GROWDNA← Back to GROWDNA

Legal

Privacy Policy

This Privacy Policy explains what personal data GROWDNA processes, why, on what legal basis, and what rights you have. It is written with the EU General Data Protection Regulation (GDPR) in mind.

Last updated: [DATE]

Draft — pending legal review

This document is a product draft. It is not legal advice and does not guarantee legal compliance. All placeholders in [BRACKETS] must be completed and the full document reviewed and finalized by a qualified EU/Slovak lawyer before GROWDNA is publicly launched or paid services are activated.

Contents

  • 1. Who we are
  • 2. What data we collect
  • 3. Purposes of processing and legal bases
  • 4. Sensitive data
  • 5. Children and young athletes
  • 6. AI & automated processing
  • 7. Data retention
  • 8. Your rights
  • 9. How to contact GROWDNA about your data
  • 10. Third-party services
  • 11. International data transfers
  • 12. Security
  • 13. Cookies
  • 14. Changes to this Policy

The controller of your personal data is [LEGAL COMPANY NAME], [BUSINESS ADDRESS], company registration number [COMPANY REGISTRATION NUMBER], VAT number [VAT NUMBER].

General contact: [CONTACT EMAIL]. Data protection contact: [DATA PROTECTION CONTACT]. Privacy requests: [PRIVACY CONTACT EMAIL]. Website: [WEBSITE URL].

Whether a Data Protection Officer must be appointed will be confirmed during legal review. [SUBJECT TO LEGAL REVIEW]

We aim to collect only what is needed to run the Platform and deliver the features you use. Depending on how you use GROWDNA, the following categories may apply.

  • Account information: name, email, age or date of birth, account type, parent/athlete relationship.
  • Athlete profile information: sport, position, club, level, goals, development areas.
  • Performance information: training and match information, achievements, results, skill progression, challenges, test results, Game Mode results.
  • Mental-performance information: confidence- and focus-related information, emotional reflections, goals, self-assessments and AI interactions.
  • Physical information: workouts, training activity and physical data entered by the user.
  • Content: uploaded videos, profile information and other user-generated content.
  • Parent information: parent account information, parent/athlete relationship, Parent Mode interactions, Parent Guidance activity.
  • Payment information: billing details and transaction records. Payments are processed by [PAYMENT PROVIDER]; GROWDNA does not store full payment card details.
  • Technical information: IP address, device information, browser, operating system, cookies, usage information and security logs.

We identify a legal basis for every processing purpose. We do not rely on consent where another basis is more appropriate.

  • Account creation, authentication and providing the Platform — performance of a contract.
  • Personalization, AI Coach, Custom Plans, Game Mode, Challenges, Athlete ID, Parent Mode — performance of a contract (the features you request).
  • 1:1 coaching, bookings and related communication — performance of a contract.
  • Customer support — performance of a contract and our legitimate interest in helping users.
  • Payments, invoicing and accounting — performance of a contract and legal obligation.
  • Fraud prevention, security and abuse detection — legitimate interests and, where applicable, legal obligation.
  • Analytics and improving the Platform — legitimate interests or consent, depending on the tools used.
  • Service communications — performance of a contract. Marketing communications — consent or legitimate interests where permitted.
  • Child-safety measures and responding to reports — legitimate interests and legal obligation.
  • Legal compliance, claims and record-keeping — legal obligation and legitimate interests.

Most information in GROWDNA is general performance information: training activity, goals, reflections about confidence or focus, and self-assessments. This is not automatically health data.

However, some information you choose to enter — for example descriptions of injuries, medical conditions, or serious mental-health difficulties — may constitute special-category (sensitive) personal data under applicable law.

We ask you not to enter sensitive information unless it is necessary. Where such data is processed, we will only do so where an appropriate legal basis and additional condition exist, for example explicit consent. GROWDNA is not designed as a medical or clinical record system. [SUBJECT TO LEGAL REVIEW]

GROWDNA is designed for young athletes, so protecting children's data is central to how the Platform works.

  • Age or date of birth is collected so that experiences, content and AI tone can be age-appropriate.
  • Where applicable law requires it, a parent or legal guardian must authorize the account and, where relevant, consent to specific processing. The applicable age threshold depends on the country of residence and is configurable — the EU allows Member States to set it between 13 and 16. [SUBJECT TO LEGAL REVIEW]
  • Parental authorization can be requested and recorded through the parent account linking process.
  • Data minimization, restricted visibility and safe defaults apply to accounts identified as belonging to minors.
  • Parents or legal guardians may exercise applicable data-protection rights on behalf of a child, including access, correction and deletion, subject to verification and the child's own interests.
  • A child's account and associated data can be deleted on request, subject to any legal retention obligations.

To provide coaching responses, personalized recommendations, Custom Plans, Game Mode analysis, parent guidance and educational recommendations, your inputs are processed by AI systems operated by [AI PROVIDER / PROCESSOR].

What is sent: the message or input you provide plus relevant context from your profile and activity that is needed to generate a useful response. We aim to limit this to what is necessary.

Where the AI provider acts on our documented instructions, it is a processor under a data processing agreement. Where a provider acts as an independent controller, this will be identified. [SUBJECT TO LEGAL REVIEW]

Conversations may be stored in your account so you can revisit them and so the coaching remains continuous. Retention is described below.

We do not permit the use of your personal data to train third-party AI models unless you have been informed and, where required, have consented. [SUBJECT TO LEGAL REVIEW]

AI Features support your development; they are not used to make decisions producing legal or similarly significant effects about you.

We keep personal data only as long as necessary for the purpose it was collected for, or as required by law. Exact periods are being finalized:

  • Account data: [RETENTION PERIOD]
  • AI conversations: [RETENTION PERIOD]
  • Athlete development data (plans, challenges, journal, progress): [RETENTION PERIOD]
  • Payment and accounting records: [RETENTION PERIOD]
  • Marketing data: [RETENTION PERIOD]
  • Security logs: [RETENTION PERIOD]

Under the GDPR you have the following rights, explained in plain language:

  • Access — ask what data we hold about you and get a copy.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — ask us to delete your data where there is no overriding reason to keep it.
  • Restriction — ask us to pause processing in certain situations.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time.
  • Portability — receive data you provided in a structured, machine-readable format, or have it transferred where technically feasible.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting past processing.
  • Complain — lodge a complaint with the competent supervisory authority, for example the authority in your country of residence. [SUPERVISORY AUTHORITY]

Send privacy requests to [PRIVACY CONTACT EMAIL] or to [DATA PROTECTION CONTACT]. We may need to verify your identity before responding, and we will respond within the period required by law.

We use service providers to operate the Platform. Provider names are being finalized and will be listed here:

  • Hosting and infrastructure: [HOSTING PROVIDER]
  • Authentication and database: [AUTH / DATABASE PROVIDER]
  • AI processing: [AI PROVIDER / PROCESSOR]
  • Payments: [PAYMENT PROVIDER]
  • Analytics: [ANALYTICS PROVIDER]
  • Email delivery: [EMAIL PROVIDER]
  • Video and file storage: [STORAGE PROVIDER]

Some service providers may process data outside the European Economic Area. Where that happens, we use appropriate safeguards required by law, such as an adequacy decision or Standard Contractual Clauses, together with supplementary measures where needed.

The specific transfers, if any, depend on the final provider setup and will be confirmed here. [SUBJECT TO LEGAL REVIEW]

We apply technical and organizational measures appropriate to the risk, including access controls, encryption in transit, row-level access rules in the database and logging. No online service can be guaranteed to be perfectly secure.

We use cookies and similar technologies. Non-essential cookies are only used where a valid consent mechanism applies.

  • Necessary cookies — required for login, security and core functionality. Always active.
  • Preference cookies — remember choices such as language.
  • Analytics cookies — help us understand how the Platform is used. Used only with consent where required.
  • Marketing cookies — used only if and when marketing tools are introduced, and only with consent where required.
  • Cookie settings: [COOKIE SETTINGS] — a preference centre will be linked here once the cookie tooling is configured.

We may update this Privacy Policy. Material changes will be communicated by a reasonable means, and the date of the latest version is shown at the top of this page.

Terms & ConditionsPrivacy PolicyRefund & Cancellation PolicyCookie Settings
Edit with