GDPR Compliance

General Data Protection Regulation

Last Updated: January 30, 2025

For EU/EEA Users

This page provides specific information for users in the European Economic Area (EEA), United Kingdom, and Switzerland about how Beatrace complies with the General Data Protection Regulation (GDPR) and protects your rights.

1. Data Controller

Beatrace is the data controller responsible for your personal data. We can be reached at:

Beatrace Data Protection Officer

Email: dpo@beatrace.app

Address: [Your Company Address]

2. Legal Basis for Processing

Under GDPR, we process your personal data based on the following legal grounds:

Consent (Article 6(1)(a) and 9(2)(a))

We process your health data (heart rate, HRV, etc.) based on your explicit consent. You may withdraw consent at any time.

Contract Performance (Article 6(1)(b))

Processing necessary to provide the Service you've subscribed to, including account management and service delivery.

Legitimate Interests (Article 6(1)(f))

Processing for fraud prevention, security, service improvement, and analytics, where your interests don't override ours.

Legal Obligation (Article 6(1)(c))

Processing required to comply with applicable laws and regulations.

3. Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

πŸ” Right to Access (Article 15)

You can request a copy of all personal data we hold about you.

Response time: Within 1 month (may be extended to 3 months for complex requests)

✏️ Right to Rectification (Article 16)

You can correct inaccurate or incomplete personal data.

Available in-app settings or by contacting support

πŸ—‘οΈ Right to Erasure / "Right to be Forgotten" (Article 17)

You can request deletion of your personal data in certain circumstances.

Note: Some data may be retained for legal compliance

⏸️ Right to Restriction (Article 18)

You can request we limit how we process your data.

Applies when accuracy is contested or processing is unlawful

πŸ“¦ Right to Data Portability (Article 20)

You can receive your data in a structured, machine-readable format (JSON, CSV).

Includes health data, profile information, and activity history

🚫 Right to Object (Article 21)

You can object to processing based on legitimate interests or for direct marketing.

We will stop processing unless we have compelling legitimate grounds

βš–οΈ Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing.

Note: Beatrace calculations are algorithmic but not legally significant automated decisions

❌ Right to Withdraw Consent (Article 7(3))

You can withdraw consent for health data processing at any time.

Available in-app: Settings β†’ Privacy β†’ Manage Consents

4. How to Exercise Your Rights

To exercise any of your GDPR rights, you can:

πŸ“±

In-App

Settings β†’ Privacy β†’ Data Rights

πŸ“§

Response Timeline: We will respond to your request within 1 month. For complex requests, we may extend this to 3 months and will inform you of the delay.

5. Special Category Data (Health Data)

Your heart rate, HRV, and related metrics are classified as "special category data" under GDPR Article 9. We process this sensitive data based on:

  • Explicit Consent: You provide clear, affirmative consent during onboarding
  • Necessary Processing: Required to provide the Service you requested
  • Enhanced Security: Additional encryption and access controls
  • Anonymization: Health data is anonymized for leaderboards

6. International Data Transfers

Your data may be transferred outside the EEA. We ensure adequate protection through:

Standard Contractual Clauses (SCCs)

We use EU-approved Standard Contractual Clauses with all data processors outside the EEA.

Adequacy Decisions

We transfer data to countries with EU adequacy decisions where possible.

Supplementary Measures

End-to-end encryption and additional technical safeguards protect your data during transfers.

7. Data Retention

We retain your personal data only as long as necessary:

  • Active Accounts: Data retained while account is active
  • After Deletion Request: Personal data removed within 30 days
  • Anonymized Data: May be retained indefinitely for analytics
  • Legal Requirements: Some data retained as required by law (e.g., financial records for 7 years)
  • Backup Systems: Data in backups deleted within 90 days

8. Data Processing Activities

In compliance with GDPR Article 30, we maintain records of processing activities:

PurposeLegal BasisData Categories
Account ManagementContractName, Email, Profile
Health TrackingConsentHeart Rate, HRV
RankingsLegitimate InterestAnonymized Metrics
Payment ProcessingContractPayment Info
Service ImprovementLegitimate InterestUsage Analytics

9. Data Breach Notification

In the event of a data breach affecting your personal data:

  • We will notify the relevant supervisory authority within 72 hours of becoming aware
  • We will inform you without undue delay if the breach poses a high risk to your rights
  • Notifications will include the nature of the breach, likely consequences, and measures taken

10. Right to Lodge a Complaint

If you believe we have not complied with GDPR, you have the right to lodge a complaint with:

Your Local Supervisory Authority

Contact the data protection authority in your EU country:

Find Your Supervisory Authority β†’

Our Lead Supervisory Authority

[Name of your lead supervisory authority]
[Contact details]

11. Data Protection by Design

We implement data protection by design and by default:

  • Pseudonymization and encryption of personal data
  • Regular security assessments and audits
  • Data minimization - we only collect what's necessary
  • Privacy settings default to most protective options
  • Regular staff training on data protection
  • Privacy Impact Assessments for high-risk processing

12. Contact Information

For GDPR-related inquiries, contact our Data Protection Officer:

Data Protection Officer

Email: dpo@beatrace.app

GDPR Requests: gdpr@beatrace.app

Address: [Your Company Address]

We respond to all GDPR requests within 1 month. For urgent matters, please mark your email as "Urgent - GDPR Request."