Personal Data Treatment Policy

Version 1.0 — March 2026

IMPORTANT NOTICE

This policy is issued by COPAIRO, a project currently operated by an individual based in Pereira, Risaralda, Colombia. Once COPAIRO S.A.S. is formally incorporated, the data controller responsibility will be transferred to said legal entity, and this policy will be updated accordingly. Data subjects will be notified via registered email. The data controller will fully identify themselves upon exercise of data subject rights under applicable law.

1. Data Controller

ControllerCOPAIRO
DomicilePereira, Risaralda, Colombia
Contact email[email protected]
DescriptionManagement platform for gyms and sports centers

Note: When a data subject exercises any of their rights through written communication to the contact email, the data controller will fully identify themselves with their full name, identification document, and domicile, as required by applicable law.

2. Applicable Legal Framework

This policy is governed by applicable data protection laws of the data subject's jurisdiction:

Americas

  • Colombia: Statutory Law 1581/2012 and Decree 1377/2013.
  • Mexico: LFPDPPP.
  • Argentina: Law 25,326.
  • Brazil: LGPD (Law 13,709/2018).
  • Chile: Law 19,628.
  • Peru: Law 29733.
  • United States: CCPA, CPRA, and applicable state laws.
  • Canada: PIPEDA.

European Union and EEA

GDPR — Regulation (EU) 2016/679. Applicable when the data subject resides in the EU/EEA or when COPAIRO directs services to said territories.

Legal basis under GDPR: Explicit consent (Article 6(1)(a)). May be withdrawn at any time without affecting lawfulness of prior processing.

United Kingdom

UK GDPR and Data Protection Act 2018.

In case of conflict, local legislation shall prevail.

3. Personal Data Collected

COPAIRO collects personal data differentiated by user profile:

3.1. Gym owners, administrators, or operators

  1. Full name.
  2. Email address.
  3. Phone/WhatsApp (optional).
  4. Gym name.
  5. City and country.
  6. Role (owner, administrator, partner, employee, other).
  7. Approximate number of active members.
  8. Services offered (weight training, crossfit, yoga, swimming, martial arts, etc.).
  9. Current management software (optional).

3.2. End users (gym members)

  1. Full name.
  2. Email address.
  3. City and country.
  4. Type of physical activity (optional).

COPAIRO does not collect sensitive data (biometric, health, sexual orientation, ethnic origin, religious beliefs, political opinions, financial data, or minors' data). No cookies, automated tracking, or automated decision-making.

4. Purposes of Data Processing

For gym owners and administrators

  1. Register interest as potential client.
  2. Send development, launch, beta, and availability communications.
  3. Offer early access, demos, or special conditions.
  4. Understand market needs for product improvement.

For end users

  1. Register interest as potential user.
  2. Communicate app availability in their city or gym.

For both profiles

  1. Aggregated anonymous statistical analysis without individual identification.

COPAIRO will not sell, rent, assign, or share personal data with third parties for purposes other than described herein, except as required by law or with express authorization.

5. Consent

Collection requires free, express, specific, informed, and unambiguous consent through explicit acceptance of this policy when completing the registration form.

Data subjects may withdraw consent at any time by writing to [email protected], without affecting lawfulness of prior processing.

6. Data Subject Rights

Data subjects have the following rights under applicable legislation:

  1. Access: know what data COPAIRO holds and confirm processing.
  2. Rectification: correct inaccurate, incomplete, or outdated data.
  3. Erasure (right to be forgotten): delete data when no longer necessary or consent withdrawn.
  4. Withdrawal of consent: revoke consent at any time.
  5. Portability: receive data in structured, machine-readable format (under GDPR/LGPD).
  6. Objection: object to processing for certain purposes.
  7. Restriction: restrict processing under certain circumstances (under GDPR).
  8. Lodge a complaint: file with competent authority. Colombia: SIC. EU: supervisory authority.

Requests to [email protected] with full name, description, and contact info. Response: 15 business days (1 month under GDPR). The controller will fully identify themselves when addressing the request.

7. Storage and Security

Data stored on platforms with adequate technical and organizational security. Servers in Colombia, US, or countries with adequate protection. Encryption in transit and at rest where feasible.

8. Data Retention

Data retained only as necessary. Secure deletion within 30 calendar days of erasure request, purpose fulfillment, or consent withdrawal, unless legally required otherwise.

9. International Data Transfers

Data may be stored internationally via cloud services. For EU/EEA subjects: transfers only to countries with adequate protection or appropriate safeguards per GDPR Chapter V.

10. Policy Modifications

COPAIRO may modify this policy at any time. Updated upon incorporation of COPAIRO S.A.S. Material changes communicated via email. Data subjects may exercise erasure if they disagree.

11. Contact

ControllerCOPAIRO
Email[email protected]
DomicilePereira, Risaralda, Colombia
Data protection authority (Colombia)SIC — www.sic.gov.co

Last updated: March 2026