FITENABLE

Data Protection Policy

FITENABLE LLP · Last updated: 21 June 2026 · Version 1.0 · Owner: Abhishek Maurya, Designated Partner / Data Protection Lead

1. Purpose and Scope

This Data Protection Policy sets out how FITENABLE LLP ("FITENABLE") handles personal data in compliance with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, the "DPDP"), and other applicable law.

It applies to all designated partners, employees, interns, coaches, contractors and any other person who processes personal data on behalf of FITENABLE ("Personnel"), and to all personal data we process, in any format or location.

Compliance with this Policy is mandatory. Breach may result in disciplinary action or termination of engagement, and may expose FITENABLE to significant regulatory penalties.

2. Key Roles

  • Data Fiduciary. FITENABLE is the Data Fiduciary and determines the purpose and means of processing personal data of its users ("Data Principals").
  • Data Protection Lead / Contact Person. Abhishek Maurya, Designated Partner / Data Protection Lead is responsible for data-protection compliance, responding to Data Principal requests and grievances, and coordinating breach response. Their contact details are published in the Privacy Policy and Grievance Redressal Policy.
  • Data Processors. Coaches (engaged as independent contractors) and third-party service providers who process personal data on our behalf are Data Processors and must be engaged under a Data Processing Agreement.

3. Data Protection Principles

Personnel must ensure that personal data is:

  • processed lawfully, on the basis of valid consent or a recognised legitimate use under the DPDP;
  • collected for specified, clear and lawful purposes and not used in incompatible ways (purpose limitation);
  • limited to what is necessary for those purposes (data minimisation);
  • accurate and kept up to date where it is used to make decisions affecting the Data Principal;
  • retained only as long as necessary and then erased (storage limitation);
  • kept secure with appropriate safeguards (see the Information Security Policy); and
  • handled with accountability and proper records.

4. Categories of Data We Handle

We process, among other things: account / identity data; health and lifestyle data (Assessment answers, measurements, conditions disclosed, progress logs), which is sensitive in nature and must be handled with heightened care; transaction data (payment-instrument data is handled by Razorpay and not stored by us); communications; and technical / usage data.

Health data is processed solely to provide and personalise the Services. It must never be used for advertising and must never be sold or disclosed except as permitted in the Privacy Policy.

5. Lawful Basis and Consent Management

Personnel must ensure a valid lawful basis exists before processing. Where consent is relied upon, it must be free, specific, informed, unconditional and given by clear affirmative action, with a plain-language notice of what is collected and why.

Service consent (necessary to deliver the Services) and marketing consent must be kept separate. Marketing communications require a distinct opt-in.

Records of consent (what, when, version, method) must be maintained, and consent-withdrawal requests must be honoured promptly.

6. Children's Data: 18+ Only

FITENABLE serves only persons aged 18 or older and does not knowingly process the personal data of any person under 18.

If any Personnel becomes aware that a user is under 18, they must immediately escalate to the Data Protection Lead. The account must be suspended, the personal data deleted, and behavioural tracking ensured off for that user, in line with the Privacy Policy.

7. Data Principal Rights

Data Principals have rights to access, correction / completion / updating, erasure, grievance redressal, nomination, and withdrawal of consent.

Personnel who receive any such request must forward it to the Data Protection Lead within 24 hours and must not ignore, delete or attempt to handle it informally. Requests will be verified and fulfilled within the timelines required by law.

8. Sharing and Processors

Personal data may be shared only as permitted in the Privacy Policy and only with Processors engaged under a Data Processing Agreement with appropriate security and confidentiality obligations.

Before onboarding any new vendor that will handle personal data, Personnel must complete vendor due diligence and ensure a Data Processing Agreement is in place (coordinate with the Data Protection Lead).

Processors, coaches, contractors and vendors must not use Data Principal contact details, health data, progress data, chat history or any Company Personal Data to solicit, divert, contact or serve users outside FITENABLE, request direct payments, or support personal, freelance, competing or unrelated work.

9. Cross-Border Transfer

Where personal data is processed outside India by our providers, it must be done in accordance with the DPDP and any Government-prescribed conditions or restrictions, and payment-data handling must comply with applicable RBI requirements (managed via Razorpay).

10. Retention and Deletion

Personal data must be retained only for as long as necessary for the relevant purpose and for legal / tax / regulatory requirements, then securely erased.

The Data Protection Lead maintains the Retention Schedule. Personnel must not retain personal data on personal devices or unapproved storage.

11. Security

All processing must comply with the Information Security Policy, including access control, encryption, and secure handling of health data.

12. Personal Data Breach Response

A personal data breach includes any unauthorised access, disclosure, alteration, loss or destruction of personal data.

Any suspected or actual breach must be reported immediately (and no later than 24 hours of becoming aware) to the Data Protection Lead.

The Data Protection Lead will coordinate containment, assessment and notification, including notifying the Data Protection Board of India and affected Data Principals in the manner and within the timelines required under the DPDP. Records of breaches and the response must be kept.

13. Training and Awareness

All Personnel who handle personal data must complete data-protection awareness training on onboarding and periodically thereafter. Coaches must be briefed on safe handling of client health data.

14. Records and Accountability

The Data Protection Lead maintains records of processing activities, consents, Processor agreements, Data Principal requests and breaches, sufficient to demonstrate compliance.

15. Review

This Policy will be reviewed at least annually and whenever the law or our processing changes materially.

FITENABLE LLP · Data Protection Policy · Last updated: 21 June 2026 · Version 1.0