Privacy Policy

Last updated: August 2026

1. Controller
Cenvik GmbH
Goslarer Ufer 1a
10589 Berlin
Germany

Email: info@cenvik.com

Cenvik GmbH ("Cenvik", "we", "us") is responsible for the processing of personal data described in this Privacy Policy.

2. Principles of Data Processing

Protecting your personal data, and in particular your health and fitness data, is of paramount importance to us.

We process personal data in accordance with applicable data protection laws, including the General Data Protection Regulation ("GDPR"), and only for specified and legitimate purposes.

Health and fitness data are treated as sensitive personal data and are subject to enhanced safeguards.

3. Categories of Data We Process

Depending on how you use our website, applications and services, we may process the following categories of personal data:

• Contact and account information, such as your name, email address and account details.
• Technical information, such as IP address, device type, operating system, browser information and application version.
• Usage information relating to your interaction with our website, applications and services.
• Health, fitness and wellness information that you provide directly or choose to make available through connected devices, applications or health-data services.

Health, fitness and wellness information may include, depending on the services and permissions you choose to enable:

• Physical activity, movement, steps and exercise information.
• Heart rate and other cardiovascular measurements.
• Sleep duration, sleep patterns and related sleep measurements.
• Stress and recovery-related measurements.
• Blood oxygen saturation and respiratory measurements.
• Body measurements and other health and fitness metrics.
• Other health or wellness information that you explicitly choose to make available to Cenvik.

Cenvik only seeks access to health and fitness data that are necessary to provide the relevant features and services.

You control which supported health and fitness data you choose to make available to Cenvik through the permissions provided by your device or connected health-data service.

4. Purpose and Legal Basis

We process personal data for the following purposes:

• Providing and operating our website, applications and services.
• Creating and administering your account.
• Responding to inquiries and communicating with you.
• Enabling you to connect supported health, fitness and wearable-data sources.
• Bringing together health, fitness and wellness information from different sources in one service.
• Helping you understand your fitness, activity, sleep, stress, recovery and other health trends.
• Providing personalised health and wellness insights, preventive health monitoring and lifestyle coaching.
• Supporting health coaching and, where applicable, preventive health services.
• Maintaining the security and technical operation of our services.
• Improving the reliability, functionality and user experience of our services.
• Complying with applicable legal obligations.

The legal bases for processing personal data may include:

• Art. 6(1)(b) GDPR – performance of a contract or pre-contractual measures.
• Art. 6(1)(f) GDPR – our legitimate interests in operating, securing and improving our services.
• Art. 6(1)(a) GDPR – your consent.

Where health-related data constitute special-category personal data under Art. 9 GDPR, processing is based, as applicable, on:

• Art. 9(2)(a) GDPR – your explicit consent.
• Art. 9(2)(h) GDPR – preventive or healthcare purposes, where applicable.

Where processing is based on your consent, you may withdraw that consent at any time with effect for the future.

5. Connected Health, Fitness and Wearable Data

Cenvik allows users to connect supported devices, applications and health-data services.

Connecting such a service is voluntary. Cenvik will only access the categories of information that you have authorised and that are necessary to provide the relevant Cenvik functionality.

Data obtained from connected health and fitness services are used to provide user-facing health and wellness features, including the consolidation and presentation of health information, identification of trends and changes over time, personalised insights, preventive health monitoring and lifestyle coaching.

We do not sell health or fitness data.

We do not use health or fitness data for advertising, marketing profiling, determining creditworthiness, insurance eligibility or employment decisions.
We do not share health or fitness data with data brokers.

Health and fitness data are not disclosed to third parties except where this is necessary to provide a service requested by you, where you have provided the required consent, or where disclosure is required by law.

6. Data Sharing and Service Providers

Personal data are only shared where necessary to provide our services, where you have authorised the sharing, or where we are legally required to do so.

Recipients may include:

• Hosting, cloud infrastructure and IT service providers.
• Technology providers that support the secure operation of our platform and connected health-data services.
• Medical or health professionals involved in providing services to you, where applicable and appropriately authorised.
• Professional advisers and authorities where disclosure is legally required.

Service providers processing personal data on our behalf are subject to appropriate contractual and data-protection obligations.

7. International Data Transfers

Where personal data are processed outside the European Union or European Economic Area, we ensure that appropriate safeguards are in place in accordance with applicable data protection law.

These may include adequacy decisions, Standard Contractual Clauses or other legally recognised safeguards.

8. Data Security

We implement appropriate technical and organisational measures designed to protect personal and health-related data against unauthorised access, alteration, disclosure, loss or destruction.

These measures include, where appropriate:

• Encryption during transmission using current security standards.
• Appropriate encryption and protection of stored sensitive data.
• Access controls limiting personal data to authorised persons and systems.
• Technical and organisational measures appropriate to the sensitivity of health-related information.
• Monitoring and security measures designed to protect our systems and services.

Access to personal health information is restricted to persons and systems that require such access for authorised purposes.

9. Data Retention and Deletion

We retain personal data only for as long as necessary for the purposes for which they were collected or as required by applicable law.

Health and fitness data obtained through connected services are retained only for as long as necessary to provide the relevant Cenvik services or for another purpose for which you have provided valid consent.

You may withdraw permission for Cenvik to access data from a connected health or fitness service at any time using the controls provided by the relevant device, application or service.

Disconnecting a data source prevents Cenvik from obtaining new data from that source but does not automatically delete data previously received by Cenvik.

You may request deletion of personal data held by Cenvik by contacting us at info@cenvik.com, subject to any legal obligations requiring us to retain certain information.

Where a Cenvik account is deleted, associated personal data will be deleted or anonymised unless continued retention is required by law or another lawful basis applies.

10. Your Choices and Control of Health Data

Connecting health and fitness data to Cenvik is voluntary.

You may:

• Decide whether to connect a supported health-data source.
• Choose which requested categories of health and fitness information you permit Cenvik to access.
• Change or revoke permissions through the relevant device or connected service.
• Disconnect a connected data source.
• Withdraw consent for future processing where processing is based on consent.
• Request deletion of data held by Cenvik, subject to applicable legal retention requirements.

Revoking access to a connected service will stop future access through that connection but may not automatically delete information already transferred to Cenvik. You can request deletion of such information by contacting us.

11. Your Rights

Under applicable data protection law, you may have the right to:

• Access your personal data.
• Request correction of inaccurate personal data.
• Request deletion of your personal data.
• Request restriction of processing.
• Object to certain processing.
• Request data portability.
• Withdraw consent at any time with effect for the future.

To exercise these rights, please contact:

info@cenvik.com

12. Cookies and Website Analytics

We use cookies and, where applicable, analytics technologies to operate our website, understand website usage and improve our services.

Further information and configuration options are available through our cookie settings.

13. Right to Lodge a Complaint

You have the right to lodge a complaint with a competent data-protection supervisory authority if you believe that the processing of your personal data infringes applicable data-protection law.

14. Changes to this Privacy Policy

We may update this Privacy Policy where necessary to reflect changes to our services, technology, legal requirements or data-processing practices.

The current version will always be made available through our website and applications.