HUMAN
limits

Human Limits Privacy Policy

Effective Date: Aug 15, 2024

Middlepoint SL ("Middlepoint", "we", "our", or "us") operates the Human Limits platform ("Human Limits", "Service", or "Platform"). This Privacy Policy describes our privacy practices regarding the information we collect from users ("you" or "your") of the Human Limits platform located at humanlimits.app.

1. Information We Collect

Information you provide

When you use our Service, we may collect your device ID and certain device information. When you sign up for a Human Limits account, we ask you for personal information such as your name, e-mail address, telephone number, and account password, as well as your gender. At the time you register as a member, during your free trial period, or when you make a purchase, we request payment card or other payment account information which we retain in encrypted form on secure servers. We combine the information you submit under your account with information from other Middlepoint services or third parties, such as Facebook and Google, in order to provide you with a better experience and to improve the quality of our Service.

Health information

Through your use of the Service, we may ask you to fill out questionnaires and share your Apple Health application and Apple HealthKit data with Human Limits. We may collect and process health data that we receive through your smartphone and connected device(s) via the Apple Health application or Apple HealthKit with your consent. You may withdraw your consent to our collection of health information through the Apple Health application and Apple HealthKit at any time by following the process set forth in the "Your Choices" section below.

Cookies

When you visit Human Limits, we send one or more cookies - a small file containing a string of characters - to your computer that uniquely identifies your browser. We use cookies to improve the quality of our Service by storing user preferences and tracking user trends. Most browsers are initially set up to accept cookies, but you can reset your browser to refuse all cookies or to indicate when a cookie is being sent. However, some Human Limits features and services will not function properly if your cookies are disabled. Cookies collect the date and time of your visit, your registration information, and other technical information.

Activity Information

In order to provide the best possible service and to allow us to make certain internal reports and make recommendations, we collect aggregate information about the use of the Service, including information about users accessing the Website such as internet protocol addresses, browser type, browser language, referring / exit pages and URLs, other browser history, platform type, number of clicks, domain names, landing pages, pages viewed and the order of those pages, the amount of time spent on particular pages, the date and time of your visit, and other technical information.

IP Address

An Internet Protocol (IP) address is a number that's automatically assigned to your computer whenever you're surfing the Web. We retain your IP address in order to help us diagnose problems with our servers, to administer our Website, to help identify you, to gather broad anonymous demographic and location information (such as the number of visitors from a geographic area), to enforce compliance with the Website terms and conditions, or otherwise in order to protect our services, sites, customers, or others.

Log information

When you use the Service, our servers automatically record information that your browser sends whenever you visit a Website. These server logs include information such as your web request, IP address, browser type, browser language, the date and time of your request, and one or more cookies that uniquely identify your browser.

User communications

When you send email, text, sms, or other communication to Middlepoint, including transmissions, while using the Coaching Service, we retain those communications in order to process your inquiries, respond to your requests, and improve our services.

Affiliated sites

We offer some of our Services in connection with other websites. Personal information that you provide to those websites is sent to Middlepoint in order to deliver the Service. We process such information in accordance with this Policy. The affiliated websites have different privacy practices and we encourage you to read their privacy policies.

Links

Middlepoint presents links in a format that enables us to keep track of whether these links have been followed. We use this information to improve the quality of our Website.

2. Information Use and Sharing

We use your personal information for the purposes described in this Policy and/or any privacy notice provided for specific Services. Such purposes include, but are not limited to:

  • Providing our Services to users, including the display of customized content and advertising;
  • Sharing information to our business partners who perform core services (such as hosting, billing, data storage, security, and reporting services) related to the operation of the Service;
  • Collecting and processing information about your actual location to provide location-aware products, services, and other content;
  • Verifying your identity;
  • Following up with transactions or inquiries initiated on the Website, the application, or via email;
  • Auditing, research and analysis in order to maintain, protect, and improve our Services;
  • Ensuring the technical functioning of our network; and
  • Developing new Services.

We may use the health data we obtain through the Human Limits Coaching Service, the Apple Health application or the Apple HealthKit to provide feedback on your activity or health status and to improve the Service by creating a more personalized experience for you (i.e., serving content that is relevant to your activity or health, but in no event used for advertising or marketing purposes as set forth herein).
We will not disclose any of your health data we obtain to advertising platforms, data brokers, or information resellers, or for advertising, marketing, or use-based data mining purposes. We will not disclose such data to other third parties without your consent, and then only for the purposes of enabling the third party to provide health, motion, and/or fitness services.
We may provide information, including health data, to our subsidiaries, affiliated companies, and other trusted third parties or persons for the purpose of processing personal information on our behalf. We require that these parties agree to process such personal information based on our instructions and in compliance with the appropriate confidentiality and security measures.
We also may disclose personal information and health information: (i) if required to do so by law or in the good-faith belief that such action is necessary to (1) conform to the edicts of the law or comply with legal process served on Middlepoint or its parent company, subsidiaries, or affiliates, (2) protect and defend the rights or property of Middlepoint or the users of the Website, or (3) act under exigent circumstances to protect the safety of the public or users of the Website; (ii) in connection with a partial or total sale of stock or assets, merger, or any other change of control transaction, including in bankruptcy; or (iii) when we have your consent to do so.
We do not use automatic decision-making or engage in profiling that produces legal effects or similarly significant effects.
We may share technical or personal information that has been anonymized or aggregated without limitation.

3. Your Choices

When you sign up for the Service, we ask you to provide personal information. If we use this information in a manner different than those described in this Policy and/or in the specific service notices, then we will ask for your consent prior to such use. If you no longer wish to receive email notifications from Human Limits, please let us know by contacting us. Please specify which notifications you no longer wish to receive and provide your exact name, email address and/or physical address so that we can do our best to ensure that you stop receiving the notifications that you no longer wish to receive. Please note that you will continue to receive communications related to our transaction(s) and relationship with you.

If we propose to use personal information for any purposes other than those described in this Policy and/or in the specific service notices, and you decline, Middlepoint may not be able to provide its Service to you.

If you would like to withdraw your consent to our collection of health data through the Apple Health application and Apple HealthKit, you may do so by using your device settings.

We may partner with third-party ad networks and other ad serving providers ("Advertising Providers") that serve ads on our behalf and others' on non-affiliated platforms. Some of those ads may be personalized, meaning that they are intended to be relevant to you based on information Advertising Providers collect about your use of the Website and other sites or apps over time, including information about relationships among different browsers and devices. This type of advertising is known as interest-based advertising.

Human Limits adheres to the Digital Advertising Alliance ("DAA") Self-Regulatory Principles in connection with this interest-based advertising activity. You can visit www.aboutads.info or www.youradchoices.com/AppChoices to learn more about interest-based advertising and how to opt out of this advertising by companies participating in the DAA self-regulatory program. If you delete your cookies, reset your device advertising identifier, or use a different browser or mobile device, you will need to renew your opt-out choices. You may also be able to limit data collection for advertising purposes using tools available on your device. Note that electing to opt out will not stop advertising from appearing in your browser or applications. It may make the ads you see less relevant to your interests. Even if you opt out, Advertising Providers may continue to collect data for other purposes, including analytics and other operational purposes.

We may also work with third parties that collect data about your use of the Website and other sites or apps over time for non-advertising purposes. For example, Middlepoint uses Google Analytics and other third-party services to improve the performance of the Website and for analytics and marketing purposes. For more information about how Google Analytics collects and uses data when you use our Website, visit www.google.com/policies/privacy/partners, and to opt out of Google Analytics, visit tools.google.com/dlpage/gaoptout.

When you use the Service, we make good faith efforts to provide you with access to your personal information and either to correct this data if it is inaccurate or to delete such data at your request if it is not otherwise required to be retained by law or for legitimate business purposes. We ask individual users to identify themselves and the information requested to be accessed, corrected, or removed before processing such requests, and we in some cases decline to process requests in certain circumstances. In any case where we provide information access and correction, we perform this service free of charge, except if doing so would require a disproportionate effort.

4. Data Security

We take appropriate security measures to protect against unauthorized access to or unauthorized alteration, disclosure, or destruction of data. These include internal reviews of our data collection, storage and processing practices, and security measures, as well as physical security measures to guard against unauthorized access to systems where we store personal information.

We restrict access to personal information to Middlepoint employees, contractors, and agents who need to know that information in order to operate, develop, or improve our services. These individuals are bound by confidentiality obligations and may be subject to discipline, including termination and criminal prosecution, if they fail to meet these obligations.

However, please note that no data transmission over the Internet can be guaranteed to be 100% secure, so while Middlepoint strives to protect your information, Middlepoint cannot ensure or warrant the security of any information that you voluntarily give to Middlepoint.



5. Website Areas Beyond Middlepoint's Control

Human Limits may choose various third party websites to link to, link from, and frame within, the Website. Middlepoint also may participate in co-branding and other relationships to offer e-commerce and other services and features to its users. However, even if the third party is affiliated with Middlepoint, we have no control over these linked sites, each of which has separate privacy and data collection practices independent of Middlepoint. We have no responsibility or liability for these independent policies or actions and are not responsible for the privacy practices or the content of any such websites. Please make sure you are comfortable with the privacy practices of every site you visit before providing the site with your personal information. These linked sites are only for your convenience and you therefore access them at your own risk.

We also may make chat rooms, forums, and message boards available to you through the Services. Please remember that we cannot control the information that is shared by members and that anything you voluntarily provide in any public area of the Internet will be publicly available to other visitors on that website and potentially to other third parties. Thus, please note that you should always exercise caution when deciding to publicly disclose any of your personal information in these and similar areas.

6. International Visitors

This section applies to those that visit our Website or use our Service from the European Economic Area, the United Kingdom, and Switzerland.

Middlepoint processes personal information with your consent (e.g., when you agree that Middlepoint may place cookies, or when Middlepoint processes personal information submitted for specified purposes). On other occasions, Middlepoint may process personal information when it needs to do this to fulfill a contract (for example, for billing purposes) or where required to do so by law.

If necessary, Middlepoint may also process personal information when it is in Middlepoint's legitimate interests to do this (e.g., for customer service or fraud detection) and when these interests are not overridden by your data protection rights. If you wish to exercise the right to withdraw consent, please contact us. See the "Contact" section below for contact information.

Please be aware that the personal information we collect may be transferred to and maintained on servers or databases located outside your state, province, country, or other jurisdiction, where the privacy laws may not be as protective as those in your location. If you are located outside of the United States, please be advised that we process and store personal information in the United States and your consent to this privacy notice represents your agreement to this processing and storage.

You have a right to the following:

  • To request access to the personal information we hold about you;
  • To request that we rectify or erase your personal information;
  • To request that we restrict or block the processing of your personal information;
  • Under certain circumstances, to receive personal information about you that we store and transmit to another without hindrance from us, including requesting that we provide your personal information directly to another, i.e., a right to data portability; and
  • Where we previously obtained your consent, to withdraw consent to processing your personal information.


To exercise these rights, see the "Contact" section below. Please be aware that Middlepoint may be unable to provide these rights to you under certain circumstances, such as if we are legally prevented from doing so. Additionally, you have the right to lodge a complaint against us. To do so, contact the supervisory authority in your country of residence.

We will process and store your personal information only for the period necessary to achieve the purpose of the storage, or as permitted by law. We will retain and use your personal information to the extent necessary to enforce our agreements. The criteria used to determine the period of storage of personal information is the respective statutory retention period or six years in the case of contracts. After expiration of that period, the corresponding data is routinely deleted, as long as it is no longer necessary for the fulfillment of a contract or the initiation of a contract or for other lawful purposes.

Personal Information We Collect, Disclose for a Business Purpose, and Sell

We collect the categories of personal information about California users identified in the chart below. As further set forth in the chart below, in the past 12 months, we have disclosed and sold California users’ personal information to third parties for business or commercial purposes.

Categories of Personal InformationCollected in the last 12 monthsCategories of sources from which information is collectedBusiness or commercial purposes for collection, use, and sharingDisclosed for business purposes to the following categories of third partiesSold to the following categories of third parties
Personal and online identifiers (such as first and last name, telephone number, email address, or unique online identifiers)YesUsers; Affiliates; Social Networks; and Search engines.All purposes listed below.Business partners that perform core services; Middlepoint Subsidiaries; Affiliates; Data Analytics Providers; and Advertising Platforms.Advertising Platforms; Middlepoint Subsidiaries; Affiliates; Data Analytics Providers; Data brokers; and Information Resellers.
Categories of information described in Section 1798.80(e) of the California Civil Code (such bank account number, credit card number, debit card number, or any other financial information)YesUsers; Business partners that perform core services; and Affiliates.All purposes listed below.Business partners that perform core services; Middlepoint Subsidiaries; Affiliates; Data Analytics Providers; and Advertising Platforms.Advertising Platforms; Middlepoint Subsidiaries; Affiliates; Data Analytics Providers; Data brokers; and Information Resellers.
Characteristics of protected classifications under California or federal law (such as gender)YesUsersAll purposes listed below.Business partners that perform core services; Middlepoint Subsidiaries; Affiliates; Data Analytics Providers; and Advertising Platforms.Advertising Platforms; Middlepoint Subsidiaries; Affiliates; Data Analytics Providers; Data brokers; and Information Resellers.
Internet or other electronic network activity information (such as browsing history, search history, interactions with a website, email, application, or advertisement)YesUsers; Affiliates; Social Networks; and Search engines.All purposes listed below.Business partners that perform core services; Middlepoint Subsidiaries; Affiliates; Data Analytics Providers; and Advertising Platforms.Advertising Platforms; Middlepoint Subsidiaries; Affiliates; Data Analytics Providers; Data brokers; and Information Resellers.
Biometric information (such as health or exercise data that contains identifying information)YesUsers.All business purposes listed below.Business partners that perform core services; Middlepoint Subsidiaries; and Affiliates.Middlepoint does not sell biometric information, including health data.
Geolocation informationYesAll business purposes listed below.

Why We Collect, Use, and Share California Information

California residents have certain rights with respect to the personal information collected by businesses. If you are a California resident, you may exercise the following rights regarding your personal information, subject to certain exceptions and limitations:

  • The right to know the categories and specific pieces of personal information we collect, use, disclose, and sell about you, the categories of sources from which we collected your personal information, our purposes for collecting or selling your personal information, the categories of your personal information that we have either sold or disclosed for a business purpose, and the categories of third parties with which we have shared personal information;
  • The right to request that we delete the personal information we have collected from you or maintain about you;
  • The right to opt out of our sale(s) of your personal information. Please note that if you opt out of certain types of sales, we will be unable to provide you with the services that rely on such sales; and
  • The right not to receive discriminatory treatment for the exercise of the privacy rights conferred by the CCPA.


To exercise any of the above rights, please contact Middlepoint using the following information and submit the required verifying information, as further described below:

By email at info@humanlimits.app

Verification Process and Required Information

Note that we may need to request additional information from you to verify your identity or understand the scope of your request, although you will not be required to create an account with us to submit a request or have it fulfilled. We will require you to provide, at a minimum your name and e-mail address.

Authorized Agent

You may designate an authorized agent to make a CCPA request on your behalf by e-mailing info@humanlimits.app from your Human Limits registered e-mail address a notarized affidavit of identity and signed request that includes the full name, phone number and e-mail address of such an agent.

Minors’ Right to Opt In

We do not sell the personal information of minors under 16 years of age.

9. Enforcement

Middlepoint regularly reviews its compliance with this Policy. Please feel free to direct any questions or concerns regarding this Policy or Middlepoint's treatment of personal information by contacting us using the information in the Contact section below.
When we receive formal written complaints at this address, it is Middlepoint's policy to contact the complaining user regarding his or her concerns. We will cooperate with the appropriate regulatory authorities, including local data protection authorities, to resolve any complaints regarding the transfer of personal information that cannot be resolved between Middlepoint and an individual.

10. Direct Marketing

We may send marketing communications for purposes disclosed to you (including as specified herein) and, where required by applicable law, with your consent. You can unsubscribe from direct marketing at any time by contacting us directly. We will process your request within a reasonable time after receipt, in accordance with the applicable laws. Unsubscribe options are provided in electronic marketing communications as required by applicable law.

Email, SMS, and Telephone

You can unsubscribe from email communications at any time. To stop receiving our promotional emails, follow the unsubscribe instructions in the email messages you receive from us or contact us info@humanlimits.app. We will process your request as soon as possible after receiving it, in accordance with applicable laws. Please note that you will still receive transaction-related emails regarding products or services you have requested. Additionally, we may send you certain non-promotional communications regarding Human Limits and our services, and to the extent allowed by law, you will not be able to opt out of those communications (such as communications about updates to our Terms or this Privacy Policy).

If you opt in, you will receive text messages from Human Limits. These text messages, called "SMS Programs" are promotional marketing messages, such as information about Human Limits’ future products and services and non-promotional, such as failed subscription payments, and other alerts related to your subscription or purchases. To opt out of receiving text messages, text STOP to the number from which you received the message. We will send you a final message to confirm your unsubscribe request, and we will process it within a reasonable timeframe according to applicable laws.

If you encounter any issues with text messages from Human Limits, text HELP to the referenced number or email our customer support team at info@humanlimits.app. Carriers are not responsible for delayed or undelivered messages. Message frequency may vary, and message and data rates may apply. We adhere to "do-not-call" and "do-not-mail" lists as required by law. We handle requests to be placed on do-not-mail, do-not-phone, and do-not-contact lists within the legally mandated timeframes.

Push Notifications

If you opt in on your device, Human Limits may occasionally send you push notifications through our Apps, providing updates, achievements, and other notices that may be of interest to you. You can opt out of receiving these types of communications at any time by adjusting the settings on your device.

11. Users Under 18

Human Limits' content is not directed at users under eighteen (18) years of age, and if you provide information about yourself as a user of Human Limits, you are representing that you are at least eighteen (18) years of age. We do not knowingly collect personal information from anyone under eighteen (18) years of age, but if we do become aware of having collected personal information from a user who is younger than eighteen (18) years of age, we will remove such information from our files.

12. Changes To This Policy

This Policy may be amended from time to time. You should visit this page periodically to review any changes to the Policy. If we believe that the changes are material, Middlepoint will let you know by doing one (or more) of the following: (i) posting the changes on or through the Website or Service, or (ii) sending you an email or message about the changes.

13. Contact Us

If you have any comments, questions or concerns with respect to our Privacy Policy or practices of personal information protection, please contact us via:

Email: info@humanlimits.app

We will review your privacy or personal information requests as soon as possible and respond to you in 15-30 days after verifying your user identity. If your request itself involves any complicated or significant issue, we may ask you for more information.

If you are not satisfied with our response, especially when you believe that your legitimate rights and interests have been violated by us, you can seek remedy from relevant data protection regulatory authority in your jurisdiction. If you consult us, we will provide information on the relevant complaint channels that may be applicable based on your circumstance.

Thank you for your time to read our Privacy Policy!

14. Data Portability

Users have the right to request a copy of their personal data in a structured, commonly used, and machine-readable format. This includes the ability to transmit this data to another service provider, where technically feasible, without hindrance from Middlepoint.

15. Automated Decision-Making

Human Limits may use automated decision-making processes for certain functionalities, such as personalized recommendations or fraud detection. These processes do not produce legal or similarly significant effects on users. If you believe an automated decision has negatively impacted you, please contact us for a review.

16. Third-Party Processors

We collaborate with trusted third-party service providers to perform functions and process user data on our behalf. These include payment processing, data analysis, hosting services, and customer support. All third-party processors are contractually obligated to protect your data and comply with applicable data protection laws.

17. Children’s Privacy

Human Limits does not knowingly collect personal information from children under 13 (or the age defined by local regulations). If we become aware of such data collection, we will delete the information promptly. Parents or guardians who believe their child has provided personal information should contact us immediately.

18. Cross-Border Data Transfers

Human Limits operates globally, and your personal data may be transferred to and processed in countries other than your own. We ensure that such transfers comply with applicable data protection laws and that your data remains protected, regardless of its location.

19. Data Retention Policies

Personal data will be retained only as long as necessary to fulfill the purposes outlined in this policy or as required by law. Users may request deletion of their data by contacting us, subject to certain limitations such as legal obligations.

20. Consent and Preferences Management

Users can manage their consent preferences and update their settings related to data collection, cookies, and marketing communications through their account settings or by contacting us. Withdrawal of consent may limit the availability of certain services.


Please review the policy carefully to ensure all placeholders are correctly filled and all necessary information is included. Let me know if there are any specific sections you need more detail on or any other assistance you require.