Kysero
Skip to main content

Legal

Privacy Policy

What Kysero collects, why it is needed and the choices and rights available to you.

Effective date: July 26, 2026

01

Scope

This Privacy Policy explains how Kysero handles personal data when you use kysero.io, the Kysero Plan Builder and related account, support and communication features.

The wider Kysero gym-management service may also be used by gyms, studios and trainers. In those workspaces, the organisation managing the member or client relationship may be the data controller for records it enters into the service.

02

Who controls the data

Kysero generally acts as controller for Plan Builder accounts, authentication, security, service operation, direct support requests and proportionate product analytics.

A gym, studio, trainer or coaching business generally controls the member and client records it manages through its own workspace. For that data, Kysero generally acts as a processor and follows the organisation's lawful instructions.

03

Data we may process

Account and profile data

  • Name, email address, password hash, verification status and preferred language.
  • Profile details you choose to provide, such as date of birth, height, weight, time zone and unit preferences.
  • Roles, workspace memberships and account-security records where those features apply.

Plan and training data

  • Plan inputs such as goal, experience level, available equipment, training frequency and program length.
  • Generated and saved plans, exercise selections, sets, repetitions, duration, rest, load, RIR, notes and plan versions.
  • Supported limitation information when you choose to provide it. This may concern health and should only be entered when appropriate.

Technical, support and billing data

  • Device and browser information, language, time zone, request timestamps, security logs, diagnostic information and cookie or local-storage identifiers.
  • Support correspondence and any information you send to us.
  • Subscription, invoice and limited payment metadata where paid services apply. Full card details are normally handled by the payment provider.
04

How we collect data

  • Directly from you when you use the Plan Builder, register, edit a profile or contact support.
  • From an authorised gym, trainer or staff member where they manage a workspace.
  • Automatically from your browser, device and interaction with the service.
  • From providers used for authentication, email, security, analytics or payment processing.
05

Why we use data

We process personal data to provide requested features, administer accounts, secure the service, prevent abuse, deliver operational messages, respond to support requests, comply with legal duties and improve the product using proportionate analytics.

The applicable lawful basis may be performance of a contract, steps requested before a contract, legitimate interests, a legal obligation or consent. Where consent is the basis, you may withdraw it without affecting earlier processing.

06

Cookies and analytics

Strictly necessary cookies or local storage support login, security, language, session continuity and preferences. Non-essential analytics are used only after consent where required.

When Plan Builder analytics are allowed, Kysero may use random browser and session identifiers to measure visits, plan creation, repeat use and conversion from anonymous use to registration. We may also record campaign or referring information, country code supplied by the network provider, device class and non-sensitive plan categories such as goal, experience level, training frequency and program length.

This analytics stream does not store raw IP addresses, full user-agent strings, health or limitation answers, or the contents of anonymous plans. Google Analytics is loaded only after the visitor accepts analytics on the marketing website.

07

Sharing and service providers

We share personal data only where needed to operate the service, comply with law or protect users and the platform.

  • Authorised users in the relevant gym or coaching workspace.
  • Hosting, storage, email, security, authentication, analytics, support and payment providers acting under appropriate terms.
  • Professional advisers, auditors, insurers or public authorities where disclosure is lawfully required.
  • A lawful successor in a merger, financing, reorganisation or sale, subject to applicable safeguards.
08

No sale of personal data

Kysero does not sell personal data and does not disclose member health data for third-party advertising. A workspace must not use member data for unrelated marketing without a lawful basis and any consent required by law.

09

International transfers

Some providers may process data outside the European Economic Area. Where an adequacy decision does not apply, we use an approved transfer mechanism such as the European Commission's Standard Contractual Clauses and appropriate supplementary safeguards.

10

Retention

We retain controller data only for as long as needed for service, security, contractual, tax, accounting and legal-claim purposes. Different records have different retention periods.

Workspace-controlled data follows the workspace's instructions, subject to legal and contractual requirements. Historical plan snapshots, workout records and audit entries may be retained when needed to preserve the integrity of activity already completed. Backups are deleted or overwritten on a controlled schedule.

11

Security

We use technical and organisational safeguards appropriate to the risk, including access controls, tenant separation, authentication protections, encryption in transit where supported, logging and backups. No online service can guarantee absolute security.

You are responsible for protecting your credentials and devices. Contact us promptly if you suspect unauthorised access.

12

Your rights

Subject to applicable conditions and exceptions, people in the EEA may have rights to access, correct, erase, restrict or object to processing; receive portable data; withdraw consent; and avoid certain solely automated decisions.

For data controlled by a gym or trainer, contact that organisation first. For data controlled by Kysero, email [email protected]. We may verify identity before responding.

You may also complain to the Hellenic Data Protection Authority at dpa.gr or to the supervisory authority in your habitual EU residence or workplace.

13

Children

The service is not intentionally offered directly to children without the involvement required by law. Workspaces using it with minors must provide suitable notices, obtain parental or guardian authorisation where required and apply heightened safeguards.

14

Automated decisions and AI

The current service does not use member data to make solely automated decisions with legal or similarly significant effects.

Kysero does not use identifiable health, workout or message content to train general-purpose AI models without a separate lawful basis, appropriate transparency and any required consent or controller instruction.

15

Changes and contact

We may update this Policy to reflect legal, technical or service changes. The effective date will be updated and material changes will be communicated where required.

Questions or requests about this Policy can be sent to [email protected].