Privacy Policy
Your privacy is important to us. This Privacy Policy explains how Kiné Health collects, uses, and protects your information.
Last updated: April 2026
Your privacy is important to us. This Privacy Policy explains how Kiné Health collects, uses, and protects your information.
Data We Collect
We collect information to provide and improve our services:
- Personal information (name, email, contact details)
- Health data (injury history, recovery goals, progress)
- Usage data (app interactions, exercise completion)
- Technical data (device info, IP address)
How We Use Your Data
Your data helps us provide personalised care:
- Personalise your recovery programs and recommendations
- Provide and improve our services
- Communicate with you about your progress
- Improve our AI algorithms (using anonymised data)
Data Protection
We take your data security seriously:
- End-to-end encryption for all personal data
- Anonymisation of data used for research
- Strict access controls and regular audits
- Full GDPR compliance and data protection standards
Your Rights
Under GDPR, you have the right to:
Access Your Data
View all personal data we hold about you
Correct Your Data
Update or correct any inaccurate information
Delete Your Data
Request complete deletion of your account
Data Portability
Export your data in a readable format
Data Controller
The data controller responsible for your personal data is:
Legal Basis for Processing (Article 6 GDPR)
We process your personal data on the following legal bases:
Consent
Where you have given us explicit consent to process your data, such as for marketing communications or non-essential cookies.
Contract Performance
Where processing is necessary to provide the services you have signed up for or requested.
Legitimate Interests
Where we have a legitimate business interest, such as improving our services and preventing fraud, that does not override your rights.
Data Retention
We retain your personal data for as long as your account remains active. Following account deletion, your data is retained for a further 2 years to comply with legal obligations and resolve any disputes, after which it is securely deleted or anonymised.
Third-Party Processors
We work with the following trusted third-party service providers who may process your data on our behalf:
- EmailJS — used to send contact form submissions and transactional emails.
- Google — used for sign-in authentication via Google OAuth.
- Analytics tools — used to understand how users interact with our service and improve it (e.g. Google Analytics).
All processors are contractually bound to process data only on our instructions and in accordance with applicable data protection law.
Supervisory Authority
If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with a supervisory authority. In Greece, the relevant authority is:
Contact Us
For any privacy-related questions or requests: