's member list to market StudiU or NXT LVL.
Each studio must provide its own privacy information and have a valid legal basis, including an Article 9 GDPR condition where it uses health data.
4. Personal data we collect as controller
Depending on your relationship with us, we may process:
Website and demo information
- name, email address and telephone number;
- role, business name, business type and business website or social-media page;
- approximate numbers of clients and staff;
- information about your current systems, business needs and demo requests;
- requested language, appointment details and correspondence;
- the version of the privacy information shown and the date/time it was acknowledged;
- technical request, security and abuse-prevention information, including IP or pseudonymous identifiers processed by our infrastructure providers, and a pseudonymous (hashed) IP identifier that we store ourselves with the enquiry for abuse prevention. We do not store the raw IP address you submit the demo form from.
Please do not include health information or other unnecessary sensitive data in the demo form.
Customer and business-account information
- name, business contact details, organisation, role and permissions;
- account, login, authentication, session and device information;
- customer configuration, service usage and administrative actions;
- support requests and communications;
- contracts, service selections and account status;
- invoices, payment status, refunds and financial-administration records;
- security, access and audit logs.
Marketing information
- email address or telephone number;
- brand, studio, channel and subjects you selected;
- the consent wording/version, date, time, source and withdrawal history;
- a minimal suppression record after opt-out so we do not add you again.
Marketing is optional. Service messages, such as security alerts, appointment information, invoices and important service changes, are not marketing.
Information from other sources
We may receive information from your employer or studio, a referral, Mollie, our service providers, or a previous system during a customer-authorised migration. If data was not obtained from you directly, the relevant controller must inform you as required by law.
5. Why we use data and our legal bases
We use personal data for the following purposes:
| Purpose | Legal basis where StudiU is controller |
|---|---|
| Respond to enquiries, arrange a demo and take requested pre-contract steps | Contract/pre-contract steps where applicable; otherwise our legitimate interest in responding to business enquiries |
| Create and administer customer accounts and provide the StudiU service | Performance of a contract; legitimate interests for representatives of business customers |
| Customer support, service communications and account administration | Contract and our legitimate interest in operating and supporting the service |
| Invoicing, accounting and compliance with tax/administrative duties | Legal obligation and contract |
| Platform, account and network security; fraud, misuse and incident prevention | Our legitimate interest and the interests of customers and users in a secure service |
| Maintain access, approval, migration and audit records | Our legitimate interest in accountability, security and dispute handling; legal obligation where applicable |
| Optional marketing from StudiU | Consent |
| Optional AI functionality for our direct users | Consent or performance of the specifically requested optional service, depending on context |
| Aggregated service and website statistics | Our legitimate interest in understanding and improving the service, provided the data is minimised and not used for advertising tracking |
| Establish, exercise or defend legal claims | Our legitimate interest and legal obligations |
When we act only as a processor, the customer studio determines the legal basis. We do not use consent where processing is necessary and withdrawal would not be genuinely possible.
6. Required and optional information
The information required depends on the selected service:
- a name and email address are normally required to create and administer an account;
- a billing/residential address may be required for a subscription, invoicing, payment reminders or recovery of contractual amounts;
- an IBAN and payment information are required only when direct debit or another relevant recurring-payment method is selected;
- health information, measurements, profile photos, emergency contacts, WhatsApp, AI and marketing are optional;
- a verified date of birth or under-18 status is required where age affects guardian authority or access to adult-only features.
If required service information is not provided, the relevant account, payment method or feature may not be available. Refusing optional processing does not prevent access to the core service.
7. Health data and minors
Health, injury and some fitness/measurement information can be special-category data under the GDPR. Customer studios are responsible for obtaining a valid Article 9 condition, normally including separate explicit consent where appropriate, and for collecting only relevant information. StudiU applies additional access and security controls to this data.
Where consent is relied upon for a person under 16 in the Netherlands, the legal representative's consent is generally required. Guardian authority, health consent, membership acceptance and payer/SEPA approval must be recorded separately. Children should also receive an age-appropriate explanation.
StudiU's AI functionality is restricted to adults. Data from accounts identified as belonging to people under 18 must not be sent to Anthropic.
8. Artificial intelligence
Studios may choose an optional AI feature powered through the commercial Anthropic API using Claude models (currently Claude Haiku and Claude Sonnet). It can answer limited questions about an adult user's subscription or schedule and suggest, prepare or — where the studio has enabled this — carry out actions within the permissions and rules described below.
- Users are told when they are interacting with AI and can contact a human.
- The feature is optional and can be disabled or withdrawn.
- Consequential bookings, billing, contractual, account or record actions are carried out only to the extent the studio has enabled them: on the basis of a person's explicit instruction, an automation rule configured by the studio or the user, or affirmative approval from an authorised person. Every action is logged and can be reviewed and reversed by the studio, and a person can always be involved.
- The system minimises and pseudonymises context before transmission. Direct contact details, addresses, IBANs, health information, trainer notes and unrestricted message history are not permitted in AI prompts. The only health-related exception is the scan feedback described below, which transmits derived scan figures under the member's explicit consent.
- Server-side permissions determine which data and actions are available; the model cannot grant itself access.
- Data belonging to one studio is not used in another studio's AI context.
- Customer data is not permitted to be used to train Anthropic or StudiU generative models.
- StudiU does not use AI to make solely automated decisions that produce legal or similarly significant effects.
Studios may additionally enable AI-written feedback on body scans. When a studio switches this on, the app generates a short training-focused paragraph about a member's own scan results, shown in the member app and to studio staff and labelled as AI-assisted. Only derived figures are transmitted for this purpose: rounded scan values, changes since the previous scan, session counts and activity types. The member's name, contact details, date of birth, raw scan data and scan report are never included. Because these derived figures concern health, the paragraph is only generated for adult members whose explicit health-data consent (Article 9 GDPR) is in force; withdrawing that consent stops generation and hides existing paragraphs. Studio staff can also hide or regenerate a paragraph at any time, and the feedback never contains medical advice or a diagnosis.
Raw AI prompts and responses are normally retained for no longer than 30 days. Approval/action audit records may be retained for up to 24 months; financial records follow the applicable financial-retention period.
9. Payments and SEPA direct debit
Each customer studio generally connects its own Mollie merchant account. Mollie processes payments for its own payment, fraud-prevention and regulatory purposes and provides its own privacy information.
StudiU may process the Mollie customer/merchant identifier, transaction and payment status, account-holder name, IBAN, BIC, unique mandate reference, signature date and mandate status on the studio's instructions. Full IBANs are restricted and masked where full display is unnecessary. They are not used for marketing, analytics or AI.
StudiU does not store card verification codes, PINs or full payment-card credentials. When the payer is not the member, such as a parent paying for a child, the payer must accept their own SEPA mandate and is treated as a separate data subject.
10. Who receives personal data
Access is limited to authorised people who require it for service operation, support, security, migration or administration and who are subject to confidentiality obligations. Customer-studio users see information according to their role and permissions.
Depending on the enabled features, the following providers may process data:
- Supabase: database, authentication and storage; the primary project region is Frankfurt, Germany;
- Vercel: website/application hosting and privacy-focused Web Analytics. Application functions execute in the European Union (Frankfurt, Germany), the same region where the database is stored;
- Resend: transactional and consented marketing email;
- Cloudflare: Turnstile and abuse/bot protection; and encrypted off-site backup storage (R2, EU jurisdiction). Backups are encrypted before they leave our systems with keys held only by us, so Cloudflare cannot access their contents;
- Anthropic: optional adult-only AI processing through the commercial API;
- Sentry: error and reliability monitoring configured to minimise personal data;
- Google Workspace: business email, calendar, meetings and documents;
- Mollie: payment processing, as described above;
- WhatsApp Business/Meta: optional operational messaging where selected by the studio or user.
We may also disclose limited information to professional advisers, auditors, insurers, competent authorities or courts where reasonably necessary or legally required. We do not sell personal data.
Our current subprocessor information and transfer safeguards can be requested at empower@nextlevelams.nl.
11. International transfers
Some providers or their subprocessors may process personal data outside the European Economic Area, including in the United States. Where an applicable adequacy decision does not cover the transfer, we use safeguards such as the European Commission's Standard Contractual Clauses and, where appropriate, supplementary technical and organisational measures.
Application hosting and function execution, database storage and backup storage are all located in the European Union. Transfers outside the EEA are limited to the specific provider services described in section 10.
You may request more information or a copy of the relevant safeguards, subject to necessary redactions for confidential or security-sensitive information.
12. Cookies, browser storage and analytics
StudiU uses storage that is necessary for authentication, security, language or service preferences. Cloudflare Turnstile processes technical device and network information to protect forms and may, depending on security configuration, use a necessary security cookie.
Vercel Web Analytics is configured as a cookieless, privacy-focused analytics service. It provides aggregated information such as pages, referrers, general location, browser, device and operating-system categories. We do not intentionally send names, contact details, form answers, member identifiers, health data or payment information in analytics events.
We do not use advertising or retargeting trackers. If we introduce non-essential cookies or tracking in the future, we will provide information and obtain consent before they are activated where required.
13. Retention
We retain personal data only for as long as needed for the stated purpose, customer instructions, legal obligations or a documented legal claim.
Our usual controller retention periods are:
- demo enquiries that do not convert: 12 months after the demo or last meaningful contact;
- customer account data: for the customer relationship, then normally 12 months, unless a longer period applies to a specific record;
- invoices, payment and core accounting records: 7 years;
- closed support requests: 24 months; sensitive attachments are normally deleted within 90 days after resolution;
- ordinary security/access logs: 12 months; actual incident records may be kept for up to 5 years or until the matter is resolved;
- marketing consent evidence: as needed to demonstrate consent, normally up to 5 years after the relevant marketing; a minimal opt-out record is retained while marketing continues;
- AI data: as described in section 8.
For studio-controlled member data, StudiU follows the studio's documented instructions and configured periods. Platform defaults normally delete or anonymise ordinary member data within 12 months after membership ends, subject to shorter studio instructions and legally required financial/mandate records. Temporary successful-migration files are normally deleted within 7 days and raw migration packages within 30 days after studio approval.
After a studio contract ends, the studio normally has a 30-day export/recovery window before production data is deleted. Encrypted backup copies expire through the normal backup cycle, within a maximum of 90 days. If a backup is restored, previous deletion instructions are reapplied.
14. Security
We use technical and organisational measures appropriate to the nature and risk of the processing. These include role-based and tenant-separated access, multi-factor authentication for privileged roles, encryption in transit and at rest, additional protection and masking for sensitive data, access/audit logs, session controls, backups, vulnerability management and incident procedures.
No system can guarantee absolute security. If a personal-data breach occurs, we document and address it, notify affected customer studios without undue delay when we act as processor, and make regulatory or individual notifications where required.
15. Your rights
Subject to the GDPR's conditions and exceptions, you may have the right to:
- access your personal data and receive a copy;
- correct inaccurate or incomplete data;
- request deletion;
- restrict processing;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- receive data in a portable format where applicable;
- withdraw consent at any time, without affecting earlier lawful processing;
- request human involvement where legally relevant automated decision-making applies.
For data controlled by an external studio, contact that studio first. For data controlled by StudiU, email empower@nextlevelams.nl. We may verify your identity, for example through a one-time code sent to the registered email address. We normally respond within one month.
Deletion is not absolute. Limited information may be retained where necessary for tax, payment, mandate, security, dispute or other legal obligations, with access restricted to that purpose.
You may lodge a complaint with the Dutch Data Protection Authority: Autoriteit Persoonsgegevens.
16. Marketing and communications
We send electronic marketing only where the recipient has opted in or another specific legal exception applies. Consent is separated by sender, brand and channel. Every marketing message identifies the sender and provides a free, easy opt-out.
StudiU marketing is limited to opted-in StudiU business contacts and leads. NXT LVL manages its own marketing. External studios control their own member marketing through StudiU. We do not combine these lists or use an external studio's member data for StudiU or NXT LVL advertising.
WhatsApp is optional. Users can use an available email or in-app alternative. Detailed health, financial and trainer-note information should remain inside StudiU rather than WhatsApp.
17. Changes to this policy
We may update this policy when our services, providers or legal obligations change. The current version and effective date are published on this page. We will notify affected users by email before material changes take effect. Where a new purpose requires consent, we will request new consent before starting it.
18. Contact
Questions or requests can be sent to:
Tal Assa — StudiU privacy contact
Email: empower@nextlevelams.nl
Address: Eleanor Rooseveltlaan 106, 1183 CL Amstelveen, the Netherlands