Privacy Policy
At AthleteApp we take your privacy seriously. This policy explains what personal data we process when you visit athleteapp.io or write to us through the contact form, for what purpose, and what rights you have over it. It covers the website; the processing of data within the AthleteApp mobile app is governed by the terms provided in the service itself.
This is a courtesy translation. In case of any discrepancy, the Spanish version prevails.
Data controller
The controller of your personal data is:
- Owner: ZeroGravity SL (“AthleteApp”, “we”, “us”).
- Tax ID (NIF / CIF): available on request by writing to hello@athleteapp.io.
- Registered address: Carrer Coll de Solanet, 2 (08181) Sentmenat.
- Contact email: hello@athleteapp.io.
For any question about this policy or about how we process your personal data, you can write to us at hello@athleteapp.io.
What data we process
We only process the data needed for the purposes described below. Specifically:
- Contact form data. When you fill in the form you give us your name, your organization (optional), your email address and the message you write. You provide this data voluntarily.
- Technical browsing data. Like any website, our server and our hosting provider automatically log technical data such as your IP address, the type and version of your browser and device, the date and time of your visit and the pages requested. We also use your IP address to limit the number of form submissions and prevent abuse (anti-spam).
- Aggregated usage data. Statistical information about how the site is used (see the “Analytics and cookies” section).
We do not ask you for special categories of data (health data, biometric data, etc.) through this website. Please do not include sensitive information in the form message.
Purposes and legal basis
We process your data for the following purposes, each with its legal basis under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD):
- Answering your inquiry sent through the form, including sending a confirmation email. Basis: taking steps at your request prior to entering into a contract, or your consent when you submit the form (Art. 6(1)(b) and 6(1)(a) GDPR).
- Keeping the site secure, preventing abuse and fraud, and maintaining technical logs. Basis: our legitimate interest in protecting the service (Art. 6(1)(f) GDPR).
- Measuring site usage in aggregate in order to improve it. Basis: your consent where required, or our legitimate interest where the analytics are anonymous (Art. 6(1)(a) / 6(1)(f) GDPR).
- Complying with legal obligations that apply to us. Basis: compliance with legal obligations (Art. 6(1)(c) GDPR).
Analytics and cookies
We want this website to respect your privacy by default:
- We do not use advertising, profiling or cross-site tracking cookies, and we do not sell your data to third parties.
- To understand how the website is used—for example, number of visits, most viewed pages, device type or approximate region derived from the IP address—we may use privacy-respecting analytics tools that process information in aggregate and, wherever possible, without identifying you personally or setting tracking cookies.
- The site may use the storage that is strictly necessary for it to work (for example, remembering your reduced-motion preference or the state of the interface). That storage is not used to track you.
- If in the future we add analytics or third-party services that require your consent, we will ask for it beforehand through a cookie notice, where you will be able to accept or reject them. In any case, you can configure your browser to block or delete cookies.
Recipients and data processors
We do not share your data with third parties unless legally required. To provide the service we rely on providers that act as data processors on our behalf and under contract:
- Hosting and infrastructure: Vercel Inc., which hosts and serves the website and processes the associated technical logs.
- Email delivery: Resend (Plus Five Five, Inc.), which processes the form data (name, organization, email and message) to deliver your inquiry to us and send you the confirmation email.
These providers only process the data following our instructions and with the safeguards required by data protection law.
International transfers
Some of our providers (such as Vercel or Resend) are located in, or may process data in, the United States. When an international transfer of data outside the European Economic Area takes place, it is covered by the safeguards provided for in the GDPR, such as the Standard Contractual Clauses approved by the European Commission or the applicable adequacy frameworks (for example, the EU-U.S. Data Privacy Framework).
Data retention
We keep contact form data for as long as needed to deal with your request and, afterwards, for the period during which legal liabilities may arise. Technical and security logs are kept for a limited period. When data is no longer needed, it is deleted or anonymized.
Your rights
You can exercise the following rights over your personal data at any time:
- Access your personal data.
- Request the rectification of inaccurate data.
- Request the erasure of your data.
- Object to the processing or request its restriction.
- Request the portability of the data you have provided to us.
- Withdraw the consent you have given, without affecting the lawfulness of the processing carried out before the withdrawal.
To exercise them, write to us at hello@athleteapp.io stating the right you wish to exercise. If you believe we have not handled your request properly, you have the right to lodge a complaint with the Spanish Data Protection Agency, the AEPD (www.aepd.es).
Minors
This website and its contact form are intended for people over the age of 14 (clubs, federations, coaches and adults interested in the app). We do not knowingly collect data from anyone under that age through the website. The processing of data of underage athletes within the app is governed by the specific terms of the service and, where applicable, requires the consent of those holding parental authority or guardianship.
Security
We apply reasonable technical and organizational measures to protect your data, such as encrypting communications over HTTPS, limiting form submissions and restricting access to information. No system is completely infallible, but we work to keep your data protected.
Changes to this policy
We may update this policy to reflect changes in the law or in the service. We will publish the current version on this page, stating the date of the last update. We recommend that you review it periodically.
Contact
If you have any questions about this policy or about how we process your data, write to us at hello@athleteapp.io. See also our Terms of Use.