This Privacy Policy (the "Policy") governs how Kanda Performance Ltd ("KP", "we", "us", "our") collects, uses, shares, stores, transfers, secures and deletes personal information when you install, access, register for, subscribe to or otherwise interact with the Kanda Performance mobile application, any related websites (including kandaperformance.com), associated features such as the AK Engine training programme generator, training session logger, nutrition logger, supplement stack tracker, check-in system, analysis dashboards, mesocycle planner, readiness calculator and any other product or service offered by KP (collectively the "Service" or "App").
Kanda Performance Ltd is the Data Controller for the purposes of the UK GDPR, the EU GDPR, the Swiss revFADP and equivalent concepts worldwide. Under the CCPA/CPRA we are a "business". Under the LGPD we are the "controlador". Under the PIPL we are the "personal information handler". Under the DPDPA we are the "data fiduciary". Under Japan's APPI we are a "personal information handling business operator".
Our registered office: 66 Paul Street, London, EC2A 4NA.
Company number: 17164938 (England & Wales).
This Policy applies globally. In the event of conflict between the main body of this Policy and a regional supplement in Section 14, the regional supplement prevails for residents of that region.
Before the long version, here is the short version. This summary is for orientation only; the rights and obligations in this Policy are set out in Sections 3–17 below.
The table below is a comprehensive register of data categories collected by the Service, tied specifically to KP's features. "Health data" marks categories treated as special-category / sensitive personal data.
| Category | Examples | Source | Health? |
|---|---|---|---|
| Account identifiers | Name, username, email, password hash (bcrypt cost 12), user ID (UUID), profile photo, Sign in with Apple private-relay email alias, Google/Apple subject ID | You, Apple/Google OAuth | No |
| Training data | Exercise name and group, sets, reps, weight, RPE, tempo, rest time, set type (warm-up / top set / AMRAP / failure / back-off / drop-set / tempo / cluster / feeder), session duration, session notes, estimated 1RM (E1RM) history, personal records, muscle-group volume distribution, adherence metrics, AK Engine programme outputs, mesocycle plans, deload tracking | You | Yes |
| Nutrition data | Logged foods, brand, quantity, calories, protein, carbs, fat, fibre, sugar, sodium, meal time, meal type, food quality score (FQS), protein distribution score (PDS), hydration, custom foods | You, barcode scan, food database | Yes |
| Supplement data | Stack composition, dose, timing, adherence, brand, cost tracking | You | Yes |
| Body & check-in data | Bodyweight, waist/hip/arm measurements, sleep hours, sleep quality (1-10), muscle soreness (1-10), energy (1-10), mood, readiness, weekly/phase check-ins, menstrual-cycle phase (optional), progress photos you elect to upload | You | Yes |
| Goals & programme data | Goal type (cut / bulk / recomp / maintain), target weight, training age, weak points, injuries you declare, active phase, KP Score, fatigue index | You | Yes |
| Subscription & payment | Subscription tier, start/renewal date, trial status, platform (Apple/Google/Stripe), purchase receipts, transaction IDs. We do not receive or store your payment card details, Apple, Google or Stripe processes them. | Apple, Google, Stripe, RevenueCat | No |
| Device & technical | Device model, OS version, App version, language, time zone, crash logs (Sentry), approximate IP-derived region (country/region only, we do not store full IP long-term), advertising identifier (IDFA / AAID) only if you grant consent via Apple ATT or Android prompt, default is off | Device SDKs | No |
| Usage & diagnostic | Feature interactions (which tabs/screens viewed), session duration, performance metrics, error events. First-party and anonymised. On by default to improve the app, with an opt-out in Settings. Global Privacy Control honoured. | App telemetry | No |
| Communications | Support tickets, email correspondence, in-app feedback, push-notification token, contact preferences | You, device | No |
| HealthKit / Google Fit (optional, read-only) | If you grant permission: steps, active energy, heart rate, heart-rate variability, sleep, workouts, weight, height. You control which categories. | Apple HealthKit / Google Fit | Yes |
| Biometric unlock (optional) | Face ID / Touch ID / fingerprint gate for App access. The biometric template never leaves your device. We only receive a pass/fail result from the OS. | Device | No (we do not hold biometrics) |
| Third-party sign-in | If you sign in with Apple or Google: identifier, verified email (optionally anonymised via Apple Private Relay), display name | Apple, Google | No |
In accordance with Apple's App Store policy our app bundles a PrivacyInfo.xcprivacy manifest. The categories we declare are: Contact Info (email); Health & Fitness (user-provided); Sensitive Info (health data); User Content (photos, notes); Identifiers (device ID, user ID); Usage Data (product interaction); Diagnostics. We declare data types "Linked to User" except diagnostics which may be "Not linked". We do not declare any data type under "Data used to track you".
Under the UK/EU GDPR, LGPD, DPDPA and similar frameworks we must have a lawful basis for each processing purpose. This table is our register.
| Purpose | Data used | GDPR Art. 6 basis | Art. 9 (health) |
|---|---|---|---|
| Operating the App (accounts, logging, programmes, analytics) | Service data | Contract (6(1)(b)) | Explicit consent (9(2)(a)) |
| AK Engine programme generation & audit | Goal, training history, check-ins | Contract (6(1)(b)) | Explicit consent (9(2)(a)) |
| KP Score, Readiness, Fatigue Index computation | Check-ins, sessions | Contract (6(1)(b)) | Explicit consent (9(2)(a)) |
| Subscription billing and receipt verification | Purchase receipts | Contract (6(1)(b)) | - |
| Fraud and chargeback prevention | Transaction metadata, device signals | Legitimate interest (6(1)(f)) | - |
| Security, debugging, abuse detection | Device, IP, crash logs | Legitimate interest (6(1)(f)) | - |
| Service emails (password reset, receipts, breach notice) | Contract (6(1)(b)) / legal obligation | - | |
| Optional marketing emails | Email, preferences | Consent (6(1)(a)), opt-in, revocable | - |
| Product analytics (first-party, opt-out) | Usage events | Legitimate interest (6(1)(f)), opt-out in Settings | - |
| Legal, tax, audit, AML | Transaction records | Legal obligation (6(1)(c)) | - |
| Defending legal claims / responding to legal process | Account records as needed | Legitimate interest / legal obligation | Legal claims (9(2)(f)) |
| Aggregated, de-identified research | Strictly anonymised (k-anonymity & differential privacy) | Legitimate interest (6(1)(f)) | Anonymisation + substantial public interest safeguards (9(2)(j)) |
Changes of purpose: If we propose to process your data for a new purpose incompatible with those listed above we will provide 30 days' advance notice and seek fresh consent where required.
Fitness, nutrition, supplement, body-measurement, sleep, mood, soreness, menstrual-cycle and check-in data are treated as special category personal data under Article 9 GDPR. The same categories are classified elsewhere as follows:
Personal data is shared only with the categories of recipient listed below, each bound by a written Data Processing Agreement satisfying GDPR Art. 28, and where applicable the UK IDTA, EU SCCs, Swiss Addendum, Brazilian SCCs or CAC Standard Contract (see Section 7). A live register of sub-processors is maintained in Part F.
We give 30 days' advance notice of a new sub-processor via in-app notice and the public register, and permit reasoned objection for material risks. On objection we will either provide an alternative or give you a pro-rata subscription refund and a data export.
We do not sell personal data within the meaning of the CCPA/CPRA, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA, Iowa ICDPA, Indiana INCDPA, Delaware DPDPA, or any other law. We do not "share" personal data for cross-context behavioural advertising. We have not sold or shared personal data in the preceding 12 months.
Legal disclosure: We may disclose data where required by a valid, binding legal process (court order, properly-issued subpoena, warrant, official request from a supervisory authority), where necessary to protect the vital interests of any person, to prevent fraud, to enforce our Terms, or to defend our legal rights. We reject overbroad or unlawful requests, require specificity, and, where legally permitted, will notify you of demands affecting your data before responding. We publish an annual Transparency Report of the aggregate number of government requests received.
Business transfers: In the event of a merger, acquisition or asset sale, data may be transferred to the successor entity. You will be notified by email and in-app banner and given the opportunity to delete your account and export your data before the transfer takes effect.
KP is a global service. Cross-border transfers of personal data are carried out with the following safeguards:
To request copies of the safeguards applicable to your data contact dpo@kandaperformance.com.
We hold personal data only for as long as necessary for the purpose for which it was collected, or for any longer period required by law.
| Data | Retention |
|---|---|
| Account and profile | Lifetime of account + 30 days grace period |
| Training, nutrition, check-in, body data (health) | Lifetime of account + 30 days |
| Progress photos | Until you delete them, or +30 days after account deletion |
| Backups (encrypted) | Rolling 90 days |
| Crash logs / diagnostics (Sentry) | 90 days |
| Support correspondence | 24 months from last message |
| Transaction / billing records | 7 years (UK / EU tax + AML) |
| Marketing opt-out preferences | 5 years or until erasure requested |
| Server and access logs | 30 days |
| IP-derived region (country-level) | Session only, discarded on logout |
| Legal-hold records | Duration of hold + limitation period |
Deletion is triggered from Settings → Account → Delete Account. After a 30-day reversible grace window, data is irreversibly purged from production systems within a further 60 days and from backups on the rolling 90-day cycle. Legal/tax records and opt-out records are preserved only to the minimum extent required by law.
In-app deletion is a hard requirement (Apple App Store Guideline 5.1.1(v)). We comply and allow deletion without routing you through a support request.
We implement technical and organisational measures ("TOMs") proportionate to the risk of processing. A summary is below; a detailed schedule (TOMs Annex) is incorporated into our DPA at Part C.
No security system is impenetrable. In the event of a breach, we follow Section 15 below and Part D.
Depending on residency, you have some or all of the following rights. As a matter of policy we honour all of them for all users regardless of residency, except where expressly limited.
Submit requests via Settings → Privacy → My Data in-app or email privacy@kandaperformance.com. We verify identity via an email confirmation link. Response time: 30 days (GDPR / LGPD), 45 days extendable once (CCPA/CPRA), or the applicable local statutory window. No fee unless the request is manifestly unfounded or excessive.
We honour the Global Privacy Control (GPC) signal as a valid opt-out under California, Colorado and Connecticut law.
KP is not directed at children under 16. We do not knowingly collect personal data from:
At signup we present an age gate. If a user declares they are below threshold we refuse account creation. If we discover we have inadvertently collected data from an under-age user we delete it within 48 hours and take steps to prevent recurrence.
We comply with the UK Age Appropriate Design Code and the California Age-Appropriate Design Code for any under-18 user, including high-privacy defaults, no nudging, transparent wording, and minimum-necessary data collection.
KP uses automated algorithms for:
These processes do not produce legal or similarly significant effects. They are advisory. You may accept, reject, modify, or ignore any output. There is no solely-automated decision that affects your rights.
No third-party model training. We do not send your data to OpenAI, Anthropic, Google or any other third-party AI provider for training purposes. Where an on-device or first-party server-side model is used for inference, only minimal data required for inference is transmitted, and it is not retained for model improvement without separate opt-in.
Future AI features will be introduced only with prominent disclosure, separate opt-in for any data used in training, and the ability to opt out at any time. We commit to the EU AI Act's general-purpose-AI transparency requirements where applicable.
We send you two categories of message:
We do not engage in cold-call marketing. We comply with:
Push notifications are subject to device OS consent. You can disable them at the OS level or in-app.
The following regional addenda apply in addition to, and where in conflict prevail over, the rest of this Policy for residents of the specified jurisdictions.
Controller: Kanda Performance Ltd, 66 Paul Street, London, EC2A 4NA. EU Representative (GDPR Art. 27): [EU REP NAME], [ADDRESS], eu-rep@kandaperformance.com. UK Representative: [UK REP NAME], [ADDRESS], uk-rep@kandaperformance.com. DPO: dpo@kandaperformance.com. You may complain to your lead supervisory authority (UK ICO, ico.org.uk; Irish DPC, dataprotection.ie; or your national DPA). Lead SA: [LEAD SA, e.g. Irish DPC if main establishment is Ireland].
We are a "business". Categories of PI collected (CCPA categories A–K): A (identifiers, name, email, IP), B (customer records, account), D (commercial, subscription), F (internet/network activity, usage), G (geolocation, approximate only), H (sensory, none), I (professional, none), J (education, none), K (inferences, we do not draw inferences for profiling). Sensitive PI categories: account log-in (but not passwords in plaintext); health and exercise data (collected only with consent). Sources, purposes and disclosures: Sections 3, 4 and 6. Retention: Section 8. We do not sell or share PI for cross-context behavioural advertising. Rights: Know, Delete, Correct, Portability, Opt-out of Sale/Share, Limit Use of Sensitive PI, Non-Discrimination, Authorised Agent. We honour GPC. Appeal: reply to any rights decision email; escalation to appeals@kandaperformance.com; ultimate recourse, California AG, OAG or CPPA. Shine the Light (Civil Code §1798.83): we do not disclose PI to third parties for their direct marketing. Financial incentive programmes: none.
For residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Indiana (INCDPA), Delaware (DPDPA), Tennessee (TIPA), New Hampshire (NHDPA), New Jersey (NJDPA), Minnesota (MCDPA), Maryland (MODPA), Rhode Island (DTPPA), Kentucky (KCDPA) and any other US state that enacts similar laws: access, correct, delete, portability, opt-out of targeted ads, opt-out of sale, opt-out of significant-effects profiling, appeal. Sensitive data (including health) processed only with consent. Submit requests in-app or at privacy@kandaperformance.com. Appeal window: 45 days. Further recourse: state AG.
Under the Washington MHMDA, Nevada SB 370 and the Connecticut consumer-health-data provisions you have: the right to confirm collection, access, withdraw consent, delete, and a private right of action (Washington). We: (a) obtain separate consent for collection and sharing of consumer health data; (b) do not geofence around healthcare facilities; (c) honour deletion within 30 days; (d) maintain a distinct consumer health data privacy notice at kandaperformance.com/legal/consumer-health; (e) do not sell consumer health data.
Privacy Officer: privacy-ca@kandaperformance.com. Quebec residents are notified in advance of cross-border disclosure (Law 25, Art. 17). Rights include access, correction, de-indexation. Privacy Impact Assessments performed where required. Complaints: OPC (priv.gc.ca) or Commission d'accès à l'information du Québec (cai.gouv.qc.ca).
Controller: Kanda Performance Ltd. DPO (Encarregado): dpo@kandaperformance.com. Legal bases per Arts. 7 and 11 (contract, consent, legitimate interest, legal obligation). Rights: confirmation, access, correction, anonymisation / blocking / deletion, portability, deletion of consent-based data, information on sharing, information on non-consent consequences, revocation. Complaints: ANPD (gov.br/anpd).
We comply with the Australian Privacy Principles. Cross-border disclosures subject to APP 8. Notifiable Data Breaches notified within 30 days to OAIC (oaic.gov.au).
Notifiable privacy breaches reported to the OPC (privacy.org.nz) without delay.
We act as a Personal Information Handling Business Operator. Rights: disclosure, correction, suspension. Cross-border transfer only with consent or equivalent safeguards. Contact: privacy-jp@kandaperformance.com.
Sensitive information processed only with separate consent. Chief Privacy Officer designated where thresholds met. Complaints: Personal Information Protection Commission (pipc.go.kr). KISA ISMS-P certification pursued.
Data Principal rights: access, correction / erasure, grievance redressal, nominate a successor. Consent in plain language. Children (<18) processing requires verifiable parental consent, we therefore do not process children's data. Grievance Officer: grievance-in@kandaperformance.com. Escalation: Data Protection Board of India.
Users in Mainland China: explicit and separate consent for each category of sensitive PI; CAC Standard Contract or security assessment for cross-border transfers; localised storage where volume thresholds are met. Rights of access, correction, deletion, portability. KP may restrict availability of certain features in Mainland China pending regulatory clearance. For enquiries: privacy-cn@kandaperformance.com.
DPO: dpo-sg@kandaperformance.com. Consent withdrawal in-app. Complaints: PDPC (pdpc.gov.sg).
Information Officer designated. Complaints: Information Regulator (inforegulator.org.za).
Swiss residents enjoy all rights in Section 10. Swiss Addendum to SCCs applies for cross-border transfers.
VERBIS registration maintained where required. Complaints: KVKK (kvkk.gov.tr).
Separate consent for sensitive data. DPO: dpo-th@kandaperformance.com.
ARCO rights (Access, Rectification, Cancellation, Opposition) plus revocation. Complaints: INAI (inai.org.mx).
Data Subject rights mirror Section 10. Complaints: DPA under the Ministry of Communication and Informatics.
Cross-border transfer impact assessment performed; filing to A05/MPS where required.
UAE Data Office adequacy / safeguards relied upon. DIFC and ADGM users separately served where applicable.
SDAIA compliance. Cross-border transfer mechanism per the PDPL.
NITDA / NDPC compliance. Grievance Officer: grievance-ng@kandaperformance.com.
ODPC registration maintained. Rights mirror Section 10.
In the unlikely event of a personal-data breach we will:
Our full Incident Response Plan is summarised in Part D. We publish an annual Transparency Report disclosing the number of breach incidents, categories of data affected, and remedial steps taken.
We may update this Policy. Material changes are communicated by email and in-app banner at least 30 days before they take effect. A version history is maintained at kandaperformance.com/legal/privacy-history. Continued use after the effective date constitutes acceptance of the updated Policy. You may always close your account in response.
Controller: Kanda Performance Ltd, 66 Paul Street, London, EC2A 4NA, Company No. 17164938.
General privacy enquiries: privacy@kandaperformance.com
Data Protection Officer: dpo@kandaperformance.com
EU Representative (GDPR Art. 27): [EU REP NAME & ADDRESS]
UK Representative: [UK REP NAME & ADDRESS]
Postal: Data Protection Office, 66 Paul Street, London, EC2A 4NA.
Your consent withdrawal, opt-out, access, deletion and portability requests can be raised directly in-app: Settings → Privacy & Data.
Cookies are small text files stored on your device by a website or app. Similar technologies include localStorage, sessionStorage, IndexedDB, service workers, pixel tags and software development kits (SDKs) that achieve the same effect. This Policy covers all of them.
The KP mobile app does not use traditional browser cookies. It uses device local storage, secure keychains and platform-provided identifiers (device token for push, and, only if you actively grant consent via the Apple App Tracking Transparency prompt, the IDFA). By default, ATT is denied and the IDFA is unavailable to KP.
| Category | Purpose | Consent? | Retention |
|---|---|---|---|
| Strictly necessary | Authentication session, CSRF token, load-balancing, consent-state memory | No consent required (ePrivacy Art. 5(3) exemption) | Session / 12 months (consent state) |
| Functional | Remember UI preferences (dark mode, units, tab state) | Consent opt-in | 12 months |
| Analytics (privacy-respecting) | Aggregate product analytics via Plausible / PostHog EU-hosted; anonymous; no cross-site profiling | Consent opt-in | 12 months |
| Marketing / advertising | We do not currently use marketing cookies. | N/A | N/A |
This Addendum applies where Customer (for example a personal trainer, gym or team) engages KP to process personal data on Customer's behalf via the KP platform or API. In consumer contexts (individual users), KP acts as Controller and this Addendum does not apply.
Customer is Controller; KP is Processor. KP processes Personal Data only on documented instructions from Customer. KP notifies Customer without delay if an instruction infringes applicable data protection law.
Subject matter: provision of the KP platform. Duration: the term of the underlying agreement plus 30 days for deletion/return. Nature: storage, organisation, display, computation, export. Purposes: as authorised by Customer. Categories of Data Subjects: Customer's end users. Categories of Personal Data: account identifiers and health/fitness data as defined in Section 3 above.
Customer provides general authorisation for KP to engage the sub-processors listed in Part F and any future sub-processor added with 30 days' notice. Customer may object for material risks; absent alternative, either party may terminate the affected service on a pro-rata refund.
KP ensures that all personnel authorised to process Personal Data are bound by confidentiality obligations and have received appropriate training.
KP implements the technical and organisational measures set out in Section 9 above as the minimum "Annex II" TOMs for SCC purposes. These include encryption in transit (TLS 1.3), encryption at rest (AES-256), access control (MFA, least privilege), resilience (backups, DR), testing (annual penetration test), incident response, certification pursuit (SOC 2 Type II, ISO 27001).
KP assists Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise Data Subject rights.
KP notifies Customer of a Personal Data Breach without undue delay and in any event within 48 hours of becoming aware, providing information sufficient for Customer to meet its own GDPR Art. 33-34 obligations.
The Parties incorporate the EU SCCs (2021 modules 2 and 3 as applicable), the UK IDTA, and the Swiss Addendum for restricted transfers. Transfer Impact Assessments are made available to Customer on request.
Customer may audit once per year by reviewing KP's SOC 2 / ISO 27001 report and a KP-provided questionnaire. On-site audits are permitted on 60 days' notice at Customer's cost where documentation is insufficient, subject to confidentiality and non-disruption.
On termination, Customer can export data within 30 days. Thereafter KP deletes or returns all Personal Data within 90 days, except where retention is required by law.
Security researchers: email security@kandaperformance.com. We operate a coordinated-disclosure policy and a safe-harbour for good-faith research (no legal action so long as you act within the rules). Bug-bounty programme details at kandaperformance.com/security.
PGP key fingerprint: [PGP FINGERPRINT].
KP is committed to making the Service accessible to everyone, including users with disabilities. We target conformance with the W3C Web Content Accessibility Guidelines (WCAG) 2.2 Level AA and align with the EU European Accessibility Act (EAA) that became enforceable on 28 June 2025.
If you encounter an accessibility barrier please contact accessibility@kandaperformance.com. We aim to respond within 5 business days and resolve reported issues as a priority.
EU residents may escalate unresolved accessibility complaints to their national enforcement body under the EAA.
| Sub-processor | Purpose | Data | Region | Transfer mechanism |
|---|---|---|---|---|
| Apple Inc. | App Store distribution; Sign in with Apple; push notifications; in-app purchases | Account ID, purchase receipts, push token | US / Ireland | SCCs + DPF |
| Google LLC | Play Store distribution; Firebase Auth / Push | Account ID, push token | US | SCCs + DPF |
| Amazon Web Services EMEA SARL | Primary hosting (EU) | All service data (encrypted) | Ireland | n/a (intra-EEA) |
| Amazon Web Services Inc. | DR / secondary region | Encrypted backups | US | SCCs + DPF |
| Google Cloud EMEA Ltd. | Secondary storage / ML inference | Encrypted feature data | Ireland | n/a |
| Stripe Payments Europe Ltd. | Card processing for non-App-Store purchases | Transaction metadata | Ireland / US | SCCs + DPF |
| RevenueCat Inc. | Subscription receipt verification | Receipt tokens, pseudonymous user ID | US | SCCs + DPF |
| Sentry (Functional Software Inc.) | Crash reporting | Stack traces, device, pseudo-UID | EU-hosted | n/a |
| Cloudflare Inc. | CDN / WAF / DDoS | Ephemeral edge metadata | Global edge | SCCs |
| Postmark (ActiveCampaign) | Transactional email | Email, event | US | SCCs + DPF |
| Plausible Analytics / PostHog | Privacy-respecting analytics | Aggregate event counts | EU | n/a |
| Zendesk | Support ticketing | Support correspondence | EU / US | SCCs + DPF |
| Okta (Auth0) (if used) | Identity infrastructure | Account identifiers | EU / US | SCCs + DPF |
Historical versions of this register are archived at kandaperformance.com/legal/subprocessors-history.
Kanda Performance Ltd · Company No. 17164938 · Registered in England & Wales
Document reviewed and issued 16 April 2026 · Version 2.0.
Questions: privacy@kandaperformance.com