Last updated: 2026-08-22
This policy adds information about consumer health data to the Privacy Policy. It includes disclosures required by laws such as the Washington My Health My Data Act. The Coach named on a signed form normally controls the coaching data. Audunn, Jarlsberggade 5B, 4.2, 5000 Odense C, Denmark provides the platform and processes that data on the Coach's instructions. Contact the Coach shown on the form first. Contact audunn@realaudunn.com if you need help from the platform.
The data can include:
Only provide data that the Coach specifically requests for fitness and wellness coaching. Do not provide medical records, diagnosis details, medication details, or emergency information.
Consumer health data can come directly from the client or the Coach. It can also come from a linked platform account, service, or device. We do not get consumer health data from data brokers.
The Coach and platform use consumer health data to provide the fitness and wellness coaching that the person requested. We use it to receive check-ins, track stated progress, let the Coach review files, and respond to the person. We can use it for optional approved AI help when the person makes that choice. We also use it to secure the service, honor rights requests, and meet legal duties.
We do not sell consumer health data. We do not use it for targeted advertising. We do not use identifiable client health data to train a general-purpose model for our own purposes.
Before a pre-account client can answer a health question or upload a file, the form asks for a separate health-data choice. The request identifies the Coach, data categories, purpose, platform, and withdrawal method. Acceptance of the general Terms is not health consent.
In some places, the law lets us collect only the data needed for a service that the person requests. We do not use that basis for unrelated analytics, advertising, model training, or other purposes.
The Coach can receive the submitted data. The platform can process the data on the Coach's instructions. Necessary service providers can host, secure, store, transmit, and support the form. The current service and AI provider register is at /legal/ai-providers.
If the client separately chooses AI, we can share health data only through a route approved for health data. The client can send the form to the Coach without AI. A provider is not authorized only because it appears in a public catalog.
We can share data with companies that provide storage, hosting, security tests, error reports, and email. An approved AI inference provider can also receive data. The active register identifies each company, its purpose, its location, and its restrictions.
The law in your location can give you these rights:
A pre-account client can withdraw through the active check-in link. The client can also contact the Coach shown on the form. A Member can use the member privacy controls. Contact audunn@realaudunn.com if the Coach does not respond. Use the same address for requests about the platform's own controller activities. We will not unlawfully discriminate against a person who uses a privacy right.
We keep active coaching records while the Coach needs them for the stated service. The Coach or client can use the available deletion process. We schedule abandoned check-in uploads for removal after the documented grace period. We can keep consent and security evidence to show compliance, resolve disputes, prevent fraud, and meet legal duties. Provider logs, encrypted backups, and recovery copies follow the schedules in the provider register and data record.
Deletion from the active application does not remove every encrypted backup immediately. Backup copies expire under the stated schedule. We restore them only for disaster recovery.
We use encrypted transport, encrypted storage, private files, and expiring and revocable form links. We also use server-side consent checks, workspace separation, access controls, rate limits, audit evidence, and incident procedures. No service can guarantee absolute security.
A disclosure without permission can be a health-data breach. Hacking is not required. We investigate suspected incidents and give the notices that the law requires.
We will not collect, use, or share additional health-data categories or use them for materially new purposes without the disclosure and affirmative choice required by law. The date above identifies this version.