Skip to main content

PRIVACY POLICY

Swimming Analysis — operated by Swimlytics Dijital Spor Teknolojileri Limited Şirketi

Last Updated: 17 August 2026 Version: 1.0


1. WHO WE ARE AND HOW TO CONTACT US

Data Controller: Swimlytics Dijital Spor Teknolojileri Limited Şirketi Altıntepe Mah. İstasyon Yolu Sk. No: 3/1, Maltepe/İstanbul, Türkiye Email: [email protected] Phone: +90 532 673 17 13 Website: swimminganalysis.com

Swimming Analysis ("we", "us", "our") is the data controller responsible for your personal data processed through this platform. For any privacy-related inquiries, data subject requests, or complaints, please contact us at [email protected].


2. SCOPE AND LANGUAGE

This Privacy Policy applies to all users of swimminganalysis.com and its associated services, regardless of location. It covers the collection, use, storage, transfer, and deletion of your personal data.

This policy is published in Turkish and English. In the event of any conflict between the two versions, the Turkish text shall prevail for users located in Türkiye. For users located in the European Economic Area (EEA) or United Kingdom, the English text shall prevail. For all other users, the English text shall apply.


3. WHAT DATA WE COLLECT AND WHY

3.1 Account Registration

When you create an account, we collect:

  • Full name
  • Date of birth
  • Email address
  • Password (stored in encrypted form; we never see your plain-text password)
  • Account type (Athlete, Coach, or Team Owner)

Legal basis (GDPR): Performance of a contract (Article 6(1)(b)) — this data is necessary to provide you with access to our services. Legal basis (KVKK): Processing necessary for the establishment or performance of a contract to which the data subject is a party (Article 5(2)(c)).

Consent records. When you accept the Terms of Service and Privacy Policy at registration (and, where applicable, confirm that you are an adult or the legal guardian of a minor athlete), we record that acceptance as proof of consent: the time of acceptance, the exact versions of the documents you accepted, the confirmation text shown to you, your IP address, and your browser information. This record is kept for as long as your account exists and is never shared or displayed.

Legal basis (GDPR): Legal obligation (Article 6(1)(c)) — Article 7(1) requires us to be able to demonstrate that consent was given. Legal basis (KVKK): Legal obligation of the data controller (Article 5(2)(ç)).

3.2 Minor Athletes (Under 18)

Parents do not have a separate account type — a parent or legal guardian registers an Athlete account on behalf of their minor child. If you are registering on behalf of a minor athlete, you must be that child's parent or legal guardian. During registration you will provide:

  • The child's full name and date of birth
  • Your own email address as the account holder
  • Your explicit consent on behalf of the child

We set a minimum age of 10 years for athlete accounts. We do not knowingly collect data from children under 10. If you believe we have inadvertently collected data from a child under 10 without proper parental consent, please contact us immediately at [email protected] and we will delete the data promptly.

Age verification mechanism. Users who register on behalf of a minor must select the "Parent" pathway during registration, which creates an Athlete account flagged as parent-managed. The parent provides their own email address as the account holder, confirms the child's name and date of birth, and provides explicit consent on behalf of the child by checking a dedicated consent checkbox. By completing registration, the parent or guardian confirms that they have the authority to provide this consent and that all data processing described in this policy is authorized. We rely on this declaration as reasonable verification of parental authority under Article 8 GDPR. We do not currently use technical age verification systems. If we receive credible information that an account was registered without proper parental consent, we will investigate and delete the relevant data promptly.

All data rights for minor athlete accounts are exercised by the parent or legal guardian.

3.3 Race Videos

When you upload a race video, we collect:

  • The video file itself
  • Race metadata you provide: event date, distance, stroke, race session, lane number, split/lap times, and any notes

Race videos are kept only as long as needed to perform the analysis and are then deleted automatically and permanently:

  • Analyzed videos — deleted 14 days after the analysis is completed.
  • Rejected videos — deleted 14 days after rejection.
  • Videos not analyzed within 30 days of upload — automatically rejected (the credit is refunded) and the video is deleted at that point.

If you delete a race from your profile, all of its remaining data — including the video, where one still exists — is permanently erased within 30 days. After deletion, no copy of the video is retained by us. Video deletion never affects your saved race metrics and analysis results.

Race video analysis is performed by authorized personnel only. Access to uploaded videos is strictly restricted to those personnel required to perform the analysis. Uploaded videos are never publicly displayed within the platform.

Race videos may contain images of multiple individuals (spectators, other athletes, coaches) who have not consented directly to data processing. By uploading a race video, you confirm that: (a) the video was recorded in a public sporting event or competition venue; (b) you have the right to share the video for analysis purposes; and (c) where required by applicable law, appropriate consent or authorization exists.

Legal basis (GDPR): Performance of a contract (Article 6(1)(b)) — video analysis is the core service you have purchased. Legal basis (KVKK): Performance of a contract (Article 5(2)(c)).

3.4 Performance and Analysis Data

We collect and permanently retain the following performance metrics derived from your race video:

  • Split times and lap times
  • Segment velocities
  • Stroke rate
  • Distance per stroke (DPS)
  • Underwater phase metrics
  • Start and turn metrics
  • Any other technical metrics generated through our analysis process

Upon account deletion, personally identifiable fields (name, email, phone, exact date of birth) are deleted within 14 days. The following data is retained indefinitely in genuinely anonymized form for benchmark and percentile analysis: age (a single integer derived from the year of birth at the time of analysis, e.g. 14), gender (Men/Women), and performance metrics (together with pool type, stroke, and distance). The combination of age, gender, and performance metrics cannot reasonably be used to re-identify any individual and we treat as anonymized data for the purposes of GDPR Recital 26.

Legal basis (GDPR): Performance of a contract (Article 6(1)(b)) for service delivery; legitimate interests (Article 6(1)(f)) for anonymized aggregate analytics. Legal basis (KVKK): Performance of a contract (Article 5(2)(c)); legitimate interests of the data controller (Article 5(2)(f)).

3.5 Credits and Payment Data

Our platform operates on a credit system. You purchase credit packages using a credit card processed by Iyzico Ödeme Hizmetleri A.Ş. ("Iyzico"). We do not store your card number, CVV, or full payment credentials. Iyzico processes and stores payment card data in accordance with PCI-DSS standards.

We retain:

  • Records of credit purchases (amount, date, package type, transaction reference)
  • Records of credit usage (which race each credit was applied to)
  • Credit refund records (issued when we reject a video for quality reasons)

Refund policy: Credit purchases are non-refundable. The only credit refund is the automatic return of 1 credit when we reject a submitted race video. No monetary refunds are issued. For full details, see our Refund Policy.

Billing records are retained for a minimum of 5 years in compliance with Turkish tax law (Vergi Usul Kanunu).

Legal basis (GDPR): Performance of a contract (Article 6(1)(b)); legal obligation (Article 6(1)(c)) for financial record retention. Legal basis (KVKK): Performance of a contract (Article 5(2)(c)); legal obligation (Article 5(2)(ç)).

Saved billing preferences (optional). During checkout, you may tick a box to let us save your billing details — phone number, address, city, and country — on your profile for faster future checkouts. This is opt-in: we store these details only when you explicitly request it, and we record the timestamp of your consent. Your name on the saved record is the name already on your profile. You can clear these saved details at any time from your profile settings under "Delete my Billing Information," or by emailing us at [email protected]. Saved billing preferences are also deleted when you delete your account, alongside other profile data, within 14 days.

Legal basis (GDPR): Consent (Article 6(1)(a)). Legal basis (KVKK): Explicit consent (Article 5(1)).

3.6 Team Accounts

Team administrators (Team Owners) may invite coaches and athletes to their team. When an invitation is sent, we store the invited person's email address. Invited individuals may accept or decline; invitation records are retained for operational and audit purposes.

Coach and Team Owner access to athlete data. When an athlete (or, for minors, their parent/guardian) accepts an invitation to join a team, the Team Owner and any coaches assigned to that athlete's sub-team are granted access to the athlete's performance data within the platform. This includes: race videos and metadata submitted while on the team, performance insights and analysis results, race metrics (split times, stroke rate, DPS, underwater/start/turn metrics, etc.), progress over time, and race and event history. This access is a core part of the team coaching feature and continues for as long as the athlete remains a member of the sub-team. Athletes (or their parent/guardian) may revoke this access at any time by leaving the team. This data sharing applies equally to minor athletes — the parent or guardian must be logged in to their account and explicitly accept the team invitation on behalf of the child, which constitutes documented consent for the child's participation in the team.

Legal basis (GDPR): Performance of a contract (Article 6(1)(b)); consent (Article 6(1)(a)) given by accepting the team invitation. Legal basis (KVKK): Performance of a contract (Article 5(2)(c)); explicit consent (Article 5(1)).

Team dissolution and access changes. Athlete data (account, race videos, performance metrics, analyses) belongs to the athlete, not to the team. The following lifecycle rules apply:

  • If a team is deleted: the team relationship is severed, but the athlete's account and all of the athlete's personal data continue to exist independently. Athletes retain full access to their own race history and analyses.
  • If a coach is removed from a team or sub-team: the coach loses access to the affected athletes' data immediately. No copies of athlete data are retained by the coach.
  • If an athlete leaves a team or sub-team: the Team Owner and coaches lose access to that athlete's data going forward. Race analyses created while the athlete was on the team remain accessible to the athlete in their own account.
  • If a Team Owner deletes their team: all team-level relationships (memberships, sub-team assignments, coach access) are removed. Individual athlete accounts and their data are not deleted.

Pro / public benchmark data. We maintain a separate library of elite-athlete race analyses sourced from public competitions, used by all users as a benchmark reference. Public competition data used for benchmark analysis is processed on the basis of legitimate interests (GDPR Article 6(1)(f); KVKK Article 5(2)(f)).

3.7 Transactional and Service Emails

We do not send marketing emails. Every email we send is transactional or service-related and necessary for the operation of the platform. These include: account sign-up confirmation emails, email-change confirmation emails (sent to both your current and your new address), payment confirmations and credit purchase receipts, password reset emails, team invitation notifications, race rejection notifications, data export delivery emails, and other service notifications directly related to your use of the platform. You cannot opt out of transactional emails while maintaining an active account.

Legal basis (GDPR): Performance of a contract (Article 6(1)(b)). Legal basis (KVKK): Performance of a contract (Article 5(2)(c)).

We may also send platform-wide announcements to all registered users regarding service changes, important updates, or maintenance. Legal basis (GDPR): Legitimate interests (Article 6(1)(f)). Legal basis (KVKK): Legitimate interests of the data controller (Article 5(2)(f)).

3.8 Support Communications

When you contact us by email or through our contact and support forms, we collect:

  • Your name and email address
  • The content of your message
  • Any attachments or information you choose to share

Support communications are retained for 1 year from the date of last correspondence.

Legal basis (GDPR): Legitimate interests (Article 6(1)(f)) — responding to your inquiry and maintaining service quality records. Legal basis (KVKK): Legitimate interests of the data controller (Article 5(2)(f)).

3.9 Technical and Usage Data

When you use our platform, we automatically collect certain technical data necessary to operate the service:

  • Session authentication data (managed via industry-standard authentication systems)
  • Browser type and operating system (for compatibility purposes)
  • IP address (used for security and rate limiting; retained as part of activity logs — see Section 7)
  • Pages visited and features used within the platform

Legal basis (GDPR): Legitimate interests (Article 6(1)(f)) — ensuring platform security and functionality. Legal basis (KVKK): Legitimate interests of the data controller (Article 5(2)(f)).

3.10 AI-Generated Race Reports

After our analyst completes a race analysis, our systems may automatically generate a plain-language narrative report explaining that analysis. The report text is produced using an artificial-intelligence model operated by Anthropic, PBC ("Anthropic"), a US-based AI provider acting as our data processor.

What is sent to Anthropic — non-identifying data only:

  • Age in whole years (e.g. 16) — a single integer calculated from the athlete's year of birth. The day and month of birth are never used in the calculation and are never transmitted.
  • Gender
  • Race and performance data — the analysis metrics (split times, segment velocities, stroke rate, distance per stroke, underwater metrics, and similar technical values), together with the race context (distance, stroke, pool type, race session).

Age and gender are included because the report is athlete-specific: without them, the model would have no way to relate the times to the correct comparison group for the athlete.

What is never sent to Anthropic: full name, date of birth (day and month), email address, contact details, meet or event names, free-text notes, and the race video itself. The athlete's name that appears on the finished report is inserted by our own systems after the text is generated; it never leaves our servers.

Report generation is initiated by our systems as part of delivering the analysis service, or by you when you request a report update from your analysis page. In either case the model receives only the data described above — users cannot submit free-form content to the AI model. Generated reports are stored on our EU-hosted infrastructure together with the associated race analysis and are removed when that analysis is deleted. Under our agreement with Anthropic, data submitted through its API is not used to train Anthropic's models.

Because Anthropic processes data in the United States, this transfer is safeguarded as described in Section 6 (International Data Transfers).

Legal basis (GDPR): Performance of a contract (Article 6(1)(b)) — the narrative report is part of the analysis service. Legal basis (KVKK): Performance of a contract (Article 5(2)(c)).


4. COOKIES AND LOCAL STORAGE

4.1 What We Use

We use the following cookies and browser storage:

TypePurposeDuration
Authentication session cookie (sb-<project>-auth-token, split across .0/.1 for large sessions)Maintains your login session — holds the tokens that authenticate your requests and renew your session in the backgroundSession, or up to ~400 days if "Remember me" is selected
sb-rememberRecords whether you chose "Remember me", so your session cookies are given the correct lifetimeSession
sb-<project>-auth-token-code-verifierTemporary security value used to complete a sign-in or password reset; normally removed once you finish signing inUntil sign-in completes (up to ~400 days if a sign-in is started but abandoned)
__cf_bm (Cloudflare)Bot management — distinguishes humans from automated trafficUp to 30 minutes
UI preferences (localStorage)Stores your display preferences (theme, sidebar state)Persistent until cleared

We do not currently use third-party advertising pixels, behavioral tracking tools, analytics cookies, or session recording software. For full details, see our Cookie Policy.

4.2 Future Cookies

We may in the future embed YouTube video content on our public pages. YouTube may set its own cookies when embedded content is loaded. We will update this policy and our Cookie Policy and implement a cookie consent mechanism before adding any third-party cookie-setting content.

4.3 Managing Cookies

You can control cookies through your browser settings. Disabling authentication cookies will prevent you from logging in to the platform.


5. HOW WE SHARE YOUR DATA

We do not sell your personal data. We do not share your personal data with advertisers. We share data only with the following categories of recipients:

5.1 Service Providers (Data Processors)

ProviderPurposeLocation
Supabase Inc.Database hosting, file storage, authenticationEU (Frankfurt)
Railway Corp.Application server hostingEU West (Amsterdam, Netherlands)
Iyzico Ödeme Hizmetleri A.Ş.Payment processingTürkiye
Resend Inc.Transactional email deliveryUS (see Section 6)
Functional Software Inc. (Sentry)Error monitoring and application performanceEU
Cloudflare Inc.CDN, DDoS protection, DNS proxy, and bot-protection captcha (Turnstile) on sign-up, sign-in, and other sensitive formsGlobal network (see Section 6)
Upstash, Inc.Temporary in-memory data store: rate-limit counters (keyed by IP address or user ID), a short-lived profile cache, and short-lived PDF download tokensEU (Frankfurt)
Anthropic, PBCAI generation of narrative race reports (see Section 3.10 — receives age in whole years, gender, and performance metrics only)US (see Section 6)

All service providers are bound by data processing agreements and are contractually required to process your data only on our instructions and in accordance with applicable data protection law. Our processors may engage sub-processors; details are available in their respective privacy policies.

5.2 Legal Requirements

We may disclose your data where required by law, court order, or government authority, including Turkish courts and regulators (KVKK Board), EU supervisory authorities, or equivalent bodies in other jurisdictions.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred to the acquiring entity. We will notify you before your data becomes subject to a different privacy policy.


6. INTERNATIONAL DATA TRANSFERS

Our primary database is hosted on our database infrastructure located in the European Union (Frankfurt, Germany). This means your data is stored within the EU and benefits from GDPR-level protections.

For users in the EEA and UK (GDPR): where data is transferred to processors outside the EU/EEA (for example, Resend Inc., Cloudflare Inc., and Anthropic, PBC in the United States), we rely on the European Commission's Standard Contractual Clauses (SCCs) as the transfer safeguard, as incorporated into our processor agreements. The data shared with Anthropic is limited to non-identifying information as described in Section 3.10.

For users in Türkiye: transfers of personal data outside Türkiye are subject to Article 9 of KVKK, which provides for safeguard mechanisms including the standard contract announced by the Personal Data Protection Board.


7. DATA RETENTION

Data CategoryRetention Period
Race videosDeleted automatically: 14 days after analysis or rejection; if never analyzed, rejected and deleted 30 days after upload (see Section 3.3)
Account data (name, email, phone, exact date of birth)Deleted within 14 days of confirmed account deletion request
Consent records (acceptance of Terms/Privacy Policy, adult/guardian declarations)For the life of your account
Race performance metrics, age (integer derived from birth year), genderRetained indefinitely as anonymized data for benchmark and aggregate analytics
AI-generated race reportsRetained with the associated race analysis; removed when the analysis is deleted
Payment and billing recordsMinimum 5 years in our accounting records (Turkish tax law requirement); in-app payment transaction history is preserved when an account is anonymized
Saved billing preferences (opt-in)Until you clear them from profile settings or delete your account
Support communications1 year from last correspondence
Invitation records1 year from invitation creation or expiry
Activity logs120 days rolling; credit-related activity records (purchases, usage, transfers) are retained for the life of the account
In-app notificationsRead notifications deleted after 30 days; all notifications deleted after 120 days

When data is deleted, we take reasonable steps to ensure deletion from backup systems within 90 days.


8. SECURITY

We implement the following security measures to protect your data:

  • All data in transit is encrypted using TLS/HTTPS
  • All data at rest is encrypted using industry-standard encryption at rest
  • Authentication and session management use industry-standard mechanisms
  • Access to production systems is restricted to authorized personnel only
  • Payment data is handled exclusively by Iyzico (PCI-DSS compliant); we do not store card data
  • Rate limiting and brute-force protections are in place on all authentication endpoints
  • All sessions are invalidated on password change

We have assessed that the appointment of a Data Protection Officer is not required under Article 37 GDPR given the scale and nature of our processing activities. We keep this assessment under review as our operations grow.

We have assessed our processing activities under Article 35 GDPR and determined that a formal Data Protection Impact Assessment is not currently required given the scale and nature of our operations.

We do not process special category data as defined in Article 9 GDPR or Article 6 KVKK. Swimming performance metrics (times, splits, stroke rate, and similar measurements) are athletic performance data, not health data.

Despite these measures, no system is completely secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within the timeframes required by applicable law (72 hours under GDPR; as soon as practicable under KVKK). Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected users without undue delay by email to the address registered to their account.


9. YOUR RIGHTS

Depending on your location, you have the following rights regarding your personal data:

9.1 Rights Under KVKK (All Users, Including Turkish)

Under Article 11 of KVKK, you have the right to:

  • Learn whether your personal data is being processed
  • Request information about the processing if it is
  • Learn the purpose of processing and whether data is used in accordance with that purpose
  • Know the third parties to whom data has been transferred domestically or abroad
  • Request rectification if data is incomplete or inaccurate
  • Request deletion or destruction of your data within the framework of applicable law
  • Request notification of rectification/deletion to third parties to whom data was transferred
  • Object to outcomes that arise solely from automated processing
  • Claim compensation for damages arising from unlawful processing

9.2 Additional Rights Under GDPR (EEA and UK Users)

  • Right of access — obtain a copy of your personal data
  • Right to rectification — correct inaccurate data
  • Right to erasure — request deletion ("right to be forgotten") where no overriding legal basis exists
  • Right to restriction — restrict processing in certain circumstances
  • Right to data portability — receive your data in a structured, machine-readable format (CSV)
  • Right to object — object to processing based on legitimate interests
  • Right to withdraw consent — at any time, without affecting the lawfulness of prior processing
  • Right to lodge a complaint with your local supervisory authority

9.3 How to Exercise Your Rights

Submit your request by email to: [email protected]

Application channels. For requests sent by email, your request must be sent from the email address registered to your account — this is how we verify your identity for the email channel. In accordance with the Turkish Communiqué on the Procedures and Principles of Application to the Data Controller (Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ), you may equally submit your request in writing (bearing your signature, delivered in person or through a notary) to our postal address in Section 1, or via registered electronic mail (KEP), secure electronic signature, or mobile signature. We do not refuse a request solely because it arrives through one of these other channels.

What your application must contain (per the Communiqué): your name and surname; your signature, if the application is in writing; your Turkish ID number (or nationality and passport number for foreign nationals); your residential or workplace address for notification; your email address, telephone, or fax number for notification, if any; and the subject of your request.

Response times:

  • Requests under KVKK (users in Türkiye): we will conclude your request free of charge as soon as possible and at the latest within 30 days of receiving it, as required by Article 13/2 of KVKK; this period is not extendable. We will either fulfil your request or notify you of our reasoned refusal in writing or electronically (Article 13/3). Where the Communiqué's fee tariff permits a charge (for example, for printed copies beyond the free page limit), we charge no more than that tariff.
  • Requests under GDPR (EEA and UK users): we will respond free of charge within one month. In complex cases we may extend this by up to two additional months, in which case we will notify you within the first month.

To request account deletion specifically: email [email protected] from the email address registered to your account with the subject line "Account Deletion Request". We will confirm receipt and process your request within the response period stated above. Note that anonymized performance metrics derived from your race data are retained after deletion as described in Section 3.4.

To withdraw consent given by accepting a team invitation (see Section 3.6), leave the team from your account settings; this immediately revokes the Team Owner's and coaches' access to your data going forward.

9.4 Supervisory Authorities

For users in Türkiye: Kişisel Verileri Koruma Kurumu (KVKK) kvkk.gov.tr +90 312 216 50 50

If you believe your application was refused, answered insufficiently, or not answered in time, you may lodge a complaint with the Kişisel Verileri Koruma Kurulu within 30 days of learning of our response and in any case within 60 days of the date of your application (Article 14 of KVKK). Under Article 14/2, the application procedure in Section 9.3 must be exhausted before a complaint is lodged with the Kurul.

For users in the EU/EEA: Contact the data protection authority in your country of residence. A list is available at: edpb.europa.eu

For users in the UK: Information Commissioner's Office (ICO) ico.org.uk


10. AUTOMATED DECISION-MAKING

We do not currently make any decisions about you that are based solely on automated processing and that produce legal or similarly significant effects.

Profiling for analytics. We do conduct performance profiling in the sense of tracking and comparing individual athlete metrics over time and against population benchmarks. As described in Section 3.4, anonymized performance metrics — together with age and gender — are retained as our work product and fall outside the scope of GDPR erasure rights.

AI-generated race reports. The narrative race reports described in Section 3.10 are produced automatically by an AI model from your computed analysis metrics. They are informational summaries only: they produce no legal or similarly significant effects, and no decision about you or your access to the service is based on them.


11. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Notify registered users by email at least 14 days before the change takes effect
  • Where required by law, obtain fresh consent

Continued use of the platform after the effective date of a revised policy constitutes acceptance of the updated terms, except where applicable law requires fresh consent, in which case we will seek your explicit consent before the change takes effect.


12. CONTACT

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, email [email protected]. Full controller details are listed in Section 1.