GDPR Data Protection Processes

Effective Date: 11 August 2026 · Version 1.0

This document describes the internal data protection processes Applied Science follows to comply with the GDPR (EU) 2016/679 and the Maltese Data Protection Act. It complements our Privacy Policy by describing how we operationalise your rights and our obligations.

1. Role

Applied Science acts as the data controller for personal data processed to operate the Platform. Coaches act as independent controllers for the coaching content they create. Payment processor Stripe and authentication provider Google act as independent controllers for the data they collect directly.

2. Records of Processing

We maintain a record of processing activities covering: account and identity data; performance and health data; payment and billing data; communication data; and usage data. Each record identifies the purpose, lawful basis, categories of data subjects and recipients, retention period, and security measures.

3. Lawful Bases

We rely on contract performance, legal obligation, legitimate interests and consent as described in the Privacy Policy. We document the basis for each processing activity and do not process data for incompatible new purposes without a fresh lawful basis.

4. Data Subject Rights Handling

We provide a single contact point (privacy@myappliedscience.com) for all rights requests. Requests are logged, identity is verified, and responses are provided within one month, extendable by two months for complex requests with written explanation of the extension. We do not charge for reasonable requests and may refuse or charge a reasonable fee for manifestly unfounded or excessive requests.

5. Subject Access Request (DSAR) Process

On a DSAR we provide: confirmation of processing; the categories of data; the purposes; recipients or categories of recipients; retention periods; and the existence of your rights including the right to lodge a complaint with the IDPC. Data is provided in a structured, commonly used and machine-readable format.

6. Data Breach Response

We maintain a breach response procedure. On becoming aware of a personal data breach, we assess the risk to affected individuals. Where a breach is likely to result in a risk to rights and freedoms, we notify the Maltese Data Protection Authority (IDPC) within 72 hours. Where the breach is likely to result in a high risk, we also notify affected individuals without undue delay, together with remedial guidance.

7. Retention Schedule

Account and billing records: up to 7 years (tax/accounting). Session logs, wellness and performance data: up to 3 years after account closure. Enquiry and marketing consent records: up to 2 years. Authentication logs: up to 12 months. Records are securely deleted or anonymised at the end of the retention period.

8. International Transfers

Where data is transferred outside the EU/EEA, we rely on Standard Contractual Clauses, an adequacy decision, or another appropriate safeguard under Chapter V of the GDPR. We record the transfer mechanism and the third country involved.

9. Sub-processors

Our key sub-processors include: hosting and infrastructure providers, Stripe (payments), and Google (authentication and Calendar). We enter into written data processing agreements with each sub-processor, impose confidentiality obligations, and require equivalent security standards. A current list of sub-processors is available on request.

10. Privacy by Design & Security

We apply data minimisation, role-based access control, row-level security to separate athletes’ data, encryption in transit, secure secret storage, and audit logging. Access is granted on a least-privilege basis and reviewed periodically.

11. Children’s Data

The Platform is not intended for users under 18. Where a minor accesses the Platform with guardian consent, we apply enhanced protection to health and performance data and do not profile or market to minors.

12. Data Protection Contact

For any data protection matter, contact us at privacy@myappliedscience.com. You also have the right to lodge a complaint with the Information and Data Protection Commissioner (IDPC), Malta, or with your local supervisory authority.

© 2026 Applied Science. All rights reserved. Last updated 11 August 2026.