Privacy Policy
Version 2.0 · Effective 5 September 2026
1. Who is responsible for your data?
Eliving ApS is the data controller for Performance By Eliving.
CVR no. 46348443
Koralvænget 5
6640 Lunderskov
Denmark
Email: info@eliving.dk
Website: performancebyeliving.com
2. What information do we process?
Information you provide
- Account information, such as email address, password hash, security settings and acceptance records.
- Profile and coaching information, such as name, timezone, cycling level, FTP, goals, event dates, available training time and preferred days.
- Training-plan information, completed-session status, coach conversations, feedback, plan approvals and coach memory you choose to confirm.
- Information you enter about recovery, sleep, injuries, illness, limitations or other health-related circumstances. This may constitute sensitive health data.
- Support messages and other communications with us.
Information from integrations you connect
Depending on the permissions and provider, we may receive activity and workout data, dates, duration, distance, elevation, heart rate, power, cadence, energy estimates, sleep, HRV, resting heart rate, readiness, strain and recovery scores from Strava, WHOOP, Oura or Intervals.icu. We also store connection tokens and, where you use your own developer app or API key, encrypted credentials needed to operate the connection.
Technical information
We process security and operational data such as session identifiers, authentication events, IP address and basic server logs. We use a strictly necessary session cookie to keep you signed in and protect access.
Optional analytics and marketing technologies are disabled by default. If you consent, analytics may help us understand use of the service, while marketing technologies may help us measure campaigns and relevant advertising. You can accept, reject or choose these categories separately. Your choice is stored in your browser; withdrawing consent stops future optional tracking on that browser.
3. Where does the information come from?
Most information comes directly from you. Integration data comes from the service you deliberately connect. We may also create derived information, such as recovery recommendations, training analyses, plan suggestions and coach-memory summaries, based on these inputs.
4. Why and on what legal basis do we process it?
- Provide the service and manage your account: necessary to perform our agreement with you (GDPR Article 6(1)(b)).
- Process health-related data for personalised coaching: based on your explicit consent (Articles 6(1)(a) and 9(2)(a)). You may withdraw this consent at any time. Withdrawal does not affect earlier lawful processing, but relevant features may no longer work.
- Security, fraud prevention, troubleshooting and service improvement: our legitimate interests in operating a safe and effective service (Article 6(1)(f)). We balance those interests against your rights.
- Accounting, disputes and legal compliance: compliance with legal obligations (Article 6(1)(c)) and, where relevant, establishment, exercise or defence of legal claims.
- Email marketing: only with the permission required under applicable marketing law. You can unsubscribe at any time without affecting service messages.
- Analytics and advertising measurement: only with your consent (GDPR Article 6(1)(a)). You can withdraw that consent at any time through Cookie settings.
You are not required by law to provide personal data. Basic account information is needed to create and secure an account. Training information is needed for personalised planning. Optional integration and health data are needed only for the connected and recovery-aware features that use them.
5. AI processing and profiling
Performance uses AI providers to generate coach messages, training plans, analyses and recommendations. Relevant parts of your profile, training history, connected recovery data and coach conversation may be included in prompts when needed for the requested feature. We instruct service providers to process data on our behalf and apply data-minimisation measures.
The service uses profiling in the everyday sense that recommendations are personalised to your goals, history and recovery. It does not make solely automated decisions that produce legal or similarly significant effects about you. AI recommendations can be wrong and should be reviewed critically, especially where health or safety is involved.
6. Who receives the information?
Access is limited to people and suppliers who need it for the purposes described above. Categories of recipients include:
- Hosting, infrastructure, security and backup providers.
- AI service providers, currently OpenAI and, where configured as a fallback, Anthropic.
- Transactional email provider, currently Resend.
- Integration providers you choose to connect, currently including Strava, WHOOP, Oura and Intervals.icu. Data may flow both from and, for supported workout-sync features, to the selected provider.
- Meta Platforms Ireland Limited, when you consent to marketing technologies, for campaign measurement through Meta Pixel.
- Professional advisers, authorities or other parties where required by law or necessary to protect legal rights.
Zwift and TrainingPeaks workout files are downloaded by you for your own import; we do not send those files directly to those services unless a specific delivery feature clearly tells you otherwise.
We do not sell your personal data.
7. Transfers outside the EU/EEA
Some suppliers or integration providers may process data in countries outside the EU/EEA, including the United States. Where required, we rely on an EU adequacy decision, including the EU–US Data Privacy Framework for certified recipients, or approved Standard Contractual Clauses together with supplementary safeguards where appropriate. You can contact us for more information about the relevant transfer safeguard.
8. How long do we keep information?
- Account, profile, plans, coaching and imported training data: while your account is active. After a verified deletion request, we delete or anonymise it without undue delay, normally within 30 days, unless retention is required by law or for a specific legal claim.
- Integration credentials and tokens: until you disconnect the integration, close the account or the credentials expire, subject to short-lived technical backups.
- Authentication and security records: only as long as reasonably needed to protect the service and investigate incidents.
- Accounting records for the paid Standard plan: for the period required by Danish bookkeeping law, generally five years after the relevant financial year.
- Backups: removed on the normal backup rotation and protected from ordinary use until deletion.
We may retain information longer if necessary to comply with law, resolve a dispute or establish, exercise or defend a legal claim. Where possible, we restrict its use during that period.
9. Your choices and rights
Subject to the conditions in data-protection law, you may:
- request access to and a copy of your personal data;
- have inaccurate information corrected;
- request deletion or restriction;
- object to processing based on legitimate interests;
- receive certain data in a portable format;
- withdraw consent at any time; and
- complain to a supervisory authority.
You can disconnect integrations in your profile. To exercise a right, close your account or withdraw health-data consent, email info@eliving.dk. We may need to verify your identity and will normally respond within one month.
You can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, through datatilsynet.dk. You may also contact the supervisory authority in the EU/EEA country where you live or work.
10. Security
We use technical and organisational measures intended to protect personal data, including encrypted transport, password hashing, multi-factor authentication, access controls and encryption of stored integration secrets. No online service can guarantee absolute security. Please use a unique password and contact us promptly if you suspect misuse.
11. Children
Performance is intended for adults aged 18 or over. We do not knowingly offer the service to children. Contact us if you believe a child has provided personal data so we can investigate and take appropriate action.
12. Changes to this policy
We may update this policy when the service, suppliers or law changes. We will publish the new version and effective date here. We will provide reasonable advance notice of material changes where appropriate and request renewed consent if the law requires it.