PRIVACY POLICY
KUNTO – Inclusive Sport & Coaching
1. Introduction
KUNTO (hereinafter «we», «our»), a digital sports and nutrition coaching platform, is committed to protecting your personal data in accordance with Regulation (EU) 2016/679 of April 27, 2016 (GDPR) and the amended Law No. 78-17 of January 6, 1978.
This Policy describes the processing of personal data that we carry out, their legal bases, the rights you have, and our protection methods.
This Policy applies to:
- Our website: https://www.kunto.fr/
- Our mobile application (iOS and Android)
- All interactions with our services
We recommend that you read it carefully and regularly. Any changes will be communicated to you by email and on our platforms.
For any questions, please contact us: contact@kunto.fr | +33 7 77 72 64 23
2. Treatment Synthesis Table
| Purpose | Legal Basis | Shelf Life |
|---|---|---|
| User Account Creation and Management (Registration, access, profile, history) | Execution of the Contract (Article 6.1.b of the GDPR) | Active base : Duration of the contractual relationship. Archiving: 5 years after account closure (legal limitation period) |
| Provision of Sport & Nutrition Coaching Services (Video programs, performance tracking, nutritional advice, video coaching) | Execution of the Contract (Article 6.1.b of the GDPR) | Active base : As long as the subscription/program is active. Archiving: 5 years after the end of the program (civil liability) |
| Health Data Processing (Chronic conditions, disability, physical vitals, for program adaptation) | Explicit Consent (Article 9.2.a of the GDPR) | Active base : As long as valid consent and service used. Archiving: 5 years (probationary and medical liability obligations) |
| Billing and Payment Management | Legal Obligation (Article 6.1.c of the GDPR) | 10 years (Accounting and tax obligation – Article L123-22 of the French Commercial Code) |
| Management of Requests, Complaints, and Exercise of Rights (Support requests, right of access, right to be forgotten, etc.) | Legal Obligation (Article 6.1.c of the GDPR) | 5 years as of the closing of the application |
| Notification Tracking and User Preferences Adapting our services to your expectations | Legitimate Interest (Article 6.1.f of the GDPR) | Active base : As long as you use the app. Archiving: 2 years after last activity |
| Fraud Prevention (Promo codes, payment methods, unpaid invoices) | Legitimate Interest (Article 6.1.f of the GDPR) | 3 years as of the detected suspicious activity |
| Service Improvement and Statistical Analysis (Anonymized usage, engagement, and program effectiveness data) | Legitimate Interest (Article 6.1.f of the GDPR) | 25 months before complete anonymization of the logs (Anonymized data: unlimited retention) |
| Research and Retrospective Studies (Optional – Studies on the effectiveness of inclusive health and fitness) | Public Interest / Legitimate Interest + Consent for health data (Article 9.2(i) or (j) of the GDPR) | According to CNIL Reference Methodology MR-004: 2 years after publication of the results or until the signing of the final report if not published |
3. Categories of Collected Data
We collect the following data according to the needs of each purpose:
3.1 Essential Data (All Users)
- Identity: First name, Last name, Email, Phone number
- Login: Usernames, hashed passwords, login history
- Profile: Date of birth, gender, approximate location
- Payment: IBAN/Card (processed via secure provider, never stored directly by Kunto), invoices
3.2 Health Data (With Consent)
- Pathologies: Chronic diseases, disabilities, relevant medical history
- Physical Constants: Weight, height, blood pressure, heart rate (if monitored)
- Fitness Level: Mobility, endurance, muscular strength
- Health Behavior Data: Sleep, energy, stress, mood, adherence to programs
- You have the option to share your application data Apple's CoreMotion and/or Google Fit by Google with our Services to synchronize the number of steps taken, as well as the walking time. This only happens if you explicitly authorize this data sharing.
3.3 Usage Data
- Interaction: Programs consulted, videos watched, sessions completed
- Progression: Weight, performance, objective physical results
4. Detailed Legal Foundations
4.1 Performance of the Contract (Article 6.1.b of the GDPR)
Processing is necessary to provide you with access to the application, personalized coaching programs, coach support, and the management of your subscription.
4.2 Consent (Article 6.1.a and Article 9.2.a of the GDPR)
To process your health data, we request your explicit consent at the time of registration. You can withdraw it at any time without justification, which will result in the adaptation or termination of our services.
4.3 Legal Obligation (Article 6.1.c GDPR)
- Billing: Accounting and tax obligations (10 years)
- Rights Management: GDPR obligations to document and respond to requests
4.4 Legitimate Interest (Article 6.1.f GDPR)
We use this database to:
- Customize your notifications and coaching preferences
- Prevent fraud and abuse (promo codes)
- Improve the quality of our services through anonymized usage analysis
Balancing interests: We have evaluated that these treatments do not infringe upon your rights and freedoms, as the data is processed securely and you may object at any time.
5. Recipients of Your Data
Your data is accessible only To whom it may concern:
5.1 Internally (Kunto Team)
- Support and Account Management Team
- Product team (anonymized data for improvement)
- Direction (aggregated/anonymized data)
5.2 Subcontractors and Service Providers
| Service provider | Role | Localization | Certifications |
|---|---|---|---|
| Hostinger | Showcase Website Hosting | EU | GDPR-compliant |
| AWS | App & Web App Hosting | EU (Paris) | HDS (Health Data Hosting Certified), ISO 27001 |
| Brevo | Send transactional emails | N/A | GDPR-compliant |
| Stripe | Payment processing | N/A | PCI-DSS |
| Analytics | Anonymized usage analytics | N/A | Privacy-by-Design |
Note: All service providers sign data processing agreements (DPAs) including standard contractual clauses to secure transfers.
5.3 Partner Professionals (Coaches)
For video coaching appointments and personalized tracking, the listed coaches and professionals have access to:
- Your health profile (to adapt the coaching)
- Your availability calendar
- Your progress
Important: Professionals are responsible for processing your data for this purpose. Kunto is merely a facilitator. Their own policies apply.
5.4 Legal Transfers
We may disclose your data if legally required (court order, public authorities).
6. Transfers Outside of the European Union
Some of our service providers (notably AWS or Hostinger) may host data or have backup servers in countries outside the EEA.
Protective Measures:
- Standard Contractual Clauses Our partners accept the European Commission's Standard Contractual Clauses (SCC).
- HDS Certification: For health data, hosting is provided by a certified host (AWS), meeting French and European standards.
- Regular Audit: We regularly verify compliance with these guarantees.
7. Data Security
We implement technical and organizational measures to protect your data:
Technical Measures
- Encryption: In transit (TLS/HTTPS) and at rest (sensitive data encrypted)
- Authentication: Hashed passwords (bcrypt/argon2), optional multi-factor authentication
- Restricted Access: Role-Based Access Control (RBAC)
- Audit: Sensitive data access logs, alerts on suspicious access
Organizational Measures
- Education: All our employees receive GDPR training
- Privacy: Confidentiality clauses in all contracts
- Incident Policy: Reporting procedure in the event of a leak (72h to CNIL if necessary)
Despite our best efforts, no system is 100% secure. We recommend that you do not share sensitive data via unencrypted email.
8. Cookies and Tracking Technologies
8.1 Technical Cookies (Without Consent)
These cookies are essential for the app to function:
- User session (login)
- Security (CSRF protection)
- Display preferences (language, theme)
8.2 Cookie Management
On the Website:
- A consent banner appears
- You can accept or decline non-essential cookies
- Consent settings available in your account settings
On Mobile App:
- Technical cookies only (no third-party cookies)
- You can turn off usage analytics in the settings
Via Browser: You can refuse cookies at any time via your browser settings.
Warning: This may degrade your experience.
9. Your Rights and How to Exercise Them
In accordance with the GDPR, you have the following rights:
9.1 Right of Access (Article 15 of the GDPR)
You can ask: Know what data concerns you, how it is processed, who has access to it.
Response time: 30 days (extendable to 60 days for complex requests).
9.2 Right to Rectification (Article 16 of the GDPR)
You can request: Modify inaccurate or outdated data (e.g., change of address).
You can also: Directly modify certain data from your account (profile, email).
9.3 Right to Be Forgotten / Erasure (Article 17 GDPR)
You can request the deletion if:
- Your data is no longer needed for the intended purpose
- You are withdrawing your consent
- You object to the processing
- The expiration date has passed
Exceptions: We cannot delete data if legal obligations (accounting, taxes) require us to retain it.
9.4 Right to Restriction of Processing (Article 18 of the GDPR)
You may request: To temporarily suspend the processing of your data (without deleting it), e.g., pending correction.
9.5 Right to Data Portability (Article 20 of the GDPR)
You can request: To receive your data in a structured format (JSON, CSV) so you can transfer it to another service.
9.6 Right to Object (Article 21 of the GDPR)
You may object to:
- Processing Based on Legitimate Interests (Notifications, Service Improvements)
- Transfers outside the EEA (under certain conditions)
Consequence: Some features may be limited if you opt out.
9.7 Withdrawal of Consent (Article 7 of the GDPR)
For processing based on consent: You may withdraw your consent at any time without providing a reason.
Example: You may opt out of having your health data processed; this will affect the personalization of your experience.
9.8 Post-Mortem Directives (Article 89 GDPR)
You can let us know: What will happen to your data after your death (deletion, donation to research, etc.).
10. How to Exercise Your Rights
Step 1: Contact Us
By email: contact@kunto.fr
Subject: Request to Exercise Rights [Type of Right Requested]
By Mail:
KUNTO
3 Balance Street
91350 Grigny
France
By Phone: +33 7 77 72 64 23
Step 2: Provide Proof of Identity
Please attach a copy of your ID (unless your information already allows for your unambiguous identification).
Step 3: State Your Request Clearly
Please specify:
- Your name and email address (as on file with us)
- The right you wish to exercise
- The relevant data (if applicable)
- Your return address
Response Time
Standard: 30 calendar days from receipt.
Possible extensions: +30 days if request is complex or high volume (you will be notified).
11. Complaints and Supervisory Authority
If you are not satisfied with our response or consider that your rights are not being respected, you can lodge a complaint with the CNIL (French data protection authority):
CNIL – National Commission on Informatics and Liberty
Postal address: 3 Place Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
Online platform https://www.cnil.fr/plaintes
Deadline: You have 3 years from the breach to file a complaint.
12. Duration and Modifications of this Policy
12.1 Vigor
This Policy is effective as of 05/01/2026 and applies to all present and future processing.
12.2 Modifications
We reserve the right to modify this Policy to:
- Comply with legal developments
- Improve clarity
- Integrate new services or providers
In case of modification:
- You will be notified by email and via our app/site
- The changes will be visible with the update date
- If the modifications strengthen your rights: applicable immediately
- If the changes impact you negatively, you will have 30 days to accept or terminate.
Last update date: [JANUARY 2026]
13. Contact Information
Data Controller
KUNTO
Email: contact@kunto.fr
Data Protection Officer (DPO)
For any questions regarding your personal data, you can contact our DPO at the following address: contact@kunto.fr
14. Legal References
This Policy complies with the following provisions:
- GDPR: Regulation (EU) 2016/679 of 27 April 2016
- Data Protection Act: Law No. 78-17 of January 6, 1978 (France)
- ePrivacy Directive: Directive 2002/58/EC (cookies and tracking)
- Commercial Code: Article L123-22 (accounting obligations – 10 years)
- HDS: Health Data Host Certification (technical service providers)
- CNIL MR-004 Methodology: Health Research and Data Retention
Appendix A: Glossary
| Term | Definition |
|---|---|
| Personal data | Any information that allows a person to be identified (name, email, IP address, etc.) |
| Health data | Special category of personal data concerning health status (illnesses, disabilities, treatments) |
| Treatment | Any operation on data (collection, storage, use, deletion) |
| Data controller | Person/organization that decides the purposes and means of the processing (here: Kunto) |
| Subcontractor | Personne/organisation qui traite pour compte du responsable (ex: AWS) |
| Base juridique | Fondement légal justifiant un traitement (contrat, loi, consentement, intérêt légitime) |
| RGPD | Règlement Général de Protection des Données (droit européen) |
| CNIL | Commission Nationale de l’Informatique et des Libertés (autorité française) |
| DPO | Data Protection Officer (Responsable Protection Données) |
| HDS | Hébergeur Agréé de Données Santé (certification française) |
| SCC | Standard Contractual Clauses (clauses contractuelles types pour transferts hors UE) |
Merci de votre confiance dans KUNTO. Nous nous engageons à protéger votre vie privée.
Pour toute question ou retour sur cette Politique, contactez-nous à contact@kunto.fr