Privacy Policy
Kanda Performance
PRIVACY POLICY & DATA GOVERNANCE STATEMENT
This is the single, global privacy document governing your use of Kanda Performance. It covers how we collect, use, protect, share, transfer and delete personal information, your rights in every jurisdiction we operate in, our security posture, our cookie and tracking practices, our agreement for corporate data processing, and our accessibility commitments.
Effective: 16 April 2026  ·  Version 2.0  ·  Global  ·  Supersedes all prior versions
UK GDPREU GDPRCPRALGPDPIPEDAAPPIPIPLDPDPAPOPIAMHMDAWCAG 2.1 AAApple HealthKit
Table of Contents
  1. Part A, Privacy Policy
  2. 1. About KP & scope
  3. 2. Plain-language summary
  4. 3. Data we collect
  5. 4. Purposes & legal bases
  6. 5. Special category / health data
  7. 6. Sub-processors & sharing
  8. 7. International transfers
  9. 8. Retention & deletion
  10. 9. Security controls
  11. 10. Your rights
  12. 11. Children & minors
  13. 12. Automated processing & AI
  14. 13. Marketing & communications
  15. 14. Regional addenda
  16. 15. Breach notification
  17. 16. Changes
  18. 17. Contact
  19. Part B, Cookie & Tracking Policy
  20. Part C, Data Processing Addendum
  21. Part D, Security & Incident Response
  22. Part E, Accessibility Statement
  23. Part F, Sub-processor register
  24. Part G, Definitions
Part A
PRIVACY POLICY
The core notice explaining what data we collect, why, who we share it with and the rights you hold.
Section 01
About KP & Scope

This Privacy Policy (the "Policy") governs how Kanda Performance Ltd ("KP", "we", "us", "our") collects, uses, shares, stores, transfers, secures and deletes personal information when you install, access, register for, subscribe to or otherwise interact with the Kanda Performance mobile application, any related websites (including kandaperformance.com), associated features such as the AK Engine training programme generator, training session logger, nutrition logger, supplement stack tracker, check-in system, analysis dashboards, mesocycle planner, readiness calculator and any other product or service offered by KP (collectively the "Service" or "App").

Kanda Performance Ltd is the Data Controller for the purposes of the UK GDPR, the EU GDPR, the Swiss revFADP and equivalent concepts worldwide. Under the CCPA/CPRA we are a "business". Under the LGPD we are the "controlador". Under the PIPL we are the "personal information handler". Under the DPDPA we are the "data fiduciary". Under Japan's APPI we are a "personal information handling business operator".

Our registered office: 66 Paul Street, London, EC2A 4NA.
Company number: 17164938 (England & Wales).

This Policy applies globally. In the event of conflict between the main body of this Policy and a regional supplement in Section 14, the regional supplement prevails for residents of that region.

The Service processes health and fitness information. This is treated as "special category" personal data under Article 9 GDPR, "sensitive personal information" under the CPRA, "consumer health data" under the Washington My Health My Data Act, and "sensitive personal data" under the LGPD, PIPL, DPDPA, APPI and equivalent laws. Throughout this Policy we identify where heightened protections apply.
Section 02
Plain-Language Summary

Before the long version, here is the short version. This summary is for orientation only; the rights and obligations in this Policy are set out in Sections 3–17 below.

  • We collect the information you give us (account, training, nutrition, body, supplements, check-ins) plus the minimum device/diagnostic data required to make the App run.
  • We do not sell your personal data. We have never sold it. We have no plans to sell it.
  • We do not use your health data for advertising. Ever.
  • We use Apple, Google Cloud / AWS, Stripe, RevenueCat, Sentry, Cloudflare and a small number of other service providers to run the App. They are listed in Part F and bound by data processing agreements.
  • Your data is encrypted in transit (TLS 1.3) and at rest (AES-256). Health data is additionally encrypted with envelope encryption and per-user keys where feasible.
  • You can export your entire dataset as JSON at any time from the App.
  • You can delete your account and all associated data from inside the App. Deletion is irreversible after a 30-day grace period.
  • You have region-specific rights (access, correction, deletion, portability, restriction, objection, opt-out of sale, limit sensitive PI, appeal) which we honour everywhere in the world as a matter of policy.
  • Children under 16 cannot use KP. We age-gate.
  • If we have a data breach we will tell you and the regulator within the statutory timeframe (72 hours in the EU).
  • We use no behavioural advertising cookies. Analytics cookies fire only with consent.
Section 03
Data We Collect

The table below is a comprehensive register of data categories collected by the Service, tied specifically to KP's features. "Health data" marks categories treated as special-category / sensitive personal data.

CategoryExamplesSourceHealth?
Account identifiersName, username, email, password hash (bcrypt cost 12), user ID (UUID), profile photo, Sign in with Apple private-relay email alias, Google/Apple subject IDYou, Apple/Google OAuthNo
Training dataExercise name and group, sets, reps, weight, RPE, tempo, rest time, set type (warm-up / top set / AMRAP / failure / back-off / drop-set / tempo / cluster / feeder), session duration, session notes, estimated 1RM (E1RM) history, personal records, muscle-group volume distribution, adherence metrics, AK Engine programme outputs, mesocycle plans, deload trackingYouYes
Nutrition dataLogged foods, brand, quantity, calories, protein, carbs, fat, fibre, sugar, sodium, meal time, meal type, food quality score (FQS), protein distribution score (PDS), hydration, custom foodsYou, barcode scan, food databaseYes
Supplement dataStack composition, dose, timing, adherence, brand, cost trackingYouYes
Body & check-in dataBodyweight, waist/hip/arm measurements, sleep hours, sleep quality (1-10), muscle soreness (1-10), energy (1-10), mood, readiness, weekly/phase check-ins, menstrual-cycle phase (optional), progress photos you elect to uploadYouYes
Goals & programme dataGoal type (cut / bulk / recomp / maintain), target weight, training age, weak points, injuries you declare, active phase, KP Score, fatigue indexYouYes
Subscription & paymentSubscription tier, start/renewal date, trial status, platform (Apple/Google/Stripe), purchase receipts, transaction IDs. We do not receive or store your payment card details, Apple, Google or Stripe processes them.Apple, Google, Stripe, RevenueCatNo
Device & technicalDevice model, OS version, App version, language, time zone, crash logs (Sentry), approximate IP-derived region (country/region only, we do not store full IP long-term), advertising identifier (IDFA / AAID) only if you grant consent via Apple ATT or Android prompt, default is offDevice SDKsNo
Usage & diagnosticFeature interactions (which tabs/screens viewed), session duration, performance metrics, error events. First-party and anonymised. On by default to improve the app, with an opt-out in Settings. Global Privacy Control honoured.App telemetryNo
CommunicationsSupport tickets, email correspondence, in-app feedback, push-notification token, contact preferencesYou, deviceNo
HealthKit / Google Fit (optional, read-only)If you grant permission: steps, active energy, heart rate, heart-rate variability, sleep, workouts, weight, height. You control which categories.Apple HealthKit / Google FitYes
Biometric unlock (optional)Face ID / Touch ID / fingerprint gate for App access. The biometric template never leaves your device. We only receive a pass/fail result from the OS.DeviceNo (we do not hold biometrics)
Third-party sign-inIf you sign in with Apple or Google: identifier, verified email (optionally anonymised via Apple Private Relay), display nameApple, GoogleNo
What we do NOT collect
  • Precise GPS geolocation. We do not request location permission.
  • Your contacts, calendar, microphone, or photo library at large. Only the specific photos you elect to upload.
  • HealthKit / Google Fit data without your explicit in-app permission.
  • Biometric templates or face-prints. Any progress photos you upload are treated as user content and are not processed for identification.
  • Data from data brokers. We do not buy or enrich personal data.
  • Background audio, screen recordings, keyboard content or clipboard contents.
  • Social graph data.
Apple Privacy Manifest disclosures

In accordance with Apple's App Store policy our app bundles a PrivacyInfo.xcprivacy manifest. The categories we declare are: Contact Info (email); Health & Fitness (user-provided); Sensitive Info (health data); User Content (photos, notes); Identifiers (device ID, user ID); Usage Data (product interaction); Diagnostics. We declare data types "Linked to User" except diagnostics which may be "Not linked". We do not declare any data type under "Data used to track you".

Section 04
Purposes & Legal Bases

Under the UK/EU GDPR, LGPD, DPDPA and similar frameworks we must have a lawful basis for each processing purpose. This table is our register.

PurposeData usedGDPR Art. 6 basisArt. 9 (health)
Operating the App (accounts, logging, programmes, analytics)Service dataContract (6(1)(b))Explicit consent (9(2)(a))
AK Engine programme generation & auditGoal, training history, check-insContract (6(1)(b))Explicit consent (9(2)(a))
KP Score, Readiness, Fatigue Index computationCheck-ins, sessionsContract (6(1)(b))Explicit consent (9(2)(a))
Subscription billing and receipt verificationPurchase receiptsContract (6(1)(b))-
Fraud and chargeback preventionTransaction metadata, device signalsLegitimate interest (6(1)(f))-
Security, debugging, abuse detectionDevice, IP, crash logsLegitimate interest (6(1)(f))-
Service emails (password reset, receipts, breach notice)EmailContract (6(1)(b)) / legal obligation-
Optional marketing emailsEmail, preferencesConsent (6(1)(a)), opt-in, revocable-
Product analytics (first-party, opt-out)Usage eventsLegitimate interest (6(1)(f)), opt-out in Settings-
Legal, tax, audit, AMLTransaction recordsLegal obligation (6(1)(c))-
Defending legal claims / responding to legal processAccount records as neededLegitimate interest / legal obligationLegal claims (9(2)(f))
Aggregated, de-identified researchStrictly anonymised (k-anonymity & differential privacy)Legitimate interest (6(1)(f))Anonymisation + substantial public interest safeguards (9(2)(j))
We do not use your data for behavioural advertising, profiling for ad targeting, or training third-party generative-AI models. Any personalisation (AK Engine, KP Score) is performed on your data solely for your benefit, under the Contract basis.

Changes of purpose: If we propose to process your data for a new purpose incompatible with those listed above we will provide 30 days' advance notice and seek fresh consent where required.

Section 05
Special Category / Health Data

Fitness, nutrition, supplement, body-measurement, sleep, mood, soreness, menstrual-cycle and check-in data are treated as special category personal data under Article 9 GDPR. The same categories are classified elsewhere as follows:

  • "Sensitive personal information", CPRA (California);
  • "Consumer health data", Washington My Health My Data Act, Nevada SB 370, Connecticut's consumer-health-data provisions;
  • "Sensitive data", Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA, Iowa ICDPA, Indiana INCDPA, Delaware DPDPA, Tennessee TIPA, New Hampshire SB 255, New Jersey SB 332, Minnesota, Maryland MODPA, Rhode Island DTPPA, Kentucky CPA;
  • "Sensitive personal data", Brazil LGPD (Art. 11), China PIPL (Art. 28), Korea PIPA, Japan APPI "special care-required";
  • "Sensitive personal data", India DPDPA 2023 (implicitly through child and fiduciary rules);
  • Medical/health information under Canadian PHIPA and equivalent provincial rules.
Our heightened protections
  • Explicit opt-in consent obtained at onboarding before any health data is stored;
  • Separate granular consent per HealthKit / Google Fit category;
  • No third-party sharing for advertising. Sharing is limited to infrastructure sub-processors bound by DPAs;
  • DPIA (Data Protection Impact Assessment) completed prior to launch and updated for each material feature change; summary available on request;
  • Role-based access internally with least-privilege, 2FA and audit logging;
  • Envelope encryption for health-data payloads, per-user data-encryption keys where feasible;
  • Data minimisation: we collect only what is necessary for the declared feature;
  • Revocation: consent withdrawal in Settings → Privacy → Revoke Health Data Consent; corresponding data is deleted within 30 days;
  • No geofencing around healthcare facilities (compliance with Washington MHMDA);
  • No sale of consumer health data ever.
Apple HealthKit rules: Data obtained via HealthKit is never used for advertising, marketing, or data-mining purposes other than to improve health, medical, fitness or research. It is never sold or disclosed to third parties, including advertising platforms, data brokers, or information resellers. These commitments are an inherent condition of Apple's HealthKit terms and we adopt them regardless of user geography.
Google Fit rules: Where Fit REST or Android APIs are used we adhere to Google's User Data Policy and the Fit-specific policies, including the restriction against sale or advertising targeting.
Section 06
Sub-Processors & Sharing

Personal data is shared only with the categories of recipient listed below, each bound by a written Data Processing Agreement satisfying GDPR Art. 28, and where applicable the UK IDTA, EU SCCs, Swiss Addendum, Brazilian SCCs or CAC Standard Contract (see Section 7). A live register of sub-processors is maintained in Part F.

  • Apple Inc., App distribution, Sign in with Apple, push notifications, in-app purchases (US & Ireland).
  • Google LLC, Play Store distribution, Firebase Auth and Push (Android only) (US).
  • Amazon Web Services / Google Cloud Platform, hosting, encrypted storage, backups. EU data is pinned to EU-West (Dublin / Frankfurt). Backups remain in-region.
  • Stripe Payments Europe Ltd, card processing for web/desktop purchases outside the Apple/Google stores (Ireland / US).
  • RevenueCat Inc., subscription receipt validation and lifecycle orchestration (US).
  • Sentry, crash and error diagnostics (EU region selected).
  • Postmark / SendGrid (Twilio), transactional email.
  • Cloudflare Inc., CDN, TLS termination, DDoS protection (ephemeral edge processing).
  • Zendesk (or equivalent), support ticketing. Health data is excluded from support ticket contents by policy.
  • Plausible / PostHog (EU-hosted), privacy-respecting product analytics (subject to CMP consent). Neither uses cookies on iOS.

We give 30 days' advance notice of a new sub-processor via in-app notice and the public register, and permit reasoned objection for material risks. On objection we will either provide an alternative or give you a pro-rata subscription refund and a data export.

We do not sell personal data within the meaning of the CCPA/CPRA, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA, Iowa ICDPA, Indiana INCDPA, Delaware DPDPA, or any other law. We do not "share" personal data for cross-context behavioural advertising. We have not sold or shared personal data in the preceding 12 months.

Legal disclosure: We may disclose data where required by a valid, binding legal process (court order, properly-issued subpoena, warrant, official request from a supervisory authority), where necessary to protect the vital interests of any person, to prevent fraud, to enforce our Terms, or to defend our legal rights. We reject overbroad or unlawful requests, require specificity, and, where legally permitted, will notify you of demands affecting your data before responding. We publish an annual Transparency Report of the aggregate number of government requests received.

Business transfers: In the event of a merger, acquisition or asset sale, data may be transferred to the successor entity. You will be notified by email and in-app banner and given the opportunity to delete your account and export your data before the transfer takes effect.

Section 07
International Transfers

KP is a global service. Cross-border transfers of personal data are carried out with the following safeguards:

  • EU/EEA-origin: EU Standard Contractual Clauses (2021 modules), supplemented by a Transfer Impact Assessment.
  • UK-origin: International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs.
  • Swiss-origin: Swiss Addendum to the SCCs.
  • US reception: DPF (Data Privacy Framework) enrolment where available, in addition to SCCs.
  • Brazil-origin: ANPD-approved international transfer mechanisms (SCCs or Binding Corporate Rules).
  • Mainland China-origin: CAC Standard Contract for Cross-border Transfer of Personal Information or PIPL security assessment where thresholds are triggered.
  • India-origin: Transfers restricted to jurisdictions permitted under the DPDPA 2023 regime.
  • Australia-origin: APP 8 safeguards, we take reasonable steps to ensure the overseas recipient does not breach the APPs.
  • Canada-origin: Comparable-protection test; Quebec residents are given prior notice (Law 25).
  • South Korea, Japan, Singapore, Thailand, South Africa, Turkey, UAE, Nigeria: explicit consent for cross-border transfer and/or contractual safeguards meeting local adequacy tests.

To request copies of the safeguards applicable to your data contact dpo@kandaperformance.com.

Section 08
Retention & Deletion

We hold personal data only for as long as necessary for the purpose for which it was collected, or for any longer period required by law.

DataRetention
Account and profileLifetime of account + 30 days grace period
Training, nutrition, check-in, body data (health)Lifetime of account + 30 days
Progress photosUntil you delete them, or +30 days after account deletion
Backups (encrypted)Rolling 90 days
Crash logs / diagnostics (Sentry)90 days
Support correspondence24 months from last message
Transaction / billing records7 years (UK / EU tax + AML)
Marketing opt-out preferences5 years or until erasure requested
Server and access logs30 days
IP-derived region (country-level)Session only, discarded on logout
Legal-hold recordsDuration of hold + limitation period

Deletion is triggered from Settings → Account → Delete Account. After a 30-day reversible grace window, data is irreversibly purged from production systems within a further 60 days and from backups on the rolling 90-day cycle. Legal/tax records and opt-out records are preserved only to the minimum extent required by law.

In-app deletion is a hard requirement (Apple App Store Guideline 5.1.1(v)). We comply and allow deletion without routing you through a support request.

Section 09
Security Controls

We implement technical and organisational measures ("TOMs") proportionate to the risk of processing. A summary is below; a detailed schedule (TOMs Annex) is incorporated into our DPA at Part C.

Technical measures
  • TLS 1.3 in transit with HSTS and certificate pinning (mobile);
  • AES-256 at rest, with envelope encryption and KMS-managed keys;
  • Per-user data-encryption keys for health data payloads where feasible;
  • Argon2id / bcrypt (cost 12) password hashing, salted;
  • OAuth 2.0 / OIDC for third-party sign-in (Apple, Google);
  • Mandatory MFA for all staff admin access (WebAuthn preferred);
  • Row-level security and tenant isolation in databases;
  • Secrets managed in AWS KMS / GCP KMS / HashiCorp Vault; no secrets in code;
  • Code signing, SBOM, automated dependency scanning;
  • Web Application Firewall (Cloudflare) with OWASP ruleset;
  • Runtime intrusion detection, SIEM centralisation, real-time alerting;
  • Automated encrypted backups; documented restore tests.
Organisational measures
  • Background checks and signed confidentiality undertakings for all staff;
  • Annual privacy & security training with refresher modules;
  • Written Access Control Policy with least-privilege defaults;
  • Written Incident Response Plan, tested twice yearly;
  • Vendor security due-diligence prior to engagement; re-review annually;
  • Records of Processing Activities (GDPR Art. 30) maintained;
  • DPIA library maintained for high-risk processing;
  • Secure-by-default software development lifecycle with threat modelling;
  • Annual independent penetration testing and quarterly internal scans;
  • Clean-desk / clear-screen policies; encrypted laptops; MDM;
  • Disaster recovery: RPO 24h, RTO 4h; failover tested quarterly.

No security system is impenetrable. In the event of a breach, we follow Section 15 below and Part D.

Section 10
Your Rights

Depending on residency, you have some or all of the following rights. As a matter of policy we honour all of them for all users regardless of residency, except where expressly limited.

  • Access, obtain a copy of personal data we hold about you, plus metadata (source, purpose, recipients, retention).
  • Rectification / Correction, correct inaccurate or incomplete data.
  • Erasure / Right to be Forgotten, delete data subject to legal retention. Available in-app.
  • Restriction of Processing, pause processing while a dispute is resolved.
  • Data Portability, receive your data in JSON (machine-readable) or CSV format. Available as an in-app export.
  • Objection, object to processing based on legitimate interest, including profiling.
  • Withdraw Consent, at any time without prejudice to prior lawful processing.
  • Non-discrimination, service will not be denied, priced higher, or degraded because you exercised your rights (CCPA/CPRA).
  • Limit Use of Sensitive PI, under the CPRA we already limit SPI use to strictly necessary purposes; you may additionally instruct us to avoid any discretionary use.
  • Opt-out of Sale / Share / Targeted Advertising, we do none of these, but the opt-out flag is available and honoured.
  • Profiling with legal/significant effects, not to be subject to solely automated decisions with such effects. KP's AK Engine is advisory, not determinative.
  • Appeal, appeal a rights decision; US states require this, we offer it globally.
  • Lodge a complaint, with your local Data Protection Authority.
  • Authorised agent, permitted under CCPA/CPRA and several other laws; we verify agent authority via signed authorisation.
  • Successor nomination, under the DPDPA (India) you may nominate a successor for posthumous exercise of rights.

Submit requests via Settings → Privacy → My Data in-app or email privacy@kandaperformance.com. We verify identity via an email confirmation link. Response time: 30 days (GDPR / LGPD), 45 days extendable once (CCPA/CPRA), or the applicable local statutory window. No fee unless the request is manifestly unfounded or excessive.

We honour the Global Privacy Control (GPC) signal as a valid opt-out under California, Colorado and Connecticut law.

Section 11
Children & Minors

KP is not directed at children under 16. We do not knowingly collect personal data from:

  • Children under 13 (US, COPPA);
  • Children under 16 (EU baseline, certain Member States set the threshold between 13 and 16);
  • Children under 18 where local law requires parental consent for health data (e.g. South Korea, India's DPDPA, Brazil's LGPD for certain sensitive processing, Indonesia PDP).

At signup we present an age gate. If a user declares they are below threshold we refuse account creation. If we discover we have inadvertently collected data from an under-age user we delete it within 48 hours and take steps to prevent recurrence.

We comply with the UK Age Appropriate Design Code and the California Age-Appropriate Design Code for any under-18 user, including high-privacy defaults, no nudging, transparent wording, and minimum-necessary data collection.

Section 12
Automated Processing & AI

KP uses automated algorithms for:

  • Training programme generation (AK Engine);
  • Programme auditing and critique;
  • Computation of derived metrics (KP Score, Readiness, Fatigue Index, Adherence);
  • Recommendation of actions during check-ins;
  • Barcode and natural-language food search.

These processes do not produce legal or similarly significant effects. They are advisory. You may accept, reject, modify, or ignore any output. There is no solely-automated decision that affects your rights.

No third-party model training. We do not send your data to OpenAI, Anthropic, Google or any other third-party AI provider for training purposes. Where an on-device or first-party server-side model is used for inference, only minimal data required for inference is transmitted, and it is not retained for model improvement without separate opt-in.

Future AI features will be introduced only with prominent disclosure, separate opt-in for any data used in training, and the ability to opt out at any time. We commit to the EU AI Act's general-purpose-AI transparency requirements where applicable.

Section 13
Marketing & Communications

We send you two categories of message:

  • Service messages (password reset, security alerts, billing receipts, breach notices, material policy changes, deletion confirmations). These are required to operate the App and cannot be opted out of without closing your account.
  • Optional marketing (product news, tips, promotions). These are sent only if you expressly opt-in. You can unsubscribe at any time via the link in every email, via Settings → Notifications, or by replying STOP to an SMS. Unsubscribe requests are honoured within 3 business days (in practice, immediately).

We do not engage in cold-call marketing. We comply with:

  • The UK Privacy and Electronic Communications Regulations (PECR);
  • The EU ePrivacy Directive 2002/58/EC;
  • The US CAN-SPAM Act, TCPA (for SMS), and FTC Health Breach Notification Rule;
  • The Canadian Anti-Spam Legislation (CASL);
  • Australia's Spam Act 2003.

Push notifications are subject to device OS consent. You can disable them at the OS level or in-app.

Section 14
Regional Addenda

The following regional addenda apply in addition to, and where in conflict prevail over, the rest of this Policy for residents of the specified jurisdictions.

European Economic Area & United Kingdom

Controller: Kanda Performance Ltd, 66 Paul Street, London, EC2A 4NA. EU Representative (GDPR Art. 27): [EU REP NAME], [ADDRESS], eu-rep@kandaperformance.com. UK Representative: [UK REP NAME], [ADDRESS], uk-rep@kandaperformance.com. DPO: dpo@kandaperformance.com. You may complain to your lead supervisory authority (UK ICO, ico.org.uk; Irish DPC, dataprotection.ie; or your national DPA). Lead SA: [LEAD SA, e.g. Irish DPC if main establishment is Ireland].

California, CCPA / CPRA

We are a "business". Categories of PI collected (CCPA categories A–K): A (identifiers, name, email, IP), B (customer records, account), D (commercial, subscription), F (internet/network activity, usage), G (geolocation, approximate only), H (sensory, none), I (professional, none), J (education, none), K (inferences, we do not draw inferences for profiling). Sensitive PI categories: account log-in (but not passwords in plaintext); health and exercise data (collected only with consent). Sources, purposes and disclosures: Sections 3, 4 and 6. Retention: Section 8. We do not sell or share PI for cross-context behavioural advertising. Rights: Know, Delete, Correct, Portability, Opt-out of Sale/Share, Limit Use of Sensitive PI, Non-Discrimination, Authorised Agent. We honour GPC. Appeal: reply to any rights decision email; escalation to appeals@kandaperformance.com; ultimate recourse, California AG, OAG or CPPA. Shine the Light (Civil Code §1798.83): we do not disclose PI to third parties for their direct marketing. Financial incentive programmes: none.

Other US States

For residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Indiana (INCDPA), Delaware (DPDPA), Tennessee (TIPA), New Hampshire (NHDPA), New Jersey (NJDPA), Minnesota (MCDPA), Maryland (MODPA), Rhode Island (DTPPA), Kentucky (KCDPA) and any other US state that enacts similar laws: access, correct, delete, portability, opt-out of targeted ads, opt-out of sale, opt-out of significant-effects profiling, appeal. Sensitive data (including health) processed only with consent. Submit requests in-app or at privacy@kandaperformance.com. Appeal window: 45 days. Further recourse: state AG.

Washington, Nevada, Connecticut, Consumer Health Data Laws

Under the Washington MHMDA, Nevada SB 370 and the Connecticut consumer-health-data provisions you have: the right to confirm collection, access, withdraw consent, delete, and a private right of action (Washington). We: (a) obtain separate consent for collection and sharing of consumer health data; (b) do not geofence around healthcare facilities; (c) honour deletion within 30 days; (d) maintain a distinct consumer health data privacy notice at kandaperformance.com/legal/consumer-health; (e) do not sell consumer health data.

Canada (PIPEDA) & Quebec (Law 25)

Privacy Officer: privacy-ca@kandaperformance.com. Quebec residents are notified in advance of cross-border disclosure (Law 25, Art. 17). Rights include access, correction, de-indexation. Privacy Impact Assessments performed where required. Complaints: OPC (priv.gc.ca) or Commission d'accès à l'information du Québec (cai.gouv.qc.ca).

Brazil (LGPD)

Controller: Kanda Performance Ltd. DPO (Encarregado): dpo@kandaperformance.com. Legal bases per Arts. 7 and 11 (contract, consent, legitimate interest, legal obligation). Rights: confirmation, access, correction, anonymisation / blocking / deletion, portability, deletion of consent-based data, information on sharing, information on non-consent consequences, revocation. Complaints: ANPD (gov.br/anpd).

Australia (Privacy Act 1988 + APPs)

We comply with the Australian Privacy Principles. Cross-border disclosures subject to APP 8. Notifiable Data Breaches notified within 30 days to OAIC (oaic.gov.au).

New Zealand (Privacy Act 2020)

Notifiable privacy breaches reported to the OPC (privacy.org.nz) without delay.

Japan (APPI)

We act as a Personal Information Handling Business Operator. Rights: disclosure, correction, suspension. Cross-border transfer only with consent or equivalent safeguards. Contact: privacy-jp@kandaperformance.com.

South Korea (PIPA)

Sensitive information processed only with separate consent. Chief Privacy Officer designated where thresholds met. Complaints: Personal Information Protection Commission (pipc.go.kr). KISA ISMS-P certification pursued.

India (DPDPA 2023)

Data Principal rights: access, correction / erasure, grievance redressal, nominate a successor. Consent in plain language. Children (<18) processing requires verifiable parental consent, we therefore do not process children's data. Grievance Officer: grievance-in@kandaperformance.com. Escalation: Data Protection Board of India.

China (PIPL + CSL + DSL)

Users in Mainland China: explicit and separate consent for each category of sensitive PI; CAC Standard Contract or security assessment for cross-border transfers; localised storage where volume thresholds are met. Rights of access, correction, deletion, portability. KP may restrict availability of certain features in Mainland China pending regulatory clearance. For enquiries: privacy-cn@kandaperformance.com.

Singapore (PDPA)

DPO: dpo-sg@kandaperformance.com. Consent withdrawal in-app. Complaints: PDPC (pdpc.gov.sg).

South Africa (POPIA)

Information Officer designated. Complaints: Information Regulator (inforegulator.org.za).

Switzerland (revFADP)

Swiss residents enjoy all rights in Section 10. Swiss Addendum to SCCs applies for cross-border transfers.

Turkey (KVKK)

VERBIS registration maintained where required. Complaints: KVKK (kvkk.gov.tr).

Thailand (PDPA)

Separate consent for sensitive data. DPO: dpo-th@kandaperformance.com.

Mexico (LFPDPPP)

ARCO rights (Access, Rectification, Cancellation, Opposition) plus revocation. Complaints: INAI (inai.org.mx).

Indonesia (PDP Law No. 27/2022)

Data Subject rights mirror Section 10. Complaints: DPA under the Ministry of Communication and Informatics.

Vietnam (PDPD Decree 13/2023)

Cross-border transfer impact assessment performed; filing to A05/MPS where required.

UAE (Federal PDPL Law No. 45/2021)

UAE Data Office adequacy / safeguards relied upon. DIFC and ADGM users separately served where applicable.

Saudi Arabia (PDPL)

SDAIA compliance. Cross-border transfer mechanism per the PDPL.

Nigeria (NDPA 2023)

NITDA / NDPC compliance. Grievance Officer: grievance-ng@kandaperformance.com.

Kenya (DPA 2019)

ODPC registration maintained. Rights mirror Section 10.

Section 15
Breach Notification

In the unlikely event of a personal-data breach we will:

  • notify the UK ICO / EU lead supervisory authority within 72 hours of becoming aware (GDPR Arts. 33-34);
  • notify you without undue delay where the breach is likely to result in high risk;
  • notify under the FTC Health Breach Notification Rule where applicable (US);
  • notify OAIC (Australia), OPC (Canada), ANPD (Brazil), PIPC (Korea), PDPC (Singapore), CAC (China), DPBI (India), ODPC (Kenya) and other applicable regulators under their own timelines;
  • notify affected Washington residents within the statutory MHMDA window.

Our full Incident Response Plan is summarised in Part D. We publish an annual Transparency Report disclosing the number of breach incidents, categories of data affected, and remedial steps taken.

Section 16
Changes

We may update this Policy. Material changes are communicated by email and in-app banner at least 30 days before they take effect. A version history is maintained at kandaperformance.com/legal/privacy-history. Continued use after the effective date constitutes acceptance of the updated Policy. You may always close your account in response.

Section 17
Contact

Controller: Kanda Performance Ltd, 66 Paul Street, London, EC2A 4NA, Company No. 17164938.
General privacy enquiries: privacy@kandaperformance.com
Data Protection Officer: dpo@kandaperformance.com
EU Representative (GDPR Art. 27): [EU REP NAME & ADDRESS]
UK Representative: [UK REP NAME & ADDRESS]
Postal: Data Protection Office, 66 Paul Street, London, EC2A 4NA.

Your consent withdrawal, opt-out, access, deletion and portability requests can be raised directly in-app: Settings → Privacy & Data.

Part B
COOKIE & TRACKING POLICY
ePrivacy Directive compliant. Equal prominence to Accept / Reject. No dark patterns.
B.1   What are cookies?

Cookies are small text files stored on your device by a website or app. Similar technologies include localStorage, sessionStorage, IndexedDB, service workers, pixel tags and software development kits (SDKs) that achieve the same effect. This Policy covers all of them.

The KP mobile app does not use traditional browser cookies. It uses device local storage, secure keychains and platform-provided identifiers (device token for push, and, only if you actively grant consent via the Apple App Tracking Transparency prompt, the IDFA). By default, ATT is denied and the IDFA is unavailable to KP.

B.2   Categories we use
CategoryPurposeConsent?Retention
Strictly necessaryAuthentication session, CSRF token, load-balancing, consent-state memoryNo consent required (ePrivacy Art. 5(3) exemption)Session / 12 months (consent state)
FunctionalRemember UI preferences (dark mode, units, tab state)Consent opt-in12 months
Analytics (privacy-respecting)Aggregate product analytics via Plausible / PostHog EU-hosted; anonymous; no cross-site profilingConsent opt-in12 months
Marketing / advertisingWe do not currently use marketing cookies.N/AN/A
B.3   How we obtain consent
  • On first visit to the web version you see our Consent Management Platform (CMP) banner.
  • "Accept All" and "Reject All" are given equal prominence. "Reject All" is always one tap.
  • A "Customise" option lets you toggle each non-essential category independently.
  • Consent is stored server-side against your user ID (or pseudonymously via a first-party cookie if you are logged out) with a timestamp and the version of the banner shown.
  • You can change preferences at any time via Settings → Privacy → Cookies or the "Cookie preferences" link in the web footer.
  • Consent is refreshed after 12 months or sooner if we add a new purpose.
  • We honour Global Privacy Control signals and the Do-Not-Track header as opt-outs.
Part C
DATA PROCESSING ADDENDUM (DPA)
Incorporated into the Terms of Service. Operates where KP acts as Processor, e.g. B2B / coaching plans. Includes GDPR Art. 28 terms, SCCs by reference, and TOMs annex.
C.1   Scope

This Addendum applies where Customer (for example a personal trainer, gym or team) engages KP to process personal data on Customer's behalf via the KP platform or API. In consumer contexts (individual users), KP acts as Controller and this Addendum does not apply.

C.2   Roles & instructions

Customer is Controller; KP is Processor. KP processes Personal Data only on documented instructions from Customer. KP notifies Customer without delay if an instruction infringes applicable data protection law.

C.3   Nature & duration

Subject matter: provision of the KP platform. Duration: the term of the underlying agreement plus 30 days for deletion/return. Nature: storage, organisation, display, computation, export. Purposes: as authorised by Customer. Categories of Data Subjects: Customer's end users. Categories of Personal Data: account identifiers and health/fitness data as defined in Section 3 above.

C.4   Sub-processing

Customer provides general authorisation for KP to engage the sub-processors listed in Part F and any future sub-processor added with 30 days' notice. Customer may object for material risks; absent alternative, either party may terminate the affected service on a pro-rata refund.

C.5   Confidentiality, personnel

KP ensures that all personnel authorised to process Personal Data are bound by confidentiality obligations and have received appropriate training.

C.6   Security (TOMs Annex)

KP implements the technical and organisational measures set out in Section 9 above as the minimum "Annex II" TOMs for SCC purposes. These include encryption in transit (TLS 1.3), encryption at rest (AES-256), access control (MFA, least privilege), resilience (backups, DR), testing (annual penetration test), incident response, certification pursuit (SOC 2 Type II, ISO 27001).

C.7   Data subject requests

KP assists Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise Data Subject rights.

C.8   Incident notification

KP notifies Customer of a Personal Data Breach without undue delay and in any event within 48 hours of becoming aware, providing information sufficient for Customer to meet its own GDPR Art. 33-34 obligations.

C.9   International transfers

The Parties incorporate the EU SCCs (2021 modules 2 and 3 as applicable), the UK IDTA, and the Swiss Addendum for restricted transfers. Transfer Impact Assessments are made available to Customer on request.

C.10   Audit

Customer may audit once per year by reviewing KP's SOC 2 / ISO 27001 report and a KP-provided questionnaire. On-site audits are permitted on 60 days' notice at Customer's cost where documentation is insufficient, subject to confidentiality and non-disruption.

C.11   Return / deletion

On termination, Customer can export data within 30 days. Thereafter KP deletes or returns all Personal Data within 90 days, except where retention is required by law.

Part D
SECURITY & INCIDENT RESPONSE
Summary of controls, incident classification, notification timelines and contact channels.
D.1   Certifications pursued
  • SOC 2 Type II (security, availability, confidentiality);
  • ISO/IEC 27001 and ISO/IEC 27701;
  • PCI-DSS SAQ A (we do not touch cardholder data, processed by Apple/Google/Stripe);
  • Cloud-provider HITRUST r2 alignment.
D.2   Incident classification
  • SEV-0, Confirmed breach of production data affecting users.
  • SEV-1, Suspected breach; integrity or availability impact.
  • SEV-2, Vulnerability identified; no exploitation.
  • SEV-3, Low-risk anomaly.
D.3   Response timelines
  • Triage and containment begun within 1 hour of confirmation (SEV-0/1).
  • Notification to regulators: 72 hours (EU/UK GDPR), equivalents elsewhere.
  • Notification to affected users: without undue delay where high risk; in any event aligned to statutory requirements.
  • Post-incident root-cause analysis: within 30 days; remediation tracked in internal tracker.
D.4   Report a vulnerability

Security researchers: email security@kandaperformance.com. We operate a coordinated-disclosure policy and a safe-harbour for good-faith research (no legal action so long as you act within the rules). Bug-bounty programme details at kandaperformance.com/security.

PGP key fingerprint: [PGP FINGERPRINT].

Part E
ACCESSIBILITY STATEMENT
WCAG 2.1 AA / 2.2 AA conformance commitment. EAA 2025 ready.
E.1   Our commitment

KP is committed to making the Service accessible to everyone, including users with disabilities. We target conformance with the W3C Web Content Accessibility Guidelines (WCAG) 2.2 Level AA and align with the EU European Accessibility Act (EAA) that became enforceable on 28 June 2025.

E.2   Measures taken
  • Semantic HTML, ARIA landmarks, descriptive labels on form fields and icon-only buttons;
  • Colour contrast ratio ≥ 4.5:1 for body text, 3:1 for large text;
  • Keyboard navigability of every interactive element;
  • VoiceOver (iOS) and TalkBack (Android) tested;
  • Dynamic-type support and respect for reduced-motion OS preferences;
  • No reliance on colour alone to convey meaning;
  • Captions on any video content;
  • Accessible-first design reviews for new features.
E.3   Feedback / requests

If you encounter an accessibility barrier please contact accessibility@kandaperformance.com. We aim to respond within 5 business days and resolve reported issues as a priority.

EU residents may escalate unresolved accessibility complaints to their national enforcement body under the EAA.

Part F
SUB-PROCESSOR REGISTER
Live copy of every third party processing personal data on KP's behalf.
Sub-processorPurposeDataRegionTransfer mechanism
Apple Inc.App Store distribution; Sign in with Apple; push notifications; in-app purchasesAccount ID, purchase receipts, push tokenUS / IrelandSCCs + DPF
Google LLCPlay Store distribution; Firebase Auth / PushAccount ID, push tokenUSSCCs + DPF
Amazon Web Services EMEA SARLPrimary hosting (EU)All service data (encrypted)Irelandn/a (intra-EEA)
Amazon Web Services Inc.DR / secondary regionEncrypted backupsUSSCCs + DPF
Google Cloud EMEA Ltd.Secondary storage / ML inferenceEncrypted feature dataIrelandn/a
Stripe Payments Europe Ltd.Card processing for non-App-Store purchasesTransaction metadataIreland / USSCCs + DPF
RevenueCat Inc.Subscription receipt verificationReceipt tokens, pseudonymous user IDUSSCCs + DPF
Sentry (Functional Software Inc.)Crash reportingStack traces, device, pseudo-UIDEU-hostedn/a
Cloudflare Inc.CDN / WAF / DDoSEphemeral edge metadataGlobal edgeSCCs
Postmark (ActiveCampaign)Transactional emailEmail, eventUSSCCs + DPF
Plausible Analytics / PostHogPrivacy-respecting analyticsAggregate event countsEUn/a
ZendeskSupport ticketingSupport correspondenceEU / USSCCs + DPF
Okta (Auth0) (if used)Identity infrastructureAccount identifiersEU / USSCCs + DPF

Historical versions of this register are archived at kandaperformance.com/legal/subprocessors-history.

Part G
DEFINITIONS
Key defined terms used throughout.
  • Applicable Law, any privacy, data-protection or consumer-protection law applicable to the processing, including the GDPR, UK GDPR, CPRA, LGPD, PIPL, DPDPA, POPIA, APPI, PDPA, PIPA and any successor legislation.
  • Consumer Health Data, data identifying a consumer's past, present or future physical or mental health, including in the context of fitness activity and biometric-derived attributes, as defined in Washington's MHMDA and similar laws.
  • Controller / Business / Fiduciary, the entity determining the purposes and means of processing.
  • Processor / Service Provider / Processor, the entity processing personal data on behalf of a Controller.
  • Personal Data / Personal Information, any information relating to an identified or identifiable natural person.
  • Sensitive Personal Information, as defined under CPRA (California) and parallel concepts elsewhere.
  • Special Category Data, data listed in GDPR Art. 9(1), including health data.
  • Sub-processor, a third party engaged by KP to process Personal Data on its behalf.
  • Supervisory Authority, a competent national data-protection authority.
  • DPF, EU-US Data Privacy Framework, including its UK and Swiss extensions.
  • SCCs, Standard Contractual Clauses adopted by the European Commission in 2021.

Kanda Performance Ltd  ·  Company No. 17164938  ·  Registered in England & Wales
Document reviewed and issued 16 April 2026  ·  Version 2.0.
Questions: privacy@kandaperformance.com