Privacy Policy for the Processing of Personal Data of the Dave Coach Service

Last updated: 23 May 2026

1. Preamble and Identification of the Data Controller

The present Privacy Policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter, the “GDPR”), and in compliance with the provisions of Legislative Decree no. 196 of 30 June 2003, as amended by Legislative Decree no. 101 of 10 August 2018 (hereinafter, the “Privacy Code”), to all persons who interact with the digital service known as “Dave Coach” (hereinafter, the “Service”), accessible through the website https://davecoach.app and the dedicated mobile application.

The Data Controller is RESET DI ZACCARIELLO DAVIDE EMANUELE, sole proprietorship with registered office at Via Selva no. 34, 51031 Agliana (PT), Italy, VAT number 02053300477 (hereinafter, the “Controller”). For any matter relating to the processing of personal data, the data subject may contact the Controller at the email address indicated on the contact page published on the official website, or may consult the constantly updated version of the present Privacy Policy at https://policy.davecoach.app.

No Data Protection Officer (DPO) has been appointed for the processing activities covered by the present Privacy Policy pursuant to Article 37 of the GDPR, as the statutory conditions requiring mandatory appointment do not currently apply. The Controller nevertheless reserves the right to make such appointment where it deems it appropriate in light of the development of its activities.

2. Categories of Personal Data Processed

The Controller processes different categories of personal data, collected directly from the data subject during registration, during use of the Service, or generated automatically by the information systems used. The main categories are set out below.

Account and Profile Data: Name, surname, email address, profile image (on an optional basis), preferred language, any account suspension status, and related reason. Authentication takes place exclusively by means of an OTP (one-time password) sent to the email address indicated by the data subject; accordingly, no password is requested or stored.

Technical and Session Data: Session token, session expiry, IP address, browser identifier (user agent), and information relating to any active organization or team.

Product Data: Chat messages, attachments, uploaded files, audio files, transcriptions, user preferences and memory, workspaces, organizations, invitations, and administrative roles.

Payment Data: Metadata relating to the customer, subscription, and payments, managed through the Stripe platform. The data subject is redirected to Stripe pages for the completion of payments and subscription management; no information relating to the payment method, IBAN, or card used is stored in the Controller’s database. Only the active or inactive status of the subscription is recorded internally.

Device Data (Mobile Application): Push token for notifications sent through Expo, platform used, application version, and device name.

Telemetry and Diagnostic Data: Events, logs, errors, performance indicators, and request identifiers; in the mobile environment, after authentication, such data may be associated with the user ID, email address, and name. Such data is subject to an automatic maximum retention period (TTL), as specified in the relevant section of the present Privacy Policy.

Data Derived from Conversations: Chats with related messages, attachments, estimated costs, generation statuses, and interaction logs. The system also produces technical summaries of conversations, including summarization prompts, generated output, number of tokens used, and associated costs.

3. Purposes of Processing and Legal Bases

Personal data is processed for the purposes set out below, each supported by a specific legal basis under Article 6 of the GDPR.

Provision of the Service: Account registration, OTP authentication, platform access, use of chat and digital coaching functions, and management of personal workspaces and organizations. The legal basis is the performance of a contract to which the data subject is party, pursuant to Article 6(1)(b) of the GDPR.

Management of Conversations and User Memory: Storage of chats, generation and retention of technical summaries, maintenance of session continuity, access to past conversations, and application of the coaching method underlying the Service. Such processing is likewise based on contractual performance, as it constitutes an essential component of product delivery.

Processing of Voice Messages and Transcriptions: Uploading of audio files to storage systems, automatic transcription, return of text to the AI assistant, and management of audio playback within the conversation thread. The processing is based on the performance of the contract, pursuant to Article 6(1)(b) of the GDPR.

Management of Payments and Subscriptions: Processing of payments, verification of subscription status, invoicing, and fulfilment of related tax and accounting obligations, pursuant to Article 6(1)(b) and Article 6(1)(c) of the GDPR, in accordance with Presidential Decree no. 633 of 26 October 1972 and Presidential Decree no. 600 of 29 September 1973.

Security of the Service and Diagnostic Activities: Collection of logs and telemetry, detection of anomalies, prevention of misuse, management of incidents, and restoration of operational continuity, on the basis of the Controller’s legitimate interest under Article 6(1)(f) of the GDPR, balanced against the fundamental rights and freedoms of the data subject following an appropriate balancing assessment.

Service Communications: Sending of messages necessary for management of the relationship, including communications concerning security, changes to terms, and account operation, within the framework of contractual performance.

Legal Compliance: Retention of documentation, response to requests from competent authorities, and management of disputes, pursuant to Article 6(1)(c) of the GDPR.

Establishment, Exercise, or Defence of Legal Claims: Processing that may be necessary to establish, exercise, or defend a right in legal proceedings, on the basis of the Controller’s legitimate interest under Article 6(1)(f) of the GDPR.

For the purposes indicated above, the provision of data requested during registration and subscription is necessary. Refusal to provide such data will make it impossible to access the Service or use the related functions.

4. Conversations, Generated Content, and Voice Messages

Given the nature of the Service, particular attention must be given to processing connected with conversations held with the AI assistant. Chats, including text messages, attachments, and audio files, are stored on the Controller’s systems in order to ensure continuity of the conversational relationship and maintenance of the interaction history. The system also produces technical summaries intended to support the assistant’s memory and contextualize future responses.

Conversations may contain personal, professional, and relational information relating to the data subject. The data subject is therefore invited to exercise caution when communicating particularly sensitive information and to assess the relevance and appropriateness of such information in relation to the nature of the Service. The Controller does not request the transmission of special categories of data pursuant to Article 9 of the GDPR, including, by way of example, data concerning health, sexual orientation, religious or philosophical beliefs, political opinions, genetic data, or biometric data. Where the data subject nevertheless decides to include such information, its disclosure shall constitute explicit consent to processing under Article 9(2)(a) of the GDPR, limited to the purposes of providing the Service.

Voice messages are uploaded to S3-compatible storage systems through pre-signed URLs. The server transcribes the audio file and stores the transcribed text within the conversation thread. The AI assistant processes the textual transcription, not the original audio file. Audio playback remains available in the thread, with access filtered through the backend, which verifies authorization and redirects the request to a temporary signed URL suitable for protecting the confidentiality of the content.

5. Processing Methods and Security Measures

Processing is carried out using electronic tools and organizational procedures aimed at ensuring the confidentiality, integrity, availability, and resilience of systems and services, in accordance with Article 32 of the GDPR. The technical and organizational measures adopted by the Controller include the following.

Passwordless Authentication: Access through an OTP sent to the email address, rather than through a traditional username-password combination.

Request Limitation: Rate-limiting systems designed to contain abnormal or repeated access attempts.

Access Controls: Segregation of privileges, management of administrative roles, and tracking of access to restricted areas.

Security Headers: Server configurations intended to mitigate known vulnerabilities of web applications.

Encryption at Rest: Protection of server volumes containing databases through LUKS (Linux Unified Key Setup) technology, suitable for protecting data confidentiality even in the event of unauthorized physical access.

Secrets Management: Secure custody of application credentials, tokens, and API keys.

Upload Controls: Checks on type, size, and integrity of files uploaded by users.

In accordance with the transparency principle under Article 5 of the GDPR, no digital system can be considered entirely free of risk. Without prejudice to its commitment to maintaining high security standards, the Controller shall not be liable for unauthorized access, malfunctions, vulnerabilities, or incidents arising from causes outside its control, including those attributable to third-party providers or external infrastructure, within the limits permitted by applicable law.

6. Use of Artificial Intelligence Systems and Third-Party Providers

For the provision of the Service, the Controller uses carefully selected third-party providers, appointed, where the conditions under Article 28 of the GDPR apply, as processors by means of specific Data Processing Agreements. The main parties involved are listed below.

OpenRouter: https://openrouter.ai is the platform used to process interactions through large language models (LLMs), generate responses, summaries, content analyses, and conversational memory. The Controller has activated on OpenRouter the configuration that allows requests to be routed exclusively to AI providers operating under a Zero Data Retention regime, under which the data transmitted is not stored by the provider and is not used to train models. Within the limits of such configuration, the data subject’s conversations do not contribute to artificial intelligence model training datasets.

Cartesia and ElevenLabs: These providers are used for Text-to-Speech and automatic Speech-to-Text functions. The Controller expressly informs data subjects that, at present, no Zero Data Retention agreements are in place with these providers; therefore, audio content transmitted to them may be stored in their systems in accordance with their respective policies. The Controller reserves the right to enter into Zero Data Retention agreements with voice providers in the future, within the framework of enterprise service plans.

Stripe: https://stripe.com is the payment processor, acting as an independent controller for purposes connected with payment data custody, fraud prevention, and compliance with regulatory obligations applicable to the financial sector. The conditions applied by Stripe may be consulted on the provider’s official website.

Resend: https://resend.com is the service used to send transactional email communications, including messages containing OTP authentication codes.

Self-Hosted Storage and Backup on Cloudflare R2: https://www.cloudflare.com. All attachments, including documents, audio files, PDF files, and DOCX files, are stored on self-hosted storage systems managed directly by the Controller. For operational continuity purposes, files are backed up on Cloudflare R2 infrastructure.

Expo Push Service: https://expo.dev is the service used to send push notifications to the mobile application.

The data subject is invited to consult the respective privacy policies published on the official websites of the providers indicated above, in order to obtain a complete understanding of how each party operates independently.

7. Disclosure, Dissemination, and Categories of Recipients

The personal data of the data subject may be accessed, as persons authorized to process data pursuant to Article 29 of the GDPR, by duly instructed internal personnel. Data may also be disclosed to the providers indicated in Article 6 above, appointed as processors where the legal conditions apply, and to the Controller’s external consultants in tax, accounting, legal, and information-security matters, solely for the performance of the services respectively entrusted to them. No dissemination of personal data to indefinite recipients is envisaged.

Data may also be disclosed to judicial, administrative, or supervisory authorities where required by law, by an order of the authority, or for the defence of the Controller’s rights in judicial or out-of-court proceedings.

8. Transfers of Personal Data Outside the European Union

Given the architecture of the Service and the location of certain providers in countries outside the European Economic Area, particularly the United States of America, processing may involve transfers of personal data to third countries. Such transfers take place in accordance with Chapter V of the GDPR, Articles 44 to 49, and are based, as applicable, on an adequacy decision adopted by the European Commission under Article 45 of the GDPR or, failing that, on the adoption of standard contractual clauses approved by the European Commission pursuant to Article 46(2)(c) of the GDPR.

For U.S. providers, where they hold the relevant certification, the transfer may also be based on participation in the EU-U.S. Data Privacy Framework, which was the subject of the adequacy decision adopted by the European Commission on 10 July 2023.

The data subject may request, by sending a specific communication to the Controller, a copy of the safeguards adopted or an indication of where they have been made available.

9. Retention Periods

Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected, in compliance with the storage limitation principle under Article 5(1)(e) of the GDPR.

Account data and conversation content are retained for the entire duration of the contractual relationship, given their function in providing the Service and ensuring continuity of interactions with the AI assistant. Following termination of the relationship, or upon a deletion request submitted by the data subject, data is deleted from the Controller’s operational systems; it may remain in system backups until their natural rotation, which takes place indicatively within thirty days.

Telemetry and diagnostic data are subject to an automatic retention period (TTL) of thirty days, also applied to the related backups, in view of their exclusively technical and diagnostic function.

Data relating to invoicing, accounting, and tax obligations is retained for the period required under applicable tax and civil law, and in particular for ten years pursuant to Article 2220 of the Italian Civil Code and the relevant provisions of Presidential Decree no. 633/1972.

Data that may be necessary for the defence of legal claims is retained for the duration of the limitation periods provided by applicable law, in accordance with Articles 2946 et seq. of the Italian Civil Code.

10. Automated Decision-Making and Profiling

Given the nature of the Service, the Outputs provided to the data subject are generated through algorithmic processing performed by generative artificial intelligence models. Such processing does not, in itself, constitute fully automated decision-making producing legal effects concerning the data subject or similarly significantly affecting the data subject pursuant to Article 22(1) of the GDPR. The Outputs are informational and intended to support reflection, while any subsequent decision-making process remains entirely under the responsibility of the data subject.

Consistently with Article 50 of Regulation (EU) 2024/1689, the AI Act, the Controller expressly informs data subjects that interactions take place with an artificial intelligence system and that generated content derives from algorithmic processing, without any cognitive, emotional, or clinical component inherent in a human relationship.

11. Rights of the Data Subject

The data subject may exercise, at any time, the rights recognized by Articles 15 to 22 of the GDPR. In particular, the data subject may request the following.

Right of Access: To obtain confirmation as to whether personal data concerning them is being processed, to access such data, and to obtain a copy pursuant to Article 15 of the GDPR.

Right to Rectification: To request correction of inaccurate data or completion of incomplete data, in accordance with Article 16 of the GDPR.

Right to Erasure: To obtain erasure of data in the cases provided by Article 17 of the GDPR, known as the “right to be forgotten,” without prejudice to retention obligations incumbent upon the Controller.

Right to Restriction of Processing: To request suspension of specific processing activities in the cases referred to in Article 18 of the GDPR.

Right to Data Portability: To receive the data provided in a structured, commonly used, and machine-readable format pursuant to Article 20 of the GDPR, or to obtain direct transmission to another controller, where technically feasible.

Right to Object: To object, on grounds relating to the data subject’s particular situation, to processing based on the Controller’s legitimate interest, pursuant to Article 21 of the GDPR.

Right Not to Be Subject to Automated Decisions: To avoid being subject to decisions based solely on automated processing that produce legal effects or significantly affect the data subject, pursuant to Article 22 of the GDPR.

Right to Withdraw Consent: To withdraw any consent given at any time, without affecting the lawfulness of processing carried out before withdrawal, pursuant to Article 7(3) of the GDPR.

12. Methods for Exercising Rights and Complaint to the Authority

To exercise their rights, the data subject may send a written request to the email address indicated on the contact page of the official website, attaching suitable documentation useful to verify their identity. The Controller shall respond to the request within one month of receipt, in accordance with Article 12 of the GDPR; such period may be extended by a further two months in cases of particular complexity.

The data subject’s right to lodge a complaint with the competent supervisory authority remains unaffected, pursuant to Article 77 of the GDPR. In Italy, the supervisory authority is the Garante per la protezione dei dati personali, with registered office at Piazza Venezia no. 11, 00187 Rome, website https://www.garanteprivacy.it. The data subject also has the right to bring proceedings before the ordinary courts, pursuant to Articles 78 and 79 of the GDPR and Article 152 of the Privacy Code.

13. Processing of Minors’ Data

The Service is not intended for persons below the age established by the Controller in its access conditions. Where, during an operational transition phase, no age limit has been set during registration, use is reserved to adults. Otherwise, consent to the processing of data relating to a minor under the age of fourteen, pursuant to Article 8 of the GDPR and Article 2-quinquies of the Privacy Code, must be given by the person exercising parental responsibility. The Controller shall adopt every reasonable measure to verify the age of data subjects and reserves the right to suspend the account in the event of an established breach of such requirements.

14. Amendments to the Privacy Policy

The present Privacy Policy may be updated as a result of regulatory developments, changes to the Service or to the Controller’s organization, or clarification needs. Updated versions shall be published at https://policy.davecoach.app, indicating the date of the last update. The data subject is responsible for periodically consulting the page in order to verify any changes.

15. Contacts

For any request concerning the present Privacy Policy, the exercise of rights, or further clarification regarding personal data protection, the data subject may contact:

RESET DI ZACCARIELLO DAVIDE EMANUELE
Via Selva no. 34, 51031 Agliana (PT), Italy
VAT number: 02053300477
Website: 
https://davecoach.app
Terms and Conditions: 
https://terms.davecoach.app
Privacy Policy: 
https://policy.davecoach.app.