Privacy Policy
Last updated: July 13, 2026 Effective from: July 13, 2026
Table of Contents
- Introduction
- Who We Are (Data Controller)
- Who This Policy Applies To
- What Data We Collect
- Purposes and Legal Bases for Processing
- Who We Share Data With
- International Data Transfers
- How Long We Keep Data
- Your Rights
- Cookies and Similar Technologies
- Data Security
- Instructors and Companies as Independent Controllers
- Automated Decision Making
- Contact
- Changes to This Policy
1. Introduction
Protecting your privacy and the security of your personal data is our priority. This Privacy Policy (hereinafter: "Policy") is for informational purposes and explains how we collect, use, store, and protect your personal data when you use the Exercio platform (hereinafter: "Platform"), available at exercio.app.
2. Who We Are (Data Controller)
The Data Controller is:
| Field | Value |
|---|---|
| Controller | Jakub Adamski, conducting business under the name [...] |
| Contact Email | support@exercio.app |
| Address | [to be completed] |
| Tax ID (NIP) | [to be completed] |
| Data Protection Officer (DPO) | Not appointed — no legal obligation at this stage |
For all matters related to personal data processing, you can contact us at: support@exercio.app.
3. Who This Policy Applies To
This Policy applies to the following categories of users:
| Role | Description |
|---|---|
| Client | An individual who registers on the Platform to search for instructors, browse profiles, book sessions, and leave reviews |
| Instructor | An individual or business who creates an instructor profile on the Platform to offer training/sports/dance services |
| Enterprise (Company) | A business (dance school, gym, MMA club, fitness studio, etc.) that purchases a subscription and manages instructor profiles |
| Guest | A person browsing the Platform without logging in, who can make a guest booking. Guest data is processed solely to the extent necessary to fulfill the booking |
| User | A general term for all of the above |
4. What Data We Collect
4.1 Data Voluntarily Provided During Registration
| Data Category | Scope |
|---|---|
| Identification Data | First name, last name, username, email address, phone number (optional) |
| Login Data | Password (stored in encrypted form — modern one-way hashing algorithms) |
| OAuth Data | If you log in via Google or Facebook — we collect: email address, avatar (profile picture), provider identifier |
4.2 Instructor Profile Data
| Data Category | Scope |
|---|---|
| Professional Data | Bio/description, specializations, years of experience, tagline, tags, training goals |
| Location Data | City, location |
| Financial Data | Hourly rate, session price, payment method information |
| Multimedia | Profile picture, photo gallery (voluntarily provided) |
| Additional | Languages, availability, package information |
4.3 Enterprise (Company) Profile Data
| Data Category | Scope |
|---|---|
| Company Data | Company name, address, email, phone, website |
| Profile Data | Logo, cover image, description, category, tags |
| Location Data | Address, city, postal code |
| Social Media | URLs to Facebook, Instagram, YouTube, TikTok |
| Operational Data | Business hours, amenities, pricing, certificates |
| Subscription Data | Stripe subscription ID, subscription status |
4.4 Booking Data
| Data Category | Scope |
|---|---|
| Booking Data | Date, time, duration, price, status |
| Notes | Any notes added by the client or instructor |
| Guest Data | First name, last name, email, phone (for guest bookings without registration) |
4.5 Review Data
| Data Category | Scope |
|---|---|
| Review Content | Rating (1-5), comment, low rating reason (if applicable) |
| Metadata | Date of review, booking ID |
4.6 Automatically Collected Data
| Data Category | Scope |
|---|---|
| Technical Data | IP address, browser type, operating system, time zone |
| Behavioral Data | Interaction with the Platform, visited pages, session time |
| Preferences | Selected language, cookie preferences |
4.7 Contact Data
| Data Category | Scope |
|---|---|
| Contact Form | First name, last name, email, category, message content |
| Enterprise Lead | Company name, email, phone, website, city, business type, number of instructors |
5. Purposes and Legal Bases for Processing
5.1 For All Users
| Processing Purpose | Data | Legal Basis | Retention Period |
|---|---|---|---|
| Account creation and management | Identification data, login data | Art. 6(1)(b) GDPR (necessary for contract) | Duration of account + 3 years |
| Authentication and security | Login data, IP address | Art. 6(1)(b) GDPR | Duration of account |
| Service-related communication | Email, push notifications | Art. 6(1)(b) GDPR | Duration of account |
| Handling inquiries and complaints | Contact data, message content | Art. 6(1)(b) and (f) GDPR | 1 year from case closure |
| Legal obligations (accounting, DSA) | Transaction data, user data | Art. 6(1)(c) GDPR | 6 years (accounting) |
| Analytics and Platform improvement | Technical data, behavioral data | Art. 6(1)(a) GDPR (consent) or (f) (legitimate interest) | Up to 2 years |
5.2 For Clients
| Processing Purpose | Data | Legal Basis | Retention Period |
|---|---|---|---|
| Searching for instructors | Location, preferences | Art. 6(1)(b) GDPR | Session / until logout |
| Booking sessions | Booking data | Art. 6(1)(b) GDPR | 3 years from booking date |
| Leaving reviews | Review content | Art. 6(1)(a) GDPR (consent) | Duration of review visibility |
| Saving favorites | Favorite instructors list | Art. 6(1)(b) GDPR | Duration of account |
5.3 For Instructors
| Processing Purpose | Data | Legal Basis | Retention Period |
|---|---|---|---|
| Creating and managing public profile | Instructor profile data | Art. 6(1)(b) GDPR | Duration of account |
| Accepting bookings | Booking data, client data | Art. 6(1)(b) GDPR | 3 years |
| Managing availability | Availability data | Art. 6(1)(b) GDPR | Duration of account |
| Settlements and payments | Financial data | Art. 6(1)(b) and (c) GDPR | 6 years |
5.4 For Enterprise Companies
| Processing Purpose | Data | Legal Basis | Retention Period |
|---|---|---|---|
| Managing company profile | Company data | Art. 6(1)(b) GDPR | Duration of account |
| Managing subscription | Subscription data | Art. 6(1)(b) GDPR | Duration of subscription + 6 years |
| Managing instructors | Assigned instructor data | Art. 6(1)(b) GDPR | Duration of membership |
| Publishing news | News content | Art. 6(1)(b) GDPR | Duration of visibility |
6. Who We Share Data With
6.1 Data Recipients
| Recipient | Purpose of Sharing | Data Category |
|---|---|---|
| Payment Provider (Stripe) | Processing Enterprise subscription payments | Subscription ID, amount, email (Stripe is an independent controller) |
| Cloud Infrastructure Provider | Platform and database hosting | All data (based on data processing agreement) |
| OAuth Provider (Google, Facebook) | Authentication via external identity providers | Email address, avatar, provider identifier |
| Email Service Provider | Sending service-related email notifications | Email address |
| Analytics Provider (Google Analytics) | Analyzing Platform traffic (with consent) | Anonymized technical data |
| Instructors | Booking fulfillment — the instructor receives client data necessary to conduct the session | Client identification data, booking data |
| Enterprise Companies | Managing instructors assigned to the company | Instructor profile data |
| Law enforcement and courts | Fulfilling legal obligations | Scope as defined in the request |
6.2 Instructors and Companies as Independent Data Controllers
After a booking is made, the instructor or enterprise company may become a separate data controller of personal data to the extent necessary to provide their services. Detailed information can be found in section 12.
7. International Data Transfers
Some of the providers we use are based outside the European Economic Area (EEA), particularly in the US. Data transfers to these providers are carried out with appropriate safeguards:
| Provider | Country | Safeguard |
|---|---|---|
| Stripe | USA | Data Privacy Framework (DPF) |
| Google (OAuth, Analytics) | USA | Data Privacy Framework (DPF) |
| Meta (Facebook OAuth) | USA | Data Privacy Framework (DPF) |
| Vercel (hosting) | USA/EU | Standard Contractual Clauses (SCC) |
You have the right to request a copy of the safeguards applied by contacting us.
8. How Long We Keep Data
We retain your personal data for as long as necessary to fulfill the purposes outlined in this Policy, unless the law requires longer retention, or until the statute of limitations for claims, if applicable.
| Data Type | Retention Period |
|---|---|
| Account data (active) | Duration of account |
| Account data (after closure) | 3 years after closure (claims) |
| Booking data | 3 years from booking date |
| Accounting/invoice data | 6 years (legal requirement) |
| Cookie consent data | 1 year |
| Analytics data | Up to 2 years |
| Inactive account | Deletion after 3 years of inactivity |
9. Your Rights
Under the GDPR, you have the following rights:
| Right | Description | How to Exercise |
|---|---|---|
| Right of Access (Art. 15) | You have the right to know whether we process your data and to receive a copy | Email: support@exercio.app |
| Right to Rectification (Art. 16) | You have the right to correct inaccurate or incomplete data | Account panel → edit profile |
| Right to Erasure (Art. 17) | You have the right to request deletion of your data ("right to be forgotten") | Email: support@exercio.app |
| Right to Restrict Processing (Art. 18) | You have the right to request restriction of processing | Email: support@exercio.app |
| Right to Data Portability (Art. 20) | You have the right to receive your data in a structured format (JSON) | Email: support@exercio.app |
| Right to Object (Art. 21) | You have the right to object to processing based on legitimate interest | Email: support@exercio.app |
| Right to Withdraw Consent (Art. 7(3)) | You have the right to withdraw consent at any time | Cookie panel / email: support@exercio.app |
| Right to Lodge a Complaint (Art. 77) | You have the right to lodge a complaint with the supervisory authority | https://uodo.gov.pl (Polish DPA) |
Note: Exercising some rights may prevent us from further providing services (e.g., deletion of data = deletion of account).
We respond to requests within 30 days, in accordance with Art. 12(3) GDPR.
10. Cookies and Similar Technologies
Detailed information about cookies can be found in the Cookie Policy.
In summary — we use:
| Type | Purpose | Consent |
|---|---|---|
| Essential | Platform operation (session, login, security) | No consent needed |
| Functional | Remembering preferences (language) | Consent required |
| Analytical | Google Analytics — traffic analysis | Consent required |
| Marketing | Advertising, targeting | Consent required |
You can manage your cookie preferences in the cookie banner available on the Platform.
11. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Transmission encryption — SSL/TLS certificate (HTTPS)
- Password encryption — modern one-way hashing algorithms
- Regular security testing
- Regular system updates
- Backups
- Security monitoring
- Access control — data accessible only to authorized persons
- Data segmentation — production data separated from test data
Nevertheless, data transmission over the Internet is not 100% secure. Use a secure internet connection.
12. Instructors and Companies as Independent Controllers
If you are an instructor or Enterprise company:
By using the Platform to accept bookings and provide services, you process personal data of your clients. In this respect, you are an independent data controller under the GDPR.
This means that:
- You decide on the purposes and means of processing your clients' data
- You should have your own privacy policy
- You are responsible for fulfilling information obligations towards your clients
- Exercio, by providing you with technical tools, acts as a data processor in this regard
- Exercio is not responsible for how you process client data
If you run a business and wish to sign a Data Processing Agreement (DPA) with us, contact us at: support@exercio.app.
13. Automated Decision Making
Exercio does not make decisions concerning users that produce legal effects or similarly significant effects solely by automated means, including profiling, as referred to in Article 22 of the GDPR.
14. Contact
For all matters related to personal data protection:
| Channel | Data |
|---|---|
| support@exercio.app | |
| Address | [to be completed] |
| Contact form | https://exercio.app/contact |
15. Changes to This Policy
We reserve the right to change this Policy. Changes do not limit users' rights under applicable law. We will inform you of changes:
- via a notice on the Platform
- in case of significant changes — additionally by email (if you have an account)
We recommend regularly checking the content of this Policy.
Exercio — exercio.app