This policy describes the personal data Co-Sport processes, why it does so, who has access to it, how long it is kept, and the means available to you to retrieve it or have it erased.
1.Data controller
The data controller is the publisher of the platform, identified in the legal notice, to which reference is made for its company name, address and registration.
A dedicated address is available for any question or request about your data; we reply within one month.
Data protection contact : dpo@co-sport.com
2.Data we collect
Not all of the categories below concern you: we only process what corresponds to the features you actually use.
Account and identification
- Email address and password, stored in encrypted form and never in clear text.
- Your Google, Apple or Strava account identifier when you sign in that way.
- The date and version of the terms of use you accepted.
- Open sessions and devices associated with your account.
Sports profile
- Name or nickname, profile picture, bio, link to a social network.
- City, country, and where applicable an approximate position for nearby search.
- Date of birth, sex and nationality, when you provide them.
- Sports practised, level, goals, and whether you are a sports professional.
Training
- Sessions, exercises, sets, loads, repetitions, durations and self-reported effort.
- Personal records, statistics by exercise and by muscle group.
- Programmes followed, planning and daily goals.
- Activities imported from Strava: distance, elevation, pace, track, heart rate.
Health-related data
- Height, weight, weight history and body composition goals.
- Injury history entered in the AI coach profile.
- Heart rate, perceived effort and training load indicators from your activities.
- Food and hydration logs, when you use nutrition tracking.
Data from camera-based analysis
- Numerical results of camera-tracked sessions: repetitions counted, durations, tempo, execution score, number of repetitions judged incorrect, estimated calories.
- Image analysis is performed on your device. No photo or video is sent to our servers, and we keep none.
- Camera access is requested by your phone's operating system and can be withdrawn at any time in its settings.
Location
- Declared or detected position, to find partners and events nearby.
- Route tracks, logged outings and points of interest you save.
- The place attached to a listing, an event or a post you create.
Published content
- Posts, comments, likes, shares and stories.
- Photos and videos, together with their technical metadata.
- Listings, events, blog articles and reviews you write.
- Follows, followers and blocked members.
Messaging
- The content of messages exchanged with other members, and attachments.
- Participants, timestamps and read receipts for conversations.
- Exchanges with the automated training assistant.
Transactions
- Subscriptions, payments, invoices and your customer identifier at the payment provider.
- Coaching sessions booked, amounts and commission.
- Sales listings, enquiries and reviews left after a transaction.
Technical and security data
- IP address, device type and browser at the time of connection.
- Connection logs, used to detect fraudulent access.
- Notification tokens, if you have allowed notifications.
- Aggregated audience measurement, performed without cookies or persistent identifiers.
Support and moderation
- Messages sent to support, contact requests and feedback.
- Reports you submit and moderation decisions concerning you.
- Documents submitted as part of a professional profile verification.
3.Health-related data
Some of the information you may enter falls into special categories under the GDPR: it benefits from enhanced protection and is only processed with your explicit consent.
- They are collected only if you turn on the matching features: weight tracking, AI coach and nutrition tracking. Until you have given your consent, those features record nothing.
- It is never used for advertising purposes and never passed to third parties for that purpose.
- It is not visible to other members, unless you explicitly choose to publish the content that carries it.
- You can withdraw your consent at any time from your settings: the features concerned are turned off and the data they produced is deleted — AI coach profile (weight, height, goals, injury history), weight history, food and hydration logs, coach conversations and proposals.
- Your training sessions and the activities imported from Strava fall under performance of the service contract: they carry effort indicators (including heart rate) and are not erased by this withdrawal. Strava synchronisation is enabled only by your explicit authorisation, revocable at any time from your Strava account; activities already imported disappear when your account is deleted, or earlier on request to the contact given in the “Your rights” article.
We are not a healthcare service. None of this data is subject to medical interpretation, and nothing displayed on the platform constitutes a diagnosis or a treatment.
4.Purposes
Your data is processed for the following purposes, and for those alone:
- Creating and managing your account, authenticating you and securing your access.
- Connecting you with other members according to your sports, level and area.
- Recording and displaying your training history and statistics.
- Providing the automated training assistant and personalising its suggestions.
- Enabling content publication, messaging and interaction between members.
- Processing orders, payments and invoicing, and producing the required accounting records.
- Carrying out moderation and preventing fraud, abuse and uses contrary to the terms.
- Sending you the notifications and emails matching your preferences.
- Measuring the audience of the service in aggregate, in order to improve it.
5.Legal bases
Each processing activity rests on one of the grounds set out in the GDPR:
| Ground | Processing concerned |
|---|---|
| Performance of the contract | Account, profile, matching, content, messaging, training tracking, orders and services. |
| Consent | Health data, precise location, Strava connection, AI coach, non-essential notifications and emails. |
| Legitimate interest | Service security, fraud and abuse prevention, moderation, aggregated audience measurement. |
| Legal obligation | Retention of accounting records, retention of connection data, responses to requests from the authorities. |
6.Recipients and processors
Your data is only accessible to the people who need it, and to the technical providers below, acting on our instructions:
| Provider | Role | Location |
|---|---|---|
| Hosting and file storage | Hosting of the application, the database, and photos and videos. | European Union |
| Email delivery service | Transactional emails and, where applicable, newsletters. | European Union |
| Account sign-in, when you choose that method. | Outside the European Union | |
| Apple | Account sign-in, when you choose that method. | Outside the European Union |
| Strava | Importing your sports activities, if you have linked your account. | Outside the European Union |
| Language model provider | Processing of exchanges with the automated training assistant. | Outside the European Union |
| Rate-limiting service | Protection against abuse and automated attacks. | Inside or outside the European Union depending on the region |
| Mobile notification service | Delivering notifications to your device. | Outside the European Union |
| Map and weather providers | Displaying base maps, routes and forecasts. | Inside and outside the European Union |
| Payment provider | Collecting payment for subscriptions and coaching sessions. | To be specified when payments go live |
We do not sell your data and do not pass it to any data broker or advertising network.
7.Transfers outside the European Union
Some providers are established outside the European Union, in particular in the United States.
- These transfers are governed by the European Commission's standard contractual clauses or by an adequacy decision.
- They are limited to the data strictly necessary for the feature concerned.
- The features that involve such a transfer — signing in with Google or Apple, Strava import, the training assistant — are optional and are your choice.
8.Retention periods
We keep your data only for as long as the purpose requires:
| Data | Period |
|---|---|
| Account and profile | For as long as the account exists, then deleted |
| Sessions, statistics, health data | For as long as the account exists, then deleted |
| Posts, photos, stories, listings | Until you delete them, or until the account is closed |
| Private messages | Until the account is closed; the content of your messages is then erased |
| Invoices and accounting records | 10 years (accounting and tax obligation) |
| Connection logs | 12 months at most |
| Reports and moderation decisions | 1 year after the case is closed, or until ongoing proceedings end |
| Audience measurement | 90 days for detailed records, then anonymous aggregated statistics |
| Exchanges with support | 3 years after the last exchange, then deletion |
9.Your rights
You have the following rights over your personal data:
- Right of access: obtain confirmation that your data is processed and receive a copy of it.
- Right to rectification: correct inaccurate or incomplete information, directly from your profile.
- Right to erasure: request deletion of your data, by deleting your account.
- Right to portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interest, and to marketing.
- Right to restriction: ask for processing to be frozen while a challenge is examined.
- Right to withdraw your consent at any time, without affecting the lawfulness of earlier processing.
Exporting your data and deleting your account are done directly from your settings, with no involvement on our part. For the other rights, write to the contact address given above: we reply within one month, extendable by two months for complex requests.
10.Minors
The service is not intended for children under 16. We do not knowingly collect their data. If you hold parental authority and believe your child has opened an account, write to us: the account will be closed and the data deleted.
11.Security
We implement technical and organisational measures appropriate to the risk:
- Encryption of traffic between your device and our servers.
- Passwords stored as hashes, never in clear text and never reversible.
- Separation of environments and access limited to authorised staff only.
- Logging of administrative actions and two-factor authentication for administrator accounts.
- Regular, encrypted backups.
- Rate limiting and detection of automated behaviour.
In the event of a data breach likely to result in a high risk to your rights, you will be informed as soon as possible, and the supervisory authority will be notified within 72 hours.
13.Changes to this policy
This policy may be amended to reflect changes in the service or in regulations. Each version carries a date, and any substantial change is notified to you before it takes effect.
14.Complaints
If you believe your rights are not being respected, send your complaint to us first: it is the fastest route.
You may also lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris, or with the supervisory authority of your country of residence.