KKAVYLO

Privacy Policy for KAVYLO

Last updated: July 14, 2026

1. Controller

The controller responsible for the processing of personal data in connection with the KAVYLO app, the associated Apple Watch app, and the KAVYLO website is:

Naomi Stiel Sole proprietor Bonner Str. 301 50968 Köln Germany

Email: naomistiel.apps@outlook.com

In this Privacy Policy, the controller may also be referred to as "KAVYLO", "we", "us", or "our".

2. Scope

This Privacy Policy applies to:

  • the KAVYLO app for iPhone,
  • the associated KAVYLO app for Apple Watch,
  • the KAVYLO website,
  • the registration and management of a KAVYLO account,
  • support requests and other communications with KAVYLO.

Where services provided by other companies are used, the privacy policies of those providers may also apply.

3. Principles of Data Processing

KAVYLO processes personal data only to the extent necessary to provide the app and its functions, manage user accounts and subscriptions, communicate with users, maintain security, or comply with legal obligations.

KAVYLO does not sell personal data.

KAVYLO does not use advertising networks and currently does not display personalized or behavior-based advertising. KAVYLO does not track users across apps or websites for advertising purposes.

Health, fitness, and HealthKit data are not used for advertising, marketing, or advertising-related profiling.

4. Sources of Data

We may obtain personal data from the following sources:

  • directly from you when you create an account, enter information, or upload content,
  • from your device and the KAVYLO app,
  • from Apple Health or HealthKit if you grant access,
  • from your Apple Watch when you use watch-related features,
  • from Apple or Google if you use their sign-in services,
  • from the App Store and RevenueCat in connection with purchases and subscriptions,
  • from other KAVYLO users, for example through invitations, teams, reports, or community interactions,
  • from publicly accessible product databases such as Open Food Facts when you use food search or barcode scanning.

5. Account and Sign-In

To create and manage a KAVYLO account, the following data may be processed:

  • email address,
  • internal user ID,
  • sign-in method,
  • authentication and session data,
  • registration date and last sign-in date,
  • technical security information,
  • where applicable, first name, last name, or display name.

Sign-In with Email and Password

If you register using an email address and password, authentication is provided through Supabase Auth. Data required for account creation, sign-in, session management, email confirmation, and, where applicable, password recovery is processed.

Sign in with Apple

If you use Sign in with Apple, we receive the information Apple provides after your approval. This may include an Apple user identifier, your email address, an Apple private relay email address, and your name during the first sign-in.

Sign in with Google

If you use Google Sign-In, we receive the information released by Google. This may include a Google user identifier, your email address, and your name.

Apple and Google may also process sign-in data under their own responsibility.

Purpose: account registration, sign-in, account security, and session management. Legal basis: Article 6(1)(b) GDPR.

6. Profile, Settings, and Local App Data

Depending on how you use KAVYLO, the following data may be processed:

  • display name and username,
  • profile picture or avatar,
  • language and region,
  • training and nutrition goals,
  • units and display preferences,
  • visibility and privacy settings,
  • reminder and notification settings,
  • other voluntary profile information.

Certain settings, cached data, and recently displayed values may be stored locally on your device. Deleting the app generally removes local app data, but it does not automatically delete your KAVYLO account or data stored in the cloud.

Purpose: personalization and provision of the app. Legal basis: Article 6(1)(b) GDPR and, for purely optional information, Article 6(1)(a) GDPR.

7. Training, Progress, and HYROX Data

When you use training and progress features, the following data may be processed:

  • sport and workout type,
  • training plans and scheduled workouts,
  • exercises and workout steps,
  • sets, repetitions, weights, and load information,
  • duration, distance, pace, and speed,
  • workout history and personal records,
  • calorie and heart-rate values,
  • perceived exertion values such as RPE,
  • readiness values and recovery or regeneration data,
  • daily check-in values such as sleep quality, stress, energy, and physical complaints,
  • badges, rewards, challenge participations, and participations in seasonal programs,
  • body weight and body measurements,
  • body-fat percentage and waist circumference,
  • progress goals and progress photos,
  • HYROX simulations, stations, split times, and evaluations,
  • training notes and voluntary comments,
  • statistics and recommendations derived from this information.

Purpose: recording and evaluating training and progress, creating summaries, planning workouts, and providing personalized recommendations. Legal basis: Article 6(1)(b) GDPR. Where health data is involved, Article 9(2)(a) GDPR also applies based on your explicit consent.

Location Data for Route-Based Workouts

Precise GPS coordinates are only collected and stored when you actively start a route-based workout, such as an outdoor run or ride, and only for as long as that workout is running. This location data is used exclusively for route and workout functions, for example route recording, distance, pace, and the map view of a workout.

Precise location data is not used for advertising, marketing, or advertising-related profiling. You can grant or withdraw location access at any time in iOS Settings. Without location access, route-based workouts can still be recorded without a route.

8. Nutrition Data

When you use nutrition features, the following data may be processed:

  • meals and foods,
  • calorie and nutritional values,
  • quantities and portion sizes,
  • water intake,
  • nutrition goals and dietary preferences,
  • allergies and intolerances,
  • fasting periods,
  • recipes and saved foods,
  • weekly plans and meal-prep data,
  • pantry items and grocery lists,
  • meal photos,
  • notes and voluntary information,
  • weight and body data,
  • summaries, statistics, and recommendations derived from this information.

Nutrition information may reveal details about your health, intolerances, or personal lifestyle.

Purpose: nutrition tracking, planning, evaluation, and provision of the nutrition features selected by you. Legal basis: Article 6(1)(b) GDPR. Where health data is involved, Article 9(2)(a) GDPR also applies based on your explicit consent.

9. Open Food Facts and Barcode Scanner

KAVYLO may use Open Food Facts to retrieve food information using a barcode or search term.

The following information may be transmitted to Open Food Facts:

  • entered search term,
  • scanned barcode,
  • technical connection data such as IP address, time, and device information.

Product information retrieved from Open Food Facts may include the product name, brand, quantity, product image, and nutritional values. If you save a product in KAVYLO, the imported product data is associated with your KAVYLO account.

Camera access is only requested after you grant permission. Camera images are used for scanning and are not saved as photographs unless you actively choose a separate storage function.

Purpose: food search and automatic import of product information. Legal basis: Article 6(1)(b) GDPR.

10. Photos and Files

Depending on the feature, you may upload profile pictures, progress photos, meal photos, or community content.

Private photos are stored in access-restricted storage areas intended for that purpose. Profile or community content that you publish may be visible to other users.

When a photo or file is uploaded, the following data may also be processed:

  • file name,
  • file type and size,
  • upload time,
  • internal user and content ID,
  • technical metadata.

Selecting an image through the iOS photo picker does not automatically give KAVYLO full access to your photo library. KAVYLO generally receives access only to the file you select.

Legal basis: Article 6(1)(b) GDPR and, where publication is voluntary, Article 6(1)(a) GDPR.

11. Apple Health, HealthKit, and Health Data

KAVYLO may access Apple Health and HealthKit. Access only occurs after you explicitly grant the relevant permission through iOS.

Depending on the feature you activate and the permissions you grant, KAVYLO may read the following HealthKit data types:

  • steps,
  • active energy or active calories,
  • heart rate,
  • resting heart rate,
  • sleep data,
  • workouts and workout duration,
  • workout distance,
  • body weight,
  • body-fat percentage,
  • waist circumference,
  • dietary energy or calories,
  • protein,
  • carbohydrates,
  • fat,
  • fiber,
  • sugar,
  • sodium or salt,
  • water intake.

Depending on the synchronization features you activate, KAVYLO may also write data recorded in KAVYLO to Apple Health. This may include workouts, nutrition values, water intake, and selected body or progress values.

Apple's permission overview shows which data types KAVYLO is permitted to read or write. You may change or withdraw individual permissions at any time in iOS Settings or in the Apple Health app.

Refusing or withdrawing a HealthKit permission generally affects only the relevant HealthKit feature. Other parts of KAVYLO remain available unless the permission is technically required for that specific function.

HealthKit data is used solely to provide the health, training, nutrition, progress, HYROX, and Apple Watch features selected by you.

HealthKit data is not:

  • sold,
  • used for advertising,
  • used for marketing,
  • transmitted to advertising networks,
  • used for advertising-related profiling.

HealthKit values may initially be processed locally on your device. If you import, synchronize, or save values in KAVYLO for cross-device histories, reports, or evaluations, the relevant data may be associated with your KAVYLO account and stored through the KAVYLO backend.

KAVYLO does not use a separate iCloud database to store your health data. If you enable Apple Health synchronization through iCloud, that processing is carried out under Apple's responsibility.

Legal basis: Article 6(1)(a) GDPR and, for health data, Article 9(2)(a) GDPR based on your explicit consent.

You may withdraw your consent at any time with effect for the future by disabling the relevant synchronization feature in KAVYLO and withdrawing the permissions in Apple Health or iOS Settings. The lawfulness of processing carried out before the withdrawal remains unaffected.

12. Apple Watch and Watch Connectivity

If you use the Apple Watch app, the following data may be transferred between your iPhone and Apple Watch:

  • scheduled workouts,
  • workout steps and exercises,
  • start, pause, and completion status,
  • workout duration,
  • heart rate,
  • active calories,
  • distance,
  • completed workouts and workout results,
  • selected nutrition or water information,
  • technical synchronization data.

The transfer between your devices uses system functions provided by Apple. Workouts and measurements recorded on Apple Watch may be stored in Apple Health and then displayed or evaluated in KAVYLO according to your permissions.

Legal basis: Article 6(1)(b) GDPR and, where health data is involved, Article 9(2)(a) GDPR.

13. Teams, Invitations, and HYROX Team Features

When you use team features, the following data may be processed:

  • team name,
  • team ID,
  • user and member IDs,
  • roles and permissions,
  • team slots and assignments,
  • invitations and invitation tokens,
  • invitation status,
  • team notes,
  • shared plans or simulations,
  • training and result data shared within the team.

Invitation links may be shared outside KAVYLO. People who receive such a link may be able to see that it relates to a KAVYLO or HYROX team invitation.

Purpose: team management, invitations, and shared training features. Legal basis: Article 6(1)(b) GDPR.

14. Community, Public Content, and Moderation

If you use community features, the following data may be processed:

  • display name and username,
  • profile picture,
  • posts and comments,
  • badges, rewards, and visible achievements,
  • participation in community challenges and seasonal programs,
  • likes and other interactions,
  • publicly shared workouts, plans, or recipes,
  • creation and modification dates,
  • reports and report reasons,
  • blocks,
  • moderation decisions,
  • related user and content IDs.

Content you publish may be viewed by other users. Other users may be able to copy, save, or take screenshots of publicly accessible content. KAVYLO has only limited control over such independent actions by other users.

To protect the community, reported content may be reviewed, temporarily hidden, or deleted. Accounts may be restricted or suspended if they violate the Terms of Use.

Purpose: providing the community, enabling communication, protecting users, and enforcing the Terms of Use. Legal basis: Article 6(1)(b) GDPR and Article 6(1)(f) GDPR. The legitimate interest is maintaining a safe, functional, and respectful community and preventing misuse.

Gamification, Badges, Rewards, Challenges, and Seasonal Programs

For clarity, these features mean the following in KAVYLO:

  • Badges are digital achievements that are unlocked automatically when existing progress or activity conditions are met.
  • Rewards are digital items that can be unlocked inside the app. They have no monetary value, cannot be exchanged for money, and cannot be transferred.
  • Community challenges are shared time-based or goal-based challenges.
  • Seasonal programs consist of several tasks with saved progress.
  • Readiness is a non-medical assessment of your training readiness. It is not a diagnosis and not a medical statement.
  • Recovery and regeneration cover your recovery status and the regeneration measures suggested or recorded in the app.
  • Stress, energy, pain, and physical complaints are voluntary entries in your daily check-in.

Gamification data may include points, levels, badges, rewards, challenge participations, program progress, and the times at which unlocks occurred.

KAVYLO does not offer private direct messages between users. Community interaction takes place through posts, comments, and other visible community functions.

Purpose: providing progress, motivation, and community features and displaying your achievements. Legal basis: Article 6(1)(b) GDPR.

15. KAVYLO Pro, In-App Purchases, and RevenueCat

KAVYLO Pro may be offered through the Apple App Store as an in-app purchase or subscription. Payments are processed by Apple. KAVYLO does not receive full credit-card or bank-account details.

KAVYLO uses RevenueCat to manage and verify purchases and subscriptions.

The following data may be processed:

  • internal KAVYLO or RevenueCat user ID,
  • anonymous RevenueCat ID,
  • product identifier,
  • purchase and transaction information,
  • purchase date,
  • subscription status,
  • renewal and expiration dates,
  • entitlement status,
  • trial or offer status,
  • purchase-restoration information,
  • technical device and app information.

RevenueCat is used to recognize KAVYLO Pro access across devices, restore purchases, and unlock purchased features.

Apple processes the actual payment and App Store account under its own responsibility.

Legal basis: Article 6(1)(b) GDPR and Article 6(1)(c) GDPR where statutory documentation or retention obligations apply.

Deleting your KAVYLO account does not automatically terminate a subscription purchased through Apple. You must cancel the subscription separately through your Apple Account or the App Store subscription management page.

16. Push Notifications and Local Reminders

If you enable notifications, the following data may be processed:

  • Apple push token,
  • internal user ID,
  • device assignment,
  • language,
  • operating system and app version,
  • notification settings,
  • delivery and technical status information.

Push notifications may include training and nutrition reminders, team or community updates, and technical or account-related messages.

KAVYLO does not request notification permission automatically during the first app launch. Permission is requested only when you choose to enable notifications.

Local reminders may also be scheduled directly on your device. These reminders are generally managed by iOS on your device.

You may disable notifications at any time in KAVYLO settings or iOS Settings.

Legal basis: Article 6(1)(a) GDPR based on your consent.

17. Technical Data, Security, and Troubleshooting

When KAVYLO is used, technical data may be processed automatically, including:

  • IP address,
  • device type and model,
  • operating system and version,
  • app version and build number,
  • language and region,
  • request times,
  • technical user and session identifiers,
  • accessed functions,
  • network and server information,
  • error, diagnostic, and security logs.

This data is used to provide the app, identify errors, prevent attacks and misuse, secure sessions, and maintain technical stability.

This technical data is not used for advertising.

Legal basis: Article 6(1)(b) GDPR where processing is necessary to provide the app, and Article 6(1)(f) GDPR. The legitimate interest is the secure, stable, and misuse-resistant operation of KAVYLO.

18. Supabase and Backend Infrastructure

KAVYLO uses Supabase as its backend infrastructure. Supabase provides functions including:

  • authentication,
  • database services,
  • file storage,
  • real-time functionality,
  • server-side functions,
  • session management,
  • access controls and security policies.

Supabase may store and process account, profile, training, nutrition, progress, team, community, file, push-notification, and purchase-assignment data.

Access to private data areas is restricted through technical access rules. Users should generally only be able to access data intended for them.

The primary database of the KAVYLO Supabase project is hosted in the Central EU (Frankfurt), Germany region.

Supabase may use additional infrastructure providers and subprocessors for certain technical services, backups, support, security, and platform operations.

Supabase generally processes data as a technical service provider on behalf of KAVYLO. Supabase may process certain technical, security-related, and billing-related data under its own responsibility.

Legal basis: depending on the relevant app feature, Article 6(1)(b), Article 6(1)(c), or Article 6(1)(f) GDPR and, where health data is involved, Article 9(2)(a) GDPR.

19. KAVYLO Website, Lovable, and Website Statistics

The KAVYLO website is provided with technical support from Lovable.

When the website is accessed, the following technical data may be processed:

  • IP address,
  • date and time of access,
  • requested page or file,
  • browser type and version,
  • operating system,
  • referrer address,
  • device information,
  • HTTP status code,
  • technical error and security information.

This data is technically necessary to deliver the website, identify attacks, and ensure stable operation.

If forms are offered on the website and you use them, the information you enter is processed for the purpose stated in the relevant form.

The KAVYLO website does not use advertising networks, personalized advertising, cross-site tracking, or any additional third-party analytics service installed by KAVYLO, such as Google Analytics.

As part of its hosting and platform services, Lovable may process technical access and usage data and may provide KAVYLO with aggregated website statistics. These statistics may include information such as page views, visits, approximate country, device type, referral source, session duration, and similar usage metrics.

KAVYLO uses these statistics only to understand the general use and technical performance of the website. They are not used by KAVYLO for personalized advertising, cross-site tracking, or advertising-related user profiling.

Technically necessary cookies, local storage, or similar storage technologies may be used where required for navigation, security, or a function expressly requested by the user. Where consent is legally required for non-essential technologies, those technologies may only be used after the required consent has been obtained.

Lovable may use its own infrastructure providers as technical service providers.

Legal basis: Article 6(1)(b) GDPR for services requested by you and Article 6(1)(f) GDPR for security, technical operation, and the evaluation of aggregated website performance. Where consent is legally required, Article 6(1)(a) GDPR applies.

20. Support and Communication through Outlook

If you contact KAVYLO by email, the following data may be processed:

  • name and email address,
  • content of your message,
  • attachments,
  • date and time of the communication,
  • technical email metadata,
  • where necessary, user or transaction information required to process your request.

The contact address is provided through Microsoft Outlook. Microsoft may process email data and technical connection data as a service provider.

Purpose: processing your request, technical support, and communication. Legal basis: Article 6(1)(b) GDPR for contract-related requests and Article 6(1)(f) GDPR for general inquiries. The legitimate interest is responding to inquiries and documenting support cases.

21. Data Exports and Sharing Initiated by You

A data export is available. You can export a copy of your KAVYLO data, for example in CSV or PDF format, and you can also request a copy of your personal data from us at any time.

If you export a file or share it through the iOS share sheet, you decide which app, person, or platform receives the file. Once the file is transferred to a third party selected by you, further processing is governed by that third party's privacy policy.

Exported files may contain sensitive health, fitness, or nutrition data. You should only share them with trusted recipients and store them securely.

22. Recipients and Service Providers

Where necessary for the relevant purpose, personal data may be transferred to the following categories of recipients:

  • Apple, for the App Store, in-app purchases, Apple Account, Sign in with Apple, Apple Watch, HealthKit, and push notifications,
  • Supabase, for authentication, database services, storage, and backend functions,
  • RevenueCat, for purchase, subscription, and entitlement status,
  • Google, if you use Google Sign-In,
  • Open Food Facts, if you use food search or barcode scanning,
  • Lovable, for technical provision of the KAVYLO website and aggregated website statistics,
  • Microsoft, for processing emails through Outlook,
  • technical hosting, network, and security providers,
  • public authorities or other bodies where required by law,
  • legal or tax advisers where necessary to comply with legal obligations or establish, exercise, or defend legal claims.

Data is disclosed only where necessary to provide a feature, where you have consented, where a legal obligation applies, or where there is a legitimate interest.

23. International Data Transfers

Some providers or their subprocessors may process personal data outside Germany or outside the European Economic Area, particularly in the United States.

Where the European Commission has adopted an adequacy decision for the relevant country or recipient, data may be transferred on that basis.

Otherwise, data is transferred only where appropriate safeguards are in place, particularly the European Commission's Standard Contractual Clauses, or where another legal exception applies.

Despite contractual and technical safeguards, it cannot be completely ruled out that authorities in third countries may access data under the laws applicable there.

24. Overview of Legal Bases

KAVYLO processes personal data in particular on the following legal bases:

Performance of a Contract – Article 6(1)(b) GDPR

This applies in particular to:

  • registration and sign-in,
  • provision of app functions,
  • storage of your training and nutrition data,
  • team and community features,
  • KAVYLO Pro,
  • restoration of purchases,
  • processing contract-related support requests.

Consent – Article 6(1)(a) GDPR

This applies in particular to:

  • push notifications,
  • optional permissions,
  • voluntary publication of content,
  • certain optional features,
  • non-essential website technologies where consent is legally required.

Health Data – Article 9(2)(a) GDPR

Where KAVYLO processes health data, it generally does so based on your explicit consent in conjunction with Article 6(1)(a) GDPR.

Legitimate Interests – Article 6(1)(f) GDPR

This applies in particular to:

  • IT and account security,
  • error analysis,
  • misuse and fraud prevention,
  • protection of the community,
  • moderation,
  • establishment, exercise, or defense of legal claims,
  • stable operation of the app and website,
  • evaluation of aggregated website performance.

Legal Obligations – Article 6(1)(c) GDPR

This applies in particular to statutory retention, documentation, disclosure, or cooperation obligations.

25. Required and Optional Information

Certain account information is required to create a KAVYLO account, particularly an email address or a user identifier provided by the selected sign-in service.

Without this required information, a personal KAVYLO account cannot be provided.

The following features are generally optional:

  • Apple Health and HealthKit access,
  • Apple Watch connectivity,
  • push notifications,
  • profile picture,
  • progress and meal photos,
  • public community content,
  • teams and invitations,
  • additional profile, health, or nutrition information.

If you do not provide optional information or permissions, the relevant feature may be unavailable or limited. Other parts of the app generally remain available unless the relevant permission is technically required.

26. Retention Periods

Personal data is stored only for as long as necessary for the relevant purpose or for as long as legal obligations require longer storage.

The following criteria generally apply:

  • Account data: for the duration of the KAVYLO account,
  • Profile and app data: until deleted by you or until the account is deleted,
  • Training, nutrition, and progress data: until the relevant entries or account are deleted,
  • Health data: until the relevant KAVYLO data or account is deleted; withdrawing a HealthKit permission does not automatically delete data already stored in KAVYLO,
  • Photos and files: until the associated content or account is deleted,
  • Community content: until deleted by you, removed through moderation, or deleted with the account,
  • Reports and moderation data: for as long as necessary to investigate reports, protect the community, prevent misuse, or establish, exercise, or defend legal claims,
  • Push tokens: until notifications are disabled, the user signs out, the token becomes invalid, or the account is deleted,
  • Purchase and subscription data: for as long as necessary to recognize purchased access, restore purchases, or comply with legal obligations,
  • Support communications: until the request is fully resolved and beyond that where required for documentation, legal defense, or statutory obligations,
  • Technical logs: only for as long as necessary for security, troubleshooting, and misuse prevention,
  • Website access and usage data: only for as long as required for technical operation, security, aggregated website statistics, and any applicable platform retention periods,
  • Business records subject to statutory retention: for the applicable statutory retention period.

After deletion, data may remain in technically necessary backups for a limited time until it is deleted through the regular backup and overwrite cycle. During this period, it is generally no longer used for normal app operations.

Fully anonymized data that can no longer be linked to an individual may be retained indefinitely.

27. Account Deletion

You may request deletion of your KAVYLO account through the relevant function in the app or by contacting us at naomistiel.apps@outlook.com.

When an account is deleted, personal data associated with the account is generally deleted or anonymized unless legal obligations, security requirements, ongoing disputes, or legitimate claims require limited further retention.

Publicly published content will be removed or anonymized where technically and legally possible. Copies independently stored by other users outside KAVYLO cannot be deleted by KAVYLO.

Deleting your account does not terminate a subscription purchased through Apple. You must cancel the subscription separately through Apple's subscription management.

28. Withdrawal of Consent and Permissions

You may withdraw consent at any time with effect for the future.

Depending on the feature, you may do this by:

  • disabling the feature in KAVYLO settings,
  • withdrawing a permission in iOS Settings,
  • changing access rights in Apple Health,
  • disabling push notifications,
  • deleting voluntarily provided data,
  • contacting naomistiel.apps@outlook.com.

The withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

29. Automated Recommendations and Decisions

KAVYLO may automatically generate summaries, statistics, or recommendations based on your training, nutrition, goal, and progress data.

These functions are provided solely for your personal information and training or nutrition support.

KAVYLO does not make solely automated decisions that produce legal effects concerning you or similarly significantly affect you.

30. Minors

KAVYLO is generally intended for persons aged 16 or older and is not specifically directed at younger children.

Persons under the age of 16 may use KAVYLO only where the required consent of a parent or legal guardian has been provided and the use is permitted under applicable law.

If we become aware that personal data of a child has been processed without the required consent, we will take appropriate steps to investigate and, where necessary, delete the data.

31. Your Data Protection Rights

Where the legal requirements are met, you have the following rights:

  • the right to access your personal data,
  • the right to correct inaccurate or incomplete data,
  • the right to deletion,
  • the right to restriction of processing,
  • the right to data portability,
  • the right to object to processing based on legitimate interests,
  • the right to withdraw consent with effect for the future,
  • the right not to be subject to a solely automated decision that produces legal or similarly significant effects,
  • the right to lodge a complaint with a data protection supervisory authority.

To exercise your rights, contact:

Naomi Stiel Bonner Str. 301 50968 Köln Germany Email: naomistiel.apps@outlook.com

To prevent unauthorized disclosure, we may request reasonable proof of identity.

32. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates applicable data protection law.

The supervisory authority responsible for KAVYLO's place of business is:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia Postfach 20 04 44 40102 Düsseldorf Germany

Email: poststelle@ldi.nrw.de

You may also contact another supervisory authority that is competent under applicable law.

33. Data Security

KAVYLO uses appropriate technical and organizational security measures to protect personal data against:

  • unauthorized access,
  • loss,
  • alteration,
  • unauthorized disclosure,
  • destruction,
  • other unlawful processing.

Depending on the system, these measures may include encrypted data transmission, access controls, authentication, database policies, private storage areas, and restricted permissions.

No electronic system can guarantee absolute security. You should also take appropriate steps to protect your device, Apple Account, KAVYLO account, and login credentials.

34. Changes to This Privacy Policy

This Privacy Policy may be updated if:

  • new features are introduced,
  • existing processing activities change,
  • new service providers are used,
  • legal requirements change,
  • security or transparency considerations require an update.

The current version will be published in the KAVYLO app or on the KAVYLO website. Where changes are material, we may also inform you through the app or by another appropriate method.

35. Contact

For questions about privacy, the processing of your data, or the exercise of your rights, contact:

Naomi Stiel Sole proprietor Bonner Str. 301 50968 Köln Germany

Email: naomistiel.apps@outlook.com