GDPR Compliance

Last updated 1 August 2026

STRIVE processes personal and health data under the General Data Protection Regulation (EU 2016/679). This page summarises how we meet those obligations.

1. Controller

STRIVE, operating from the Netherlands, is the data controller for personal data processed through this platform. Contact: liftwithzin@gmail.com.

2. Lawful bases

Contract: account management, plan generation, subscription, and consultations.

Explicit consent (Article 9(2)(a)): processing of health-related assessment data.

Consent: newsletter subscription.

Legitimate interest: platform security, fraud prevention, and service communications.

Legal obligation: financial and tax record-keeping.

3. Data subject rights

Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent are all available to you. Your dashboard lets you export and delete your own data directly; requests by email are answered within 30 days.

4. Data minimisation and purpose limitation

We collect only what is needed to generate and adjust your plan. Optional assessment fields are clearly marked as optional, and no assessment answer is used for advertising.

5. Security measures

Encryption in transit and at rest, row-level access rules that isolate each client's records, authenticated server-side data access, restricted administrative access, and private storage for uploaded photos and documents.

6. International transfers

Data is stored inside the European Union. Where a processor operates outside the EEA, transfers rely on Standard Contractual Clauses.

7. Breach notification

In the event of a personal data breach that poses a risk to your rights, we notify the Autoriteit Persoonsgegevens within 72 hours and inform affected clients without undue delay.

8. Supervisory authority

You may lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch Data Protection Authority.

Questions about this document? Email liftwithzin@gmail.com.