Draft for legal review
This is a starting point prepared for your solicitor to review and adapt. It is not legal advice. Because MMA Pathway processes body measurements, you may have additional obligations under the UK GDPR, EU GDPR, CCPA/CPRA and Apple's and Google's data-disclosure rules. Placeholders are marked [LIKE THIS].
This Privacy Policy explains how [LEGAL ENTITY NAME] ("we", "us", "our") collects, uses, stores and shares information when you use the MMA Pathway mobile application and mmapathway.com (together, the "Service").
We are the data controller for the personal data described below. If you have questions, contact us at privacy@mmapathway.com.
1. Information we collect
Information you give us
- Account details — name or display name, email address, password (stored hashed), and date of birth or age.
- Body measurements — height, weight, reach, leg length, body fat percentage, stance, and age.
- Training profile — experience level, training goals, primary disciplines, weight class, and any amateur or professional record you enter.
- Performance logs — sessions you record, including duration, session type, heart-rate figures you enter or import, and perceived exertion (RPE).
- Support correspondence — messages you send us and any information you include in them.
Information collected automatically
- Device and app data — device model, operating system version, app version, language, time zone, and crash and diagnostic logs.
- Usage data — screens viewed, features used, and session timestamps.
- Website analytics — aggregated, privacy-preserving analytics collected via [Plausible / Google Analytics]. See section 8.
Information from third parties
- Health platforms — where you explicitly grant permission, we may read specified data from Apple Health or Google Fit (for example weight or heart rate). [CONFIRM WHETHER THE APP USES THESE INTEGRATIONS.]
- App stores — Apple and Google provide us with aggregate download and subscription reporting, and confirmation of purchases. They do not share your payment card details with us.
2. Sensitive data and biometrics
Body measurements, body fat percentage and heart-rate information relate to your physical characteristics and health. Under the UK and EU GDPR these may constitute special category data (data concerning health). We process this data only on the basis of your explicit consent, which you give when you enter your measurements during onboarding.
You can withdraw consent at any time by deleting the relevant data in the app, or by requesting deletion of your account. Withdrawing consent does not affect processing carried out before withdrawal. Note that without measurements the core features of the Service cannot function.
We do not use facial recognition, fingerprints, or other identifying biometric templates. [UPDATE IF PHOTO- OR SCAN-BASED FEATURES ARE ADDED.]
3. How we use your information
- To create and maintain your account.
- To generate your personalized training pathway, optimal weight class, body-type classification and pro benchmarking.
- To display your profile, statistics and performance history back to you.
- To provide customer support and respond to your enquiries.
- To fix bugs, monitor stability and improve the Service.
- To send service messages, and — where you have opted in — product updates and marketing email.
- To detect and prevent fraud, abuse and security incidents.
- To comply with our legal obligations.
We do not sell your personal data, and we do not use your body measurements for advertising or profiling unrelated to the Service.
4. Legal bases for processing (UK/EU users)
- Consent — health and body-measurement data; marketing email; optional analytics.
- Contract — creating your account and delivering the features you sign up for.
- Legitimate interests — securing the Service, preventing abuse, and improving our product, balanced against your rights.
- Legal obligation — retaining records where law requires it.
5. Sharing your information
We share personal data only with:
- Service providers acting on our instructions — hosting and infrastructure [e.g. Laravel Forge / DigitalOcean / AWS], database and backup providers, crash reporting [e.g. Sentry], email delivery [e.g. Postmark / Mailchimp], and analytics [e.g. Plausible].
- Payment processors — Apple and Google handle in-app purchases; we never receive your full card details.
- Professional advisers, auditors and insurers where reasonably necessary.
- Authorities where we are legally required to disclose, or to protect our rights or someone's safety.
- A successor entity in connection with a merger, acquisition or asset sale, subject to this Policy.
6. International transfers
Our providers may process data outside your country, including in the [UNITED STATES / EEA / UNITED KINGDOM]. Where data leaves the UK or EEA, we rely on adequacy decisions or on Standard Contractual Clauses together with appropriate technical safeguards. [CONFIRM YOUR HOSTING REGIONS.]
7. Retention
- Account and profile data — kept while your account is active.
- Deleted accounts — removed from production systems within [30] days, and purged from encrypted backups within [90] days.
- Support correspondence — kept for [24 months].
- Aggregated, anonymised statistics — may be retained indefinitely, as they no longer identify you.
8. Cookies and analytics
The website uses only essential cookies needed to serve pages. We use [Plausible Analytics], which is cookie-free and does not track individuals across sites, so no consent banner is required for it. [IF YOU SWITCH TO GOOGLE ANALYTICS OR ADD ADVERTISING OR SOCIAL PIXELS, YOU MUST ADD A GDPR-COMPLIANT CONSENT BANNER AND UPDATE THIS SECTION.]
9. Security
We use encryption in transit (TLS), encryption at rest for databases and backups, hashed passwords, access controls limiting staff access to what their role requires, and regular dependency patching. No system is completely secure, and we cannot guarantee absolute security. If a breach affects your rights, we will notify you and the relevant regulator as required by law.
10. Your rights
Depending on where you live, you may have the right to:
- access a copy of your personal data;
- correct inaccurate data;
- delete your data (see our deletion request page);
- restrict or object to processing;
- withdraw consent at any time;
- receive your data in a portable format;
- not be subject to unlawful automated decision-making;
- lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).
California residents have equivalent rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of "sharing". We do not sell personal information.
To exercise any right, email privacy@mmapathway.com. We respond within 30 days.
11. Children
The Service is not directed at children under [16], and we do not knowingly collect their data. If you believe a child has provided us with personal data, contact us and we will delete it. [SET AN AGE THRESHOLD CONSISTENT WITH YOUR APP STORE AGE RATING AND LOCAL LAW.]
12. Not medical advice
MMA Pathway provides general training and performance information. It is not medical advice, diagnosis or treatment, and it does not replace a qualified coach, physician or physiotherapist. Always seek professional guidance before starting or changing a training programme.
13. Changes to this Policy
We may update this Policy from time to time. We will change the "Last updated" date above and, for material changes, notify you in the app or by email before the changes take effect.
14. Contact
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
[COMPANY REGISTRATION NUMBER]
Email: privacy@mmapathway.com
[IF YOU HAVE APPOINTED A DATA PROTECTION OFFICER OR AN EU/UK REPRESENTATIVE, LIST THEM HERE.]