Skip to content

Privacy Policy

1. General Information

The protection of your personal data is important to us. We process your data exclusively in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR).

This Privacy Policy explains which personal data is processed when using our training platform, for what purposes, and what rights you have.

2. Controller

The controller within the meaning of the GDPR is:

Ralph Gorges
Vorderer Berg 12
95100 Selb
Germany
mail@maxshape.de

3. Purposes of Processing

Personal data is processed for the following purposes:

  • Creation of individualized training and nutrition plans
  • Adjustment of plans based on feedback and progress
  • Performance and workload analysis
  • Optimization of training management
  • Communication related to coaching
  • Technical provision and improvement of the platform

The platform does not replace medical advice or treatment.

4. Categories of Data Processed

Depending on usage, we may process the following categories of personal data:

Profile Data

  • Age
  • Height
  • Body weight

Training-Related Data

  • Training goals
  • Training level / experience
  • Training frequency
  • Available time
  • Equipment
  • Training history
  • Subjective workload feedback
  • Individual strengths and weaknesses

Depending on context and analysis, this data may allow conclusions about physical condition or performance capacity and may therefore qualify as health data within the meaning of Art. 4 No. 15 GDPR.

We do not actively request medical diagnoses or clinical records.

5. Legal Basis

Processing is based on:

  • Art. 6(1)(b) GDPR (performance of a contract)
  • Art. 6(1)(a) GDPR (consent)
  • Art. 9(2)(a) GDPR (explicit consent for potential health data)

Where data qualifies as health data, processing takes place solely on the basis of explicit consent provided during onboarding.

Consent can be withdrawn at any time with future effect.

6. Use of AI Systems

We use AI-supported systems to generate and adapt training and nutrition plans.

This involves:

  • Processing user-provided data for individualized training management
  • Evaluation of performance-related parameters
  • Personalized workload optimization

This may constitute profiling within the meaning of Art. 4 No. 4 GDPR.

No automated decision-making with legal or similarly significant effects pursuant to Art. 22 GDPR takes place.

7. Processing by OpenAI

To provide AI functionality, data may be processed by OpenAI.

  • A data processing agreement pursuant to Art. 28 GDPR is in place.
  • Processing occurs strictly on our instructions.
  • Data is not used to train general AI models.
  • No independent use of the data by OpenAI takes place.

8. Data Transfers

Personal data is not transferred to third parties unless required for contractual performance.

If processing occurs outside the European Union, appropriate safeguards under Art. 44 et seq. GDPR (e.g., Standard Contractual Clauses) are applied.

9. Retention Period

Personal data is stored only as long as necessary for the stated purposes or as required by statutory retention obligations. Afterwards, data is deleted or anonymized.

10. Your Rights

You have the right to:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Withdraw consent at any time (Art. 7(3) GDPR)

You also have the right to lodge a complaint with a supervisory authority.

11. Data Security

We implement appropriate technical and organizational measures to protect personal data against loss, misuse, or unauthorized access.

12. Changes to this Policy

We reserve the right to update this Privacy Policy to reflect legal or technical changes. The current version is always available within the app or on the website.