Privacy Policy

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is:

Atmea – Maximilian Tömelc/o Impressumservice Dein-ImpressumStettiner Str. 4135410 HungenGermany
Phone: 0157 9234 1658Email: info@atmea.appWebsite: https://www.atmea.appThe legal notice is available at: https://www.atmea.app/impressum

2. General information and SSL/TLS encryption

This privacy policy informs you about the nature, scope and purpose of the processing of personal data on the website https://www.atmea.app. Personal data is any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR).

For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the browser’s address bar shows “https://” and a padlock symbol appears. When SSL/TLS encryption is enabled, data you transmit to the operator cannot be read by third parties.

The operator points out that data transmission over the internet (e.g. when communicating by email) can have security gaps. Complete protection of data against access by third parties is not possible.

3. Legal bases for processing

The GDPR provides six equivalent legal bases for the processing of personal data in Art. 6(1). Where this privacy policy refers to legal bases, the following definitions apply:

  • Art. 6(1)(a) GDPR (consent): The data subject has given consent to the processing of their personal data for one or more specific purposes.
  • Art. 6(1)(b) GDPR (performance of a contract): Processing is necessary for the performance of a contract to which the data subject is party, or in order to take pre-contractual steps.
  • Art. 6(1)(c) GDPR (legal obligation): Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Art. 6(1)(d) GDPR (vital interests): Processing is necessary in order to protect the vital interests of the data subject or of another natural person.
  • Art. 6(1)(e) GDPR (public interest): Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
  • Art. 6(1)(f) GDPR (legitimate interests): Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where the interests or fundamental rights and freedoms of the data subject override them.

4. Hosting of the website www.atmea.app

This website is hosted by statichost.eu, a European provider. Processing takes place exclusively within the European Union or the European Economic Area; no transfer to third countries takes place. When the website is accessed, the IP address of the accessing device is processed for technical reasons in order to deliver the requested content. According to the provider, no personal data relating to website visits is stored in the process. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and efficient provision of the website). A data processing agreement pursuant to Art. 28 GDPR is in place with the host.

4.1 No cookies, no tracking

This website does not embed any analytics or tracking services, advertising cookies or external content (e.g. no Google Fonts). Fonts used are served locally. For basic functions (e.g. the selected colour scheme and language), only the browser’s local storage (localStorage) is used; this information remains on your device and does not require consent.

Purpose: Ensuring trouble-free operation of the website, detecting and preventing attacks, and error correction.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the technically secure and stable provision of the website.

5. The Atmea app – local data processing

All data recorded in the app (e.g. exercises, training sessions, maximum attempts, BOLT scores, settings) is stored exclusively locally on the device used, in an SQLite database. There is no user account, no server and no cloud to which this data is transferred. No transfer to us or to third parties takes place. The data leaves the device only if you actively initiate this yourself (see “Data backup”). The local storage is used on the basis of Section 25(2) no. 2 TTDSG, as it is technically strictly necessary to provide the function you have requested.

5.1 The Atmea app – device functions and permissions

The app uses only local device functions: an optional counting of diaphragm contractions via the motion sensor (accelerometer), which is disabled by default and evaluated exclusively on the device; a function to keep the screen on during an exercise; and the included voice output via pre-produced audio files stored in the app. No microphone, camera or location data is used, and no sensor data is transmitted. If you explicitly enable it, the app additionally reads your nightly sleep values (time in bed, sleep duration, deep-sleep and REM portions, average and lowest pulse, heart-rate variability and respiratory rate) from Apple Health in order to relate them to your training. This access is opt-in, read-only (no data is written back to Apple Health), and the values are stored and processed exclusively on the device; they are not transmitted to us or to third parties. You can revoke the permission at any time in your iOS settings.

5.2 Data backup (export/import)

You can export your data in the app as a file at your own initiative and import it again. Optionally, the export can be encrypted with a password. The export leaves your device only if you pass on or store the file yourself; we do not receive any data in the process.

5.3 Automatic device backup by the operating system

In addition to section 5, please note the following: modern operating systems automatically include the data of installed apps in the device backup, provided you have enabled backups on your smartphone. Atmea's local database is covered by this as well. This is a function of your operating system and not a function of our app: the backup is performed by Apple or Google, not by us. We never receive any data in this process, we have no access to the backup and no influence over it.

Apple (iOS): If “iCloud Backup” is enabled, a backup of the app data is stored in your personal iCloud account. Apple stores this backup in encrypted form; under the standard setting, Apple manages the corresponding keys and is technically able to decrypt the backup, for example when legally obliged to disclose it to authorities. If you additionally enable “Advanced Data Protection” in your iCloud settings (available from iOS 16.2), the backup is end-to-end encrypted and even Apple no longer has access to its contents. A local backup created via Finder or iTunes on your computer remains entirely with you and can additionally be protected there with a password.

Google (Android): If Google backup is enabled, app data is stored in your personal Google account. Provided a screen lock (PIN, pattern or password) is set up on your device, these backups are end-to-end encrypted on the device itself; the key is derived from your screen lock, so that according to Google's own statements Google cannot read the contents. Without a screen lock in place, this additional protection does not apply.

You decide yourself whether Atmea is included in the device backup: on iOS you can exclude the app specifically from the backup (Settings → [your name] → iCloud → Manage Storage → Backups). On Android you can disable the backup of app data in your Google settings.

Please note: Apple and Google alone are responsible for the processing carried out as part of these device backups; their respective privacy policies apply (see section 5.4). If you exclude the app from the device backup, the export described in section 5.2 is the only way to keep your data if your device is lost, damaged or replaced.

5.4 Obtaining the app via app stores

The app is provided via the Apple App Store and Google Play. During download, installation, payments and any crash reports, these platforms process their own data under their own responsibility in accordance with their respective privacy policies.

We have no influence over this processing and do not receive any individual personal data from it.

5.5 Disclosure of data

No disclosure or sale of personal data takes place. Apart from the hosting provider named above, which provides the website technically, no other recipients are involved.

6. Contacting us

6.1 Contact by email or telephone

If you contact the operator by email or telephone, the data you provide (e.g. name, email address, telephone number, content of your enquiry) will be stored and processed for the purpose of handling your enquiry and in case of follow-up questions.

This data is processed:

  • on the basis of Art. 6(1)(b) GDPR, insofar as your enquiry is related to the performance of a contract or is necessary to carry out pre-contractual measures;
  • on the basis of Art. 6(1)(f) GDPR otherwise – the legitimate interest lies in the effective handling of enquiries addressed to the operator;
  • on the basis of Art. 6(1)(a) GDPR, insofar as you have expressly consented to the processing.

The data remains with the operator until you request its deletion, withdraw your consent or the purpose of storing the data no longer applies (e.g. after your enquiry has been dealt with) – see Section 7, Retention periods and deletion concept. Mandatory statutory retention periods – in particular commercial and tax law retention obligations of up to ten years (Section 147 AO, Section 257 HGB) – remain unaffected.

7. Retention periods and deletion concept

Contact and enquiry data (email, telephone): after the enquiry has been finally dealt with; where there is a business context, up to 10 years in accordance with commercial and tax law retention obligations (Section 257 HGB, Section 147 AO).

App data (Atmea app) is stored exclusively locally and is not subject to any server-side retention period.

8. Transfers to third countries

All data processing arising in connection with the operation of this website (in particular the technically required processing of the IP address to deliver the content) takes place exclusively on servers within the European Union or the European Economic Area. No transfer of personal data to a third country outside the EU/EEA within the meaning of Art. 44 et seq. GDPR takes place. Therefore, neither an adequacy decision nor appropriate safeguards (e.g. standard contractual clauses) are required for a third-country transfer.

9. Automated decision-making and profiling

Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place on this website. No decisions are made that are based solely on automated processing and that produce legal effects concerning the data subject or similarly significantly affect them.

10. Rights of data subjects

You have the following rights vis-à-vis the controller, provided the respective legal requirements are met:

10.1 Right of access (Art. 15 GDPR)

You have the right to obtain confirmation as to whether personal data concerning you is being processed. If this is the case, you have the right to access this data as well as to further information pursuant to Art. 15 GDPR (e.g. purposes of processing, categories of data, recipients, envisaged storage period).

10.2 Right to rectification (Art. 16 GDPR)

You have the right to request the immediate rectification of inaccurate personal data concerning you and the completion of incomplete personal data.

10.3 Right to erasure (Art. 17 GDPR)

You have the right to request the immediate erasure of personal data concerning you, provided that one of the reasons set out in Art. 17(1) GDPR applies and the processing is no longer necessary. Statutory retention obligations may preclude the right to erasure (Art. 17(3) GDPR).

10.4 Right to restriction of processing (Art. 18 GDPR)

You have the right to request the restriction of the processing of your personal data if one of the conditions set out in Art. 18(1) GDPR is met (e.g. if you contest the accuracy of the data, for the duration of the verification by the controller).

10.5 Right to data portability (Art. 20 GDPR)

You have the right to receive the personal data concerning you that you have provided to the controller in a structured, commonly used and machine-readable format, and the right to transmit this data to another controller without hindrance, provided the processing is based on consent (Art. 6(1)(a) GDPR) or a contract (Art. 6(1)(b) GDPR) and is carried out by automated means.

10.6 Right to object (Art. 21 GDPR)

You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you that is based on Art. 6(1)(e) or (f) GDPR. The controller will then no longer process the personal data unless it can demonstrate compelling legitimate grounds for the processing that override the interests, rights and freedoms of the data subject, or the processing serves to assert, exercise or defend legal claims (Art. 21(1) GDPR). You will be expressly informed of this right at the latest at the time of first contact.

You can send your objection informally by email to info@atmea.app.

10.7 Right to withdraw consent given (Art. 7(3) GDPR)

Insofar as the processing of your personal data is based on consent, you have the right to withdraw this consent at any time with effect for the future. The lawfulness of the processing carried out on the basis of the consent until withdrawal is not affected by the withdrawal. You can send your withdrawal informally by email to info@atmea.app.

10.8 Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data concerning you infringes the GDPR.

The controller is based in Bavaria. The competent supervisory authority is therefore:

Bavarian State Office for Data Protection Supervision (BayLDA)Promenade 1891522 AnsbachGermanyPhone: +49 981 180093-0Email: poststelle@lda.bayern.deWebsite: https://www.lda.bayern.de

You may also contact the supervisory authority of your habitual residence or place of work.

Last updated: July 2026