Hold The Beat Privacy Policy

Last updated: February 2026

At Hold The Beat, we take your privacy very seriously. This Privacy Policy explains in a transparent and detailed manner how we handle your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the LOPDGDD 3/2018. Hold The Beat is a service specifically designed to maximize your anonymity and privacy. We have minimized the collection of identifying data as much as possible.

1. Data Controller

  • Responsible Party: Hold The Beat - [Not Registered yet]
  • Address: [Not Registered yet]
  • Email: privacy@holdthebeat.com
  • Website: www.holdthebeat.com

2. What data do we NOT collect? (Minimalism by design)

Full name
Surnames
Postal address
Mobile/landline phone
Email
ID/Passport
Complete bank details
Persistent IP (only temporary security logs)
Geolocation
Biometric data (face, voice)

3. What data DO we collect?

3.1. Registration data (Pro version)

  • Username/pseudonym (e.g., "user123")
  • Password (bcrypt/argon2 hash)
  • Approximate age (range: 18-24, 25-34, etc. - optional)

3.2. Training session data (all versions)

  • Temporary Session ID (UUID generated on client)
  • Session duration (seconds)
  • BPM used
  • Number of stops (Start-Stop)
  • First stop time (IELT proxy)
  • Exercises completed (Kegel, breathing)
  • Session result (completed/failed)
  • Date/time of session

3.3. Payment data (Pro users only)

  • Stripe/PayPal/crypto transaction ID
  • Amount and date of payment
  • Subscription status (active/expired)
  • Plan type (Pro/Pack/One-Shot)

3.4. Temporary technical data (security)

  • Source IP (TTL maximum 7 days)
  • Browser/device User-Agent
  • Error logs/failed sessions (TTL 30 days)

4. Purposes of processing

DataPurposeGDPR Legal Basis
Username + passwordAuthentication and secure accessExecution of contract (Art. 6.1.b)
Session metricsPersonal statistics, adaptive algorithm and execution of the training serviceExplicit consent (Art. 9.2.a) and execution of contract (Art. 6.1.b)
Payment transaction IDPayment management, tax claimsLegal obligation (Art. 6.1.c)
Anonymized dataAlgorithm improvement, statistical analysisLegitimate interest (Art. 6.1.f)
Technical logsSecurity, fraud preventionLegitimate interest (Art. 6.1.f)

5. Irreversible anonymization (automatic process)

When deleting your account or requesting cancellation:

Steps:

  • STEP 1: Immediate deletion (users, trainersessions)
  • STEP 2: Anonymization of historical sessions (user_id = NULL, unique UUID)
  • STEP 3: Final result (Impossible to re-identify data)

Anonymized data is kept indefinitely only for:

  • Aggregated statistical analysis
  • Algorithm optimization and calibration
  • Program efficacy research

6. Retention periods

Data TypePeriodReason
Username/passwordUntil account closureService provision
User sessionsSecurely while the account is activePersonal statistics and execution of the service
Transaction ID5 yearsSpanish tax obligation
IP/error logs7-30 daysSecurity
Anonymized dataIndefiniteService improvement

7. Data recipients

We do NOT sell data to third parties. We only communicate data to:

RecipientPurposeData Type
StripeSecure payment processingTransaction ID and payment information
Hosting provider (EU)Technical infrastructureEncrypted data
AuthoritiesLegal requirementAny data
Google LLC (Gemini/Vertex AI)Adaptive algorithm (calibration and optimization)Anonymized training metrics

International transfers: Transfers are made to Stripe Inc. for payment processing and to Google LLC (Gemini/Vertex AI) for algorithm optimization and calibration using anonymized training metrics, under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses if necessary.

8. Your GDPR rights (ARSOPL)

You can exercise these rights free of charge at any time:

RightWhat you can doResponse time
ACCESSKnow what data we process1 month
RECTIFICATIONCorrect inaccurate data1 month
ERASURE"Right to be forgotten"1 month
OBJECTIONObject to processing1 month
PORTABILITYReceive data in structured format1 month
RESTRICTIONTemporarily suspend processing1 month

How to exercise them: Send an email identifying yourself to privacy@holdthebeat.com with reference 'GDPR Rights'.

Complaints: Spanish Data Protection Agency (www.aepd.es)

9. Explicit consent (special categories)

Your training session data contains information about your sexual life and health (Art. 9 GDPR), which requires explicit consent. ☑️ I EXPRESSLY CONSENT to Hold The Beat processing my Start-Stop session data, Kegel tests, and progress. You can withdraw this consent at any time.

  • Start-Stop sessions (duration, stops, BPM)
  • Kegel tests and exercises
  • Progress and personal statistics

10. Data Security

We implement technical and organizational measures above average:

🔒Mandatory HTTPS/TLS 1.3
🔒bcrypt/argon2 passwords (unique salt)
🔒Rate limiting (100 req/min IP)
🔒Database encrypted at rest (PostgreSQL)
🔒Session ID UUID v4 (128 bits entropy)
🔒TTL IP logs (maximum 7 days)
🔒Automatic anonymization on deletion
🔒Activity Logs audit

11. Minors

Services exclusively for those over 18 years of age. If we become aware of use by minors, we will suspend the account immediately.

12. Cookies

We use strictly necessary technical cookies:

  • User session
  • Language preferences
  • JWT authentication

We do NOT use marketing cookies, third-party tracking, or Google Analytics.

See Cookie Policy for full details.

13. Changes to the Policy

Any modification will be published here with a new update date. Substantial changes will be communicated in advance.

14. Contact

privacy@holdthebeat.com - To exercise GDPR rights or any privacy-related questions.