Privacy Policy

privacy policy

1 May, 2026

1 May, 2026

Privacy and Cookie Statement: GezondRijk app

This privacy and cookie statement was last updated on 1 May 2026.

This privacy statement applies specifically to the GezondRijk app, a walking and lifestyle app published by NEC Nijmegen as part of the GezondRijk programme. The GezondRijk app runs on the Fittar platform.

Roles and responsibilities

  • NEC Nijmegen is the partner and publisher of the GezondRijk app. The app is distributed under NEC's Apple App Store and Google Play developer accounts.

  • Fittar B.V. ('Fittar') operates the underlying platform, develops the app, and is responsible for the processing of personal data described in this statement. For privacy purposes, Fittar B.V. acts as the data controller for the data processed within the GezondRijk app.

During the processing of personal data, Fittar works in accordance with the requirements of the applicable data protection legislation, including the General Data Protection Regulation (GDPR). This means we:

  • clearly specify our purposes before we process personal data, by using this privacy and cookie statement;

  • limit our collection of personal data to only the personal data needed for legitimate purposes;

  • first ask for explicit permission to process your personal data in cases where your permission is required;

  • take appropriate security measures to protect your personal data and we demand the same from parties who process personal data on our behalf;

  • respect your right to access, correct or delete your personal data held by us.

Your personal data is safe with us and we will always use it properly. In this privacy and cookie statement, we explain what kind of personal data we collect and for which purposes when you use the GezondRijk app. We recommend that you read it carefully.

If you have any questions regarding the processing of personal data, you can find our contact details at the end of this statement.

Account creation and use of the app

To use the GezondRijk app you create an account. We use the following personal data to create and maintain your account:

  • name;

  • email address;

  • password (stored as a hash, not in readable form);

  • date of birth or age;

  • profile picture (optional);

  • preferred language;

  • IP address.

You can register either by entering an email address and password, or by signing in with Google.

Sign in with Google. When you choose to sign in with Google, we receive your name, email address, and your Google profile picture from Google. We do not receive your Google password. You can read more about how Google handles this in Google's own privacy policy.

We process this data because we need it to provide the service to you (performance of contract). We store this information for as long as your account is active and up to 2 years after you close your account, so we can contact you in connection with the execution of the agreement, invoicing and payment, and to provide an overview of the products and services you have purchased from us. Certain data may be retained longer where required by law (for example, tax retention obligations).

Subscriptions and payments

To use all the functionalities of the GezondRijk app, you can take out a paid subscription. Subscriptions are processed through the Apple App Store, Google Play, or through our subscription provider RevenueCat. We use the following data to manage your subscription:

  • subscription status;

  • start and end date of your subscription;

  • transaction identifiers from Apple, Google or RevenueCat.

We do not receive or store your full payment card details. These are handled directly by Apple, Google and their respective payment processors. We process this data because we need it to provide the paid service to you (performance of contract).

Health and activity data (Health Connect / Apple Health)

The GezondRijk app helps you build a healthier lifestyle by giving you insight into your daily activity. With your explicit permission, the app reads activity data from Health Connect (on Android) or Apple Health (on iOS).

Depending on which permissions you grant, we may read the following data types:

  • steps;

  • distance walked;

  • active minutes;

  • calories burned;

  • heart rate (where available);

  • weight and height (only if you enter or share these).

What we do with this data:

  • show your daily and weekly progress inside the app;

  • track your participation in walking challenges and the GezondRijk walking programme;

  • personalise tips and feedback in the app and via the optional WhatsApp Coach;

  • aggregate and anonymise data for service improvement.

What we do not do:

  • we do not sell your health data to third parties;

  • we do not use your health data for advertising;

  • we do not share identifiable health data with NEC or other partners.

You control these permissions at all times in your device settings. You can revoke access through Health Connect or Apple Health at any moment, and you can delete the data we hold about you by deleting your account or contacting us.

The legal basis for processing health data is your explicit consent (Article 9(2)(a) GDPR). We store this information until you delete your account or withdraw your permission.

Location data and walking routes

The GezondRijk app includes walking routes, including a route with historical checkpoints created for NEC's 125th anniversary. To make these features work, the app uses your device's location.

We use location data for the following purposes:

  • showing your position on the walking route map;

  • recording the route you walk so we can show you your distance and progress;

  • validating QR-code checkpoints during themed walking routes;

  • enabling deep links from QR codes to the right place in the app.

How we handle your location:

  • location is only collected while you are actively using a walking route or scanning a checkpoint;

  • you can grant 'while using the app' permission rather than 'always allow';

  • you can revoke location permission at any time through your device settings;

  • we do not share your location with NEC or with advertisers;

  • routes you have walked are stored in your account so you can see your history.

The legal basis for processing location data is your consent and the performance of our agreement with you. We store walked routes for as long as your account is active.

Push notifications

If you allow it, the GezondRijk app sends push notifications to remind you of walks, challenges, and tips. We use OneSignal to deliver these messages. For this purpose we process a device token (an anonymous identifier issued by Apple or Google) and the content of the notification.

You can disable push notifications at any time in your device settings.

WhatsApp Coach

The GezondRijk app includes an optional WhatsApp Coach: a buddy that helps you stick with your goals through WhatsApp messages. When you use this feature:

  • your WhatsApp messages are processed through WhatsApp, operated by Meta Platforms, Inc.;

  • Meta acts as a controller for the WhatsApp message infrastructure. Please refer to Meta's privacy policy for details on how they process your data;

  • the content of your conversations with the coach is stored in our system to give you continuity and to personalise responses;

  • your messages may occasionally be accessed in anonymised form by our development team to ensure proper functioning and to improve the service;

  • a support staff member may take over a conversation if you indicate that you are stuck or need direct assistance.

You can stop using the WhatsApp Coach at any time by sending 'stop' or by switching it off in the app.

Contact form and customer support

You can contact us through the in-app support feature, by email, or via the contact form on our website. For this we use:

  • your name;

  • your email address;

  • your phone number (if you provide it);

  • any other personal information you provide in your message.

We use this information to answer your question and to improve our service. We store correspondence for as long as needed to handle the request and afterwards for service quality purposes, and we will remove it on request.

Sharing data with third parties

We share your personal data with third parties only where this is permitted by law and necessary for the service. We may share data because:

  • we have engaged a party to process certain data on our behalf;

  • it is necessary to perform our agreement with you;

  • you have given consent;

  • we have a legitimate interest;

  • we are legally obliged to do so (for example a request from competent authorities).

To deliver the GezondRijk app we share data with the following categories of recipients:

  • Supabase (database and authentication hosting);

  • RevenueCat (subscription management);

  • OneSignal (push notifications);

  • PostHog (product analytics, with anonymised identifiers);

  • Resend (transactional email delivery);

  • BunnyCDN (media delivery);

  • Google (sign-in and, where applicable, Health Connect);

  • Apple (sign-in and Apple Health, where applicable);

  • Meta / WhatsApp (only if you use the WhatsApp Coach);

  • AI providers (for generating coaching messages, with content sent in a way that does not allow the provider to build a profile on you);

  • Our hosting and IT service providers.

Sharing with NEC. We do not share your identifiable personal data with NEC Nijmegen. NEC may receive aggregated, anonymised statistics about app usage (for example, how many people walked a route during a campaign), from which individual users cannot be identified.

We may use providers based in a country outside the European Economic Area (EEA). We only do so if:

  1. the recipient is in a country that the European Commission has recognised as providing an adequate level of data protection (an adequacy decision); or

  2. the recipient provides appropriate safeguards (for example, EU Standard Contractual Clauses); or

  3. you have given your explicit consent.

Analytics

We use PostHog to understand how people use the GezondRijk app, so we can improve it. PostHog collects information about the screens you visit, taps, errors, and device characteristics. We do not use this data to identify you personally for marketing purposes. Where possible we use anonymised or pseudonymised identifiers.

Cookies (website only)

The GezondRijk app itself does not use cookies. The supporting websites (such as fittar.fit) use cookies and similar technologies. The first time you visit, we show a notice explaining the cookies and ask for your permission where required.

We and selected third parties use cookies to:

  • make sure the website works (technical and functional cookies);

  • analyse use of the website to improve it (analytical cookies, e.g. Google Analytics with anonymised IP addresses);

  • where applicable, show relevant advertisements (marketing cookies, only with your consent).

You can enable or disable cookies in your browser settings. Please consult your browser manual for instructions.

Security

We take appropriate technical and organisational security measures to protect your personal data against loss, misuse and unauthorised access. These measures include encryption in transit, access control, regular reviews of our security practices, and contractual safeguards with our service providers.

Children

The GezondRijk app is intended for users aged 16 and older. We do not knowingly collect personal data from children under 16 without parental consent. If you believe we have collected such data, please contact us so we can remove it.

Data protection officer

We have appointed a data protection officer responsible for privacy matters within Fittar. Our data protection officer is Alje Hoving and can be reached by email at alje@fittar.eu for all your questions and requests.

Your rights

You can always contact us with questions about this privacy and cookie statement, or if you wish to access, correct or delete your personal data. You have the following rights:

  • Right of access: you have the right to see what personal data we process about you;

  • Right of rectification: you have the right to correct any personal data that is wrong or incomplete;

  • Right to erasure: you can request that we delete personal data we hold about you;

  • Right to withdraw consent: where we process data on the basis of your consent, you can withdraw that consent at any time;

  • Right to data portability: where technically feasible, you can request that we transfer your personal data to a third party;

  • Right to restriction of processing: you can request that we (temporarily) limit how we process your data;

  • Right to object: you can object to processing of your personal data, including for direct marketing.

When you exercise any of these rights, we may ask you to confirm your identity. If we ask for a copy of your ID, please mask your social security number (BSN) and photo. We aim to respond within one month. If your request is complex, we may extend this term by two months and we will let you know.

Complaints

If you have a complaint about how we use your personal data, please email info@fittar.eu with the details of your complaint and we will look into it.

You also have the right to file a complaint with the supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens. The complaint form is available at https://autoriteitpersoonsgegevens.nl/nl/meldingsformulier-klachten.

Changes to this statement

We may update this privacy and cookie statement from time to time. We recommend that you check this page regularly so you stay informed of any changes. The date at the top of this statement shows when it was last updated.

Contact details

Fittar B.V. Abe Lenstra Boulevard 50-7 8448 JB Heerenveen The Netherlands

Email: info@fittar.eu Data protection officer: alje@fittar.eu KVK: 74409603

For matters specific to NEC Nijmegen as publisher of the GezondRijk app, you can also contact NEC through their official channels.

No quick fixes. Just real, lasting change!

Smart. Personalised. Motivating.

No quick fixes. Just real, lasting change!

Smart. Personalised. Motivating.