Privacy Policy

Last updated:

This policy explains what personal data the MIKLOS CENTERI FIT website processes, why it is processed, and what rights you have over it.

Who processes your data

The MIKLOS CENTERI FIT website is operated by Miklos Centeri, acting as a natural person providing online coaching services. MIKLOS CENTERI FIT is the trading name under which those services are offered, not a separate company.

Miklos Centeri determines the purposes and means of the processing and is therefore the controller of the data described below for the purposes of the GDPR. The service is provided from Romania.

Contact: centerimiklos@gmail.com.

How to reach us

For any request concerning your personal data, you can write to centerimiklos@gmail.com, use the consultation form on this site, or contact us through the official Instagram and Threads profiles linked in the footer.

We respond within one month of receiving your request. If a request is complex, we will tell you if that period needs to be extended.

What data we collect

We collect only what is needed to assess applications and to deliver the coaching service:

  • Consultation form data: name, email, phone, age, current and target weight, occupation, hours worked per day, what you have tried so far, your main obstacle, and an optional message.
  • Account data: name, email address, your role on the platform, and a password stored only as a bcrypt hash. The password itself is never stored.
  • Authentication data: a session token held in the database only as a SHA-256 hash, together with its expiry date.
  • Client profile data: phone, age, height, current and target weight, occupation, working pattern, and notes.
  • Progress data: weight, waist, average steps, sleep quality, hunger level, energy level, how closely you followed the plan, your own notes, and your coach's feedback.
  • Training and nutrition plans created for you by your coach.
  • Minimal technical data for security: a hashed value derived from your IP address, used to limit repeated sign-in and form submission attempts.
  • Free resource form data: the first name and email address you enter, the language of the page you requested it from, which resource you asked for, and when.
  • Marketing consent records, if you give consent: the exact wording you read, its version, the version of the privacy policy in force at the time, the language and the date. If you later withdraw consent, that moment is recorded too. If you leave the box unticked, nothing about that is recorded.

Health-related data

Weight, waist, energy levels, sleep quality, conditions, injuries, pain, medication, supplements, medical clearance, allergies and intolerances, together with anything you write about your health in the free-text fields, are data concerning health — a special category of data under Article 9 GDPR.

We process this data solely on the basis of your explicit consent, under Article 9(2)(a). That consent is asked for separately from accepting the terms, separately from your cookie choice and separately from any marketing agreement: it is its own box, and it is never pre-ticked.

We ask for it at two moments, with different wording because the purposes differ. When you submit the consultation form, to assess whether the programme suits you. And during onboarding inside your account — from the first step, which asks your age, height and weight — for personalised coaching for the duration of our work together. That second consent also covers the recurring check-ins: weight, measurements, sleep quality, hunger, energy and whatever you choose to write in the notes, used to track your progress over time and adjust your plans.

Every grant and every withdrawal is stored as its own record, together with the version of the wording you accepted, the language it was shown in, the purpose it covered and the exact moment. Records are never overwritten, precisely so that what you agreed to, and when, can always be shown.

You can withdraw your consent at any time from the Privacy section of your account, or by writing to centerimiklos@gmail.com. Withdrawal takes effect for the future and does not affect the lawfulness of processing carried out beforehand. After a withdrawal we no longer write or adjust plans based on this information; the rest of your account stays available.

Clients who supplied this kind of information before the mechanism existed do not show as having a recorded consent, because no auditable evidence of one exists. We did not create such records retrospectively. They are asked for consent before any new health information is saved.

Free resources and marketing emails

When you request a free resource, all we need is your first name and email address. The address is required because that is where the resource is sent; we do not ask for a phone number, an age or anything else in order to give you a download.

The file has no permanent public link. You receive a personal link, valid for a limited time, issued for your request.

Agreeing to marketing emails is a separate checkbox: optional, and unticked by default. You get the resource whether or not you tick it, and the two are handled separately — delivering the resource is a transactional email about your request, while marketing is a distinct communication that depends solely on your consent.

You can withdraw that consent at any time using the unsubscribe link in the emails you receive. Withdrawal stops marketing communications; it does not affect resources you have already requested, nor the lawfulness of processing carried out beforehand.

If you request several resources with the same address, we keep one contact and the history of your requests, rather than creating separate records for the same person.

Why we process your data, and on what basis

  • Assessing your consultation application and contacting you: processing is necessary to take steps at your request prior to entering into a contract — Article 6(1)(b) GDPR.
  • Delivering the coaching service, preparing plans and tracking progress: performance of the contract — Article 6(1)(b).
  • Processing health-related data within those services: your explicit consent — Article 9(2)(a).
  • Keeping you signed in, limiting repeated attempts and protecting the platform against abuse: our legitimate interest in keeping the service working and secure — Article 6(1)(f).
  • Remembering the language you selected: necessary to deliver the site in the form you asked for.
  • Delivering the free resource you asked for, and the email containing the download link: processing is necessary to do exactly what you requested — Article 6(1)(b) GDPR. That email is sent whether or not you agreed to marketing.
  • Sending emails with advice, news and offers: solely on the basis of your consent, given by ticking the optional box — Article 6(1)(a). You can withdraw it at any time.
  • Keeping a record of consent given or withdrawn: the obligation to be able to demonstrate consent — Article 7(1) GDPR.

Who has access

Internal access is limited to Miklos Centeri, as coach and operator of the platform. We do not sell your data and we do not use it for advertising.

Technically, the platform rests on three providers, each acting as a processor and handling the data only on the controller's instructions: Hostinger, which hosts the application; Supabase, which runs the PostgreSQL database holding accounts, applications, plans and check-ins; and Resend, which delivers transactional e-mail such as the account activation invitation. There are no other recipients.

The site loads no analytics tools, advertising networks, tracking pixels or embedded third-party content. Fonts are served from the same domain as the site, so viewing a page does not generate requests to external servers.

The Instagram and Threads links in the footer are ordinary links. Your data reaches those platforms only if you choose to click through, at which point their own policies apply.

Transfers outside the European Economic Area

Data is processed within the infrastructure described above. Where a hosting provider processes data outside the European Economic Area, the transfer relies on the safeguards set out in Chapter V GDPR, such as the European Commission's standard contractual clauses.

How long we keep it

Sign-in sessions expire automatically after 14 days. Records used for rate limiting are cleared automatically once their time window has passed.

Consultation applications and client data are kept for as long as needed to assess the request and to run the coaching relationship, and are deleted on request — except where retention remains necessary to establish, exercise or defend a legal claim.

Contact details collected through free resources are kept for as long as you remain interested in those communications, or until you ask for them to be deleted. The exact retention period for inactive contacts has not yet been set and will be published here once it is decided.

If you withdraw marketing consent, the record of consent given and withdrawn is kept separately from the mailing list: it is the evidence that the earlier processing was lawful, and deleting it would remove the very document that protects you.

Your rights

In relation to your personal data you have the right to:

  • access your data and obtain a copy of it;
  • have inaccurate or incomplete data corrected;
  • have your data erased;
  • restrict processing;
  • receive your data in a structured, commonly used format and have it ported;
  • object to processing based on legitimate interests;
  • withdraw your consent at any time, where processing relies on consent;
  • lodge a complaint with a supervisory authority.

Complaints

You may lodge a complaint with the supervisory authority in the Member State where you habitually reside, where you work, or where the alleged infringement took place. In Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP).

Security

Passwords are stored only as bcrypt hashes with a high work factor. The session token is kept in the database as a hash only, and is carried in the browser by an HttpOnly cookie, marked Secure in production and SameSite=Lax, so it cannot be read from JavaScript.

Forms are validated on the server, requests are checked as coming from the same origin, and both sign-in and form submission are rate limited.

Children

The service is intended for people aged 18 and over, and the consultation form does not accept ages below that. We do not knowingly collect data about children. If you become aware that a child has provided us with personal data, please contact us and we will delete it.

Automated decision-making

We do not make automated decisions producing legal or similarly significant effects, and we do not carry out profiling. Applications and check-ins are reviewed by a person.

Cookies and storage on your device

The site uses a very small number of storage technologies, all first-party and all strictly necessary: the session cookie that keeps you signed in, the cookie that remembers the language you chose, and a local record of your cookie choice. No analytics tool, advertising pixel or embedded third-party content is loaded.

The optional categories — functional, analytics and marketing — exist in the Cookie Settings panel, but nothing is currently registered against them, so switching one on starts nothing. If we ever add something, the consent version changes and we ask you again before it loads.

Full details, including how long each technology lasts, are in the cookie policy. You can change your choice at any time under Cookie Settings, in the footer of every page.

Marketing communications

The newsletter is asked for explicitly, from a dedicated section on the home page. Marketing consent is its own box, never pre-ticked, separate from accepting the terms and separate from the health-data consent. Submitting the consultation form does not subscribe you, and downloading a free resource never amounts to silent subscription.

Subscribing to the newsletter uses double opt-in. After you subscribe you receive a single email asking you to confirm that the address is yours; until you confirm we send you no marketing at all, and the address stays unsubscribed. The confirmation link is valid for seven days and can be used once. If you do not confirm, no subscription happens.

You can withdraw your consent at any time, from the unsubscribe link in the emails you receive, without it affecting the coaching service or the lawfulness of processing carried out before it. Unsubscribing stops marketing and keeps the contact and the proof of consent — that record is what shows the earlier processing was lawful.

The other emails you may receive are not marketing and do not depend on this consent: the reply to a consultation application, the invitation to activate an account, and the delivery of a resource you asked for.

  • What we store for the newsletter: your first name and email address, the language you subscribed in, where the subscription came from, and its status.
  • Proof of consent: the exact wording you read, its version, the version of the privacy policy in force, the language, when you ticked the box, when you confirmed and, where applicable, when you unsubscribed.
  • The confirmation link is stored only as a SHA-256 hash, never in the clear, and expires after seven days.

Changes to this policy

This policy may be updated as the service changes. The version published here is the one in force, and the date it was last updated is shown at the top of the page.

This document is provided for information purposes and does not constitute legal advice.

Back to the site