Effective date: 14. 08. 2026
Last updated: 14. 08. 2026
Version: 1.0
Guavi is operated by Sans Decorum d.o.o., a company registered in the Republic of Slovenia under registration number 8607222000, with its registered office at Topniška ulica 70, Suite 76, 1000 Ljubljana, Slovenia ("Guavi", "we", "us", "our").
We are the controller of the personal data described in this policy within the meaning of Article 4(7) of Regulation (EU) 2016/679 ("GDPR").
Guavi is available as a mobile application for iOS and Android and as a web application (together, the "App").
Contact for privacy matters: [email protected]
General contact: [email protected]
We collect the minimum data needed to verify that you visited a partner gym, award you points for that visit, and deliver the reward you redeem those points for.
The most important things to know:
This summary is for orientation only. The sections below govern.
Email address, password (stored only as a salted hash and never accessible to us in readable form), chosen username, and profile picture if you upload one.
Your username and profile picture are the only elements visible to other users. You can change both at any time in your profile settings.
We process location data in two distinct ways, on two distinct legal bases. See section 4.
Foreground check-in. When you open the App and start a check-in at a partner gym, we compare your device's position with the coordinates of that gym to confirm you are present.
Background arrival detection (optional). If you enable it, your device monitors a small number of circular geographic zones around partner gym locations. When your device crosses into or out of one of those zones, the operating system notifies the App. We record the entry timestamp and the exit timestamp and calculate the elapsed time to determine whether the minimum dwell requirement for a point award has been met.
What this means in practice:
The rewards you redeem, the points balance and transaction history associated with your account, the discount or product codes issued to you, and the date they were issued.
Where a reward is a physical item requiring shipment, we collect your delivery name, address, and phone number solely to fulfil that shipment.
Device model, operating system and version, App version, language and region settings, IP address, a device identifier, push notification token, and crash and diagnostic logs.
Which screens you open, which features you use, session length and frequency, and how you arrived at the App.
Year of birth and gender, if you choose to provide them. This is optional and the App is fully functional without it.
Messages you send to our support, brand partnership, or privacy contacts, and our replies.
We do not collect payment card details. We do not collect health, medical, biometric, or body composition data. We do not ask for and do not want information about your medical conditions, and you should not send it to us.
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and operating your account | Account data | 6(1)(b) performance of a contract |
| Verifying a check-in you actively start in the App | Foreground location | 6(1)(b) performance of a contract |
| Detecting arrival at a partner gym while the App is closed | Background location | 6(1)(a) consent — and Art. 9(2)(a) explicit consent, see 4.1 |
| Awarding, calculating, and displaying points | Visit records, reward data | 6(1)(b) performance of a contract |
| Issuing reward codes and shipping physical rewards | Reward data, delivery address | 6(1)(b) performance of a contract |
| Security, fraud prevention, and detecting fraudulent check-ins | Device data, visit records | 6(1)(f) legitimate interests |
| Diagnosing crashes and keeping the App stable | Device data, crash logs | 6(1)(f) legitimate interests |
| Understanding aggregate usage to improve the App | Usage data, demographic data | 6(1)(f) legitimate interests |
| Analytics and advertising cookies, pixels, and SDKs | Usage data, device identifiers | 6(1)(a) consent |
| Marketing emails and push notifications | Account data | 6(1)(a) consent |
| Responding to your support messages | Communications | 6(1)(f) legitimate interests |
| Complying with accounting, tax, and consumer law obligations | Reward and transaction data | 6(1)(c) legal obligation |
| Establishing, exercising, or defending legal claims | As relevant | 6(1)(f) legitimate interests |
| Corporate transactions | As set out in section 9 | 6(1)(f) legitimate interests |
Where we rely on legitimate interests, we have carried out and documented a balancing assessment. You may request a summary of it at [email protected], and you may object at any time under Article 21 (see section 10).
A record of your attendance at a gym may, over time, allow inferences about your physical activity. We do not treat this as health data and we do not use it to infer anything about your health, but because Article 9(1) GDPR and Recital 35 are drawn broadly, we take the cautious position and rely on your explicit consent under Article 9(2)(a) for background location monitoring.
We will ask for that consent separately and in clear terms. We will not bundle it with anything else.
You can use Guavi, check in at partner gyms, earn points, and redeem rewards without granting background location access, by opening the App at the gym and checking in manually. Declining background location does not reduce the points you can earn, restrict which rewards you can claim, or otherwise degrade the service. It only means you have to open the App yourself.
We record, for each consent you give: what you consented to, the version of the notice shown to you, and the date and time.
You can withdraw any consent at any time, and it is as easy to withdraw as it was to give:
Withdrawal takes effect immediately and stops future processing. It does not affect the lawfulness of processing carried out before withdrawal. Points you have already earned remain in your account. Visit records already created are retained under the schedule in section 8 unless you also ask us to delete them.
Points are awarded automatically when a verified visit meets the minimum dwell requirement. This is a simple rule applied consistently to everyone and is not a decision producing legal effects or similarly significant effects on you within the meaning of Article 22(1) GDPR.
We do not profile you to set different prices, different reward eligibility, or different terms from other users.
We do not sell personal data. We share it only in the following categories:
Cloud infrastructure and database providers. Google LLC / Google Cloud EMEA Limited (Firebase, Cloud Firestore, Firebase Authentication, Cloud Functions) and Vercel Inc. These host the App and its database and act as our processors under Article 28 GDPR.
App distribution platforms. Apple Inc. and Google LLC, in connection with distribution, crash reporting, and push notification delivery.
Analytics and advertising providers. [LIST — e.g. Google Analytics, Meta Pixel], where you have consented. These providers receive online identifiers and usage events. Contrary to what is sometimes claimed, such identifiers are personal data under Article 4(1) GDPR, and we do not describe this data as anonymous.
Partner gyms. Partner gyms receive aggregate, non-identifying statistics about visit volumes. They do not receive your name, email, username, or individual visit history from us, and we do not cross-reference your Guavi account with their membership records.
Partner brands. When you redeem points for a reward, the brand receives an anonymous code and the fact that a code was issued. The brand does not receive your name, email, username, or gym attendance data from us. If you then use the code in the brand's own shop, that purchase is governed by the brand's own privacy policy and the brand is an independent controller for it. We are not responsible for their processing.
Logistics providers, where a physical reward has to be shipped to you.
Professional advisers — lawyers, accountants, and auditors — bound by professional confidentiality.
Public authorities, where we are legally required to disclose.
Acquirers and successors, as described in section 9.
Every processor acting on our behalf is bound by a written data processing agreement meeting the requirements of Article 28(3) GDPR.
Our primary database and application infrastructure are hosted in the European Union ([CONFIRM REGION — e.g. europe-west3, Frankfurt]).
Some of our providers are established in, or may access data from, the United States. Where personal data is transferred outside the European Economic Area, we rely on one or more of the following safeguards under Chapter V GDPR:
You may request a copy of the relevant safeguards at [email protected].
| Category | Retention period |
|---|---|
| Account data | For the life of your account, then 30 days after deletion |
| Visit and check-in records (identified) | 24 months from the date of the visit |
| Visit records (aggregated) | Indefinitely, in irreversibly anonymised form — see below |
| Points balance and transaction history | For the life of your account, then as required by accounting law |
| Reward codes issued | 24 months, or the code's validity period plus 12 months, whichever is longer |
| Delivery addresses | Until delivery is complete, then as required by accounting and tax law |
| Invoicing and accounting records | 10 years, as required under Slovenian tax and accounting legislation |
| Device and crash data | 12 months |
| Usage and analytics data (identified) | 14 months |
| Support correspondence | 24 months from the last message |
| Consent records | For the duration of the consent plus 3 years |
| Data relevant to a legal claim | Until the claim is finally resolved |
After the identified retention period expires, we may retain visit and usage data in irreversibly anonymised, aggregated form — for example, cohort-level retention curves and visit-frequency distributions that cannot be linked back to any individual, directly or indirectly, by us or anyone else. Anonymised data of this kind is outside the scope of GDPR under Recital 26 and we may retain and use it without time limit.
If Guavi is involved in a merger, acquisition, investment, financing, corporate reorganisation, insolvency, or a sale of all or part of its business or assets, personal data may be:
Our legal basis for this disclosure is our legitimate interest in the continuity and transferability of our business under Article 6(1)(f) GDPR.
Where a transaction results in a change of the controller of your data:
Under Articles 15 to 22 GDPR you have the right to:
To exercise any right, contact [email protected]. We will respond within one month of receiving your request, extendable by a further two months where the request is complex, in which case we will tell you within the first month (Article 12(3)). Exercising your rights is free of charge unless a request is manifestly unfounded or excessive (Article 12(5)).
Right to complain. If you believe we have processed your data unlawfully, you may lodge a complaint with the Slovenian supervisory authority:
Informacijski pooblaščenec Republike Slovenije
Dunajska cesta 22, 1000 Ljubljana, Slovenia
[email protected] | +386 1 230 97 30 | www.ip-rs.si
You may also complain to the supervisory authority in your country of residence or place of work, and you have the right to an effective judicial remedy under Article 79 GDPR.
Guavi is not intended for children under 15. You must be at least 15 years old to create an account, in line with the age of consent for information society services set under Slovenian law implementing Article 8(1) GDPR.
If you are under 15, do not create an account. If we learn that we hold data relating to a person under 15 without the required authorisation of a holder of parental responsibility, we will delete it without undue delay.
If you are a parent or guardian and believe your child has created an account, contact [email protected] and we will act on it.
We implement technical and organisational measures appropriate to the risk, as required by Article 32 GDPR, including:
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Informacijski pooblaščenec within 72 hours as required by Article 33, and we will inform you directly without undue delay where the breach is likely to result in a high risk to you, as required by Article 34.
We may update this policy. Where a change is material — for example, a new purpose, a new category of recipient, a change of controller, or a change to how location data is used — we will:
Non-material changes, such as corrections and clarifications, will be published here with an updated version number and date. We keep previous versions and will provide them on request.
Privacy and data protection: [email protected]
Postal: Sans Decorum d.o.o., Topniška ulica 70, Suite 76, 1000 Ljubljana, Slovenia