Tandivia

Privacy policy

Last updated:

Draft pending review. The fields marked TODO must be completed by the controller before the site goes live, and the whole text should be reviewed by someone with legal judgement. It describes the product’s actual processing, but it does not replace that review.

1. Controller

  • Owner: TODO: full name or company name
  • Tax ID: TODO
  • Address: TODO
  • Contact email: hola@tandivia.com

2. What data we process

About visitors to this site: none. This site is static, sets no cookies, includes no analytics or third-party scripts and submits no forms. The server keeps HTTP request logs (IP address, timestamp, resource and user agent) for security and diagnostics.

About people using the application (app. + this domain), where an account exists:

  • Account data: name, email address, hashed password, language, time zone and weight unit.
  • Training data: programmes, microcycles, completed sets, loads, repetitions, effort and the estimates derived from them.
  • Physical data entered by the user, such as body weight, needed to compute strength estimates.
  • Relationship data: assigned coach and the organization the user belongs to.
  • Technical session data: session and refresh identifiers with their expiry dates.
Purpose Legal basis
Providing the planning and tracking service Performance of a contract
Keeping the session and the account secure Contract and legitimate interest
Answering enquiries received by email Legitimate interest of the sender
Meeting tax and accounting obligations Legal obligation

Physical and training data are processed because they are the content of the service: without them there is no programming. TODO: confirm with an adviser whether, in this specific case, any of this data qualifies as health data under Article 9 GDPR and requires explicit consent.

4. Who else has access

  • Your coach and the leaders of your organization, where your account belongs to one: they access your programming and training history in order to program for you.
  • Hosting: OVHcloud, with the application server located in Gravelines, France.
  • Transactional email: Brevo, for invitations, password recovery and operational notices.
  • Backups: Backblaze B2, in the European region configured for the repository.
  • Data is never sold or shared with third parties for advertising.
  • No international transfers outside the European Economic Area take place. TODO: confirm once the final provider is chosen.

5. Retention

Data is kept while the account is active. A deletion requested from the application settings takes effect immediately and removes the account, its sessions and its own training data. A coach must first reassign their athletes and, if they are the leader, transfer leadership of the organization.

Backups remain encrypted and access-restricted until their automatic rotation: 7 daily and 4 weekly copies are kept. They are never used to recover a deleted account. Emails that exhaust their retries keep their encrypted content for no more than 7 days; delivered messages are removed from the queue. The only exception is data that must be retained under an applicable legal obligation.

6. Your rights

You can request access, rectification, erasure, objection, restriction and portability by writing to the address in section 1. If you believe the processing does not comply with the law, you can lodge a complaint with the Spanish Data Protection Agency (aepd.es) or your local supervisory authority.

7. Security

Passwords are stored hashed with a purpose-built derivation function, never in clear text. The session travels in httpOnly, Secure cookies that page JavaScript cannot read. All traffic is TLS encrypted and the database is backed up daily.

8. Changes

Any material change to this policy will be announced inside the application and reflected in the update date at the top of this page.