Privacy Policy
Last updated: 2026-06-10
This Privacy Policy explains how Tavo Programa collects, uses, and protects your personal data when you use our service. We are committed to complying with the EU General Data Protection Regulation (GDPR) and Lithuanian data protection law.
Who is responsible for your data
The data controller is MB VBNetwork (legal entity code 307791342). For any data-protection questions, contact us at [email protected].
What data we collect
Account data: name, email address, and password. Profile data: gender, age, height, and weight. Product inputs: training goals, experience level, equipment, injuries, dietary preferences, and any free-text notes you provide. Order data: purchase history and payment references. Technical data: IP address and session information.
How and why we process your data
The table below summarizes why we process your personal data, what data is involved, how long we keep it, and our legal basis under the GDPR.
| Purpose | Data used | Retention | Legal basis |
|---|---|---|---|
| Creating and operating your account, and delivering the service | Name, email, password, and profile data (gender, age, height, weight) | While your account is active; deleted within 30 days of account deletion (name and email are kept with order records for 10 years - see below) | Performance of a contract (Art. 6(1)(b)) |
| Generating your personalized training, supplement, and diet plans | Goals, experience, equipment, dietary preferences, and inputs such as injuries or allergies (health data), including free-text notes | Kept with your account until you delete it | Contract (Art. 6(1)(b)); for health data, explicit consent (Art. 9(2)(a)) |
| Processing payments and keeping accounting records | Name, order history, and payment references | 10 years (Lithuanian accounting law) | Legal obligation (Art. 6(1)(c)) and contract (Art. 6(1)(b)) |
| Securing your account and preventing fraud and abuse | IP address, session and technical log data | Up to 90 days | Legitimate interest (Art. 6(1)(f)) |
| Understanding how the service is used so we can improve it (self-hosted, cookieless usage statistics) | Aggregated technical usage events (pages visited, browser type, country) - collected without cookies and not linked to your identity | Stored only in aggregated form | Legitimate interest (Art. 6(1)(f)) |
| Sending newsletters (only if you opt in) | Email address | Until you unsubscribe or withdraw consent | Consent (Art. 6(1)(a)) |
Automated plan generation and your health data
Our service creates your training, supplement, and diet plans automatically, using artificial intelligence provided by a third-party AI provider that acts as our processor and works only on our instructions. To do this, we send the inputs you provide - including any free-text notes - to that provider. Some of those inputs - such as injuries or allergies - may reveal information about your health. We process this special-category data only to generate your personalized plans, only with your explicit consent (GDPR Art. 9(2)(a)). You may withdraw that consent at any time in your profile settings (Consents section) or by emailing us at [email protected]; withdrawal does not affect processing already carried out, but after it we will no longer generate new plans for you. These plans are generated to fulfill the order you actively request, so they are not a decision producing legal or similarly significant effects within the meaning of Art. 22 GDPR. If you have any concern about a generated plan, you can contact us and ask a person to review it.
Who we share data with
We do not sell your personal data. We share it only with carefully selected service providers (processors) who handle it on our instructions and only to the extent needed to run the service: AI plan generation - our artificial-intelligence provider (based in the United States), which generates your personalized plans from the inputs you give us. Payment processing - a licensed payment institution established in Lithuania, which handles your transactions. Hosting and infrastructure - our hosting provider, which stores your data within the European Economic Area. Content delivery, security, and email - our content-delivery and security provider, which helps us deliver the service securely and send transactional emails. We may also disclose data to advisors (such as auditors or lawyers) or to public authorities where the law requires it.
International data transfers
We aim to keep your personal data within the EU/EEA. Some of our processors are located outside the EEA, including in the United States. Where your data is transferred outside the EEA, that transfer is protected by an appropriate safeguard under the GDPR - an adequacy decision of the European Commission, the EU-US Data Privacy Framework, or EU Standard Contractual Clauses - or, where applicable, your explicit consent.
How we protect your data
We apply strict technical and organizational security measures to keep your personal data protected from unauthorized access. Still, no method of transmission over the internet is completely secure, so we cannot guarantee absolute security. If a personal-data breach occurs that is likely to put your rights or freedoms at high risk, we will inform you as soon as we become aware of it and have established what information was accessed.
How long we keep your data
We keep your active account data for as long as you have an account. If you delete your account, your generated plans, health-related inputs and other personal data are deleted within 30 days. Your name, email address and order records are kept for 10 years, as required by Lithuanian accounting law. If you subscribed to the newsletter, deleting your account does not cancel the subscription - you can unsubscribe at any time. Technical logs are kept for up to 90 days. Beyond these periods, we may keep certain data longer where necessary to meet a legal obligation, to bring or defend legal claims, or to resolve a dispute.
Cookies
We use only the cookies necessary to run the service securely - such as a session cookie and a security token that keeps you logged in safely, plus small cookies that remember your basic preferences. Our content-delivery and security provider may set additional technical cookies for security and performance. We do not use advertising or third-party tracking cookies. If that ever changes, we will ask for your consent first.
Your rights
Under the GDPR you have the right to: access your personal data; have inaccurate or incomplete data corrected or completed; have your data erased when it is no longer needed or is processed unlawfully; object to the processing or withdraw your consent; restrict the processing of your data; receive your data in a commonly used format; lodge a complaint with the supervisory authority (the State Data Protection Inspectorate). You can exercise these rights from your account settings or by emailing [email protected]. We will respond within one month, and to protect your data we may ask you to verify your identity.
Where to lodge a complaint
If you believe we have infringed your rights when processing your personal data, please contact us first - we will try to resolve the matter. You also have the right to lodge a complaint with the supervisory authority, the State Data Protection Inspectorate (www.vdai.lrv.lt).
Changes to this policy
We may occasionally update this Privacy Policy. Any changes will be posted on this page with an updated date, and we will notify you by email of material changes before they take effect. We recommend reviewing this page periodically. By continuing to use the service after an update takes effect, you accept the revised Privacy Policy.
How to contact us
If you have questions about this Privacy Policy or your personal data, email us at [email protected].