← Home
Privacy Policy
Last updated: 03/08/2026
1. Data Controller
- —Matteo Ardu
- —Bingener Weg 73, 40229 Düsseldorf, Deutschland
- —Email: info@calisthenicsexperience.com
2. Data Collected
- —Identification data: first name, last name, email address
- —Access data: password (encrypted), authentication tokens
- —Physical data (optional): age, height, body weight — voluntarily provided by the user to personalise training plans
- —Fitness data: training level, goals, workout history
- —Usage data: access logs, language preferences, app interactions
3. Purposes of Processing
- —Service provision: account creation and management
- —Personalization: generation of adaptive training plans
- —Service communications: registration confirmation and password reset emails
- —Service improvement: aggregated and anonymous usage analysis
- —Legal obligations: compliance with applicable regulations
4. Legal Basis (Art. 6 GDPR)
- —Contract performance (art. 6 par. 1 lit. b): to provide the service
- —Explicit consent (art. 6 par. 1 lit. a): for physical and fitness data
- —Legitimate interest (art. 6 par. 1 lit. f): for service improvement
- —Legal obligation (art. 6 par. 1 lit. c): for regulatory compliance
5. Health Data
Data relating to physical condition (weight, height, age, fitness level, workout history) may be considered health data under Art. 9 GDPR. Such data is optional and processed exclusively with the explicit consent of the user, given during onboarding, and is used solely for the generation of personalised training plans.
6. Data Retention
- —Account data: for the duration of the contractual relationship
- —Workout history: for the duration of the active account
- —Access logs: maximum 12 months
- —Backup data: maximum 30 days after account deletion
7. Data Transfers
- —Supabase Inc. (USA) — database and authentication — with adequate safeguards under art. 46 GDPR
- —Google LLC — OAuth authentication — with adequate safeguards under art. 46 GDPR
- —No data is sold to third parties.
8. Your Rights
- —Access (art. 15): obtain a copy of your data
- —Rectification (art. 16): correct inaccurate data
- —Erasure (art. 17): request deletion of your data
- —Portability (art. 20): receive data in a structured format
- —Objection (art. 21): object to processing based on legitimate interest
- —To exercise your rights: info@calisthenicsexperience.com
9. Security
Data is protected by encryption in transit (TLS) and at rest. Access to data is limited to authorised personnel.
10. Changes
Any changes will be communicated by email to registered users with at least 15 days notice.
11. Complaints
You have the right to lodge a complaint with the competent supervisory authority. In Germany: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).
