← Darwinci

Privacy Policy - Darwinci

Last Updated: April 2026


1. Data Controller

Responsible for data processing according to Art. 4(7) GDPR:

human form+ UG (haftungsbeschränkt)
König-Heinrich-Straße 11
06217 Merseburg
Germany

Data Protection Contact:
Email: privacy@darwinci.de
Web: https://darwinci.de/privacy


2. General Information About Data Processing

We process personal data according to the EU General Data Protection Regulation (GDPR) and applicable German data protection laws.

This privacy policy informs you about what data we collect, how we process it, and what rights you have as a data subject.


3. Categories of Personal Data

The Darwinci app processes the following categories of personal data:

3.1 Identity Data

3.2 Training Data (Health/Fitness Data)

3.3 Device Data

3.4 Location Data (Optional)

3.5 Usage and Interaction Data

3.6 Payment Data


4.1 Contract Performance (Art. 6(1)(b) GDPR)

Processing of identity data and basic training data is necessary for: - Account creation and management - Provision of app functionality - Personalization of training plans - Cloud synchronization

Without this data, the app cannot be provided.

For processing of health data (specifically heart rate data), we require explicit consent according to Art. 9(2)(a) GDPR.

This consent is: - Obtained at first use of HR measurement functionality - Revocable at any time - Presented clearly and comprehensibly

Without consent, HR-based features cannot be used.

4.3 Legitimate Interests (Art. 6(1)(f) GDPR)

For the following processing, we rely on legitimate interests: - Security and fraud prevention - System optimization and bug fixes - Analytics and service improvement (when anonymized or anonymizable) - Legal compliance and enforcement


5. Processing of Health Data (Art. 9 GDPR)

5.1 Special Protection for Health Data

Heart rate data and derived values (HR zones, training load, performance level) are health data according to Art. 4(15) GDPR.

We process this data only under the conditions of Art. 9(2) GDPR:

Legal Basis: Art. 9(2)(a) GDPR — Explicit Consent

Users must actively and consciously consent to use HR measurement features.

5.2 Security Measures for Health Data


6. Data Processing and Architecture (Dual-DB System)

6.1 Separation of Identity and Training Data (ADR-011)

Darwinci uses a Dual-Database Architecture:

Database 1 (Identity DB): - Stores identity data (email, name, password hash) - Separately encrypted - Only for authentication and user management

Database 2 (Training/Health DB): - Stores all training and health data - References Identity DB only through anonymous user IDs - No retrievability of identities without additional authorization

Benefits: - Enhanced protection of health data - Reduced abuse risk - Compliance with privacy-by-design principles

6.2 Data Storage


7. Third Parties and Data Transfers

7.1 RevenueCat (In-App Payments)

Purpose: Processing in-app purchases and subscriptions
Data Transfer: - Payment metadata (transaction ID, timestamp, subscription status) - Anonymous device ID (no relation to email/identity) - NOT: Credit card or bank data (RevenueCat and App Store/Google Play process these directly)

Data Protection: RevenueCat complies with GDPR and Standard Contractual Clauses
Link: https://www.revenuecat.com/privacy

7.2 Firebase / FCM (Push Notifications)

Purpose: Sending push notifications (training reminders, challenges, updates)
Data Transfer: - Device token - Anonymous user ID - NOT: Heart rate or sensitive training data

Data Protection: Google complies with GDPR and Standard Contractual Clauses (SCCs)
Link: https://policies.google.com/privacy

7.3 Apple HealthKit (iOS)

Purpose: Optional integration for syncing with iOS Health app
Data Flow: - App reads HR data from HealthKit (with user consent) - App writes training sessions to HealthKit (with user consent) - HealthKit data remains on user device and is NOT transferred to Darwinci servers

Data Protection: Apple HealthKit subject to Apple’s privacy policy
User Control: Users can disable HealthKit permissions anytime in iOS Settings

7.4 Google Health Connect (Android)

Purpose: Optional integration for syncing with Android health apps
Data Flow: - App reads HR data from Health Connect (with user consent) - App writes training sessions to Health Connect (with user consent) - Health Connect data remains on user device and is NOT transferred to Darwinci servers

Data Protection: Google Health Connect subject to Google’s privacy policy
User Control: Users can disable Health Connect permissions anytime in Android Settings

7.5 Other Third Parties

Analytics (if enabled): - Aggregated, anonymized usage metrics - NO personal data - Opt-out available in app settings

Crash Reporting (if enabled): - Error logs and stack traces - NO health data - Automatically disabled in production, only enabled in beta/debug


8. International Data Transfers

8.1 Primary Data Location

All data is primarily hosted in the EU (Render, Frankfurt).

8.2 US Data Transfers (Firebase/RevenueCat)

For Firebase and RevenueCat, data may be transferred to the US under: - Standard Contractual Clauses (SCCs) (Art. 46 GDPR) - Google Data Processing Amendment with EU standard clauses - These clauses ensure adequate protection level

Opt-out: Users can disable Firebase/push notifications.


9. Data Subject Rights (Art. 15–22 GDPR)

Users have the following rights:

9.1 Right of Access (Art. 15 GDPR)

Users can request information about what data is processed about them at any time.

Submit Request To: privacy@darwinci.de
Response Deadline: 30 days

9.2 Right to Rectification (Art. 16 GDPR)

Users can correct incorrect or incomplete data.

In-App: Name and email can be edited in settings
By Request: Other data can be requested at privacy@darwinci.de

9.3 Right to Erasure (Art. 17 GDPR)

Users can request complete deletion of their account:

Self-service (recommended): https://darwinci.de/delete-account/ — enter your email, click the confirmation link, and your account is deactivated immediately. Works even without the app installed.

Alternatively via email to: privacy@darwinci.de
Process: 1. Request is verified 2. User account is deactivated 3. All training data is deleted 4. Identity data deleted after 30 days (for dispute resolution) 5. Confirmation sent via email

Exceptions: - Data required by tax or legal obligations cannot be immediately deleted - These are deleted after applicable retention periods

9.4 Right to Restrict Processing (Art. 18 GDPR)

Users can request that their data be stored but not processed (e.g., during a complaint).

Submit Request To: privacy@darwinci.de

9.5 Right to Data Portability (Art. 20 GDPR)

Users can export their training data in a structured, standard format (e.g., CSV, JSON).

In-App: Data export function in settings
Or By Request: privacy@darwinci.de

9.6 Right to Object (Art. 21 GDPR)

Users can object to processing of their data for direct marketing or analytics.

Email: privacy@darwinci.de

Users can withdraw consent for health data processing at any time:

In-App: Disable HR measurement in settings
Or By Request: privacy@darwinci.de

Processing of previous data remains lawful.


10. Data Security

10.1 Technical Measures

10.2 Organizational Measures


11. Automated Decision-Making & Profiling

The app uses automated algorithms for: - Training Plan Adaptive Adjustment (PL/TL-based): Calculation of next planned training - Performance Analysis: Calculation of performance metrics based on HR data

These are NOT automated decisions with legal consequences. Users can manually adjust training plans or disable algorithms.


12. Data Protection Contact / Complaints

12.1 Privacy Contact

Privacy inquiries:
Email: privacy@darwinci.de
Web: https://darwinci.de/privacy

12.2 Complaint to Supervisory Authority

Users have the right to lodge a complaint with the competent Data Protection Authority if they suspect data protection violations:

EU Authorities: https://edpb.ec.europa.eu/about-edpb/board/members_en

Germany (examples): - Federal: Bundesbeauftragte für Datenschutz und Informationsfreiheit (BfDI) - States: Respective state data protection authorities


13. Changes to This Privacy Policy

We may update this privacy policy to reflect changed laws or processes.

Material changes will be: - Announced 30 days in advance (in-app notification) - Users must accept new terms before further use

Last Updated: April 2026


14. Summary of Privacy Principles

Darwinci processes data according to these principles:

✓ Data Minimization: Collect only necessary data
✓ Purpose Limitation: Use data only for stated purposes
✓ Storage Limitation: Delete data when no longer needed
✓ Transparency: Fully inform users
✓ User Control: Users control their data
✓ Security: Maintain highest security standards
✓ EU-First: Store data primarily in the EU


Contact for Questions:
privacy@darwinci.de
https://darwinci.de/privacy