SMAIV

Legal · SMAIV B.V.

Privacy Policy

Last updated: 15 June 2026 · Version: 1.0 Effective from: 15 June 2026

This Privacy Policy explains how SMAIV B.V. processes personal data when you use our mobile application (the "SMAIV App"), our websites, the B2B Emulator (the "Emulator") and related services (together, the "Services").


1. Controller and contact

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

SMAIV B.V. Walborg 2A, 1082 AM Amsterdam, Netherlands Commercial register (KvK): 42076631 VAT (BTW): NL869598661B01 Represented by: Johannes Leiberich

Point of contact for privacy matters and data subject rights: Email: privacy@smaiv.com

Point of contact for all other matters: Email: support@smaiv.com

Note on the Data Protection Officer: Because some of the performance data we process may qualify as health data, SMAIV continuously assesses whether appointing a Data Protection Officer under Art. 37 GDPR is required. Once a DPO is appointed, their contact details will be published here. Until then, you can reach us at privacy@smaiv.com.


2. Scope and roles

This Policy applies to processing within the Services provided by SMAIV. If you use SMAIV through your employer or another organisation (e.g. in a B2B/scouting context), that organisation may be an independent controller, in which case its privacy notices apply additionally.

All performance data is captured on your device within the app – via touch input and via camera footage analysed by our engine. SMAIV does not integrate any external wearables or fitness platforms.


3. Data we process

3.1 Data you provide

3.2 Performance and, where applicable, health-related data

As part of the core functionality, SMAIV collects and processes performance data captured exclusively on the smartphone – via touch input and via camera footage analysed by our engine. This includes in particular: - reaction data (e.g. reaction times); - cognitive performance data; - jump and movement data; - athletic and physical movement data.

SMAIV processes no sleep data and integrates no external wearables.

Camera: The camera is used solely to capture and analyse movements and performance. It is not used for the unique identification of a person (biometric identification within the meaning of Art. 9 GDPR, Recital 51). Analysis takes place exclusively locally on your device (on-device); raw footage is not transmitted to SMAIV's servers and is not stored there.

Classification: To the extent that individual data – in particular cognitive and reaction data – qualifies as health data within the meaning of Art. 9 GDPR, we process it solely on the basis of your explicit consent (Art. 9(2)(a)); otherwise on the basis of contract or consent (Art. 6). Without the required consent, the relevant core functions cannot be provided.

3.3 No wearable or third-party platform data

SMAIV captures all performance data on your device within the app (touch/camera) and integrates no external wearables or fitness platforms (e.g. Garmin, Apple Health, Polar, Strava). No data is imported from such services.

3.4 Data collected automatically

3.5 Payment data

Payments for subscriptions are handled by our payment service provider bunq B.V. (Amsterdam, Netherlands); for purchases via the app stores, processing additionally takes place through Apple or Google under their terms. SMAIV does not store full payment card data; we receive transaction status and the master data required to perform the contract.


4. Purposes of processing

We process data to (a) provide and manage accounts; (b) deliver the AI-based performance, recovery and training analysis; (c) analyse performance data captured via touch and camera; (d) handle subscriptions and payments; (e) ensure security and prevent abuse and fraud; (f) improve our Services (generally using aggregated/pseudonymised data); (g) provide support; (h) comply with legal obligations.


5. Legal bases

Processing Legal basis
Account management, contract performance, subscription handling Art. 6(1)(b) GDPR (contract)
Processing of performance data captured via touch/camera and its AI analysis – where it constitutes health data Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR (explicit consent)
Security, fraud prevention, product improvement (non-health) Art. 6(1)(f) GDPR (legitimate interests)
Analytics and marketing cookies Art. 6(1)(a) GDPR (consent); ePrivacy / § 25 TDDDG and NL Telecommunications Act
Statutory retention (e.g. accounting) Art. 6(1)(c) GDPR

You may withdraw any consent at any time with effect for the future (privacy@smaiv.com or in the app settings). The lawfulness of processing carried out before withdrawal remains unaffected.


6. Recipients and processors

We share data only where necessary: - Processors (Art. 28 GDPR): - Hosting/Backend: Supabase Inc. (database, authentication, storage; operated on AWS in the EU region eu-central-1 (Frankfurt)); - Payment processing: bunq B.V., Amsterdam (Netherlands); - crash/diagnostics service: Sentry (Functional Software, Inc.; with EU data residency enabled) and email/support tools (see Subprocessor List). - Data Processing Agreements (DPAs) are in place with all processors. - Authorities/courts where legally required.

SMAIV's AI models are developed in-house and operated exclusively on infrastructure within the EU/the Netherlands. Your personal data is not disclosed to external model providers for their own purposes.

A current subprocessor list is provided (see 06_Subprocessor_List).


7. International transfers

We host data in the EU region Frankfurt (eu-central-1) of our backend provider Supabase. Because Supabase Inc. is a US company, despite EU data residency a potential access under US law (including the CLOUD Act) cannot be entirely excluded. We therefore base this processing on a Data Processing Agreement together with Standard Contractual Clauses (Art. 46 GDPR) and supplementary safeguards (including encryption, access restrictions, EU data residency). Where other recipients are located outside the EEA, we rely on an adequacy decision (e.g. the EU-US Data Privacy Framework) or on SCCs with supplementary measures. Payment processing via bunq B.V. takes place within the EEA. You can obtain a copy of the safeguards on request at privacy@smaiv.com.


8. AI-based processing and automated decisions

SMAIV uses in-house AI models operated exclusively within the EU/the Netherlands to derive training and performance recommendations from your performance data captured via touch and camera (reaction, cognitive, jump and movement data). Details are set out in our AI Policy.


9. Retention

We retain personal data only for as long as necessary for the purposes pursued (principle of storage limitation, Art. 5(1)(e) GDPR): - Active accounts: account, profile and performance data are stored for the duration of the active use of your account in order to provide the Services. - Deactivated accounts: After deactivation, your account data remains stored so that you can reactivate your account at any time – until you request erasure (Art. 17 GDPR) or withdraw your consent. In that case, we delete or anonymise the data without undue delay, unless statutory retention obligations apply. - Camera footage: Analysis takes place exclusively locally on your device (on-device); raw footage is not transmitted to SMAIV's servers and is not stored there. - Backups and logs: Information contained in backups is anonymised within 30 days or overwritten on a rolling basis. - Billing/accounting data: in line with statutory retention periods (in the Netherlands generally 7 years).

Details are set out in our internal deletion concept; we explain them on request at privacy@smaiv.com.


10. Your rights

Under the GDPR you have the right to: - access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18); - data portability (Art. 20); - object to processing based on legitimate interests (Art. 21); - withdraw consent (Art. 7(3)) with effect for the future.

To exercise these rights, simply contact privacy@smaiv.com. We generally respond within one month.

Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): The lead authority is the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). Users in Germany may also contact the data protection authority responsible for their place of residence; users in Austria, the Datenschutzbehörde.


11. Data security

We implement appropriate technical and organisational measures under Art. 32 GDPR (including encryption in transit and at rest for sensitive data, access controls, pseudonymisation, logging, and regular review). In the event of a personal data breach, we fulfil our notification obligations under Art. 33/34 GDPR.


12. Minors

The Services are intended for persons aged 16 and over. Persons below that age may use the Services only with verifiable consent of a parent or guardian. If we become aware of processing to the contrary, we delete the relevant data.


13. Changes

We may amend this Privacy Policy, for example due to feature or legal changes. We will notify material changes appropriately (e.g. in the app). The current version published within the Services applies.


SMAIV B.V. · Walborg 2A, 1082 AM Amsterdam · privacy@smaiv.com · support@smaiv.com