Privacy Policy
Last updated: 19 July 2026
This Privacy Policy explains how Soigneur UG (haftungsbeschränkt) i. Gr.(“Soigneur”, “we”, “us”) processes personal data when you visit soigneur.coach and when you use the Soigneur coaching service. We are the controller for this processing within the meaning of the EU General Data Protection Regulation (GDPR).
1. Controller & contact
Soigneur UG (haftungsbeschränkt) i. Gr.
c/o Evoleen Technology GmbH
Kochelseestraße 8–10, 81371 München, Germany
E-Mail: [email protected]
For our full company details see the Impressum. For any question about your data or to exercise your rights, contact us at the address above.
2. The website (soigneur.coach)
The following applies to everyone who visits our website.
Hosting & server logs
Our website is hosted on Cloudflare Pages (Cloudflare, Inc.). When you access the site, Cloudflare processes technical connection data — including your IP address, date and time of the request, the requested URL, referrer and browser/user-agent — to deliver the site and to keep it secure and available. Legal basis: our legitimate interest in operating a secure, reliable website (Art. 6(1)(f) GDPR). These edge and security logs are short-lived.
Regional pricing
To show prices in your local currency, an edge function reads the country associated with your IP address (Cloudflare’s CF-IPCountry signal) at the moment of the request. We use this only to select which currency to display. We do not store it, we do not set a cookie for it, and the response is not cached across visitors. Legal basis: our legitimate interest in showing you relevant pricing (Art. 6(1)(f) GDPR).
Fonts
Fonts are served directly from our own site. We do not load fonts from third-party font services (such as Google Fonts), so no data is shared with a font provider when you browse.
Cookies & analytics
The website sets no tracking cookies and uses no third-party analytics or advertising trackers. If we later introduce privacy-friendly, cookieless analytics or any technology that requires consent, we will obtain your consent where required and update this policy.
Contacting us
If you email us, we process your address and the content of your message to handle your request. Legal basis: performance of a contract or pre-contractual steps (Art. 6(1)(b)) or our legitimate interest in responding to enquiries (Art. 6(1)(f)). We keep this correspondence for as long as needed to deal with the matter and to meet legal obligations.
3. The Soigneur coaching service
The coaching service is being rolled out; this section describes how your data is processed when you create an account and use it.
Data we process
- Identity & account — name, email, and authentication identifiers (sign-in is handled via Microsoft Entra External ID).
- Health & physiology — e.g. heart rate, heart-rate variability, power and threshold data, VO₂max, sleep and wellness, illness notes, perceived exertion. This is special-category health data (Art. 9 GDPR).
- Activity & performance — rides and workouts, activity-file streams, training-load and form metrics (Fitness, Fatigue, Form, Load, Intensity), and plan adherence. Treated as special-category health data.
- Nutrition — energy and macronutrient logs. Treated as special-category health data.
- Interactions — your messages with the coach, diary entries, and answers to clarifying questions. These may contain health data and are treated accordingly.
- Derived / inferred — readiness indicators, risk flags, your coaching frame, and recommendations. Treated as special-category health data (profiling of health).
- Operational — timestamps, run identifiers, provenance and audit records (Art. 6 personal data).
- Usage metering — per-interaction metadata (which skill and model ran, token counts, estimated cost, duration, and a pseudonymous user id). This contains no message content and no health data.
Where your data comes from
We receive data directly from you and — only with your authorization — from the training accounts you connect (such as Garmin or intervals.icu). Those providers are independent controllers for your accounts with them; data enters Soigneur only through the authorization you grant, and can be disconnected by you.
Purposes & legal bases
- Explicit consent (Art. 9(2)(a)) — the basis for processing your health and other special-category data to deliver AI-assisted coaching (analysis, recommendations, plan adaptation). Consent is captured at onboarding with a clear description of purposes, the sub-processors involved and any international transfers, and can be withdrawn at any time.
- Contract (Art. 6(1)(b)) — for the ordinary account and personal data needed to provide the paid service.
- Legitimate interest (Art. 6(1)(f)) — for usage metering and fair-use enforcement (operating the service, managing capacity, and detecting abuse). This uses only the PHI-free usage metadata above.
- Separate, granular consent — for background/automated coaching runs performed while you are offline.
We do not process special-category data before your explicit consent has been recorded.
4. How AI coaching handles your data
Soigneur is an AI system, and you are told clearly when you are interacting with it. To generate coaching, relevant context is sent as a prompt to large-language-model providers through the OpenRouter gateway. This crossing is tightly governed:
- Zero data retention — providers retain nothing once the request completes.
- No training or collection — your data is not used to train models and is not collected by the providers.
- Vetted providers only — requests are pinned to an allow-list of vetted providers with fallbacks disabled, so a request can never reach an un-vetted party.
- No prompt logging — we do not store the prompt or completion text; only metadata (model, token counts, run id, latency).
The durable record of your coaching interactions is stored by us inside your own health record (in the FHIR standard), under our controls described below — not with the AI providers.
5. Sub-processors
We use the following processors and sub-processors under Art. 28 GDPR. We keep this list current and will inform you of material changes.
- OpenRouter — routes inference requests; processes the prompt and completion in transit under zero-retention terms.
- Pinned inference providers (e.g. Azure OpenAI, Anthropic) — perform the actual model inference on the routed prompt, on zero-retention endpoints.
- Microsoft Azure — hosts your health record, storage, key management and sign-in, in an EU region (West Europe / Sweden Central) within the EU Data Boundary.
- Cloudflare — content delivery, security and TLS for the website and API edge; transiently processes requests and keeps IP/URL metadata in edge logs.
- Garmin / intervals.icu — training-data sources you authorize (independent controllers).
6. International transfers
- Your stored data (health record, files, backups) is kept in the EU (Azure EU region, EU Data Boundary).
- AI inference: under our current setup, requests may be processed via a US-based gateway even when the serving model is in the EU. This international transfer is safeguarded by the EU Standard Contractual Clauses (SCCs), a transfer impact assessment, zero-retention terms, and EU-eligible providers. We are moving to EU in-region inference routing so that this processing stays within the EU.
- Where a sub-processor is US-based (e.g. Cloudflare), transfers rely on the SCCs and, where available, EU data-localization options.
7. Retention & deletion
- AI prompts and completions — not retained (zero-retention at the provider; not logged by us).
- Your health, activity, nutrition, interaction and derived data — kept for the lifetime of your account and deleted on an erasure request, subject to any statutory retention.
- Raw activity files — kept with the account.
- Backups — a rolling window (e.g. 30 days); an erasure propagates on the next cycle.
- Audit and operational logs — the minimum needed for security and accountability, with no prompt content.
- Consent records — kept for the duration of the relationship plus the applicable limitation period.
Erasing your account removes your data record and files and revokes the associated access tokens.
8. Your rights
Under the GDPR you have the right to:
- access your data (Art. 15) and receive a portable copy (Art. 20) — your record is held in a standard, machine-readable format, so this can be provided as a structured export;
- rectification (Art. 16), erasure (Art. 17), and restriction of processing (Art. 18);
- object to processing based on legitimate interest (Art. 21); and
- withdraw consent at any time (Art. 7(3)), without affecting the lawfulness of processing before withdrawal.
To exercise any of these, contact [email protected]. You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Ansbach.
9. Automated decisions & AI transparency
Coaching outputs — readiness, recommendations and plan changes — are decision support. They do not produce legal or similarly significant effects, and you stay in control: significant changes (for example to your threshold or plan) are confirmed with you, and you can reach a human for any output you wish to contest. Soigneur is a wellness and training-coaching product, not a medical device, and it does not provide medical advice or diagnosis. It will not coach you through illness or fever and will recommend rest or seeing a doctor where appropriate.
10. Security
We apply appropriate technical and organizational measures (Art. 32 GDPR), including: encryption in transit and at rest; per-user isolation of your data; access under short-lived, user-scoped tokens with no broadly privileged service account; secrets held in a managed key vault; a strict outbound-network allow-list for the coaching runtime; and no health data written to logs.
11. Children
The service is intended for adults (18+) and is not directed at children.
12. Changes to this policy
We may update this policy as the service evolves or the law changes. Where a change materially affects how your data is processed, we will notify you as required. The date at the top of this page shows the current version.