Privacy Notice – Beamline
- Introduction
- 1. Controller, processors and the legal framework of the processing
- 2. Definitions
- 3. Who is the controller? – the role of the Service Provider and of Clubs/Coaches
- 4. Registration and Profile
- 5. Training planning, training log, attendance, statistics and export
- 6. Health Data: pain and injury log, sleep log, wearable device
- 7. Video recordings and comments
- 8. Competition results
- 9. Community element names
- 10. Subscription, payment and invoicing
- 11. System messages and newsletter
- 12. Provisions concerning minors
- 13. Complaint handling and customer service
- 14. Security and usage logs, cookies and local storage
- 15. Transfers of data outside the European Economic Area
- 16. Data security
- 17. Retention periods – summary
- 18. Rights of Data Subjects and how to exercise them
- 19. Remedies
- 20. Amendments to the Notice
Notice on the processing of personal data carried out through the Beamline application
Effective from: 30 September 2026. This Notice supersedes the previous privacy notice of Sport Track Kft.
This English version is a translation of the Hungarian-language Adatkezelési Tájékoztató; in case of any discrepancy, the Hungarian version prevails.
Introduction
Sport Track Kft. (the “Service Provider”) pays particular attention to the protection of personal data and to ensuring fair and transparent processing. A fundamental requirement of this is that the Service Provider gives Data Subjects appropriate information about the processing of their personal data. This Notice describes the processing operations involved in the use of the Beamline application (the “Application”) and the mybeamline.com website (the “Website”).
In respect of certain processing operations the Service Provider acts as a controller, and in respect of others – where it is not the Service Provider but the Club or the Coach that decides on the use of the personal data – it acts as a processor (see Section 3). This Notice provides information on both activities, so that all of the Service Provider’s activities are transparent to Data Subjects.
The Application may also process data qualifying as health data (pain and injury log, sleep log, recovery data received from a wearable device). Section 6 lays down separate, stricter rules for such data: such data may only be processed with the explicit consent of the Data Subject (or, in the case of a Gymnast under the age of 16, of the Legal Guardian), given separately and withdrawable at any time.
1. Controller, processors and the legal framework of the processing
Controller: Sport Track Kft. (the “Service Provider”)
Registered office and postal address: 1138 Budapest, Tomori utca 32. 4. em. 2. ajtó
Company registration number: 01-09-378065
Tax number: 28974893-2-41
E-mail: info@mybeamline.com
Data protection enquiries: info@mybeamline.com (subject: “Data protection”)
The Service Provider engages the following processors (sub-processors) in the course of providing the service:
- Supabase Pte. Ltd. (registered office: 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513) – operation of the database, user authentication (login), file storage (e.g. uploaded competition result PDFs) and back-end functions. The data are held in a database stored in the European Union (Ireland, AWS eu-west-1 region). As Supabase is established outside the Union and may also access the data from outside the Union for support purposes, the transfer is governed by the standard contractual clauses (SCC) adopted by European Commission Implementing Decision (EU) 2021/914, which are contained in Supabase’s data processing addendum (DPA); the DPA forms part of Supabase’s terms of service and automatically extends to the Service Provider.
- Vercel Inc. (registered office: 440 N Barranca Ave #4133, Covina, CA 91723, USA) – hosting and serving of the web Application. In the course of serving the Application, Vercel processes technical data (IP address, browser data, time of request). The lawfulness of the transfer is ensured by the standard contractual clauses (SCC) incorporated in Vercel’s data processing addendum and – where Vercel is certified – by the EU–U.S. Data Privacy Framework.
- Mux, Inc. (registered office: 88 Stevenson Street, San Francisco, CA 94105, USA) – storage and processing of videos uploaded to the Application, and their signed playback (accessible only to authorised persons). The transfer is governed by the standard contractual clauses (SCC) incorporated in Mux’s data processing addendum.
- Resend (Plus Five Five, Inc.) (registered office: 2261 Market Street #5039, San Francisco, CA 94114, USA) – sending of system messages (invitations, notifications) and newsletters by e-mail. The transfer is governed by the standard contractual clauses (SCC, Module 2) incorporated in the data processing addendum signed by Resend.
- Anthropic, PBC (registered office: 548 Market Street, PMB 90375, San Francisco, CA 94104, USA) – extraction of text, using artificial intelligence, from the content of competition result PDFs uploaded by Users (see Section 8). Under the Service Provider’s commercial terms, Anthropic does not use the processed content to train its own models. The transfer is governed by the standard contractual clauses (SCC) incorporated in Anthropic’s data processing addendum.
- Stripe Payments Europe, Limited (registered office: 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland) – handling of online card payment of the Subscription Fee (from the date on which the payment function goes live). Card data are processed exclusively by Stripe; the Service Provider has no access to them. With regard to payment transactions – in particular in the context of its anti-money-laundering and fraud-prevention obligations – Stripe acts as an independent controller.
Third parties acting as independent controllers:
- WHOOP, Inc. (registered office: One Kenmore Square, #601, Boston, MA 02215, USA; EU representative: Whoop Limited, 70 Sir John Rogerson’s Quay, Dublin 2, D02 R296, Ireland, whoop@gdpr-rep.com). If a Gymnast or a Solo Gymnast connects their own WHOOP account to the Application, the Service Provider receives data via WHOOP’s application programming interface (API) on the basis of the Data Subject’s explicit authorisation (see Section 6.3). WHOOP is an independent controller in respect of the data stored on its own platform, which are governed by WHOOP’s own privacy notice (whoop.com). The Service Provider is a controller only in respect of the data fields imported into the Application.
- Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) – the browser downloads the fonts used by the Application (Google Fonts) from Google’s servers, in the course of which Google receives the user’s IP address. The Service Provider is transitioning to serving the fonts from its own server; until this is completed, this transfer is based on the Service Provider’s legitimate interest (consistent appearance) [Article 6(1)(f) GDPR].
The Service Provider will inform Data Subjects of any extension of or change in the range of processors by amending this Notice; with regard to the processing performed for Clubs and Coaches, by giving prior notice in accordance with the data processing terms of the GTC.
The Service Provider has designed its processing activities having regard to the following legislation:
- Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “GDPR”);
- Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information (the “Privacy Act”);
- Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (the “E-Commerce Act”);
- Act CLV of 1997 on Consumer Protection (the “Consumer Protection Act”);
- Act C of 2000 on Accounting, and Act CXXVII of 2007 on Value Added Tax.
2. Definitions
Terms used in this Notice that are not defined herein have the meaning given to them in the General Terms and Conditions (mybeamline.com/general).
- “User”: a person who uses the Application with their own Profile.
- “Solo Gymnast” (formerly: DIY User): a User who uses the Application as a gymnast individually, without a Coach or Club, for their own purposes.
- “Club”: the sports organisation (association, club, federation) or other group on whose behalf the Head Coach creates the Profile, and to which Coaches and Gymnasts belong.
- “Head Coach”: the User who creates and manages the Club in the Application; the Head Coach has all the permissions of a Coach.
- “Coach”: a User who uses the Application to train the Gymnasts who report to them – whether with their own team or as a member of a Club (including a coach invited by the Club).
- “Assistant Coach”: a Coach who has been invited by the Head Coach or by a Coach, who reports to a Coach or to the Head Coach within the Club, and who has access only to the data of the Gymnasts who report to them (Section 3.2).
- “Gymnast”: a person who is invited by a Coach or Club to use the Application, or whose profile is created by a Coach (a gymnast profile without login, managed by the Coach). Within a Club, a Gymnast may report to an Assistant Coach, a Coach or the Head Coach (the Application’s “Reports to” setting); the staff above the Gymnast under this setting form the Gymnast’s “reporting line” (e.g. Assistant Coach → Coach → Head Coach).
- “Legal Guardian”: the parent or guardian of a minor Gymnast or Solo Gymnast.
- “Health Data”: personal data within the meaning of point 15 of Article 4 GDPR relating to the physical or mental health of a natural person, including in particular the pain, injury, sleep and recovery data listed in Section 6.
- “Data Subject”: the User, the Gymnast (including one with a profile without login), the Legal Guardian, and the persons appearing in the competition results referred to in Section 8.
3. Who is the controller? – the role of the Service Provider and of Clubs/Coaches
3.1. The Service Provider is the controller in the following cases: registration of Users and their Profiles; all data recorded by a Solo Gymnast about themselves (including Health Data); the WHOOP connection; subscription, payment and invoicing; the newsletter; customer service and complaint handling; security and usage logs; the shared competition results database (Section 8.3); and the records of consents requested in the Application from Gymnasts and Legal Guardians.
3.2. The Service Provider is a processor, and the Club or the Coach with their own team is the controller, in respect of the data that the Club or the Coach records and uses in connection with the training of the Gymnasts belonging to them (training plans, training log, attendance, evaluations, videos, pain and injury log kept within the Club, sleep log, statistics, exports). The Club or the Coach, as applicable, is responsible for these processing operations – including in particular the legal basis and informing the Gymnasts. The Service Provider processes these data solely on the instructions of the Club/Coach, in accordance with the data processing terms of the GTC (Article 28 GDPR), for the purpose of providing the service, and does not use them for its own purposes. Access within the Club: a Gymnast’s data (Profile, training plans, training log, statistics, videos, pain and injury log, sleep log, WHOOP data) are accessible only to (a) the Gymnast themselves, (b) the Club’s Head Coach, (c) the staff above the Gymnast in their reporting line (e.g. Assistant Coach → Coach → Head Coach), and (d) while the Gymnast is not assigned to anyone, the Club’s Coaches (but not Assistant Coaches). Teammates and other members of the Club have no access to the Gymnast’s data. The Service Provider ensures this by means of database-level access control; Health Data are, in addition, subject to the rules of Section 6.5.
3.3. In the case of Health Data, the Service Provider – including when acting on behalf of the Club or Coach – technically ensures that such data can only be recorded after the Data Subject (Legal Guardian) has given explicit consent in the Application (Section 6.5).
4. Registration and Profile
4.1. Purpose of the processing: creating and maintaining the User’s Profile, managing login and permissions (roles), and communicating with the User.
4.2. Categories of data processed:
- Registration of a Head Coach, Coach or Solo Gymnast (mandatory): name, e-mail address, password (stored exclusively in encrypted, irreversible form), the selected Profile type, in the case of a Solo Gymnast the date of birth (under 16, also the Legal Guardian’s e-mail address and, if provided, name), in the case of a Head Coach or Coach the confirmation that the User is 18 or older and the time of that confirmation (for the application of the age rules, see Section 12), language, primary discipline and rule set (e.g. women’s/men’s artistic gymnastics, level); in the case of a Head Coach, the name of the Club. Optional: time zone, further settings specified in the Profile.
- Invited Gymnast, Coach or Assistant Coach: the e-mail address, name, role, level and discipline provided by the inviting person, the name of the inviting person and the relationship with the Club/Coach, including whom the invited person reports to; when a Gymnast is invited, the Gymnast’s date of birth and, for a Gymnast under 16, the Legal Guardian’s e-mail address; after the invitation has been accepted, the password set by the User and, for a Coach or Assistant Coach, the confirmation that they are 18 or older and the time of that confirmation.
- Gymnast profile without login created by a Coach: name, discipline, level, date of birth, for a Gymnast under 16 the Legal Guardian’s e-mail address and, if provided, name, and the staff member the Gymnast reports to.
- Technical data: Profile identifier, time of creation, last login, number of logins.
4.3. Legal basis: performance of the contract concluded with the User (GTC) [Article 6(1)(b) GDPR]. With regard to the data of Gymnasts and Coaches invited or created by the Club/Coach, the Club/Coach is the controller and the Service Provider is the processor (Section 3.2); the legal basis of the Club/Coach is typically the membership or contractual relationship with the Gymnast (Legal Guardian) or with the Coach [Article 6(1)(b) or (f) GDPR]. Certain data (e.g. telephone number, personal introduction) are currently stored exclusively on the User’s own device and are not transmitted to the Service Provider.
4.4. Duration: for as long as the Profile is active. The Data Subject may request deletion of the Profile and of the related personal data at info@mybeamline.com (the Application does not offer a self-service deletion function). The Service Provider fulfils the request within one month at most: it deletes the data from the live system within 30 days of the request, and from backups when the backups concerned are replaced in the ordinary backup cycle. The Service Provider does not delete data automatically after a fixed period. Data that must be retained for longer under law (e.g. invoices, Section 10) are exempt from this.
4.5. Following registration, the User may receive a confirmation e-mail; an invited User receives the invitation by e-mail (Resend).
5. Training planning, training log, attendance, statistics and export
5.1. Purpose of the processing: planning, conducting, logging and evaluating training sessions; tracking attendance; preparing statistics and reports; estimating the difficulty value (D-score).
5.2. Categories of data processed:
- the names, descriptions and dates of seasons, weeks, training days, apparatus, elements, element connections and routines, and the Gymnast or group assigned to them;
- training log data: number of attempts, successful/unsuccessful execution, quality rating, repetitions and sets, the score of the routine, in the case of an unsuccessful attempt the failed element, the person making the entry and the time of the entry;
- routines stored in the routine library;
- attendance calculated on the basis of planned and logged training sessions;
- statistics calculated from the above (e.g. success rate, readiness, load).
5.3. Legal basis: with regard to the Solo Gymnast’s own data, performance of the contract [Article 6(1)(b) GDPR], where the Service Provider is the controller. With regard to the data recorded by the Club/Coach about Gymnasts, the Club/Coach is the controller and the Service Provider is the processor (Section 3.2). Within the Club, a Gymnast’s training data can be seen and modified only by the persons listed in Section 3.2; teammates cannot see them.
5.4. Export: Coaches and the Head Coach may export statistics and attendance in PDF and XLSX format. The exported file leaves the Service Provider’s system; the exporting User or the Club, as applicable, is responsible for its retention, confidentiality and onward transmission. If the export contains Health Data (Section 6.5), the Application displays a warning to this effect before the export.
5.5. Duration: for as long as the Profile or the Club is active (deletion on request, as set out in Section 4.4), or until the User (Club/Coach) deletes the entry concerned. The limitations of the Free Plan (e.g. the time window of log history or statistics) do not delete the data; they only restrict their display.
5.6. The Service Provider does not process in the Beamline Application the body measurement data included in the previous notice (body weight, height, arm span, leg length), nor sex. The Service Provider processes the Gymnast’s date of birth solely for the purpose of applying the age rules (Sections 4.2 and 12).
6. Health Data: pain and injury log, sleep log, wearable device
6.1. Pain and injury log
Purpose: to enable the Gymnast (Solo Gymnast) and – with the Gymnast’s consent – their Coaches to monitor pain and injuries as they arise and develop, and to adjust the training load accordingly, reducing the risk of overload and injury.
Categories of data processed:
- the body part concerned (the area selected on the body map, the side, and whether a joint or a muscle is concerned, e.g. “left knee – joint”);
- the intensity of pain on a scale of 1–10;
- status (active / resolved), and the answer given to follow-up questions (“still present”, “getting worse”, “improving”, “healed”), which overwrites the previous value;
- free-text comment;
- the date of the entry (training week, day), the person making the entry (Gymnast or Coach), and the time of recording and modification.
Users should not enter in the free-text comment any health information not necessary for the training work (e.g. diagnosis, treatment, medication), or any data relating to another person.
6.2. Sleep log
Purpose: to take into account sleep quantity and quality, as an indicator of recovery, in training planning. Data processed: daily sleep duration (hours), sleep quality on a scale of 1–5, the person making the entry and the time of the entry; the short-sleep threshold set in the Profile.
6.3. Connecting a wearable device (WHOOP)
Purpose: to display the recovery, sleep and strain data measured by the Gymnast’s (Solo Gymnast’s) own WHOOP device to the Gymnast and – if the Gymnast separately authorises this – to their Coaches.
Data processed (daily values imported from WHOOP): recovery score (%), heart rate variability (HRV, ms), resting heart rate, sleep performance (%), total and required sleep time, sleep stages (light, REM, deep, awake), daily strain, blood oxygen level (SpO2 %), respiratory rate; as well as the access and refresh tokens necessary to maintain the connection, and the status and time of synchronisation. The Service Provider requests only read permission from WHOOP (cycles, recovery, sleep), and synchronises the data approximately every hour while the connection is active.
Visibility: by default, visible only to the Gymnast. The staff who have access to the Gymnast’s data under Section 3.2 (the Head Coach and the staff in the Gymnast’s reporting line or, where the Gymnast is not assigned, the Club’s Coaches) can see the data only if the Gymnast turns on the “Share WHOOP data with my coaches” setting in their Profile; this can be turned off at any time. The connection can be terminated at any time in the Application or in the WHOOP account; in that case, the Service Provider deletes the tokens and does not receive any new data.
6.4. Load monitoring
The Application calculates a load indicator from the training log (number of attempts, difficulty of elements) and displays it – where available – together with pain entries and sleep data, warning, for example, of a sudden increase in load or of short sleep. This calculation does not create a stored profile; it is produced only at the time of display.
6.5. Common rules applicable to Health Data
Legal basis. The legal basis for the processing of Health Data is the explicit consent of the Data Subject [Article 6(1)(a) GDPR and Article 9(2)(a) GDPR]. The Application requests consent before the first use of the function concerned, separately, by means of an unticked checkbox kept apart from other declarations, and records the time and content of the consent. In the case of a Gymnast under the age of 16, consent is given by the Legal Guardian through the e-mail confirmation described in Section 12: the Legal Guardian’s approval – of which the confirmation e-mail expressly informs them – also constitutes consent to the processing of Health Data; no Coach may record consent on behalf of a Gymnast under 16. A Gymnast aged 16 or over who has their own Profile gives consent personally. For a Gymnast aged 16 or over who has a profile without login (managed by a Coach), the Coach records the consent in the Application, confirming at the same time that it has been obtained from the Gymnast. In the case of logs kept within a Club, the Club as controller also relies on this consent; in the absence of consent, no Health Data may be recorded about the Gymnast – not even by the Coach.
Voluntary nature. Giving consent is voluntary; refusing or withdrawing it entails no detriment, and all other functions of the Application remain fully available regardless.
Withdrawal. Consent may be withdrawn at any time in the Profile settings or at info@mybeamline.com. Following withdrawal, no new Health Data may be recorded; at the Data Subject’s request, the Service Provider (in the case of a Club, on the Club’s instructions) deletes the previously recorded entries without delay and in any event within 30 days. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Who can see it? Exclusively (a) the Gymnast or Solo Gymnast themselves; (b) in the case of a Gymnast under the age of 16, their Legal Guardian (by means of an access request under Section 18); (c) the Head Coach of the Gymnast’s Club, the staff above the Gymnast in their reporting line (e.g. Assistant Coach → Coach → Head Coach) and, while the Gymnast is not assigned to anyone, the Club’s Coaches (but not Assistant Coaches), unless the Gymnast has turned off the “Share with my coaches” setting in their Profile; while it is off, these staff members can neither see nor record the Gymnast’s pain, injury and sleep entries. Other Gymnasts, teammates, staff outside the reporting line and other members of the Club cannot see it. WHOOP data are also subject to the separate sharing setting referred to in Section 6.3. The Service Provider’s staff and the administration interface do not have access to Health Data in the course of normal operation; such access may take place only at the explicit request of the Data Subject (troubleshooting) or in order to comply with a legal obligation, and is logged.
Export and onward transmission. Statistics containing Health Data (sleep, load and pain, recovery) may be exported in PDF/XLSX format only by an authorised Coach or by the Gymnast themselves. The Coach may use the export solely for the purpose of the Gymnast’s training and the protection of the Gymnast’s health, and may not disclose it to third parties (e.g. another club, the press); an exception applies where it is disclosed to a doctor or physiotherapist in order to protect the Gymnast’s health, with the knowledge of the Gymnast (Legal Guardian). The Service Provider does not disclose Health Data to third parties, does not use it for advertising purposes and does not sell it.
Not a medical service; no automated decision-making. The Application is not a medical device, does not make diagnoses and does not provide medical advice. Load warnings are for information purposes only; the Application does not take any decision based solely on automated processing which produces legal effects or similarly significantly affects the Data Subject within the meaning of Article 22 GDPR (e.g. regarding entry into a competition or exclusion from a squad). Such decisions are taken by the Coach, who is responsible for them.
Retention. The Service Provider processes Health Data for as long as the Gymnast’s Profile is active, or until consent is withdrawn or the entry concerned is deleted; deletion takes place on request, as set out in Section 4.4. If the Gymnast leaves the Club, the former Club’s staff no longer have access to the Health Data recorded within the Club; the Service Provider deletes such data on request or when the Gymnast’s Profile is closed.
Security. The Service Provider transmits Health Data over an encrypted connection, stores it in encrypted form, and ensures by means of database-level access control (row-level security) that only the persons listed above have access to it.
7. Video recordings and comments
7.1. Purpose: to increase the effectiveness of training work by enabling video recordings to be made of the elements and routines performed by the Gymnast for subsequent evaluation and analysis, to which authorised persons may add comments.
7.2. Data processed: the image and movement of the Gymnast in the recording, the metadata of the recording (uploader, time, length, related element or routine), the text, author and time of comments, and the shares (with whom the recording has been shared).
7.3. Legal basis: in the case of the Solo Gymnast’s own recordings, performance of the contract and the Solo Gymnast’s consent [Article 6(1)(a) and (b) GDPR]. In the case of a recording made by a Club/Coach, the Club/Coach is the controller; a recording may only be made and uploaded with the consent of the Gymnast (under the age of 16, of the Legal Guardian), and the uploading Coach/Club is responsible for obtaining such consent.
7.4. Access: videos are accessible only to logged-in, authorised Users, via a signed, expiring playback link: the Gymnast, the staff who have access to the Gymnast’s data under Section 3.2 (the Head Coach and the staff in the Gymnast’s reporting line or, where the Gymnast is not assigned, the Club’s Coaches), and those with whom the video has been expressly shared. A video of a Gymnast may be shared only with a person in that Gymnast’s reporting line; teammates cannot see it. Team videos not linked to any individual Gymnast can be seen by the members of the Club.
7.5. The uploader declares that they made the video (or that it was made by another person with their consent), that they are entitled to dispose of the rights in it without restriction, and that, if another person is visible in the recording, they have obtained that person’s consent. The Service Provider reserves the right to remove, upon notification or on its own initiative, recordings and comments that violate the law, the GTC, the Ethical Rules or public morals (in particular those that infringe personality rights, or are indecent or obscene). Users may delete their own comments; they may report another person’s comment to the Service Provider.
7.6. Duration: until the video is deleted by the uploader, or for as long as the Profile is active (deletion on request, as set out in Section 4.4). A shared video remains accessible to the recipient of the share until the share is revoked.
8. Competition results
8.1. Recording own competition results and uploading PDFs. Users (including Gymnasts) may record their own competition results and upload official competition result lists in PDF format. Data processed: name, venue and date of the competition; the competitors’ names, nationality (country code), start number, club, scores (D, E, deductions, final score) and ranking; the identity of the uploader. The Application assigns the result to the Gymnast appearing on the Club’s roster. Legal basis: with regard to the own data of the Solo Gymnast and of the uploader, performance of the contract [Article 6(1)(b) GDPR]; with regard to the data of other competitors appearing in the list, the Service Provider’s legitimate interest [Article 6(1)(f) GDPR] in processing publicly published sports results.
8.2. Text extraction using artificial intelligence. The Service Provider transmits the content of the uploaded PDF to the language model of Anthropic (Section 1), which converts the tabular results into text data. The Service Provider displays the result to the uploader for approval. AI processing may contain errors; the uploader is therefore required to check the data. The Service Provider stores the processed result within the uploader’s organisation; it becomes available to other Users only if a member of the Service Provider’s staff considers it to be a public, official result list and approves it for global visibility.
8.3. Shared competition results database. The Service Provider maintains a database of official results publicly published at international competitions (competitors’ names, nationality, scores, ranking), which can be searched and analysed by all logged-in Users. The source of the data is the result lists publicly published by competition organisers and federations. Legal basis: the legitimate interest of the Service Provider and of Users in analysing sports results [Article 6(1)(f) GDPR]; the Service Provider has carried out a legitimate interest assessment (balancing test), which is available on request. Duration: for as long as the result originates from a publicly available source, or until the Data Subject successfully objects.
8.4. Persons appearing in competition results – who are not necessarily Users – receive the information required by Article 14 GDPR through this Section; they may exercise their rights under Section 18, including in particular their right to object, at info@mybeamline.com.
9. Community element names
Users may suggest nicknames and abbreviations for elements. Where a suggestion is included in the shared name directory, the name of the suggesting User may also be displayed to other Users. Legal basis: performance of the contract [Article 6(1)(b) GDPR]. Duration: until the suggestion is deleted or the Profile is deleted (thereafter the suggestion may be retained without the name).
10. Subscription, payment and invoicing
10.1. Subscription and plan management: the Service Provider processes the plan associated with the Subscribing User’s Profile, its period, the billing e-mail address, the Stripe customer identifier, the status of the subscription and invoices, and – at the User’s request – any enquiry about changing plan and any comment attached to it. Legal basis: performance of the contract [Article 6(1)(b) GDPR]. Duration: 5 years from the termination of the subscription (civil-law limitation period).
10.2. Payment: the User provides card data directly to Stripe; the Service Provider receives notification only of the fact, amount and outcome of the transaction. Legal basis: performance of the contract [Article 6(1)(b) GDPR].
10.3. Invoicing: name, billing address, tax number (if any), e-mail address, description and amount of the service. Legal basis: compliance with a legal obligation [Article 6(1)(c) GDPR; Sections 159 and 169 of the VAT Act]. Duration: 8 years pursuant to Section 169(2) of Act C of 2000 on Accounting.
11. System messages and newsletter
11.1. System messages: the Application sends notifications related to its operation (invitations, coach contact requests, consent requests sent to Legal Guardians, important changes) by e-mail, and other notifications within the Application. In-app notifications can be turned off by type in the Profile. Legal basis: performance of the contract [Article 6(1)(b) GDPR].
11.2. Newsletter: the Service Provider sends newsletters containing advertising or professional information only where separate consent has been given for this purpose. Data processed: name, e-mail address, time of subscription. Legal basis: the Data Subject’s consent [Article 6(1)(a) GDPR; Section 6 of Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities]. Consent may be withdrawn at any time, including via the link at the bottom of the newsletter. Duration: until unsubscription.
12. Provisions concerning minors
12.1. Age check. The Profile of a Gymnast or Solo Gymnast under the age of 16 may be used in full only with the consent of the Legal Guardian [Article 8(1) GDPR]. The Application therefore asks for the Gymnast’s date of birth: at registration, and when a Coach or Club invites the Gymnast or creates a profile without login for them. If the Gymnast is under 16, the Legal Guardian’s e-mail address must be provided; their name is optional.
12.2. Consent by e-mail. The Service Provider sends an e-mail to the Legal Guardian’s address containing a unique confirmation link valid for 14 days, through which the Legal Guardian may approve or decline the request without logging in. A new e-mail may be requested in place of an expired link. Until approval, the Application pauses, for the Gymnast concerned, the uploading of videos and the recording of Health Data (pain, injury and sleep entries, WHOOP data), including the creation of a new WHOOP connection; training plans and the training log remain available in the meantime. The Legal Guardian’s approval – of which the e-mail expressly informs them – also constitutes consent to the processing of Health Data (Section 6.5). For a Gymnast under 16, whether with their own Profile or without login, the Legal Guardian’s consent cannot be replaced by a declaration of a Coach, Assistant Coach or Head Coach.
12.3. A minor under the age of 14 is represented by the Legal Guardian; a minor between the ages of 14 and 18 may conclude a contract subject to a fee with the consent of the Legal Guardian. Only a person of legal age may be a Subscribing User, Head Coach, Coach or Assistant Coach; the Head Coach, Coach and Assistant Coach confirm this by an express declaration at registration or when accepting the invitation, and the Service Provider records the time of that declaration. Where a Gymnast is invited by a Club or Coach, or their profile is created by a Club or Coach, the Club/Coach is required to provide in the Application the Gymnast’s true date of birth and – for a Gymnast under 16 – the Legal Guardian’s true e-mail address.
12.4. Data processed: the Gymnast’s date of birth; the Legal Guardian’s e-mail address and, if provided, name; the User who initiated the request; the time of the request and of the decision, the status of the request (pending, approved, declined, revoked, expired), the expiry time of the link and the version of the declaration accepted; for the purpose of demonstrating the consent, the IP address and browser identification data (user agent) used when the decision was made. The Service Provider stores the confirmation link only in irreversible (hashed) form. For a Head Coach, Coach or Assistant Coach, the time of the declaration of legal age. Purpose: to ensure and demonstrate that the Legal Guardian decides on the minor’s personal data, and that coaching roles are held by adults. Legal basis: compliance with a legal obligation [Article 6(1)(c) GDPR, Article 7(1) GDPR and Article 8(2) GDPR]. Duration: for as long as the minor’s Profile exists, or for 5 years following withdrawal of consent (in order to be able to demonstrate the consent).
12.5. The Legal Guardian may exercise the rights set out in Section 18 on behalf of the minor and may withdraw their consent at any time at info@mybeamline.com. The staff in the Gymnast’s reporting line may also revoke the consent in the Application; upon revocation, the consent to the processing of Health Data given by the Legal Guardian also ends, and the restrictions set out in Section 12.2 apply again. Upon reaching the age of majority (with regard to Health Data, upon reaching the age of 16), the minor may make declarations on their own behalf.
13. Complaint handling and customer service
13.1. Purpose: investigating and responding to complaints and questions relating to the service or the Application, and handling notifications concerning unlawful content.
13.2. Data processed: the Data Subject’s name, contact details (e-mail address, postal address), the content of the complaint or notification and the personal data disclosed therein, attached documents, and the response.
13.3. Legal basis: in the case of a consumer complaint, compliance with a legal obligation [Article 6(1)(c) GDPR; Section 17/A of the Consumer Protection Act]; in the case of other enquiries, the Service Provider’s legitimate interest [Article 6(1)(f) GDPR].
13.4. Duration: in the case of a consumer complaint and the response thereto, 3 years [Section 17/A(7) of the Consumer Protection Act]; in the case of other enquiries, 1 year following the closure of the matter.
14. Security and usage logs, cookies and local storage
14.1. Usage and security logs: the Service Provider records the time of the first and last activity of Profiles, the number of logins, and which screens of the Application the User opened and when; administrator operations are recorded in a separate log. Purpose: security of the service, detection of misuse, troubleshooting and development of the Application. Legal basis: the Service Provider’s legitimate interest [Article 6(1)(f) GDPR]. Duration: for as long as the Profile exists for screen-view data and other logs, and 5 years for the administrator log. The Service Provider does not use any third-party analytics or advertising service (e.g. Google Analytics, Facebook Pixel).
14.2. Cookies and local storage: the Application stores in the browser’s local storage (localStorage, sessionStorage) only data that are strictly necessary for its operation or that serve to retain settings requested by the User; consent is therefore not required for them [Section 13/A of the E-Commerce Act; Article 5(3) of the ePrivacy Directive]:
| Stored item | Function | Lifetime |
|---|---|---|
| sb-…-auth-token | Login session (Supabase) | until logout |
| theme (light/dark) | Display setting | until deleted |
| language | Selected language | until deleted |
| sleep and readiness settings | Local copy of the thresholds set in the Profile | until deleted |
| demo flag | Display of demo data | until deleted |
| reload flag (sessionStorage) | Error-free loading after refresh | until the browser tab is closed |
Locally stored data can be deleted at any time in the browser settings; in that case the Application logs the User out and their settings are reset to default values.
15. Transfers of data outside the European Economic Area
Certain processors identified in Section 1 are established in the United States or in Singapore. In these cases, the Service Provider ensures the lawfulness of the transfer by means of the standard contractual clauses adopted by European Commission Implementing Decision (EU) 2021/914 or – in the case of a certified U.S. partner – by the adequacy decision on the EU–U.S. Data Privacy Framework. A copy of the safeguards applied may be requested at info@mybeamline.com. The Service Provider’s primary database is located in the European Union.
16. Data security
16.1. The Service Provider ensures the security of personal data by means of technical and organisational measures appropriate to the risks in accordance with Article 32 GDPR, including in particular: encrypted (HTTPS/TLS) data transmission; encrypted storage of data; irreversible (hashed) storage of passwords; role-based, Club-based and reporting-line-based access control at database level; playback of videos via signed, expiring links; restriction and logging of administrator access; regular backups.
16.2. The Service Provider’s employees and processors are bound by confidentiality obligations. In the event of a personal data breach, the Service Provider acts in accordance with Articles 33–34 GDPR and – where the breach is likely to result in a high risk to the rights of Data Subjects (e.g. where it concerns Health Data) – informs the Data Subjects without undue delay.
16.3. In view of the processing of Health Data and of minors’ data, the Service Provider carries out a data protection impact assessment (Article 35 GDPR) and reviews it whenever the functions change.
17. Retention periods – summary
| Data category | Retention period |
|---|---|
| Profile, registration data | for as long as the Profile is active; upon a deletion request, from the live system within 30 days, from backups when they are replaced |
| Training plans, log, statistics, videos | for as long as the Profile or the Club is active, or until the entry is deleted; thereafter deletion on request |
| Health Data (pain, injury, sleep, WHOOP) | for as long as the Profile is active, or until consent is withdrawn or the entry is deleted; upon leaving the Club, the former Club’s staff lose access, deletion on request or when the Profile is closed |
| WHOOP access tokens | until the connection is terminated |
| Competition results (shared database) | for as long as it originates from a public source, or until a successful objection |
| Subscription data | 5 years from the termination of the subscription |
| Invoices | 8 years |
| Legal Guardian consent and proof of consent (e-mail address, name, times, IP address, user agent) | for as long as the Profile exists, or 5 years from withdrawal |
| Newsletter | until unsubscription |
| Consumer complaint | 3 years |
| Screen-view log | for as long as the Profile exists |
| Administrator log | 5 years |
18. Rights of Data Subjects and how to exercise them
18.1. Access: the Data Subject may request information about, and a copy of, the personal data processed about them, and information on the purpose, legal basis and duration of the processing, the recipients and the processors.
18.2. Rectification: the Data Subject may request rectification of inaccurate data; the User may also modify data that can be modified in the Profile themselves.
18.3. Erasure: the Data Subject may request erasure of their data where the data are no longer necessary; where they withdraw their consent and there is no other legal basis; where they have successfully objected; where the processing is unlawful; or where erasure is required by law. Deletion of the Profile and of the data may be requested at info@mybeamline.com (the Application does not offer a self-service deletion function); the Service Provider fulfils the request within one month (Section 4.4).
18.4. Restriction: the Data Subject may request restriction of processing for the period during which the accuracy of the data is contested, where the processing is unlawful, where the data are needed for a legal claim, or pending the assessment of an objection.
18.5. Data portability: in the case of automated processing based on consent or on a contract, the Data Subject may request that their data be provided in a structured, commonly used and machine-readable format (CSV, JSON or XLSX) or transmitted to another controller. The Service Provider prepares and provides the copy of the data within one month of a request sent to info@mybeamline.com; the Application does not offer a self-service export of the full data content.
18.6. Objection: the Data Subject may object, on grounds relating to their particular situation, to processing based on legitimate interest (e.g. Sections 8.3 and 14.1). The Service Provider will no longer process the data unless this is justified by compelling legitimate grounds or by a legal claim. Where the Data Subject objects to direct marketing, the processing ceases.
18.7. Withdrawal of consent: in the case of processing based on consent (Health Data, newsletter, video), consent may be withdrawn at any time without giving reasons; this does not affect the lawfulness of processing carried out before the withdrawal.
18.8. Club-related data: where the request concerns data of which the Club/Coach is the controller (Section 3.2), the Service Provider forwards the request to the Club/Coach without delay and assists in fulfilling it; the Service Provider also fulfils requests for the deletion of Health Data and for the withdrawal of consent directly.
18.9. Rules for exercising rights: rights may be exercised at the e-mail or postal address specified in Section 1. Exercising rights is free of charge. The Service Provider fulfils the request within one month at most (which may be extended by a further two months where justified, of which the Data Subject will be informed) or rejects it, giving reasons and indicating the available remedies. Where there are reasonable doubts concerning the identity of the Data Subject, the Service Provider may request additional information.
19. Remedies
19.1. Investigation by the Service Provider: the Service Provider asks the Data Subject, before turning to the authority or to a court, to notify the Service Provider of the problem, which the Service Provider will investigate within one month.
19.2. Supervisory authority: the Data Subject may lodge a complaint with the data protection authority of the EU Member State of their habitual residence, place of work or place of the alleged infringement; in Hungary, with the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság) (1055 Budapest, Falk Miksa utca 9–11.; postal address: 1363 Budapest, Pf. 9.; www.naih.hu; ugyfelszolgalat@naih.hu).
19.3. Court: in the event of an infringement of their rights, the Data Subject may bring an action before a court; at the Data Subject’s choice, the action may also be brought before the regional court (törvényszék) having jurisdiction over their place of residence or place of stay. The Data Subject may claim compensation for damage caused by unlawful processing, as well as restitution for non-pecuniary damage (sérelemdíj).
20. Amendments to the Notice
The Service Provider amends this Notice in the event of changes in the processing operations. The Service Provider informs Data Subjects of amendments on the Website (mybeamline.com/privacy) and in the Application and, in the case of a material change (e.g. a new processing purpose, a new category of Health Data), also by e-mail before the amendment takes effect. Where the change requires new consent, the Service Provider requests it separately.