IMPORTANT PRIVACY INFORMATION

In order to use the service, we will ask you to answer some questions and provide your email. We will also automatically collect from your device language settings, IP address, time zone, type and model of a device, device settings, operating system, Internet service provider, mobile carrier, hardware ID, Facebook ID, and other unique identifiers (such as IDFA and AAID). We need this data to provide our services, analyze how our customers use the service and to measure ads.

For improving the service and serving ads, we use third party solutions. As a result, we may process data using solutions developed by Amazon, Amplitude, Google, Firebase, Sendpulse, Zendesk. Therefore, some of the data is stored and processed on the servers of such third parties. This enables us to (1) analyze different interactions (how often users make purchases, what products our users viewed); (2) serve and measure ads (and show them only to a particular group of users, for example, only to those, who have made a purchase).

Please read our Privacy Policy below to know more about what we do with data (Section 3), what data privacy rights are available to you (Section 6) and who will be the data controller (Section 1). If any questions remain unanswered, please contact us at support@harnafit.com.

PRIVACY POLICY

This Privacy Policy explains what personal data is collected when you use HARNA websites and mobile applications (the "Website", "App", together the "Service"), how such personal data will be used, shared, and how you can control it.

BY USING THE SERVICE, YOU PROMISE US THAT (I) YOU HAVE READ, UNDERSTAND AND AGREE TO THIS PRIVACY POLICY, AND (II) YOU ARE OVER 16 YEARS OF AGE (OR HAVE HAD YOUR PARENT OR GUARDIAN READ AND AGREE TO THIS PRIVACY POLICY FOR YOU). If you do not agree, or are unable to make this promise, you must not use the Service. In such case, you must (a) contact us and request deletion of your data; (b) delete the App from your device or leave the Website and not access or use it; and (c) cancel any active subscriptions or trials.

Any translation from English version is provided for your convenience only. In the event of any difference in meaning or interpretation between the English language version of this Privacy Policy available at /privacy-policy, and any translation, the English language version will prevail. The original English text shall be the sole legally binding version

'GDPR' means the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

'EU/EEA' includes all current member states to the European Union and the European Free Trade Association. For the purpose of this policy EEA shall include the United Kingdom of Great Britain and Northern Ireland.

'Process', in respect of personal data, includes to collect, store and disclose to others.

TABLE OF CONTENT

  1. PERSONAL DATA CONTROLLER
  2. CATEGORIES OF PERSONAL DATA WE COLLECT
  3. FOR WHAT PURPOSES WE PROCESS PERSONAL DATA
  4. UNDER WHAT LEGAL BASES WE PROCESS YOUR PERSONAL DATA (Applies only to EEA-based users)
  5. WITH WHOM WE SHARE YOUR PERSONAL DATA
  6. HOW YOU CAN EXERCISE YOUR PRIVACY RIGHTS
  7. AGE LIMITATION
  8. INTERNATIONAL DATA TRANSFERS
  9. CHANGES TO THIS PRIVACY POLICY
  10. CALIFORNIA PRIVACY RIGHTS
  11. FOR VIRGINIA RESIDENTS
  12. DATA RETENTION
  13. HOW 'DO NOT TRACK' REQUESTS ARE HANDLED
  14. CONTACT US
  1. PERSONAL DATA CONTROLLER

    Amomama Media Limited, a company registered in the Republic of Cyprus (with registered office at 1st Floor, Georgiou Christoforou 8, 2012, Strovolos, Nicosia, Cyprus) will be the controller of your personal data.

  2. CATEGORIES OF PERSONAL DATA WE COLLECT

    We collect data you give us voluntarily (for example, email address). In addition, we collect data automatically (for example, your IP address). We also may receive data about you from third parties.

    1. Data you give us

      You provide us information about yourself in the process of ordering a personalized fitness plan. For example: age, weight, height, target weight, menstrual cycle dates, various symptoms related to your menstrual cycle, body type, fitness goal, past experience in fitness, diet type, name, email address, how does your typical day look like, how much you work out, your daily water intake, average time asleep. We use this information to tailor our product to your personal needs. You can also provide us with your email when you contact our support team.

    2. Data we collect automatically

      1. Data about how you found us

        We collect data about your referring app or URL (that is, the app or place on the Web where you were when you tapped on our ad).

      2. Device and Location data.

        We collect data from your device. Examples of such data include: language settings, IP address, time zone, type and model of device, device settings, operating system, Internet service provider, mobile carrier, hardware ID, and Facebook ID.

      3. Usage data

        We record how you interact with our Service. For example, we may log your taps/clicks on certain areas of the interface, the features and content you interact with, how often and for how long you use the Website.

      4. Advertising IDs

        We collect your Apple Identifier for Advertising (IDFA) or Google Advertising ID (AAID) (depending on the operating system of your device) when you access our Service from a mobile device. You can typically reset these numbers or refuse granting access to it through the settings of your device's operating system (but we do not control this).

      5. Transaction data

        When you make payments through the Service, you need to provide financial account data, such as your credit card number, to our third-party service providers. We do not collect or store full credit card number data, though we may receive credit card-related data, data about the transaction, including: date, time and amount of the transaction, the type of payment method used.

      6. Cookies

        A cookie is a small text file that is stored on a user's computer for record-keeping purposes. Cookies can be either session cookies or persistent cookies. A session cookie expires when you close your browser and is used to make it easier for you to navigate our Service. A persistent cookie remains on your hard drive for an extended period of time. We also use tracking pixels that set cookies to assist with delivering online advertising.

        Cookies are used, in particular, to automatically recognize you the next time you visit our Website. As a result, the information, which you have earlier entered in certain fields on the Website may automatically appear the next time when you use our Service. Cookie data will be stored on your device and most of the times only for a limited time period.

        How to influence use of cookies by the Service: We have implemented a consent management tool on our Website to provide you with control over technologies such as cookies. This tool enables you to decide which partners you allow to set, in particular, cookies on your browser or device. You may make the selection either (i) in the consent management pop-up window, which emerges in the footer of the page when you visit our Service the first time (if you are based in the EEA) or (ii) by clicking/pushing on Privacy Settings (located in the footer). You may view the list of such third parties in our Privacy Settings and edit your choices at "See full vendor list" or "View Companies" (designated for each separate type of the cookies) sections in the "Third Party Vendors" section. You can change your decision and revisit your consent choices at any time by returning to the Privacy Settings.

  3. FOR WHAT PURPOSES WE PROCESS PERSONAL DATA

    We process your personal data:

    1. To provide our Service

      This includes enabling you to use the Service in a seamless manner and preventing or addressing Service errors or technical issues. For this purpose, we, in particular, will send you your customized fitness plan to your email, which you indicate during the purchase.

      To host personal data and enable this Website to operate and be distributed we use Amazon Web Services (AWS), which is a hosting and backend service provided by Amazon.

    2. To customize your experience

      We process your personal data, such as menstrual cycle related information, to adjust the content of the Service and make offers tailored to your personal preferences. For example, we ask you to provide your menstrual cycle dates and various symptoms related to your menstrual cycle in order to sync your fitness plan with your period.

    3. To provide you with customer support

      We process your personal data to respond to your requests for technical support, Service information or to any other communication you initiate. For this purpose, we may send you, for example, notifications or emails about the performance of our Service, security, payment transactions, notices regarding our Terms of Service or this Privacy Policy.

    4. To communicate with you regarding your use of our Service

      We communicate with you, for example, by push notifications or by emails. These may include reminders or other information about the Service. As a result, you will, for example, receive a push notification that a new feature has been deployed in the Service. To opt out of receiving push notifications, you need to change the settings on your device. To opt-out of receiving emails, you should click unsubscribe link in the footer of each email.

      The services that we use for these purposes may collect data concerning the date and time when the message was viewed by the users, as well as when they interacted with it, such as by clicking on links included in the message.

      We use Sendpulse, which is a marketing personalization and retention platform, to deliver tailored email messages to our users.

      We use Zendesk ticketing system to handle customer inquiries. When you send us inquiries via contact form or via email, we will store the details provided by you via Zendesk ticketing system, which enables us to track, prioritize and quickly solve your requests. Privacy Policy .

    5. To research and analyze your use of the Service

      This helps us to better understand our business, analyze our operations, maintain, improve, innovate, plan, design, and develop the Service and our new products. We also use such data for statistical analysis purposes, to test and improve our offers. This enables us to better understand what features and sections of the Service our users like more, what categories of users use our Service. As a consequence, we often decide how to improve the Website based on the results obtained from this processing.

      What third-party services we use for this purpose?

      We use Facebook Analytics, which is a service provided by Facebook that allows us to use different analytical tools. On Facebook Analytics we get, in particular, aggregated demographics and insights on how many people access the Service and users' interactions within the Service. Learn more about Facebook's approach from its Privacy Policy .

      To analyse how visitors use our Website and to measure effectiveness of some ads we use Google Analytics, a web analysis program of Google. In order to provide us with analytics, Google Analytics places cookies on your device. On Google Analytics we get, in particular, aggregated information on the data you enter on our Website and users' interactions within the Website. Google allows you to influence the collection and processing of information generated by the Google, in particular, by installing a browser plug-in, available here . You can read more about how Google uses information here .

      We also use Amplitude that is an analytics service that we use to understand how customers use our Service. Amplitude collects various technical information, in particular, time zone, type of device (phone or tablet), unique identifiers (such as IDFA). Amplitude also allows us to track various interactions that occur in our App. As a result, Amplitude helps us to decide what features should we focus on. Amplitude provides more information on how they process data in its Privacy Policy .

      To track and analyze behavior of our Service users (in particular, how they react to changes of the Service structure, text or any other component), we use Firebase Remote Config. Firebase Remote Config is an A/B testing and configuration service provided by Google, which also enables us to tailor the content that our App's users see (for example, it allows us to show different onboarding screens to different users). Privacy Policy and Privacy and Security in Firebase .

      We also use Firebase Analytics, which is an analytics service provided by Google. In order to understand Google's use of data, consult Google's partner policy . Firebase Privacy information . Google's Privacy Policy .

    6. To send you marketing communications

      We process your personal data for our marketing campaigns. We may add your email address to our marketing list. As a result, you will receive information about our products, such as, for example, special offers or new features and products available on the Service. If you do not want to receive marketing emails from us, you can unsubscribe following instructions in the footer of the marketing emails.

      We use Sendpulse, which is a marketing personalization and retention platform, to deliver tailored email messages to our users.

    7. To personalize our ads

      We and our partners use your personal data to tailor ads and possibly even show them to you at the relevant time. For example, if you have accessed our Service, you might see ads of our products, for example, in your Facebook's feed.

      How to opt out or influence personalized advertising

      On the Website: You can use Consent Management Platform to make your choice whether to allow us to store or access information on your devices via cookies and other tracking technologies for the purpose of delivering interest-based advertising. You can open Consent Management Platform by clicking on Privacy button in the right lower corner of the Website.

      iOS: On your iPhone or iPad, go to Settings > Privacy > Apple Advertising and deselect Personalized Ads.

      Android: To opt-out of ads on an Android device, simply open the Google Settings app on your mobile phone, tap "Ads" and enable "Opt out of interest-based ads". In addition, you can reset your advertising identifier in the same section (this also may help you to see less of personalized ads).

      To learn even more about how to affect advertising choices on various devices, please look at the information available here .

      In addition, you may get useful information and opt out of some interest-based advertising, by visiting the following links:

      Browsers: It is also may be possible to stop your browser from accepting cookies altogether by changing your browser's cookie settings. You can usually find these settings in the "options" or "preferences" menu of your browser. The following links may be helpful, or you can use the "Help" option in your browser.

      What third-party services we use for this purpose?

      We value your right to influence the ads that you see, thus we are letting you know what service providers we use for this purpose and how some of them allow you to control your ad preferences.

      We use Facebook pixel on the Service. Facebook pixel is a code placed on the Service collecting data that helps us track conversions from Facebook ads, build targeted audience and remarket to people who have taken some action on the Website.

      We also use Facebook Ads Manager together with Facebook Custom Audience, which allows us to choose audiences that will see our ads on Facebook or other Facebook's products (for example, Instagram). Through Facebook Custom Audience we may create a list of users with certain sets of data, such as an IDFA, choose users that have completed certain actions on the Service. As a result, we may ask Facebook to show some ads to a particular list of users. As a result, more of our ads may show up while you are using Facebook or other Facebook's products (for example, Instagram). You may learn how to opt out of advertising provided to you through Facebook Custom Audience here .

      Facebook allows its users to influence the types of ads they see on Facebook. To find how to control the ads you see on Facebook, please go here or adjust your ads settings on Facebook .

      Google Ads is an ad delivery service provided by Google that can deliver ads to users. In particular, Google allows us to tailor the ads in a way that they will appear, for example, only to users that have conducted certain actions with our Website (for example, show our ads to users who visited our Website). This remarketing could be in the form of an advertisement on the Google search results page, or a site in the Good Display Network.

      Third-party vendors, including Google, use cookies to serve advertisements based on someone's past visits to the Service. Google allows its users to opt out of Google's personalized ads and to prevent their data from being used by Google Analytics .

    8. To process your payments

      We provide paid products and/or services within the Service. For this purpose, we use third-party services for payment processing (for example, payment processors). As a result of this processing, you will be able to make a payment for a personalized fitness plan and we will be notified that the payment has been made and will send you the fitness plan.

      We will not store or collect your payment card details ourselves. This information will be provided directly to our third-party payment processors.

    9. To enforce our Terms and Conditions of Use and to prevent and combat fraud

      We use personal data to enforce our agreements and contractual commitments, to detect, prevent, and combat fraud. As a result of such processing, we may share your information with others, including law enforcement agencies (in particular, if a dispute arises in connection with our Terms of Service).

    10. To comply with legal obligations

      We may process, use, or share your data when the law requires it, in particular, if a law enforcement agency requests your data by available legal means.

  4. In this section we are letting you know what legal basis we use for each particular purpose of processing. For more information on a particular purpose, please refer to Section 3. This section applies only to EEA-based users.

    We process your personal data under the following legal bases:

    1. your consent

      Under this legal basis we will send you marketing communications. You have the right to withdraw your consent any time by using the unsubscribe link in the footer of our emails. We will also send you push notifications if you allow us to. You can disable notifications any time in the settings of your device.

    2. to perform our contract with you;

      Under this legal basis we:

      • Provide our Service (in accordance with our Terms of Service)
      • Customize your experience
      • Manage your account and provide you with customer support
      • Communicate with you regarding your use of our Service
      • Process your payments
    3. for our (or others') legitimate interests, unless those interests are overridden by your interests or fundamental rights and freedoms that require protection of personal data;

      We rely on legitimate interests:

      • to research and analyze your use of the Service

      Our legitimate interest for this purpose is our interest in improving our Service so that we understand users' preferences and are able to provide you with a better experience (for example, to make the use of the Website easier and more enjoyable, or to introduce and test new features).

      • to personalize our ads

      The legitimate interest we rely on for this processing is our interest to promote our Service in a reasonably targeted way.

      • to enforce our Terms of Service and to prevent and combat fraud

      Our legitimate interests for this purpose are enforcing our legal rights, preventing and addressing fraud and unauthorised use of the Service, non-compliance with our Terms of Service.

    4. to comply with legal obligations.

  5. WITH WHOM WE SHARE YOUR PERSONAL DATA

    We share information with third parties that help us operate, provide, improve, integrate, customize, support, and market our Service. We may share some sets of personal data, in particular, for purposes indicated in Section 3 of this Privacy Policy. The types of third parties we share information with include, in particular:

    1. Service providers

      We share personal data with third parties that we hire to provide services or perform business functions on our behalf, based on our instructions. We may share your personal information with the following types of service providers:

      cloud storage providers (Amazon)

      data analytics providers (Facebook, Google, Amplitude)

      marketing partners (in particular, social media networks, marketing agencies, email delivery services; including, Facebook, Google, Sendpulse)

      communication service provider (Zendesk)

      payment service providers

      We describe for what purposes and with which third-party service providers we share information in detail in Section 3 of this Privacy Policy.

    2. Law enforcement agencies and other public authorities

      We may use and disclose personal data to enforce our Terms of Service, to protect our rights, privacy, safety, or property, and/or that of our affiliates, you or others, and to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, or in other cases provided for by law.

    3. Third parties as part of a merger or acquisition

      As we develop our business, we may buy or sell assets or business offerings. Customers' information is generally one of the transferred business assets in these types of transactions. We may also share such information with any affiliated entity (e.g. parent company or subsidiary) and may transfer such information in the course of a corporate transaction, such as the sale of our business, a divestiture, merger, consolidation, or asset sale, or in the unlikely event of bankruptcy.

  6. HOW YOU CAN EXERCISE YOUR PRIVACY RIGHTS

    To be in control of your personal data, you have the following rights:

    Accessing / reviewing / updating / correcting your personal data. You may review, edit, or change the personal data that you had previously provided on the Service.

    Deleting your personal data. You can request erasure of your personal data as permitted by law.

    When you request deletion of your personal data, we will use reasonable efforts to honor your request. In some cases, we may be legally required to keep some of the data for a certain time; in such event, we will fulfill your request after we have complied with our obligations.

    Objecting to or restricting the use of your personal data. You can ask us to stop using all or some of your personal data or limit our use thereof.

    Additional information for EEA-based users

    If you are based in the EEA, you have the following rights in addition to the above:

    The right to lodge a complaint with supervisory authority. We would love you to contact us directly, so we could address your concerns. Nevertheless, you have the right to lodge a complaint with a competent data protection supervisory authority, in particular in the EU Member State where you reside, work or where the alleged infringement has taken place.

    The right to data portability. If you wish to receive your personal data in a machine-readable format, you can send respective request as described below.

    To exercise any of your privacy rights, please send a request to support@harnafit.com.

  7. AGE LIMITATION

    We do not knowingly process personal data from persons under 16 years of age. If you learn that anyone younger than 16 has provided us with personal data, please contact us at support@harnafit.com.

  8. INTERNATIONAL DATA TRANSFERS

    We do business globally. We may transfer personal data to countries other than the country in which the data was originally collected in order to provide the Service set forth in the Terms and Conditions of Use and for purposes indicated in this Privacy Policy. If these countries do not have the same data protection laws as the country in which you initially provided the information, we deploy special safeguards.

    In particular, if we transfer personal data originating from the EEA to countries with not adequate level of data protection, we use one of the following legal bases: (i) Standard Contractual Clauses approved by the European Commission (details available here ), or (ii) the European Commission adequacy decisions about certain countries (details available here ).

  9. CHANGES TO THIS PRIVACY POLICY

    We may modify this Privacy Policy from time to time. If we decide to make material changes to this Privacy Policy, you will be notified through our Service or by other available means and will have an opportunity to review the revised Privacy Policy. By continuing to access or use the Service after those changes become effective, you agree to be bound by the revised Privacy Policy.

  10. CALIFORNIA PRIVACY RIGHTS

    The California Consumer Privacy Act of 2018 ("CCPA") provides additional rights to know, delete and opt-out, and requires us to disclose what personal information we have collected, used, and shared over the last 12 months.

    Section 2 describes the personal information we have collected about you, including the sources of that information. We collect this information for the purposes described in Section 3. We share this information as described in Section 5.

    Under CCPA you as a California resident have the following rights:

    Right to Know. You have the right to request that we disclose to you the personal information we collect, use, or disclose.

    Right to Delete. You have the right to request that we delete your personal information that we have collected from you.

    Right to Opt-Out. CCPA requires that we maintain a separate webpage that allows you to opt out of the sale of your personal information, which can be accessed by clicking the link

    Right to Non-Discrimination. We will not discriminate against you for exercising any of these rights. We will not deny you our services, charge you different prices, or provide you a lower quality of services if you exercise your rights under the CCPA.

    You may designate, in writing or through a power of attorney, an authorized agent to make requests on your behalf to exercise your rights under the CCPA. Before accepting such a request from an agent, we will require the agent to provide proof you have authorized it to act on your behalf, and we may need you to verify your identity directly with us.

    To exercise any of your privacy rights, please send a request to support@harnafit.com.

    California's Shine the Light law gives California residents the right to ask companies once a year what personal information they share with third parties for those third parties' direct marketing purposes. Learn more about what is considered to be personal information under the statute .

    To obtain this information from us, please send an email message to support@harnafit.com which includes "Request for California Privacy Information" on the subject line and your state of residence and email address in the body of your message. If you are a California resident, we will provide the requested information to you at your email address in response.

  11. FOR VIRGINIA RESIDENTS

    This section supplements our Privacy Policy and only applies if you reside in the Commonwealth of Virginia. Where applicable, it describes how we use and process your personal data and explains your particular rights under Virginia Consumer Data Privacy Act (VCDPA).

    1. Disclosures about the use of your personal data

      We may collect and use certain information about you, some of which may be personal data (such as your name, email address, IP address, payment card number, or other information which may be reasonably linked to you), in order to operate the Services and to maximize your experience.

      If you would like more information about the categories of your personal data we collect or the purposes for which we collect them, please read Section 2 and Section 3. To learn more about sharing of your personal data with our business partners and other third parties, please read Section 5.

    2. Data Rights

      Section 6 of our Privacy Policy describes the data rights we offer to all users and how to execute these rights. This includes the right to access, review, correct, update your data, obtain a portable copy of your data, or delete data related to your stored preferences and your use of the Services. Before completing your request, we may require some information sufficient to authenticate your identity.

      Additionally, VCDPA provides Virginia residents with these data rights:

      • Opt out of the Processing of your Personal Data for Targeted Advertising. In order to exercise your choice as a Virginia resident, please email us at support@harnafit.com.

      Please note that we do not process personal data for purposes of (1) the sale of personal data, as defined by the VCDPA, or (2) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.

      • Confirm whether your Personal Data is being Processed. You may confirm whether your personal data is being processed by emailing us at support@harnafit.com.

      • Appeal a Case with regard to your Request. In the case where we declined to take action on your data rights request or have rejected your request, you may contact us at support@harnafit.com to initiate an appeal of this decision. Please use the subject line "Appeal of Refusal to Take Action on Privacy Request" and provide the relevant information in the email. Once we receive your appeal, we will notify you in writing within 60 days of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions.

      If your appeal is denied, you may contact the Office of the Virginia Attorney General by via the contact details available at : www.virginia.gov/agencies/office-of-the-attorney-general/#vagov .

  12. DATA RETENTION

    We will store your personal data for as long as it is reasonably necessary for achieving the purposes set forth in this Privacy Policy (including providing the Service to you), which includes (but is not limited to) the period during which you have an account with the Service. We will also retain and use your personal data as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

  13. HOW "DO NOT TRACK" REQUESTS ARE HANDLED

    This Service does not support "Do Not Track" requests. To determine whether any of the third-party services it uses honor the "Do Not Track" requests, please read their privacy policies.

  14. CONTACT US

    You may contact us at any time for details regarding this Privacy Policy and its previous versions (if any). For any questions concerning your account or your personal data please contact us at support@harnafit.com.

    Effective as of: 2023