P90RAPIDCUT
Back to home
Privacy Policy
Last updated: April 23, 2026
1. Data Controller
Controller: Dobromir Georgiev Todorov
Tax ID: X8353053M
Address: Palma de Mallorca, Balearic Islands, Spain
Email: info@p90rapidcut.com
Web: https://p90rapidcut.com
2. Data We Collect
Depending on your interaction with the website or the contracted service, we process the following data:
- Identification and Contact Data: Name, surname, email, and phone.
- Health and Biometric Data (Special Category): Weight, height, body measurements, photos or videos of physical state (for check-ins), sports history, injuries, and health habits.
- Financial Data: Information required for payment (securely managed by Stripe; we do not store your full card).
- Technical Data: IP address, cookies, and browsing data.
3. Purpose of Processing
We process your data for the following purposes:
- Service provision: Manage your registration, deliver training plans, and answer questions.
- Personalized tracking: Analyze your physical evolution through the data and photos/videos sent in check-ins.
- Administrative management: Invoicing, payments, and accounting.
- Communications: Send you reminders, plan updates, or operational information via email or WhatsApp.
- Service improvement: Optimize user experience and website security.
4. Legal Basis
The legal basis for processing your data is:
- Contract execution: For the identification and payment data required to formalize the subscription.
- Explicit Consent (Art. 9 GDPR): For processing your health data and progress photos/videos. By registering and checking the acceptance box, you expressly authorize the processing of this sensitive information for the sole purpose of sports tracking.
- Legitimate Interest: To ensure platform security and improve our internal processes.
- Legal Obligation: To comply with tax and accounting regulations.
5. Recipients and International Transfers
Your data is confidential and not shared with third parties, except by legal obligation. However, to provide the service, we use trusted technology providers:
- Stripe: Secure payment gateway (PCI DSS Level 1).
- Hostinger: Web hosting with servers in the European Union.
- WhatsApp (Meta): For agile communication and report delivery.
- SureCart: Subscription management and checkout.
- Nutrifight (IKEX): Equipment shop as affiliate partner. If you buy equipment from our Shop, we redirect you to their checkout and they act as the data controller for that purchase. P90RapidCut does not access your banking data or order details (see section 10).
International Transfers: By using global digital tools (such as WhatsApp), some data may be processed on servers outside the European Economic Area (mainly in the U.S.). We ensure that these providers offer adequate protection guarantees, such as adherence to the Data Privacy Framework (DPF) EU-U.S. or the use of Standard Contractual Clauses (SCC).
6. Data Retention
- Customer data: Will be kept while the contractual relationship is active. Once ended, they will remain blocked for the legally required periods (fiscal/commercial) to address potential liabilities (generally 5 years).
- Health data and check-ins (Photos/Videos): Will be kept only while your subscription is active to evaluate your progress. After cancellation, they will be deleted within a maximum of 30 days, unless there is a legal obligation to keep them.
7. User Rights
As the data subject, you have the right to:
- Access your data to know what we have.
- Rectify inaccurate data.
- Erase your data when no longer needed.
- Restrict or Object to its processing.
- Request Portability of your information.
- Withdraw consent given at any time (without affecting the legality of processing prior to its withdrawal).
To exercise any of these rights, send an email to: info@p90rapidcut.com with the subject "Data Protection". We will respond within a maximum of 30 days. If you believe your rights have not been respected, you have the right to file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
8. Security
P90RapidCut applies rigorous technical and organizational measures to guarantee the confidentiality, integrity, and security of information, protecting it against loss, misuse, or unauthorized access, with special care for the protection of sensitive health data. We use 256-bit SSL/TLS encryption across the platform, and payments are processed by Stripe with PCI DSS Level 1 certification.
9. Minors
The P90RapidCut service is intended for people over 16. We do not knowingly collect data from minors under that age. If you are under 16, you need the consent of your parent or legal guardian to use our services.
10. Equipment Shop — Data Processing at Nutrifight
P90RapidCut does not receive your payment data or store order information when you purchase equipment through our Shop. That purchase is fully managed by Nutrifight (IKEX) as data controller.
When you click «Checkout» from our Shop:
- P90RapidCut does not receive your address, phone, ID, purchase email, or banking data.
- Your data is processed by Nutrifight as the controller of that transaction, in accordance with their own privacy policy.
- The only data that travels between sites is the affiliate identifier (non-personal) and the discount coupon, needed to attribute the sale for commission purposes.
- To exercise your rights (access, rectification, erasure, portability) over the order data, you must contact Nutrifight directly.
Nutrifight's website and contact channels: nutrifightshop.com
