Privacy Policy
Last updated: [EFFECTIVE DATE]
This Privacy Policy explains how [HYVIA LEGAL ENTITY NAME] (“Hyvia”, “we”, “us”), a company registered in Austria (company reg. no. [REGISTRATION NUMBER], registered office at [VIENNA ADDRESS]), handles personal data. It applies to our website at hyvia.io and to the Hyvia platform (the mobile app, wearable devices, and coach dashboard).
Hyvia provides fitness-grade performance and readiness monitoring for sports organisations. It is not a medical device and does not provide medical advice, diagnosis, or treatment.
1. Our two roles: controller and processor
Which data-protection role we hold depends on the data:
- For our website (e.g. demo requests and analytics), Hyvia is the data controller — we decide how and why that data is used.
- For the platform (data about athletes and staff), the club or organisation is the data controller and Hyvia acts as a data processor, handling the data on the club's documented instructions under a data processing agreement. The club decides what data is collected and is responsible for the lawful basis and for informing and obtaining any necessary consent from athletes and staff.
2. Data we collect
Website visitors. When you request a demo, we collect the details you submit — such as your name, role, club or organisation, and work email. We also use privacy-friendly, cookieless analytics that measure aggregate site usage without tracking you across sites, and our hosting providers keep standard server logs (including IP address) for security and reliability.
Athletes (via their club). Through the platform, we process data such as:
- identity and profile details (for example name, date of birth, photo, and physical details such as weight);
- health and physiological signals from the wearable devices, such as heart rate, heart-rate variability, blood oxygen, skin temperature, spot ECG readings, and sweat-based markers (cortisol, lactate, pH);
- the readiness, stress, recovery, and performance scores derived from that data; and
- device and app-usage information needed to operate the service.
Club staff. We process basic account details such as name and email.
3. Health data and children
Much of the athlete data we process is data concerning health, a special category of personal data that receives heightened protection under the GDPR. Some athletes may also be children (for example in youth academies). Because the club is the controller, the club is responsible for establishing a valid legal basis for this data — including any explicit consent and, for minors, appropriate parental or guardian consent — and for informing athletes about how their data is used. Hyvia processes this data only on the club's instructions and applies appropriate safeguards.
4. Why we process data, and our legal basis
Website. We process demo-request details to respond to your enquiry and to provide the service you asked about (our legitimate interest in responding to a request you initiated, and/or your consent). We process analytics and logs for the legitimate interest of keeping the site secure, reliable, and improving it.
Platform. We process athlete and staff data on behalf of the club to provide the Hyvia service — capturing signals, generating readiness and performance insights, and making them available to authorised club staff. The legal basis is determined and documented by the club as controller.
5. Artificial intelligence and machine learning
Hyvia uses machine learning to generate performance and readiness insights, and offers an optional AI assistant that helps coaches ask questions about their squad's data. Two principles apply:
- Predictive models are developed and run on Hyvia's own infrastructure. To make predictions reliable, models may be trained on data from across the platform in pseudonymised or aggregated form (with direct identifiers removed). This data is never sold or shared to train any third party's models.
- The AI assistant may use a specialist, enterprise AI provider that is contractually barred from retaining your data or using it to train its models, and that processes data within the relevant region. Only the data needed to answer a question is provided to it.
Insights and predictions are advisory. They support human decision-making; a coach or staff member always decides what to do. Hyvia does not make decisions about an athlete that produce legal or similarly significant effects on a solely automated basis.
6. Who we share data with (sub-processors)
Within a club, athlete data is visible to that club's authorised staff (such as coaches and medical staff); an athlete can see their own data in the app. Data is never shared between clubs. To run the service we use a limited set of trusted providers (“sub-processors”), each under a data processing agreement:
- Amazon Web Services — application hosting (EU, Frankfurt).
- Neon — database, hosted in the region closest to each club (e.g. an EU region for EU clubs).
- Identity provider — secure sign-in [currently AWS Cognito; may change].
- Resend — transactional email delivery.
- An enterprise AI provider — for the optional AI assistant [to be named], under no-training terms.
- Vercel and Sanity — hosting and content management for this website.
- Web3Forms — delivery of demo-request submissions.
7. Where data is stored, and international transfers
Each club's operational database is hosted in the region closest to that club, and our application layer runs in the EU (Frankfurt). Some providers may process limited data (such as sign-in details or emails) outside the EU/EEA. Where that happens, we rely on appropriate safeguards recognised under the GDPR — such as the European Commission's Standard Contractual Clauses — to protect the data.
8. How long we keep data
We retain platform data for as long as the club uses the service. The club can view, export, or request deletion of its data at any time, and we delete or return it on the club's instruction or when the agreement ends, subject to any legal retention obligations. Website enquiry data is kept only as long as needed to handle your request.
9. How we protect data
We use technical and organisational measures appropriate to the data, including per-club data isolation, access controls so that only a club's own staff can reach its data, encryption of data in transit, and encryption at rest provided by our infrastructure providers. We keep our security measures under review and improve them over time.
10. Your rights
Under the GDPR you have rights to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. Because the club is the controller of athlete and staff data, athletes and staff should direct these requests to their club, which we support as processor. For data we hold as controller (e.g. website enquiries), contact us directly at contact@hyvia.io. You also have the right to lodge a complaint with a supervisory authority — in Austria, the Datenschutzbehörde.
11. Cookies
Our website uses privacy-friendly, cookieless analytics and does not set non-essential or advertising cookies, so no cookie-consent banner is required. Any strictly necessary cookies are used only to operate the site.
12. Changes and contact
We may update this policy from time to time; the “last updated” date above reflects the latest version. For any privacy question, or to reach our Data Protection Officer, contact contact@hyvia.io [DPO / contact details to be confirmed].