07Legal
Platform privacy.
The platform holds a coach's roster and an athlete's training history. That makes the question of who decides what happens to the data as important as what we collect — so this policy answers that first.
Last updated 2026-08-29
This policy covers the Veliard training platform, the coach web application, and the Veliard iOS and Android apps. The website privacy policy covers veliard.com and does not apply here.
07.1What this policy covers
- Controller
- Veliard Ltd, reg. HE493832, Anastasiou Sioukri 1, Themis Court, 4th Floor, Office 402, 3105 Limassol, Cyprus — for the processing described in 07.2 as ours
- Contact
- contact@veliard.com
- DPO
- Article 37 has to be re-run once the platform is live. Regular and systematic monitoring, or large-scale Article 9 processing, would make a DPO mandatory; the answer today is not the answer after launch.
- Applies to
- The Veliard platform, the coach web application, and the iOS and Android apps
07.2Our role: controller and processor
This is the part worth reading carefully, because it decides who you ask when you want something done with your data. We are not in a single role. We are the controller for some processing and a processor acting on a coach’s instructions for the rest, and the line between them is drawn here rather than left to be inferred.
We are the controller for your account itself: registration, authentication, device and session security, subscription and billing, support correspondence, product diagnostics, and the notices we are legally required to send you. We decide why and how that happens, so requests about it come to us and we answer them.
We are a processor for the training content held in a coach’s roster: the programmes they write, the sessions they assign, the history they review, and the notes they keep on an athlete. The coach decides why that data exists and what is done with it, which makes them the controller. We hold and serve it on their instructions under the data processing agreement, and we do not use it for our own purposes.
If you signed up on your own, without a coach, there is no second controller: we are the controller for everything, including your training content, and every request comes to us.
The practical consequence: we can always delete your account at your request — see07.9 — because we control it. We cannot unilaterally erase the training record a coach holds about you in their roster, because that is theirs to decide, exactly as a gym cannot be made to destroy its own records by a member asking its software vendor. Ask the coach; we will pass the request on, tell you we have done so, and act the moment they instruct us.
07.3What the platform collects
- 01Account and identity. Email address, display name, password hash or the identifier from the sign-in provider you chose, language and unit preferences, and the date you accepted these terms.
- 02Training content. Exercises, sessions, loads, sets, repetitions, tempo, rest, RPE, estimated and tested maxima, session notes, and the programme a coach assigns to you. This is the substance of the product.
- 03Body and readiness entries, where you enter them. Bodyweight, and any optional field the product offers for readiness, soreness, sleep, injury status or restriction. These are treated separately — see 07.4.
- 04Device and app data. Device model, operating system version, app version, language, crash and error diagnostics, and the IP address the request arrives from. Push notification tokens where you enable notifications.
- 05Advertising identifiers. None. The apps do not read the IDFA on iOS or the Advertising ID on Android, contain no advertising SDK, and present no App Tracking Transparency prompt because there is nothing to ask about.
- 06Support and correspondence. What you write to us, and the thread it belongs to.
- 07Billing. Subscription status, plan, renewal date and the store or payment reference. Card numbers never reach us — see 07.10.
We do not buy personal data, we do not sell it, and we do not share it for anyone else’s marketing. There is no advertising in the product and no plan to add any.
07.4Training data, and where it becomes health data
Sports platforms often declare everything they hold to be health data. That is the wrong call and it damages the product: if the training log itself were special category data under Article 9, the only available basis would be explicit consent, and a withdrawn consent would have to switch the app off. So the line is drawn deliberately.
Ordinary personal data. What you lifted, for how many repetitions, at what tempo, how hard it felt, and what your coach programmed next. A training log records performance, not a state of health, and it is processed to deliver the service you signed up for — Article 6(1)(b).
Special category data under Article 9. Fields that describe a body rather than a performance: an injury, a pain or restriction entry, a medical note, a pregnancy, a menstrual cycle entry, or a physiological measurement imported from a wearable. Where the product offers such a field, it is optional, it is marked as such in the interface, and it is processed only on your explicit consent under Article 9(2)(a), which you can withdraw at any time without losing the rest of the app.
For clarity on a term that is routinely misused: “biometric data” in Article 9(1) means data processed to uniquely identify a person — a fingerprint or a face template. A heart rate is not biometric data in that sense. Where you unlock the app with Face ID or a fingerprint, the comparison happens on your device inside the operating system; we receive only a yes or no and never the template.
07.5Young athletes
Coaching platforms attract minors, so this cannot be left implicit. You may create your own account only if you are 16 or older. Cyprus has set the age of consent for information society services at 14 under Article 8(1) GDPR, and other member states set theirs between 13 and 16; where our threshold is higher than the local age, the higher one applies.
A younger athlete can still be coached on the platform, but not by signing up alone. The coach adds them to a roster, and the coach is responsible — as controller — for holding the consent or authorisation of the holder of parental responsibility, and for being able to evidence it. That obligation is written into the data processing agreement.
Accounts belonging to minors get the same treatment as everyone else with two differences: no optional Article 9 fields are offered, and no product analytics are collected even where an adult would be asked for consent.
If you believe a child has an account they should not have, write to contact@veliard.com and we will check and, if you are right, delete it.
07.6Purpose, legal basis, retention
Where we rely on legitimate interest, you can object under Article 21 and we stop unless we can show compelling grounds that override yours. Where we rely on consent, withdrawing it is as easy as giving it and does not cost you the rest of the service.
07.7Analytics, SDKs and consent
A mobile SDK that writes to or reads from your device is treated exactly like a cookie. Article 5(3) of Directive 2002/58/EC is written around “storing information, or gaining access to information stored, in the terminal equipment” — it says nothing about browsers, so an app has no exemption a website would not have.
The consequence, and we would rather state it than bury it: analytics are off when the app first launches. Nothing analytical initialises, and no identifier is written, until you have made a choice. You are asked once, in plain language, with refusing exactly as easy as accepting, and you can change the answer later in settings at any time. There is no dark pattern here, no pre-ticked box, and no “we will ask again next week”.
Crash reporting runs without that prompt. It is limited to what is strictly necessary to keep the app functioning and to diagnose a failure you have just experienced, it carries no advertising or cross-app identifier, and it is not used to build a profile. Where a crash report would carry a device identifier beyond that narrow purpose, it is consent-gated with the rest.
The SDKs actually present will be listed here by name, purpose and vendor before launch. That list is also what the store questionnaires must be answered from.
07.8Notifications
Push notifications are optional and off until you allow them at the operating system prompt. Enabling them creates a push token tied to your installation, which we hold to deliver messages about your own training — a session assigned, a programme updated, a message from your coach.
We do not send marketing push notifications. Turning notifications off in the operating system, or in the app, stops them; the token is deleted when you revoke permission, sign out or delete the account.
07.9Deleting your account and your data
You can delete your account from inside the app, without contacting us and without talking to a salesperson, and from the web at veliard.com/delete-account without installing anything. Both routes exist because Apple requires the first and Google requires the second, and both are the right thing to offer regardless.
What deletion does, precisely, so there is no surprise:
- Your account, credentials, sessions, devices and push tokens are deleted.
- Training content you own — anything you created outside a coach’s roster — is deleted.
- Any Article 9 entries you made are deleted, whoever holds the roster.
- Analytics identifiers are deleted and any analytics consent is withdrawn.
- Training content inside a coach’s roster stays with the coach, who controls it. We tell you which coaches hold data about you so you know whom to ask, and we pass your request on.
- Records we are legally required to keep — invoices and statutory accounting — survive for the six years Cyprus law requires, in accounting systems, not in the product.
Deletion completes within 30 days, including in backups, which roll off on their own schedule rather than being edited. Until a backup expires the data is inert: it is not readable by the product and is only ever restored as a whole after a disaster.
07.10Who else processes it
Each provider below is engaged under a written Article 28 agreement, and none of them may use your data for their own purposes. Card details go directly to the payment provider or the app store and never reach our servers — we see a subscription status and a reference, not a card number.
The names in that list will be filled in once the platform is live and the actual providers are chosen; the categories and their purpose will not change.
Apple and Google are not on that list. Where you subscribe through an app store, the store is the seller and processes your payment as its own controller under its own policy, not as our processor.
Business customers are notified before a sub-processor is added or replaced and may object, on the terms set out in the data processing agreement. We may also disclose data where a court or competent authority lawfully requires it.
07.11Transfers outside the EEA
We keep processing inside the EEA where we can, and the hosting region for the platform database is an EU region.
Where a provider processes data outside the EEA, the transfer runs on an adequacy decision or on the European Commission’s Standard Contractual Clauses with a transfer impact assessment on file. For providers in the United States we check whether the specific entity is certified under the EU–US Data Privacy Framework rather than assuming it — the Framework covers only organisations that have self-certified and remain on the list — and we keep Standard Contractual Clauses in place as a fallback, because an adequacy decision can be annulled and this one has been challenged. Ask us which mechanism covers a specific provider and we will tell you.
07.12Security
Traffic is encrypted in transit with TLS and data is encrypted at rest. Access to production is limited to the people who need it, protected by multi-factor authentication and logged. Passwords are stored only as salted hashes from a memory-hard function, never recoverably. Rosters are separated so that one coach cannot read another’s, and that separation is enforced in the data layer rather than in the interface.
Where a personal data breach is likely to result in a risk to your rights, we notify the Office of the Commissioner for Personal Data Protection within 72 hours and tell you without undue delay. Where we are the processor, we notify the coach without undue delay so they can meet the same deadline.
07.13Your rights
You can ask for access to your data, correction, erasure, restriction of processing, portability, and you can object to processing based on legitimate interest. Where processing rests on consent you can withdraw it at any time, which does not affect what was lawful before you withdrew it. There is no automated decision-making with legal or similarly significant effects: a training recommendation is a suggestion to you and your coach, not a decision taken about you.
Send requests to contact@veliard.com. We answer within one month and say so if a complex request needs the extension Article 12(3) allows. Exercising a right is free.
If the request concerns training content in a coach’s roster, we are the processor and cannot decide it. We will tell you that plainly, name the coach, and forward the request rather than leaving you to start again.
07.14Complaints and changes
Tell us first if something has gone wrong — it is usually faster. You also have the right to complain to the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, or to the supervisory authority where you live or work.
When this policy changes materially we update the date at the top, and where the change affects data we already hold we tell affected users in the app or by email rather than relying on you to re-read the page. Where a change requires consent, we ask for it before the change takes effect. Earlier versions are available on request.
Want your account and its data gone?
Delete your account