← PT Chronos

Privacy Policy

Last updated: 25 August 2026  ·  Versione italiana

This policy describes how personal data of users of the PT Chronos mobile application (the "App") is processed, under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.

1. Data controller

ControllerPT Chronos
Contact emailinfo@pt-chronos.com

The controller has not appointed a Data Protection Officer, the conditions of Article 37 GDPR not being met.

2. Personal data processed

2.1 Data provided by the controller or the user

Accounts are created by the controller (the gym); users do not register themselves. The following are processed:

2.2 Membership and class data

Important note. The App records only a yes/no value for whether a medical certificate was handed in. The certificate itself, medical reports, diagnoses and any other health-related data are never collected, uploaded or stored in the App. The processing therefore does not concern special categories of data under Article 9 GDPR. Any paper or digital retention of the certificate by the gym takes place outside the App and is covered by a separate notice.

2.3 Technical data

2.4 Data that never leaves the device

The App uses no profiling cookies, advertising trackers or third-party behavioural analytics.

3. Purposes and legal bases

PurposeLegal basis (Art. 6 GDPR)
Account creation and management, authenticationPerformance of a contract — Art. 6(1)(b)
Managing membership, bookings, attendance and make-up sessionsPerformance of a contract — Art. 6(1)(b)
Operational notifications (confirmations, waitlist promotions, cancellations, reminders)Performance of a contract — Art. 6(1)(b)
Recording medical certificate and membership form statusLegal obligation and legitimate organisational interest — Art. 6(1)(c) and 6(1)(f)
Infrastructure security, abuse prevention, technical logsLegitimate interest — Art. 6(1)(f)
Telegram notificationsConsent — Art. 6(1)(a), withdrawable at any time
Profile pictureConsent — Art. 6(1)(a), optional and withdrawable by removing the photo

Providing the data in sections 2.1 and 2.2 is necessary to deliver the service: without it the App cannot be used. Providing a profile picture and a Telegram identifier is optional.

No automated decision-making or profiling under Article 22 GDPR takes place.

4. Recipients and processors

Data may be processed by the following parties, appointed as processors under Article 28 GDPR:

PartyRoleData processed
Supabase, Inc.Database hosting, authentication, file storage, server functions (region: Ireland, EU)All data in sections 2.1–2.3
Expo (650 Industries, Inc.)Push notification deliveryNotification token, notification title and body
Proton AG (Proton Mail)Sending service emailsEmail address, message content
Telegram FZ-LLCTelegram notification delivery (only if enabled)Chat identifier, notification text
Apple Inc. / Google LLCApp distribution and notification transportTechnical delivery data

Data is never disclosed publicly, sold, or transferred to third parties for commercial purposes.

Authorised staff of the controller (App administrators) access member data only as far as necessary to run the sports activity.

5. Transfers outside the EU

The database, authentication system and file storage are hosted on Supabase infrastructure located in Ireland (European Union): that data does not leave the European Economic Area.

Only push notification delivery involves a transfer to the United States, as it is operated by Expo (650 Industries, Inc.), and concerns solely the notification token and the message text. That transfer relies on the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR) and/or participation in the EU-U.S. Data Privacy Framework, where applicable. A similar transfer may apply to Telegram delivery, if the user enables it.

6. Retention periods

On account deletion, data is removed as described in section 7.

7. Your rights

Users may exercise the rights in Articles 15–22 GDPR at any time:

Deleting your account

Users can delete their own account from within the App, under Profile › Delete account. This immediately and irreversibly removes the profile, access credentials, profile picture, bookings, membership periods, make-up requests and notifications. Any places freed up in future classes are reassigned to members on the waitlist at the same time.

Accounting and tax records relating to payments, held outside the App, are retained only for as long as legal obligations require.

Complaints

Users have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it), or to bring proceedings before a court.

Requests should be sent to info@pt-chronos.com. The controller responds within one month of receipt, extendable by two months in particularly complex cases.

8. Security

Data is protected by encrypted transmission (HTTPS/TLS), encryption at rest, password storage as hashes, and row-level access rules in the database that prevent any user from reading another member's data.

Profile pictures are held in private storage: they are not reachable through public addresses and are shown in the App only through temporary links, generated on request for authenticated users and valid for a limited time.

9. Minors

The service is not intended for anyone under 14. For minors, registration and the provision of data must be carried out by whoever holds parental responsibility, who acts as the data subject for the purposes of this policy.

10. Changes to this policy

The controller may update this policy. Material changes will be communicated through the App or by email. Please check this page periodically; the date of the last update is shown at the top.