Personal data is understood to be all information that relates to an identified or identifiable person.
1. Responsible and contact
Responsible for the data processing we describe here is kinastic AG, Klosterstrasse 34, 8406 Winterthur, Switzerland. If you have any questions or concerns about data protection in connection with the App, you can contact us at this address or via e-mail at: email@example.com.
2. Collection and Use of personal data
We collect personal data through the App in a number of ways, including in connection with your registration, your requests and when you use the App.
We collect and process the following data in connection with the App:
a. Registration data:
The App is only available to registered users. When registering for the App, we collect the following personal data: First and last name, email address, date of birth, user name, password, date and time of registration and, if applicable, means of payment, purchases and payments made via the App and other details that you provide to us during registration.
We use this information to identify you, to make the App and the functions of the App available to you, and to communicate with you and inform you of news and offers.
b. Usage data (including health data):
On the one hand, we collect personal data that you provide to us yourself, e.g. when you record your height, weight, interests, preferences, goals or information about your mental state, health and diet. On the other hand, we process and store personal data that is automatically collected or generated through your use of the App, e.g. when we create a training plan for you, when you complete workouts, participate in programmes or create evaluations.
This may also involve personal data that is particularly worthy of protection. In particular, the personal data processed may, under certain circumstances, allow conclusions to be drawn about your health and your health-related behaviour.
We use this information to provide you with the features of the App. We also process this information automatically in order to adapt and personalise the offers to your needs and preferences. For example, we use this data to analyse and evaluate your physical and mental condition and, based on this, to create individual training plans, nutrition tips and other recommendations for you and to inform you about offers that may be of interest to you. Under no circumstances will we pass on this data to your employer, fitness centre, insurance company or other contractual partner without your express consent.
We also analyse this information and use it to improve and further develop the App and our offers. Such data analysis help us, for example, to better understand the connections between physical and mental condition as well as our coaching and the implementation of our coaching and to develop further functions of the App based on this.
If you contact us by e-mail, via the App or in any other way, the data you provide will be automatically stored. This data is used for the purpose of processing your contact
c. Contractors' programmes:
If you receive or obtain the App through an offer provided by your employer, fitness centre, sports provider, health insurer or other contractor, or if you use a contractor’s programme available through the App, then we will also collect this information and the programme you have chosen.
We use this information to provide you with the app and the services under the programme of the contractual partner. Under no circumstances do we pass on personal data about you to the contractual partner without your express consent.
d. Automatically collected data:
When you activate and use the App, certain data is automatically collected, e.g. device manufacturer, operating system, settings, MAC address and other details about your smartphone, IP address, date and time of use, pages visited and content viewed, functions used, Apple Health as well as Google Fit data and others (if permitted by you).
Certain functions require the use of your device’s location. We only collect and use location data if you actively share it.
We need this data primarily to be able to provide you with the App and the App’s functions and to ensure the proper and secure operation of the App. We also use this information to improve and further develop the App and our offers. For this purpose, the data is evaluated on an aggregated basis, for example to determine which pages and functions are favoured or how many accesses occur and when.
e. Aggregated data
We may aggregate the personal data that you and other App users provide. Provided that the aggregated data does not personally identify you or any other person, we may use such aggregated data for the purposes set out in section 2 and for any other purposes.
In addition to the aforementioned purposes, we may also use the personal data collected to assert or enforce our legal claims (e.g. in the event of unauthorised access to the App), to defend ourselves in connection with legal disputes and official proceedings, and to prevent and investigate criminal offences and misuse of kinastic’s services.
3. Legal basis
The use of the App and the entry of personal data is voluntary. If you want to use the App, you must register and enter certain information in the App. By registering, a contract is concluded between you and us. The processing of personal data is necessary for the performance of this contract and the provision of the functions of the App. The processing is also in our legitimate interest. It enables us to better and more specifically tailor our services to your needs and interests and to expand and improve our offerings. We rely on your express consent for the processing of particularly sensitive personal data such as health data and any disclosure of such data to third parties (for example, within the scope of programmes of contractual partners). Depending on the functions offered, we may also ask for your consent in other cases.
4. Cookies, Analytics, Tools and other technologies related to the use of the app
The App uses „cookies“, i.e. small text files that are stored on the user’s terminal device. Cookies allow the identification of the user and are used to provide more user-friendly, effective and secure services. Cookies only collect data as listed in this clause 4 or in clause 2.
b. Analytics tools
We use Firebase Analytics and Google Analytics to measure App usage. Firebase Analytics and Google Analytics are services provided by Google Inc.
With the help of these tools, user behaviour within our App can be determined. When you install the App, we record when and for how long the App is used, which pages of the App are visited, which functions are selected and which content is displayed. This allows us to understand how you interact with our App.
If you wish to object to interest-based advertising by Google marketing services, you can use the settings and opt-out options provided by Google at http://www.google.com/ads/preferences .
You can revoke your consent to the use of Firebase and Google Analytics in the App settings at any time with effect for the future. Deactivating this function does not affect the normal operation of the App.
5. Disclosure of personal data and transfer abroad
We disclose personal data to third parties in the course of our business activities and for the purposes set out in section 2, to the extent permitted by law. Such third parties are in particular the following entities:
- External IT service providers of ours who provide services to us to enable us to provide the App and its functionality, for example, the provision of IT infrastructure, software, data analytics, email delivery and other services.
- Contractual partners under special programmes (e.g. your employer or your health insurance), provided you have given us your consent to do so.
- Recipients chosen by you, if you have chosen this accordingly in the App, e.g. by sharing data with a specific person.
- Acquirers or parties interested in acquiring divisions, companies or other parts of kinastic AG, in connection with a reorganisation, merger, transfer or other disposal of our company, our assets or parts thereof.
We also use and disclose your personal information, including health information, when we believe it is necessary or appropriate:
- To protect the rights, privacy, safety or property of us, you or others.
The recipients of the data can be anywhere in the world. In particular, you must expect the transfer of your data to other countries in Europe and the USA, where our IT service providers are located (such as Google). The hosting of the website and your data happens on Google servers in Zürich/Switzerland.
We take the legally required precautions to protect personal data when it is transferred abroad. If we transfer personal data to a country without adequate legal data protection, we ensure an adequate level of protection by concluding data protection clauses with the recipients of the data as provided for by law or rely on the legal exceptions such as your consent, the conclusion or performance of a contract, the establishment, exercise or enforcement of legal claims. You can obtain further information and a copy of the contractual guarantees mentioned from the office mentioned in point 1.
6. Storage Period
We will retain your data for as long as it is necessary for the purpose for which it was collected (e.g. as long as your user account exists and is active, we will also retain the registration and usage data) and beyond that in accordance with the statutory retention and documentation obligations or as far as we have a legitimate interest in retaining it (e.g. for evidence purposes or for IT security).
App profiles, including the profile data provided by the user, can be deleted by us in the event of inactivity three years after the last login.
As soon as your personal data is no longer required for the above-mentioned purposes, it will be deleted or made anonymous as far as possible. The personal data collected during registration is generally stored at least for the duration of the registration.
For operational data (e.g. system logs, logs), shorter retention periods of twelve months or less apply in principle.
7. Data Security
We take reasonable technical and organisational precautions to protect your personal data from unauthorised access and misuse and from the risk of loss, accidental alteration or unintentional disclosure. Although we and our technical partners do our best to protect your personal data, we cannot guarantee the security of any information transmitted to and through the App. Any transmission is at your own risk.
Please keep your access data for your user account carefully and do not pass them on.
8. Your rights
You have the right to request information about the personal data concerning you as well as its correction or deletion. The data you have entered can be viewed at any time within the App and can be corrected and deleted by you there. If you delete your user account or data in the App, this data will be deleted or anonymised so that no further personal reference can be made. Data that has already been aggregated remains aggregated.
If the processing is based on your consent, you have the right to revoke this consent with effect for the future. Such a revocation does not affect the lawfulness of the data processing carried out until the revocation.
To exercise such rights, please contact us at the contact address in section 1. If you incur any costs, we will inform you in advance.
For our part, we reserve the right to invoke the restrictions provided for by law, for example if we are obliged to retain or process certain data, require it for the assertion of claims or have another overriding interest.
A data subject also has the right to enforce his or her claims in court or to file a complaint with the competent data protection authority. The competent data protection authority in Switzerland is the Federal Data Protection and Information Commissioner (www.edoeb.admin.ch). The competent data protection authorities of EU countries can be found at this link: https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm
9. Changes to the data protection declaration