1. Who we are and what this policy covers
QUS Tech GmbH (“we”, “us” or “our”) provides QUS Tech, including compatible smart textiles, sensors, chest straps, an On-Board Unit (“OBU”), the QUS Tech mobile application (the “App”), the QUS Tech Data Platform and related analytics services (together, the “Services”).
This Privacy Policy explains how we process personal data when you use the App and Services, and the choices and rights available to you.
For questions, data-rights requests, data export requests or account-deletion requests, contact us at office@qus.tech.
This policy does not replace a privacy notice supplied by a club, coach, employer, research institution, sports organisation or other organisation that gives you access to QUS Tech (an “Organisation”). Section 8 explains this distinction.
2. Important information about the QUS Tech system
The QUS Tech system can capture and display physiological, movement and location information from a compatible smart textile, sensor or chest strap and an OBU. Depending on the configuration and sensors used, this may include ECG-related signal data, heart rate, breathing or respiration rate, temperature, calories, activity intensity, distance, speed, elevation, steps, latitude, longitude, timestamps and related session measurements.
The OBU stores the recorded session data in a file on the OBU itself. The presence of a file on the OBU does not by itself upload the file to us or make it available to another person. Cloud processing occurs only when the user expressly chooses one of the following options through the App or another QUS Tech interface:
- Upload or synchronise a session file: the selected recorded session is uploaded to the QUS Tech Data Platform; or
- Enable live streaming: while a session is in progress, selected measurements are transmitted to the QUS Tech Data Platform in real time or near real time so that they can be monitored, stored and analysed remotely.
You remain responsible for the files stored on an OBU in your possession, including any export, sharing or deletion you choose to perform.
The App may process data received from the OBU locally on your mobile device to enable pairing, live display, session control and on-device functionality. If you elect to upload a session or enable live streaming, the selected session data is sent to the QUS Tech Data Platform for storage, visualisation and analysis. Live streaming is optional; stopping a live stream stops future transmission, but does not automatically delete data already received by the QUS Tech Data Platform.
3. Personal data we process
The data we process depends on how you use the Services, the connected equipment, the account configuration and the permissions you grant.
| Category | Examples | Why we use it |
|---|---|---|
| Account and organisation data | Name, email address, account ID, role, Organisation, team or group membership | To create and administer access, authenticate users and apply the correct permissions. |
| Sensor, physiological and health-related data | ECG-related readings, heart rate, respiration rate, temperature, calories, activity intensity and other measurements | To capture, display, store and analyse a session; and, where live streaming is enabled, transmit selected measurements to the cloud. |
| Location and movement data | Precise latitude/longitude, route, elevation, distance, speed, steps, movement information and timestamps | To record, map, display and analyse a session and, where enabled, provide location and movement data through a live stream. |
| Session and derived data | Session time, duration, labels, charts, trends, performance and recovery-related insights | To show session history and deliver analysis and visualisations. |
| Equipment and technical data | OBU or sensor identifier, pairing information, firmware or app version, device type, operating-system version, connection and diagnostic information | To connect equipment, maintain compatibility, diagnose faults, prevent abuse and secure the Services. |
| Support communications | Information you send to support, including export, deletion or assistance requests | To respond to you, verify requests and improve support. |
We do not sell personal data or use sensor, health or precise-location data for advertising or targeted advertising.
4. How and why we use personal data
We use personal data only where necessary to provide the Services: pairing compatible equipment; receiving and showing live measurements; starting and stopping sessions; retaining selected cloud sessions; creating session analytics, charts and insights; managing accounts and permissions; supporting authorised team workflows; maintaining security and reliability; and complying with law or protecting legal rights. We use aggregated or de-identified information for service improvement where reasonably possible.
We do not make decisions based solely on automated processing that produce legal effects or similarly significant effects on you.
5. Legal bases for processing (EEA/UK users)
Where the GDPR or similar law applies, we rely on the legal basis appropriate to the context:
- Performance of a contract for ordinary personal data needed to provide your account and requested Services.
- Explicit consent for health-related data and, where required, precise location data in connection with recording, uploading and analysing sessions. You may withdraw consent for future processing at any time; this does not affect prior lawful processing and may prevent the relevant feature from operating.
- Legitimate interests for security, fraud prevention, diagnostics, reliability and improvement, where those interests are not overridden by your rights and freedoms.
- Legal obligation where applicable law requires processing or retention.
Physiological data captured by the QUS Tech system may be health data or otherwise sensitive personal data. We process it with enhanced care and only for the purposes described here or in an applicable Organisation notice.
6. Permissions and your choices
The App may request permissions necessary for particular functions, including Bluetooth or nearby-device access to connect the OBU, location access to record location-based session data, NFC access for compatible temperature sensors, and device-storage access to select, export or manage session files. We request permissions only when a feature requires them.
You can decline or revoke a device permission through mobile-device settings. Functions depending on that permission may not work. Revoking a permission does not automatically delete data already received by the QUS Tech Data Platform.
You control whether an OBU session is uploaded to the cloud and whether live streaming is enabled. The App does not upload OBU session files merely because they have been created or because the OBU is paired, and it does not begin live streaming unless that option has been expressly enabled. You can stop live streaming at any time; this stops future transmission but does not automatically delete data already received by the QUS Tech Data Platform.
7. When we share personal data
We share personal data only as necessary:
- With you and users you authorise: uploaded session data is displayed in your App and, where applicable, through the QUS Tech Data Platform.
- With your Organisation: authorised Organisation users, such as designated coaches, analysts, managers or researchers, may access session data for purposes the Organisation has communicated to you. Access is role-based and is not public.
- With service providers: cloud-hosting, database, infrastructure, support and security providers process data only on our documented instructions and subject to confidentiality and security obligations. We may use European-hosted infrastructure, including Supabase services, and may change providers as the Services evolve.
- For legal, safety and corporate purposes: where required by law, to protect rights, security or property, or in connection with a merger, acquisition, financing, reorganisation or sale of assets.
We do not share personal data for third parties’ independent marketing purposes.
8. Organisation accounts: coaches, teams, employers and researchers
QUS Tech can be used by individuals as well as through Organisations. The privacy role depends on the relationship and the applicable agreement:
- For a directly provided QUS Tech account, QUS Tech GmbH generally acts as the controller for the processing described in this policy.
- Where an Organisation decides why data is collected, which people participate, who may access the data and how it will be used—for example, a coach analysing players’ sessions, an employer administering a safety programme, or a research institution conducting a study—that Organisation will generally be the controller for that processing. We generally act as its service provider/processor for the hosted platform.
The Organisation is responsible for giving you any required notice, identifying its legal basis, limiting access to authorised personnel and handling the broader use of your data. Please contact the Organisation first with questions about why it collects or accesses data, participation requirements, its retention period or how it uses analysis results. We will assist the Organisation with data-rights requests where required by law and our agreement.
For employment, workplace safety and research uses, the Organisation must ensure its use of the Services complies with applicable employment, health-and-safety, research-ethics and data-protection laws. In particular, an Organisation should not rely on consent where consent would not be freely given under applicable law.
9. International transfers
Personal data may be processed outside your country or, for EEA users, outside the European Economic Area (“EEA”) when we or a service provider use facilities or personnel there. Where a GDPR-restricted transfer occurs, we use an appropriate mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful safeguard, together with supplementary measures where required. Contact office@qus.tech for information about the relevant safeguard.
10. Security
We apply technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include access controls, role-based permissions, authentication, encryption in transit, security monitoring and processes intended to limit access to those with a legitimate need.
No electronic transmission, storage system or device is completely secure. Keep your account credentials and OBU secure, and contact us promptly if you believe your account or device has been compromised.
11. Retention, deletion and local OBU files
We retain cloud-account and session data until the relevant user or Organisation deletes it, requests deletion, or the account or customer relationship ends, unless longer retention is necessary to comply with law, resolve disputes, enforce agreements or protect security. Limited information may be retained for those purposes and will then be deleted or de-identified when no longer required. Backups are retained for a limited operational period and are not ordinarily used to restore data after a deletion request unless necessary for system recovery or legal reasons.
You may request deletion of your QUS Tech account and cloud data, export of your personal data, or correction of account information by emailing office@qus.tech. If an Organisation manages your account, its administrator may need to action or approve the request. Deleting cloud data does not delete an OBU session file or an exported copy; you control those local files.
12. Your privacy rights
Depending on your location and applicable law, you may have rights to access, correct, delete, restrict or object to processing; receive portable data; withdraw consent; and complain to a supervisory authority. To exercise a right, email office@qus.tech. We may need to verify your identity and, where an Organisation controls the relevant data, refer your request to it.
13. Children
The Services are not intended for use by children except where an Organisation has lawfully arranged access and provided any notice or obtained any consent required by applicable law. If you are responsible for a child who has provided personal data without the required authorisation, contact office@qus.tech.
14. Not medical advice or emergency monitoring
Unless expressly stated otherwise for a specific regulated product and intended use, the Services are not designed to diagnose, treat, cure, mitigate or prevent disease; are not a substitute for professional medical advice; and must not be relied on for emergency monitoring or emergency response. Seek qualified medical advice for health concerns and contact local emergency services in an emergency.
15. Changes to this policy
We may update this policy to reflect changes to the Services, legal requirements or our practices. We will post the updated policy with a revised effective date and, where required, provide additional notice or seek renewed consent.
16. Contact
QUS Tech GmbH
Stangersdorf-Gewerbegebiet 1, A-8403 Lebring, Austria
Email: office@qus.tech