Privacy Policy
1. Who We Are and What This Policy Covers
Individual entrepreneur Karnaukh Iryna Oleksandrivna, registered in the Unified State Register of Legal Entities, Individual Entrepreneurs and Public Formations of Ukraine, taxpayer registration number 3029410706 ("IK Pilates", "we", "us" or "our"), operates the IK Pilates studios in Kharkiv and the platform through which they are booked.
We are the owner of the personal data files within the meaning of Article 2 of the Law of Ukraine "On Personal Data Protection" No. 2297-VI of 1 June 2010 ("the Law") for all processing described in this Policy. Our contact details are set out in Section 13.
This Policy applies to personal data we process when you visit ikpilates.com, create an account on the IK Pilates platform, use our iOS or Android applications, attend classes or personal training at our Kharkiv studios, join a waiting list, contact us, or otherwise interact with us as a client, prospective client or instructor.
Our Bulgarian operations are conducted by a separate legal person, IK Pilates Studio EOOD, which acts as an independent controller for data collected in Bulgaria under Regulation (EU) 2016/679. If you are located in the European Economic Area, or you are a client of our Sofia studio, the Bulgarian version of this Policy applies to you and offers the protections of that Regulation.
2. Legal Framework
We process personal data in accordance with Article 32 of the Constitution of Ukraine, the Law of Ukraine "On Personal Data Protection" No. 2297-VI, the Law of Ukraine "On Information" No. 2657-XII, the Law of Ukraine "On Electronic Commerce" No. 675-VIII, the Law of Ukraine "On Electronic Communications" No. 1089-IX, and the Typical Procedure for the Processing of Personal Data approved by the Ukrainian Parliament Commissioner for Human Rights.
Ukraine is a party to Convention 108 of the Council of Europe for the Protection of Individuals with regard to Automatic Processing of Personal Data. Draft Law No. 8153 "On Personal Data Protection", which would align Ukrainian law with the General Data Protection Regulation and establish an independent supervisory authority, passed its first reading in the Verkhovna Rada on 20 November 2024 and is being prepared for a second reading. We monitor its progress and will update this Policy when it is adopted.
3. Categories of Personal Data We Process
We collect only the data we need to run a Pilates studio and the platform that supports it. We do not buy personal data and we do not build advertising profiles.
Identity and contact data. Given name, family name, display name, email address, telephone number in international format, preferred language and country, and the internal identifier we assign to you.
Account and authentication data. Password credentials held in hashed form by our authentication provider, authentication tokens, the list of active sessions and devices associated with your account, device type, application version, approximate location derived from your IP address at country level, and the date and time of each sign-in.
Booking and attendance data. Classes and personal training sessions you book, the studio, room and instructor concerned, booking status including cancellations, reschedules, waiting-list position and non-attendance, invitations you send or receive, and your class history.
Onboarding and preference data. Your training goals, experience level, preferred class times, preferred contact channels, how you heard about us, unit preferences and notification settings.
Data concerning health. Where you choose to provide it: pregnancy status, injuries, medical conditions and physical limitations relevant to safe practice. In our mobile applications, and only if you grant permission for each category separately, heart rate, heart rate variability, sleep, weight, recovery, steps, active energy, mindful minutes and workout records read from Apple Health or Google Health Connect. Under Article 7 of the Law, data concerning health belongs to the special categories of personal data whose processing is prohibited save on the grounds listed there, and is subject to the additional safeguards described in Section 5.
Payment and billing data. The reference and amount of bank transfers received, invoicing details where requested, and the record of payments made at the studio. We do not operate online card payments and we do not receive or store card numbers.
Communications data. Messages you send us through the contact form, by email, by telephone or by messenger, transactional emails we send you and their delivery status, push notification preferences and delivery logs, and any complaint correspondence.
Technical and security data. IP address stored in hashed form using a secret key, user agent, security event and audit records, anti-abuse challenge results, and error diagnostics.
Website usage data. Aggregate, cookieless measurement of page views as described in our Cookie Policy.
4. Purposes and Grounds for Processing
Article 11 of the Law sets out the grounds on which personal data may be processed. We rely on the following.
Consent of the data subject. Processing data concerning health, sending marketing communications, sending push notifications, reading data from Apple Health or Google Health Connect, and storing non-essential information on your device. Consent is specific and granular, is recorded, and may be withdrawn at any time under Article 8 of the Law without affecting the lawfulness of processing carried out before withdrawal.
Conclusion and performance of a transaction to which the data subject is a party. Creating and administering your account, taking and confirming bookings, managing waiting lists, reschedules and cancellations, delivering classes and personal training, issuing invoices and processing payments, and providing customer support.
Permission to process granted to the owner of the file by law. Keeping accounting and tax records as required by the Tax Code of Ukraine and the Law of Ukraine "On Accounting and Financial Reporting in Ukraine", responding to lawful requests from competent authorities, and handling requests and complaints under Article 8 of the Law.
Protection of the legitimate interests of the owner of the file or of third parties. Securing our platform against unauthorised access, fraud and abuse, maintaining audit trails, preventing repeated non-attendance, measuring website performance in aggregate, improving our services, and establishing or defending legal claims. Such processing is carried out only where the rights and freedoms of the data subject are not infringed.
Protection of the vital interests of the data subject. In a medical emergency at the studio, disclosing relevant health information to emergency services.
5. Data Concerning Health and Additional Safeguards
Health data is never required to browse our website or to hold an account. You may use the platform fully without providing any health information; where a health feature is declined, the relevant screen simply shows its empty state.
Where you do provide health data, we process it on the basis of your unambiguous consent within the meaning of Article 7 of the Law, and we apply the following safeguards.
Sensitive fields, including pregnancy status and injury records, are encrypted at rest at column level using PGP symmetric encryption with a key derived per client, so that a single compromised value does not expose other clients.
Consent is recorded per category and enforced on the server, so withdrawing consent for one category never affects another.
Health data is used exclusively to make your practice safe and to power features you have asked for. It is never used for advertising, never sold, never shared with third parties for their own purposes, and never used for tracking across applications or websites.
Only the instructors and studio staff who need it in order to supervise your session can view the health information you have chosen to share, and only in a form limited to what is necessary for safe instruction. All such persons are bound by written confidentiality undertakings as required by Article 10 of the Law.
Where your relationship with the studio as a client ends, encrypted health fields are scheduled for erasure and are automatically nulled after a grace period of thirty days, with an audit record of the purge.
6. Recipients and Third Parties
We do not sell personal data. We share it only with the following categories of recipient.
Our instructors and studio staff, under written confidentiality obligations and on a need-to-know basis.
Service providers who process data on our behalf and on our instructions under written agreements requiring confidentiality and appropriate security. As at the date of this Policy these are:
Supabase - authentication, database and realtime services, European Union region hosting Railway - application hosting for our backend interfaces Vercel - hosting and cookieless aggregate analytics for our website Resend - delivery of transactional email Google (Firebase Cloud Messaging) - delivery of push notifications Google (Sheets API) - read-only import of legacy studio schedules Cloudflare - protection of our contact form against automated abuse Apple - delivery of push notifications to iOS devices
Our accountant and, where necessary, our legal adviser, subject to professional confidentiality.
State authorities and courts, where disclosure is required by law or is necessary to establish or defend a legal claim. Under Article 14 of the Law, disclosure to third parties is permitted only with the consent of the data subject or on the grounds provided by law, and each such disclosure is recorded.
7. Cross-Border Transfer of Personal Data
Article 29 of the Law permits the transfer of personal data to foreign parties where the receiving state provides adequate protection of personal data. Member States of the European Economic Area and states party to Convention 108 are deemed by law to provide such protection.
Our principal data stores are located within the European Union. A limited number of providers, principally those delivering push notifications and email, may process limited data outside the European Economic Area. In such cases we rely on the transfer safeguards offered by the provider, including the Standard Contractual Clauses of the European Commission, together with encryption in transit and at rest and minimisation of the data transferred.
Push notification payloads are limited to the information necessary to display the notification and do not contain health data.
8. Automated Processing
We do not take decisions concerning you based solely on automated processing that produce legal consequences for you.
Some features order or filter information automatically, for example waiting-list position by time of request or the suggestion of available slots. These operations do not evaluate your personal characteristics and do not produce legal consequences.
9. Retention Periods
We keep personal data only for as long as necessary for the purposes for which it was collected, and then delete or irreversibly anonymise it.
Account and profile data - for the life of your account, then erased on deletion subject to the tombstone rule below Booking and attendance records - 3 years from the end of the year in which the service was provided, corresponding to the general limitation period under the Civil Code of Ukraine Primary accounting documents and tax records - for the periods required by the Tax Code of Ukraine and the rules of the State Archival Service Data concerning health - for the life of your client relationship, then nulled 30 days after that relationship ends Contact form and enquiry correspondence - 2 years from the last exchange Notification delivery logs - 1 year Security and audit records - 2 years Records of revoked sessions - 90 days Consent record for information stored on your device - 12 months Inactive accounts - flagged after 24 months without activity and subject to deletion after notice
When you request deletion of your account, we place it in a thirty-day grace period during which you may cancel the request. After that period all purely personal records are erased. Records that we are required to retain, such as booking and accounting entries, are retained without identifying data: your identity record is reduced to a data-free tombstone, which depersonalises every remaining record that refers to it.
10. Your Rights
Article 8 of the Law gives you the following rights in relation to your personal data.
To know the sources of collection, the location of your personal data, the purposes of processing, and the location or place of residence of the owner or manager of the personal data file.
To receive information about the conditions under which access to your personal data is granted, and in particular information about third parties to whom your data is transferred.
To access your personal data.
To receive, not later than thirty calendar days from the date of receipt of your request, an answer as to whether your personal data is processed and to receive the content of that data.
To present a reasoned demand objecting to the processing of your personal data.
To present a reasoned demand for the change or destruction of your personal data by any owner or manager, where the data is processed unlawfully or is unreliable.
To protect your personal data against unlawful processing and accidental loss, destruction or damage caused by intentional concealment, failure to provide, or untimely provision of data, and to protection against information that is unreliable or discredits your honour, dignity or business reputation.
To lodge a complaint concerning the processing of your personal data with the Ukrainian Parliament Commissioner for Human Rights or with a court.
To apply legal remedies in the event of a breach of personal data protection legislation.
To make reservations concerning the restriction of the right to process your personal data when giving consent.
To withdraw consent to the processing of personal data.
To know the mechanism of automatic processing of personal data.
To be protected against an automated decision that has legal consequences for you.
11. How to Exercise Your Rights
Most rights can be exercised directly in your account. Your profile and preferences can be viewed and edited at any time; active sessions and devices can be reviewed and revoked individually; notification and health consents can be granted or withdrawn per category; and account deletion, together with a copy of your data, can be requested from your account settings.
Alternatively, send a request to the address in Section 13. A request should state your name, contact details, a description of the right you wish to exercise and, where relevant, the data concerned. We will answer within thirty calendar days of receipt, as required by Article 16 of the Law.
Where a request is refused in whole or in part, we will state the reason and the legal ground, and inform you of your right to complain to the Ukrainian Parliament Commissioner for Human Rights or to a court.
12. Security
We apply the organisational and technical measures required by Article 24 of the Law and appropriate to the risk. These include encryption of all data in transit using TLS, column-level encryption at rest for sensitive health fields, per-client key derivation, row-level security in our database, asymmetric signing of authentication tokens with short lifetimes, a session revocation list, hashing of IP addresses with a secret key, access control by role on the principle of least privilege, audit logging of privileged operations, a content security policy on our web properties, and written confidentiality undertakings from every person who has access to personal data.
Where we become aware of unlawful access to personal data or of an incident affecting its security, we assess the incident, take containment measures, record it, and inform the data subjects concerned and the Ukrainian Parliament Commissioner for Human Rights where the incident may affect the rights of data subjects.
13. Contact Details
Individual entrepreneur Karnaukh Iryna Oleksandrivna Taxpayer registration number: 3029410706 Registered address: prov. Otakara Yarosha 12a, Kharkiv, 61045, Ukraine Studios: prov. Otakara Yarosha 12a and prov. Otakara Yarosha 22b, Kharkiv, 61045, Ukraine Email: studio@ikpilates.com Data protection enquiries: privacy@ikpilates.com Telephone: +380 67 508 4343 Website: ikpilates.com
A person responsible for the organisation of the work relating to the protection of personal data, within the meaning of Article 24 of the Law, is designated by internal order. Requests concerning personal data may be addressed to privacy@ikpilates.com and will be directed to that person.
14. Supervisory Authority
The control body for compliance with personal data protection legislation in Ukraine is the Ukrainian Parliament Commissioner for Human Rights.
Ukrainian Parliament Commissioner for Human Rights Address: vul. Instytutska 21/8, Kyiv, 01008, Ukraine Hotline: 0 800 50 17 20 Email: hotline@ombudsman.gov.ua Website: www.ombudsman.gov.ua
You may also apply to a court for the protection of your rights.
15. Children
Our services are directed to adults. Where a minor attends classes, the account must be created and managed by a parent or guardian, who accepts our Terms of Use and provides any health information on the minor's behalf. Consent to the processing of a minor's personal data is given by the parent or guardian in accordance with the Civil Code of Ukraine.
If we learn that we have collected data concerning a minor without the required authorisation, we will delete it promptly.
16. Changes to This Policy
We review this Policy at least annually, whenever our processing changes materially, and upon the adoption of new Ukrainian data protection legislation.
Where a change materially affects your rights we will notify registered users by email or through an in-application notice at least fourteen days before it takes effect. The version number and effective date at the head of this document identify the applicable text. Previous versions are retained and are available on request.
