Privacy Policy
Delta Auxilium AI Fitness Application — how we collect, use, and protect your data
DELTA-PP-001 • Version 1.0 • Effective Date: 31.07.2026 • GDPR (EU) • MHMDA (Washington) • SB 370 (Nevada) • FTC Act & HBNR (US)
{{ t.enOnly }}
| Applicable Law | GDPR (EU) • MHMDA – Washington State • SB 370 – Nevada • FTC HBNR |
|---|---|
| Entity / Controller | Delta Auxilium Sp. z o.o., Ul. Bonarka 19/5, Kraków, 30-415, Poland |
| DPO Contact | DPO@aiadvisor.fitness • privacy@aiadvisor.fitness |
| Related Documents | DELTA-DSR-001 (DSR Procedures) • DELTA-CHD-001 (Consumer Health Data Policy) • DELTA-ISP-001 (Information Security Policy) • DELTA-HBNR-001 (Breach Notification Policy) |
Introduction
This Privacy Policy (“Policy”) explains how Delta Auxilium Sp. z o.o. (“Delta,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information in connection with the Delta Auxilium AI fitness mobile application (the “App”).
This Policy applies to all users of the App, regardless of where they are located. Delta is established in Poland and operates under EU law, including the General Data Protection Regulation (“GDPR”). Where users are located in Washington State or Nevada (USA), additional obligations under the Washington My Health My Data Act (“MHMDA”) and Nevada’s Consumer Health Data Law (“SB 370”) also apply. Users located in other US states benefit from the protections described in the “Notice for US Users” section of this Policy.
For the purposes of applicable data protection laws, Delta acts as the data controller, meaning we determine the purposes and means of processing your personal data. Please also review our Terms of Service, which govern your use of the App. Our Consumer Health Data Policy (DELTA-CHD-001), which provides additional disclosures required under MHMDA and SB 370, is incorporated into and forms part of this Policy.
1. Information We Collect
What data the App processes and how it is obtained
1.1 Information You Provide
Account Details
We collect information you provide when creating and maintaining your account, including your name, email address, date of birth, gender, and password.
Fitness Intake and Profile Data
During onboarding, you complete a structured Fitness Intake Form. This includes self-reported information about your current fitness level, training preferences, primary goals, workout schedule, available equipment, and any injuries, health conditions, or past surgeries that may affect training intensity. This information is used exclusively to generate and calibrate your AI fitness plan.
Health and Medical Information (Sensitive Data)
You may voluntarily provide the following sensitive health-related data. Providing this data is optional; however, it improves the accuracy and personalisation of your AI-generated plans:
- Bloodwork and laboratory results: uploaded as files (PDF) or images (JPG, PNG). These may include hormonal panels, biochemical markers, and other lab values. This data is processed solely for AI-based interpretation to support fitness and recovery insights;
- Medication information: details of medications you are currently taking. This data is processed exclusively for harm-reduction purposes, including monitoring potential interactions with exercise and recovery. Delta does not prescribe, sell, or promote any medication;
- Supplement information: dietary supplements, vitamins, and sports nutrition products you use. AI-generated supplement guidance is general and educational only;
- Sleep data: sleep duration and quality indicators;
- Nutrition data: caloric intake, macronutrient breakdown, and dietary habits;
- Hydration: daily fluid intake;
- Activities and steps
Voice Input
The app allows you to log data or interact with the AI by voice. Voice input will be transmitted to a speech recognition system solely to convert it to text. Voice recordings are not stored, no voiceprint is created, and no biometric identification or authentication is performed using your voice.
Support Requests
We collect any information you provide when contacting us for support or submitting inquiries.
1.2 Information Collected Automatically
Usage Data
We collect information about how you interact with the App, such as screens viewed and features used. This data is used to improve usability and functionality.
Device and Technical Information
We collect technical data from the device you use to access the App, including device model, operating system version, and approximate location derived from IP address (used solely for localisation, technical compatibility, and security purposes).
Crash and Performance Logs
We collect pseudonymised or anonymised technical data to identify and resolve application errors (for example, via services such as Firebase and Sentry Crashlytics).
1.3 Information Obtained from Third-Party Services
Apple Health and Google Fit (Planned Integration)
The App has been integrated with Apple Health and Google Fit to synchronise step count and sleep data. This integration is subject to your explicit permission granted through your device settings. Where such integrations provide health-related data, we do not sell this information, do not use it for advertising, and do not share it with third parties except as necessary to provide the App.
LLM Providers
The App uses one or more Large Language Model (“LLM”) providers (which may include services such as Google Gemini, OpenAI, Meta LLaMA, or equivalent platforms) to process your data and generate personalised recommendations. LLM providers act as data processors on our behalf under Data Processing Agreements. Please see Section 3 and the notice in Section 1.4 regarding potential use for AI model training.
1.4 AI Model Training – Important Disclosure
1.5 Information We Do Not Collect
To avoid ambiguity, Delta does not collect:
- Payment or card data – all payments are processed exclusively through Apple App Store and Google Play Store via In-App Purchases. Delta never receives or stores your payment card information;
- Biometric identifiers – the App does not create faceprints, voiceprints, fingerprints, or similar templates;
- Precise GPS location – the App does not use GPS tracking or location-based features;
- Social or community data – no social features, messaging, leaderboards, or user-to-user interactions exist in the App;
- Data from children – the App is exclusively for users aged 18 and over. See Section 9.
2. How We Use Your Information
Purposes of processing and the activities they enable
2.1 Delivery and Operation of the App
We use your information to:
- Create, manage, and maintain your user account;
- Administer your auto-renewable subscription, including subscription status and renewal management (billing itself is handled by the App Store / Google Play);
- Generate your initial personalised fitness, nutrition, and lifestyle plan based on your Fitness Intake Form;
- Continuously update and recalibrate your plan in near-real time as you enter new data;
- Interpret correlations across all data categories to provide risk-awareness and harm-reduction insights (for example, interactions between sleep quality, medications, and bloodwork indicators);
- Provide workout timers and session tracking functionality.
2.2 Service Improvement and AI Development
We process information to:
- Evaluate how the App is used, identify errors, and improve functionality;
- Conduct research and develop new features;
- Train, test, and refine AI and machine learning models, subject to the separate consent described in Section 1.4. Where feasible, we rely on aggregated or de-identified data for these purposes.
2.3 Safety, Security, and Enforcement
We process information to:
- Maintain the security of the App and user accounts;
- Detect and prevent fraud, misuse, or unauthorised access;
- Enforce our Terms of Service and applicable policies.
2.4 Legal and Regulatory Compliance
We process information where necessary to:
- Respond to lawful requests from courts, regulators, or law enforcement;
- Meet our obligations under GDPR, MHMDA, SB 370, the FTC Health Breach Notification Rule, and applicable Polish and EU law;
- Maintain records required by tax, accounting, or other legal obligations.
2.5 What We Do Not Do
3. How We Share Your Information
Third parties who may access your data and the basis for sharing
3.1 Service Providers and Processors
We share information with third-party service providers who assist us in operating, maintaining, and improving the App. These include:
- LLM providers (AI processing of your health data to generate recommendations);
- Cloud infrastructure and hosting providers;
- Crash reporting and performance analytics services (e.g., Firebase Crashlytics);
- Customer support tooling.
All processors are engaged under Data Processing Agreements that restrict their use of your data to the specific purpose for which it is shared. They may not use your data for their own independent purposes. Under MHMDA (RCW 19.373.060) and SB 370 (Sec. 29), these agreements contain specific additional provisions required by those laws for consumer health data.
3.2 Legal and Regulatory Disclosures
We may disclose your information to law enforcement, courts, regulators, or government authorities where required or permitted by applicable law, including to:
- Respond to valid legal process (court orders, subpoenas, or equivalent);
- Protect against fraud, harm, or violation of our policies;
- Comply with our regulatory obligations.
3.3 Business Transactions
If Delta is involved in a merger, acquisition, restructuring, or transfer of assets, your information may be transferred to the relevant parties as part of that process. We will provide notice of any such transfer and the applicable privacy terms.
3.4 With Your Consent
We may share your information with third parties for purposes beyond those described above only with your prior, specific, and informed consent. This includes any sharing of consumer health data for secondary purposes under MHMDA and SB 370.
3.5 What We Do Not Share
- We do not sell your personal data or consumer health data;
- We do not share your health data with advertising networks, data brokers, or insurance providers;
- We do not share your data with supplement vendors or commercial partners for promotional purposes.
4. Legal Grounds for Processing
GDPR legal bases and US equivalents
Certain data protection frameworks, including the GDPR applicable in the European Economic Area, require Delta to rely on a valid legal basis when processing personal information. The table below summarises the primary legal grounds we rely on for each processing activity.
| Purpose | Data Categories Processed | Legal Basis (GDPR / US) |
|---|---|---|
| Account creation and service delivery | Account detailsFitness intake and profile dataDevice and technical informationUsage data | Performance of contract (GDPR Art. 6(1)(b))Legitimate interests (GDPR Art. 6(1)(f)) – service operation |
| Processing of health and medical data (Special Category) | All health metrics (bloodwork, medications, supplements, sleep, nutrition, hydration) | Explicit consent (GDPR Art. 9(2)(a))MHMDA / SB 370: affirmative opt-in consent required prior to collection |
| AI plan generation and real-time recalibration | All health metricsFitness profile dataAI-generated outputs | Performance of contract (GDPR Art. 6(1)(b))Explicit consent for Special Category data (GDPR Art. 9(2)(a)) |
| AI model training and improvement | Health metricsFitness dataUsage patterns | Consent (GDPR Art. 6(1)(a) and Art. 9(2)(a))MHMDA: separate opt-in requiredSeparate consent request in-app |
| App analytics and improvement | Usage dataDevice and technical informationCrash and performance logs | Legitimate interests (GDPR Art. 6(1)(f))Consent where required by local law (ePrivacy) |
| Security and fraud prevention | Account dataUsage and interaction dataTechnical information | Legitimate interests (GDPR Art. 6(1)(f))Vital interests where relevant (GDPR Art. 6(1)(d)) |
| Legal and regulatory compliance | Any data necessary to respond to legal obligations | Compliance with legal obligation (GDPR Art. 6(1)(c))Legitimate interests (GDPR Art. 6(1)(f)) |
4.1 Automated Decision-Making
The App uses AI systems to generate personalised fitness, nutrition, and lifestyle plans. This constitutes a form of automated processing. Delta’s position, consistent with our legal analysis, is that this does not constitute automated decision-making that produces legal or similarly significant effects within the meaning of GDPR Article 22, as the App does not make consequential decisions about healthcare access, insurance eligibility, or equivalent matters.
You have the right to receive meaningful information about the logic involved in AI-generated recommendations and to flag any recommendation you believe is inappropriate or inaccurate. Please contact us using the details in Section 11.
5. Cross-Border Data Transfers
How we safeguard data transferred outside the EEA
Delta is established in Poland (European Union). The App is available to users in the United States and other countries outside the European Economic Area (“EEA”). When we transfer personal data outside the EEA — for example, to LLM providers or cloud infrastructure based in the United States — we implement appropriate safeguards in accordance with GDPR Chapter V.
Such safeguards include:
- Standard Contractual Clauses (“SCCs”) approved by the European Commission, where applicable supplemented by a Transfer Impact Assessment;
- Additional technical and organisational measures (such as encryption and access controls) where required by the assessment;
- Other lawful transfer mechanisms recognised under applicable EU data protection law.
You may request further information about the specific safeguards applicable to transfers involving your data by contacting our DPO using the details in Section 11.
6. Your Privacy Rights and Choices
How to exercise your rights under GDPR, MHMDA, and SB 370
Depending on your location and applicable law, you have the following rights in relation to your personal data. These rights are subject to verification of your identity and to applicable legal limitations. Full procedures are set out in our Data Subject Rights Procedures document (DELTA-DSR-001).
6.1 Right of Access
You may request confirmation of whether we process personal data about you and obtain a copy of that data, together with information about the purposes of processing, categories of data, recipients, and retention periods. A significant portion of your data is accessible directly through your account settings. (GDPR Art. 15 • MHMDA RCW 19.373.040(1) • SB 370 Sec. 24(1))
6.2 Right to Rectification
You may request correction of inaccurate or incomplete personal data. Most profile and health data can be updated directly through the App. (GDPR Art. 16)
6.3 Right to Deletion (Erasure)
You may request deletion of your personal data and, where applicable, that we instruct third parties who have received your data to delete it. You can initiate full account deletion directly within the App. Please note that certain data may be retained where required by law and that technical limitations may prevent removal of data already incorporated into AI model weights — we will explain this clearly at the time of your request. (GDPR Art. 17 • MHMDA RCW 19.373.040(3) • SB 370 Sec. 24(3))
6.4 Withdrawal of Consent
Where processing is based on your consent (including all health and Special Category data), you may withdraw that consent at any time using the consent management controls in the App’s Privacy Settings. Withdrawal does not affect the lawfulness of processing prior to withdrawal. Withdrawing consent for core health data processing will substantially affect the App’s ability to generate personalised recommendations. (GDPR Art. 7(3) • MHMDA RCW 19.373.030 • SB 370 Sec. 18)
6.5 Right to Data Portability
Where processing is based on consent or contract and carried out by automated means, you may receive your personal data in a structured, commonly used, machine-readable format (JSON) and, where technically feasible, have it transmitted to another controller. (GDPR Art. 20)
6.6 Right to Restriction and Objection
You may request that we restrict certain processing activities, or object to processing based on our legitimate interests. We will cease such processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. (GDPR Arts. 18–21)
6.7 Right Not to Be Discriminated Against
Delta will not penalise you, deny you service, or provide a lower quality of service as a result of your exercising any privacy right. (MHMDA RCW 19.373.040(5) • SB 370 Sec. 24(5))
6.8 How to Submit a Request
You may exercise your rights through any of the following channels:
- In-App: “Menu ‘More’ → Profile →” Legal and Privacy” → “Data Subject Acess Request” (preferred channel — identity is verified by your existing authentication);
- Email: privacy@aiadvisor.fitness;
- Post: Delta Auxilium Sp. z o.o., Ul. Bonarka 19/5, Kraków, 30-415, Poland, Attn: Privacy Team.
We will respond within 30 days of a verified request (extendable by up to two additional months for complex requests). US users in Washington and Nevada: response timelines and escalation paths are as described in the Consumer Health Data Policy and DELTA-DSR-001.
7. Data Retention
How long we keep your information
We retain personal data for as long as necessary to provide the App and fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.
In general:
- Account and profile data is retained for the duration of your account and deleted following account closure, subject to legal retention requirements;
- Health and medical data is retained for the duration of your account. You may delete individual data categories at any time within the App;
- Uploaded files (laboratory results) are deleted upon your request or upon account closure;
- Usage and analytics data is retained in pseudonymised form for up to 24 months following the end of your subscription;
- Crash logs and performance data are retained for up to 12 months;
- Financial and billing records (limited to subscription transaction logs, as Delta does not store payment card data) are retained for 5 years in accordance with Polish accounting law;
- Records of consent and consent withdrawal are retained for the duration of any applicable limitation period to enable us to demonstrate compliance.
Retention periods are reviewed periodically and adjusted where legal obligations change. Data subject to a legal hold or regulatory investigation will be retained for the duration of the relevant proceedings.
8. Security Measures
How we protect your information
We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorised access, disclosure, alteration, or destruction. Given the sensitivity of the health data we process, our security programme is designed to meet a standard appropriate for organisations processing Special Category data and consumer health data under GDPR and MHMDA.
Our security measures include, among others:
- Encryption of health and personal data in transit and at rest;
- Access controls restricting data access to authorised personnel on a need-to-know basis;
- Security monitoring, logging, and incident response procedures;
- Contractual security requirements imposed on all processors and subprocessors;
- Alignment with recognised security frameworks (such as NIST or ISO 27001) as detailed in our Information Security Policy (DELTA-ISP-001).
In the event of a personal data breach involving your health data, Delta will notify you and the relevant authorities in accordance with GDPR Article 33/34 and the FTC Health Breach Notification Rule, as applicable. Our breach notification procedures are set out in DELTA-HBNR-001.
9. Age Restrictions
The App is for adults only
The App is exclusively intended for users who are 18 years of age or older. Delta does not knowingly collect personal data from individuals under 18. If we become aware that personal data has been collected from a person under 18, we will delete that data promptly.
If you believe a person under 18 has submitted personal data to the App, please notify us at privacy@aiadvisor.fitness.
10. Notice for Users in Washington State and Nevada (USA)
Additional rights under MHMDA and SB 370
This section provides additional disclosures required by the Washington My Health My Data Act (MHMDA, RCW Ch. 19.373) and Nevada’s Consumer Health Data Law (SB 370). These disclosures supplement, and do not replace, the rest of this Policy. Our full Consumer Health Data Policy (DELTA-CHD-001) is available separately and is incorporated into this Policy by reference.
10.1 Consumer Health Data We Collect
We collect the following categories of consumer health data from Washington and Nevada residents:
- Sleep data (duration, quality indicators);
- Nutrition and hydration data;
- Bloodwork and laboratory results;
- Medication information (for harm-reduction purposes only);
- Supplement usage;
- Step count and activity data (via Apple Health / Google Fit integration, where enabled);
- Data derived or inferred by our AI from the above categories.
10.2 Purposes for Collection
Consumer health data is collected and used exclusively to generate and continuously improve your personalised AI fitness, nutrition, and recovery plans, and for the harm-reduction purposes described in Section 2. It is not used for advertising, marketing, or sale to third parties.
10.3 Who We Share Consumer Health Data With
We share consumer health data only with:
- LLM providers acting as processors under Data Processing Agreements;
- Cloud infrastructure providers acting as processors;
- Parties required by applicable law.
We do not sell consumer health data. We do not share consumer health data with third parties for secondary purposes without your separate affirmative opt-in consent.
10.4 Your Rights as a Washington or Nevada Resident
In addition to the rights described in Section 6, you have the right to:
- Confirm whether we collect your consumer health data and receive a list of all third parties with whom it is shared;
- Request deletion of your consumer health data and require us to instruct third parties who have received it to delete it;
- Withdraw your consent to the collection or sharing of consumer health data at any time;
- Be free from discrimination for exercising these rights.
Requests may be submitted via the channels in Section 6.8. We respond within 45 days (extendable by a further 45 days with notice to you).
10.5 Enforcement and Complaints
MHMDA violations may be enforced by the Washington State Attorney General (statutory penalties up to $7,500 per violation) and may give rise to a private right of action (actual damages, injunctive relief, and potential treble damages up to $25,000). If you have a complaint about how we handle your consumer health data, you may contact us first at privacy@aiadvisor.fitness. You also have the right to file a complaint with the Washington State Attorney General.
11. Updates and Contact Information
11.1 Updates to This Policy
We may update this Policy from time to time. Any changes will be reflected by publishing the updated version within the App together with a revised effective date. Where changes are material, we will provide advance notice through the App or by email. If you do not agree with the updated Policy, you should discontinue use of the App and may request deletion of your account.
11.2 Contact Us
If you have any questions about this Policy or our data handling practices, or wish to exercise your rights, please contact us:
| Privacy / DSR Team | privacy@aiadvisor.fitness |
|---|
| Data Protection Officer | DPO@aiadvisor.fitness |
|---|
| Postal Address | Delta Auxilium Sp. z o.o., Ul. Bonarka 19/5, Kraków, Malopolskie, 30-415, Poland — Attn: Legal / Privacy |
|---|
EU residents also have the right to lodge a complaint with the Polish data protection authority (UODO):
| UODO (Polish DPA) | Urząd Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa • https://uodo.gov.pl |
|---|
Residents of other EU member states may alternatively lodge a complaint with the supervisory authority in their country of habitual residence.
Delta Auxilium Sp. z o.o. • DELTA-PP-001 v1.0 • Effective Date: [31.07.206]
This policy should be read together with: DELTA-CHD-001 (Consumer Health Data Policy) • DELTA-DSR-001 (Data Subject Rights Procedures)