ΣΥΣΤΗΜΑ ΣΤΕΝΩΝ ΖΩΝΩΝ ΑΝΤΟΧΗΣBack to website

PRIVACY · GDPR · DATA CONTROL

Privacy Policy

This policy explains how the Narrow Endurance Zones System (Greek name: Σύστημα Στενών Ζωνών Αντοχής) handles personal data.

Last updated28 August 2026ControllerIoannis VafeiadisContactioannis.vafeiadis@systema-stenon-zonon-antochis.com
01

Scope and data controller

This policy applies to the website at systema-stenon-zonon-antochis.com, the web application, account access, subscriptions, support communications and any connected services made available through the application.

The data controller is Ioannis Vafeiadis, Greece. Privacy questions and requests may be sent to ioannis.vafeiadis@systema-stenon-zonon-antochis.com.

02

Personal data we process

  • Account data: email address, account identifier, authentication status and security-related metadata.
  • Subscription data: plan, status, activation and expiry dates, Stripe customer/subscription references and transaction status. We do not receive or store full card numbers.
  • Support data: the sender, address and content of messages you choose to send us.
  • Technical data: necessary logs, IP address, browser/device information and security events produced by our infrastructure providers.
  • Training data: settings and values you enter, such as MLSS/LT, heart-rate references, training preferences, race targets and course information.
03

Why we process data and our legal bases

  • To create and authenticate accounts, provide the application and manage subscriptions — performance of a contract or steps requested before entering one.
  • To process payments and maintain legally required transaction and accounting records — performance of a contract and compliance with legal obligations.
  • To protect accounts, prevent fraud and abuse, diagnose faults and secure the service — our legitimate interests in operating a safe and reliable service.
  • To answer support requests — performance of the service and our legitimate interest in communicating effectively with users.
  • For an optional Garmin connection or optional communications — your consent, which you may withdraw at any time without affecting earlier lawful processing.
04

GPX, FIT, browser storage and cookies

In the current application, GPX and FIT files that you select are analysed in your browser unless a feature clearly states that data will be transferred to a connected service. We do not sell uploaded course, workout or activity data.

Profile settings, training preferences, programme configurations and similar working data may be stored locally on your device through browser storage. You can remove this data by using the application's reset controls or by clearing site data in your browser.

Essential cookies or equivalent local-storage technologies may be used for authentication, security, session continuity and language or unit preferences. The service does not currently use advertising cookies of its own.

05

GARMIN CONNECT · PLANNED INTEGRATION

Garmin data

Garmin integration is not active yet and remains subject to Garmin's approval. If it becomes available, connecting a Garmin account will be optional and will require your explicit authorisation through Garmin's official authorisation flow.

With your permission, the application may send a workout you select to Garmin Connect and receive completed activity data needed for analysis, such as activity time, distance, pace, heart rate, elevation, route and workout execution data. Such data will be used only to provide the features you request, not for advertising or sale. Authorisation credentials will be handled on the server and will not be placed in public front-end code.

You will be able to revoke access through Garmin and request deletion of Garmin-derived data by contacting us. This policy will be updated before the integration is released if its final data flow requires additional disclosures.

06

Processors and data recipients

We use a limited number of providers to deliver the service:

  • Supabase for authentication, database and server-side application functions.
  • Stripe for checkout, payments, subscriptions and billing management.
  • Brevo for transactional account emails.
  • Papaki for company email hosting and related communications.
  • Website hosting, CDN and security providers needed to serve and protect the website and application.
  • Garmin only if the integration is approved, released and voluntarily connected by the user.

Providers process data under their own terms and applicable data-processing arrangements. Where data is processed outside the European Economic Area, we rely on legally recognised transfer mechanisms and safeguards where required. We may also disclose data when required by law or necessary to protect legal rights and security.

07

Retention and security

We keep account and subscription data while the account is active and afterwards only for as long as necessary for support, security, disputes or legal obligations. Payment and accounting records are retained for the period required by applicable law. Local browser data remains on your device until you remove it. Connected-service data is deleted or anonymised when no longer needed, subject to legal and security requirements.

We use reasonable technical and organisational safeguards, including encrypted connections, managed authentication, restricted server-side secrets and access controls. No online service can guarantee absolute security.

08

Your privacy rights

Subject to applicable law, you may request access, rectification, erasure, restriction, portability or objection, and you may withdraw consent. You may also request account deletion or deletion of connected Garmin data by emailing ioannis.vafeiadis@systema-stenon-zonon-antochis.com. We may need to verify your identity before completing a request.

You may lodge a complaint with the Hellenic Data Protection Authority at dpa.gr, or with the competent authority where you live or work.

The service is not directed to children. A person below the age at which they may independently consent to online services in their country should not create an account without the involvement of a parent or legal guardian.

09

Changes to this policy

We may update this policy when the application, its providers or legal requirements change. The date at the top of the page will show the latest revision. Material changes will be communicated in an appropriate way.


ΕΛΛΗΝΙΚΗ ΑΠΟΔΟΣΗ

Πολιτική Απορρήτου

Η παρούσα πολιτική ισχύει για τον ιστότοπο και την εφαρμογή «Σύστημα Στενών Ζωνών Αντοχής», τους λογαριασμούς, τις συνδρομές, την υποστήριξη και τις συνδεδεμένες υπηρεσίες. Υπεύθυνος επεξεργασίας είναι ο Ιωάννης Βαφειάδης. Για κάθε αίτημα: ioannis.vafeiadis@systema-stenon-zonon-antochis.com.

Δεδομένα και σκοποί

Επεξεργαζόμαστε το email και τα τεχνικά στοιχεία του λογαριασμού, την κατάσταση της συνδρομής, τα απαραίτητα στοιχεία συναλλαγών, μηνύματα υποστήριξης και τις προπονητικές τιμές που εισάγει ο χρήστης. Τα χρησιμοποιούμε για σύνδεση, παροχή της υπηρεσίας, πληρωμές, ασφάλεια, τεχνική υποστήριξη και συμμόρφωση με τον νόμο. Δεν λαμβάνουμε ούτε αποθηκεύουμε ολόκληρους αριθμούς καρτών.

Αρχεία GPX/FIT και τοπική αποθήκευση

Στην τρέχουσα έκδοση, τα GPX και FIT που επιλέγει ο χρήστης αναλύονται στον browser, εκτός αν μια λειτουργία αναφέρει καθαρά ότι θα γίνει διαβίβαση σε συνδεδεμένη υπηρεσία. Ρυθμίσεις προφίλ και προγράμματος μπορεί να αποθηκεύονται τοπικά στη συσκευή. Βασικά cookies ή αντίστοιχη αποθήκευση χρησιμοποιούνται για σύνδεση, ασφάλεια και προτιμήσεις.

Garmin Connect

Η διασύνδεση Garmin δεν είναι ακόμη ενεργή και προϋποθέτει έγκριση. Εφόσον διατεθεί, θα είναι προαιρετική και θα ενεργοποιείται μόνο με ρητή εξουσιοδότηση του χρήστη μέσω της Garmin. Θα μπορεί να στέλνει επιλεγμένες προπονήσεις και να λαμβάνει τα δεδομένα ολοκληρωμένων δραστηριοτήτων που απαιτούνται για την ανάλυση. Τα δεδομένα αυτά δεν θα πωλούνται ούτε θα χρησιμοποιούνται για διαφήμιση. Τα διαπιστευτήρια εξουσιοδότησης θα φυλάσσονται στον server και όχι στον δημόσιο κώδικα της εφαρμογής.

Πάροχοι, διατήρηση και δικαιώματα

Χρησιμοποιούνται οι Supabase, Stripe, Brevo, Papaki και οι απαραίτητοι πάροχοι φιλοξενίας/ασφάλειας· η Garmin μόνο μετά από έγκριση και επιλογή σύνδεσης από τον χρήστη. Τα δεδομένα διατηρούνται μόνο όσο απαιτείται για την υπηρεσία, την ασφάλεια και τις νόμιμες υποχρεώσεις. Ο χρήστης μπορεί να ζητήσει πρόσβαση, διόρθωση, διαγραφή, περιορισμό, φορητότητα ή εναντίωση και να ανακαλέσει συγκατάθεση. Μπορεί επίσης να προσφύγει στην Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα.

Η υπηρεσία δεν απευθύνεται σε παιδιά. Άτομο κάτω από το όριο ανεξάρτητης συναίνεσης για διαδικτυακές υπηρεσίες στη χώρα του δεν πρέπει να δημιουργεί λογαριασμό χωρίς τη συμμετοχή γονέα ή νόμιμου κηδεμόνα.