Data controller
- Controller
- Alejandro Lorenzo Rodríguez, owner of the website zokuathletics.com and of the Zoku Athletics mobile application. Operates as a self-employed natural person.
- Tax ID (NIF)
- 77464696Y.
- Address
- Calle Islandia, 1, Residencial Playa Blanca 249, 35580 Yaiza (Las Palmas) (Spain).
- Privacy email
- privacidad@zokuathletics.com
- Data Protection Officer
- Not appointed. The Controller's activity does not fall within the cases of Article 37 GDPR requiring a DPO (public authority, systematic large-scale monitoring, or large-scale processing of special categories of data).
Categories of data processed
Depending on the features you use, we may process the following categories of data:
- Account data: name, surnames, username, email address, encrypted password, preferred language and role (athlete, support, moderator or administrator).
- Profile and configuration data: avatar photo (original and crop), declared country and city, privacy settings ("Profile privacy", training visibility, kudos), notification preferences.
- Sports activity data: training sessions (WOD), completed benchmarks, personal records (PR), outdoor routes and distances, "Vital Flow" data (internal load, estimated fatigue), unlocked achievements, gamification points.
- Optional physical data: height, weight, gender, declared injuries and other conditions voluntarily provided through the physical profile to personalize training and metrics, including, where applicable, the menstrual cycle phase you record through the cycle tracker. Health data — injuries, declared conditions and menstrual cycle — qualifies as special categories of data under Article 9 GDPR and requires your explicit consent.
- Menstrual cycle data (optional): if you enable cycle tracking, we process your period start and end dates, the derived predictions (estimated next period, ovulation and fertile window) and, if you choose to log them, an optional diary with flow intensity, symptoms, mood and notes, as well as pregnancy status when you indicate it. This is special category health data (Article 9 GDPR): it is processed only with your explicit consent, stored encrypted on your device and, where applicable, synced to your account in a database with Row-Level Security. It is never used for advertising and you can disable tracking at any time, keeping or deleting your data.
- Geolocation data: only when you actively enable SafeTrack, the safety feature for outdoor training, or the location indicator in the Tribe. Geolocation is not collected in the background without your authorization.
- Emergency contacts: the names and phone numbers you voluntarily register to be notified by SafeTrack in the event of an SOS alert. By registering them, you confirm that you have informed them of this processing and that you have their consent or another lawful basis to provide them to us. We process them for the sole purpose of being able to alert them in an emergency, on the basis of vital interest (Art. 6.1.d GDPR); you can delete them at any time. This information is treated as confidential data.
- Third-party health data (optional): if you connect Health Connect or other integrable services, we may import metrics such as heart rate, calories, steps or sleep. The connection is based on your explicit authorization and may be revoked at any time from the app settings.
- Social data: feed posts —including photos and videos, in galleries of up to 10 images—, comments, kudos, follower/following relationships, participation in "Solidary Reps" campaigns and "Rival Live" events, and your membership in clubs (your role within each one, your participation in their leagues, challenges and classes, and your standing in their rankings).
- Messaging data: the content of your direct, group and club conversations —text, photos, videos, voice notes, GIFs (searched through GIPHY), reactions and feed posts you share inside a chat—. Messages are stored in our database, protected by encryption in transit (TLS) and by Row-Level Security policies that restrict access to conversation participants; no end-to-end encryption is applied. When you delete a message "for yourself", it only stops showing on your device —other participants still see it—; you have a one-hour window from sending to also delete it for everyone.
- Audio data (voice notes): we record microphone audio only when you press the record button inside a chat; there is no background or continuous capture. The recording is encoded in AAC format (.m4a) and uploaded to private storage accessible only through signed, time-limited links that expire after one hour. Alongside the audio we store its duration and a simplified waveform representation (48 amplitude values) so it can be displayed without downloading the file. We do not transcribe the audio, analyze it, identify the speaker or use it to train any model. The device's microphone permission is also used, independently, for the voice commands of SafeTrack's hands-free mode.
- Support data: support tickets opened by you, subject, category, priority and history of messages exchanged with the team.
- Subscription and billing data: contracted plan, subscription status, start date and next billing date. The card number and full banking data are processed by Stripe Payments Europe Ltd.: they are never stored on our servers.
- Technical data: IP addresses, device identifiers, browser type, operating system, login timestamps, app versions and minimum error logs necessary for diagnostics and security.
Purposes of processing
We process your data for the following purposes, each with its legal basis:
- Providing the Services
- Creating and maintaining your account, authenticating you, offering training, metrics, social feed and support features. Legal basis: contract performance (Art. 6.1.b GDPR).
- Subscription management
- Showing the Free, Pro and Elite plan catalog. Today only the free plan is available through self-service: paid checkout is not active, so we do not process recurring charges or issue invoices. Once paid contracting is operational, this purpose will be extended to cover processing via Stripe. Legal basis: contract performance (Art. 6.1.b GDPR).
- Personalization with physical data
- Adjusting load prescription and gender-based Rx weights based on your physical profile; AI Coach posture analysis runs entirely on your device. Legal basis: explicit consent (Arts. 6.1.a and 9.2.a GDPR), revocable at any time.
- AI-assisted WOD adaptation (Vital Flow)
- Exception under review (2026-09-23): when you use "Adapt WOD" on a custom WOD, your fatigue index, load factor, and the location and severity of each active injury (health data, Art. 9 GDPR) are sent to Google Gemini to substitute contraindicated exercises. This processing remains active and does not yet have an Article 9 legal basis or separate explicit consent; until it is resolved, avoid this feature if you do not want that data to leave Zoku.
- Messaging and chat
- Enabling the sending and receiving of text messages, photos, videos, voice notes, GIFs and reactions in direct, group and club conversations. Legal basis: contract performance (Art. 6.1.b GDPR), as this is a Service feature you contract when registering.
- Menstrual cycle tracking
- Logging your cycle, computing predictions (period, ovulation and fertile window), sending you reminders and adapting training load (Vital Flow) to the phase. Legal basis: explicit consent (Arts. 6.1.a and 9.2.a GDPR), revocable at any time. This data is never used for advertising.
- SafeTrack and emergencies
- Detecting inactivity or route deviations during outdoor training and notifying your emergency contacts. Legal basis: explicit consent and, where applicable, vital interest (Arts. 6.1.a, 6.1.d and 9.2.c GDPR).
- Push and in-app notifications
- Notifying you of support replies, kudos received, training reminders and operational service information. Legal basis: contract performance (Art. 6.1.b) and consent for promotional purposes (Art. 6.1.a).
- Commercial communications
- Sending you information about news, discounts or Zoku products, only if you have expressly accepted. Legal basis: consent (Art. 6.1.a GDPR). You may withdraw it at any time without affecting other processing.
- Security and fraud prevention
- Detecting unauthorized access, automated attacks or abusive use. Legal basis: legitimate interest (Art. 6.1.f GDPR) and legal security obligations.
- Compliance with legal obligations
- Retaining tax documentation and responding to requests from competent authorities. Legal basis: legal obligation (Art. 6.1.c GDPR).
- Statistics and Service improvement
- Analyzing aggregated and anonymized data to improve features, technical performance and experience. Legal basis: legitimate interest (Art. 6.1.f GDPR).
Retention periods
We keep your data only for as long as strictly necessary to fulfill the purposes for which it was collected and, where applicable, during the periods required by applicable regulations:
- Account and activity data: for the duration of the contractual relationship and until the cancellation request. After cancellation, data is deleted unless legally blocked.
- Physical and health data: until consent is revoked or the account is cancelled. After revocation, data is deleted within a maximum of 30 days.
- Menstrual cycle data: while you keep cycle tracking enabled. If you disable it keeping your data, it remains so you can re-enable without losing your history; if you choose to delete it or withdraw consent, it is erased within a maximum of 30 days.
- SafeTrack geolocation: retained exclusively for the time necessary to provide the safety service and automatically deleted 7 days after the end of the training, unless an emergency case is opened.
- Resolved or closed SOS alert records: kept for a maximum of 2 years from their resolution and then automatically deleted. Active alerts are never deleted.
- Diagnostic telemetry (app performance metrics, such as load times): automatically deleted after 180 days.
- Chat messages (direct, group and club) and their attachments (photos, videos and voice notes): kept for as long as your account remains active. We do not currently apply automatic deletion of this content based on age.
- Billing data and tax obligations: 6 years, in accordance with Article 30 of the Spanish Commercial Code.
- Security and connection logs: 12 months, unless longer retention is required for incident investigation.
- Anonymized data used for statistical purposes: no time limit, as it loses the status of personal data.
Recipients and processors
We do not sell your data. We share personal data exclusively with providers that supply services necessary to operate Zoku Athletics, acting as processors under contract pursuant to Article 28 GDPR:
- Supabase (database storage and authentication, EU infrastructure).
- Google Cloud Platform (Spring Boot backend hosting on Cloud Run, europe-west1 region).
- Vercel Inc. (hosting and CDN of the Next.js Website). Vercel acts as a processor and has EU standard contractual clauses for international transfers.
- Stripe Payments Europe, Ltd. (payment processing and invoice issuance), only once paid contracting is operational: checkout is not active today.
- Google Gemini (Vital Flow WOD adaptation with active injuries when using "Adapt WOD"; processing pending a legal basis and explicit consent, not covered by this policy until resolved).
- Firebase Cloud Messaging (push notifications for the Android app).
- Spotify AB (when you authorize the OAuth integration for music playback and basic account metadata).
- GIPHY, Inc. (searching and sending animated GIFs inside the chat, when you choose to use this feature).
- Resend (transactional email delivery: two-factor verification, password reset and account security notices; it processes your email address).
- Sentry (error monitoring and application stability; crash reports are scrubbed to minimize the personal data they contain).
- Upstash (temporary in-memory storage to rate-limit requests and protect against abuse; it processes session identifiers and IP addresses).
- Legal, tax or audit advisors, and public authorities, when there is a legal obligation to communicate.
Additionally, other users may see your profile, your feed posts and your ranking scores depending on the privacy settings you have chosen. You can adjust this visibility at any time from the mobile app, in Settings → Privacy and Security.
International transfers
Our servers and those of our main processors are located within the European Economic Area. However, some providers (for example, Stripe, Vercel, Firebase, Resend, Sentry or Upstash) may carry out occasional processing outside the EEA. In such cases, we guarantee an adequate level of protection through:
- Adequacy decisions of the European Commission, when the destination country has one.
- Standard Contractual Clauses approved by the European Commission (Decision 2021/914), supplemented with additional measures where appropriate.
- Certification mechanisms or binding codes of conduct, where applicable.
You can request a copy of the safeguards applied through privacidad@zokuathletics.com.
Automated decisions and profiling
Training recommendations, Vital Flow adjustments, AI Coach suggestions and personalized Rx weights constitute automated processing using your physical profile and activity data. These processes do not produce legal effects on you nor significantly affect you: their purpose is strictly informational and sporting. In any case, you may object to these decisions, request human intervention or challenge the result by contacting us.
Your rights
As a data subject, the GDPR grants you the following rights, exercisable free of charge:
- Access: know what data of yours we process.
- Rectification: correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"): request deletion when data is no longer necessary.
- Objection: object to certain processing based on legitimate interest or marketing.
- Restriction of processing: block the use of your data while a request is resolved.
- Portability: receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Withdraw consent at any time, without affecting the lawfulness of prior processing based on it.
- Not be subject to automated decisions with significant legal effects.
You can exercise your rights by sending a request to privacidad@zokuathletics.com or by postal mail to the address indicated in the Controller section, identifying yourself appropriately. We will resolve your request within a maximum of one month, extendable by up to two additional months in complex cases (Art. 12.3 GDPR).
If you believe the processing does not comply with regulations or that your request has not been properly handled, you can file a complaint with the Spanish Data Protection Agency (www.aepd.es).
Security measures
We apply technical and organizational measures appropriate to the risk, in line with Article 32 GDPR. In particular:
- Encryption in transit (TLS 1.2 or higher) on all communications between client, web, app and backend.
- Encryption at rest of databases and avatar files using the native mechanisms of the infrastructure provider.
- Credential storage using secure key derivation algorithms (bcrypt or equivalent). The session token is managed in an HttpOnly cookie and is never exposed to client JavaScript code.
- Row-Level Security policies in the database to prevent cross-access between athletes.
- Role-based access control (Athlete, Support, Moderator, Administrator) and audit logs of administrative actions.
- Backup and disaster recovery procedures, as well as periodic restore tests.
- Breach notification procedure to the AEPD and affected individuals within the deadlines of Arts. 33 and 34 GDPR when applicable.
Minors
The Services are intended for persons aged 14 or over, the minimum age required by Zoku Athletics to register and the same minimum age of consent for the processing of personal data set by Spanish law (Article 7 LOPDGDD). Between 14 and 15 years of age, registration and the processing of personal data require the express consent and active supervision of the holder of parental authority or guardianship. Registration is not permitted under 14 years of age. Regardless of that age range, any paid plan taken out by a minor (aged 14 to 17) may only be purchased or confirmed by their legal representative. If we detect that data has been collected from a person under 14, or from a person aged 14 to 15 without the required consent, we will proceed with its immediate deletion.
Changes to this Policy
This Policy may be updated to reflect regulatory, technical or operational changes. When the modification substantially affects the processing of your data, we will inform you by email or by prominent notice within the Services with reasonable advance notice. We keep version history for traceability and audit purposes.
