BACK TO HOME

VOLIA FITNESS - EXHAUSTIVE PRIVACY POLICY, DATA PROCESSING, AND COOKIE AGREEMENT

DATA CONTROLLER: GrupoVolia S.A.S. (operating as "Volia Fitness" and "Volia AI") JURISDICTION & COMPLIANCE: Republic of Ecuador (LOPDP), European Union (GDPR), United States (CCPA, VCDPA, CPA)


1. INTRODUCTION, SCOPE, AND LEGALLY BINDING CONSENT

GrupoVolia S.A.S. ("Company," "we," "us," or "our") respects your privacy and is fundamentally committed to protecting it through our strict compliance with this Exhaustive Privacy Policy ("Policy"). This Policy governs the collection, processing, storage, encryption, and deletion of your data when you access the Volia Fitness website, mobile applications, API integrations, and AI-driven SaaS platform (collectively, the "Platform").

Given the highly sensitive, biological, and health-related nature of the data required to autonomously operate the Volia Fitness Artificial Intelligence (AI) protocols, this document is intentionally exhaustive.

By accessing, browsing, registering for an account, or purchasing a subscription on the Platform, you explicitly, affirmatively, and electronically consent to the data practices described in this Policy. If you do not agree with our policies and practices, your sole recourse is to abstain from using the Platform.

2. EXHAUSTIVE CATEGORIES OF INFORMATION WE COLLECT

To provide you with highly personalized, AI-generated fitness and nutritional templates, we must collect granular data. We collect this data directly from you when you provide it to us, automatically as you navigate the Platform, and from third-party API integrations (if authorized by you).

2.1 Personal Identifiable Information (PII):

  • Identity Data: First name, last name, date of birth, biological sex.
  • Contact Data: Email address, telephone number (including WhatsApp numbers for concierge services), billing address, and timezone.
  • Profile Data: Account credentials, hashed/encrypted passwords, profile photographs, and user preferences.

2.2 Sensitive Health, Biological, and Biometric Data ("Special Category Data"):

  • Biometrics: Height, current fasting weight, goal weight, body fat percentage estimates, waist circumference, and limb measurements.
  • Medical & Clinical History: Confirmed physician diagnoses (e.g., Type 1 or Type 2 Diabetes, Hypertension, Herniated Discs, PCOS), active pharmacological prescriptions, over-the-counter supplements, and severe food allergies (e.g., celiac disease, anaphylactic triggers).
  • Symptom & Progression Tracking: Ongoing check-in data, including sleep architecture (hours, quality), subjective energy levels (RPE), gastrointestinal distress markers (bloating, reflux), and uploaded biological progress photographs (front, side, back profiles).
  • Legal Note: Under the EU GDPR (Article 9) and the Ecuadorian LOPDP, this is classified as "Special Category Data." You explicitly grant us affirmative consent to process this data upon account creation solely for the purpose of generating your customized protocols.

2.3 Financial and Transactional Data:

  • Third-Party Processing: We utilize PCI-DSS compliant third-party payment processors (e.g., Stripe, Kushki). GrupoVolia S.A.S. does not collect, store, or process full credit card numbers, CVV codes, or bank routing information on our proprietary servers. We only store transaction history, billing tier status, and subscription renewal dates.

2.4 Automatically Collected Device, Technical, and Usage Data:

  • Technical Data: Internet Protocol (IP) addresses, browser type and version, time zone setting, browser plug-in types, operating systems (e.g., iOS, Android), and unique device identifiers (UDID).
  • Usage Data: Granular interaction data, including Uniform Resource Locators (URLs) clickstreams to, through, and from our Platform, page response times, lengths of visits to certain pages, AI prompt submission timestamps, and page interaction information (scrolling, clicks, and mouse-overs).

3. THIRD-PARTY WEARABLE AND API INTEGRATIONS

3.1 Opt-In Integrations: If you explicitly authorize the Platform to connect with any third-party health aggregators, wearable devices, or external biometric APIs, we will continuously ingest biometric data from those authorized sources (e.g., daily step counts, resting heart rate, HRV, sleep stages). 3.2 API Data Limitations: We use this ingested API data strictly to refine the AI's nutritional and recovery recommendations. We do not use third-party health API data for advertising or marketing purposes, nor do we sell this data to data brokers, in strict compliance with the developer guidelines of major health platforms.

3.3 Revocation of Device Access: You have the absolute right to disconnect and revoke our platform's access to your third-party health accounts (e.g., Terra API, Apple Health, Samsung Health) at any time via the "Disconnect Device" button in your Dashboard. By doing so, GrupoVolia S.A.S. will immediately cease the collection of new biometric data from these sources, and you assume responsibility for the consequent loss of biometric adaptation in the protocols generated by our AI.

4. HOW WE PROCESS AND USE YOUR DATA

We do not collect health data to sell it. Your data is used exclusively to operate, secure, and improve the Platform.

4.1 Primary Service Delivery (The AI Engine): Your health and biometric data is ingested by our backend architecture and processed via advanced Large Language Models (LLMs) to generate your custom workout, fasting, and nutritional protocols. 4.2 Human-in-the-Loop Operations: Your data is accessible to our internal administrative staff (specifically the lead coach) to perform manual overrides, safety checks, review check-ins, and provide VIP coaching feedback. 4.3 Automated Decision Making and Algorithmic Independence (GDPR Art. 22 Compliance): You explicitly acknowledge that the Platform uses Artificial Intelligence to make independent, automated decisions regarding your customized caloric intake and exercise routines. Human involvement is strictly limited to the initial design, architectural prompting, and philosophical framing of the AI logic. The AI operates autonomously to combine this proprietary logic with real-time internet research to optimize your protocol. Because these automated decisions do not produce "legal or similarly significant adverse effects" under GDPR Article 22, and because the final responsibility to review and execute the generated protocol rests entirely with you (the User), this architecture strictly complies with global restrictions on automated profiling. 4.4 Service Improvements (Aggregated Anonymization): We may aggregate and strictly anonymize user data to train our internal algorithms, identify broad fitness trends, and optimize the AI's logic. Once anonymized (stripped of PII), this data falls outside the scope of privacy laws and can no longer be linked to your identity. 4.5 Communication & Marketing: To send you routine updates, billing receipts, weekly newsletters, and security alerts. You may opt-out of marketing communications at any time, but you cannot opt-out of critical transactional or security emails.

5. DATA SHARING AND THIRD-PARTY SUB-PROCESSORS

GrupoVolia S.A.S. will NEVER sell, rent, or lease your Personal Identifiable Information or Sensitive Health Data to third-party data brokers, advertising networks, or pharmaceutical companies. We only share data with highly vetted sub-processors required to operate the business:

  • Cloud Infrastructure (Google Cloud / Firebase): Your data is securely hosted on enterprise-grade cloud servers.
  • AI Providers (Google Gemini / OpenAI): Data is transmitted via encrypted APIs to generate protocols. Crucially, we have strict Data Processing Agreements (DPAs) in place ensuring that your specific, identifiable health data is treated ephemerally (zero data retention) and is explicitly prohibited from being used by these companies to train their public or foundational AI models.
  • WhatsApp / Meta (Data Wall): We utilize the WhatsApp Business API for the Volia AI Coach. However, due to security compartmentalization, WhatsApp is strictly barred from handling sensitive medical data, bloodwork, or billing info. The WhatsApp bot will only process routine workout, meal plan, and FAQ queries. Any sensitive inquiries must be handled securely within the encrypted web dashboard.
  • Payment Processors (Stripe, Kushki): For the secure execution of recurring subscription billing.
  • Business Transfers (M&A): In the event that GrupoVolia S.A.S. is involved in a merger, acquisition, reorganization, or sale of assets, your data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Platform of any change in ownership.
  • Legal Compliance & Subpoenas: We may disclose your data if required by a valid subpoena, court order, or governmental request from a competent jurisdiction, or to protect the safety of our users (e.g., if we believe a user is in imminent physical danger).

6. COOKIE POLICY AND TRACKING TECHNOLOGIES

Our Platform uses all forms of cookies, web beacons, tracking pixels, local storage, and similar tracking technologies to distinguish you from other users, optimize our global advertising, and analyze traffic patterns.

  • Strictly Necessary Cookies: Required for the foundational operation and security of the Platform (e.g., session management, authentication).
  • Analytical/Performance Cookies: Allow us to recognize and count the number of visitors and map how visitors move around the Platform, utilizing various third-party analytics providers.
  • Targeting and Advertising Cookies: Used within our marketing funnels to record your visit, the pages you interacted with, and the links you followed. We utilize these across various advertising networks (social media, search engines, programmatic display) to deliver highly targeted advertisements. We strictly DO NOT share your internal Sensitive Health Data or biometrics with external advertising networks.
  • Do Not Track (DNT) Signals: At this time, our Platform does not universally respond to browser "Do Not Track" signals.

7. INTERNATIONAL DATA TRANSFERS (CROSS-BORDER COMPLIANCE)

GrupoVolia S.A.S. is a registered Ecuadorian corporation. However, our server architecture (Google Cloud Platform) relies on data centers that may be located in the United States, the European Union, or elsewhere. By using the Platform, you acknowledge and consent to the transfer, storage, and processing of your data across international borders. We ensure that all international transfers from the European Economic Area (EEA) comply with the European Commission's Standard Contractual Clauses (SCCs) and robust encryption protocols to maintain an adequate level of data protection.

8. DATA SECURITY, ENCRYPTION, AND BREACH PROTOCOLS

We implement draconian security measures to protect your Sensitive Health Data from accidental loss, unauthorized access, alteration, and disclosure.

  • Encryption at Rest: All biometric and open-text medical data stored in our databases (e.g., Google Firestore) is secured using military-grade AES-256 encryption.
  • Encryption in Transit: All data transmitted between your device, our servers, and our AI sub-processors is encrypted using strict Transport Layer Security (TLS 1.2 or higher).
  • Access Controls: Access to unencrypted user data is strictly limited to authorized administrative personnel on a "need-to-know" basis, protected by Multi-Factor Authentication (MFA).
  • Data Breach Notification Protocol: In the highly unlikely event of a security breach that compromises your unencrypted PII or Health Data, GrupoVolia S.A.S. commits to notifying affected users and the relevant supervisory authorities (e.g., the Ecuadorian Data Protection Authority) within 72 hours of becoming aware of the breach, detailing the nature of the breach and the mitigation steps taken.

9. THE EXPLICIT HIPAA DISCLAIMER (UNITED STATES COMPLIANCE)

While GrupoVolia S.A.S. voluntarily utilizes enterprise-grade, "HIPAA-level" security protocols (such as AES-256 encryption and strict access controls) to protect your privacy, we are NOT a "Covered Entity" or a "Business Associate" under the US Health Insurance Portability and Accountability Act (HIPAA). Because Volia Fitness operates as a consumer fitness and wellness SaaS platform—and not as a medical provider, hospital, pharmacy, or health insurance clearinghouse—the strict regulatory frameworks, audit requirements, and liability statutes of HIPAA do not legally apply to our operations. By using the Platform, you explicitly acknowledge that your data is protected by our strict internal policies, but you have no legal recourse under HIPAA regulations.

10. YOUR DATA PRIVACY RIGHTS (GDPR, CCPA, VCDPA, & LOPDP)

Regardless of your global location, GrupoVolia S.A.S. grants you the maximum privacy rights afforded by the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act (VCDPA), and the Ecuadorian Ley Orgánica de Protección de Datos Personales (LOPDP).

You possess the absolute legal right to:

  • The Right to Access (Data Subject Access Request - DSAR): Request a complete, transparent copy of all personal and biometric data we hold about you.
  • The Right to Rectification: Correct any inaccurate or incomplete health or account data immediately via your dashboard.
  • The Right to Erasure ("Right to be Forgotten"): You may request the permanent deletion of your account and all associated health data from our active servers. (Exceptions: We may retain anonymized data, or data required to establish legal defenses, or billing records required for strict tax compliance in Ecuador).
  • The Right to Data Portability: Request your data in a structured, commonly used, and machine-readable format (JSON or CSV) for transfer to another service.
  • The Right to Restrict Processing: Demand that we halt the processing of your data by our AI engines (which will result in the inability to generate new protocols).
  • The Right to Opt-Out of Sale (CCPA): While we do not sell your data, California residents have the right to explicitly opt-out of the "sale" or "sharing" of personal information for cross-context behavioral advertising.

Verification and Execution: To exercise any of these rights, you must submit a written request to our Data Protection Officer at: privacy@voliafitness.com. To protect against social engineering, we will require you to verify your identity (e.g., confirming account details or responding from the registered email) before processing the request. We will process all verifiable requests within thirty (30) days.

11. DATA RETENTION LIFECYCLE

We will retain your Personal Information and Sensitive Health Data only for as long as your subscription is active, or as long as is necessary for the purposes set out in this Policy. Once you cancel your subscription and explicitly request account deletion, your biometric data will be permanently wiped from our active databases within 30 days. We will retain strictly anonymized metrics (which cannot identify you) and legally required financial transaction logs for up to seven (7) years to comply with Ecuadorian SRI tax audits.

12. CHILDREN'S PRIVACY (COPPA COMPLIANCE)

The Volia Fitness Platform involves extreme physical exertion, caloric deficits, and severe macronutrient alterations. Our Platform is strictly intended for adults. We do not knowingly collect personal data from anyone under the age of 18. If you are under 18, do not use or provide any information on this Platform. If we become aware that we have collected personal data from a minor without parental consent, we will take immediate steps to permanently purge that information from our servers.

13. GOVERNING LAW AND DISPUTE RESOLUTION

This Privacy Policy shall be governed by and construed strictly in accordance with the laws of the Republic of Ecuador, specifically aligning with the Ley Orgánica de Protección de Datos Personales (LOPDP). Any disputes arising from the processing of your data or this Policy shall be subject to the exclusive jurisdiction of the competent courts in Guayaquil, Ecuador, and subject to the Binding Arbitration and Class Action Waivers as exhaustively detailed in our Terms of Service.

14. CHANGES TO THIS PRIVACY POLICY

We reserve the right to update or radically alter this Privacy Policy at any time to reflect changes in global data protection laws, shifts in our AI architecture, or new third-party integrations. We will notify you of any material changes by sending an email to the primary address specified in your account or by placing a prominent, unmissable notice on our Platform prior to the change becoming effective.


BY CREATING AN ACCOUNT, YOU ELECTRONICALLY CONSENT TO THE COLLECTION, PROCESSING, ENCRYPTION, AND INTERNATIONAL TRANSFER OF YOUR SENSITIVE HEALTH DATA AS EXHAUSTIVELY OUTLINED IN THIS PRIVACY POLICY.

Annex: Smart Devices and Wearables Integration

Revocation of Device Access: You have the absolute right to disconnect and revoke our platform's access to your third-party health accounts (e.g., Terra API, Apple Health, Samsung Health) at any time via the "Disconnect Device" button in your Dashboard. By doing so, GrupoVolia S.A.S. will immediately cease the collection of new biometric data from these sources, and you assume responsibility for the consequent loss of biometric adaptation in the protocols generated by our AI.