Privacy Notice

Updated 24 September 2026 · Draft under review

Legal documents
Contents
Document in preparation

Testing draft. This document is not yet active; company and operational details must be completed before activation.

Privacy Notice

1. About this notice

This policy explains data used through the Vulkio website and application, who determines its use, purposes, recipients and available choices. It addresses visitors, professional trainers and adult clients in Romania and the EU. Reading or acknowledging it is not consent to every operation described.

This is an inactive draft. Identity, contacts, schedules and safeguards marked “—” must be completed before using it as an active notice.

2. Controllers and contact details

Proposed entity: Vulkio SRL — company in formation. Registration/tax number: —. Registered address: —. Data protection contact: —. Data protection officer, if designation is applicable: —; this field does not imply an officer has been appointed.

The trainer identified in the coaching relationship controls client records, coaching and their own publications and must supply their identity, contact and notice. Vulkio processes these records on documented trainer instructions as processor. Vulkio determines purposes for its own trainer account administration, own billing, platform security and own reposting, with corresponding controller duties. Roles depend on the actual operation, not merely contractual labels.

3. Information you provide

Account and contact data include name, email, profile information, birth date when requested for age verification and the chosen avatar. Coaching records include bookings, attendance, goals, plans, form responses, messages and progress information.

Sensitive records include weight, body fat, muscle mass, waist and other measurements, limitations, injuries and health information in submitted content. Progress photographs may reveal health. An ordinary avatar is separate from progress photographs and is not used for biometric identification in the functions described here.

4. Information from trainers and other providers

Trainers may enter client details, bookings, observations, plans, measurements and commercial records. Application stores and RevenueCat provide purchase and entitlement information. Stripe supplies information needed to track trainer payments. Communication providers may return email or notification delivery status.

These records do not necessarily come directly from the client. The responsible controller provides indirect-collection information within applicable time limits; an invitation or approval flow does not justify earlier sensitive-data use without a legal basis.

5. Technical data and device permissions

Operating the website and APIs may involve IP addresses, request times, browser or device characteristics, session identifiers and error or security records. Notifications may involve device tokens. Camera, photo library and notification access use operating-system permissions for requested functions.

Device camera permission is not permission to publish photographs. Device settings allow permissions to be changed; dependent functions may become unavailable.

6. Purposes and legal bases for Vulkio operations

Professional account administration, contracted access and necessary support rely on contract performance or pre-contractual steps under GDPR Article 6(1)(b). Tax records and other mandatory retention rely on the applicable legal obligation under Article 6(1)(c); specific laws and schedules must be completed in the retention register.

Preventing unauthorised access, investigating incidents and defending rights may rely on legitimate interests under Article 6(1)(f), following assessment of necessity and individuals’ rights. That basis does not automatically authorise health-data use. Vulkio reposts described in the dedicated permission rely on the optional choice for the stated purpose and destinations.

7. Coaching and sensitive-data bases

Trainers determine the basis for administering their client relationship and explain their own uses. In the described functions, health processing for coaching and publication of body results require explicit consent separately for each purpose under Articles 6(1)(a) and 9(2)(a). Photograph permission covers private use and requires health permission where images reveal such data.

Vulkio does not replace trainer notices or supply blanket permission to use all records. A trainer contract alone is not an exception allowing health-data processing.

8. Publishing names, avatars and results

One ranking choice covers name, avatar, position, completed sessions and described attendance streaks. A separate review choice covers name and avatar alongside a review. Public body results and Vulkio reposts have separate choices. Ordinary avatar permission does not cover progress photographs.

Specific destinations — the trainer website and identified X, Facebook, Instagram or TikTok accounts, or Vulkio accounts — are displayed before consent and recorded with its evidence. A new destination requires a new choice. Shareable rankings exclude ineligible clients; appearing in an internal ranking does not make private information public.

9. Website storage and traffic analytics

Authentication and preferences may use session and device-storage mechanisms. The website integrates Vercel Analytics; in the verified implementation it is excluded from /privacy/ approval routes but is not gated by an analytics selector elsewhere. We do not claim a rejection button exists where it has not been implemented.

The exact storage inventory, transmitted information, durations and traffic-analysis basis are —, to be verified before this policy becomes active. Non-essential technologies requiring permission must not run without an appropriate mechanism. Browser restrictions can affect technical functions and do not replace controller obligations.

10. Recipients

Recipients include the authorised trainer, personnel requiring access for their duties and providers needed for selected functions. Supabase provides database, authentication and storage functions; Vercel hosting and analytics; Resend transactional email; Stripe trainer payments; RevenueCat subscription synchronisation; Apple and Google stores and related services. Actual Expo Push Service, APNs and FCM notification configuration must be confirmed.

Authorities, advisers or other recipients may receive necessary data where an applicable obligation or basis exists. Authorised publications are accessible to the public and selected external platforms. Payment providers and stores may act as controllers for their own duties, not solely as Vulkio processors. The provider and retention notice supplies further details.

11. Processing locations

The confirmed Supabase project region is Ireland. This does not imply that every operation, support activity or other provider service takes place only in Ireland or the EEA.

For each transfer outside the EEA, the recipient, country and applicable mechanism must be identified — adequacy decision, standard contractual clauses or another permitted mechanism, with required assessments. Verified details and how safeguards can be obtained: —. A provider is not assumed to qualify for a mechanism merely because its service is used.

12. Retention

Retention depends on purposes, the contractual relationship, requests and applicable obligations. The retention notice distinguishes account, coaching, photograph, payment, consent, log and backup records; unverified periods are marked for completion.

When withdrawing health or photograph permission, clients can explicitly choose 30 days of private preservation without coaching access. This is not the default. On expiry, the deletion workflow processes records and retries failures. We do not promise instantaneous deletion from every backup.

13. Data security

Implemented measures include authentication, trainer–client relationship checks, function and media access controls, consent checks and decision records. Internal access must be limited to duties and confidentiality. Measures and procedures are assessed proportionately to risk.

No service can guarantee absolute security. Incidents are handled according to controller and processor responsibilities, including legally required notifications. The operational measures inventory and incident contact procedure must be completed before activation.

14. Rights and requests

Subject to GDPR conditions, you can request access and a copy, correction, erasure, restriction or portability, and object to legitimate-interest processing. Direct-marketing objections do not require justification. Rights differ between situations; a refusal must be explained with information on challenging it.

Use available Settings → Privacy functions or contact the responsible controller. Coaching requests go to the trainer, assisted by Vulkio. The contact for Vulkio’s own purposes is —. Identity verification is proportionate. Responses are normally provided within one month; a justified extension of up to two further months is notified within the first month. Requests are generally free, subject to legal exceptions.

15. Withdrawal and required information

Permissions can be withdrawn in privacy settings without affecting the lawfulness of earlier processing. Declining publicity does not remove authorised coaching; withdrawing health or photograph permission stops dependent functions. Account administration data may be necessary for the requested service; consequences of not providing it are explained in the relevant flow.

Publication withdrawal stops future exports and relevant displays controlled by Vulkio. Downloaded and externally reposted copies are not automatically deleted. The responsible controller handles recipient requests as required by law. Optional preservation does not reauthorise coaching.

16. Children and automated decisions

The described service is for people aged at least 18. If a minor’s information is identified contrary to this rule, the controller investigates and restricts or erases it according to the circumstances and applicable obligations.

Rankings and charts calculate statistics from available records; the verified functions do not make solely automated decisions producing legal or similarly significant effects. Any future such use requires prior information and assessment.

17. Complaints

You may complain to ANSPDCP using contact information at https://www.dataprotection.ro, or to the competent EU authority where you habitually reside, work or consider an infringement occurred. Using the service does not require giving up a complaint or court action.

18. Updates and related documents

Relevant changes are communicated appropriately, and new purposes requiring consent are presented before a choice is made. Publishing a revised policy does not automatically grant optional permissions. Terms, DPA, health and photograph agreements, publication information and the provider register are available in the website’s Legal documents section.

Retention and providers

1. Scope and responsibilities

This notice supplements the Privacy Notice and DPA. Vulkio SRL — company in formation (registration, address and contact: —) retains records for its own purposes and separately on the trainer’s behalf. Trainers determine coaching instructions while respecting client rights. This is a service inventory, not evidence that contracts or transfer authorisations have been completed.

2. Accounts and coaching records

Necessary account information is retained to administer the relationship and subsequently only for justified purposes or applicable obligations. Coaching records and photographs follow authorised permissions and instructions. Post-closure periods, inactive-account rules and the technical deletion completion window: —. These must be set before activation and do not mean unlimited retention.

3. Private 30-day preservation

When withdrawing health or photograph permission, clients may expressly choose 30 days of private preservation. It is not automatic. Preserved information is unavailable for coaching, publication or trainer export. Withdrawal takes effect even where physical deletion follows later.

At expiry the deletion workflow runs and retries failed operations. Valid new authorisation before deletion may restore functions; preservation does not itself authorise resumption. Ordinary avatars are not automatically included in progress-photograph deletion.

4. Transactions, permissions and disputes

Fiscal records follow obligations applicable to the entity and document category. Specific periods and legislation: —, to confirm. Transaction identifiers do not justify retention of an entire coaching file.

Acceptance, withdrawal and publication evidence is retained to demonstrate operations and handle requests or disputes. Duration, starting event and authorised access: —. A legal or litigation hold must be documented and limited to necessary records, without reuse for coaching or publicity.

5. Logs, technical messages and backups

Security, delivery, error logs and processing queues have limited operational purposes. Retention, rotation, access and backup deletion schedules are —. Restorations must reapply relevant withdrawals and deletions; a backup must not reactivate withdrawn consent.

Independent-controller provider records may follow separate schedules explained in provider notices. Vulkio does not promise automatic deletion of external copies or simultaneous deletion across every system.

6. Supabase and Vercel

Supabase: database, authentication and storage for accounts, trainer–client relationships, content and materials. Confirmed project region: Ireland. Contracting entity, support access, other locations, subprocessors and backup periods: —.

Vercel: website and API hosting, request technical data and information necessary to serve functions. Vercel Analytics is integrated except on /privacy/ approval routes. Configuration, actual collected information, legal basis, locations and periods: —, to verify. The verified implementation has no general traffic-analytics selector.

7. Stripe, RevenueCat, Apple and Google

Stripe: trainer service payment processing with necessary transaction, customer and merchant information. Roles differ for instructed operations and its own payment, verification or fraud-prevention duties. Contract, entity, locations and retention: —.

RevenueCat: verifying/synchronising software purchases and entitlements using identifiers and purchase information. Apple App Store and Google Play: distribution and store purchases, with their own roles and terms. They do not receive progress photographs merely because they administer a subscription. Entities, countries, exact categories and periods: —.

8. Email and notifications

Resend: transactional emails involving recipient addresses, necessary message content and delivery information. Message configuration, locations and log periods: —.

Expo Push Service, APNs and FCM: notification infrastructure according to the actual configuration. Device tokens and notification content may be required. Actual use, entities, transmitted records, locations and periods: —, to confirm. Device notification permission does not authorise publicity or data publication.

9. Public platforms and independent recipients

Trainer websites and identified social accounts are destinations only for authorised publications. X, Facebook, Instagram and TikTok may process content and visitor data under their policies. They are not automatically Vulkio subprocessors. Exact accepted accounts are recorded with consent evidence; permission for every platform is not implied.

10. Transfers, updates and outstanding details

Each service requires confirmation of legal entity, role, hosting and access countries, outside-EEA transfer mechanism and available safeguards, plus retention by category. The Irish Supabase project region does not resolve these questions for all operations.

Subprocessor changes follow DPA notice and authorisation. New publication purposes or destinations require appropriate client choices. This draft must not be activated before operational fields and contacts are completed and contracts and actual configuration verified.