Last updated: 25 August 2026 · Versione italiana
This policy describes how personal data of users of the PT Chronos mobile application (the "App") is processed, under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.
| Controller | PT Chronos |
|---|---|
| Contact email | info@pt-chronos.com |
The controller has not appointed a Data Protection Officer, the conditions of Article 37 GDPR not being met.
Accounts are created by the controller (the gym); users do not register themselves. The following are processed:
Important note. The App records only a yes/no value for whether a medical certificate was handed in. The certificate itself, medical reports, diagnoses and any other health-related data are never collected, uploaded or stored in the App. The processing therefore does not concern special categories of data under Article 9 GDPR. Any paper or digital retention of the certificate by the gym takes place outside the App and is covered by a separate notice.
The App uses no profiling cookies, advertising trackers or third-party behavioural analytics.
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Account creation and management, authentication | Performance of a contract — Art. 6(1)(b) |
| Managing membership, bookings, attendance and make-up sessions | Performance of a contract — Art. 6(1)(b) |
| Operational notifications (confirmations, waitlist promotions, cancellations, reminders) | Performance of a contract — Art. 6(1)(b) |
| Recording medical certificate and membership form status | Legal obligation and legitimate organisational interest — Art. 6(1)(c) and 6(1)(f) |
| Infrastructure security, abuse prevention, technical logs | Legitimate interest — Art. 6(1)(f) |
| Telegram notifications | Consent — Art. 6(1)(a), withdrawable at any time |
| Profile picture | Consent — Art. 6(1)(a), optional and withdrawable by removing the photo |
Providing the data in sections 2.1 and 2.2 is necessary to deliver the service: without it the App cannot be used. Providing a profile picture and a Telegram identifier is optional.
No automated decision-making or profiling under Article 22 GDPR takes place.
Data may be processed by the following parties, appointed as processors under Article 28 GDPR:
| Party | Role | Data processed |
|---|---|---|
| Supabase, Inc. | Database hosting, authentication, file storage, server functions (region: Ireland, EU) | All data in sections 2.1–2.3 |
| Expo (650 Industries, Inc.) | Push notification delivery | Notification token, notification title and body |
| Proton AG (Proton Mail) | Sending service emails | Email address, message content |
| Telegram FZ-LLC | Telegram notification delivery (only if enabled) | Chat identifier, notification text |
| Apple Inc. / Google LLC | App distribution and notification transport | Technical delivery data |
Data is never disclosed publicly, sold, or transferred to third parties for commercial purposes.
Authorised staff of the controller (App administrators) access member data only as far as necessary to run the sports activity.
The database, authentication system and file storage are hosted on Supabase infrastructure located in Ireland (European Union): that data does not leave the European Economic Area.
Only push notification delivery involves a transfer to the United States, as it is operated by Expo (650 Industries, Inc.), and concerns solely the notification token and the message text. That transfer relies on the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR) and/or participation in the EU-U.S. Data Privacy Framework, where applicable. A similar transfer may apply to Telegram delivery, if the user enables it.
On account deletion, data is removed as described in section 7.
Users may exercise the rights in Articles 15–22 GDPR at any time:
Users can delete their own account from within the App, under Profile › Delete account. This immediately and irreversibly removes the profile, access credentials, profile picture, bookings, membership periods, make-up requests and notifications. Any places freed up in future classes are reassigned to members on the waitlist at the same time.
Accounting and tax records relating to payments, held outside the App, are retained only for as long as legal obligations require.
Users have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it), or to bring proceedings before a court.
Requests should be sent to info@pt-chronos.com. The controller responds within one month of receipt, extendable by two months in particularly complex cases.
Data is protected by encrypted transmission (HTTPS/TLS), encryption at rest, password storage as hashes, and row-level access rules in the database that prevent any user from reading another member's data.
Profile pictures are held in private storage: they are not reachable through public addresses and are shown in the App only through temporary links, generated on request for authenticated users and valid for a limited time.
The service is not intended for anyone under 14. For minors, registration and the provision of data must be carried out by whoever holds parental responsibility, who acts as the data subject for the purposes of this policy.
The controller may update this policy. Material changes will be communicated through the App or by email. Please check this page periodically; the date of the last update is shown at the top.