WHO WE ARE
NEURONDIGITAL LTD, a company incorporated under the laws of Malta on the 14th May 2021, having official number C99146, and its official address at 8, Maranatha, Triq tal-Fieres, Kirkop, Malta (hereinafter referred to as “We” or “Us”) operate the Exercise Timer application currently available on Google Play & Apple App Store. Persons having interest in obtaining more information on our practices or otherwise can send an email on email@example.com. We respect the privacy of individuals and we are committed to protect information of visitors and customers.
TYPES OF DATA COLLECTED
In General, Exercise Timer processes personal data that you as a user of the App make available to us, for example by using the App, information that others provide to us (“Data”), and information we collect from you automatically. We collect the following types of information about you:
Registration, authentication & Profile
By registering, authenticating or filling profile details, Users allow Exercise Timer to identify them and give them access to dedicated services. User registers by filling out the registration form and providing the Personal Data directly to Exercise Timer. Personal Data processed: date of birth; email address; password; profile picture; username, weight & gender (to calculate estimate calorie burn).
Exercise Timer allows you to sign in and log in to the services using third party products and services such as Facebook & Apple. This type of service allows Exercise Timer to access Data from your account on a third-party service and perform actions with it. These services are not activated automatically, but require explicit authorization by the User. Personal Data processed: email address; profile picture; username.
Workout, Training Plans and Activity Information
This is the data collected when you create a new Exercise, Workout, Training Plan or a Workout History Log and when you perform an Workout Activity (including workout duration, time, date, workout notes & exercise details).
Content you Share
When you are using our App, you might share a workout, training plan or workout history. When a user shares a workout, a training plan or workout history, this is made publicly available to anyone who has the link.
Payment and Subscription Information
We use Google in-App Billing to process payments. Although we do not store any credit card information ourselves, we store a payment ID number that is given out by the Google and can be allocated to a person by that Google, as well as duration of your subscription, price, currency and VAT (based on country info).
When you are using our App, we will collect certain event information (e.g. opening Exercise Timer, completing a workout, saving a workout, opening pages inside the app) and send them to our servers. This information can include, but is not limited to the workout name, duration, exercise names and number of laps. This allows us to analyse and constantly improve the use of our Products.
Technical Information & Log Data
Whenever you use our Service, in a case of an error in the app we collect data and information (through third party products) on your phone called Log Data. This Log Data may include information such as unique device identifiers for advertising (Google Advertiser ID or IDFA, for example), device name, operating system version, the configuration of the app when utilizing our Service, the time and date of your use of the Service, IP Addresses, number of clicks, referring/exit pages and other statistics. This type of service allows Exercise Timer to monitor the use and behaviour of its components so its performance, operation, maintenance and troubleshooting can be improved.
Cookies are files with a small amount of data that are commonly used as anonymous unique identifiers. These are sent to your browser from the websites that you visit and are stored on your device's internal memory. This Service does not use these “cookies” explicitly. However, the app may use third party code and libraries that use “cookies” to collect information and improve their services. You have the option to either accept or refuse these cookies and know when a cookie is being sent to your device. If you choose to refuse our cookies, you may not be able to use some portions of this Service.
By filling in the contact form with their Data, the User authorizes Exercise Timer to use these details to reply to requests for information, quotes or any other kind of request as indicated by the form’s header. Personal Data processed: email address.
HOW EXERCISE TIMER USES INFORMATION
Operate our Product
Exercise Timer uses the information we collect and receive to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, enforce our terms of service, to process payments, to promote safety, to provide you with customer support, provide you with calorie burn estimates (when providing your weight & gender).
Improve our Product
We also use your information to analyze, develop and improve the Services. To do this, Exercise Timer may use third party analytics providers to gain insights into how our Services are used and to help us improve the Services. Additionally, your information may be shared with third parties, as set forth below.
To ensure that you receive only information that corresponds to your interests, we may use information such as unique device identifiers for advertising (Google Advertiser ID or IDFA, for example) to deliver personalized advertisements (“ads”).
We use your information to communicate with you about the Services, send you marketing communications (where you have agreed to receive such messages), or let you know about new features or updates to our Terms of Service.
HOW INFORMATION IS SHARED
We may share your information with third parties who provide services to Exercise Timer such as: To facilitate our Service; To provide the Service on our behalf; To perform Service-related services; or To assist us in analyzing how our Service is used; Process Payments; Promote Service. These service providers only have access to the information necessary to perform these limited functions on our behalf and are required to protect and secure your information. More details on our service providers:
Google Play Services
Exercise Timer is distributed on the Google Play Store, a platform for the distribution of mobile apps, provided by Google Ireland Limited. By virtue of being distributed via this app store, Google collects usage and diagnostics data and share aggregate information with the Owner. Much of this information is processed on an opt-in basis. Users may opt-out of this analytics feature directly through their device settings. More information on how to manage analysis settings can be found on this page.
Personal Data processed: Usage Data.
Apple App Store (Apple Inc.)
Exercise Timer is distributed on Apple's App Store, a platform for the distribution of mobile apps, provided by Apple Inc. By virtue of being distributed via this app store, Apple collects basic analytics and provides reporting features that enables the Owner to view usage analytics data and measure the performance of Exercise Timer. Much of this information is processed on an opt-in basis. Users may opt-out of this analytics feature directly through their device settings. More information on how to manage analysis settings can be found on this page.
Personal Data processed: Usage Data.
AdMob (Google Ireland Limited)
AdMob is an advertising service provided by Google Ireland Limited. In order to understand Google's use of Data, consult Google's partner policy.
Personal Data processed: Cookies; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example); Usage Data.
Google Analytics (Google Ireland Limited)
Google Analytics is a web analysis service provided by Google Ireland Limited (“Google”). Google utilizes the Data collected to track and examine the use of Exercise Timer, to prepare reports on its activities and share them with other Google services. Google may use the Data collected to contextualize and personalize the ads of its own advertising network.
Personal Data processed: Cookies; Usage Data.
Google Analytics for Firebase (Google Ireland Limited)
Personal Data processed: Application opens; Application updates; device information; first launches; geography/region; In-app purchases; number of sessions; number of Users ; operating systems; session duration; Usage Data.
Amplitude (Sonalight, Inc.)
Personal Data processed: Cookies; Usage Data, Device Info, IP Address.
Google Pay (Google Ireland Limited)
Apple Pay (Apple Inc.)
Crashlytics (Google Ireland Limited)
Firebase Performance Monitoring (Google Ireland Limited)
Firebase Performance Monitoring is a monitoring service provided by Google Ireland Limited.
Freshdesk (Freshworks, Inc.)
Freshdesk is a support and contact request management service provided by Freshworks, Inc.
Facebook Authentication (Facebook, Inc.)
Facebook Authentication is a registration and authentication service provided by Facebook, Inc. and is connected to the Facebook social network.
Branch Attribution is an analytics service provided by Branch Metrics, Inc.
Affiliates and Acquirers of our Business or Assets
Law enforcement or legal requests
We may preserve and share your information with third parties, including law enforcement, public or governmental agencies, or private litigants, within or outside your country of residence, if we determine that such disclosure is reasonably necessary to comply with the law, including to respond to court orders, warrants, subpoenas, or other legal or regulatory process. We may also retain, preserve or disclose your information if we determine that disclosure is reasonably necessary or appropriate to prevent any person from death or serious bodily injury, to address issues of national security or other issues of public importance, to prevent or detect violations of our Terms of Service or fraud or abuse of Exercise Timer or its members, or to protect our operations or our property or other legal rights, including by disclosure to our legal counsel and other consultants and third parties in connection with actual or potential litigation.
MODE AND PLACE OF PROCESSING THE DATA
Methods of processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of Exercise Timer (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.
Legal basis of processingThe Owner may process Personal Data relating to Users if one of the following applies:
- Users have given their consent for one or more specific purposes. Note: Under some legislations the Owner may be allowed to process Personal Data until the User objects to such processing (“opt-out”), without having to rely on consent or any other of the following legal bases. This, however, does not apply, whenever the processing of Personal Data is subject to European data protection law;
- provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
- processing is necessary for compliance with a legal obligation to which the Owner is subject;
- processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
- processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party.
- In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located. Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the sharing of Personal Data.
Users are also entitled to learn about the legal basis of Data transfers to a country outside the European Union or to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data. If any such transfer takes place, Users can find out more by checking the relevant sections of this document or inquire with the Owner using the information provided in the contact section.
Retention timePersonal Data shall be processed and stored for as long as required by the purpose they have been collected for.
- Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
- Personal Data collected for the purposes of the Owner’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.
The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
THE RIGHTS OF USERS
Users may exercise certain rights regarding their Data processed by the Owner. In particular, Users have the right to do the following:
- Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
- Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent. Further details are provided in the dedicated section below.
- Access their Data. Users have the right to learn if Data is being processed by the Owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
- Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
- Restrict the processing of their Data. Users have the right, under certain circumstances, to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.
- Have their Personal Data deleted or otherwise removed. Users have the right, under certain circumstances, to obtain the erasure of their Data from the Owner.
- Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance. This provision is applicable provided that the Data is processed by automated means and that the processing is based on the User's consent, on a contract which the User is part of or on pre-contractual obligations thereof.
- Lodge a complaint. Users have the right to bring a claim before their competent data protection authority.
Details about the right to object to processing
Where Personal Data is processed for a public interest, in the exercise of an official authority vested in the Owner or for the purposes of the legitimate interests pursued by the Owner, Users may object to such processing by providing a ground related to their particular situation to justify the objection.
Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time without providing any justification. To learn, whether the Owner is processing Personal Data for direct marketing purposes, Users may refer to the relevant sections of this document.
How to exercise these rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. These requests can be exercised free of charge and will be addressed by the Owner as early as possible and always within one month.
ADDITIONAL INFORMATION ABOUT DATA COLLECTION AND PROCESSING
The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of Exercise Timer or the related Services. The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
Additional information about User's Personal Data
System logs and maintenance
For operation and maintenance purposes, Exercise Timer and any third-party services may collect files that record interaction with Exercise Timer (System logs) use other Personal Data (such as the IP Address) for this purpose.
Protecting the privacy of children is important. For this reason, we do not knowingly collect or solicit personal information from anyone under the age of 16 or knowingly allow such persons to register. Under no circumstance persons under the age of 16 may use Exercise Timer. In the event that we notice that we collected personal data from a person under 16 years of age, without verification of parental consent, we will delete that information as quickly as possible. If you believe that we might have any data on children under 16, please contact us on this email: firstname.lastname@example.org
Information not contained in this policy
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.
How “Do Not Track” requests are handled
Exercise Timer does not support “Do Not Track” requests. To determine whether any of the third-party services it uses honor the “Do Not Track” requests, please read their privacy policies.
Should the changes affect processing activities performed on the basis of the User’s consent, the Owner shall collect new consent from the User, where required.
DEFINITIONS AND LEGAL REFERENCES
Personal Data (or Data)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Information collected automatically through Exercise Timer (or third-party services employed in Exercise Timer), which can include: the IP addresses or domain names of the computers utilized by the Users who use Exercise Timer, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.
The individual using Exercise Timer who, unless otherwise specified, coincides with the Data Subject.
The natural person to whom the Personal Data refers.
Data Processor (or Data Supervisor)
Data Controller (or Owner)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of Exercise Timer. The Data Controller, unless otherwise specified, is the Owner of Exercise Timer.
Exercise Timer (or this Application)
The means by which the Personal Data of the User is collected and processed.
The service provided by Exercise Timer as described in the relative terms (if available) and on this site/application.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Small sets of data stored in the User's device.