Privacy Policy
- This Privacy Policy applies to the personal data of Users using the YouHero mobile application and Services (hereinafter collectively referred to as the "Application").
- Personal data means information about an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- The controller of personal data processed within the Application is Szczepan Wącław, Marcin Mazur YouHero s.c., with its registered office at ul. Uzdrowiskowa 11, 43-450 Ustroń, Poland, using Tax Identification Number (NIP): 5482765978, REGON: 540745093 ("Controller"). The Service Provider is the owner and operator of the YouHero mobile application and the domain www.youhero.be. In the further part of the Terms and Conditions, the Controller will also be referred to as "YouHero".
- For matters related to personal data protection, you may contact the Controller via email at hello@youhero.be or by mail at the address provided in point 3 above.
- YouHero collects, uses, discloses, and processes personal data in accordance with this Privacy Policy, including for the purposes of managing and improving the Services and our operations; for advertising and marketing purposes; and to provide you with innovative fitness-related services, as described in this Privacy Policy.
- In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR), and other applicable data protection regulations, we are committed to ensuring the security and confidentiality of your personal data. YouHero implements appropriate technical and organizational measures to protect data against unauthorized access, loss, or alteration, in compliance with legal requirements.
- While using the Services and the Application, we process your personal data in various ways and for various purposes, including:
- During account registration or interaction with our Services - we process personal data to conclude a contract for the provision of Services and to provide them, based on Article 6(1)(b) GDPR; this data may include login and password, email address, first and last name, correspondence address, and optionally nickname, weight, height, and reports from completed workouts; this data is used to create your User Account and enable you to use the Application's functionalities within our Services.
- When you communicate with us via the form in the Application or email address - we process personal data to conduct correspondence — for this purpose, we process, among others, your email address based on Article 6(1)(f) GDPR; we may send you notifications related to the performance of our Services, such as changes to our Terms and Conditions or this Privacy Policy, or other formal messages related to the Services; additionally, we may use your personal data to respond to your requests for technical support, information about the Services, including Paid Services, as well as to address your inquiries and complaints;
- We collect data through the Application used for the administration of the Services (including statistical purposes), e.g., IP address, device type information. More details about the types of data collected for statistical purposes can be found later in this Privacy Policy. The legal basis for processing data collected for statistical purposes is Article 6(1)(f) GDPR, i.e., the legitimate interest of the Controller in maintaining statistics related to the Application and Services, while the retention period depends on the data's usefulness for achieving the intended purpose and cannot be predetermined.
- As a rule, data is processed for the duration of the provision of Services or fulfillment of orders for Paid Services, until the withdrawal of consent or the submission of an effective objection to processing in cases where the legal basis for processing is the legitimate interest of the Controller. The data processing period may be extended if processing is necessary to establish and pursue potential claims or defend against them, and after that time, only to the extent and in cases required by law. After the processing period expires, data is irreversibly deleted or anonymized.
- The Application may contain buttons, tools, or content linking to third-party services, including advertising banners. Using these tools may result in the transfer of your data to the aforementioned external entities. The Controller is not responsible for the security of personal data processing on external services.
- The recipients of your personal data include entities processing data on behalf of the Controller, involved in the Controller's activities (e.g., Controller's employees), entities processing personal data under the Controller's instructions (e.g., providers of IT systems and services, including hosting and marketing service providers), providers of legal and advisory services (in particular law firms in case of a dispute), and other entities authorized to process data under applicable legal provisions.
- Due to YouHero's use of Google tools (Firebase), your data collected as a result of using the Application may be transferred to countries outside the European Economic Area. The Google tools used are provided — unless otherwise specified in any additional terms — by Google LLC, with its registered office at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and for users in the European Economic Area and Switzerland, by Google Ireland Ltd, registered and operating under Irish law (registration number: 368047), with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland (Google LLC or Google Ltd hereinafter referred to as "Google"). Since Google utilizes technical infrastructure located worldwide, including outside the EEA, Google has joined the EU-US Privacy Shield Framework and the Swiss-US Privacy Shield Framework to ensure an adequate level of personal data protection as required by Swiss and European regulations. Additionally, Google uses standard contractual clauses approved by the EU.
- Using Google Firebase, we process information regarding the number of Users, how they use the Application, their approximate geographical location, technical data about the device on which the Application is installed, statistical data on the number of Application installations, User retention, time spent in the Application, operating system versions used, Application versions, device models, and features used in the Application. This data processing aims to better understand User behavior and optimize the Application. Additionally, other Firebase features are used to detect causes of errors in the Application and send push notifications. Firebase's privacy policy can be found at firebase google data processing terms.
- More information on how to control the data collected by Google can be found at: Policies Google partner-sites.
- The Service does not automatically collect information from users, except for information contained in mobile identifiers as mentioned above.
- YouHero will not make automated decisions based on your personal data, including profiling.
- In accordance with GDPR provisions, every individual whose personal data we process as the Controller has the right to:
- access their personal data (Article 15 GDPR) - by providing us with data, you may access and review it; you have the right to know what data we process and for what purpose, and to receive a copy of it. The first copy is free of charge, while subsequent copies may incur an administrative fee in accordance with GDPR, corresponding to the cost of preparing it;
- rectify, supplement, update, or correct personal data (Article 16 GDPR) - if your data has changed or is incorrect (e.g., due to an error), please inform us so we can update or correct it;
- erase data, i.e., the right to be forgotten (Article 17 GDPR) - you may request the deletion of your data by YouHero, particularly when:
- the purpose for which the data was collected has been achieved, e.g., we have completed providing the Services;
- processing was based on consent that has been withdrawn, and there is no other legal basis for further processing;
- you have objected pursuant to Article 21 GDPR, and we have no overriding legitimate grounds for further processing;
- the data was processed unlawfully;
- deletion of the data is required by law.
- restrict processing (Article 18 GDPR) - you may request the restriction of data processing (e.g., to storage only) if:
- you contest the accuracy of the data;
- you believe we are processing data without a legal basis, but you do not want it deleted;
- you have objected pursuant to Article 21 GDPR, and we are reviewing the matter;
- data portability (Article 20 GDPR) - you may receive your data in a machine-readable format or request its transfer to another controller if the processing is based on consent or carried out by automated means;
- object to the processing of data (Article 21 GDPR) - you may object to the processing of your data if you believe we have no lawful basis for doing so;
- lodge a complaint with a supervisory authority (Article 77 GDPR) - if you believe we are processing your data unlawfully, you may file a complaint with the President of the Personal Data Protection Office (PUODO).
- Providing your data is voluntary. Failure to provide data will result in the inability to use the Application and Services, or, in the case of changing privacy settings on your device, the inability to use all Application functionalities. For data provided optionally, you have the right to withdraw consents granted for the processing of personal data. Withdrawal of consent does not affect YouHero's right to process data for the purpose for which consent was given until its withdrawal.
- Any capitalized terms have the meaning assigned to them in the Application's Terms and Conditions, unless otherwise specified in this Privacy Policy.
- Matters not regulated by this Privacy Policy shall be governed by the applicable provisions of generally binding law. In case of any inconsistency between the provisions of this Privacy Policy and the aforementioned regulations, those regulations shall take precedence.