GDPR Compliance
Last updated 1 August 2026
STRIVE processes personal and health data under the General Data Protection Regulation (EU 2016/679). This page summarises how we meet those obligations.
1. Controller
STRIVE, operating from the Netherlands, is the data controller for personal data processed through this platform. Contact: liftwithzin@gmail.com.
2. Lawful bases
Contract: account management, plan generation, subscription, and consultations.
Explicit consent (Article 9(2)(a)): processing of health-related assessment data.
Consent: newsletter subscription.
Legitimate interest: platform security, fraud prevention, and service communications.
Legal obligation: financial and tax record-keeping.
3. Data subject rights
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent are all available to you. Your dashboard lets you export and delete your own data directly; requests by email are answered within 30 days.
4. Data minimisation and purpose limitation
We collect only what is needed to generate and adjust your plan. Optional assessment fields are clearly marked as optional, and no assessment answer is used for advertising.
5. Security measures
Encryption in transit and at rest, row-level access rules that isolate each client's records, authenticated server-side data access, restricted administrative access, and private storage for uploaded photos and documents.
6. International transfers
Data is stored inside the European Union. Where a processor operates outside the EEA, transfers rely on Standard Contractual Clauses.
7. Breach notification
In the event of a personal data breach that poses a risk to your rights, we notify the Autoriteit Persoonsgegevens within 72 hours and inform affected clients without undue delay.
8. Supervisory authority
You may lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch Data Protection Authority.
Questions about this document? Email liftwithzin@gmail.com.