Sospita Privacy Policy


Effective Date: May 06, 2025
SOSPITA Yazılım Limited Şirketi (“Sospita”, “we”, “us”, “our”) is committed to protecting personal data and ensuring compliance with the EU General Data Protection Regulation (GDPR), the Turkish Personal Data Protection Law (KVKK), and other applicable privacy regulations.
This Privacy Policy explains how we collect, use, store, and protect personal data processed through our Sospita-SafeGuard platform, including e-Permit-to-Work, Risk Assessment, and Observation Management workflows and Sospita Fitness (Sports Academy Management) .

1. Roles Under GDPR

1.1 Sospita as Data Processor (Platform Data)

For all data entered into the Sospita-SafeGuard platform (PTW, risk assessments, observations, user accounts), Sospita Fitness (Sports Academy Management) Sospita acts as a Data Processor.
The subscribing organization acts as the Data Controller and determines what data is processed and for what purpose.

1.2 Sospita as Data Controller (Website, Marketing, Billing)

We act as a Data Controller for:
* Website visitors
* Support inquiries
* Demo requests
* Marketing communication
* Billing and subscription administration

2. Personal Data We Process
2.1 Platform Users (On behalf of the Organization)

- Name, surname
- Email address
- Role (admin, user)
- Organization affiliation
- Account activity and audit logs
- Workflow actions (permits, approvals, observations, comments)
- Uploaded documents/photos (if included in PTW or observation records)

All such data is determined and controlled by the subscribing organization.

2.2 Technical and Security Data

Collected automatically during platform use:
- IP address
- Device/browser type
- Operating system
- Login times
- Error logs and performance metrics

Used to secure, maintain, and improve the platform.

2.3 Payment and Subscription Data

- Organization contact details
- Subscription plan
- Billing information
Payments are handled via:
- IYZICO
- Apple App Store
- Google Play Store
We do not process credit card or bank information.

2.4 Website Cookies & Analytics

- Essential cookies (no consent required)
- Google Analytics (IP anonymized; no personal data tracking)

See our Cookie Notice for details.

2.5 Health and Fitness Data (Sospita Fitness)

When using Sospita Fitness features, we may collect and process health and fitness-related data.
This includes:
- Physical attributes (height, weight, age, sex)
- Performance measurements (speed, jump height, strength metrics, etc.)
- Workout activity data (completed workouts, schedules, progress)
- Health-related data obtained via integrations such as:
- Apple HealthKit
- Android Health ConnectThis data may include:
- Activity levels
- Sleep patterns
- General wellness indicators (categorical data only)

We do NOT collect clinical medical records or sensitive diagnostic data.This data is collected only with user consent and can be revoked at any time through device settings.

3. Purposes of Processing

We process data to:
* Provide and operate the Sospita-SafeGuard platform
* Authenticate users and enforce access control
* Execute  workflows
* Maintain audit trails and safety compliance
* Improve performance and reliability
* Manage customer subscriptions and provide support
* Comply with legal and regulatory obligations
* Ensure system security and prevent fraud

3.1 AI Processing (Sospita Fitness)
Sospita Fitness uses artificial intelligence (AI) to provide personalized coaching insights and recommendations.
AI processing may use:
- Workout activity data
- Performance measurements
- Health-related signals (if enabled by the user)AI is used to:
- Generate daily coaching suggestions
- Provide performance evaluations
- Enhance user experience
All AI outputs are informational and should not be considered medical advice.
Data used for AI processing:
- Is handled securely
- Is not sold or used for advertising
- Is only used to provide app functionality
Users can control data sharing via app settings and device permissions.

Health and fitness data is never shared with third parties for advertising or marketing purposes.

4. Legal Bases for Processing (GDPR)

Platform (Processor role)

* Performance of a contract (Art. 6(1)(b))
* Legitimate interest of the Controller for safety management (Art. 6(1)(f))
* Legal obligation where applicable (incident reporting, safety records)

Website & Marketing (Controller role)

* Consent (non-essential cookies)
* Legitimate interest (security, analytics, communication)

5. Data Hosting & International Transfers

EU-Only Hosting for Platform Data

All platform data is stored exclusively in the European Union, using:
* Amazon Web Services (AWS) – EU (Frankfurt & Ireland)
* Render Web Services - EU (Frankfurt)
* Google Cloud Storage – EU region

Backups remain inside the EU.
We do not transfer platform data outside the EEA unless explicitly requested by the customer and protected by Standard Contractual Clauses (SCCs).

6. Subprocessors

Sospita uses the following GDPR-compliant service providers:

Infrastructure

AWS Europe – hosting, compute, database
GCP Europe – media storage

Email Delivery

SendGrid – transactional emails

Analytics

Google Analytics (basic, IP anonymization enabled)

Subprocessors are listed and updated at www.sospita.io/legal#subprocessors-en

7. Data Security

We employ industry-standard security measures, including:
* Encryption in transit (TLS 1.2/1.3)
* Encryption at rest (AES-256)
* Role-based access control (RBAC)
* Multi-tenant data isolation
* Secure authentication and password hashing
* Audit logs for all workflow actions
* Daily encrypted backups (EU-only)
* Least-privilege administrative access

8. Data Retention

Platform Data

* Retained for the duration of the organization’s subscription
* Deleted or returned within 60 days after termination
* Backups retained for 30 days
* Audit logs retained for 2 years

Website Data

* Contact form submissions: up to 12 months
* Cookie data: per cookie policy

Retention can be adjusted per the Controller’s written instructions.

9. Data Subject Rights

If your organization uses Sospita-SafeGuard, you may request through your employer:
* Access to your data
* Correction of inaccurate data
* Deletion (subject to safety/legal retention)
* Restriction of processing
* Portability
* Objection to processing

Sospita supports the Controller in fulfilling these requests.
To assist, contact: info@sospita.io

10. Data Breach Notification

In the event of a personal data breach affecting the platform:
* Sospita will notify the Data Controller without undue delay and within 72 hours of becoming aware of the breach.
* We will provide details on scope, impact, risks, and mitigation steps.

11. Changes to This Policy

We may update this Privacy Policy to reflect legal or operational changes.
Significant changes will be communicated to organizations at least 30 days before they take effect.
Updated versions will always be available at: www.sospita.io/legal#privacy-en

12. Contact Information

SOSPITA Yazılım Limited Şirketi
Email: info@sospita.io

Distance Sales Agreement ( SaaS Service)


This Distance Sales Agreement (“Agreement”) is made electronically between the following parties, in accordance with the Turkish Law on Consumer Protection No. 6502 and the Regulation on Distance Contracts, and is applicable to international buyers as well.

1. PARTIES


BUYER:
The individual or legal entity completing the online subscription order through the Sospita website or mobile applications. Buyer details (name, address, phone, email) are collected at checkout and form part of this Agreement.
By approving this Agreement electronically, the Buyer acknowledges the obligation to pay the subscription fee and applicable taxes.

SELLER:
Company: SOSPITA Yazılım Limited Şirketi
Address: Talaytepe Mah. 4035. Sok. Sunrise Garden Sitesi H blok No:27 Kayapınar/Diyarbakır
Phone: +90 555 462 21 94
Email: info@sospita.io
Company Reg. No: 48415
Tax No: 7750985110

By confirming this agreement, the BUYER acknowledges and accepts the obligation to pay the service fee and applicable taxes.

2. DEFINITIONS
Ministry: The Ministry of Trade of the Republic of Türkiye
Law: Law No. 6502 on Consumer Protection
Regulation: Regulation on Distance Contracts
Service: Subscription-based access to SaaS
Agreement: This Distance Sales Agreement
SaaS: Software as a Service
Website: www.sospita.io

3. SUBJECT OF THE AGREEMENT
This Agreement regulates the rights and obligations of the parties in relation to the Buyer’s subscription to the digital software service offered by the Seller (SOSPITA-SafeGuard) through the Seller’s website or mobile applications.

4. SERVICE DETAILS
Service: Digital Permit to Work (PTW), Risk Assessment, and Observation Management SaaS Platform
Delivery Method: Online account activation—no physical delivery
Subscription Term: Monthly or annual plans
License: Non-transferable; valid only for the subscribing individual or organization

5. SERVICE FEE AND INVOICE
Subscription Fee: As displayed on the checkout page (VAT included)
Payment Method: Credit card, online payment systems, or app store purchases
Invoice: Delivered electronically to the Buyer’s email address

6. DELIVERY AND ACCESS
Once payment is successfully completed, service delivery is fulfilled by activating the Buyer’s account. No physical shipment is made.

7. RIGHT OF WITHDRAWAL
According to Article 15/ğ of the Regulation on Distance Contracts.
* The Buyer loses the right of withdrawal once access to the digital service is provided.
* If access has not been granted, the Buyer may withdraw within 14 days of purchase.

International buyers: These terms apply except where local mandatory consumer rights provide additional protection.

8. CASES WHERE WITHDRAWAL IS NOT POSSIBLE
The right of withdrawal cannot be exercised if:
* The Buyer’s account has already been activated
* The Buyer has accessed or used the digital service

9. BUYER DEFAULT AND LEGAL CONSEQUENCES
In cases of non-payment or payment reversal, the Buyer is responsible for any interest, banking charges, or legal consequences arising from their financial institution.

10. DISPUTE RESOLUTION
For Buyers in Türkiye:
Disputes will be handled by Consumer Arbitration Committees or Consumer Courts located in the Buyer’s place of residence.
For international Buyers:
Disputes shall be resolved under the applicable consumer laws of the Buyer’s country, unless mandatory law dictates otherwise.Disputes shall be resolved by Consumer Arbitration Committees or Consumer Courts located in the BUYER’s place of residence.

11. ENFORCEMENT
By confirming this Agreement electronically during the subscription process, the Buyer agrees to all its terms.This Agreement is stored electronically and made available upon request.

Distance Sales Agreement ( Mobile App Service)


This Distance Sales Agreement (“Agreement”) is made electronically between the following parties, in accordance with the Turkish Law on Consumer Protection No. 6502 and the Regulation on Distance Contracts, and is applicable to international buyers as well.

1. PARTIES


BUYER:
The individual or legal entity completing the online subscription order through the Sospita website or mobile applications. Buyer details (name, address, phone, email) are collected at checkout and form part of this Agreement.
By approving this Agreement electronically, the Buyer acknowledges the obligation to pay the subscription fee and applicable taxes.

SELLER:
Company: SOSPITA Yazılım Limited Şirketi
Address: Talaytepe Mah. 4035. Sok. Sunrise Garden Sitesi H blok No:27 Kayapınar/Diyarbakır
Phone: +90 555 462 21 94
Email: info@sospita.io
Company Reg. No: 48415
Tax No: 7750985110

By confirming this agreement, the BUYER acknowledges and accepts the obligation to pay the service fee and applicable taxes.

2. DEFINITIONS
Ministry: The Ministry of Trade of the Republic of Türkiye
Law: Law No. 6502 on Consumer Protection
Regulation: Regulation on Distance Contracts
Service: Subscription-based access to SaaS
Agreement: This Distance Sales Agreement
SaaS: Software as a Service
Website: www.sospita.io

3. SUBJECT OF THE AGREEMENT
This Agreement regulates the rights and obligations of the parties in relation to the Buyer’s subscription to the digital software service offered by the Seller (Sospita Fitness (Sports Academy Management)) through the Seller’s website or mobile applications.

4. SERVICE DETAILS
Service: Sospita Fitness (Sports Academy Management))
Delivery Method: Online account activation—no physical delivery
Subscription Term: Monthly or annual plans
License: Non-transferable; valid only for the subscribing individual or organization

5. SERVICE FEE AND INVOICE
Subscription Fee: As displayed on the checkout page (VAT included)
Payment Method: Credit card, online payment systems, or app store purchases
Invoice: Delivered electronically to the Buyer’s email address

6. DELIVERY AND ACCESS
Once payment is successfully completed, service delivery is fulfilled by activating the Buyer’s account. No physical shipment is made.

7. RIGHT OF WITHDRAWAL
According to Article 15/ğ of the Regulation on Distance Contracts.
* The Buyer loses the right of withdrawal once access to the digital service is provided.
* If access has not been granted, the Buyer may withdraw within 14 days of purchase.

International buyers: These terms apply except where local mandatory consumer rights provide additional protection.

8. CASES WHERE WITHDRAWAL IS NOT POSSIBLE
The right of withdrawal cannot be exercised if:
* The Buyer’s account has already been activated
* The Buyer has accessed or used the digital service

9. BUYER DEFAULT AND LEGAL CONSEQUENCES
In cases of non-payment or payment reversal, the Buyer is responsible for any interest, banking charges, or legal consequences arising from their financial institution.

10. DISPUTE RESOLUTION
For Buyers in Türkiye:
Disputes will be handled by Consumer Arbitration Committees or Consumer Courts located in the Buyer’s place of residence.
For international Buyers:
Disputes shall be resolved under the applicable consumer laws of the Buyer’s country, unless mandatory law dictates otherwise.Disputes shall be resolved by Consumer Arbitration Committees or Consumer Courts located in the BUYER’s place of residence.

11. ENFORCEMENT
By confirming this Agreement electronically during the subscription process, the Buyer agrees to all its terms.This Agreement is stored electronically and made available upon request.

Subscription & Cancellation Policy (Sospita-SafeGuard)


Subscription & Cancellation Policy — Sospita-SafeGuard
Effective Date:
2025-05-08
Sospita-SafeGuard is a subscription-based digital platform offering AI-powered Permit to Work, Risk Assessment, and Observation Management services. This policy explains subscription terms, renewals, cancellations, and refund rules applicable to individual and organizational users.

1. Delivery of Digital Services
Upon successful payment, users receive immediate access to their selected subscription plan through the web or mobile application.
No physical product is delivered.

2. Subscription Plans
Users may subscribe to:
Monthly plans
Annual plans
Enterprise plans
(custom contract required)
Prices are displayed in EUR unless otherwise stated. VAT may apply based on the customer’s location.

3. Automatic Renewal
All subscriptions renew automatically at the end of each billing period unless cancelled before the renewal date.
We send renewal reminders (where legally required) before charging the next cycle.

4. Payment Methods
Depending on the platform, payments may be processed through:
Apple App Store
Google Play Store
Credit card providers
Bank transfer (for Enterprise plans)
All payments are handled securely by certified payment processors.

5. Right of Withdrawal (EU & UK Consumers)
In accordance with the EU Consumer Rights Directive (CRD):
Individual (non-business) consumers may cancel their subscription within 14 days of purchase provided they have not substantially used the service.
Simple login or viewing does not count as substantial use.
Once the service is actively used (creating permits, uploading data, inviting users, etc.), the right of withdrawal no longer applies.
Organizational and commercial customers are not eligible for the 14-day withdrawal right.

6. Cancellation Policy
Users may cancel anytime via the account dashboard.
* Cancellation prevents future renewals.
* No refunds are issued for the current billing cycle.
* Access continues until the end of the current period.
Enterprise clients follow the terms in their custom agreement.

7. Refund Policy
Refunds are only issued in the following cases:
* Duplicate payments
* Technical failures directly caused by Sospita preventing service access and not resolved within a reasonable time
* Legally required consumer refund obligations
Refunds are not provided for:
* Mid-cycle cancellations
* Lack of useIncorrect plan purchases
* Requests after service was substantially used

8. Free Trials
If a free trial is offered:
* No charges are made until the trial ends
* Users may cancel anytime during the trial to avoid billing
* Once billed, the refund rules above apply

9. Data Retention After Cancellation
After subscription termination:
* User access ends at the end of the billing cycle
* Organizations may request data export
* Data is retained for up to 90 days unless otherwise required by law
* Enterprise clients may negotiate custom retention terms

10. Contact
For subscription or billing questions:
📧 info@sospita.io

Subscription & Cancellation Policy (Sospita: Athletic Performance)


Subscription & Cancellation Policy — Sospita: Athletic Performance
Effective Date:
2025-05-08
Sospita-Athletic Performance is a subscription-based digital platform offering AI-powered Fitness Management services. This policy explains subscription terms, renewals, cancellations, and refund rules applicable to individual and organizational users.

1. Delivery of Digital Services
Upon successful payment, users receive immediate access to their selected subscription plan through the web or mobile application.
No physical product is delivered.

2. Subscription Plans
Users may subscribe to:
Monthly plans
Annual plans
Enterprise plans
(custom contract required)
Prices are displayed in EUR unless otherwise stated. VAT may apply based on the customer’s location.

3. Automatic Renewal
All subscriptions renew automatically at the end of each billing period unless cancelled before the renewal date.
We send renewal reminders (where legally required) before charging the next cycle.

4. Payment Methods
Depending on the platform, payments may be processed through:
Apple App Store
Google Play Store
Credit card providers
Bank transfer (for Enterprise plans)
All payments are handled securely by certified payment processors.

5. Right of Withdrawal (EU & UK Consumers)
In accordance with the EU Consumer Rights Directive (CRD):
Individual (non-business) consumers may cancel their subscription within 14 days of purchase provided they have not substantially used the service.
Simple login or viewing does not count as substantial use.
Once the service is actively used (creating permits, uploading data, inviting users, etc.), the right of withdrawal no longer applies.
Organizational and commercial customers are not eligible for the 14-day withdrawal right.

6. Cancellation Policy
Users may cancel anytime via the account dashboard.
* Cancellation prevents future renewals.
* No refunds are issued for the current billing cycle.
* Access continues until the end of the current period.
Enterprise clients follow the terms in their custom agreement.

7. Refund Policy
Refunds are only issued in the following cases:
* Duplicate payments
* Technical failures directly caused by Sospita preventing service access and not resolved within a reasonable time
* Legally required consumer refund obligations
Refunds are not provided for:
* Mid-cycle cancellations
* Lack of useIncorrect plan purchases
* Requests after service was substantially used

8. Free Trials
If a free trial is offered:
* No charges are made until the trial ends
* Users may cancel anytime during the trial to avoid billing
* Once billed, the refund rules above apply

9. Data Retention After Cancellation
After subscription termination:
* User access ends at the end of the billing cycle
* Organizations may request data export
* Data is retained for up to 90 days unless otherwise required by law
* Enterprise clients may negotiate custom retention terms

10. Contact
For subscription or billing questions:
📧 info@sospita.io

Subscription & Cancellation Policy — My-Checklists


Subscription & Cancellation Policy — My-Checklists
Effective Date:
2026-07-18
My-Checklists is a mobile checklist application developed and operated by SOSPITA Yazılım Limited Şirketi (“Sospita”, “we”, “us”, or “our”).The application may require a one-time purchase payment and may also offer optional monthly or discounted annual subscriptions for access to additional or ongoing features.This policy explains the applicable purchase, renewal, cancellation and refund conditions.

1. Delivery of Digital Services
My-Checklists is delivered digitally through the Apple App Store or Google Play Store.
Once the applicable purchase is successfully completed, the application or purchased features become available through the relevant app-store account.
No physical product is delivered.

2. One-Time Purchase FeeUsers may subscribe to:
My-Checklists may require a one-time purchase fee when the application is downloaded, installed or unlocked, depending on the app-store listing and purchasing model available in the user’s country.
The one-time purchase fee:
* Is charged through the Apple App Store or Google Play StoreIs normally charged only once for the relevant app-store account
* Does not automatically renew
* Does not include subscription features unless specifically stated on the purchase screen

The exact price, currency and applicable taxes are displayed by the relevant app store before the purchase is confirmed.

3. Subscription Options
My-Checklists may offer the following optional subscription plans:
* Monthly subscription
* Annual subscription offered at a discounted rate compared with twelve separate monthly payments
The features included in each subscription are displayed in the application and on the relevant app-store purchase screen.
Prices may vary depending on:
* Country or region
* Local currency
* Applicable taxes
* App-store pricing rules
* Promotional offers
The final price is always shown before the user confirms the purchase.

4. Automatic Renewal
Monthly and annual subscriptions renew automatically unless they are cancelled before the renewal date through the relevant app-store account settings.
The subscription fee is charged by Apple or Google to the payment method associated with the user’s app-store account.
Users are responsible for cancelling their subscription before the renewal date if they do not want the next subscription period to begin.
Deleting the application does not automatically cancel an active subscription.

5. Payment Processing
All purchases and subscription payments are processed by:
* Apple App Store, for purchases made on Apple devices
* Google Play Store, for purchases made on Android devices
Sospita does not directly collect, process or store:
* Credit card numbers
* Debit card numbers
* Bank account information
* App-store payment credentials
RevenueCat is used to help manage purchase entitlements, subscription status and access to paid features.
RevenueCat does not replace Apple or Google as the payment processor. Payment authorization, billing and refunds remain managed by the app store through which the purchase was made.


6. Managing or Cancelling a Subscription
Users may cancel their subscription at any time through the subscription-management settings of the app store used for the purchase.
For Apple App Store subscriptions, cancellation must be completed through the user’s Apple ID subscription settings.
For Google Play subscriptions, cancellation must be completed through the user’s Google Play subscription settings.
Cancellation:
* Prevents future automatic renewals
* Does not normally end access immediately
* Allows subscription features to remain available until the end of the already-paid billing period
* Does not automatically provide a refund for the current billing period
Sospita cannot cancel an Apple or Google subscription on behalf of the user.

7. Refund Policy
Refund requests for purchases made through the Apple App Store or Google Play Store are handled under the refund policies and procedures of the relevant app store.
Sospita does not directly control or approve app-store refunds.Users must submit refund requests to:
* Apple, for Apple App Store purchases
* Google, for Google Play Store purchases
Refund availability may depend on:
* The applicable app-store rules
* The user’s country or region
* The date of purchase
* Whether the digital service has already been accessed or used
* Mandatory consumer-protection laws
Sospita may provide reasonable information regarding a technical problem, but the final refund decision remains with Apple or Google.

8. Right of Withdrawal
The availability and exercise of any statutory right of withdrawal depend on:
* The country or region of the user
* The applicable consumer-protection laws
* Whether the purchase concerns digital content or a digital service
* Whether access or performance began immediately
* The terms accepted during the app-store purchase process
Where the purchase is made through the Apple App Store or Google Play Store, the withdrawal or refund request must normally be submitted through the relevant store.
Nothing in this policy limits any mandatory consumer right that cannot legally be excluded.

9. Free Trials and Promotional Offers
If a free trial, introductory price or promotional subscription is offered, the conditions will be displayed before the user confirms the offer.
Unless cancelled before the end of the trial or promotional period, the subscription may automatically convert into a paid subscription at the price shown during enrolment.
Users should cancel through their app-store subscription settings before the trial or promotional period ends if they do not want to be charged.
Promotional eligibility may be determined by Apple, Google or RevenueCat based on previous subscriptions or purchases.

10. Price Changes
Subscription prices may change from time to time.
Any price change will be managed in accordance with the rules of the relevant app store and applicable law.
Where required, Apple or Google may:
* Notify the user in advance
* Request acceptance of the new price
* Allow the user to cancel before the new price applies
A price change will not affect a completed one-time purchase unless the user purchases a separate product or feature.

11. Data Stored on the User’s Device
Checklist templates, checklist answers, saved drafts, completed checklist records, uploaded files and other checklist content are stored locally on the user’s device unless a future optional synchronization or backup feature is expressly introduced.
Sospita does not collect or retain this locally stored checklist content through the current version of the application.
Cancelling a subscription does not automatically delete checklist data stored on the device.
However, uninstalling the application, clearing application storage, resetting the device, losing the device or failing to maintain a device backup may result in permanent loss of locally stored data.
Users are responsible for protecting their device and maintaining any backups that may be available through the device operating system.

12. Effect of Subscription Expiry
When a subscription expires or is cancelled:
* Automatic renewal stops
* Paid subscription features remain available until the end of the current billing period
* Access to subscription-only features may end after the paid period expires
* Locally stored checklist data is not automatically deleted by Sospita
* Access to some existing data or premium functions may be limited depending on the feature structure described in the application
Any limitations that apply after subscription expiry will be displayed within the application or purchase screen.

13. Changes to This Policy
Sospita may update this Subscription and Cancellation Policy to reflect:
Changes to the applicationNew subscription features
Changes to app-store requirementsLegal or regulatory developments
Changes to RevenueCat or payment-management arrangements
The updated version will be published on the My-Checklists legal page with a revised effective date.

14. Contact
For questions about My-Checklists features or subscription status, contact:
📧 info@sospita.io

Personal Data Protection Policy — SOSPITA


Effective Date: 2025-06-08
Last Updated: 2026-07-20

SOSPITA Yazılım Limited Şirketi (“SOSPITA”, “we”, “us”, or “our”) is committed to protecting personal data in compliance with the EU General Data Protection Regulation (GDPR), the Turkish Personal Data Protection Law (KVKK), and other applicable privacy laws.
This Personal Data Protection Policy explains the general principles applied by Sospita when collecting, using, storing, sharing and protecting personal data through our websites, communications and software products.
Because Sospita products have different functions and data-processing activities, this policy should be read together with the application-specific Privacy Policy for:
Sospita-SafeGuard
Sospita: Athletic Performance
My-Checklists
Any future Sospita application


1. Sospita Products Covered by This Policy

1.1 Sospita-SafeGuard
Sospita-SafeGuard is a workplace safety-management platform that may include Permit-to-Work, Risk Assessment, Observation Management, checklist and related workflow functions.

1.2 Sospita: Athletic Performance
Sospita: Athletic Performance, formerly referred to as Sospita Fitness, is an athlete, coach, team, workout, schedule and performance-management platform.
Depending on the functions used, it may process athlete profiles, performance measurements, training information and other health- or fitness-related information.

1.3 My-Checklists
My-Checklists is a mobile checklist application designed to store checklist templates, answers, attachments, signatures and completed checklist records locally on the user’s device.
My-Checklists does not require a Sospita user account and does not ask users to provide their name, email address or other identifying profile information to Sospita.
Checklist content created in My-Checklists is not transmitted to or stored on Sospita servers under the current application design.
Subscription status and purchase entitlement information may be processed through Apple App Store, Google Play Store and RevenueCat as described in this policy and the My-Checklists Privacy Policy.

2. Roles Under Data Protection Law

2.1 Sospita as a Data Processor
Sospita generally acts as a data processor when it processes platform information on behalf of a subscribing organization.
This may apply to information processed through:
* Sospita-SafeGuard
* Sospita: Athletic Performance
* Other organization-controlled Sospita platforms
In these cases, the subscribing organization normally acts as the data controller and determines:
* Which personal data is entered into the platform
* The purposes for which the data is processed
* Who may access the information
* How long the information must be retained
* The applicable legal basis for processing
Depending on the product, the data controller may be an employer, company, sports club, academy, coach, team or another organization.
Sospita processes such data according to the customer’s documented instructions, the applicable agreement and relevant data protection laws.

2.2 Sospita as a Data Controller
Sospita may act as an independent data controller for personal data processed for its own purposes, including:
* Website visitors
* Contact and support enquiries
* Demo or trial requests
* Customer and business contact management
* Marketing communications
* Billing and subscription administration
* Srvice and security notifications
* Fraud prevention
* Legal and regulatory compliance
* Supplier, vendor and partner relationships
* Management of app purchase and subscription entitlements
* Protection and security of Sospita services


2.3 My-Checklists
Sospita does not act as the data controller or processor for checklist content that remains exclusively on the user’s device and is not transmitted to Sospita.
The user controls the content stored locally in My-Checklists.
Sospita may act as a data controller for limited technical, purchase or support information associated with My-Checklists, where such information is made available to Sospita through RevenueCat, Apple, Google or a direct support request

3. Categories of Personal Data Processed
The categories of information processed depend on the Sospita product and how the individual interacts with us.

3.1 Sospita-SafeGuard
Information entered by customer organizations may include:
* Name and surname
* Business email address
* Organization and department
* User role and access permissions
* Login timestamps
* Account and audit logs
* Permit-to-Work records
* Risk assessments
* Observations and comments
* Checklist answers
* Approvals and workflow actions
* Signatures, where used
* Uploaded photographs and documents
* Device, browser and security information
The customer organization determines which information is entered into the platform.

3.2 Sospita: Athletic Performance
Depending on the features used, information may include:
* Name and surname
* Email address
* Age or date of birth
* Sex
* Club, academy, team or organization
* Athlete, coach or administrator role
* Height and weight
* Workout plans and schedules
* Attendance information
* Training and performance measurements
* Progress records
* Injury-related information, where entered
* Uploaded photographs or documents
* Health- or fitness-related information
* Application activity and security logs
* Information received through authorized health or fitness integrations
Health and fitness information may constitute sensitive or special-category personal data under applicable law. Such data must only be processed where an appropriate legal basis and any required additional conditions are satisfied.

3.3 My-Checklists
My-Checklists does not ask users to create a Sospita account and does not collect or transmit the following checklist content to Sospita:
* Checklist names and templates
* Categories and questions
* Instructions
* Checklist answers
* Draft checklist runs
* Completed or recorded checklist runs
* Comments
* Photographs
* Documents
* Signatures
* Other content entered into a checklist
This content is stored locally on the user’s device.
For purchase and subscription management, limited information may be processed by Apple, Google and RevenueCat, including:
* An anonymous or pseudonymous application user identifier
* App-store purchase receipts or purchase tokens
* Purchased product or subscription
* Subscription status
* Purchase, renewal and expiry dates
* App version
* Device type
* Operating system
* Country, region or storefront information
* Last application activity time
* Technical information required to validate purchases and restore entitlements
Sospita does not receive or store the user’s full credit card number, debit card number, bank account details or app-store payment credentials.

3.4 Website and Communications
Information processed through the Sospita website or direct communications may include:
* Name and surname
* Email address
* Telephone number
* Company or organization
* Job title
* Contact-form content
* Demo or support request details
* Business correspondence
* IP address
* Browser and device information
* Cookie and analytics information, where applicable

3.5 Billing and Customer Administration
Depending on the purchasing method, we may process:
* Customer or organization name
* Billing contact details
* Subscription plan
* Payment statusInvoice information
* Transaction reference
* Purchase and renewal dates
* Tax-related information where required
Payment-card and bank-account information is processed by the relevant payment provider or app store and is not directly stored by Sospita unless expressly stated at the point of collection.

4. Purposes of Processing
Personal data may be processed for the following purposes.

4.1 Platform Operations
* Providing and operating Sospita products
* Creating and administering user accounts
* Authenticating users
* Managing roles and access permissions
* Executing application workflows
* Maintaining audit trails
* Providing requested features
* Supporting synchronization, storage and backup functions where applicable
* Validating purchases and subscription entitlements
* Restoring purchases
* Providing customer and technical support

4.2 Security and Reliability
* Protecting accounts and services
* Detecting unauthorized access
* Preventing fraud and misuse
* Monitoring system performance
* Investigating errors and technical problems
* Maintaining logs
* Managing backups and disaster recovery
* Applying security updates and vulnerability controls

4.3 Customer and Business Relationships
* Responding to enquiries
* Arranging demonstrations and trials
* Managing subscriptions and contracts
* Processing invoices
* Sending important service communications
* Managing customer, supplier and partner relationships

4.4 Product Improvement
* Diagnosing technical problems
* Improving usability and reliability
* Understanding aggregated product performance
* Developing new functions
* Measuring service quality
Where analytics or optional technologies require consent, they will only be used after obtaining the required permission.

4.5 Legal Compliance
* Meeting tax, accounting and commercial obligations
* Responding to lawful requests
* Establishing, exercising or defending legal claims
* Enforcing agreements
* Complying with regulatory and legal requirements

5. Legal Bases for Processing
Depending on the circumstances, personal data may be processed on one or more of the following legal bases:
* Performance of a contract
* Steps requested before entering into a contract
* Compliance with a legal obligation
* Legitimate interests pursued by Sospita or the relevant customer organization
* Consent, where required
* Establishment, exercise or defence of legal claims
* Other legal grounds permitted under applicable data protection laws
Where Sospita acts as a data processor, the customer organization is responsible for determining and documenting the appropriate legal basis for its processing activities.
Where sensitive or special-category information is processed, the relevant additional legal condition must also apply.

6. Local Storage in My-Checklists
Checklist data created in My-Checklists is stored on the user’s device and is not backed up or retained by Sospita under the current application design.
Users are responsible for:
* Protecting access to their device
* Using device security controls
* Maintaining any available operating-system backups
* Preventing unauthorized access to checklist content
* Exporting or preserving records where an export function is available
* Complying with any legal or organizational retention requirements that apply to their checklist records
Uninstalling My-Checklists, clearing application storage, resetting the device, losing the device or experiencing device failure may permanently delete locally stored checklist content.
Because Sospita does not possess this locally stored content, Sospita cannot:
* View the content
* Recover deleted checklist records
* Correct checklist answers
* Export the content on the user’s behalf
* Delete the content remotely

7. Payments and Subscription Management
Purchases made through My-Checklists or other Sospita mobile applications may be processed by:
* Apple App Store
* Google Play Store
* RevenueCat, for subscription and entitlement management
Apple and Google manage payment authorization and payment credentials.
RevenueCat may process technical identifiers, app-store receipts, purchase tokens and subscription-status information to determine whether a user is entitled to access purchased features.
Sospita does not use purchase or subscription information for third-party advertising.
The privacy policies and contractual terms of Apple, Google and RevenueCat also apply to information processed independently by those providers.

8. Data Hosting and International Transfers
Data processed through cloud-based Sospita platforms may be hosted using service providers located in the European Economic Area or other approved locations, depending on the product and service used.Sospita uses appropriate safeguards for international transfers where required, which may include:
* An adequacy decision
* Standard Contractual Clauses
* Contractual and technical safeguards
* Other lawful transfer mechanisms
My-Checklists checklist content is not hosted on Sospita cloud infrastructure because it remains locally stored on the user’s device.However, purchase and subscription information processed through Apple, Google or RevenueCat may be processed in countries determined by those providers and subject to their applicable privacy terms and transfer safeguards.

9. Subprocessors and Service Providers
Sospita may use service providers for functions such as:
* Cloud hosting
* Database services
* File storage
* Transactional email
* Security and error monitoring
* Customer supportAnalytics
* Payment processing
* Purchase validation
* Subscription and entitlement management
Depending on the product, these providers may include:
* Amazon Web Services
* Render
* Google Cloud Platform
* SendGrid or other email providers
* Apple
* Google
* RevenueCat
* Other providers listed in the current Sospita Subprocessor List
Not every provider is used by every Sospita product.
An updated list of relevant subprocessors and service providers is available on the Sospita Legal Centre.

10. Data Security
Sospita applies technical and organizational measures appropriate to the nature of the relevant service and the risks involved.
Depending on the product, these measures may include:
* Encryption in transit
* Encryption at rest
* Secure authentication
* Password hashing
* Role-based access control
* Tenant separation
* Access logging
* Restricted administrative access
* Backup and recovery controls
* Security monitoring
* Software updates and vulnerability management
* Incident-response procedures
For My-Checklists, the confidentiality of locally stored checklist content also depends on the security of the user’s device, operating system, passcode, biometric controls and backup settings.
No method of electronic storage or transmission is completely secure, and Sospita cannot guarantee absolute security.

11. Data Retention
Personal data is retained only for as long as reasonably necessary for the relevant purpose, including:
* While a customer account or contract remains active
* For the period instructed by a customer acting as data controller
* To provide subscription or purchase entitlements
* To comply with tax, accounting and legal obligations
* To prevent fraud
* To resolve disputes
* To establish or defend legal claims
* To enforce agreements
Retention periods may differ between products and categories of data.
After the applicable retention period ends, personal data is deleted, anonymized or securely disposed of unless continued retention is required by law.
My-ChecklistsSospita does not determine the retention period for checklist content stored locally on the user’s device.
The user controls deletion of that content by deleting records within the application, clearing application data or uninstalling the application.
RevenueCat, Apple and Google determine their own retention periods for purchase and subscription records under their respective legal obligations and privacy policies.

12. Data Subject Rights
Depending on applicable law, individuals may have the right to:
* Request information about whether their personal data is processed
* Access their personal data
* Request correction of inaccurate or incomplete data
* Request deletion or erasureRequest restriction of processing
* Object to processing
* Request data portability
* Withdraw consent where processing is based on consent
* Submit a complaint to an applicable data protection authority

Requests concerning organization-controlled platforms
Where personal data was entered into Sospita-SafeGuard or Sospita: Athletic Performance by an employer, club, academy, coach or other customer organization, the request should normally be submitted to that organization as the data controller.
Sospita will provide reasonable assistance to the customer organization in responding to the request.

Requests concerning Sospita-controlled data
Requests concerning Sospita’s own website, communications, billing, support or subscription-management records may be submitted directly to Sospita.

Requests concerning My-Checklists content
Sospita cannot access, correct, export or delete checklist content stored exclusively on the user’s device.
The user must manage this content directly through the application or device.
Requests concerning purchase records processed by Apple or Google may need to be submitted directly to the applicable app store.

13. Personal Data Breaches
If Sospita becomes aware of a personal data breach affecting data processed on behalf of a customer organization, Sospita will:
* Notify the relevant customer without undue delay
* Provide available information about the nature and scope of the incident
* Explain the likely impact where known
* Describe mitigation measures taken or proposed
* Provide reasonable assistance with applicable notification obligations
Where Sospita acts as data controller, it will assess and manage notification obligations in accordance with applicable law.
Because My-Checklists checklist content is stored locally and is not accessible to Sospita, loss of or unauthorized access to a user’s device may not be detectable by Sospita.

14. Children and Young Users
Certain Sospita products, particularly Sospita: Athletic Performance, may be used in connection with athletes under the age of 18.
The responsible organization must ensure that:
* The product is used lawfully
* Required parent or guardian permissions are obtained
* Appropriate privacy information is provided
* Access to young users’ data is appropriately restricted
* Health and performance information is handled with suitable safeguards
My-Checklists is not specifically designed to collect information from children. Because checklist content remains locally stored, Sospita does not knowingly collect checklist content directly from children through My-Checklists.

15. Changes to This Policy
Sospita may update this policy to reflect:
* Changes to our products
* New applications or functions
* Changes to service providers
* Legal or regulatory developments
* Changes to data-processing practices
The updated version will be published in the Sospita Legal Centre with a revised effective date.
Material product-specific changes may also be communicated through the relevant application or customer account where appropriate.

16. Contact
For privacy or personal data enquiries, contact:
SOSPITA Yazılım Limited Şirketi
Email: info@sospita.io

Registered address:
Talaytepe Mah. 4035. Sok.
Sunrise Garden Sitesi H Blok No: 27
Kayapınar, Diyarbakır
Türkiye

Account & Data Deletion Request — Sospita Fitness

Send an email to info@sospita.io with:
Subject: Account deletion request
Your account email/username
Your organization name (if applicable)
We may ask you to confirm ownership of the account before processing the request.
What will be deleted
After confirmation, we will delete or anonymize the personal data linked to your account, such as:
*Profile and account information
*App usage data linked to your account
*Training and performance records linked to your account
Retention and processing time
*Requests are typically processed within 30 days.
*Some data may be retained if required by law, tax/accounting rules, fraud prevention, or to resolve disputes. In that case, access is restricted and the data is deleted as soon as the retention requirement ends.
Contact
If you have questions, contact
info@sospita.io.

SOSPITA Subprocessor List


1. Hosting & Infrastructure
Amazon Web Services (AWS) Europe
Purpose: Application hosting, database, backups
Region: EU (Frankfurt, Ireland)
Google Cloud Platform (GCP) – EU Region
Purpose: Media file storage
Region: EU

2. Email & Communication
SendGrid
Purpose: Transactional emails
Location: EU-compliant under SCCs

3. Analytics
Google Analytics (Basic)
Purpose: Anonymous usage statistics
Notes: IP anonymization enabled; no personal data tracking

4. Other subprocessors (if used during support)
* GitHub (source code)
* Slack / Teams (internal support communication)
These services do not store production data unless explicitly provided by the customer.