Last updated: August 27, 2026
Privacy Policy
1. Who We Are
Balansa is operated by:
BALANSA APP SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (Balansa App sp. z o.o.)
ul. Jana Matejki 6/9, 80-232 Gdańsk, Poland
Registered in the Polish National Court Register (KRS) under number 0001262788
NIP 9571206159 · REGON 54555577600000
Email: info@balansa.app
For any questions about how we handle your personal data, contact us at info@balansa.app.
2. What This Policy Covers
This Privacy Policy explains how Balansa collects, uses, and protects personal data when you use the Balansa platform — including the studio admin portal, client booking portal, and teacher portal.
Balansa operates in two distinct roles depending on context:
- Data controller — for data we collect about studio owners, teachers, and platform visitors for our own operational purposes (described in Section 3 below).
- Data processor — for personal data of studio clients (bookings, attendance, memberships) that we process strictly on behalf of studios. In this case, the studio is the data controller and their own privacy policy applies to their clients. Our obligations as processor are governed by a Data Processing Agreement (GDPR Art. 28) signed with each studio.
3. Data We Collect as Controller
| Who | Data collected | Purpose | Legal basis |
|---|---|---|---|
| Studio owners and teachers | Name, email address, phone number, account credentials | Creating and managing your Balansa account | Performance of contract (Art. 6(1)(b) GDPR) |
| All portal visitors | Browser and device information, pages visited, feature interactions | Understanding how the platform is used and improving the product | Legitimate interest (Art. 6(1)(f) GDPR) — see Section 8 |
| All portal visitors | Error logs and technical diagnostics | Ensuring service stability and resolving bugs | Legitimate interest (Art. 6(1)(f) GDPR) |
Our legitimate interest in using analytics and error monitoring is to operate and improve a reliable product. This interest does not override your rights — you can object to analytics-based processing at any time (see Section 9).
4. Our Role as Processor for Studio Client Data
When a studio uses Balansa to manage their clients, Balansa processes client personal data — including name, contact details, booking history, attendance records, and membership status — solely on behalf of and under instruction from that studio.
We do not use this data for our own purposes. The studio is responsible for informing their clients about how their data is used and for providing a lawful basis for the processing under GDPR.
If you are a studio client (you booked a class through a studio that uses Balansa), please contact the studio directly regarding your personal data — they are the data controller.
5. Sub-Processors
We use the following third-party service providers to operate the platform. All sub-processors are bound by data protection agreements ensuring an equivalent level of protection.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure and data storage | Frankfurt, EU |
| AWS SES / SNS | Transactional email and SMS notifications | Frankfurt, EU |
| Sentry | Error monitoring and diagnostics | EU region |
| Amplitude | Product analytics and usage tracking | EU region |
We will notify studio owners at least 14 days in advance of any changes to this list.
6. International Data Transfers
We do not transfer personal data outside the European Economic Area (EEA). All sub-processors listed above operate within EU/EEA infrastructure.
7. Data Retention
| Data | Retention period |
|---|---|
| Studio owner and teacher account data | Duration of the contract + 12 months after termination |
| Product analytics data (Amplitude) | 24 months on a rolling basis |
| Error logs (Sentry) | 90 days |
| Studio client data (processed on behalf of studios) | Deleted or returned within 30 days of contract termination, per the studio's written instruction |
8. Cookies and Tracking
We use two categories of cookies:
- Essential cookies — required for the platform to function (authentication, session management, security). These are set automatically and cannot be disabled without breaking core functionality.
- Analytics cookies — used by Amplitude to understand how features are used and to improve the product. These are only placed with your explicit consent.
You can accept or reject analytics cookies via the consent banner shown on your first visit to any Balansa portal. You may change your choice at any time via the cookie settings link in the page footer.
9. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Rectification — ask us to correct inaccurate or incomplete data
- Erasure — ask us to delete your data (“right to be forgotten”)
- Restriction — ask us to pause processing in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interest, including analytics
To exercise any of these rights, email us at info@balansa.app. We will respond within 30 days.
Note for studio clients: If you booked classes through a studio using Balansa, your data is controlled by that studio, not by Balansa. Please contact the studio directly to exercise your rights.
10. Supervisory Authorities
If you believe your data is being processed unlawfully, you have the right to lodge a complaint with a data protection supervisory authority. Depending on your country of residence:
- Poland: Prezes Urzędu Ochrony Danych Osobowych (UODO) — uodo.gov.pl
- Czech Republic: Úřad pro ochranu osobních údajů (UOOU) — uoou.gov.cz
We would appreciate the opportunity to address your concerns directly before you contact a supervisory authority.
11. Changes to This Policy
We may update this policy as the platform evolves. We will notify studio owners by email of any material changes at least 14 days before they take effect. The “last updated” date at the top of this page always reflects the current version.
Minor updates (such as adding a new sub-processor) will be reflected here and in the sub-processor notification process described in Section 5.