Hatipikal App · Legal
Privacy Policy
Last updated: 7 September 2026 · privacy-notice-2026-09-07-v3-roles-por-finalidad
1. Responsible
This policy explains how Hatipikal App handles the data of people who request access to and use the website or app available at app.hatipikal.com.
Data controller: MIRIAMPDMODA COACHING SOCIEDAD LIMITADA., with tax ID B90394909 (NIF-IVA / VAT number ESB90394909) and registered address at Calle Conde de Andrade 31, 29602 Marbella, Málaga, Spain. Hatipikal App is the platform's public identity and trade name.
Hatipikal App provides shared infrastructure for coaches who independently manage their relationships with and support for their own clients. It may act as a shared technical sender for operational communications; when a communication relates to a specific coach, the platform will identify that coach or their space where applicable.
General contact: info@hatipikal.com.
Technical and privacy contact: pablo@miriampdmoda.com.
Who is responsible for each purpose
Hatipikal and your coach are not responsible for the same things. Each party’s role is assigned by purpose, based on who actually decides why and how the data is processed.
- Hatipikal is the controller for your account, access, security, platform operation and support, compliance, its own commission, and the personal features you use directly, including your studies, tracking, and the results you generate.
- Your coach is the controller for their private CRM, notes, forms they ask you to complete, schedule, professional tracking, and plans they create. For these purposes, Hatipikal acts as a data processor and only processes this data to provide the tool according to their instructions.
- For sales by your coach, each party is separately responsible: your coach for delivery, support, invoicing, taxes, refunds, and complaints; Hatipikal for payment security, its commission, and its own platform obligations.
- Joint controllership only applies when Hatipikal and your coach jointly decide the purpose and essential means of a campaign or program. This is not the general rule and does not apply by default.
- Service providers—including hosting, email, media delivery, artificial intelligence, and others—act as processors or subprocessors for whoever is the controller in each operation.
The same data may be subject to different roles depending on the operation. You can exercise any of your rights through Hatipikal. If the relevant purpose is your coach’s responsibility, Hatipikal will coordinate the response with them.
This allocation may be updated following the ongoing external legal review. Any changes will be published in a new version of this policy.
2. Data we collect
We may collect first and last name, email address, phone number, Herbalife ID, encrypted password, language, time zone, communication preferences, coach-client relationship, tax details provided by the user, progress status, current or past challenges, bookings, passes, cards, rates, orders, products, saved content, configured integrations, and any photos, files, or visual references voluntarily uploaded by the user, as well as technical security and performance data such as IP address, date and time, browser, device, access, consent, and error logs.
When a coach verifies their ID, we may check their personal volume (PV) and the corresponding period. We retain the checks and resulting tier needed to show their progress and provide access to the tools included in each tier.
If the user enables push notifications, we process an installation ID and the technical token assigned to the device by Apple or Google. They are used solely to deliver Hatipikal notifications to that device and are disabled when the user logs out, withdraws permission, or the provider reports that they are no longer valid.
When using tracking, challenges, nutrition plans, or workout plans, the user may enter data related to habits, meals, photos, physical progress, weight, measurements, goals, bookings, sessions, images, workout plans, nutrition plans, or sensitive information. This data is processed solely to provide the requested personalized tracking and requires the explicit, separate consent of the person it belongs to, whether client or coach. Every coach is also a client regarding their own tracking and consents only to the processing of their own data, never anyone else’s. Features that require health data will not be enabled without this consent.
In the mobile app, users can choose to connect Apple Health or Health Connect in read-only mode to view their steps, workouts, and active calories in My Diary. This data remains on the device unless they enable «Share with my coach» using a separate control. If enabled, we only store a daily summary with the date, steps, sport, minutes, active calories, type, and estimated intensity. We do not store heart rate, individual samples, or full history. When consent is withdrawn, shared summaries and their automatic entries are deleted.
In the finance tools, we can handle tickets, invoices, receipts, images, PDFs, suppliers, clients, amounts, categories, dates, payment methods, notes, tax data, and packages ready for accounting when the user uses those features.
If you use AI-powered features, we process the content you upload or enter, images, health or activity data when needed, attachments, instructions, and generated responses to analyze, extract data, suggest text, classify, translate, recommend, or help create plans. The feature must indicate or make it clear that the result was generated using artificial intelligence before you rely on it.
3. Why we use your data
We use the data to manage user registration and approval, enable secure access, link clients with coaches, save progress across devices, personalize messages and content, manage bonuses, bookings, challenges, plans, products, rates, and payments, prepare financial documents, send recovery emails or operational alerts, sync calendars if the user authorizes it, manage contacts on request, read or send emails via Gmail if the coach connects that integration, and improve the app experience.
For coaches, we also use verified personal volume to determine the applicable tier and enable the tools available to them under the requirements published on the platform.
Each purpose has its own legal basis. Creating and using your account, requesting plans, maintaining your relationship with your coach and booking services are based on performance of the requested service (Article 6(1)(b) GDPR). A function that needs health data also requires your separate, explicit consent (Article 9(2)(a)). Sharing those data with your coach requires a separate choice: your coach cannot consent on your behalf.
Orders and payments are based on the contract; invoicing, taxes and accounting on applicable legal obligations (Article 6(1)(c)). Security and fraud prevention rely on legitimate interests (Article 6(1)(f)), limited to what is necessary and subject to a balancing assessment of your rights. You can object where applicable.
Integrations you connect voluntarily, such as Google, perform the function you request; their technical authorization is not blanket consent. You can disconnect them. AI uses the legal basis of the purpose it supports and does not permit reuse of your instructions or results to train our own or the provider's models.
The standard AI features you request are enabled from registration as part of the service described in this policy, without additional authorization for each feature. You can turn them off and back on in Privacy and account. Explicit withdrawals are respected; health data and photos retain their specific controls.
The Healthy League is optional: you’ll only appear if you tap “Join the league.” By joining, you agree to show your name, photo, healthy days, and stars to other Hatipikal participants on the monthly and all-time leaderboards. You can withdraw your consent by tapping “Leave the league,” without losing your personal progress. We keep a record of when you join or leave to document your request.
Marketing communications require consent for each channel and sender (Article 6(1)(a)); we do not use the existing-customer exception. Handling your rights fulfils legal obligations; retaining minimal evidence and managing incidents or reports may also rely on documented legitimate interests. Backups retain the legal basis of the original data and are limited to security and recovery, subject to the relevant retention periods.
Withdrawing permission stops the corresponding purpose without cancelling your account or functions that do not depend on it. Erasure and retention exceptions are explained below. Delivery of our own editorial media, where it involves personal data, is limited to documented legitimate interests in publication and availability.
Telegram group participation tracking remains disabled until specific consent and an approved data protection impact assessment are in place. Its design is limited to daily contribution and reaction counts. We do not copy or retain message text, photographs, files, their content or exact times. The purpose is to support the requested coaching and identify changes in the person's usual participation, never to compare or rank them against other users. Connecting Telegram only links the account to the bot and does not activate these counters. You can delete previous statistics using the separate control beside your connected accounts.
4. Communications & integrations
If you request access or take relevant actions, we may notify administrators or coaches by email, Telegram, in-app notifications, or push notifications, depending on your preferences. Passwords are never sent via Telegram or notifications. Push notifications display minimal text on the lock screen and avoid including names, email addresses, measurements, amounts, or other sensitive data. When you open them, Hatipikal checks your session and permissions again before displaying the full content.
Push notifications are optional. Permission is requested only after you take a specific action, and you can disable them in both your Hatipikal preferences and your iPhone or Android settings. We deliver them using Apple Push Notification service (APNs) on iPhone and Google's Firebase Cloud Messaging (FCM) on Android. These services receive the device's technical token and the minimum content needed for delivery.
If you connect Google services, we request permission to identify your account; create, update, or delete events related to your challenges in a Hatipikal calendar; create Google Meet links for activities; and sync or update contacts when you request it.
Some document generation and reading, data extraction, classification, translation, recommendation, or image features may use artificial intelligence providers. Depending on the feature and current settings, Hatipikal uses OpenAI, Anthropic, or NVIDIA. This policy provides centralized information about these providers and purposes; each feature identifies when AI is involved if there is direct interaction or its use is not obvious. Only the content needed to perform the requested action is sent. Before sending a photo, document, audio, or sensitive text, make sure it does not include unnecessary information about other people.
Emails or notifications are used for records, verifications, security, invites, bookings, challenges, plans, payments, products, account changes, and necessary Hatipikal alerts. These aren’t separate marketing messages, but service-related communications.
5. Automated decision-making and artificial intelligence
Hatipikal does not intend to make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. Scores, classifications, image analyses, product recommendations, drafts, plans, and alerts are for guidance only and must be reviewed by a person. You may request information, express your point of view, or challenge a result by contacting the address provided in this policy.
Data sent to artificial intelligence providers may include personal or health information when required by the requested feature. We limit what is sent to what is necessary, but you must not include information about third parties without their authorization. We do not use these results for behavioral advertising or sell personal data.
6. Coaches and their clients’ data
When a client registers by invitation or links to a coach, the associated coach can view the information needed to provide the service: profile, tracking, photos, measurements, plans, bookings, challenges, payments, products, messages, or activity related to that client.
The summary from Apple Health or Health Connect is only visible to the assigned coach when the client has explicitly enabled permission to share it. Native access to health history remains on the client’s phone and is not granted to the coach.
When a coach enters, manages, or views client data, they commit to doing so with a legitimate basis, sufficient consent, confidentiality, and a proper professional purpose. The coach is responsible for any information uploaded, shared, or kept about their clients, especially tracking data, images, progress, bookings, or any sensitive data.
If a client disconnects from a coach, the coach stops seeing their associated data. The client can remain in Hatipikal without an assigned coach; in that state, they can’t join challenges or services that require a coach until they link with a new one.
Telegram group participation is only visible to the direct coach while the client and coach are both members of that group and have linked their accounts. If either leaves the group, access is no longer available. Periods when they were not both members are not shown, and identified counters are automatically deleted after 90 days. For traceability, coach access is logged by time slot for up to 365 days.
7. Use of Google data
Data authorized through Google is used only to provide the features requested by the user within Hatipikal: secure access, calendar syncing, creating events or Meet links, managing contacts related to their activity, and reading or sending emails with Gmail when the coach enables that integration. When a coach connects Google Ads, Hatipikal uses the advertising permission only to show their accounts and conversion actions and to set up their chosen measurement; this permission is separate from access to Gmail, calendars, and contacts. Hatipikal does not sell personal data, use information obtained from Google APIs to create advertising profiles, or share this data unless necessary to provide the service, comply with the law, or protect account security.
Hatipikal uses calendar permission only to create its own secondary calendar and manage events generated by Hatipikal within it; it does not need access to the primary calendar or calendars created by other apps. Read-only Gmail access is limited to finding messages that may contain invoices or receipts and downloading their attachments when the coach enables this feature. Send permission is used only to send operational messages requested by the coach from Hatipikal using the connected account. Contacts permission allows Hatipikal to find, create, update, and, where appropriate, delete only contacts synced by Hatipikal. Google Ads is queried only to show accessible ad accounts and conversion actions and to set up the measurement selected by the coach.
Financial attachments that the coach chooses to import from Gmail may be processed through OpenAI's enterprise API to extract an editable proposal of the invoice or receipt data. Hatipikal has not enabled the use of this data to train or improve OpenAI models and does not send Google Workspace data to Anthropic, NVIDIA, or any other artificial intelligence providers. The results are used solely to provide the requested feature and are always subject to human review.
Hatipikal's use of raw or derived data received from Google Workspace APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. This data is not used to create, train, or improve generalized artificial intelligence or machine learning models, nor is it sold or used for personalized advertising.
Non-medical wellness appointments
No diagnosis or treatment. For health concerns, consult a healthcare professional.
To arrange the appointment, we process identity and contact details, the activity, date, time, format, chosen professional, and participants. The professional receives these scheduling details, but the booking does not give them access to the client's regular profile, nutrition, weight, progress, plans, workouts, test results, injuries, symptoms, medication, or photos. Private photos remain excluded.
During the meeting, you may voluntarily show information from your own device. This does not give the professional access to your profile, create permanent permission, or authorize them to store it in Hatipikal or ask you to send it through another channel.
If the appointment is paid, we retain the seller’s and professional’s tax and contact details, their operational verification through Stripe, the accepted agreement and its fingerprint, percentages, price, transaction, refunds, transfers, and disputes. This information is used to perform the contract, prevent fraud, handle claims, reconcile transactions, and comply with accounting, tax, and platform reporting obligations, including DAC7 where applicable. Stripe verifies identity and the financial account; Hatipikal does not store full card details.
To reconcile refunds, we also record, by currency and financial party, the amounts recovered through reversals, fees not refunded by Stripe, Hatipikal's earned commission, the balance allocated to the seller or professional, and any offsets applied to future payouts. These entries are traceable and idempotent and are linked to the transaction and the parties through their account identity. They do not change the amount to be refunded to the buyer or contain full card details.
Trader traceability information is retained for the duration of the relationship and for six months afterward where the Digital Services Regulation applies. Business records are retained for six years, and DAC7 due diligence records for between five and ten years from the reportable period, without prejudice to legal interruptions, claims, or retention holds. Declined invitations that do not result in a transaction are deleted or anonymized when their operational period expires. You can exercise your rights through the channels indicated in this policy.
8. Processors, providers, and transfers
To operate Hatipikal, we may rely on technical providers for hosting, databases, backups, email, messaging, payments, artificial intelligence, document processing, file storage, Google, and other services required to provide the requested features. Providers currently used include OpenAI, Anthropic, and NVIDIA for the artificial intelligence features described in this policy; Google for sign-in, calendar, contacts, Meet, email, fonts, and Firebase Cloud Messaging; LinkedIn to identify the profile authorizing access through their name and email, connect advertising accounts, and measure campaigns when the coach enables that integration; Apple to deliver push notifications; Stripe for payments; Twilio to verify phone numbers; Microsoft to verify email addresses; Resend to send emails; and HostSuAr, using Leaseweb Netherlands B.V. infrastructure in the Netherlands, for hosting, databases, files, logs, and backups. Cloudflare Developer Platform is used to signal in real time that there is new activity in a chat: it receives technical connection metadata, pseudonymous identifiers, and a content-free signal, but it does not receive message text, files, names, email addresses, or the internal conversation identifier. The channel runs within the European jurisdiction available for Durable Objects; certain provider identifiers and technical logs may be processed outside the EEA under the applicable safeguards. These providers act as processors or service providers, as applicable, and must not use the data for their own purposes unrelated to Hatipikal.
On the canonical domains, Cloudflare Turnstile may verify that someone attempting to sign in or request a password reset is a person. Cloudflare receives the challenge token and technical signals from the browser and connection; Hatipikal does not send it the email address, password, or form content during verification.
During the visual generation pilot, Hatipikal stores the resulting image in private local storage for 30 days and then deletes it automatically. Hatipikal uses specialist audiovisual generation providers for this feature. The technical generation provider may temporarily retain the generated file for up to 14 days and task records—such as the prompt and technical metadata—for up to two months. The image is only delivered after verifying the session and that it belongs to the account that requested the generation.
If you voluntarily connect Instagram, Facebook, TikTok or LinkedIn, Hatipikal will read only the selected account or page, your own posts and available statistics to personalize recommendations, without publishing or modifying content. AI analysis requires separate, specific authorization: only minimized excerpts of your own text and performance figures are sent to OpenAI. Images, videos, comments, followers, messages, tokens and keys are not sent. You can withdraw this permission and delete the reports without disconnecting the accounts.
Images uploaded by users—progress photos, facial assessments, meal photos, profile photos, and images attached to a technical issue—are stored as of August 24, 2026, on Bunny.net (BunnyWay d.o.o., Slovenia). Hatipikal has configured the zone by declaring primary storage in Germany, a replica in Sweden, and delivery limited to Europe; the sanitized independent export of that configuration remains pending. There is no public version of the file, and each view is generated only after verifying that the requester is the owner, an authorized coach, or a platform administrator; the generated link expires after a few minutes. Hatipikal does not keep a second permanent copy on its server. When a user deletes an image or their account, removal is requested from the provider and is only considered complete once the provider confirms it.
Uploading a photo does not require additional approval for each image. Photos and analyses requested for your personal follow-up use your current health-data consent. We respect previous explicit withdrawals. Publishing an image requires you to hold the necessary rights; you do so from the content where you add it, without another approval panel.
Photos provided by coaches for landing pages, teams, forms, catalogues, activities, promotions and exercises are also stored in Bunny. Images intended for publication are only displayed publicly when linked to active public content. You can remove them from the profile or content where you added them. Anyone appearing in an image can request its removal through “Report content”. When an image is removed, Hatipikal blocks its delivery and processes its deletion; it cannot retrieve copies that third parties have already downloaded. Images for these uses are prepared without EXIF metadata or GPS location. Images of financial supporting documents are retained in Bunny with their original bytes intact, under restricted access. Their retention follows the obligation applicable to the document, including where retention is required after an account is closed.
Cloudinary is reserved for editorial assets selected by Hatipikal, including default template images. Replacing a default photo with your own photo makes it user-provided content, which is stored in Bunny.
Some providers may be outside the European Economic Area. In those cases, available safeguards apply according to regulations, such as contractual clauses, provider data processing terms, or other valid mechanisms.
9. Retention
We keep data while your account is active or as long as needed to provide the service, meet legal obligations, resolve issues, or maintain security. You can request full deletion of your account and data by emailing our contact address. If there are legal, tax, contract, or security obligations, some records may be kept blocked for the strictly necessary period.
To prevent a backup restore from reactivating an account that has already been deleted, we temporarily retain a minimal technical record of the deleted account ID. This ID is stored encrypted, separately from the operational database, with restricted access, and only for as long as needed to cover backup rotation and verify that the request was fulfilled.
10. Security
Passwords are securely hashed. Access is protected by session, user approval, consent logs, and admin controls. Photos, documents, and files are stored in system folders and should be treated as personal data if they identify someone or contain sensitive information.
11. Cookies, analytics, and local storage
We use essential session cookies and browser local storage to keep you signed in and remember your language, interface state, and preferences needed for the app to work properly. Public landing pages also use our own random identifiers to distinguish visits and visitors without storing the IP address or full user agent. Hatipikal retains the source, campaign, referring domain, general device type, and relevant sections viewed in a form that can be aggregated, so the coach can see their landing page performance and conversions.
On public pages belonging to a coach who has enabled Google Ads, we also retain visit attribution parameters (such as UTM parameters and advertising platform click IDs), but only after the visitor accepts advertising. If they reject it or later withdraw consent, these parameters are not stored and are deleted from the browser. The Google advertising tag is downloaded only after the visitor expressly accepts measurement; if they reject it, the page remains fully functional. Google Analytics, when enabled by Hatipikal, is subject to the same choice and receives only a pseudonymized coach reference, the landing page path, and its language—never their email address. PostHog is used only after measurement is accepted to track page views and explicit functional events. It is hosted in the European region, does not receive names, emails, photos, form content, or health data, and has session recording and general interaction autocapture disabled. The LinkedIn Insight Tag is subject to the same consent choice and is used only for the advertising account selected by the coach. The TikTok Pixel and, when enabled, the TikTok Events API follow the same choice and are limited to the pixel expressly selected by the coach. Meta Pixel and Conversions API operate under the same consent and only with the account and pixel connected by the coach.
Each coach is responsible for the purpose and content of their campaigns. Hatipikal provides the technical mechanism and records contact conversions only for the advertising account selected by the coach. No advertising tag or server event is activated before the visitor expressly accepts measurement.
Your choice is made by category—essential, measurement, and advertising—and, within each category, provider by provider. Rejecting is as easy as accepting, and you can change or withdraw your choice at any time from this panel, which also deletes anything already stored in the browser: . Each consent and withdrawal is recorded with the date and version of the text shown.
12. Rights and account deletion
You can request access, correction, deletion, objection, restriction of processing, data portability when applicable, and withdrawal of consent by writing to info@hatipikal.comYou can also file a complaint with the relevant authority if you believe the processing doesn’t comply with regulations.
Deletion, access, export, correction, or restriction can be requested via the data management form or by email. The request must identify the account, and we may verify your identity before processing it.
13. Minors
Hatipikal is exclusively for people aged 18 or over. We do not allow accounts for minors, even with permission from their legal guardians. If we detect that an account or information belongs to a minor, we may block access, verify their age, and delete their data, except for the minimum records that must be temporarily retained to meet a legal obligation or document the action taken.
14. Health limitations
Hatipikal offers support tools for organization, tracking, training, and nutrition. Its content doesn’t replace a doctor, dietitian-nutritionist, physiotherapist, psychologist, or any health professional. You should consult a qualified professional before starting or changing plans if you have an illness, injury, pregnancy, medication, eating disorder, or any relevant health condition.
15. Changes to this policy
We may update this policy to reflect changes in the app, new integrations, or legal requirements. The version published at this URL will always be the current one.