Legal · v1.0

Privacy Policy

Last updated: 29 August 2026

This Privacy Policy explains how Triforma collects, uses, shares, stores and protects your personal data, and the rights you have under the EU General Data Protection Regulation (GDPR) and Cyprus Law 125(I)/2018. By using Triforma you agree to this policy.

1. Who we are (Data Controller)

The data controller is Sonovita Company Ltd, a company registered in the Republic of Cyprus (registration number HE 448674), registered office Melanos 2, House 2, Chloraka, 8220, Paphos, Cyprus.

Contact for privacy matters: info@triforma.app.

2. Important note on health data

Triforma processes data about your body and training — heart rate, heart-rate variability (HRV), sleep, recovery, readiness and related metrics. Under GDPR Article 9 this is a special category of personal data ("health data"). We only process it with your explicit consent, which you can withdraw at any time by disconnecting your services or contacting us.

3. Data we collect

Account & profile. Name, email, date of birth, sex, height, weight, sport and discipline, experience, goals and target races, training zones/thresholds (e.g. FTP, threshold pace, heart-rate zones), injuries and limitations, time zone and notification preferences.

Training & activity data from connected services — distance, duration, pace/speed, power, heart rate, elevation, activity type and training load.

Recovery & health data (special category) from connected services — sleep, HRV, resting heart rate, stress, readiness.

Connected services. Garmin, WHOOP, Oura, Strava, Zwift, Training Peaks and Apple (Apple Health / Apple Watch). We connect through each provider's official, secure authorization (OAuth) and access only the data needed to run the service.

Calendar data. If you connect a calendar, we read events to schedule training around your life. We use this only for planning and do not store more than needed.

Communications. Messages and voice notes you send to the Triforma assistant in Telegram, and post-session feedback you choose to leave.

Payment data. Handled by our payment processor; we do not store full card details.

Technical data. Access tokens for connected services, device/usage and log data needed to operate and secure the service.

4. Legal bases for processing

  • Explicit consent — for health/recovery data and for connecting third-party services (GDPR Art. 9(2)(a) and Art. 6(1)(a)).
  • Performance of a contract — to provide the service you or your coach signed up for (Art. 6(1)(b)).
  • Legitimate interests — to secure, maintain and improve the service (Art. 6(1)(f)).
  • Legal obligation — e.g. tax and accounting records (Art. 6(1)(c)).

5. How we use your data

  • Analyze training and recovery, compute load and form, and raise risk flags.
  • Generate summaries, plan drafts, adaptations and answers for the coach to review.
  • Send reminders, alerts, daily summaries and wellbeing prompts.
  • Process natural-language commands (text and voice) in the assistant.
  • Operate, secure and improve the service and handle billing.

6. AI processing and the MCP integration

Triforma uses AI/large-language-model providers to analyze data and generate text (summaries, plans, answers). Triforma also supports MCP (Model Context Protocol), which lets you connect Triforma to an external AI assistant of your choice (for example Claude or ChatGPT) and operate the platform by conversation.

  • When you use an AI feature, relevant data may be sent to the AI provider to process your request only.
  • We use providers under data-processing terms that do not permit training their models on your data via their API.
  • If you connect your own external AI through MCP, that assistant and its provider process your data under their terms — review them before connecting.
  • AI output is advisory. Anything that changes an athlete's plan or is sent to an athlete is confirmed by a human before it takes effect.

7. Sharing your data

We share data only as needed to run the service:

  • with your coach (if you are an athlete) or your athletes within their own scope (if you are a coach);
  • with processors acting on our behalf under contract — hosting and database, Telegram, the connected wearable/service APIs, AI/LLM providers, our payment processor and analytics;
  • where required by law.

We do not sell your personal data or use it for advertising.

8. International transfers

Some processors may be located outside the European Economic Area. Where that happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) or an adequacy decision.

9. Retention

We keep your data for as long as your account is active and as needed to provide the service, then delete or anonymize it, except where longer retention is required by law (e.g. accounting records). You can request deletion at any time.

10. Security

We store data securely and protect access tokens for connected services using encryption and a secrets manager. We treat missing data as missing — Triforma flags gaps and does not draw conclusions from absent data.

11. Your rights

Under the GDPR you have the right to: access your data; rectify it; erase it; restrict or object to processing; data portability; and withdraw consent at any time. You can also disconnect any connected service at any time.

To exercise these rights, contact info@triforma.app.

You have the right to lodge a complaint with the Cyprus supervisory authority: Office of the Commissioner for the Protection of Personal Data, Nicosia, Cyprus — www.dataprotection.gov.cy.

12. Children

Triforma is not intended for anyone under 16. We do not knowingly collect data from children under 16.

13. Changes

We may update this policy as the product evolves. The current version is posted here with an updated date; for material changes we will notify users.

14. Contact

Privacy questions: info@triforma.app. Operator: Sonovita Company Ltd, Cyprus (HE 448674).