Privacy Policy

Last updated: July 13, 2026 Effective from: July 13, 2026


Table of Contents

  1. Introduction
  2. Who We Are (Data Controller)
  3. Who This Policy Applies To
  4. What Data We Collect
  5. Purposes and Legal Bases for Processing
  6. Who We Share Data With
  7. International Data Transfers
  8. How Long We Keep Data
  9. Your Rights
  10. Cookies and Similar Technologies
  11. Data Security
  12. Instructors and Companies as Independent Controllers
  13. Automated Decision Making
  14. Contact
  15. Changes to This Policy

1. Introduction

Protecting your privacy and the security of your personal data is our priority. This Privacy Policy (hereinafter: "Policy") is for informational purposes and explains how we collect, use, store, and protect your personal data when you use the Exercio platform (hereinafter: "Platform"), available at exercio.app.


2. Who We Are (Data Controller)

The Data Controller is:

FieldValue
ControllerJakub Adamski, conducting business under the name [...]
Contact Emailsupport@exercio.app
Address[to be completed]
Tax ID (NIP)[to be completed]
Data Protection Officer (DPO)Not appointed — no legal obligation at this stage

For all matters related to personal data processing, you can contact us at: support@exercio.app.


3. Who This Policy Applies To

This Policy applies to the following categories of users:

RoleDescription
ClientAn individual who registers on the Platform to search for instructors, browse profiles, book sessions, and leave reviews
InstructorAn individual or business who creates an instructor profile on the Platform to offer training/sports/dance services
Enterprise (Company)A business (dance school, gym, MMA club, fitness studio, etc.) that purchases a subscription and manages instructor profiles
GuestA person browsing the Platform without logging in, who can make a guest booking. Guest data is processed solely to the extent necessary to fulfill the booking
UserA general term for all of the above

4. What Data We Collect

4.1 Data Voluntarily Provided During Registration

Data CategoryScope
Identification DataFirst name, last name, username, email address, phone number (optional)
Login DataPassword (stored in encrypted form — modern one-way hashing algorithms)
OAuth DataIf you log in via Google or Facebook — we collect: email address, avatar (profile picture), provider identifier

4.2 Instructor Profile Data

Data CategoryScope
Professional DataBio/description, specializations, years of experience, tagline, tags, training goals
Location DataCity, location
Financial DataHourly rate, session price, payment method information
MultimediaProfile picture, photo gallery (voluntarily provided)
AdditionalLanguages, availability, package information

4.3 Enterprise (Company) Profile Data

Data CategoryScope
Company DataCompany name, address, email, phone, website
Profile DataLogo, cover image, description, category, tags
Location DataAddress, city, postal code
Social MediaURLs to Facebook, Instagram, YouTube, TikTok
Operational DataBusiness hours, amenities, pricing, certificates
Subscription DataStripe subscription ID, subscription status

4.4 Booking Data

Data CategoryScope
Booking DataDate, time, duration, price, status
NotesAny notes added by the client or instructor
Guest DataFirst name, last name, email, phone (for guest bookings without registration)

4.5 Review Data

Data CategoryScope
Review ContentRating (1-5), comment, low rating reason (if applicable)
MetadataDate of review, booking ID

4.6 Automatically Collected Data

Data CategoryScope
Technical DataIP address, browser type, operating system, time zone
Behavioral DataInteraction with the Platform, visited pages, session time
PreferencesSelected language, cookie preferences

4.7 Contact Data

Data CategoryScope
Contact FormFirst name, last name, email, category, message content
Enterprise LeadCompany name, email, phone, website, city, business type, number of instructors

5.1 For All Users

Processing PurposeDataLegal BasisRetention Period
Account creation and managementIdentification data, login dataArt. 6(1)(b) GDPR (necessary for contract)Duration of account + 3 years
Authentication and securityLogin data, IP addressArt. 6(1)(b) GDPRDuration of account
Service-related communicationEmail, push notificationsArt. 6(1)(b) GDPRDuration of account
Handling inquiries and complaintsContact data, message contentArt. 6(1)(b) and (f) GDPR1 year from case closure
Legal obligations (accounting, DSA)Transaction data, user dataArt. 6(1)(c) GDPR6 years (accounting)
Analytics and Platform improvementTechnical data, behavioral dataArt. 6(1)(a) GDPR (consent) or (f) (legitimate interest)Up to 2 years

5.2 For Clients

Processing PurposeDataLegal BasisRetention Period
Searching for instructorsLocation, preferencesArt. 6(1)(b) GDPRSession / until logout
Booking sessionsBooking dataArt. 6(1)(b) GDPR3 years from booking date
Leaving reviewsReview contentArt. 6(1)(a) GDPR (consent)Duration of review visibility
Saving favoritesFavorite instructors listArt. 6(1)(b) GDPRDuration of account

5.3 For Instructors

Processing PurposeDataLegal BasisRetention Period
Creating and managing public profileInstructor profile dataArt. 6(1)(b) GDPRDuration of account
Accepting bookingsBooking data, client dataArt. 6(1)(b) GDPR3 years
Managing availabilityAvailability dataArt. 6(1)(b) GDPRDuration of account
Settlements and paymentsFinancial dataArt. 6(1)(b) and (c) GDPR6 years

5.4 For Enterprise Companies

Processing PurposeDataLegal BasisRetention Period
Managing company profileCompany dataArt. 6(1)(b) GDPRDuration of account
Managing subscriptionSubscription dataArt. 6(1)(b) GDPRDuration of subscription + 6 years
Managing instructorsAssigned instructor dataArt. 6(1)(b) GDPRDuration of membership
Publishing newsNews contentArt. 6(1)(b) GDPRDuration of visibility

6. Who We Share Data With

6.1 Data Recipients

RecipientPurpose of SharingData Category
Payment Provider (Stripe)Processing Enterprise subscription paymentsSubscription ID, amount, email (Stripe is an independent controller)
Cloud Infrastructure ProviderPlatform and database hostingAll data (based on data processing agreement)
OAuth Provider (Google, Facebook)Authentication via external identity providersEmail address, avatar, provider identifier
Email Service ProviderSending service-related email notificationsEmail address
Analytics Provider (Google Analytics)Analyzing Platform traffic (with consent)Anonymized technical data
InstructorsBooking fulfillment — the instructor receives client data necessary to conduct the sessionClient identification data, booking data
Enterprise CompaniesManaging instructors assigned to the companyInstructor profile data
Law enforcement and courtsFulfilling legal obligationsScope as defined in the request

6.2 Instructors and Companies as Independent Data Controllers

After a booking is made, the instructor or enterprise company may become a separate data controller of personal data to the extent necessary to provide their services. Detailed information can be found in section 12.


7. International Data Transfers

Some of the providers we use are based outside the European Economic Area (EEA), particularly in the US. Data transfers to these providers are carried out with appropriate safeguards:

ProviderCountrySafeguard
StripeUSAData Privacy Framework (DPF)
Google (OAuth, Analytics)USAData Privacy Framework (DPF)
Meta (Facebook OAuth)USAData Privacy Framework (DPF)
Vercel (hosting)USA/EUStandard Contractual Clauses (SCC)

You have the right to request a copy of the safeguards applied by contacting us.


8. How Long We Keep Data

We retain your personal data for as long as necessary to fulfill the purposes outlined in this Policy, unless the law requires longer retention, or until the statute of limitations for claims, if applicable.

Data TypeRetention Period
Account data (active)Duration of account
Account data (after closure)3 years after closure (claims)
Booking data3 years from booking date
Accounting/invoice data6 years (legal requirement)
Cookie consent data1 year
Analytics dataUp to 2 years
Inactive accountDeletion after 3 years of inactivity

9. Your Rights

Under the GDPR, you have the following rights:

RightDescriptionHow to Exercise
Right of Access (Art. 15)You have the right to know whether we process your data and to receive a copyEmail: support@exercio.app
Right to Rectification (Art. 16)You have the right to correct inaccurate or incomplete dataAccount panel → edit profile
Right to Erasure (Art. 17)You have the right to request deletion of your data ("right to be forgotten")Email: support@exercio.app
Right to Restrict Processing (Art. 18)You have the right to request restriction of processingEmail: support@exercio.app
Right to Data Portability (Art. 20)You have the right to receive your data in a structured format (JSON)Email: support@exercio.app
Right to Object (Art. 21)You have the right to object to processing based on legitimate interestEmail: support@exercio.app
Right to Withdraw Consent (Art. 7(3))You have the right to withdraw consent at any timeCookie panel / email: support@exercio.app
Right to Lodge a Complaint (Art. 77)You have the right to lodge a complaint with the supervisory authorityhttps://uodo.gov.pl (Polish DPA)

Note: Exercising some rights may prevent us from further providing services (e.g., deletion of data = deletion of account).

We respond to requests within 30 days, in accordance with Art. 12(3) GDPR.


10. Cookies and Similar Technologies

Detailed information about cookies can be found in the Cookie Policy.

In summary — we use:

TypePurposeConsent
EssentialPlatform operation (session, login, security)No consent needed
FunctionalRemembering preferences (language)Consent required
AnalyticalGoogle Analytics — traffic analysisConsent required
MarketingAdvertising, targetingConsent required

You can manage your cookie preferences in the cookie banner available on the Platform.


11. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Transmission encryption — SSL/TLS certificate (HTTPS)
  • Password encryption — modern one-way hashing algorithms
  • Regular security testing
  • Regular system updates
  • Backups
  • Security monitoring
  • Access control — data accessible only to authorized persons
  • Data segmentation — production data separated from test data

Nevertheless, data transmission over the Internet is not 100% secure. Use a secure internet connection.


12. Instructors and Companies as Independent Controllers

If you are an instructor or Enterprise company:

By using the Platform to accept bookings and provide services, you process personal data of your clients. In this respect, you are an independent data controller under the GDPR.

This means that:

  1. You decide on the purposes and means of processing your clients' data
  2. You should have your own privacy policy
  3. You are responsible for fulfilling information obligations towards your clients
  4. Exercio, by providing you with technical tools, acts as a data processor in this regard
  5. Exercio is not responsible for how you process client data

If you run a business and wish to sign a Data Processing Agreement (DPA) with us, contact us at: support@exercio.app.


13. Automated Decision Making

Exercio does not make decisions concerning users that produce legal effects or similarly significant effects solely by automated means, including profiling, as referred to in Article 22 of the GDPR.


14. Contact

For all matters related to personal data protection:

ChannelData
Emailsupport@exercio.app
Address[to be completed]
Contact formhttps://exercio.app/contact

15. Changes to This Policy

We reserve the right to change this Policy. Changes do not limit users' rights under applicable law. We will inform you of changes:

  • via a notice on the Platform
  • in case of significant changes — additionally by email (if you have an account)

We recommend regularly checking the content of this Policy.


Exercio — exercio.app