Privacy Policy Polityka prywatności
This is an English translation, provided for your convenience. The Polish version is the binding one — if the two ever differ, the Polish text governs. Read the Polish version.
1. Administrator danych i kontakt
Administratorem Twoich danych osobowych jest:
Movebuddy Software Spółka z Ograniczoną Odpowiedzialnością
ul. Marsz. Józefa Piłsudskiego 74 lok. 320, 50-020 Wrocław
KRS 0001258724 · NIP 8971976759 · REGON 545419926
Sąd rejestrowy: Sąd Rejonowy dla Wrocławia-Fabrycznej we Wrocławiu, VI Wydział Gospodarczy Krajowego Rejestru Sądowego
Kapitał zakładowy: 5000,00 zł
W każdej sprawie dotyczącej danych osobowych możesz napisać na contact@movebuddy.pl albo na adres siedziby wskazany wyżej.
Nie powołaliśmy inspektora ochrony danych. Wszystkie sprawy dotyczące danych osobowych, w tym realizację praw opisanych w sekcji 15, kierujemy na contact@movebuddy.pl.
Jesteśmy administratorem w zakresie prowadzenia Twojego Konta i działania Aplikacji. Jeżeli współpracujesz z Trenerem, Trener jest odrębnym, niezależnym administratorem w zakresie własnej usługi trenerskiej — szczegóły opisuje sekcja 6.
Zasady korzystania z Aplikacji opisuje odrębny Regulamin.
2. Skąd mamy Twoje dane
- Od Ciebie. Większość danych podajesz sam: przy rejestracji, w profilu, w Ankiecie Wstępnej, w check-inach, w trakcie treningów i w czacie.
- Od Twojego Trenera. Trener może wprowadzić dane, które Ciebie dotyczą — pomiary ciała, notatki o Tobie, plan i komentarze do treningów.
- Od Trenera, który Cię zaprosił — zanim jeszcze cokolwiek zrobiłeś. Trener
może dodać Cię do swojej listy klientów, podając Twoje imię, nazwisko i adres
e-mail. Powstaje wtedy wpis oraz techniczna tożsamość bez hasła, a Trener może
przygotować dla Ciebie plan, ankiety, harmonogram, notatki i pomiary — zanim się o tym
dowiesz.
- Źródłem tych danych jest Trener, nie Ty. Podaje je z własnej inicjatywy i odpowiada za podstawę prawną ich przetwarzania.
- Wysyłamy jedną wiadomość z zaproszeniem. Po potwierdzeniu adresu e-mail pokazujemy, kto Cię dodał, i pytamy o zgodę. Odmowa jest równie łatwo dostępna jak przyjęcie.
- Jeżeli nie zareagujesz w ciągu 14 dni, albo Trener wycofa zaproszenie, usuwamy wszystko: tożsamość techniczną, wpis na liście oraz plan, ankiety, harmonogram, notatki i pomiary, które Trener do niego dołączył.
- Możesz w każdej chwili sprzeciwić się takiemu przetwarzaniu, pisząc na contact@movebuddy.pl.
- Od Apple lub Google — jeżeli logujesz się kontem Apple lub kontem Google albo kupujesz Subskrypcję w App Store lub Google Play. Otrzymujemy wtedy identyfikator tożsamości oraz status i metadane zakupu.
- Automatycznie z Twojego urządzenia — dane techniczne opisane w sekcji 3.
3. Jakie dane przetwarzamy
3.1. Dane konta i profilu
Adres e-mail, imię, nazwisko, płeć, data urodzenia (nie sam wiek — dokładna data, wymagana i weryfikowana na serwerze), wzrost, zdjęcie profilowe oraz — w przypadku Trenera — numer telefonu. Hasło przechowujemy wyłącznie w postaci nieodwracalnego skrótu; nigdy nie mamy dostępu do jego jawnej postaci.
3.2. Dane o zdrowiu
Ankieta Wstępna zbiera dane o Twoim zdrowiu. Domyślnie włączone są pytania o przebyte urazy, choroby i stany zdrowia oraz o poziom codziennej aktywności. O regularnie przyjmowane leki pytamy wyłącznie wtedy, gdy Trener sam doda takie pytanie do swojego szablonu — nie ma go w szablonie domyślnym. Odpowiedzi wpisujesz swobodnym tekstem.
Są to dane szczególnej kategorii w rozumieniu art. 9 RODO. Zadajemy te pytania wyłącznie po uzyskaniu odrębnej, wyraźnej zgody, o którą prosimy na osobnym ekranie przed sekcją zdrowotną ankiety (art. 9 ust. 2 lit. a RODO). Odpowiedź jest dobrowolna, a odmowa nie ogranicza dostępu do Aplikacji ani do żadnej jej funkcji. Zgodę możesz wycofać w każdej chwili w ustawieniach Konta; wycofanie powoduje usunięcie tych odpowiedzi i utratę do nich dostępu przez Trenera. Trener nie może uczynić pytania o zdrowie obowiązkowym.
Nie oceniamy tych odpowiedzi, nie interpretujemy ich i nie wyciągamy z nich wniosków — służą wyłącznie temu, aby Twój Trener miał informacje, które sam zdecydowałeś się mu przekazać. Aplikacja nie prowadzi kwalifikacji do wysiłku i nie jest wyrobem medycznym.
3.3. Pomiary ciała, cele i historia treningów
- Pomiary ciała: masa ciała (obowiązkowa), procent tkanki tłuszczowej oraz dziewięć obwodów — szyi, barków, klatki piersiowej, bicepsa, przedramienia, talii, bioder, uda i łydki. Każdy pomiar ma datę i informację, kto go wprowadził. Przechowujemy pełną historię, bez nadpisywania.
- Check-iny: masa ciała, jakość snu, poziom energii, pełne pomiary ciała oraz opcjonalnie Zdjęcia Postępów — każde zgłoszenie jako nowy, datowany punkt.
- Cele treningowe: typ celu, wartość docelowa, termin, tytuł i opis, postęp; poprzednie cele zachowujemy jako historię.
- Historia treningów: wykonane sesje i ćwiczenia oraz wartości serii — ciężar, powtórzenia, czas, dystans, RPE, RIR, rundy, tempo, prędkość; znaczniki rozpoczęcia i zakończenia; rekordy życiowe; kalendarz.
- Samoocena po treningu: nastrój, liczba godzin snu, poziom energii w skali 1–10 oraz Twój swobodny komentarz.
3.4. Zdjęcia Postępów
Do trzech zdjęć sylwetki na check-in (przód, bok, tył). Przed pierwszym wysłaniem pokazujemy odrębną informację o tym, dokąd trafia zdjęcie i kto je zobaczy, i prosimy o potwierdzenie. Ze zdjęć usuwamy metadane, w tym współrzędne GPS: najpierw na urządzeniu, a następnie ponownie na serwerze, przed zapisaniem. Każde zdjęcie możesz usunąć samodzielnie w dowolnym momencie; usunięcie działa również wobec Trenera.
3.5. Czat
Treść wiadomości tekstowych, zdjęcia, pliki wideo, wiadomości głosowe oraz karty ćwiczeń i podsumowań treningów.
3.6. Notatka Trenera o Tobie
Trener może prowadzić o Tobie prywatną notatkę, do 10 000 znaków. Notatka nie jest widoczna dla Ciebie w Aplikacji i nie jest dostępna dla naszej roli administracyjnej. O jej treści decyduje Trener jako odrębny administrator (sekcja 6). Żądanie dostępu prosimy kierować na contact@movebuddy.pl; przekażemy je Trenerowi.
3.7. Dane techniczne
- Model urządzenia, system operacyjny i jego wersja, wersja Aplikacji, platforma, język i strefa czasowa.
- Token powiadomień push przypisany do urządzenia.
- Logi dostępu i błędów oraz dane telemetryczne o działaniu Aplikacji i serwera.
- Adres IP przetwarzamy przy odrzuceniu żądania z powodu przekroczenia limitu zapytań — wyłącznie jako sygnał bezpieczeństwa. Nieudanych prób logowania nie rejestrujemy u siebie: logowanie obsługuje dostawca uwierzytelniania (sekcja 8).
- Zapis akceptacji Regulaminu i Polityki Prywatności oraz udzielonych zgód — data, wersja dokumentu, identyfikator Konta i techniczne dane zdarzenia.
Do logów technicznych nie zapisujemy treści Twoich danych. Nie logujemy adresów e-mail, numerów telefonu, imion, dat urodzenia, treści wiadomości ani notatek, ani wartości zdrowotnych — celów, pomiarów i wyników treningów.
3.8. Dane o subskrypcji
Status subskrypcji, plan, data końca okresu rozliczeniowego, kanał zakupu, identyfikatory transakcji sklepu oraz historia zdarzeń subskrypcyjnych. Nie mamy dostępu do danych Twojej karty ani do Twojej metody płatności — płatność obsługuje jako sprzedawca sklep, w którym kupiono Subskrypcję: Apple (App Store) albo Google (Google Play).
4. Cele i podstawy prawne
Twoje dane przetwarzamy w następujących celach: świadczenie Usługi i wykonanie umowy o prowadzenie Konta, w tym udostępnianie danych Trenerowi w czasie otwartej Współpracy; obsługa Subskrypcji i uprawnień na Koncie; kontakt z Tobą w sprawach dotyczących Usługi; zapewnienie bezpieczeństwa Kont, danych i infrastruktury oraz przeciwdziałanie nadużyciom i obchodzeniu limitów; wykrywanie, diagnozowanie i naprawa awarii; pomiar sposobu korzystania z Aplikacji, tworzenie zestawień zbiorczych i anonimizacja danych w celu utrzymania, rozwoju i planowania Usługi; wykonanie ciążących na nas obowiązków prawnych, w tym rozpatrywanie reklamacji, obsługa zgłoszeń treści bezprawnych i żądań organów oraz wykazanie zgodności z przepisami o ochronie danych osobowych; ustalenie, dochodzenie i obrona roszczeń; informowanie o zmianach Usługi, Regulaminu i Polityki Prywatności; a za Twoją zgodą — przetwarzanie danych o zdrowiu oraz komunikacja marketingowa.
| Cel | Podstawa prawna |
|---|---|
| Prowadzenie Konta i świadczenie Usługi — plany, treningi, pomiary, cele, czat, kalendarz | art. 6 ust. 1 lit. b RODO — wykonanie umowy o świadczenie Usługi |
| Udostępnianie Twoich danych Twojemu Trenerowi w ramach otwartej Współpracy | art. 6 ust. 1 lit. b RODO — jest to istota Usługi, o którą prosisz przyjmując Zaproszenie |
| Dane o zdrowiu z Ankiety Wstępnej | art. 6 ust. 1 lit. a oraz art. 9 ust. 2 lit. a RODO — odrębna, wyraźna zgoda, którą można wycofać w każdej chwili (sekcja 3.2) |
| Zdjęcia Postępów wysyłane przez Ciebie w check-inie | art. 6 ust. 1 lit. b RODO — przetwarzanie niezbędne do wykonania funkcji, którą uruchamiasz, wysyłając zdjęcie swojemu Trenerowi |
| Obsługa Subskrypcji i uprawnień na Koncie | art. 6 ust. 1 lit. b RODO oraz art. 6 ust. 1 lit. c RODO w zakresie obowiązków rozliczeniowych |
| Bezpieczeństwo — zapis adresu IP przy odrzuceniu żądania z powodu limitu zapytań, wykrywanie nadużyć | art. 6 ust. 1 lit. f RODO — ochrona Kont i infrastruktury |
| Diagnostyka awarii i telemetria techniczna | art. 6 ust. 1 lit. f RODO — utrzymanie i naprawa Usługi |
| Pomiar sposobu korzystania z Aplikacji, zestawienia zbiorcze i anonimizacja | art. 6 ust. 1 lit. f RODO — utrzymanie, rozwój i planowanie Usługi; nie wykorzystujemy do tego treści danych o zdrowiu, Zdjęć Postępów, nagrań głosowych ani treści wiadomości |
| Rozpatrywanie reklamacji, obsługa zgłoszeń treści bezprawnych i żądań organów | art. 6 ust. 1 lit. c oraz lit. f RODO |
| Ustalenie, dochodzenie i obrona roszczeń | art. 6 ust. 1 lit. f RODO, a w zakresie danych o zdrowiu w archiwum roszczeniowym — art. 9 ust. 2 lit. f RODO |
| Utrzymanie dowodu akceptacji Regulaminu i udzielonych zgód | art. 6 ust. 1 lit. c RODO (art. 7 ust. 1 RODO — rozliczalność) oraz lit. f |
| Wysyłka wiadomości o zmianach Usługi, Regulaminu i Polityki | art. 6 ust. 1 lit. b oraz lit. c RODO |
| Komunikacja marketingowa dotycząca naszych usług | art. 6 ust. 1 lit. f RODO co do treści oraz odrębna zgoda na kanał komunikacji elektronicznej |
| Dane osoby zaproszonej przez Trenera, zanim ta osoba się zgodzi | art. 6 ust. 1 lit. f RODO — uzasadniony interes Trenera i nasz, ograniczony w czasie do 14 dni; patrz sekcja 2 |
5. Czy podanie danych jest obowiązkowe
- Dane wymagane do założenia Konta — adres e-mail, imię, nazwisko, płeć i data urodzenia (Trener dodatkowo numer telefonu) — są niezbędne do zawarcia umowy. Bez nich nie da się utworzyć Konta.
- Aplikacja prosi o wypełnienie Ankiety Wstępnej przed rozpoczęciem korzystania z części treningowej. W samej ankiecie cztery pytania — data urodzenia, płeć, wzrost i początkowa masa ciała — są wymagane, aby ją wysłać.
- Dane o zdrowiu podajesz dobrowolnie, po wyrażeniu odrębnej zgody. Możesz pominąć te pytania i korzystać z Aplikacji w pełnym zakresie.
- Zdjęcia Postępów, check-iny i samoocena po treningu są dobrowolne. Check-iny nigdy nie blokują dostępu do Aplikacji.
- Zgody na dostęp do kamery, galerii, mikrofonu i powiadomień są dobrowolne. Odmowa wyłącza daną funkcję, ale nie blokuje pozostałej części Aplikacji.
6. Kto widzi Twoje dane i kto jest administratorem
Podział ról. W odniesieniu do danych Klienta prowadzonego przez Trenera Usługodawca i Trener są odrębnymi, niezależnymi administratorami. Nie jesteśmy współadministratorami ani podmiotem przetwarzającym dane na zlecenie Trenera.
- My jesteśmy administratorem w zakresie: prowadzenia Twojego Konta i świadczenia Ci Usługi, udostępniania danych Trenerowi w czasie otwartej Współpracy, bezpieczeństwa Aplikacji, obsługi Subskrypcji i reklamacji, wykonania obowiązków prawnych oraz utrzymania i rozwoju Aplikacji.
- Trener jest administratorem w zakresie własnej usługi trenerskiej — decyduje, o co pyta w pytaniach własnych ankiety, jakie dane o Tobie wprowadza, jakie prowadzi notatki i jak wykorzystuje wyniki. W tym zakresie samodzielnie wykonuje obowiązki administratora, w tym obowiązki informacyjne i obsługę Twoich żądań.
- Żądanie dotyczące danych, o których decyduje Trener, przekazujemy Trenerowi i informujemy Cię o tym. Nie odpowiadamy za sposób wykonania przez Trenera jego obowiązków. Zasadniczą treść uzgodnień stosowanych na wypadek uznania nas za współadministratorów zawiera Załącznik nr 1 do Regulaminu.
- Twój Trener widzi wszystko, co dotyczy Twojego treningu: profil, odpowiedzi w Ankiecie Wstępnej — także te dotyczące zdrowia — odpowiedzi w check-inach, pomiary ciała i ich pełną historię, Zdjęcia Postępów, cele, całą historię treningów, kalendarz, statystyki oraz całą rozmowę na czacie.
- Notatka Trenera o Tobie jest widoczna tylko dla niego. Komentarze Trenera do treningu widzisz Ty, w trybie tylko do odczytu.
- Inni Klienci nie widzą Twoich danych. Aplikacja nie ma funkcji społecznościowych, rankingów ani porównań między Klientami.
- Po zakończeniu Współpracy Trener traci dostęp do Twoich bieżących danych. Zachowuje wpis w archiwum, przeszłe sesje w swoim kalendarzu, własne notatki oraz historię czatu w trybie tylko do odczytu. Twoje dane zostają na Twoim Koncie.
- Nasza rola administracyjna ma dostęp techniczny do danych Kont w zakresie niezbędnym do utrzymania Usługi i obsługi zgłoszeń. Nie obejmuje notatek Trenera o Kliencie.
- Nie sprzedajemy Twoich danych i nie udostępniamy ich w celach marketingowych podmiotom trzecim. Poza Twoim Trenerem i podwykonawcami technicznymi z sekcji 8 dane mogą zostać ujawnione wyłącznie wtedy, gdy wymagają tego przepisy prawa albo gdy jest to konieczne do ustalenia, dochodzenia lub obrony roszczeń.
7. Gdzie fizycznie leżą Twoje dane i pliki
Twoje dane nie są przechowywane wyłącznie na Twoim telefonie. Pamięć urządzenia służy jedynie jako lokalny cache — źródłem danych jest nasz serwer.
- Zdjęcia, wideo i nagrania głosowe. Zdjęcia Postępów są zmniejszane i kompresowane na urządzeniu, a następnie wysyłane na nasze serwery i tam przechowywane; widzi je Twój Trener. Wiadomości głosowe są nagrywane na urządzeniu, a następnie wysyłane na nasze serwery i tam przechowywane; odsłuchuje je druga strona rozmowy. Zdjęcia i wideo z czatu również leżą na naszych serwerach. Żaden z tych plików nie jest przetwarzany wyłącznie na Twoim urządzeniu.
- Magazyn plików. Prywatny magazyn — Zdjęcia Postępów i media z czatu — jest przypisany do infrastruktury na terenie Europejskiego Obszaru Gospodarczego. Pliki prywatne nie mają publicznych adresów i są udostępniane wyłącznie przez krótko żyjące, podpisane linki, generowane po sprawdzeniu uprawnień.
- Zdjęcia profilowe leżą w magazynie publicznym, pod nieodgadywalnym adresem, razem z materiałami biblioteki ćwiczeń oraz nagraniami demonstracyjnymi ćwiczeń wgranymi przez Trenera — takie nagranie może zawierać wizerunek Trenera. Nie są indeksowane, ale nie są chronione podpisanym linkiem. Zdjęcia Postępów nigdy nie trafiają do magazynu publicznego.
- Nie prowadzimy drugiej kopii plików prywatnych. Utrata danych po stronie dostawcy magazynu oznaczałaby utratę plików. Dlatego zalecamy zachowanie własnych kopii zdjęć, które są dla Ciebie ważne.
- Baza danych nie stoi u nas. Konto, pomiary, cele, historia treningów, treść wiadomości, odpowiedzi w ankietach i dane subskrypcyjne prowadzi dla nas dostawca infrastruktury chmurowej i bazy danych, w regionie na terenie Europejskiego Obszaru Gospodarczego.
- Serwer aplikacji (część obliczeniowa, bez trwałych danych Użytkowników) działa na serwerze dedykowanym na terenie Europejskiego Obszaru Gospodarczego.
8. Komu powierzamy dane
Korzystamy z podwykonawców technicznych. Poniżej wskazujemy kategorie odbiorców, do czego z nich korzystamy i jakie dane do nich trafiają.
| Kategoria odbiorcy | Do czego | Co do niego trafia | Gdzie |
|---|---|---|---|
| Dostawca infrastruktury chmurowej i bazy danych | uwierzytelnianie i baza danych | dane Konta, hasło w postaci skrótu, tożsamości z logowania kontem Apple lub Google oraz cała baza aplikacji — pomiary, historia treningów, ankiety, treść wiadomości | EOG |
| Dostawca magazynu obiektowego oraz sieci dostarczania treści | przechowywanie i dostarczanie plików | zdjęcia profilowe i materiały ćwiczeń (publiczne); Zdjęcia Postępów i media z czatu (prywatne) | magazyn prywatny przypisany do EOG; dostawca może podlegać prawu państwa trzeciego — patrz sekcja 9 |
| Dostawca infrastruktury serwerowej | serwer aplikacji | ruch aplikacji; bez trwałych danych Użytkowników | EOG |
| Dostawca poczty transakcyjnej | potwierdzenie rejestracji, zaproszenie, reset hasła, zawiadomienia dotyczące Konta | adres e-mail odbiorcy i treść wiadomości | EOG lub państwo trzecie na standardowych klauzulach umownych |
| Dostawca obsługi subskrypcji sklepowych | weryfikacja i status subskrypcji | wyłącznie pseudonimowy identyfikator Konta i metadane zakupu | państwo trzecie, na standardowych klauzulach umownych — patrz sekcja 9 |
| Dostawca monitorowania błędów, logów i telemetrii | diagnostyka awarii, logi i telemetria techniczna | ślad awarii, logi serwera i żądań oraz logi diagnostyczne przesłane z Aplikacji — patrz sekcja 12; bez treści danych | EOG |
| Operatorzy usługi powiadomień push | dostarczanie powiadomień | token urządzenia oraz treść powiadomienia — patrz sekcja 12 | zgodnie z warunkami operatorów |
| Apple | dystrybucja Aplikacji, logowanie kontem Apple, sprzedaż subskrypcji | dane niezbędne dla tych funkcji, zgodnie z warunkami Apple | zgodnie z warunkami Apple |
| dystrybucja Aplikacji (Google Play), logowanie kontem Google, sprzedaż subskrypcji, dostarczanie powiadomień push na Androidzie (Firebase Cloud Messaging) | dane niezbędne dla tych funkcji, zgodnie z warunkami Google | zgodnie z warunkami Google |
Tożsamość konkretnych podmiotów przetwarzających udostępniamy na żądanie osoby, której dane dotyczą — wystarczy napisać na contact@movebuddy.pl.
Lista podwykonawców może się zmieniać wraz z rozwojem Usługi. Nowego podwykonawcę dopuszczamy dopiero po zawarciu z nim umowy powierzenia przetwarzania spełniającej wymagania art. 28 RODO i po sprawdzeniu, czy zapewnia wystarczające gwarancje wdrożenia odpowiednich środków technicznych i organizacyjnych. Zmiana listy podwykonawców nie wymaga zgody Użytkownika. O zmianie istotnej — w szczególności o powierzeniu przetwarzania nowemu podmiotowi poza Europejskim Obszarem Gospodarczym — informujemy w Aplikacji albo e-mailem.
9. Przekazywanie danych poza EOG
- Co do zasady przetwarzamy Twoje dane na terenie Europejskiego Obszaru Gospodarczego.
- Część przekazań do państw trzecich jest jednak konieczna — dotyczy to obsługi subskrypcji sklepowych (pseudonimowy identyfikator Konta i metadane zakupu) oraz dostawców, którzy przechowują dane w EOG, ale sami podlegają prawu państwa trzeciego. Podstawą takich przekazań są standardowe klauzule umowne zatwierdzone przez Komisję Europejską, uzupełnione o środki dodatkowe tam, gdzie są potrzebne.
- Apple i Google przetwarzają dane zgodnie z własnymi warunkami i własnymi politykami prywatności.
- Masz prawo uzyskać kopię zabezpieczeń zastosowanych do tych przekazań oraz informację o tożsamości podmiotów, którym dane są przekazywane. Napisz na contact@movebuddy.pl.
10. Jak długo przechowujemy dane
| Dane | Okres |
|---|---|
| Dane Konta, pomiary, cele, historia treningów, odpowiedzi w ankietach, treść wiadomości | przez czas istnienia Konta, nie dłużej niż 24 miesiące od ostatniej aktywności na Koncie |
| Zdjęcia, wideo i wiadomości głosowe z czatu | 60 dni od wysłania, po czym usuwamy je automatycznie. Treść wiadomości tekstowej i podpis pod plikiem pozostają; sam plik znika |
| Zdjęcia Postępów | do czasu ich usunięcia przez Ciebie albo do usunięcia Konta |
| Niedokończone przesyłanie pliku | 48 godzin |
| Dane osoby zaproszonej, która nie przyjęła zaproszenia | 14 dni, po czym usuwamy je w całości |
| Zapis akceptacji Regulaminu i udzielonych zgód | czas trwania umowy oraz okres przedawnienia roszczeń |
| Logi i telemetria techniczna | 31 dni |
| Archiwum roszczeniowe po usunięciu Konta | do upływu terminu przedawnienia roszczeń; zakres i zasady poniżej |
| Dokumentacja rozliczeniowa i podatkowa | 5 lat od końca roku podatkowego, w którym upłynął termin płatności podatku — w zakresie, w jakim obowiązek dotyczy nas |
Po usunięciu Konta usuwamy wszystkie treningi, plany, ankiety wraz z odpowiedziami, cele, pomiary, Zdjęcia Postępów, notatki Trenera o Tobie, kalendarz oraz całą rozmowę na czacie. Zakres usunięcia opisuje szczegółowo § 20 Regulaminu.
Zachowujemy natomiast dane niezbędne do ustalenia, dochodzenia lub obrony roszczeń — imię, nazwisko, adres e-mail, daty zawarcia i rozwiązania umowy, oznaczenie zaakceptowanej wersji Regulaminu oraz historię reklamacji i korespondencji z nami. W razie zgłoszenia roszczenia albo powstania uzasadnionych podstaw do jego przewidywania zachowujemy także dane niezbędne do obrony przed tym konkretnym roszczeniem, w tym odpowiedzi z Ankiety Wstępnej i zapis rozmowy na czacie. Dane te przechowujemy w ograniczonym dostępie, oddzielone od danych używanych operacyjnie, wyłącznie w tym celu i wyłącznie przez okres przedawnienia roszczeń. Podstawa: art. 17 ust. 3 lit. e RODO, a w zakresie danych o zdrowiu — art. 9 ust. 2 lit. f RODO.
Pozostają ponadto: pseudonimowy zapis samego usunięcia (identyfikator, data żądania, data zakończenia), rekordy subskrypcji odłączone od Twojej tożsamości, pseudonimowe identyfikatory w logach do końca ich retencji oraz pseudonimowy rekord u dostawcy obsługującego subskrypcje, usuwany zgodnie z warunkami tego dostawcy.
11. Analityka i diagnostyka
- Diagnostyka awarii. Zbieramy raporty awarii, aby móc je naprawić. Raport zawiera informacje techniczne i pseudonimowy identyfikator Konta, bez treści Twoich danych.
- Telemetria. Zbieramy dane o działaniu Aplikacji i serwera — czasy odpowiedzi, błędy, ekran, na którym wystąpił problem.
- Wersja Aplikacji dystrybuowana w App Store i Google Play nie rejestruje sposobu korzystania z ekranów. Nie prowadzimy w niej nagrywania sesji ani map aktywności. Narzędzie tego rodzaju może zostać uruchomione wyłącznie w wewnętrznych wersjach testowych i wyłącznie po uzyskaniu wyraźnej zgody osoby korzystającej z takiej wersji; zgodę można w każdej chwili wycofać.
- Pomiar sposobu korzystania z Aplikacji. Analizujemy użycie funkcji, liczniki zdarzeń, czasy odpowiedzi i wskaźniki błędów w celu utrzymania, pomiaru i rozwoju Usługi. Do celów tych nie wykorzystujemy treści danych o zdrowiu, Zdjęć Postępów, nagrań głosowych ani treści wiadomości. Podstawą jest nasz prawnie uzasadniony interes; możesz wnieść sprzeciw (sekcja 15).
- Na tej podstawie tworzymy zestawienia zbiorcze i zbiory zanonimizowane, z których nie da się zidentyfikować żadnej osoby. Stanowią one nasz zasób i możemy z nich korzystać bez ograniczenia czasowego, także po usunięciu Konta.
- Nie korzystamy z Twoich treści do trenowania modeli uczenia maszynowego udostępnianych podmiotom trzecim. Nie wyklucza to wykorzystania danych zanonimizowanych i zestawień zbiorczych do rozwoju własnych rozwiązań.
12. Powiadomienia push i logi z Aplikacji
- Do operatora powiadomień push trafia treść powiadomienia. W przypadku wiadomości z czatu jest to imię nadawcy i fragment wiadomości — do 140 znaków.
- W treści powiadomienia nigdy nie umieszczamy odpowiedzi z ankiet, pomiarów ani danych zdrowotnych — takie dane nie mogą pojawić się na ekranie blokady.
- Wysyłamy powiadomienia o zdarzeniach w Aplikacji oraz wiadomości niezbędne do wykonania umowy, zapewnienia bezpieczeństwa i poinformowania o zmianach. Wiadomości marketingowe wysyłamy wyłącznie za Twoją odrębną zgodą, którą możesz wycofać w każdej chwili; brak zgody nie wpływa na dostęp do Usługi. Każdy rodzaj powiadomienia możesz wyłączyć osobno.
- Logi diagnostyczne przesyłane z Aplikacji na nasz serwer i dalej do dostawcy monitorowania zawierają: identyfikator Konta, identyfikator sesji, nazwę ekranu, wersję Aplikacji, platformę oraz treść komunikatu diagnostycznego. Nie zawierają treści Twoich danych — patrz sekcja 3.7.
13. Bezpieczeństwo danych
Stosujemy środki techniczne i organizacyjne odpowiednie do ryzyka, w szczególności:
- szyfrowanie w tranzycie — połączenia z Aplikacji i z przeglądarki są szyfrowane;
- kontrolę dostępu — dostęp do danych mają wyłącznie Ty, Twój Trener w czasie otwartej Współpracy, upoważnieni pracownicy i współpracownicy w niezbędnym zakresie oraz podwykonawcy techniczni z sekcji 8. Uprawnienia są sprawdzane po stronie serwera, nie w interfejsie Aplikacji;
- pliki prywatne bez publicznych adresów — wyłącznie krótko żyjące, podpisane linki, generowane po sprawdzeniu uprawnień;
- hasła w postaci nieodwracalnego skrótu — nigdy w postaci jawnej;
- usuwanie metadanych ze zdjęć, w tym współrzędnych GPS — na urządzeniu i ponownie na serwerze;
- ograniczanie liczby zapytań jako zabezpieczenie przed nadużyciami;
- przeglądy kodu i monitoring — zmiany przechodzą przegląd, a działanie Aplikacji i serwera jest monitorowane.
Nie prowadzimy kopii zapasowej plików prywatnych — mówimy o tym wprost, bo jest to brak zabezpieczenia, a nie zabezpieczenie (sekcja 7).
14. Brak zautomatyzowanych decyzji i profilowania
Nie podejmujemy wobec Ciebie decyzji opartych wyłącznie na zautomatyzowanym przetwarzaniu, które wywoływałyby wobec Ciebie skutki prawne lub w podobny sposób istotnie na Ciebie wpływały, i nie prowadzimy profilowania w rozumieniu art. 22 RODO.
Aplikacja wykonuje obliczenia na danych, które sam wprowadziłeś — progresję, rekordy życiowe, tonaż, zgodność z planem, procent maksimum. Są to narzędzia pomocnicze, a nie decyzje o Tobie: nie oceniają Twojej osoby, nie przewidują Twojego zachowania i nie wpływają na Twoje uprawnienia w Aplikacji ani na warunki Usługi.
15. Twoje prawa
W odniesieniu do swoich danych osobowych masz prawo:
- dostępu — możesz uzyskać potwierdzenie, czy przetwarzamy Twoje dane, oraz ich kopię, a także informację o odbiorcach lub kategoriach odbiorców;
- sprostowania — możesz poprawić dane nieprawidłowe lub uzupełnić niekompletne;
- usunięcia — możesz usunąć Konto w Aplikacji albo zażądać usunięcia danych. Zakres i skutki opisuje sekcja 10;
- ograniczenia przetwarzania;
- sprzeciwu — wobec przetwarzania opartego na naszym prawnie uzasadnionym interesie, z przyczyn związanych z Twoją szczególną sytuacją. Sprzeciw rozpatrujemy indywidualnie. Możemy dalej przetwarzać dane mimo sprzeciwu, jeżeli istnieją ważne prawnie uzasadnione podstawy nadrzędne wobec Twoich interesów, praw i wolności — w szczególności gdy przetwarzanie jest niezbędne do zapewnienia bezpieczeństwa Kont i infrastruktury, do wykrycia lub zapobieżenia nadużyciu, do zapewnienia integralności i dostępności Usługi dla pozostałych Użytkowników albo do ustalenia, dochodzenia lub obrony roszczeń;
- przenoszenia danych — możesz otrzymać dane w ustrukturyzowanym, powszechnie używanym formacie nadającym się do odczytu maszynowego. Aplikacja nie ma dziś funkcji eksportu, więc takie żądanie realizujemy ręcznie, po zgłoszeniu na adres kontaktowy;
- wycofania zgody w każdej chwili, bez wpływu na zgodność z prawem przetwarzania sprzed jej wycofania (sekcja 16);
- wniesienia skargi do organu nadzorczego — w Polsce jest nim Prezes Urzędu Ochrony Danych Osobowych (uodo.gov.pl).
Żądania kieruj na contact@movebuddy.pl. Odpowiadamy bez zbędnej zwłoki, nie później niż w terminie miesiąca od otrzymania żądania. Żądanie dotyczące danych, o których decyduje Trener, przekazujemy Trenerowi (sekcja 6). Trener usuwa Konto przez zgłoszenie żądania na adres kontaktowy — wewnętrzny profil klienta trenera jest trwały, więc usunięcie wykonujemy po stronie Usługodawcy (§ 20 ust. 3 Regulaminu).
16. Zgody i ich wycofanie
Zgody są odrębne i wycofuje się je osobno. Zapoznanie się z Regulaminem i Polityką Prywatności nie jest zgodą — jest potwierdzeniem, że dokumenty zostały Ci udostępnione.
| Zgoda | Czego dotyczy | Jak wycofać |
|---|---|---|
| Dane o zdrowiu | odrębna, wyraźna zgoda na przetwarzanie odpowiedzi o urazach, chorobach, stanach zdrowia i lekach (art. 9 ust. 2 lit. a RODO) | w ustawieniach Konta albo pisząc na adres kontaktowy; wycofanie powoduje usunięcie tych odpowiedzi |
| Komunikacja marketingowa | wiadomości i powiadomienia o charakterze marketingowym | w ustawieniach Konta albo pisząc na adres kontaktowy |
| Analityka w wersjach testowych | wyłącznie wewnętrzne wersje testowe Aplikacji — sekcja 11 | w ustawieniach Aplikacji albo pisząc na adres kontaktowy |
| Dostęp do kamery, galerii, mikrofonu i powiadomień | uprawnienia systemu operacyjnego | w ustawieniach systemowych urządzenia |
Wysłanie Zdjęcia Postępów nie wymaga zgody w rozumieniu RODO — przetwarzamy je w celu wykonania funkcji, którą sam uruchamiasz (sekcja 4). Przed pierwszym wysłaniem pokazujemy informację o tym, dokąd trafia zdjęcie i kto je zobaczy.
Wycofanie zgody nie wpływa na zgodność z prawem przetwarzania, którego dokonano na jej podstawie przed wycofaniem.
17. Dane osób poniżej 16 roku życia
Aplikacja nie jest przeznaczona dla osób, które nie ukończyły 16 lat. Wiek jest weryfikowany na serwerze na podstawie podanej daty urodzenia — rejestracja osoby młodszej niż 16 lat jest odrzucana. Nie zbieramy świadomie danych od dzieci. Jeżeli dowiesz się, że osoba poniżej 16 roku życia założyła Konto, napisz na contact@movebuddy.pl — usuniemy takie Konto.
18. Zmiany polityki prywatności
Możemy aktualizować niniejszą politykę prywatności. O istotnych zmianach poinformujemy Cię w Aplikacji lub e-mailem, wskazując, co się zmienia, i podając datę wejścia zmiany w życie. Każda wersja ma datę wejścia w życie i numer wersji, podane na początku tego dokumentu.
19. Kontakt
- Wszystkie sprawy, w tym żądania dotyczące danych: contact@movebuddy.pl
- Adres do korespondencji: ul. Marsz. Józefa Piłsudskiego 74 lok. 320, 50-020 Wrocław
- Inspektor Ochrony Danych: nie powołaliśmy inspektora ochrony danych — sprawy dotyczące danych kierujemy na contact@movebuddy.pl
- Organ nadzorczy: Prezes Urzędu Ochrony Danych Osobowych (uodo.gov.pl)
Koniec Polityki Prywatności. Wróć na górę strony · Regulamin · Kontakt
1. Data controller and contact
The controller of your personal data is:
Movebuddy Software Spółka z Ograniczoną Odpowiedzialnością
ul. Marsz. Józefa Piłsudskiego 74 lok. 320, 50-020 Wrocław, Poland
KRS 0001258724 · NIP 8971976759 · REGON 545419926
Registry court: District Court for Wrocław-Fabryczna in Wrocław, VI Commercial Division of the National Court Register
Share capital: PLN 5,000.00
You can write to us about any personal data matter at contact@movebuddy.pl or to the registered address given above.
We have not appointed a data protection officer. All personal data matters, including the exercise of the rights described in section 15, are handled at contact@movebuddy.pl.
We are the controller as regards maintaining your Account and operating the App. If you work with a Trainer, the Trainer is a separate, independent controller as regards their own training service — details are in section 6.
The rules for using the App are described in the separate Terms of Service.
2. Where we get your data from
- From you. You provide most of the data yourself: on registration, in your profile, in the Intake Questionnaire, in check-ins, during training sessions and in chat.
- From your Trainer. A Trainer may enter data concerning you — body measurements, notes about you, a plan and comments on training sessions.
- From the Trainer who invited you — before you had done anything at all. A
Trainer may add you to their client list by providing your first name, surname and e-mail
address. An entry and a technical identity without a password are then created, and the
Trainer may prepare a plan, questionnaires, a schedule, notes and measurements for you — before
you learn about it.
- The source of that data is the Trainer, not you. They provide it on their own initiative and are responsible for the legal basis for processing it.
- We send one invitation message. After the e-mail address is confirmed we show who added you and ask for your consent. Refusing is just as easily available as accepting.
- If you do not respond within 14 days, or the Trainer withdraws the invitation, we delete everything: the technical identity, the list entry, and the plan, questionnaires, schedule, notes and measurements the Trainer attached to it.
- You may object to such processing at any time by writing to contact@movebuddy.pl.
- From Apple or Google — if you sign in with an Apple or Google account, or buy a Subscription on the App Store or Google Play. We then receive an identity identifier and the status and metadata of the purchase.
- Automatically from your device — the technical data described in section 3.
3. What data we process
3.1. Account and profile data
E-mail address, first name, surname, gender, date of birth (not age alone — the exact date, required and verified on the server), height, profile picture and, for a Trainer, a telephone number. We store the password solely as an irreversible hash; we never have access to it in plain text.
3.2. Health data
The Intake Questionnaire collects data about your health. Questions about past injuries, illnesses and health conditions, and about daily activity levels are enabled by default. We ask about regularly taken medication only where the Trainer adds such a question to their own template — it is not in the default template. You enter your answers as free text.
This is special category data within the meaning of Article 9 GDPR. We ask these questions only after obtaining separate, explicit consent, which we request on a dedicated screen before the health section of the questionnaire (Article 9(2)(a) GDPR). Answering is voluntary, and refusing does not limit access to the App or to any of its functions. You may withdraw your consent at any time in Account settings; withdrawal deletes those answers and removes the Trainer’s access to them. A Trainer cannot make a health question mandatory.
We do not assess these answers, we do not interpret them and we draw no conclusions from them — they exist solely so that your Trainer has the information you have chosen to share with them. The App does not screen anyone for fitness to exercise and is not a medical device.
3.3. Body measurements, goals and training history
- Body measurements: body weight (mandatory), body fat percentage and nine circumferences — neck, shoulders, chest, biceps, forearm, waist, hips, thigh and calf. Each measurement has a date and a record of who entered it. We keep the full history, without overwriting.
- Check-ins: body weight, sleep quality, energy level, full body measurements and, optionally, Progress Photos — each submission as a new, dated point.
- Training goals: goal type, target value, deadline, title and description, progress; previous goals are kept as history.
- Training history: completed sessions and exercises and set values — weight, repetitions, time, distance, RPE, RIR, rounds, tempo, speed; start and finish markers; personal records; the calendar.
- Post-training self-assessment: mood, hours of sleep, energy level on a 1–10 scale and your free-text comment.
3.4. Progress Photos
Up to three physique photos per check-in (front, side, back). Before the first upload we show separate information about where the photo goes and who will see it, and we ask for confirmation. We strip metadata from photos, including GPS coordinates: first on the device and then again on the server, before saving. You can delete any photo yourself at any time; deletion also takes effect for the Trainer.
3.5. Chat
The content of text messages, photos, video files, voice messages and exercise and training summary cards.
3.6. The Trainer’s note about you
A Trainer may keep a private note about you, up to 10,000 characters. The note is not visible to you in the App and is not accessible to our administrative role. The Trainer decides its content as a separate controller (section 6). Please address access requests to contact@movebuddy.pl; we will forward them to the Trainer.
3.7. Technical data
- Device model, operating system and its version, App version, platform, language and time zone.
- The push notification token assigned to the device.
- Access and error logs and telemetry about how the App and the server perform.
- We process the IP address when a request is rejected for exceeding the rate limit — solely as a security signal. We do not record failed sign-in attempts ourselves: sign-in is handled by the authentication provider (section 8).
- The record of acceptance of the Terms and the Privacy Policy and of consents given — the date, the document version, the Account identifier and technical data about the event.
We do not write the content of your data to technical logs. We do not log e-mail addresses, telephone numbers, first names, dates of birth, message content or notes, or health-related values — goals, measurements and training results.
3.8. Subscription data
Subscription status, plan, billing period end date, purchase channel, store transaction identifiers and subscription event history. We have no access to your card details or to your payment method — payment is handled as the seller by the store where the Subscription was bought: Apple (App Store) or Google (Google Play).
4. Purposes and legal bases
We process your data for the following purposes: providing the Service and performing the contract for maintaining the Account, including making data available to the Trainer during an open Collaboration; handling Subscriptions and Account entitlements; contacting you about matters concerning the Service; ensuring the security of Accounts, data and infrastructure and preventing abuse and the circumvention of limits; detecting, diagnosing and repairing failures; measuring how the App is used, creating aggregate compilations and anonymising data in order to maintain, develop and plan the Service; performing our legal obligations, including handling complaints, notices of unlawful content and requests from authorities, and demonstrating compliance with data protection law; establishing, pursuing and defending claims; informing you about changes to the Service, the Terms and the Privacy Policy; and, with your consent, processing health data and marketing communication.
| Purpose | Legal basis |
|---|---|
| Maintaining the Account and providing the Service — plans, training sessions, measurements, goals, chat, calendar | Article 6(1)(b) GDPR — performance of the contract for the provision of the Service |
| Making your data available to your Trainer within an open Collaboration | Article 6(1)(b) GDPR — this is the essence of the Service you ask for by accepting an Invitation |
| Health data from the Intake Questionnaire | Article 6(1)(a) and Article 9(2)(a) GDPR — separate, explicit consent, which can be withdrawn at any time (section 3.2) |
| Progress Photos you send in a check-in | Article 6(1)(b) GDPR — processing necessary to perform the function you trigger by sending a photo to your Trainer |
| Handling Subscriptions and Account entitlements | Article 6(1)(b) GDPR and Article 6(1)(c) GDPR as regards accounting obligations |
| Security — recording the IP address when a request is rejected for exceeding the rate limit, detecting abuse | Article 6(1)(f) GDPR — protecting Accounts and infrastructure |
| Crash diagnostics and technical telemetry | Article 6(1)(f) GDPR — maintaining and repairing the Service |
| Measuring how the App is used, aggregate compilations and anonymisation | Article 6(1)(f) GDPR — maintaining, developing and planning the Service; we do not use the content of health data, Progress Photos, voice recordings or message content for this |
| Handling complaints, notices of unlawful content and requests from authorities | Article 6(1)(c) and (f) GDPR |
| Establishing, pursuing and defending claims | Article 6(1)(f) GDPR and, as regards health data in the claims archive, Article 9(2)(f) GDPR |
| Keeping proof of acceptance of the Terms and of consents given | Article 6(1)(c) GDPR (Article 7(1) GDPR — accountability) and (f) |
| Sending messages about changes to the Service, the Terms and this Policy | Article 6(1)(b) and (c) GDPR |
| Marketing communication concerning our services | Article 6(1)(f) GDPR as to content and separate consent for the electronic communication channel |
| Data of a person invited by a Trainer, before that person consents | Article 6(1)(f) GDPR — the legitimate interest of the Trainer and of us, limited in time to 14 days; see section 2 |
5. Is providing data mandatory
- The data required to create an Account — e-mail address, first name, surname, gender and date of birth (a Trainer additionally a telephone number) — is necessary to conclude the contract. Without it an Account cannot be created.
- The App asks for the Intake Questionnaire to be completed before you start using the training part. Within the questionnaire itself, four questions — date of birth, gender, height and starting body weight — are required in order to submit it.
- You provide health data voluntarily, after giving separate consent. You may skip those questions and use the App in full.
- Progress Photos, check-ins and post-training self-assessment are voluntary. Check-ins never block access to the App.
- Permissions for the camera, photo library, microphone and notifications are voluntary. Refusing disables the relevant function but does not block the rest of the App.
6. Who sees your data and who is the controller
Division of roles. In relation to the data of a Client worked with by a Trainer, the Provider and the Trainer are separate, independent controllers. We are neither joint controllers nor a processor acting on the Trainer’s instructions.
- We are the controller as regards: maintaining your Account and providing the Service to you, making data available to the Trainer during an open Collaboration, the security of the App, handling Subscriptions and complaints, performing legal obligations, and maintaining and developing the App.
- The Trainer is the controller as regards their own training service — they decide what to ask in their own questionnaire questions, what data about you they enter, what notes they keep and how they use the results. In that scope they independently perform the controller’s obligations, including information obligations and handling your requests.
- We forward a request concerning data decided on by the Trainer to that Trainer and inform you that we have done so. We are not responsible for how the Trainer performs their obligations. The essence of the arrangement applied should we be found to be joint controllers is set out in Schedule 1 to the Terms.
- Your Trainer sees everything relating to your training: your profile, Intake Questionnaire answers — including health-related ones — check-in answers, body measurements and their full history, Progress Photos, goals, the entire training history, the calendar, statistics and the entire chat conversation.
- The Trainer’s note about you is visible only to them. You see the Trainer’s comments on a training session, in read-only mode.
- Other Clients do not see your data. The App has no social features, no leaderboards and no comparisons between Clients.
- After a Collaboration ends, the Trainer loses access to your current data. They keep the archive entry, past sessions in their calendar, their own notes and the chat history in read-only mode. Your data stays on your Account.
- Our administrative role has technical access to Account data to the extent necessary to maintain the Service and handle support requests. It does not include a Trainer’s notes about a Client.
- We do not sell your data and we do not share it with third parties for marketing purposes. Apart from your Trainer and the technical subprocessors listed in section 8, data may be disclosed only where required by law or where necessary to establish, pursue or defend claims.
7. Where your data and files physically sit
Your data is not stored on your phone alone. Device memory serves only as a local cache — the source of the data is our server.
- Photos, video and voice recordings. Progress Photos are resized and compressed on the device and then sent to our servers and stored there; your Trainer sees them. Voice messages are recorded on the device and then sent to our servers and stored there; the other party to the conversation listens to them. Photos and video from chat also sit on our servers. None of these files is processed on your device alone.
- File storage. The private store — Progress Photos and chat media — is assigned to infrastructure within the European Economic Area. Private files have no public addresses and are served only through short-lived, signed links, generated after permissions are checked.
- Profile pictures sit in public storage, at an unguessable address, together with exercise library material and exercise demonstration recordings uploaded by a Trainer — such a recording may show the Trainer’s image. They are not indexed, but they are not protected by a signed link. Progress Photos never go into public storage.
- We do not keep a second copy of private files. Data loss at the storage provider would mean the loss of the files. We therefore recommend keeping your own copies of photos that matter to you.
- The database is not hosted by us. The Account, measurements, goals, training history, message content, questionnaire answers and subscription data are operated for us by a cloud infrastructure and database provider, in a region within the European Economic Area.
- The application server (the compute part, holding no persistent User data) runs on a dedicated server within the European Economic Area.
8. Who we entrust data to
We use technical subprocessors. Below we identify the categories of recipients, what we use them for and what data reaches them.
| Recipient category | Purpose | What reaches them | Where |
|---|---|---|---|
| Cloud infrastructure and database provider | authentication and database | Account data, the password as a hash, identities from Apple or Google sign-in, and the entire application database — measurements, training history, questionnaires, message content | EEA |
| Object storage and content delivery network provider | storing and delivering files | profile pictures and exercise material (public); Progress Photos and chat media (private) | private store assigned to the EEA; the provider may be subject to the law of a third country — see section 9 |
| Server infrastructure provider | application server | application traffic; no persistent User data | EEA |
| Transactional e-mail provider | registration confirmation, invitations, password resets, Account notifications | the recipient’s e-mail address and the message content | EEA or a third country under standard contractual clauses |
| Store subscription handling provider | subscription verification and status | only a pseudonymous Account identifier and purchase metadata | a third country, under standard contractual clauses — see section 9 |
| Error, log and telemetry monitoring provider | crash diagnostics, logs and technical telemetry | the crash trace, server and request logs, and diagnostic logs sent from the App — see section 12; no data content | EEA |
| Push notification service operators | delivering notifications | the device token and the notification content — see section 12 | in accordance with the operators’ terms |
| Apple | App distribution, Apple sign-in, subscription sales | the data necessary for those functions, in accordance with Apple’s terms | in accordance with Apple’s terms |
| App distribution (Google Play), Google sign-in, subscription sales, delivering push notifications on Android (Firebase Cloud Messaging) | the data necessary for those functions, in accordance with Google’s terms | in accordance with Google’s terms |
We disclose the identity of specific processors at the request of the data subject — simply write to contact@movebuddy.pl.
The list of subprocessors may change as the Service develops. We admit a new subprocessor only after concluding a data processing agreement with them meeting the requirements of Article 28 GDPR and after checking whether they provide sufficient guarantees to implement appropriate technical and organisational measures. A change to the list of subprocessors does not require the User’s consent. We give notice of a material change — in particular entrusting processing to a new entity outside the European Economic Area — in the App or by e-mail.
9. Transfers outside the EEA
- As a rule we process your data within the European Economic Area.
- Some transfers to third countries are nevertheless necessary — this concerns the handling of store subscriptions (a pseudonymous Account identifier and purchase metadata) and providers who store data in the EEA but are themselves subject to the law of a third country. Such transfers are based on standard contractual clauses approved by the European Commission, supplemented by additional measures where needed.
- Apple and Google process data in accordance with their own terms and their own privacy policies.
- You have the right to obtain a copy of the safeguards applied to those transfers and information about the identity of the entities to which data is transferred. Write to contact@movebuddy.pl.
10. How long we keep data
| Data | Period |
|---|---|
| Account data, measurements, goals, training history, questionnaire answers, message content | for as long as the Account exists, no longer than 24 months from the last activity on the Account |
| Photos, video and voice messages from chat | 60 days from sending, after which we delete them automatically. The text of the message and the file caption remain; the file itself disappears |
| Progress Photos | until you delete them or until the Account is deleted |
| An unfinished file upload | 48 hours |
| Data of an invited person who did not accept the invitation | 14 days, after which we delete it entirely |
| Record of acceptance of the Terms and of consents given | the duration of the contract and the limitation period for claims |
| Technical logs and telemetry | 31 days |
| Claims archive after Account deletion | until the limitation period for claims expires; the scope and rules are set out below |
| Accounting and tax documentation | 5 years from the end of the tax year in which the tax payment deadline fell — to the extent the obligation applies to us |
After an Account is deleted we delete all training sessions, plans, questionnaires together with the answers, goals, measurements, Progress Photos, the Trainer’s notes about you, the calendar and the entire chat conversation. The scope of deletion is described in detail in § 20 of the Terms.
We do, however, keep the data necessary to establish, pursue or defend claims — first name, surname, e-mail address, the dates the contract was concluded and terminated, the version of the Terms accepted, and the history of complaints and correspondence with us. Where a claim is raised or reasonable grounds arise to anticipate one, we also keep the data necessary to defend against that specific claim, including Intake Questionnaire answers and the chat record. We keep this data with restricted access, separated from data used operationally, solely for that purpose and solely for the limitation period for claims. Basis: Article 17(3)(e) GDPR and, as regards health data, Article 9(2)(f) GDPR.
The following also remain: a pseudonymous record of the deletion itself (identifier, date of the request, date it completed), subscription records detached from your identity, pseudonymous identifiers in logs until the end of their retention, and a pseudonymous record at the provider handling subscriptions, deleted in accordance with that provider’s terms.
11. Analytics and diagnostics
- Crash diagnostics. We collect crash reports so that we can fix them. A report contains technical information and a pseudonymous Account identifier, without the content of your data.
- Telemetry. We collect data about how the App and the server perform — response times, errors, the screen on which a problem occurred.
- The version of the App distributed through the App Store and Google Play does not record how screens are used. It carries no session recording or activity heatmaps. A tool of that kind may be enabled only in internal test builds and only after obtaining the explicit consent of the person using such a build; consent may be withdrawn at any time.
- Measuring how the App is used. We analyse feature usage, event counters, response times and error rates in order to maintain, measure and develop the Service. For those purposes we do not use the content of health data, Progress Photos, voice recordings or message content. The basis is our legitimate interest; you may object (section 15).
- On that basis we create aggregate compilations and anonymised datasets from which no individual can be identified. They constitute our asset and we may use them without time limit, including after an Account is deleted.
- We do not use your content to train machine learning models made available to third parties. This does not preclude the use of anonymised data and aggregate compilations to develop our own solutions.
12. Push notifications and logs from the App
- The content of a notification reaches the push notification operator. For chat messages this is the sender’s first name and an excerpt of the message — up to 140 characters.
- We never put questionnaire answers, measurements or health data in the body of a notification — such data must never appear on a lock screen.
- We send notifications about events in the App and messages necessary to perform the contract, ensure security and inform you about changes. We send marketing messages only with your separate consent, which you may withdraw at any time; the absence of consent does not affect access to the Service. You can turn off each type of notification separately.
- Diagnostic logs sent from the App to our server and on to the monitoring provider contain: the Account identifier, session identifier, screen name, App version, platform and the text of the diagnostic message. They do not contain the content of your data — see section 3.7.
13. Data security
We apply technical and organisational measures appropriate to the risk, in particular:
- encryption in transit — connections from the App and from the browser are encrypted;
- access control — data is accessible only to you, your Trainer during an open Collaboration, authorised employees and associates to the extent necessary, and the technical subprocessors listed in section 8. Permissions are checked on the server side, not in the App interface;
- private files without public addresses — only short-lived, signed links, generated after permissions are checked;
- passwords as an irreversible hash — never in plain text;
- stripping metadata from photos, including GPS coordinates — on the device and again on the server;
- rate limiting as a safeguard against abuse;
- code review and monitoring — changes go through review, and the operation of the App and the server is monitored.
We do not keep a backup of private files — we say so plainly, because that is an absence of a safeguard, not a safeguard (section 7).
14. No automated decision-making or profiling
We do not take decisions concerning you based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you, and we do not carry out profiling within the meaning of Article 22 GDPR.
The App performs calculations on data you entered yourself — progression, personal records, tonnage, plan adherence, percentage of maximum. These are auxiliary tools, not decisions about you: they do not evaluate you as a person, they do not predict your behaviour and they do not affect your entitlements in the App or the terms of the Service.
15. Your rights
In relation to your personal data you have the right:
- of access — you can obtain confirmation of whether we process your data, and a copy of it, as well as information about the recipients or categories of recipients;
- to rectification — you can correct inaccurate data or complete incomplete data;
- to erasure — you can delete your Account in the App or request erasure of your data. The scope and effects are described in section 10;
- to restriction of processing;
- to object — to processing based on our legitimate interest, on grounds relating to your particular situation. We consider each objection individually. We may continue processing despite an objection where there are compelling legitimate grounds overriding your interests, rights and freedoms — in particular where processing is necessary to ensure the security of Accounts and infrastructure, to detect or prevent abuse, to ensure the integrity and availability of the Service for other Users, or to establish, pursue or defend claims;
- to data portability — you can receive your data in a structured, commonly used, machine-readable format. The App currently has no export function, so we fulfil such a request manually, after you submit it to the contact address;
- to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (section 16);
- to lodge a complaint with a supervisory authority — in Poland this is the President of the Personal Data Protection Office (uodo.gov.pl).
Send requests to contact@movebuddy.pl. We reply without undue delay and no later than within one month of receiving the request. We forward a request concerning data decided on by the Trainer to that Trainer (section 6). A Trainer deletes their Account by submitting a request to the contact address — the Trainer’s internal client profile is permanent, so we carry out the deletion on the Provider’s side (§ 20 paragraph 3 of the Terms).
16. Consents and their withdrawal
Consents are separate and are withdrawn separately. Reading the Terms and the Privacy Policy is not a consent — it is confirmation that the documents were made available to you.
| Consent | What it covers | How to withdraw |
|---|---|---|
| Health data | separate, explicit consent to process answers about injuries, illnesses, health conditions and medication (Article 9(2)(a) GDPR) | in Account settings or by writing to the contact address; withdrawal deletes those answers |
| Marketing communication | marketing messages and notifications | in Account settings or by writing to the contact address |
| Analytics in test builds | internal test builds of the App only — section 11 | in App settings or by writing to the contact address |
| Access to the camera, photo library, microphone and notifications | operating system permissions | in your device’s system settings |
Sending a Progress Photo does not require consent within the meaning of the GDPR — we process it in order to perform the function you trigger yourself (section 4). Before the first upload we show information about where the photo goes and who will see it.
Withdrawing consent does not affect the lawfulness of processing carried out on its basis before withdrawal.
17. Data of persons under 16
The App is not intended for persons under 16 years of age. Age is verified on the server on the basis of the date of birth provided — registration by a person under 16 is rejected. We do not knowingly collect data from children. If you learn that a person under 16 has created an Account, write to contact@movebuddy.pl — we will delete that Account.
18. Changes to this privacy policy
We may update this privacy policy. We will inform you of material changes in the App or by e-mail, stating what is changing and giving the date the change takes effect. Each version has an effective date and a version number, given at the beginning of this document.
19. Contact
- All matters, including data requests: contact@movebuddy.pl
- Correspondence address: ul. Marsz. Józefa Piłsudskiego 74 lok. 320, 50-020 Wrocław, Poland
- Data Protection Officer: we have not appointed a data protection officer — data matters are handled at contact@movebuddy.pl
- Supervisory authority: President of the Personal Data Protection Office (uodo.gov.pl)
End of the Privacy Policy. Back to top · Terms of Service · Contact