Privacy Policy
1. Who We Are
DigitAquos is operated by OARA TECH S.R.L., a company registered in Romania (CUI: 53927238), located in Cluj County, Romania. We provide a software platform for swimming club management, individual training, health monitoring, and performance tracking.
DigitAquos is available as a web application at app.digitaquos.com, and as native mobile applications on iOS (App Store) and Android (Google Play). The mobile apps wrap the web application in a native shell using Capacitor, providing access to device-level features including push notifications, Apple HealthKit, and Android Health Connect.
For any privacy-related inquiries, contact us at razvanoara@digitaquos.com.
2. Data We Collect
We collect different categories of data depending on how you use DigitAquos:
Account Data
Full name, email address, username, password (hashed), country, club name (for coaches), swimming level (for individual swimmers).
Swimmer Profile Data
Date of birth, gender, training group, attendance records, performance times, personal bests, goals, and training preferences. For club swimmers, this may also include home address and emergency/parent contact details where the club collects them as part of registration.
Health & Medical Data
Medical certificate status and expiry dates, height, weight, body metrics. For swimmers with connected wearables: heart rate, heart rate variability (HRV), resting heart rate, sleep data (stages, duration, score, SpO₂), stress levels, body battery, respiration rate, and swim activity metrics (SWOLF, stroke count, pace, laps, distance).
Wearable & Device Health Data
When swimmers connect a Garmin device, we receive physiological data through the Garmin Connect API via OAuth2 webhooks. This is a one-way data flow — we receive data from Garmin but do not send any personal data back to Garmin.
On iOS, the DigitAquos mobile app can read health data from Apple HealthKit with your explicit permission. This includes heart rate, workout sessions, sleep analysis, and other health metrics stored on your device. HealthKit data is read locally on your device and transmitted securely to our servers. We do not write data back to HealthKit.
On Android, the DigitAquos mobile app can read health data from Health Connect with your explicit permission. This includes heart rate, exercise sessions, sleep data, and other health metrics. Health Connect data is read locally on your device and transmitted securely to our servers. We do not write data back to Health Connect.
You can revoke HealthKit or Health Connect permissions at any time through your device's system settings. Revoking permissions stops future data syncing. Previously synced data can be deleted upon request.
Training Data
Workouts created or generated, training plans, session completions, performance metrics, and coach feedback. For AI-powered features, this includes data generated by AI services on your behalf (training plans, workout suggestions, session feedback).
Payment Data
When you subscribe to a paid plan, payment processing is handled by Stripe. We receive confirmation of payment status, subscription tier, and billing period. We do not store credit card numbers, CVVs, or full payment credentials on our servers. Invoices are generated through Oblio for Romanian e-invoicing compliance. For clubs that bill their own members through the platform, payments are processed via Stripe Connect, where the club is the merchant of record.
Media & Files
User-uploaded content such as profile photos, medical certificate scans, club gallery images, and club logos are stored on Cloudflare R2, a cloud object storage service. Files are served over HTTPS and are accessible only through authenticated platform requests.
Push Notification Data
The DigitAquos mobile app uses Firebase Cloud Messaging (FCM) to deliver push notifications. When you enable push notifications, a device token is stored on our servers to route notifications to your device. We do not use FCM for advertising or tracking. You can disable push notifications at any time through your device settings or within the app.
Guest Meet Registration Data
When a swimming club registers for a public swim meet hosted on DigitAquos without holding a full platform account (guest registration), we store the guest club's contact details (club name, contact name, email, phone) and the names, birth years, and genders of the swimmers it enters into the meet. This data is used solely to organize and run the meet and to allow the guest club to manage its own entries.
Usage & Analytics Data
We use our own first-party analytics to understand how our website and platform are used (for example, pages viewed, referring source, general country, and language). We do not use third-party analytics services such as Google Analytics, advertising cookies, tracking pixels, or data brokers. Visitor identifiers used for aggregate pageview statistics are pseudonymised using a daily-rotating salted hash, so individual visitors are not tracked across days. When you create an account, we record the signup event linked to your account for internal product analytics. We may also collect basic server logs (IP address, request timestamps) for security and debugging purposes.
3. How We Use Your Data
We use your data exclusively to provide and improve the DigitAquos platform:
- Providing club management, training planning, and health monitoring features
- Generating readiness scores, recovery insights, and performance analytics
- Powering AI features: generating personalized training plans, workouts, session feedback, and daily check-ins based on your profile, goals, and wearable health data
- Adjusting workout intensity and volume based on recovery, sleep quality, and readiness metrics
- Enabling communication between coaches and swimmers
- Managing registrations, medical compliance, and GDPR consent tracking
- Organizing and running swim meets, including guest registrations
- Processing payments and generating invoices
- Sending platform-related notifications via push notifications and in-app messaging (schedule changes, announcements, medical certificate reminders)
- Understanding aggregate usage of our website and platform to improve them
- Maintaining platform security and preventing abuse
We do not use your data for advertising, profiling, or any purpose unrelated to the swimming platform.
4. AI Data Processing
DigitAquos Pro includes AI-powered features that generate personalized training plans, workouts, session feedback, and coaching insights. To provide these features:
- Certain personal data is sent to Google (Gemini API) for processing. This includes: your swimming level, goals, training schedule, recent workout history, and wearable health metrics (readiness score, sleep quality, heart rate, recovery status).
- Data is transmitted securely over encrypted connections (HTTPS/TLS).
- Google processes the data solely to generate your requested content and does not store your data beyond the duration of the API request.
- Google does not use your data to train their AI models.
- No identifying information (full name, email, exact date of birth) is sent to the AI provider — only training and health context necessary for content generation.
- For individual swimmers (accounts not managed by a club), training plans and workouts may be generated automatically by a combination of algorithmic logic and AI, without a coach reviewing the output beforehand. This automated generation produces suggestions only; it does not constitute medical, coaching, or professional advice, and you remain responsible for how you use it. Where a coach is involved (club swimmers), the coach reviews and is responsible for training assigned to swimmers.
- You can opt out of AI features at any time by not using them or by downgrading to the Basic plan. No data will be sent to AI services unless you actively use an AI-powered feature.
For more information on Google's data practices, see Google's Privacy Policy.
5. Legal Basis for Processing (GDPR)
- Contract performance — Processing necessary to provide you with the DigitAquos platform and its features, including AI-powered features included in your subscription.
- Consent — For health and medical data processing, wearable device connection, HealthKit and Health Connect data access, AI data processing via third-party services, push notification delivery, and for minors' data (parental consent required for users under 16).
- Legitimate interest — Platform security, preventing fraud, service improvements, aggregate website/platform analytics, and outreach to prospective club customers (see Section 8).
- Legal obligation — Generating invoices and maintaining financial records as required by Romanian law.
6. Children's Data
DigitAquos serves swimming clubs and individual swimmers, and swimmers may be of any age, including young children. We take the protection of children's data seriously.
- Club swimmers: Registration is completed and managed by the swimmer's parent or legal guardian, or by the club/coach on their behalf, and the club is responsible for obtaining the necessary consent. Coaches who register minors are responsible for ensuring proper parental or guardian consent has been obtained.
- Individual swimmers (no club): When creating an individual account, the person completing registration must confirm, via a mandatory checkbox, that they are either 16 years of age or older, or the parent/legal guardian of the swimmer and consent to the processing of the swimmer's data (including health data) as described in this Privacy Policy. This confirmation is recorded together with the date and the applicable policy version. An individual account for a swimmer under 16 may not be created without this parental/guardian consent.
- Users under 16 require parental or guardian consent for all data processing, including health data, wearable integration, and HealthKit/Health Connect access.
- Medical and health data for minors receives the highest level of protection.
- AI-powered features for minor accounts require the same parental consent for third-party data processing.
- Parents or guardians may request access to, correction of, or deletion of their child's data at any time.
7. Data Sharing
We do not sell, rent, or share your personal data for advertising or marketing purposes.
We share limited data with the following third-party services, solely to provide platform functionality:
- Garmin Connect API — One-way inbound integration. We receive wearable data from Garmin when a swimmer authorizes the connection. We do not transmit personal data to Garmin.
- Apple HealthKit — Device-side integration on iOS. Health data is read locally from the user's device with explicit permission and transmitted to our servers. No data is written back to HealthKit or shared with Apple.
- Android Health Connect — Device-side integration on Android. Health data is read locally from the user's device with explicit permission and transmitted to our servers. No data is written back to Health Connect or shared with Google via Health Connect.
- Google (Gemini API) — Training and health context is sent to generate AI-powered content (training plans, workouts, feedback). No identifying information (full name, email, exact date of birth) is shared. Data is not stored by Google beyond the API request.
- Firebase Cloud Messaging — Device tokens are used to deliver push notifications. No personal data beyond the device token and notification content is shared with Firebase. Firebase is operated by Google and governed by Google's privacy policies.
- Google reCAPTCHA — Used to protect our forms (such as registration and contact forms) from automated abuse. When a protected form loads, Google receives the visitor's IP address and browser signals. Operated by Google under its own privacy policy.
- Google Fonts — Used to serve typography on our website. When a page loads, Google receives the visitor's IP address as part of the font request. Operated by Google under its own privacy policy.
- Google Maps — Used to display maps on public swim meet pages. When a map loads, Google receives the visitor's IP address and related request data. Operated by Google under its own privacy policy.
- Cloudflare R2 — User-uploaded media files (profile photos, medical certificates, gallery images) are stored on Cloudflare R2. Files are encrypted in transit and accessible only through authenticated requests.
- Stripe — Payment information is processed by Stripe for subscription management, and via Stripe Connect for clubs that bill their own members (where the club is the merchant of record). Stripe operates under its own privacy policy. We do not store credit card details.
- Oblio — Invoice data (name, email, subscription details) is sent to Oblio for Romanian e-invoicing compliance (e-Factura / ANAF).
- Hostinger — Our email (SMTP) provider. Recipient email addresses and the content of transactional emails (such as registration links, password resets, and notifications) are processed by Hostinger to deliver those emails.
No other third parties receive your data. We do not use analytics services, advertising networks, or data brokers.
8. Prospective Clubs and Outreach
Separately from the swimmers and coaches who use the platform, we maintain a record of swimming clubs we may contact about DigitAquos, including their name, contact details, address, and notes from any prior contact. Some of this information is collected without the club's direct involvement (for example, from publicly available sources or referrals).
Where this applies, our legal basis is our legitimate interest in offering our services to relevant clubs. If you are a club representative and we hold your contact details for this purpose, you have the right to object to this processing at any time by emailing razvanoara@digitaquos.com, and we will stop and delete your details on request.
9. Data Storage & Security
- All data is stored on Hetzner Cloud servers in Germany (European Union).
- Media files are stored on Cloudflare R2 with encryption in transit.
- Data is encrypted in transit (TLS/SSL — Grade A+ certified). Access to production infrastructure is restricted to authorized personnel only.
- Passwords are securely hashed — we cannot see or recover your password.
- The platform has passed OWASP security testing.
- AI API communications use encrypted connections. No personal data is stored by AI providers beyond request processing.
- Mobile apps communicate with our servers exclusively over HTTPS. No data is stored locally on the device beyond session tokens and push notification tokens.
10. Data Retention
We retain your data for as long as your account is active. If you delete your account:
- Your personal data will be permanently deleted within 30 days.
- Anonymized, aggregated data (e.g., club statistics with no personal identifiers) may be retained.
- Data required by law (e.g., financial records, invoices) may be retained for the legally required period (typically 10 years for financial records in Romania).
- AI-generated content (plans, workouts) associated with your account will be deleted with your account.
- Media files stored on Cloudflare R2 will be permanently deleted with your account.
- Push notification device tokens are deleted immediately upon account deletion.
11. Your Rights (GDPR)
As a user in the European Union, you have the following rights:
- Access — Request a copy of your personal data.
- Rectification — Correct inaccurate or incomplete data.
- Erasure — Request deletion of your data ("right to be forgotten").
- Restriction — Limit how we process your data.
- Portability — Receive your data in a structured, machine-readable format.
- Objection — Object to data processing based on legitimate interest (including our analytics and prospective-club outreach).
- Withdraw consent — Revoke consent at any time (e.g., disconnect wearable, revoke HealthKit/Health Connect permissions, revoke medical data consent, stop using AI features, disable push notifications).
- Object to AI processing — You have the right to opt out of AI-powered data processing at any time by not using AI features or by contacting us.
To exercise any of these rights, email us at razvanoara@digitaquos.com. We will respond within 30 days.
You also have the right to file a complaint with the Romanian data protection authority (ANSPDCP — www.dataprotection.ro).
12. Cookies
DigitAquos uses only essential cookies required for authentication, session management, and remembering your language preference. We do not use advertising cookies or tracking pixels. Our first-party usage analytics do not rely on cookies. Some third-party services we load (such as Google reCAPTCHA, Google Fonts, and Google Maps) may set their own cookies or receive your IP address when their content loads; see Section 7. The mobile apps do not use cookies — authentication is handled via secure tokens stored in device memory.
13. Mobile Applications
DigitAquos is available as a native mobile application on iOS and Android. The mobile apps provide the same functionality as the web application, with additional access to device-level features:
- Push Notifications — Delivered via Firebase Cloud Messaging. You can enable or disable notifications in your device settings at any time.
- Apple HealthKit (iOS) — With your permission, the app reads health data (heart rate, workouts, sleep) from HealthKit. Data is transmitted securely to our servers. You can revoke access in iOS Settings → Privacy → Health at any time.
- Health Connect (Android) — With your permission, the app reads health data (heart rate, exercise, sleep) from Health Connect. Data is transmitted securely to our servers. You can revoke access in Android Settings → Health Connect at any time.
The mobile apps do not access your camera, contacts, location, microphone, or any other device sensors beyond those explicitly listed above. The mobile apps do not collect device identifiers for advertising purposes.
14. International Data Transfers
Your data is stored within the European Union (Germany). Some processing involves transfers outside the EU:
- When AI-powered features are used, non-identifying training and health context may be processed by Google (Gemini API), whose servers may be located outside the EU (United States).
- Firebase Cloud Messaging, and Google services such as reCAPTCHA, Fonts, and Maps, may process data (including your IP address) outside the EU.
- Cloudflare R2 may process data outside the EU.
These transfers are conducted under appropriate safeguards, including data minimization, encrypted transmission (TLS/HTTPS), and the transfer mechanisms maintained by these providers (such as Standard Contractual Clauses and/or applicable data protection framework certifications). No personal data is retained by the AI provider beyond request processing.
15. Changes to This Policy
We may update this Privacy Policy to reflect changes in our platform, third-party services, or legal requirements. Significant changes will be communicated through the platform and via push notifications where appropriate. The "Last updated" date at the top of this page will always reflect the most recent revision.
16. Contact
OARA TECH S.R.L.
Str. Luțerniștei Nr. 5, Municipiul Turda, Jud. Cluj, Romania
CUI: 53927238
Email: razvanoara@digitaquos.com