Privacy Policy

Last updated: May 2026

At BioPulse we take your privacy seriously. This policy explains, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD), what personal data we collect when you use our platform, the purposes for which we process it, the legal basis, with whom we share it, how long we keep it and what rights you have over it.

1. Data controller

The controller of the data is Symbionix S.L. ("BioPulse"), Spanish Tax ID B22937023, registered office in Barcelona, Spain. Registered with the Commercial Registry of Barcelona under IRUS 1000457199810, Folio 1, Sheet B-641380, 1st entry dated 9 September 2025. Website: biopulse.fit. For any matter related to this policy or to exercise your rights, you can write to us at .

2. Personal data we collect

We process the following categories of personal data:

  • Identification and contact data: name, surname, email address, phone number.
  • Account data: login credentials, language, preferences.
  • Platform usage data: training sessions, dates, duration, associated gym or center.
  • Technical data: IP address, device type, operating system, browser, device identifiers.
  • Communications: messages you send us via the contact form or email.

3. Physiological and activity data

BioPulse may collect and process physiological and physical activity data provided by the user or by external devices and platforms. This data may include:

  • Heart rate.
  • Physical activity data (workouts, intensity, duration).
  • Derived data (effort zones, performance metrics).
  • This data is considered health data under applicable regulations (special category, Art. 9 GDPR) and receives the corresponding reinforced safeguards.

4. Third-party integrations

BioPulse may receive data from third-party platforms and devices, such as health apps or wearable devices. These may include:

  • Apple Health.
  • Garmin.
  • Other physical activity data providers.
  • Access to this data is granted only with the user's authorization, provided when connecting the corresponding integration, and may be revoked at any time.

5. Source of the data

We collect data directly from you when you register and use the platform; from biometric devices (heart rate monitors, wearables) you connect to the app; from third-party integrations you authorize (see section 4); and, where applicable, from the gym or sports center through which you access the service.

6. Purpose of processing

Personal and physiological data are used to:

  • Calculate effort and performance metrics.
  • Generate leaderboards in training sessions.
  • Provide analysis and visualization of physical activity.
  • Improve the user experience within the platform.
  • Ensure proper operation of the service.

7. Legal basis and consent

The processing of personal data is based on the user's consent. In the case of physiological or health data (such as heart rate), processing is carried out solely with the user's explicit consent, granted when using the platform and/or when connecting external devices or services. Additionally, certain processing may rely on the performance of the contract (Art. 6.1.b GDPR), compliance with legal obligations (Art. 6.1.c) or legitimate interest (Art. 6.1.f). For users aged 16 or 17, explicit consent is provided directly by the minor in accordance with Art. 8 GDPR. The user may withdraw consent at any time, without affecting the lawfulness of prior processing.

8. Data retention

Personal and activity data will be retained while the user account is active. The user may request the deletion of their data at any time. Once the account is deleted, data will be erased or anonymized within a reasonable period. Accounting and tax data will be retained for the legally required period (up to 6 years); anonymized data for statistical purposes may be retained indefinitely, since it no longer identifies you.

9. Recipients and processors

We do not sell your personal data. We may disclose it to the following categories of recipients, always under GDPR safeguards:

  • Infrastructure providers (hosting, cloud storage, email delivery, analytics) acting as processors under contract.
  • The gym or sports center through which you access the service, in its role as contractual customer.
  • Administrative or judicial authorities when legally required.

10. International transfers

Your data is primarily stored on servers located within the European Union. If we use providers outside the EEA, we guarantee that the transfer is carried out under an adequacy decision of the European Commission or by means of Standard Contractual Clauses, in accordance with Arts. 44–49 GDPR.

11. Your rights

You may exercise the following rights over your personal data at any time:

  • Access: obtain confirmation as to whether we are processing your data and, if so, a copy of it.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten"): request deletion of your data when it is no longer necessary.
  • Restriction of processing: ask us to suspend processing in certain cases.
  • Portability: receive your data in a structured, commonly used and machine-readable format.
  • Objection and withdrawal of consent: object to processing or withdraw consent previously given, without affecting the lawfulness of prior processing.

12. How to exercise your rights

To exercise any of these rights, send a request to indicating which right you wish to exercise and attaching a copy of an ID document. We will respond within a maximum of one month, extendable by two additional months in complex cases.

13. Complaints to the supervisory authority

If you believe that the processing of your data infringes the GDPR, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es.

14. Automated decisions and profiling

BioPulse uses algorithms (including PulseScore™) to analyze your biometric metrics and provide you with information about your performance. These calculations do not produce legal effects on you nor significantly affect you in a similar way, within the meaning of Art. 22 GDPR. In any case, you may object to this processing by contacting us.

15. Minors

BioPulse is available to users aged 16 or over. This minimum age is consistent with Article 8 GDPR and Spanish LOPDGDD Article 7, which set the age of digital consent at 14 in Spain; we apply a stricter threshold of 16 given the sensitive nature of biometric data (Article 9 GDPR). Users aged 16 or 17 may register and provide explicit consent to the processing of their biometric data, but we recommend discussing the use of the service with a parent, guardian, or healthcare professional. If we become aware that we have collected personal data from a user under 16, we will delete that data without undue delay. Parents or guardians who believe their child under 16 has registered may contact us at the email provided in Section 1 to request immediate account deletion.

16. Data security

BioPulse adopts appropriate technical and organizational measures to protect personal data, including access control, secure storage, encryption in transit (TLS) and at rest, activity logging, periodic security reviews and protection against unauthorized access, loss, alteration or destruction.

17. Changes to this policy

We may update this policy to reflect legal changes or changes to our services. We will notify substantial changes by email or within the application. The current version will always be published on this page, indicating the date of the last update.