Your personal data is incredibly important which is why we do everything we can to make sure it stays safe.

This Privacy Policy describes how Activo AI Limited (a New Zealand registered company with company number 9361972) (we, us or our) collects, uses, shares and protects the personal data of individuals (you or your) accessing or using the Activo App, the website at www.activoapp.io , or interacting with us through social media or our marketing activities (collectively the Platform). It also tells you about your privacy rights and howthe law protects you. By accessing or using our Platform you acknowledge that you have read and understood this Privacy Policy.
We are committed to complying with the New Zealand Privacy Act 2020, and for our customers and website users based in the European Economic Area (EEA), the General Data Protection Regulation (GDPR). We will also endeavour to ensure compliance with applicable data protection legislation of other countries or jurisdictions where we operate or have users, to the extent reasonably practicable, including the Australian Privacy Act 1988, the UK Data Protection Act 2018, and relevant US state privacy laws.
What personal data do we collect?“Personal data” (known as “personal information” under the NZ Privacy Act 2020) is any information that relates to an identified or identifiable individual. It does not include data that can’t identify an individual (such as deidentified or aggregated data). Personal data we collect from you may include:
• Contact data: your name, email address
• Profile data: user name and password
• Special Category/Sensitive Personal Data: injury status. We collect this special category data solely for the purpose of generating personalized fitness programs through our AI-powered service. We will only process this data with your explicit consent, which you may withdraw at any time by contacting us at support@activoapp.io. Please note that if you withdraw consent for processing this health data, we will be unable to continue providing personalized fitness programs to you, and your access to certain features of the Platform may be restricted or terminated.
• Fitness profile data: Age, intended workout frequency, fitness goals
• Usage data: information about how you use our website and Activo App, including pages viewed, features accessed, time spent, frequency of use, and interaction patterns. This also includes technical data such as device type, operating system, browser type and version, IP address, device identifiers, and general location data.
For detailed information about cookies and similar tracking technologies, see the "Cookies and other tracking technologies" section below.
The Activo App is intended to be used by persons aged 18 years and over. We do not knowingly collect or process personal data from anyone under 18 years of age. If you are under 18, you must not use the Activo App or provide any personal data to us. If we become aware that we have collected personal data from someone under 18, we will delete that information promptly and in any event within 30 days of becoming aware, except to the extent we are required to retain such data to comply with legal obligations or to establish, exercise or defend legal claims.
We use third party services for payment processing and do not collect or store your payment card details. Our third-party payment processors' use of your personal data (such as credit card details) is governed by their respective privacy policies. While we select reputable payment processors, we are not responsible for their privacy practices or any breach of your data that occurs within their systems.
Apple Store In-App PaymentsTheir Privacy Policy can be viewed at:https://www.apple.com/legal/privacy/en-ww/
Google Play In-App PaymentsTheir Privacy Policy can be viewed at: https://www.google.com/policies/privacy/
How do we collect your personal information?We collect your personal information directly from you, such as when you register an account, contact us via email, use our website or social media, or access or use our Platform. We may also collect personal information from publicly available sources, third-party service providers, business partners, and other people you have authorised us to collect it from. By providing us with personal information about another person, you represent and warrant that you have obtained all necessary consents and authorizations from that person. We may also collect information while you use our Platform using technology like cookies, in accordance with the section below.
You are responsible for ensuring the accuracy of all information you provide to us. You will indemnify and hold us harmless from any claims arising from your provision of inaccurate information or unauthorized disclosure of third-party personal data. Cookies and other tracking technologies We use cookies and similar tracking technologies to monitor your activity on our website and store certain information (such as your internet protocol address, browser type, browser version, time spent). We may also use third-party vendors (including Google Analytics) who may collect data through cookies and similar technologies. These third parties may collect information about your online activities over time and across different websites. We require these third parties to respect the security of your personal data and to treat it in accordance with applicable law. We do not permit our third-party service providers to use your personal data for their own purposes except where we have obtained your consent for them to do so. Cookies are small data files placed on your device that enable us to enhance and personalise your online experience, understand website usage, and improve our services. The cookies we use may include: essential cookies necessary for the functioning of the Website; performance cookies to monitor site usage; functional cookies that remember your preferences; and targeting or advertising cookies to deliver personalised content and advertisements. You can manage your cookie preferences at any time by either accessing the cookie settings on our Website or directly through your web browser. We will obtain your consent through a cookie banner before deploying any non-essential cookies on your device. You can withdraw your consent at any time, but this will not affect the lawfulness of processing based on consent before its withdrawal.
For more information on how to manage and delete cookies, visit: https://www.aboutcookies.org/ or www.allaboutcookies.org
Withdrawing your consent may impact your user experience and prevent you from using certain parts of our Website. Essential cookies, which are strictly necessary for the operation of the website and to provide services you have requested, do not require consent as they are required for website security, functionality and accessibility.
You may opt-out of certain Google Analytics features through your mobile device settings, such as your device advertising settings or by following the instructions provided by Google in their Privacy Policy: https://policies.google.com/privacy
To opt out of Google's use of cookies for advertising purposes, visit Google's Ads Settings at https://www.google.com/settings/ads
You may also opt out of third-party vendor cookies for personalized advertising by visiting www.aboutads.info/choices or www.youronlinechoices.eu (for users in the EEA).
For what purposes do we use your personal information?We may use personal data collected from you to:
• provide our Platform
• set up and manage your account with us
• communicate with you by email, phone, SMS or other electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities, including the security updates, when necessary or reasonable for their implementation
• get feedback and improve our Platform and your experience
• handle complaints and disputes
• to deliver targeted advertising and remarketing to you (either directly or through our third-party vendors), where you have provided explicit consent to such marketing communications. You may withdraw your consent and opt out of marketing communications at any time by contacting us at support@activoapp.io or using the unsubscribe mechanism in our communications
• comply with our legal and contractual obligations or enforce our legal rights
• promote our services to you and provide other information we think you may find interesting, where you have consented to receive marketing communications or where we have a legitimate interest to do so and you have not objected. You may opt out of marketing communications at any time
• by aggregating and de-identifying your personal data such that it can no longer identify you, to analyse, improve and promote our business and services, and
• for any other purposes for which you have provided explicit written consent, or as required or permitted by applicable law.
We will only use or process your personal information for the purposes we collect it and only where there is a lawful basis for such processing under applicable law. The lawful bases we rely on include: (a) your consent (which you may withdraw at any time); (b) performance of our contract with you; (c) compliance with our legal obligations; and (d) our legitimate interests (such as improving our Platform). For users based in the EEA or UK, we comply with GDPR requirements. For special category data (such as injury status), we process such data based on your explicit consent, which you provide when creating your account and entering this information. This information is only used to generate training programs with your explicit consent.
Who do we disclose your personal data to and why?We may disclose your personal data to others for the purposes specified above. This may include:
• any business that helps us or works with us to provide our Platform or operate our business, for example, service providers, technology providers, cloud-providers such as Amazon Web Services, data storage and back-up providers, payment providers, App stores (Apple and Google)
• Artificial intelligence integration partners, such as OpenRouter via API. You can review OpenRouter's privacy practices at https://openrouter.ai/privacy• any other person where required or permitted by applicable law, or with your prior express consent, provided we will notify you of such disclosures where legally permitted to do so
• in connection with, or during negotiations of, any merger, acquisition, financing, sale of assets, or other similar transaction involving all or a portion of our business, provided that the recipient enters into a written agreement to protect your personal data in accordance with this Privacy Policy and applicable data protection laws, and
• any other third parties with your prior explicit consent, which you may provide electronically through the Activo App or in writing, and which you may withdraw at any time by contacting us at support@activoapp.io.
We do not sell your personal data.
International Data TransfersYour personal data may be transferred to and processed in countries outside of the country you are in when you provide your information and such countries may not provide the same level of protection as your home country. Specifically, your data is stored on Amazon Web Services servers and processed by OpenRouter, both of which involve transfers to and processing in the United States of America. Your data may also be processed by staff or service providers located in New Zealand, and potentially other countries as we expand our service provider relationships. We will take all steps reasonably necessary to ensure that your personal data is treated securely and in accordance with this Privacy Policy and applicable data protection laws, and no transfer of your personal data will take place to an organization or a country unless there are adequate safeguards are in place. By using our Platform, you acknowledge and agree to the transfer of your personal data to the overseas recipients described in this Privacy Policy.
How we keep your personal data safe and secureWe are committed to keeping your personal data as safe and secure as possible and follow generally accepted industry standards to protect the personal data submitted to us, both during transmission and once we receive it. We have implemented industry-standard physical, electronic, and managerial procedures to keep personal data safe and secure and protect it from misuse, interference, loss, or unauthorised access, modification, anddisclosure. However, no method of transmission over the Internet, or method of electronic storage is 100% secure. While we use reasonable efforts to maintain the security of your information. to protect your personal data, we cannot guarantee its absolute security. In the event of a data breach, we will notify you and relevant authorities in accordance with and to the extent required by applicable law.
Retention of personal dataWe will retain your personal data only for as long as it is necessary for the purposes set out in this Privacy Policy and in accordance with any statutory retention periods. If you reside within the EEA, we will also comply with the GDPR requirements regarding the retention and deletion of personal data.
Your rights regarding personal data Depending on the law applicable to your location, you may have rights regarding your personal data to:
• request erasure, restriction of processing, object to processing, and data portability
• request access to and correction of your personal data
• object to processing, and
• withdraw consent
You can exercise these rights by contacting us at support@activoapp.io. We will respond to your request within the timeframes required by applicable law after verifying your identity. Please note that certain data, including fitness programs you have created, may not be able to be deleted once generated as they form part of our service records and may be necessary for our legitimate business interests, system integrity, or legal compliance, though we will delete or anonymize your personal identifiers associated with such data where legally permissible and technically feasible.
Direct MarketingSubject to applicable law, we may contact you by telephone, regular mail, or electronically (email, SMS or via other electronic means) with promotional material and offers of products or services from us. We will not share your personal data with business partners for their direct marketing purposes without your explicit consent. You can unsubscribe from receiving marketing messages at any time by: (a) using the opt-out function provided in the message; (b) emailing us at support@activoapp.io.
How to make a privacy complaintIf you think we have not followed our privacy obligations, you can make a complaint by contacting us at support@activoapp.io. We will acknowledge your complaint within the timeframe required by applicable law. You also have the right to lodge a complaint with the relevant supervisory authority:
• New Zealand residents: Office of the Privacy Commissioner enquiries@privacy.org.nz or www.privacy.org.nz• EEA residents: Your local Data Protection Authority (contact details available at https://edpb.europa.eu/about-edpb/board/members_en• UK residents: Information Commissioner's Office https://ico.org.uk or casework@ico.org.uk• Australian residents: Office of the Australian Information Commissioner enquiries@oaic.gov.au or www.oaic.gov.au• California residents: California Attorney General https://oag.ca.gov/contact/consumer-complaint-against-business-or-company
Changes to this Privacy PolicyWe may amend this Privacy Policy from time to time. We will notify you of material changes through our Platform. Your continued use of the Platform after the effective date of the changes constitutes your acceptance of the revised Privacy Policy. Where required by applicable law, we will obtain your consent to material changes.
If you have any questions about this policy or want to exercise your rights, please contact us at support@activoapp.io
Policy last updated: 28.10.2025
