1. Controller and contact
Mateusz Konieczny — Balance IT, ul. Święty Marcin 29 lok. 8, 61-806 Poznań, Poland, NIP 7812090221, REGON 541862820, is the controller for OpenBikeFit product processing and data deliberately sent through the feedback or business-inquiry service. Contact: kontakt@balanceit.pl.
2. Data, purposes and legal bases
- Contract and acceptance receipt: notice versions, adult confirmation, locale and timestamps; used to prove and enforce the agreement you requested (GDPR Article 6(1)(b)).
- Local setup records: body and bicycle measurements, setup coordinates, bike profiles, component notes, workflow drafts, journals and preferences; used to calculate and retain the service you requested (Article 6(1)(b)).
- Camera-derived data: reduced MediaPipe landmarks for indices 11–16 and 23–32, timestamps, confidence/quality facts and derived 2D angles. Face and hand landmarks are zeroed immediately; raw video is not retained unless a feature gives you an explicit local-save choice. Purpose and basis: provide the requested local movement comparison (Article 6(1)(b)).
- Feedback: category, message, optional email, page path, submission time and ordinary request/security metadata; used to answer, debug and secure the service (Articles 6(1)(b) and 6(1)(f)).
- Business inquiries: organization, business type, requested work, message, work email, page path, submission time, an allowlisted channel label when the inquiry link contains one, and ordinary request/security metadata; used to assess and answer your request before a possible contract, identify which non-behavioural distribution channel produced the inquiry and protect the endpoint (Articles 6(1)(b) and 6(1)(f)). The channel label is sent only with a submitted inquiry; opening the page creates no page-view event. Sending an inquiry does not create a paid engagement.
- Hosting/security metadata: IP address, requested resource, time, user agent and security signals processed by the host to deliver and protect the site (Article 6(1)(f)).
The product is intentionally not for health concerns and does not request symptoms, diagnoses or injury history. Do not place special-category data, client records, videos or individual fit records in free text, feedback or business inquiries. A one-way local migration removes fields and derived recommendations from the retired symptom-driven workflow.
3. Where data is processed
Core records stay in IndexedDB, localStorage or sessionStorage in this browser. The camera and bundled MediaPipe runtime/model execute locally; no runtime or model request is made to jsDelivr or Google. Balance IT does not receive the local database and cannot restore it. URL fragments used for local handoffs are not sent in the HTTP request, although a browser may keep them in local history.
The complete Settings export includes all six IndexedDB stores (sessions, poseSeries, videos, meta, bikeProfiles and bikeJournal), known device keys and workflow drafts. Optional videos are embedded with type and byte size. Delete all data clears and verifies every listed store, known key, draft, OpenBikeFit cache and Service Worker registration.
4. Recipients and transfers
Cloudflare hosts the public site and optional feedback/business-inquiry endpoint and acts as a processor where it handles data for Balance IT. Its infrastructure may involve international transfers under applicable adequacy decisions or safeguards. The self-hosted MediaPipe code runs in your browser and is not a data recipient. No advertising pixels or behavioural analytics are used. Current vendors and their roles are listed in the governance vendor register.
5. Retention and your controls
Local data remains until you delete it, clear site data or a documented workflow expiry removes a temporary draft (normally 30 days). A calculator-to-camera session handoff ends when read or when the tab session ends. The acceptance receipt remains until withdrawal or version invalidation. Optional offline caches remain until you disable offline mode, delete all data or clear site data.
Feedback and business inquiries are scheduled for deletion after 180 days unless needed for a shorter response period or longer to establish, exercise or defend a legal claim. Hosting/security metadata follows the configured processor and security-retention schedule documented in the vendor register; Balance IT operates no separate analytics log.
6. Your rights
Where applicable, you may request access, rectification, erasure, restriction or portability, and object to processing based on legitimate interests. Email kontakt@balanceit.pl; identity verification may be required. For browser-only data, Settings gives you direct access, export and verified deletion because Balance IT cannot identify or retrieve that local copy remotely.
You may complain to the President of the Polish Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl. OpenBikeFit makes no decision with legal or similarly significant effect and does not profile for advertising.
7. Choice, security and changes
The on-device-processing choice is separate from accepting the terms. You can withdraw the local receipt and delete data in Settings. Withdrawing does not affect processing already carried out. HTTPS, data minimisation, same-origin model assets, restrictive permissions and security headers reduce risk; no internet or local-storage system can promise absolute security.
Material changes receive a new date and, when the acceptance-controlled notice version changes, require a new choice before protected workflows reopen.