Privacy Policy
1. Controller
Helia AI GmbH
Rossertstr. 34
65817 Eppstein, Germany
Email: team@relayathletic.com
2. Data We Collect
2.1 Account Data
When you register for Relay, we collect your name, email address, and password. If you subscribe to a paid plan, we also process payment information through our payment processor.
2.2 Usage Data
We automatically collect information about how you interact with our service, including pages visited, features used, browser type, IP address, and device information.
2.3 Athlete Data
Coaches may enter data about their athletes, including names, performance metrics, training programs, and questionnaire responses. Coaches are responsible for ensuring they have appropriate consent or legal basis to share this data with Relay.
2.4 AI Interaction Data
When you use AI-powered features (e.g., voice AI, program generation), we process the inputs you provide and the outputs generated. This data may be sent to our AI provider (Google Gemini) for processing.
3. Purpose and Legal Basis
We process your data for the following purposes under GDPR Art. 6:
- Contract performance (Art. 6(1)(b)): To provide and maintain the Relay service, process subscriptions, and deliver AI features.
- Legitimate interests (Art. 6(1)(f)): To improve our service, ensure security, prevent fraud, and conduct analytics.
- Consent (Art. 6(1)(a)): For optional cookies and tracking technologies (see Section 4).
- Legal obligation (Art. 6(1)(c)): To comply with tax, accounting, and other legal requirements.
4. Cookies and Tracking
4.1 Essential Cookies
We use essential cookies for authentication and session management. These are necessary for the service to function and do not require consent.
4.2 Analytics (PostHog)
We use PostHog for product analytics to understand how users interact with Relay. PostHog may set cookies to track usage across sessions.
4.3 Advertising
We use Google Ads conversion tracking and Meta Pixel to measure the effectiveness of our advertising campaigns. These services may set cookies and collect data about your visit for ad targeting and conversion measurement.
5. Third-Party Services and International Transfers
We use the following third-party services to operate Relay:
- Vercel (United States): Hosting and content delivery. Data may be processed in the US. Transfer basis: EU Standard Contractual Clauses (SCCs).
- Supabase (European Union): Database and authentication. Data is stored in the EU.
- Google Cloud / Gemini (EU and US): AI processing for intelligent features. Data may be processed in both EU and US regions. Transfer basis: EU Standard Contractual Clauses (SCCs).
- PostHog: Product analytics.
- Google Ads: Advertising conversion tracking.
- Meta Pixel: Advertising conversion tracking.
6. Data Retention
We retain your account data for as long as your account is active. After account deletion, we may retain certain data for up to 30 days in backups and as required by law (e.g., invoicing records for 10 years under German tax law). Usage and analytics data is retained in anonymized or aggregated form.
7. Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, access controls, and regular security reviews.
8. Your Rights (GDPR)
Under the GDPR, you have the following rights:
- Access (Art. 15): Request a copy of the personal data we hold about you.
- Rectification (Art. 16): Request correction of inaccurate personal data.
- Erasure (Art. 17): Request deletion of your personal data.
- Restriction (Art. 18): Request that we restrict the processing of your data.
- Data portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
- Objection (Art. 21): Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at team@relayathletic.com.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement.