Privacy Policy
This Privacy Policy explains how NETBULLS Sp. z o.o. ("ProovX", "we", "us", or "our") collects, uses, and protects your information when you use the ProovX mobile application, the ProovX Dev build, the ProovX web application, or any other ProovX service that links to this policy (collectively, the "Service"). ProovX is a product of NETBULLS Sp. z o.o.
NETBULLS Sp. z o.o. is the controller of the personal data described in this policy. Clubs and organisations you join are separately responsible for the decisions they make about their members within the club — for example, who is enrolled, attendance, and gradings. The club's own privacy notice covers those decisions.
This policy works alongside our Terms of Service, which govern your use of the Service.
Information We Collect
Information you provide to us
- Account information. When you create an account or sign in, we collect your email address, display name, phone number, and — if you choose to use them — credentials from linked social identity providers (e.g., Google, Apple).
- Profile information. Optional profile details you enter, such as club affiliation, preferences, or avatar.
- Training and club data. Sessions, events, attendance, gradings and achievements, metrics, notes, and any other content you or your club record within the Service.
- Communications. Messages, support requests, and feedback you send to us.
Information collected automatically
- Device information. Device model, operating system version, application version, language, and time zone.
- Usage information. Interactions with app features, navigation events, and diagnostic logs when errors occur. These are used to maintain and improve the Service.
- Authentication tokens. Stored securely on your device to keep you signed in across sessions.
We do not collect your precise location, contacts, photos, camera input, or microphone data unless you explicitly grant permission and use a feature that requires it.
Information from third parties
- Authentication. We use a self-hosted instance of Logto as our identity provider. Logto processes sign-in credentials, including those from linked social providers if you choose to use them.
- Phone verification. Sign-in codes are sent on WhatsApp if your number can receive them, otherwise by SMS. The first code to a number we have not verified before is sent by SMS; once your number is verified with us, later codes go to WhatsApp first unless you have switched WhatsApp off. You can switch WhatsApp off or on at any time in Settings › Account, you can always ask for an SMS code instead with one tap, and if WhatsApp can't deliver we send an SMS automatically. SMS is delivered by Twilio and WhatsApp by the WhatsApp Business Platform (Meta Platforms Ireland Ltd.); we share your phone number with the respective provider solely to deliver the code.
- Map services. When you use location-based features, we use Mapbox to render maps. Mapbox may receive approximate region information necessary to render map tiles.
- Data sync. We use a self-hosted PowerSync instance to synchronize your data between your devices and our backend.
Why We Process Your Data and On What Basis
Under the General Data Protection Regulation (GDPR), we process your personal data for the purposes and on the legal bases set out below.
| What we do | Data we use | Legal basis |
|---|---|---|
| Provide the Service — your account, profile, and the training and club data you and your club record | Account, profile, training/club data, device information | Performance of our contract with you (Art. 6(1)(b)) — where the member is a child, the contract is with the parent or legal guardian (or the club acting on their instructions), never with the child |
| Send verification codes and account or security notices by SMS, WhatsApp, or email | Phone number, email address | Contract (Art. 6(1)(b)) for delivering the code you requested; the choice of WhatsApp as the channel rests on our legitimate interest in reliable, low-cost delivery (Art. 6(1)(f)) — you are told before requesting the code and can switch WhatsApp off at any time |
| Keep the Service secure — prevent abuse and fraud, run device attestation and rate limits, keep audit logs | Device information, usage data, IP address, phone number | Our legitimate interests in a secure service (Art. 6(1)(f)) |
| Diagnose problems and improve the Service using our own self-hosted telemetry | Usage data, error logs | Our legitimate interests in a reliable service (Art. 6(1)(f)) |
| Send push notifications about your clubs' activity | Device push token | Our legitimate interests (Art. 6(1)(f)) — you can switch these off in your device settings at any time |
| Optional profile details you add, and linking a social sign-in account | The details you choose to add; social account identifier | Your consent (Art. 6(1)(a)) — withdraw by removing them |
| Keep billing and accounting records where a club sells paid items | Transaction records | Compliance with a legal obligation (Art. 6(1)(c)) |
| Process a child's data where consent applies | The child's data described in this policy | Parent or legal guardian consent (Art. 8) |
Cookies and Tracking
We do not run advertising, analytics, or tracking technologies on proovx.com or in our apps. We use only the strictly necessary cookies and local storage needed to sign you in and keep your session active. We do not sell your personal information or share it with data brokers or advertising networks.
Special-Category Data
We do not collect special-category data such as health or medical information. Please do not enter this kind of information into free-text fields in the Service.
Automated Decision-Making
We do not make decisions that produce legal or similarly significant effects about you using solely automated processing.
Data Storage and Security
- All data in transit is encrypted using TLS 1.2 or higher.
- Data at rest is stored on infrastructure we operate in the European Union.
- Access to personal data is restricted to authorized personnel who need it to operate the Service.
- We implement reasonable technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction.
No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
Data Retention
We keep personal data only as long as we need it, using the following criteria:
- Account data — kept while your account is active. After you delete your account, we remove it from our live systems within 30 days.
- Backups — encrypted backups are retained for up to 30 days and then cycled out.
- Security, audit, and code-delivery logs — up to 12 months.
- Billing and accounting records — for the period Polish law requires (5 years).
- Records a club keeps about you (such as attendance and gradings) — retained according to the club's own retention rules.
Your Rights
If you are in the European Economic Area (EEA), you have the following rights over your personal data:
- Access — request a copy of the personal data we hold about you;
- Rectification — request correction of inaccurate or incomplete information;
- Erasure — request deletion of your personal data;
- Restriction — request that we limit how we process your data;
- Portability — request your data in a machine-readable format;
- Objection — object to processing based on our legitimate interests, including our use of WhatsApp to deliver your sign-in codes (switch WhatsApp off in Settings › Account, or ask for an SMS code);
- Withdraw consent — where we rely on your consent (the optional profile details and social sign-in linking), you can withdraw it at any time by removing them.
To exercise any of these rights, contact us at privacy@netbulls.io. We respond within one month. If your request is complex, we may extend this by up to two further months and will tell you if we do (Art. 12(3) GDPR).
You also have the right to lodge a complaint with a data protection authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl. If you live elsewhere in the EEA, you may contact your local authority.
Third-Party Processors
We share personal data with the following processors, solely to operate the Service:
| Processor | Purpose | Data shared |
|---|---|---|
| Logto (self-hosted) | Authentication | Email, name, user ID, social sign-in identifiers |
| Hetzner Online GmbH (Germany) | Hosting of our servers and all self-hosted components (Logto, PowerSync, API, telemetry) | All Service data |
| Twilio Ireland Limited (Ireland) | Verification code delivery by SMS | Phone number |
| WhatsApp Business Platform — Meta Platforms Ireland Ltd. (Ireland) | Verification code delivery by WhatsApp | Phone number |
| Resend, Inc. (USA) | Transactional email delivery | Email address, message content |
| Firebase Cloud Messaging — Google Ireland Ltd. (Ireland) | Push notifications | Device push token |
| Mapbox, Inc. (USA) | Map rendering | Approximate region for tile requests |
| Cloudflare, Inc. (USA) | Media and file storage (R2) | Files you or your club upload |
| PowerSync (self-hosted) | Data sync | Training and club data, user identifiers |
| Stripe Payments Europe, Ltd. (Ireland) — only where a club has enabled online payments | Payment processing | Name, email, amount (card details are entered directly with the provider and never stored by us) |
Google and Apple sign-in are independent providers you may choose to use to sign in; they are not our processors. We do not sell your personal information.
International Data Transfers
Our servers are located in the European Union (Hetzner, Germany), and we process your data in the European Economic Area wherever we can. Some of our processors are located outside the EEA: Twilio Ireland Limited (our SMS provider) may transfer data to its US affiliate Twilio Inc. under Twilio's Binding Corporate Rules and the EU-US Data Privacy Framework; Mapbox, Inc. (USA), Resend, Inc. (USA) and Cloudflare, Inc. (USA) under the EU-US Data Privacy Framework and/or Standard Contractual Clauses. WhatsApp verification is handled by Meta Platforms Ireland Ltd. within the EEA; any onward transfers Meta makes are covered by its own data transfer terms.
Children's Privacy
Many clubs on ProovX train children. A child uses ProovX through their club, with a parent or legal guardian involved: the guardian — or the club, acting on the guardian's instructions — creates or links and manages the child's record.
Where we rely on consent to process a child's personal data and the child is under 16 (the age that applies in Poland under Article 8 GDPR), that consent is given by a parent or legal guardian. We do not knowingly create accounts for children under 16 without a parent's or guardian's involvement. If you believe a child's data has been provided to us without that involvement, contact us at privacy@netbulls.io and we will delete it.
Data Protection Officer
We have not appointed a Data Protection Officer. For any data-protection question, contact us at privacy@netbulls.io.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and revise the "Last updated" date at the top. For material changes, we will provide additional notice (for example, via the app or via email where appropriate).
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
Changes to this document
- Version 2.3 · 16 August 2026 · Sign-in codes: WhatsApp used for verified numbers where it can deliver, otherwise SMS; disclosed before you request a code; switch off any time in Settings; legal basis clarified. (current version)
- Version 2.2 · 16 August 2026 · WhatsApp delivery of sign-in codes is opt-in: SMS by default; WhatsApp only after you say yes once, changeable in Settings; consent row added. · view this version
- Version 2.1 · 16 August 2026 · Clarifications: contract with the parent or legal guardian for child members; Twilio Ireland → Twilio Inc. transfer named. · view this version
- Version 2.0 · 16 August 2026 · Full rewrite after legal review — legal-basis table, children's rule, EEA rights, retention criteria, controller statement, processors and international transfers, WhatsApp code delivery, company identity. · view this version
- Version 1.0 · 10 April 2026 · Original privacy policy. · view this version
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal data, please contact us:
NETBULLS Sp. z o.o.
Privacy matters: privacy@netbulls.io
General enquiries: hello@proovx.com
Website: https://proovx.com
Company details
NETBULLS Sp. z o.o. · ul. Żurawia 71A lok. 1.51, 15-540 Białystok, Poland · registered in the National Court Register kept by the District Court in Białystok, XII Commercial Division, KRS 0000469017 · NIP 5423232507 · share capital PLN 10,000.