Privacy & GDPR
Principles planned for account, sports and payment data.
النسخة القانونية المحلية بانتظار المراجعة. تُعرض النسخة الإنجليزية حاليًا.
Last updated: August 30, 2026Data and purposes
Account, sports profile, sessions, feedback, preferences and personalised-guidance conversations are used to provide and personalise the service. Billing data is processed to manage subscriptions.
Legal bases
Contract performance, consent where required, legal duties and documented legitimate interest depending on purpose.
Your rights
Depending on the applicable legal basis and GDPR conditions: access, correction, erasure, restriction, objection, portability and consent withdrawal. You may complain to your competent data authority.
Minimum age
perfDNA is reserved for people aged 18 and over. Any account identified as belonging to a minor may be suspended or deleted.
Automated decisions
Personalised guidance provides explanations and proposals. Sensitive choices remain under user control; no medical diagnosis is performed.
Optional health declaration
An illness, chronic condition or medical instruction may be shared voluntarily to keep the sports experience cautious. Free text is encrypted before storage and is never sent to OpenAI. Two separate, explicit and revocable permissions cover local storage and any transfer of the sole boolean signal that a health constraint exists. That signal may be sent only when personalised continuity is enabled and European processing, contractual and no-retention safeguards are validated. The store:false setting alone is not enough: without approved Zero Data Retention, provider abuse-monitoring logs may remain for up to 30 days. The account supports password-confirmed export and erasure. The declaration is never used for diagnosis, treatment or a medical decision. Before launch, GDPR Articles 6 and 9, retention, contracts, transfers and the DPIA will be finalised.