Privacy Policy
Last updated : August 15, 2026
GDPR Compliant (General Data Protection Regulation)
1. Data Controller
PWA-TECH — Christophe Bonzom, Editor
Email : contact@bikefit-ia.com
Website : www.bikefit-ia.com
Data Protection Officer : contact@bikefit-ia.com
2. Data Collected
2.1 Plans and pricing
- Mandatory : Email, name, hashed password, phone number (cryptographic hash only)
- Optional : Full name, cycling discipline
- Purpose : Account management, service personalization
- Legal Basis : Contract Performance (Art. 6.1.b GDPR)
2.2 Biomechanical Data
- Collected : Images/videos of cycling position, anatomical points detected by AI
- Purpose : Postural analysis, recommendation generation
- Legal Basis : Explicit Consent (Art. 9.2.a GDPR)
- Important: This data is specially protected sensitive data
2.2 Free offer
- Technical : IP address, browser, device, connection logs
- Analytics : Pages visited, time spent, actions performed (via Google Analytics and PostHog, hosted in EU)
- Purpose : Service improvement, security, technical support
- Legal Basis : Legitimate Interest (Art. 6.1.f GDPR)
2.4 Verification and Security Data
- Phone number: a verification code is sent by SMS upon registration. The number is not stored in plain text; only a cryptographic hash (HMAC-SHA-256) is retained for fraud prevention and account uniqueness purposes.
- Legal basis: Legitimate Interest (Art. 6.1.f GDPR) — fraud prevention
- Device identifier: an anonymous technical token (random UUID) is stored as a cookie in your browser to identify your connected devices. This token does not contain any personal data.
- Legal basis: Legitimate Interest (Art. 6.1.f GDPR) — security and fraud prevention. You can remove a device at any time from your 'My Devices' settings.
- Device fingerprint: in order to prevent fraud and the creation of multiple accounts, technical data relating to your device and browser is processed to generate a device identifier. This identifier constitutes personal data. This processing is carried out via the provider Fingerprint, with data hosted in the European Union.
- Legal basis: Legitimate interest (Art. 6.1.f GDPR) — prevention of fraud and multiple accounts.
- Retention: the phone hash is retained for the lifetime of the account. Upon account deletion, the hash is retained for an additional 30 days to prevent immediate re-registration.
3. Data Usage
3.1 Primary Purposes
- Postural Analysis: Processing by AI algorithms to generate recommendations
- Personalization: Adaptation of advice according to your profile and discipline
- History: Tracking your progress over time
- Support: Technical assistance by email
3.2 Service Improvement
To create an account and access the Services, the User must:
- Improve the accuracy of AI algorithms
- Develop new features
- Create anonymous industry statistics
Guarantee: This data is strictly anonymized and does not allow identification of you.
Legal basis: This processing relies on the Publisher's legitimate interest (Art. 6.1.f GDPR) for pseudonymized data. Fully anonymized data no longer constitutes personal data (GDPR Recital 26). You may exercise your right to object in accordance with Section 6 below.
4. Data Sharing
4.1 Principle: No Sharing
Your personal and biomechanical data are NEVER:
- Sold to third parties
- Shared with commercial partners
- Used for targeted advertising
- Transmitted outside the EU
4.2 Legal Exceptions
Sharing only in these strictly defined legal cases:
- Judicial summons or competent authority
- Protection of our legitimate rights in case of dispute
- Medical emergency with your consent
4.3 Technical Sub-processors
We use GDPR-certified sub-processors only for:
- Hosting: Hetzner Online GmbH (frontend, API, database) — EU Servers
- Video Processing: Hetzner Online GmbH — EU Servers
- Database: PostgreSQL encrypted — France Servers
- Payments: Stripe (PCI-DSS certified)
- Support: Encrypted ticketing tools
- SMS Verification: Google LLC — Firebase Authentication (Data Privacy Framework certified for EU-US transfers)
- Fraud prevention: Fingerprint — multiple-account detection (technical device data, hosted in the EU region).
- AI Coach: Anthropic PBC (USA) — Claude API. Data transmitted: joint angles, discipline, bike type (anonymized biomechanical data, no identifying information). Covered by DPA with Standard Contractual Clauses (SCCs). Data not used for model training.
Stripe Inc. is a US-based company. Although payment data is processed on servers located in the EU, the Stripe group may access it from the United States as part of its operations. This transfer is governed by the European Commission's Standard Contractual Clauses (SCCs), in accordance with Article 46.2 of the GDPR.
Google LLC is a US-based company. The phone number is transmitted to Firebase Authentication solely for sending the SMS verification code. This transfer is governed by the Data Privacy Framework (DPF), in accordance with the European Commission's adequacy decision of 10 July 2023.
Anthropic PBC is a US-based company. Anonymized biomechanical data (joint angles, discipline, goal) is transmitted to the Claude API to generate AI Coach advice. No identifying data (email, name, video) is transmitted. This transfer is governed by Anthropic's Data Processing Addendum (DPA) including the European Commission's Standard Contractual Clauses (SCCs). Anthropic is contractually committed not to use this data for training its models.
5. Data Retention Period
User Data
- Active account with a current paid subscription: analyses are retained and viewable for as long as the subscription remains active.
- Cancellation of a paid subscription: analyses remain retained, but viewing them is reserved for Clients with an active subscription. The Client has 90 days to resubscribe and regain full access; after that period, the analyses are automatically and permanently deleted.
- Biomechanical data: Videos automatically deleted within 5 minutes after each analysis, regardless of plan.
- The Client remains in control of their data: deletion is possible at any time, analysis by analysis or the entire account, directly from their personal area — no automatic deletion due to inactivity.
Technical Data
- Security logs: Maximum 1 year
- Analytics data: Maximum 2 years, anonymized after 6 months
- Cookies: For the complete list of cookies, their purposes and durations, see our cookie policy
6. Your GDPR Rights
You have the following rights regarding your data:
Access and control rights:
- Right of Access (Art. 15)
- Right of Rectification (Art. 16)
- Right to Erasure (Art. 17)
- Right to Data Portability (Art. 20)
Opposition rights:
- Right to Object (Art. 21)
- Right to Restrict Processing (Art. 18)
- Withdrawal of Consent
- CNIL Complaint
Data Protection Contact : contact@bikefit-ia.com
Response Deadline : Maximum 1 month
Complaint : CNIL.fr
7. Data Security
Technical Measures
- Encryption: TLS 1.3 for communications, AES-256 for storage
- Authentication: Hashed passwords (bcrypt), 2FA available
- Infrastructure: Secure servers, encrypted backups
- Monitoring: 24/7 intrusion detection
Organizational Measures
- Limited Access: Principle of least privilege
- Training: GDPR awareness for staff
- Audit: Regular controls of access and processes
- Incident: Notification procedure within 72 hours
8. Contact & Complaints
Questions about your data
Data Protection Email :
contact@bikefit-ia.com
Response Deadline :
Maximum 1 month (extensible to 3 months if complex)
CNIL Complaint
In case of unsatisfactory response:
CNIL : cnil.fr/plaintes
3 Place de Fontenoy - TSA 80715 — 75334 PARIS CEDEX 07
9. Protection of Minors
BikeFit IA is reserved for persons aged 16 and over. Minors aged 16 to 17 must have the authorisation of a holder of parental authority. Registration by a minor aged 16 to 17 constitutes a declaration that they have obtained the required parental authorisation. We do not knowingly collect data from minors under 16.
10. Automated Decisions and Profiling
BikeFit IA uses artificial intelligence to analyze your cycling position and generate personalized recommendations. The AI Coach is generated by Claude, an artificial intelligence model developed by Anthropic PBC (USA). Only anonymized biomechanical data (joint angles, discipline, bike type) is transmitted — no identifying data. Responses are automated and not validated by a healthcare professional. This automated processing has no legal effect or similarly significant consequence for you. Recommendations are purely informational and intended to improve your comfort and cycling performance.
In accordance with Article 22 of the GDPR, you have the right to request human intervention, express your point of view, and challenge the generated recommendations.
This privacy policy complies with GDPR and guarantees maximum protection of your personal data.