About this policy
Signa Coaching Inc. (Signa, we, us, our) is a company incorporated in the Province of Quebec, Canada. This Privacy Policy explains how we handle personal information when you use our website, our coaching platform, and our mobile application — together, the Platform.
We handle personal information in accordance with:
- the Act respecting the protection of personal information in the private sector (Quebec), as amended by Law 25;
- the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation;
- the EU and UK General Data Protection Regulation (GDPR), where they apply to you;
- the California Consumer Privacy Act as amended by the CPRA (CCPA), and comparable US state privacy laws, where they apply to you.
Personal information means information about an identifiable individual. This policy covers all of it, whether you are a coach, an athlete, a visitor to our website, a prospective customer, or someone who contacts us.
Your use of the Platform is also governed by our Terms and Conditions.
Who is responsible for your information
Signa plays two different roles, and which one applies determines who you go to about your data.
We are the controller — the person who decides why and how information is processed — for:
- account, profile, and authentication data;
- subscription, billing, and transaction records;
- how you use the Platform, including device and log data;
- support conversations and correspondence with us;
- marketing and prospect information;
- the training and health data of an athlete who uses the Platform independently, without a coach.
We are a processor — acting on someone else’s instructions — for the personal information a coach collects about their athletes through the Platform. In that relationship, the coach is the controller. The coach decides what to collect, why, and for how long, and is responsible for having a lawful basis and for answering their athletes’ privacy requests. See Coaches as independent controllers.
If you are an athlete and you are not sure which applies to a particular piece of data, write to privacy@signacoaching.com and we will tell you, and pass your request to the right party if it is not us.
Information we collect
Identity and account information
Name, email address, password (stored only as a salted hash), date of birth, gender, profile photo, language and timezone, and the identifiers assigned to your account. Where you sign in through a third-party provider, the basic profile that provider returns to us.
Coach and business information
Business or studio name, role, professional certifications or registrations you choose to provide, team structure, roster size, website and social links, and the settings of your workspace.
Training and performance information
Programs assigned and completed, exercises, loads, sets, repetitions, tempo, rest, distances, durations, paces, heart-rate and effort data, session ratings, adherence, personal records, and history over time.
Health and body information
Height, weight, body measurements and composition, injuries and limitations, symptoms, medications or conditions you or your coach record, menstrual-cycle information where you choose to track it, sleep, stress, recovery and readiness scores, and nutrition or hydration entries.
This is sensitive information. See Sensitive information and health data.
Content and communications
Messages between you and your coach or other users, notes, videos and photographs you submit for review, form submissions, feedback, survey answers, and anything you write into an AI feature.
Transaction information
Plan and tier, billing cycle, purchase and renewal history, credit balances and usage, invoices, amounts, currency, tax status, billing address, and partial payment identifiers such as the last four digits and card brand.
We never receive or store full payment-card numbers. Card data goes directly to our payment processor, or to Apple or Google for an in-app purchase, and is handled under their own terms and PCI-DSS obligations.
Device and technical information
IP address, device model and operating system, browser type and version, app version, language settings, crash reports, diagnostic logs, referring pages, pages viewed, features used, timestamps, session duration, and approximate location derived from IP address at the city or regional level. We do not collect precise GPS location unless a feature that needs it is enabled by you.
Information from integrations
Where you connect a health application, wearable, or calendar, we receive the categories of data you authorise at the moment you connect it — typically workouts, steps, heart rate, sleep, body metrics, or availability. You can disconnect at any time, which stops future syncing.
Data received from Apple Health, Google Fit, or a comparable health service is used only to provide the feature you enabled. We do not use it for advertising, we do not sell it, and we do not share it except with the service providers strictly necessary to deliver that feature. Information received from Google APIs is used in accordance with the Google API Services User Data Policy, including its Limited Use requirements.
Information from other people
A coach may enter information about you when they set up your profile. Another user may mention you in content. We may receive information from our resellers, referral partners, or from public sources such as a professional directory.
How we collect information
We collect personal information:
- directly from you, when you register, fill in a form, subscribe, communicate with us, or record training;
- automatically, as you use the Platform, through logs, cookies, and similar technologies described in Cookies and similar technologies;
- from your coach, where they administer your profile or program;
- from third parties, where you connect an integration or where a partner refers you.
We collect only what we need for the purposes set out below, and we do not require you to consent to collection that is not necessary for the service you asked for.
Why we use your information
| Purpose | Information used | Basis |
|---|---|---|
| Creating and administering your account | Identity, account, device | Performance of our contract with you |
| Delivering coaching features — assigning plans, syncing sessions, messaging | Training, health, content | Contract; express consent for health data |
| Adapting programming to how you are actually training | Training, health, usage | Contract; express consent for health data |
| Processing payments, renewals, credits, and invoices | Transaction, identity | Contract; legal obligation for tax records |
| Sending service messages — receipts, renewals, security alerts, changes to this policy | Identity, transaction | Contract; legal obligation |
| Push notifications and reminders | Account, device | Consent, withdrawable in settings |
| Support and troubleshooting | Everything relevant to your issue | Contract; legitimate interest |
| Security, fraud prevention, abuse detection, enforcing our Terms | Device, usage, account | Legitimate interest; legal obligation |
| Measuring and improving the Platform | Usage, de-identified training data | Legitimate interest; consent where required for analytics cookies |
| Research and product development on de-identified data | De-identified data only | Legitimate interest |
| Marketing about our own services | Identity, usage | Consent, withdrawable at any time |
| Complying with law and responding to lawful requests | Whatever is legally required | Legal obligation |
Where we rely on legitimate interest, we have assessed that our interest is not overridden by your rights, and you may object at any time. Where we rely on consent, you may withdraw it at any time — withdrawal applies going forward and does not affect processing already carried out.
If we ever want to use your information for a purpose that is not compatible with the ones listed here, we will tell you first and, where the law requires it, ask for your consent.
Sensitive information and health data
Health, body, and biometric information is sensitive, and Law 25 and the GDPR both require heightened protection for it.
- We collect it only to deliver coaching features, and only with your express consent, obtained separately from your general acceptance of this policy.
- It is subject to stricter internal access controls than other data. Access is limited to the personnel who need it to operate or support the service, and every access is logged.
- It is never used for advertising, never sold, and never disclosed to a data broker.
- We do not use it to train general-purpose artificial-intelligence models unless you have separately and expressly consented, and that consent can be withdrawn at any time.
- You can withdraw consent for health-data processing by turning off the relevant feature, disconnecting the integration, or writing to
privacy@signacoaching.com. Some coaching features cannot function without it, and withdrawing may mean those features stop working.
We are not a healthcare provider and Signa is not a covered entity under HIPAA. The information you record here is not a medical record, and this policy — not health-sector legislation — governs how we handle it.
Artificial intelligence and automated processing
Some features generate, adapt, and prescribe training using artificial intelligence.
What is processed. The input you provide, the relevant part of your training history, and the parameters your coach has set. Where a third-party model provider serves the feature, that input is transmitted to them as our service provider, under contractual terms that limit them to serving our request and prohibit using your information to train their own models.
Human oversight. AI output is a draft. Where a coach is involved, the coach reviews and is responsible for what they assign. See Artificial intelligence features.
Automated decision-making. We do not use exclusively automated processing to make decisions that produce legal effects for you or that similarly significantly affect you. Where a decision about you is based on automated processing, Law 25 gives you the right to:
- be informed that the decision was based on automated processing;
- be informed of the personal information used, the reasons and principal factors that led to the decision, and your right to have that information corrected;
- submit observations to a member of our personnel who is able to review the decision.
To exercise any of these, write to privacy@signacoaching.com.
Model training. We do not train models on identifiable coach or athlete content without separate express consent. We do use de-identified and aggregated data to evaluate and improve our systems; de-identified data does not identify you, and we do not attempt to re-identify it.
Cookies and similar technologies
We use cookies, local storage, SDKs, and similar technologies on our website and in our applications.
| Category | What it does | Can you refuse it |
|---|---|---|
| Strictly necessary | Authentication, session management, security, load balancing, remembering your cookie choices | No — the Platform cannot work without them |
| Preferences | Language, timezone, interface settings | Yes |
| Analytics and performance | Aggregate usage measurement, error and crash reporting | Yes |
We do not use advertising or cross-site tracking cookies, and we do not permit third parties to track you across other websites through our Platform.
Controlling cookies. Most browsers let you refuse or delete cookies through their settings, and mobile operating systems let you reset or limit advertising identifiers. Blocking strictly necessary cookies will break parts of the Platform.
Do Not Track and Global Privacy Control. There is no common industry standard for responding to browser Do Not Track signals, so we do not respond to them. Where the law requires it, we treat a Global Privacy Control signal as a valid opt-out of any sale or sharing of personal information — noting that we do not sell or share personal information in the first place.
How we share information
We do not sell personal information. We share it only in the situations below.
With your coach. If you train with a coach, they see the training and health information you record, the content you submit for review, and your messages with them. That is the point of the service. If you do not want a coach to see something, do not record it in a program they administer.
With other users, where you choose. Content you post to a shared program, a group, or a community feature is visible to the people that feature reaches. It is not confidential once shared and we cannot control what recipients do with it.
With service providers. Third parties who process information on our behalf and on our instructions, under written contracts requiring confidentiality, security, and use limited to our purposes. See Service providers and subprocessors.
Where you tell us to. With an integration you connect, or a third party you direct us to.
For legal reasons. Where we are required by law, court order, subpoena, warrant, or a lawful request from a public authority; to enforce our Terms and Conditions; to investigate suspected fraud or a security incident; or to protect the rights, property, or safety of Signa, our users, or the public — including where there is a risk of serious harm to a person.
In a corporate transaction. In connection with a merger, acquisition, financing, reorganisation, or sale of assets, or during due diligence for one, subject to confidentiality undertakings. If personal information is transferred as part of such a transaction, we will notify you and the acquirer will remain bound by commitments no less protective than these.
With professional advisers. Our lawyers, accountants, auditors, and insurers, where necessary and under a duty of confidentiality.
Service providers and subprocessors
We use service providers in the following categories:
- Cloud hosting and infrastructure — running the Platform and storing data;
- Website hosting and form handling — serving our marketing site;
- Video hosting, transcoding, and streaming — delivering exercise and demonstration video;
- Payment processing — taking payments, managing subscriptions, issuing invoices;
- Artificial-intelligence model providers — serving the generative features described above;
- Email, push notification, and messaging delivery — sending service and, where you consent, marketing messages;
- Product analytics, error monitoring, and crash reporting — keeping the Platform working;
- Customer support tooling — handling your requests;
- Identity and authentication providers — where you use third-party sign-in.
Every provider is bound by a written agreement requiring them to protect personal information, to use it only for the purposes we specify, to hold it no longer than necessary, and to notify us of any confidentiality incident.
A current list of the named providers we use, and the countries they operate in, is available on request from privacy@signacoaching.com. We maintain it there rather than in this document so that it is always accurate. Coaches subject to the GDPR who need a data processing agreement with a subprocessor list should write to the same address.
Storing information outside Quebec
We are based in Quebec, and personal information may be stored or processed in Canada, the United States, the European Union, or another country where we or our service providers operate. Laws in those countries differ from those in Quebec and, in some cases, allow access by local authorities.
Before communicating personal information outside Quebec, we conduct a privacy impact assessment as required by Law 25, taking into account the sensitivity of the information, the purposes it will be used for, the protections it would receive — including contractual ones — and the legal framework of the destination. We proceed only where the assessment shows the information will receive adequate protection.
For transfers of personal data out of the European Economic Area or the United Kingdom, we rely on an adequacy decision where one applies — including the Commission’s decision on Canada for commercial organisations — or on Standard Contractual Clauses together with supplementary technical and organisational measures. You may request a copy of the relevant transfer mechanism at privacy@signacoaching.com.
How long we keep information
We keep personal information only as long as necessary for the purposes it was collected for, or for as long as the law requires us to.
| Information | Retention |
|---|---|
| Account and profile | For the life of the account, then deleted or de-identified within 90 days of deletion |
| Training and health data | For the life of the account, unless you delete it earlier; athlete data in a coach’s workspace is retained on the coach’s instructions |
| Messages and content | For the life of the account, subject to the retention the other participant is entitled to |
| Billing and tax records | Seven (7) years from the transaction, as required by tax and accounting law |
| Security and access logs | Up to 24 months |
| Support correspondence | 36 months from resolution |
| Marketing contacts | Until you unsubscribe, then a minimal suppression record so we do not contact you again |
| Backups | Rolling backups overwritten within 35 days; deleted records disappear from backups as those cycles complete |
| De-identified and aggregated data | Indefinitely, since it no longer identifies anyone |
When a retention period ends, we destroy the information or de-identify it irreversibly. Where information must be retained to comply with a legal obligation, to establish or defend a legal claim, or to enforce our Terms, we retain only what is necessary for that purpose and isolate it from active use.
How we protect information
We maintain technical and organisational measures appropriate to the sensitivity of the information, including:
- encryption in transit using TLS, and encryption at rest for stored data;
- role-based access control, least-privilege access, and multi-factor authentication for administrative access;
- logging and monitoring of access to sensitive information;
- network segmentation, firewalls, and hardened infrastructure;
- confidentiality obligations and privacy training for personnel with access;
- vendor security review before a service provider is engaged;
- backup and disaster-recovery procedures, tested periodically;
- a documented incident-response process.
Your part. Use a strong and unique password, enable multi-factor authentication where available, keep your devices updated, and do not share your credentials. We will never ask you for your password, and we will never ask for full payment-card details by email or message.
No absolute guarantee. No method of transmission or storage is completely secure. While we work hard to protect your information, we cannot guarantee its absolute security, and transmission is at your own risk.
Confidentiality incidents
If a confidentiality incident occurs — unauthorised access to, use of, disclosure of, or loss of personal information — we will:
- take reasonable measures to reduce the risk of injury and prevent recurrence;
- assess whether the incident presents a risk of serious injury, considering the sensitivity of the information, the anticipated consequences, and the likelihood of misuse;
- where it does, notify the Commission d’accès à l’information du Québec and every affected individual promptly, as required by Law 25, and notify any other regulator entitled to be told, including the Office of the Privacy Commissioner of Canada or a supervisory authority under the GDPR;
- where we act as a processor, notify the relevant controller — normally the coach — without undue delay;
- record the incident in the register of confidentiality incidents that we maintain, and keep that record for five years.
Your privacy rights
Subject to the conditions and exceptions in applicable law, you have the right to:
- Access — obtain confirmation that we hold personal information about you, a copy of it, and information about how it is used and who it has been communicated to.
- Rectification — have inaccurate, incomplete, or ambiguous information corrected, and have information that was collected without authority deleted.
- Deletion — ask us to delete personal information where it is no longer needed for the purposes it was collected for, or where you withdraw the consent it rested on.
- Withdraw consent — at any time, for any processing based on consent, without affecting the lawfulness of processing already carried out.
- Portability — receive the computerised personal information you provided to us in a structured, commonly used technological format, and have it communicated to another organisation where that is technically feasible.
- De-indexing and cessation of dissemination — require that we stop disseminating personal information about you, or de-index a hyperlink that gives access to it, where the dissemination contravenes the law or a court order, or where it causes serious injury to your reputation or privacy that outweighs the public interest in the information.
- Object — to processing based on our legitimate interests, and to direct marketing at any time.
- Restriction — ask that processing be limited while a request of yours is being handled.
- Automated decisions — be informed, be told the factors involved, and submit observations to a human, as described in Artificial intelligence and automated processing.
- Complain — to a supervisory authority, without prejudice to any other remedy.
How to exercise your rights
Write to privacy@signacoaching.com, or use the privacy controls in your account settings where they are available for what you need.
What we need. Enough information to identify you and to understand your request. We may ask you to verify your identity before acting — we ask only for what is proportionate, and we do not use verification information for anything else.
Our timeline. We respond within 30 days of receiving a request, as required by Law 25 and PIPEDA. Under the GDPR the period is one month, extendable by two further months for complex requests, in which case we will tell you why within the first month. Requests are free unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee based on our administrative cost and will tell you before we do.
If we say no. We will tell you in writing, explain the reason and the legal basis for it, and tell you how to challenge the decision — including how to apply to the Commission d’accès à l’information for a review, and the time limit for doing so. We may refuse where the law requires or permits us to, for example where disclosing information would reveal personal information about someone else, would compromise an investigation, or is protected by professional privilege.
Authorised agents. You may act through an authorised agent or, in the circumstances the law allows, on behalf of a deceased relative. We will ask for proof of authority.
After death. Where Law 25 permits, a spouse or close relative may obtain access to information about a deceased person where knowing it may help them in their grieving process, unless the deceased recorded a refusal in writing.
Additional rights in Quebec and Canada
Signa is subject to Law 25 and to PIPEDA. In addition to the rights above:
- our Privacy Officer is the person with the highest authority within Signa, who may delegate the function in writing; their contact details are in Contact our privacy officer;
- we conduct privacy impact assessments before deploying a system that collects, uses, or communicates personal information, and before communicating personal information outside Quebec;
- our default settings for any function allowing an individual to be identified, located, or profiled provide the highest level of confidentiality without your intervention;
- we maintain internal governance policies covering the retention, destruction, and role-based handling of personal information, and we will describe them to you on request;
- you may complain to the Commission d’accès à l’information du Québec (cai.gouv.qc.ca) or to the Office of the Privacy Commissioner of Canada (priv.gc.ca). We ask that you raise it with us first so we have a chance to fix it.
Additional rights in the European Economic Area and the United Kingdom
Where the GDPR or UK GDPR applies to you, Signa Coaching Inc. is the controller of the personal information described in Who is responsible for your information, and processes it on the legal bases set out in Why we use your information.
You have the rights of access, rectification, erasure, restriction, portability, and objection, the right to withdraw consent, and the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. Health information is a special category of data, which we process on the basis of your explicit consent under Article 9(2)(a).
You may lodge a complaint with your local supervisory authority — the list is maintained by the European Data Protection Board, and in the United Kingdom by the Information Commissioner’s Office. Transfers out of the EEA or the UK are covered in Storing information outside Quebec.
Additional rights for California residents
Under the CCPA, California residents have the rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and not be discriminated against for exercising any of them.
Categories collected in the last 12 months, using the statute’s own labels:
| CCPA category | Collected | Examples |
|---|---|---|
| Identifiers | Yes | Name, email, account ID, IP address |
| Customer records information | Yes | Name, contact details, payment status |
| Protected classification characteristics | Yes | Age, gender, where you provide them |
| Commercial information | Yes | Subscriptions, purchases, credits |
| Internet or network activity | Yes | Usage, device, log data |
| Geolocation data | Approximate only | City or region derived from IP |
| Audio, visual, or similar information | Yes | Videos and photos you submit |
| Professional or employment information | Yes | Coach business details |
| Inferences | Yes | Training preferences and readiness signals |
| Sensitive personal information | Yes | Health and body data, account credentials |
Sources, purposes, and recipients are described in How we collect information, Why we use your information, and How we share information.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months, including for consumers under 16.
Sensitive personal information is used only to provide the service you requested, and for security, service quality, and legally permitted internal purposes — the uses permitted without a right to limit under the statute.
Shine the Light. California residents may request the categories of personal information disclosed to third parties for their own direct-marketing purposes in the preceding calendar year. We do not make such disclosures, but you may confirm this by writing to privacy@signacoaching.com.
To exercise a CCPA right, write to privacy@signacoaching.com. We will not discriminate against you for doing so. Residents of other US states with comparable privacy legislation have equivalent rights and may use the same address.
Privacy of minors
The Platform is not directed to children under 14 and we do not knowingly collect their personal information.
- Under 14 — accounts are not permitted. Under Law 25, consent for the collection of personal information about a minor under 14 must come from the person having parental authority. If we learn we hold information about a child under 14 without that consent, we will delete it promptly. Contact
privacy@signacoaching.comif you believe we have. - 14 to 17 — the Athlete application may be used with the involvement of a parent or guardian, as set out in Who may use Signa. We apply the highest confidentiality settings by default and we do not market to minors.
- Coaches working with minors are responsible for obtaining parental consent and for meeting any safeguarding obligation that applies to them.
We do not knowingly sell or share the personal information of anyone under 16, because we do not sell or share personal information at all.
Coaches as independent controllers
Where a coach uses the Platform to collect and manage information about their athletes, the coach is the controller of that information and Signa is a processor acting on the coach’s instructions.
Coaches are responsible for: having a lawful basis and, where required, obtaining express consent for health information; telling their athletes what they collect and why; keeping information accurate; responding to athlete requests for access, correction, deletion, and portability; setting appropriate retention; and complying with every privacy and professional-confidentiality obligation that applies to their practice.
Signa is responsible for: processing only on the coach’s documented instructions and as required by law; securing the information as described in How we protect information; engaging subprocessors under equivalent obligations; assisting the coach in responding to requests and to confidentiality incidents; and deleting or returning information at the end of the engagement.
Athletes: if your request concerns information held in your coach’s workspace, contact your coach first. Write to us at privacy@signacoaching.com if you cannot reach them or do not get an answer, and we will help. A data processing agreement is available to coaches on request.
Marketing communications
We send marketing messages only where you have consented or where our relationship permits it under Canada’s anti-spam legislation. Every marketing email carries an unsubscribe link, and unsubscribing takes effect promptly. You can also write to privacy@signacoaching.com.
Service messages are different. Receipts, renewal notices, security alerts, and notifications of changes to this policy are part of the service, and you cannot opt out of them while you hold an account.
Push notifications can be turned off in your device settings or in the application at any time.
Third party links
The Platform links to websites and services we do not operate. This policy does not apply to them. When you follow a link or connect an integration, the information you provide is governed by that provider’s own privacy policy and terms, and we are not responsible for their practices. Read their policies before you share anything with them.
Changes to this policy
We may update this policy as the Platform, our practices, or the law change. The “last updated” date at the top of this page always reflects the current version.
Where a change is material — a new purpose, a new category of recipient, or a change to your rights — we will give you notice by email or in-product notice before it takes effect, and, where the law requires consent for the new use, we will ask for it rather than assume it. Continuing to use the Platform after a non-material change takes effect means you accept it.
Contact our privacy officer
Questions, requests, or complaints about privacy go to our Privacy Officer:
| Contact | Details |
|---|---|
| Organisation | Signa Coaching Inc., Province of Quebec, Canada |
| Role | Privacy Officer — the person exercising the highest authority within Signa, or their written delegate |
| Privacy requests | privacy@signacoaching.com |
| Legal notices | legal@signacoaching.com |
| General enquiries | info@signacoaching.com |
We respond to privacy requests within 30 days. If you are not satisfied with our response, you may complain to the Commission d’accès à l’information du Québec, the Office of the Privacy Commissioner of Canada, or the supervisory authority for your region.