Legal

Privacy Policy

Effective Date: May 5, 2026
Last Updated: May 5, 2026
Version: 1.0
This policy covers health-adjacent data
Stadiora Labs processes athlete performance and wellness data that may constitute health or biometric information under applicable law — including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other regional frameworks. We take this seriously. Relevant rights under each framework are set out in Section 9. This document has been prepared in good faith and should be reviewed by qualified legal counsel before enforcement. If you have questions, contact privacy@stadioralabs.com.

01 Who We Are

Stadiora Labs ("Stadiora Labs," "we," "us," or "our") is a sports AI infrastructure company incorporated and operating across Latin America (Costa Rica) and the United States. We build the Aria Intelligence engine and the products that run on top of it: Aria, Stadiora, Aria XI, and the Aria Intelligence API.

This Privacy Policy applies to all Stadiora Labs products, services, and websites, including stadioralabs.com, runwitharia.com, and any associated applications, unless a separate privacy notice is provided for a specific product.

For the purposes of the GDPR, Stadiora Labs acts as the data controller for personal data collected through our consumer products (Aria, Stadiora, Aria XI). Where we process data on behalf of third-party developers through the Aria Intelligence API, we act as a data processor under a separate data processing agreement with that developer.

02 What We Collect

Information You Provide Directly

  • Account information: name, email address, date of birth, sport, role (athlete or coach)
  • Profile information: team affiliation, competition level, training history
  • Athlete performance inputs: training sessions, perceived exertion ratings, wellness check-in responses
  • Communications: messages you send to us via email or support channels

Health & Performance Data You Submit

See Section 3 for full detail. This includes training load, recovery scores, sleep data, heart rate variability, injury history, mental readiness ratings, nutritional inputs, and cycle-aware context where provided.

Data From Third-Party Integrations

  • Wearable device exports (GPS units, heart rate monitors, recovery devices such as WHOOP or Oura) — only when you connect and authorise these integrations
  • Calendar or scheduling tools connected to your account

Automatically Collected Technical Data

  • IP address, browser type, operating system, device identifiers
  • Pages visited, session duration, feature interactions
  • Cookies and similar tracking technologies (see Section 10)
  • Crash reports and performance diagnostics

Coach-Entered Data

If you are an athlete whose coach uses Stadiora or Aria XI, your coach may enter data on your behalf — including training assignments, attendance, physical assessments, and observations. You are notified when an account is created for you under a coach's organisation.

03 Health & Performance Data

Stadiora Labs processes data that may be classified as special category data under the GDPR and sensitive personal information under the CCPA. This includes, but is not limited to:

  • Biometric indicators: heart rate, heart rate variability (HRV), sleep stages and duration
  • Physical health signals: injury history, pain ratings, movement quality assessments, return-to-play status
  • Mental and psychological readiness: stress ratings, mood check-ins, perceived fatigue
  • Reproductive health context: menstrual cycle data provided voluntarily through the cycle-aware context feature, used solely to contextualise readiness outputs
  • Nutritional data: hydration levels, dietary inputs provided voluntarily

We process this data only for the purpose of generating the readiness, availability, and decision outputs that you or your coach have requested. We do not sell, license, or share health-category data with advertisers, data brokers, or any third party for commercial purposes unrelated to delivering our services.

Reproductive health data is particularly sensitive. We process cycle data only where you have explicitly provided it and only for the specific readiness-contextualisation purpose. It is never surfaced to coaches without your affirmative consent and is excluded from all aggregated or anonymised analytics datasets.

Important: Stadiora Labs is not a medical device, healthcare provider, or clinical service. The outputs generated by Aria Intelligence are decision-support information, not medical advice or diagnosis. See the Terms of Use for a full medical disclaimer.

04 How We Use Your Data

To Deliver Our Services

  • Generate athlete readiness scores, availability classifications, and session recommendations
  • Provide coaches with squad-level readiness intelligence and attention queues
  • Maintain athlete longitudinal profiles (Player Passport / performance history)
  • Power the Aria Intelligence API decision engine for authorised developers

To Improve Our Products

  • Analyse aggregated, anonymised performance patterns to improve decision model accuracy
  • Conduct internal research into sport-science methodology — using only anonymised datasets
  • Diagnose technical issues and improve platform stability

To Communicate With You

  • Send transactional messages: account confirmations, password resets, session summaries
  • Send product updates and feature announcements — you may opt out at any time
  • Respond to support requests

To Comply With Legal Obligations

  • Respond to lawful requests from regulatory authorities
  • Maintain records as required by applicable law
  • Enforce our Terms of Use and protect against misuse

We do not use your personal data for automated individual decision-making that produces legal or similarly significant effects without human involvement. All Aria Intelligence outputs are intended to support — not replace — decisions made by coaches, athletes, and their medical teams.

05 Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, we rely on the following legal bases under Articles 6 and 9 of the GDPR:

Art. 6(1)(b)
Contract Performance
Processing necessary to deliver the services you have signed up for — including generating readiness outputs and maintaining your athlete profile.
Art. 6(1)(a) / Art. 9(2)(a)
Explicit Consent
Processing of special category health data (including reproductive health context and biometric indicators) — obtained separately and specifically at the point of collection. You may withdraw consent at any time without affecting service delivery for non-sensitive data.
Art. 6(1)(f)
Legitimate Interests
Processing for product improvement and security, where our interests do not override your fundamental rights. We conduct a legitimate interests assessment for each such use.
Art. 6(1)(c)
Legal Obligation
Processing required to comply with applicable laws, regulatory demands, or court orders.

06 Sharing Your Data

We do not sell your personal data. We share data only in the following circumstances:

With Your Coach or Organisation

If you are an athlete registered under a coach's Stadiora or Aria XI account, your readiness outputs, availability classifications, and flagged attention signals are visible to that coach. You acknowledge this when joining an organisation. Granular health signals (including reproductive health data) are not shared with coaches unless you explicitly configure them to be.

With Service Providers

We engage trusted third-party providers who process data on our behalf — including cloud infrastructure, data analytics, and communications services. These providers are bound by data processing agreements and are prohibited from using your data for their own purposes.

With API Developers

If your data is processed through the Aria Intelligence API by a third-party developer, that developer is the data controller for your relationship with their application. We act as processor. Review the privacy policy of the third-party application you are using.

For Legal Reasons

We may disclose data where required by law, to protect the rights or safety of Stadiora Labs or others, or in connection with legal proceedings.

In a Business Transfer

In the event of a merger, acquisition, or asset sale, personal data may be transferred to the acquiring entity. We will provide notice before your data becomes subject to a different privacy policy.

07 International Data Transfers

Stadiora Labs operates across Latin America (Costa Rica) and the United States, and may use service providers located in other countries. If you are located in the EEA or the UK, your personal data may be transferred to countries that do not have an adequacy decision from the European Commission.

Where such transfers occur, we rely on appropriate safeguards — including Standard Contractual Clauses (SCCs) approved by the European Commission — to ensure your data receives an equivalent level of protection. You may request a copy of the relevant safeguards by contacting us at privacy@stadioralabs.com.

For transfers of health-category data, we apply additional contractual protections and limit transfers to service providers that have demonstrated compliance with applicable data protection standards.

08 Data Retention

We retain your personal data only for as long as necessary to deliver our services and comply with legal obligations:

  • Active account data: Retained for the duration of your account, plus 30 days following account deletion (to allow recovery if deleted in error)
  • Athlete performance history: Retained for the duration of your account. Longitudinal data (Player Passport) is a core product feature; you may export or delete it at any time from your account settings
  • Health and biometric data: Retained for the duration of your active consent. Upon withdrawal of consent or account deletion, health-category data is deleted within 30 days
  • Reproductive health data: Deleted immediately upon account deletion or consent withdrawal, with no archival retention
  • Technical and log data: Retained for up to 12 months for security and diagnostic purposes
  • Anonymised and aggregated analytics: Retained indefinitely — this data cannot be used to identify you

09 Your Rights

Depending on your location, you have the following rights over your personal data:

GDPR
EU / EEA / UK Residents
Rights of access, rectification, erasure, restriction, portability, and objection. Right to withdraw consent at any time. Right to lodge a complaint with your national supervisory authority.
CCPA
California Residents
Right to know what personal information is collected and how it is used. Right to delete. Right to opt out of sale (we do not sell data). Right to non-discrimination for exercising your rights.
Health Data
All Users — Health & Biometric Data
Right to withdraw consent for health-category data processing at any time. Withdrawal does not affect the lawfulness of prior processing. Non-sensitive service features continue after withdrawal.

Your Rights in Detail

Access
Know what we hold
Request a copy of the personal data we hold about you, including health and performance data.
Rectification
Correct inaccuracies
Request correction of any inaccurate or incomplete personal data we hold.
Erasure
Right to be forgotten
Request deletion of your personal data. Anonymised and aggregated data is not subject to erasure requests.
Portability
Take your data with you
Receive your data in a structured, machine-readable format to transfer to another service.
Restriction
Limit our processing
Request that we restrict processing of your data while a dispute is resolved.
Objection
Object to processing
Object to processing based on legitimate interests, including profiling for analytics purposes.

To exercise any of these rights, contact us at privacy@stadioralabs.com. We will respond within 30 days (or within 45 days where the request is complex). We do not charge a fee for reasonable requests.

10 Cookies

We use cookies and similar tracking technologies on our websites. These fall into three categories:

  • Essential cookies: Required for the platform to function — session management, authentication, security. These cannot be disabled.
  • Analytics cookies: Used to understand how visitors interact with our websites — pages visited, session duration, feature usage. You may opt out through your browser settings or a cookie preference centre.
  • Preference cookies: Store your settings and preferences to improve your experience across sessions.

We do not use third-party advertising cookies or cross-site tracking. You can manage cookie preferences through your browser settings at any time. Note that disabling non-essential cookies does not affect your use of core platform features.

11 Children's Privacy

Our services are not directed at children under the age of 13 (or under 16 in the EEA). We do not knowingly collect personal data from children under these ages. If a coach registers an athlete who is a minor, the coach is responsible for obtaining appropriate parental or guardian consent before submitting that athlete's data to our platform.

If you believe we have collected data from a child without appropriate consent, contact us immediately at privacy@stadioralabs.com and we will delete the data promptly.

12 Security

We implement technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include encryption of data in transit and at rest, access controls limiting data access to authorised personnel, and regular security reviews.

Given the health-adjacent nature of some data we process, we apply enhanced security controls to health and biometric data stores — including additional encryption layers and strict internal access logging.

No system is completely secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities as required by applicable law — within 72 hours for GDPR-covered breaches.

13 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, products, or applicable law. When we make material changes, we will notify you by email (if you have an account) and update the "Last Updated" date at the top of this page.

Your continued use of our services after the effective date of a revised policy constitutes acceptance of the updated terms. If you do not agree with a material change, you may delete your account and request erasure of your data before the change takes effect.

14 Contact Us

For all privacy-related enquiries, rights requests, or concerns:

Stadiora Labs — Privacy

Email: privacy@stadioralabs.com

Response time: within 30 days for standard requests, 72 hours for breach notifications

If you are an EEA resident and are not satisfied with our response, you have the right to lodge a complaint with your national data protection supervisory authority.