EN RO

Privacy Policy

Last updated: [EFFECTIVE_DATE]

1. Introduction

This Privacy Policy explains how PFA DANIEL COCOS ("we," "us," or "our") collects, uses, and protects your personal data when you use the FormChase application and website (the "Service").

We are committed to protecting your privacy and ensuring that your personal data is handled in accordance with the General Data Protection Regulation (GDPR) and Romanian data protection laws.

2. Data Controller

The data controller responsible for your personal data is:

PFA DANIEL COCOS

Bulevardul Constructorilor 24A, bl 44, sc 1, et 2, ap 16

Sector 6, Bucharest, Romania

CUI: [CUI]

Email: contact@formchase.ro

3. Important Health Data Disclaimer

FormChase collects fitness and nutrition data for personal informational tracking only. This data is NOT classified as health data under medical device regulations and is NOT used for diagnostic or treatment purposes.

The workout logs, meal records, body measurements, and progress photos you store are personal records to help you track your own wellness journey. They are not medical records and should not be treated as such.

4. Data We Collect

4.1 Account Data

When you create an account, we collect:

4.2 Authentication Data

Depending on your sign-in method:

4.3 Fitness and Workout Data

4.4 Nutrition Data

4.5 Body Measurements

4.6 Subscription and Billing Data

We do NOT store your payment card details. All payment processing is handled securely by Stripe.

4.7 Technical Data

5. Apple Health Integration (Optional)

If you choose to enable Apple Health integration, we may read:

This integration is entirely optional and requires your explicit permission. We do NOT write data to Apple Health; we only read data that you authorize.

6. Legal Bases for Processing

We process your personal data based on the following legal grounds under GDPR Article 6:

Data Category Legal Basis
Account data Contract performance (Art. 6(1)(b))
Fitness/nutrition data Contract performance (Art. 6(1)(b))
Billing data Contract and legal obligation (Art. 6(1)(b), (c))
Analytics data Legitimate interest (Art. 6(1)(f))
Apple Health data Explicit consent (Art. 6(1)(a))

7. How We Use Your Data

We use your personal data to:

8. Data Sharing and Third Parties

We share your data only with the following categories of processors:

8.1 Supabase (Database Hosting)

8.2 Stripe (Payment Processing)

8.3 Sentry (Error Reporting)

8.4 Open Food Facts (Food Database)

We do NOT sell your personal data to third parties.

9. International Data Transfers

Your data is primarily stored within the European Union (EU) on servers located in Paris, France.

When data is transferred outside the EU (to Stripe or Sentry in the US), we ensure appropriate safeguards are in place, including:

10. Data Retention

We retain your data for the following periods:

Data Type Retention Period
Account and profile data Until account deletion + 30-day cooling-off
Fitness and nutrition logs Until account deletion + 30-day cooling-off
Progress photos Until account deletion + 30-day cooling-off
Invoices and billing records 10 years (Romanian fiscal requirement)
Error logs 90 days
Analytics events 2 years

After account deletion, your personal data is anonymized or deleted, except where retention is required by law.

11. Your Rights Under GDPR

As an EU resident, you have the following rights:

11.1 Right of Access (Art. 15)

You can request a copy of all personal data we hold about you.

11.2 Right to Rectification (Art. 16)

You can correct inaccurate or incomplete personal data.

11.3 Right to Erasure (Art. 17)

You can request deletion of your personal data ("right to be forgotten"). We will delete your data within 30 days, except where retention is legally required.

11.4 Right to Restrict Processing (Art. 18)

You can request restriction of processing in certain circumstances.

11.5 Right to Data Portability (Art. 20)

You can request your data in a portable format (JSON export available in app settings).

11.6 Right to Object (Art. 21)

You can object to processing based on legitimate interests.

11.7 Right to Withdraw Consent (Art. 7)

Where processing is based on consent, you can withdraw consent at any time.

To exercise your rights, use the in-app features (Settings → Privacy → Data Export / Delete Account) or contact us at contact@formchase.ro.

We will respond to valid requests within 30 days.

12. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

13. Children's Privacy

FormChase is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at contact@formchase.ro.

14. Automated Decision-Making

FormChase does not use automated decision-making or profiling that produces legal or similarly significant effects on you. Any analytics we perform are for service improvement only.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through in-app notifications or email. Your continued use of the Service after changes constitutes acceptance of the updated policy.

16. Contact Us

For privacy-related questions or to exercise your data rights, contact us:

PFA DANIEL COCOS

Bulevardul Constructorilor 24A, bl 44, sc 1, et 2, ap 16

Sector 6, Bucharest, Romania

Email: contact@formchase.ro

Supervisory Authority

You have the right to lodge a complaint with the Romanian data protection authority:

ANSPDCP

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

B-dul G-ral. Gheorghe Magheru 28-30, Sector 1

București, 010336, Romania

Website: dataprotection.ro