Privacy Policy
1. Introduction
This Privacy Policy describes how personal data is processed in connection with the Bursta mobile application for Android (the “Application”). It is issued in accordance with Regulation (EU) 2016/679 (the “GDPR”) and applicable national data protection law.
The Application is an interval timer. It operates without a user account, without a cloud service, and without user authentication of any kind. The data described in Section 4 is the entirety of what leaves the user’s device.
2. Data controller
The data controller responsible for the processing described in this Policy is the developer of the Application, contactable at:
Enquiries relating to this Policy, and requests made under Section 8, should be addressed to that address. The controller responds to requests from data subjects without undue delay and in any event within one month of receipt, in accordance with Article 12(3) of the GDPR. Where a request is complex, that period may be extended by two further months, and the data subject will be informed of the extension and of the reasons for it within one month.
No Data Protection Officer has been appointed. The conditions set out in Article 37(1) of the GDPR are not met: the controller is not a public authority, the processing described in this Policy does not consist of regular and systematic monitoring of data subjects on a large scale, and no special categories of data within the meaning of Article 9 are processed.
3. Data stored solely on the user’s device
The following categories of data are created and retained exclusively in the Application’s local storage on the user’s device. They are not transmitted to the controller, to any processor, or to any third party:
- workouts created or saved by the user, including any names assigned to them;
- the record of completed and partial training sessions (training history);
- planned sessions, recurrence rules and calendar entries;
- application preferences, including colour theme, interface language, text size, sound set and volume.
This data is removed when the Application is uninstalled. The controller holds no copy of it and cannot restore it.
4. Data transmitted from the device
4.1 Software update checks
On launch, the Application queries the update service operated by Expo Application Services, Inc. to determine whether a newer version of its program code is available. The request transmits the platform, the application version and the release channel. The receiving server records the request, including the originating IP address, in the ordinary course of operating a network service.
4.2 Performance and usage measurement
The Application collects technical measurements relating to its own performance, processed by Expo Application Services, Inc. The following are transmitted:
- an anonymous installation identifier, generated on installation, persisting across application updates and reset upon reinstallation. It is not derived from, and cannot be linked to, any device identifier, account or contact detail;
- a session identifier generated for each launch of the Application;
- duration measurements for application launch, screen rendering and screen readiness, together with the identifier of the screen concerned;
- device state recorded at the moment of measurement: battery level, charging status, thermal state, power-saving mode, network connection type and whether the connection is metered;
- aggregate statistics concerning the Application’s own network requests during launch, including their number, duration, transferred volume and the host name of the slowest request;
- the four application events listed below, each carrying numeric and boolean values only.
| Event | Values transmitted |
|---|---|
| Workout started | number of rounds; whether a built-in preset was used |
| Workout finished | rounds planned; rounds completed; whether completed in full; elapsed active duration |
| Backup saved | none |
| Backup restored | number of sections that could not be read |
Names assigned by the user to workouts are not transmitted. The event structure admits numeric and boolean values only and provides no field capable of carrying free text.
4.3 Diagnostic reports on application failure
Where the Application terminates unexpectedly, a diagnostic report is transmitted to Functional Software, Inc. (trading as Sentry). The report comprises the error and its location within the program code, the device model, the operating system version, and the application and update version in use. It does not include the data described in Section 3. Reports are not transmitted from development builds of the Application.
4.4 Feedback submitted by the user
The Application’s settings screen provides a link to a feedback form hosted by Google LLC. The form is opened in the device’s browser. No data is transmitted unless the user completes and submits the form, in which case the content submitted is received by Google LLC and by the controller.
4.5 Backup files
Where the user creates a backup, the Application writes a file and passes it to the operating system’s sharing interface. The destination is determined solely by the user. The controller does not receive, access or retain such files. A backup file contains the data described in Section 3 in human-readable form.
5. Purposes and legal bases
| Processing | Purpose | Legal basis |
|---|---|---|
| Update checks (4.1) | Delivery of corrections and improvements to the Application | Legitimate interests, Art. 6(1)(f) GDPR — maintaining a functioning and secure application |
| Performance measurement (4.2) | Identification and correction of performance defects; understanding which functions are used | Legitimate interests, Art. 6(1)(f) GDPR — improving the Application. Data is pseudonymous and limited to technical values |
| Diagnostic reports (4.3) | Identification and correction of defects causing failure | Legitimate interests, Art. 6(1)(f) GDPR — ensuring the Application functions as intended |
| Feedback (4.4) | Responding to the user’s enquiry | Consent, Art. 6(1)(a) GDPR, given by submitting the form |
Where processing rests on legitimate interests, the controller has assessed those interests against the rights and freedoms of the data subject and considers the processing proportionate, having regard to its limitation to technical and pseudonymous data and to the absence of any profiling, advertising or automated decision-making.
6. Recipients and international transfers
| Recipient | Role | Location |
|---|---|---|
| Expo Application Services, Inc. | Processor — update delivery and performance measurement | United States |
| Functional Software, Inc. (Sentry) | Processor — diagnostic reports | United States |
| Google LLC | Processor — feedback form, where submitted | United States |
Data is not disclosed to any recipient other than those listed. It is not sold, licensed or made available for advertising purposes.
The recipients listed are established in the United States. Transfers are made on the basis of the standard contractual clauses adopted by the European Commission, or of an adequacy decision where one applies to the recipient, in accordance with Chapter V of the GDPR. The respective privacy notices are published at expo.dev/privacy, sentry.io/privacy and policies.google.com/privacy.
7. Retention
- Data described in Section 3 is retained on the device until deleted by the user or until the Application is uninstalled.
- Performance measurements (4.2) are retained by the processor for a minimum of 60 days.
- Diagnostic reports (4.3) are retained for the period configured in the processor’s data management settings for the account in use, after which the processor deletes them. The controller does not extend that period. The applicable period is published by the processor at sentry.io/privacy.
- Feedback (4.4) is retained for as long as necessary to respond to the enquiry, and is deleted on request.
8. Rights of the data subject
Subject to the conditions laid down in the GDPR, the data subject has the right to request access to personal data concerning them (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing carried out on the basis of legitimate interests (Art. 21). Where processing is based on consent, that consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
The controller draws attention to Article 11 of the GDPR. The Application collects no name, address, electronic mail address, account or device identifier by which a data subject could be identified. The controller is accordingly not in a position to identify the data subject from the data described in Section 4.2, and cannot associate a request with a particular installation. Where a data subject provides additional information enabling identification, the controller will give effect to the rights above.
The following measures are available to the data subject directly:
- uninstalling the Application ends all transmission described in Section 4 and resets the installation identifier;
- data submitted through the feedback form is deleted upon written request to the address in Section 2.
A data subject who considers that processing infringes the GDPR has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or of the alleged infringement (Art. 77 GDPR).
9. Children
The Application is not directed at children and does not knowingly process the personal data of children. It requests no personal information from any user.
10. Automated decision-making
No automated decision-making within the meaning of Article 22 of the GDPR, and no profiling, is carried out.
11. Security
Data transmitted as described in Section 4 is sent over encrypted connections. Data described in Section 3 is held in the Application’s private storage area, to which other applications have no access under the operating system’s security model. Backup files created by the user are not encrypted and their protection is a matter for the user.
12. Amendments
This Policy is amended where the processing it describes changes. The effective date and version at the head of this document are updated accordingly. The current version is published at bursta.app/privacy.
Where an amendment materially alters the categories of data processed, the purposes of processing or the recipients, the amended Policy is published not less than 30 days before it takes effect, and notice is given within the Application. Continued use of the Application after that date constitutes acknowledgement of the amended Policy. Where an amendment requires consent under applicable law, that consent will be sought before the change takes effect.
13. Cookies and similar technologies
The Application is a native mobile application. It does not use cookies, web beacons, advertising identifiers, or any comparable tracking technology, and it contains no embedded web view through which such technology could operate.
The anonymous installation identifier described in Section 4.2 is not an advertising identifier. It is not shared with any advertising network, cannot be matched against identifiers held by third parties, and is reset when the Application is reinstalled.
Where the user opens the feedback form described in Section 4.4, that form is displayed in the device’s own browser and is subject to the cookie practices of Google LLC, over which the controller exercises no control.
14. Residents of California
This Section applies to residents of the State of California and supplements the foregoing for the purposes of the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”).
In the twelve months preceding the effective date of this Policy, the categories of personal information collected are those described in Section 4: internet or other electronic network activity information, and device and diagnostic information. No categories of sensitive personal information within the meaning of the CCPA are collected.
Personal information is not sold, and is not shared for cross-context behavioural advertising. No such sale or sharing has occurred in the preceding twelve months, and none is intended. Personal information of minors under 16 is not knowingly collected and accordingly no opt-in is applicable.
California residents have the right to know what personal information is collected and for what purpose, the right to request deletion, the right to correct inaccurate information, and the right not to be discriminated against for exercising those rights. Requests may be submitted to the address in Section 2. The limitation described in Section 8 applies equally: the controller holds no identifier capable of connecting a request to a particular installation, and will say so rather than deny the request on other grounds.
15. General provisions
15.1 Governing law
This Policy is governed by, and construed in accordance with, the law of the controller’s place of establishment, without prejudice to the mandatory protections afforded to data subjects by the law of their habitual residence, and without prejudice to the right to lodge a complaint with a supervisory authority under Article 77 of the GDPR.
15.2 Third-party destinations
This Policy addresses only the Application. Where the Application directs the user to a resource operated by another party — the feedback form described in Section 4.4, or the privacy notices referenced in Section 6 — that resource is governed by the privacy practices of its operator, for which the controller bears no responsibility.
15.3 Severability
Where a provision of this Policy is or becomes invalid or unenforceable, the remaining provisions continue in full force, and the invalid provision is replaced by such valid provision as most nearly reflects its purpose.
Політика приватності
1. Загальні положення
Ця Політика приватності описує порядок обробки персональних даних у зв’язку з використанням мобільного застосунку Bursta для Android (далі — «Застосунок»). Її складено відповідно до Регламенту (ЄС) 2016/679 (далі — «GDPR») та застосовного національного законодавства про захист персональних даних.
Застосунок є інтервальним таймером. Він працює без облікового запису, без хмарної служби та без будь-якої автентифікації користувача. Дані, описані в Розділі 4, становлять вичерпний перелік того, що покидає пристрій користувача.
2. Володілець даних
Володільцем, відповідальним за обробку, описану в цій Політиці, є розробник Застосунку. Контактна адреса:
Звернення щодо цієї Політики, а також запити за Розділом 8, надсилаються на зазначену адресу. Володілець відповідає на запити суб’єктів даних без невиправданої затримки та в будь-якому разі протягом одного місяця з дня отримання, відповідно до статті 12(3) GDPR. У разі складності запиту цей строк може бути продовжено ще на два місяці, про що суб’єкта даних буде повідомлено із зазначенням причин протягом одного місяця.
Відповідальну особу з питань захисту даних не призначено. Умови статті 37(1) GDPR не виконуються: володілець не є органом публічної влади, обробка, описана в цій Політиці, не полягає в регулярному та систематичному моніторингу суб’єктів даних у великих масштабах, а особливі категорії даних у розумінні статті 9 не обробляються.
3. Дані, що зберігаються виключно на пристрої користувача
Наведені нижче категорії даних створюються та зберігаються виключно в локальному сховищі Застосунку на пристрої користувача. Вони не передаються ані володільцю, ані операторам, ані будь-яким третім особам:
- тренування, створені або збережені користувачем, разом із наданими їм назвами;
- записи про завершені та незавершені заняття (історія тренувань);
- заплановані заняття, правила повторення та записи календаря;
- налаштування Застосунку, зокрема кольорова тема, мова інтерфейсу, розмір тексту, звуковий набір і гучність.
Ці дані видаляються разом із видаленням Застосунку. Володілець не має їхньої копії та не може їх відновити.
4. Дані, що передаються з пристрою
4.1 Перевірка оновлень програмного забезпечення
Під час запуску Застосунок звертається до служби оновлень, яку надає Expo Application Services, Inc., щоб визначити наявність новішої версії програмного коду. Запит передає платформу, версію застосунку та канал випуску. Сервер-одержувач фіксує сам запит, зокрема IP-адресу відправника, у звичайному порядку роботи мережевої служби.
4.2 Вимірювання швидкодії та використання
Застосунок збирає технічні виміри власної швидкодії, обробку яких здійснює Expo Application Services, Inc. Передається таке:
- анонімний ідентифікатор установки, що створюється під час встановлення, зберігається між оновленнями застосунку та скидається при повторному встановленні. Він не походить від жодного ідентифікатора пристрою, облікового запису чи контактних даних і не може бути з ними зіставлений;
- ідентифікатор сеансу, що створюється для кожного запуску Застосунку;
- виміри тривалості запуску застосунку, відображення екрана та його готовності до взаємодії, разом з ідентифікатором відповідного екрана;
- стан пристрою на момент виміру: рівень заряду, стан заряджання, тепловий стан, режим енергозбереження, тип мережевого з’єднання та наявність обмежень трафіку;
- зведені показники власних мережевих запитів Застосунку під час запуску: кількість, тривалість, обсяг переданих даних та імʼя вузла найповільнішого запиту;
- чотири події Застосунку, наведені нижче, кожна з яких містить виключно числові та логічні значення.
| Подія | Значення, що передаються |
|---|---|
| Тренування розпочато | кількість раундів; чи використано готовий пресет |
| Тренування завершено | заплановано раундів; пройдено раундів; чи завершено повністю; тривалість активного часу |
| Копію збережено | відсутні |
| Копію відновлено | кількість розділів, які не вдалося прочитати |
Назви, надані користувачем тренуванням, не передаються. Структура подій припускає лише числові та логічні значення й не містить поля, здатного нести довільний текст.
4.3 Діагностичні звіти про збої Застосунку
У разі аварійного завершення роботи Застосунку діагностичний звіт передається до Functional Software, Inc. (торгова назва — Sentry). Звіт містить помилку та її місце в програмному коді, модель пристрою, версію операційної системи, а також версію застосунку та оновлення. Він не містить даних, описаних у Розділі 3. Зі збірок для розробки звіти не передаються.
4.4 Відгук, надісланий користувачем
Екран налаштувань Застосунку містить посилання на форму відгуку, розміщену Google LLC. Форма відкривається у браузері пристрою. Жодні дані не передаються, поки користувач самостійно не заповнить і не надішле форму; у такому разі надіслані відомості отримують Google LLC та володілець.
4.5 Файли резервних копій
Створюючи резервну копію, Застосунок формує файл і передає його системному інтерфейсу надсилання. Місце призначення визначає виключно користувач. Володілець таких файлів не отримує, не має до них доступу та не зберігає їх. Файл резервної копії містить дані, описані в Розділі 3, у придатному для читання вигляді.
5. Цілі та правові підстави обробки
| Обробка | Мета | Правова підстава |
|---|---|---|
| Перевірка оновлень (4.1) | Доставлення виправлень і вдосконалень Застосунку | Законні інтереси, ст. 6(1)(f) GDPR — підтримання працездатного та безпечного застосунку |
| Вимірювання швидкодії (4.2) | Виявлення та усунення вад швидкодії; розуміння того, які функції використовуються | Законні інтереси, ст. 6(1)(f) GDPR — вдосконалення Застосунку. Дані є псевдонімізованими й обмежені технічними значеннями |
| Діагностичні звіти (4.3) | Виявлення та усунення вад, що спричиняють збої | Законні інтереси, ст. 6(1)(f) GDPR — забезпечення належної роботи Застосунку |
| Відгук (4.4) | Відповідь на звернення користувача | Згода, ст. 6(1)(a) GDPR, надана надсиланням форми |
Щодо обробки, яка ґрунтується на законних інтересах, володілець оцінив ці інтереси у співвідношенні з правами і свободами суб’єкта даних і вважає обробку пропорційною з огляду на її обмеження технічними та псевдонімізованими даними й на відсутність профілювання, реклами та автоматизованого прийняття рішень.
6. Одержувачі та міжнародна передача
| Одержувач | Роль | Розташування |
|---|---|---|
| Expo Application Services, Inc. | Оператор — доставлення оновлень і вимірювання швидкодії | США |
| Functional Software, Inc. (Sentry) | Оператор — діагностичні звіти | США |
| Google LLC | Оператор — форма відгуку, у разі її надсилання | США |
Дані не розкриваються жодним іншим одержувачам, окрім зазначених. Вони не продаються, не ліцензуються та не надаються для рекламних цілей.
Зазначені одержувачі розташовані у Сполучених Штатах Америки. Передача здійснюється на підставі стандартних договірних положень, ухвалених Європейською Комісією, або рішення про адекватність, якщо таке поширюється на одержувача, згідно з Главою V GDPR. Відповідні повідомлення про приватність опубліковано за адресами expo.dev/privacy, sentry.io/privacy та policies.google.com/privacy.
7. Строки зберігання
- Дані, описані в Розділі 3, зберігаються на пристрої до їх видалення користувачем або до видалення Застосунку.
- Виміри швидкодії (4.2) зберігаються оператором щонайменше 60 днів.
- Діагностичні звіти (4.3) зберігаються протягом строку, налаштованого в параметрах управління даними оператора для відповідного облікового запису, після чого оператор їх видаляє. Володілець цього строку не подовжує. Чинний строк оприлюднено оператором за адресою sentry.io/privacy.
- Відгуки (4.4) зберігаються протягом часу, необхідного для відповіді на звернення, і видаляються на вимогу.
8. Права суб’єкта даних
На умовах, визначених GDPR, суб’єкт даних має право вимагати доступу до персональних даних, що його стосуються (ст. 15), їх виправлення (ст. 16), видалення (ст. 17), обмеження обробки (ст. 18), перенесення даних (ст. 20), а також заперечувати проти обробки, що здійснюється на підставі законних інтересів (ст. 21). Якщо обробка ґрунтується на згоді, таку згоду може бути відкликано в будь-який час без впливу на правомірність обробки, здійсненої до відкликання.
Володілець звертає увагу на статтю 11 GDPR. Застосунок не збирає ані імені, ані адреси, ані адреси електронної пошти, ані облікового запису чи ідентифікатора пристрою, за якими суб’єкта даних можна було б ідентифікувати. Відповідно, володілець не має змоги ідентифікувати суб’єкта даних за даними, описаними в пункті 4.2, і не може повʼязати запит із конкретною установкою. Якщо суб’єкт даних надасть додаткові відомості, що уможливлять ідентифікацію, володілець забезпечить реалізацію наведених вище прав.
Суб’єктові даних безпосередньо доступні такі заходи:
- видалення Застосунку припиняє будь-яку передачу, описану в Розділі 4, і скидає ідентифікатор установки;
- дані, надіслані через форму відгуку, видаляються за письмовою вимогою на адресу, зазначену в Розділі 2.
Суб’єкт даних, який вважає, що обробка порушує GDPR, має право подати скаргу до наглядового органу, зокрема в державі-члені свого звичайного місця проживання, місця роботи або місця ймовірного порушення (ст. 77 GDPR).
9. Діти
Застосунок не призначений для дітей і свідомо не обробляє персональних даних дітей. Він не запитує особистої інформації в жодного користувача.
10. Автоматизоване прийняття рішень
Автоматизоване прийняття рішень у розумінні статті 22 GDPR, а також профілювання, не здійснюються.
11. Безпека
Дані, що передаються згідно з Розділом 4, надсилаються через зашифровані з’єднання. Дані, описані в Розділі 3, зберігаються у приватній області сховища Застосунку, до якої інші застосунки не мають доступу згідно з моделлю безпеки операційної системи. Файли резервних копій, створені користувачем, не шифруються, і їх захист є відповідальністю користувача.
12. Внесення змін
До цієї Політики вносяться зміни в разі зміни обробки, яку вона описує. Дата набрання чинності та версія у заголовку документа оновлюються відповідно. Чинна редакція публікується за адресою bursta.app/privacy.
Якщо зміна суттєво змінює категорії оброблюваних даних, цілі обробки або перелік одержувачів, змінену Політику публікують щонайменше за 30 днів до набрання нею чинності, і повідомлення про це надається в Застосунку. Подальше користування Застосунком після зазначеної дати вважається ознайомленням зі зміненою Політикою. Якщо зміна потребує згоди за застосовним законодавством, таку згоду буде отримано до набрання зміною чинності.
13. Файли cookie та подібні технології
Застосунок є нативним мобільним застосунком. Він не використовує файлів cookie, вебмаяків, рекламних ідентифікаторів чи будь-яких порівнянних технологій відстеження й не містить вбудованого вебперегляду, через який такі технології могли б діяти.
Анонімний ідентифікатор установки, описаний у пункті 4.2, не є рекламним ідентифікатором. Він не передається до рекламних мереж, не може бути зіставлений з ідентифікаторами третіх осіб і скидається при повторному встановленні Застосунку.
Якщо користувач відкриває форму відгуку, описану в пункті 4.4, ця форма відображається у власному браузері пристрою й підпадає під практики використання cookie компанії Google LLC, на які володілець не має впливу.
14. Мешканці Каліфорнії
Цей Розділ застосовується до мешканців штату Каліфорнія та доповнює викладене вище для цілей Каліфорнійського закону про приватність споживачів зі змінами, внесеними Каліфорнійським законом про права на приватність (разом — «CCPA»).
Протягом дванадцяти місяців, що передували даті набрання чинності цією Політикою, збиралися категорії персональної інформації, описані в Розділі 4: відомості про активність в інтернеті або іншій електронній мережі, а також відомості про пристрій і діагностичні дані. Особливі категорії персональної інформації в розумінні CCPA не збираються.
Персональна інформація не продається та не передається для міжконтекстної поведінкової реклами. Протягом попередніх дванадцяти місяців такого продажу чи передання не відбувалося й не планується. Персональна інформація неповнолітніх до 16 років свідомо не збирається, тож надання окремої згоди не застосовується.
Мешканці Каліфорнії мають право знати, яку персональну інформацію збирають і з якою метою, право вимагати її видалення, право виправити неточні відомості, а також право не зазнавати дискримінації за реалізацію цих прав. Запити надсилаються на адресу, зазначену в Розділі 2. Обмеження, описане в Розділі 8, застосовується так само: володілець не має ідентифікатора, здатного повʼязати запит із конкретною установкою, і повідомить про це, а не відмовить з інших підстав.
15. Загальні положення
15.1 Застосовне право
Ця Політика регулюється правом місця осідку володільця й тлумачиться відповідно до нього, без обмеження імперативних гарантій, наданих суб’єктам даних правом їхнього звичайного місця проживання, і без обмеження права подати скаргу до наглядового органу за статтею 77 GDPR.
15.2 Ресурси третіх осіб
Ця Політика стосується виключно Застосунку. Якщо Застосунок скеровує користувача до ресурсу, яким керує інша особа, — форми відгуку, описаної в пункті 4.4, або повідомлень про приватність, зазначених у Розділі 6, — такий ресурс регулюється практиками приватності його оператора, за які володілець відповідальності не несе.
15.3 Подільність положень
Якщо будь-яке положення цієї Політики є або стає недійсним чи таким, що не підлягає виконанню, решта положень зберігають повну чинність, а недійсне положення замінюється таким дійсним положенням, яке найближче відповідає його меті.