Privacy Policy

Last updated: June 2026 — version 1.3

1. Data controller

The data controller for personal data collected through the Adapta application is:

Michele Aldeni
Email: ciao.madesign@gmail.com

2. Data collected

Adapta collects the following categories of personal data:

  • Identification data: name, email address, password (encrypted with bcrypt, not accessible in plain text).
  • Athletic profile data: age, body weight, experience level, weekly training days, usual weekly volume, self-assessed athletic characteristics.
  • Training data: logged sessions (type, duration, distance, elevation, perceived effort, feelings, skip reason).
  • Recovery data: sleep quality, energy level, leg condition (or residual limb), motivation (scale 1-10); optionally prosthetic comfort (1-10) for athletes using a sports prosthesis.
  • Goal data: race name, distance, elevation, target date.
  • Menstrual cycle data (optional): start date of last cycle, average cycle duration and period duration. Provided solely on a voluntary basis by activating the "Cycle & training" feature in the profile.
  • Adaptive profile (optional): type of adaptive characteristic (transtibial, transfemoral or bilateral amputation, limb difference, neurological condition, visual impairment, chronic / variable-capacity condition), affected side, and use of a sports prosthesis. Provided solely on a voluntary basis. This data constitutes health information under Art. 9 GDPR and is processed only with separate explicit consent, revocable at any time from the profile.
  • Postpartum data (optional): weeks since delivery. Used solely to add pelvic floor safety notes to high-impact sessions in the first 26 weeks postpartum. Constitutes health information under Art. 9 GDPR and is processed only with explicit consent at the time of entry.
  • Menopause/perimenopause status (optional): indication of menopausal status. Used to disable the Cycle sync feature (not applicable) and display a contextual note on the Recovery page. Constitutes health information under Art. 9 GDPR and is processed only on explicit indication by the user in the profile.
  • Navigation data: strictly necessary session cookies for authentication (no profiling or tracking cookies).

Data relating to body weight, physical recovery status, menstrual cycle, adaptive profile, postpartum status, and menopausal status constitute health dataunder Art. 9 GDPR and are therefore considered special category data. Their processing is subject to the user's explicit consent: for weight and recovery, expressed at registration; for menstrual cycle data, adaptive profile, postpartum data, and menopausal status, expressed separately at the time of entry, revocable at any time from the profile.

3. Purposes and legal basis

PurposeLegal basis
Account creation and managementPerformance of contract (Art. 6.1.b GDPR)
Generating and adapting the training planPerformance of contract (Art. 6.1.b GDPR)
Processing health data (weight, recovery)Explicit consent (Art. 9.2.a GDPR)
Processing menstrual cycle data to personalise the training planSeparate explicit consent, revocable in-app (Art. 9.2.a GDPR)
Processing adaptive profile to personalise the plan and training feedbackSeparate explicit consent, revocable in-app (Art. 9.2.a GDPR)
Processing postpartum data to add safety notes to high-impact sessionsSeparate explicit consent, revocable in-app (Art. 9.2.a GDPR)
Processing menopausal status to adapt the plan and available featuresSeparate explicit consent, revocable in-app (Art. 9.2.a GDPR)
Security and fraud preventionLegitimate interest (Art. 6.1.f GDPR)

4. Data retention

Data is retained for the minimum time necessary for the purposes for which it was collected:

  • Account and profile data: until account deletion by the user.
  • Training and recovery data: until account deletion.
  • Session logs: maximum 30 days.

Upon account deletion, all personal data is permanently and irreversibly deleted in real time.

5. Recipients and data transfers

Data is processed by the following service providers acting as data processors, with whom a GDPR-compliant Data Processing Agreement is in place:

  • Vercel Inc. (USA) — application hosting. Transfer to a third country based on Standard Contractual Clauses (SCC) approved by the European Commission. Vercel Privacy Policy
  • Neon Inc. (USA) — PostgreSQL database. Transfer to a third country based on Standard Contractual Clauses (SCC). Neon Privacy Policy
  • Upstash Inc. (USA) — Redis cache for rate limiting. No personal data is persistently stored; data is retained only for the duration of the rate limiting window (maximum 60 minutes). Transfer to a third country based on Standard Contractual Clauses (SCC). Upstash Privacy Policy
  • Resend Inc. (USA) — transactional email sending (e.g. password reset). Processes only the recipient's email address and the content of the sent message. Transfer based on Standard Contractual Clauses (SCC). Resend Privacy Policy

Data is not sold, transferred, or disclosed to third parties for marketing purposes.

6. Cookies and tracking technologies

Adapta uses exclusively strictly necessary technical cookies for service operation:

  • authjs.session-token — session cookie for authentication. Duration: browser session or 30 days if "stay logged in". Not transmitted to third parties.

No profiling, analytics (e.g. Google Analytics), or marketing cookies are used. Consent under the ePrivacy Directive is therefore not required for these technical cookies, but the user is informed by this policy.

7. Data subject rights

Under Arts. 15–22 GDPR, the user has the right to:

  • Access (Art. 15): obtain confirmation of processing and a copy of their data.
  • Rectification (Art. 16): correct inaccurate data or supplement it.
  • Erasure / "Right to be forgotten" (Art. 17): request deletion of all data. Available directly in the app: Profile → Delete account.
  • Portability (Art. 20): receive their data in a structured, readable format. Available directly in the app: Profile → Export data.
  • Restriction (Art. 18): request suspension of processing in certain cases.
  • Objection (Art. 21): object to processing based on legitimate interest.
  • Withdrawal of consent: withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise the above rights, write to: ciao.madesign@gmail.com. The controller responds within 30 days.

8. Data breaches

In the event of a personal data breach that may pose a risk to the rights and freedoms of data subjects, the controller will notify the competent supervisory authority within 72 hours of becoming aware of the breach, pursuant to Art. 33 GDPR.

Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, the controller will also communicate the breach to those affected without undue delay, pursuant to Art. 34 GDPR, via in-app notification or email.

9. Complaints

The user has the right to lodge a complaint with the competent supervisory authority. In Italy: Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it.

10. Changes to this policy

The controller reserves the right to update this policy. Material changes will be communicated to the user via in-app notification or email. The date of the last update is shown at the top of the page.