Who is responsible?
The MyZinergi entity named in the offer, confirmation or invoice is responsible for personal data it processes for its own purposes. Contact: info@myzinergi.com.
When an independent Coach uses Coach OS for their own client records, that Coach will generally be the controller and MyZinergi will process data on the Coach's instructions under a data processing agreement.
What data do we process?
- account, contact, profile and identification data;
- preferences, goals, language, region and content use;
- appointments, communications, payments, invoices and subscriptions;
- health data you enter or share with a Coach;
- technical, security, session and audit data;
- data required for courses, events, support and complaints.
Why and on what legal basis?
We process data to provide accounts and services, personalise the experience, arrange appointments and payments, provide support and security, comply with legal duties and improve our services responsibly.
Depending on the activity, we rely on performance of a contract, a legal obligation, legitimate interests or consent. Health data is processed only where an applicable exception under data-protection law is available, such as explicit consent or permitted professional healthcare processing.
Personalisation, Guide and AI
Guide and recommendation features may organise information and suggest appropriate next steps. They do not independently make a medical diagnosis.
Human review is required where an outcome may have significant consequences. We do not use health data for general model training without a separate valid legal basis and clear notice.
Transfers outside the EEA
Where a provider processes data outside the European Economic Area, we use a lawful transfer mechanism and additional safeguards where required, such as an adequacy decision or standard contractual clauses.
How long do we keep data?
We retain data only as long as needed for the purpose, the agreement, security, disputes and legal obligations. Administrative records may be kept for statutory tax periods.
Medical-record retention rules apply where the Dutch Medical Treatment Contracts Act (WGBO) applies. A deletion request therefore cannot always be carried out immediately or in full.
How do we protect data?
We use appropriate technical and organisational measures, including access controls, tenant isolation, encrypted connections, logging, backups, multi-factor authentication for sensitive Coach functions and periodic reviews. Suspected misuse or a breach can be reported to info@myzinergi.com.
Your privacy rights
Depending on the circumstances, you may request access, correction, deletion, restriction or portability and object to processing. Consent can be withdrawn at any time without affecting earlier lawful processing.
Submit a request through the privacy environment or by email. You may also complain to the Dutch Data Protection Authority or your local supervisory authority.
Children and representatives
For minors, we follow the applicable rules on consent, representation and access to health data. A parent or representative may act only within their legal authority and the child's interests.
Changes and contact
We may update this statement when services or laws change. Material changes will be announced appropriately and the current version will remain available here.
Privacy questions or requests: info@myzinergi.com.