1. Data Controller
TEMPO ("we", "us", "our") is the data controller responsible for the personal data collected through this service. Contact: privacy@tempo.coach
2. What Data We Collect
We collect the minimum data necessary to provide the TEMPO adaptive coaching service:
| Category | Examples | Source | |---|---|---| | Account data | Email address, display name | Registration form | | Training activity data | GPS routes, heart rate, power, pace, cadence, duration, distance, splits | Garmin Connect, Strava | | Biometric data | VO₂ max estimate, resting heart rate, heart rate zones, FTP | Garmin Connect | | Usage data | Pages visited, feature interactions, session duration | Plausible Analytics (cookieless) |
We do not collect payment card numbers (handled by our payment processor), government IDs, or sensitive personal categories as defined under GDPR Article 9.
3. Lawful Basis for Processing
We process your personal data on the following lawful bases under GDPR Article 6:
- Contract (Art. 6(1)(b)): processing your training activity data and account data is necessary to perform the coaching service you signed up for — generating plans, tracking progress, and providing analysis.
- Consent (Art. 6(1)(a)): for any optional data integrations (e.g. connecting Strava) and for analytics collection. You may withdraw consent at any time.
- Legitimate interests (Art. 6(1)(f)): for security logging and fraud prevention, where our interests are not overridden by your rights.
4. Data Processors (Third Parties)
We share data with the following processors, each bound by data-processing agreements:
Garmin Connect
Your Garmin account activity data (workouts, biometrics, device data) is fetched via the Garmin Health API on your behalf after you explicitly connect your account. Garmin is an independent data controller for your Garmin account; we act as a processor when reading your data under your authorisation. See Garmin's Privacy Policy.
Strava
If you choose to connect Strava, we access your activity data via the Strava API under your OAuth authorisation. Strava is an independent data controller for your Strava account. See Strava's Privacy Policy.
Plausible Analytics
We use Plausible Analytics for website usage statistics. Plausible is:
- Cookieless — no cookies are set, no persistent identifiers are stored
- EU-hosted — all data is processed on servers in the European Union (Germany)
- GDPR-compliant by design — no personal data is transferred outside the EU
Plausible collects only aggregated, anonymous metrics (page views, referrers, device type). It does not track individual users across sessions or sites. See Plausible's Data Policy.
5. Data Subject Rights
Under GDPR Chapter III, you have the following rights regarding your personal data:
- Right of access (Art. 15): request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data.
- Right to erasure / "right to be forgotten" (Art. 17): request deletion of your personal data, subject to legal retention obligations.
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format (JSON/CSV) and transmit it to another controller.
- Right to object (Art. 21): object to processing based on legitimate interests or for direct marketing.
- Right to restrict processing (Art. 18): request that we limit how we use your data in certain circumstances.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at privacy@tempo.coach. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority (e.g. the ICO in the UK, or the Garante in Italy).
6. Data Retention
| Data type | Retention period | |---|---| | Account data | For the duration of your account, plus 90 days after deletion request | | Training activity data | For the duration of your account, plus 30 days | | Security and audit logs | 12 months | | Anonymous analytics (Plausible) | 13 months rolling (aggregated only) |
7. Analytics Are Cookieless
Our analytics use Plausible Analytics, which requires no cookies and stores no personal data about individual visitors. No cookie consent banner is shown because none is needed. See Plausible's explanation.
8. Contact
For privacy-related enquiries, to exercise your data subject rights, or to raise a concern:
Email: privacy@tempo.coach
We aim to respond to all requests within 30 days. For complex requests we may extend this by a further 60 days, in which case we will notify you.

