...
ENG ENG
RU RU

Privacy and Personal Data Processing Policy

Effective Date: July 15, 2026
 

1. General Provisions

1.1. This Privacy Policy (the “Policy”) governs the processing of personal data of users of the LEKO service. This Policy applies to the mobile application, website, application programming interfaces, and other features of the service, collectively referred to as the “Platform”.

1.2. The Platform is provided by Deggex FZE. Deggex FZE is also the User’s contractual counterparty and the controller of personal data processed for the purposes of user identification, identity verification, document verification, sanctions screening, fraud prevention, and other mandatory compliance procedures.

1.3. Full name and details of the Operator: Deggex FZE, registered at THUB Building, Dubai Silicon Oasis, Dubai, United Arab Emirates, license number 30380.  LEKO is a service provided by Deggex FZE.

1.4. For the purposes of this Policy, Deggex FZE is referred to as the “Operator”, “Controller”, “we”, “us”, or “our”. A user of the Platform is referred to as the “User”, “you”, or “your”.

1.5. This Policy applies in all countries where the Platform is available, used, offered to users, or otherwise processes personal data. This Policy takes into account the mandatory legal requirements of the countries in which the service operates, including the United Arab Emirates, the Russian Federation, the Federative Republic of Brazil, the Kingdom of Thailand, and, where applicable, the European Union and the European Economic Area under the General Data Protection Regulation – Regulation (EU) 2016/679.

1.6. This Policy takes into account, among other laws, Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data in the United Arab Emirates, Federal Law of the Russian Federation No. 152-FZ “On Personal Data”, Law No. 13,709 of August 14, 2018, in Brazil, the Personal Data Protection Act B.E. 2562 (2019) in the Kingdom of Thailand, and Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR). If another mandatory personal data law applies in a particular country, such mandatory law shall also apply to the extent it applies to the Operator or to the relevant processing.

1.7. If the law of a particular country provides the User with a higher level of protection than this Policy, that higher level of protection shall apply. If any provision of this Policy cannot be applied in a particular jurisdiction, that provision shall apply to the maximum extent permitted by law, and the remaining provisions of this Policy shall remain in effect.

1.8. By using the Platform, creating an account, submitting data to us, undergoing identity verification, paying for services, receiving services, providing services, submitting requests, or continuing to use the Platform after this Policy has been published, the User confirms that they have read this Policy. Where applicable law requires consent, such consent will be requested separately or expressed through an affirmative action by the User, including ticking a box, clicking a button, signing a form, or using the relevant Platform feature.

1.9. If the User does not agree with this Policy or does not wish to provide the data necessary for the operation of the Platform, the User must stop using the Platform. In such case, certain Platform features may be unavailable.

2. Terms and Definitions

2.1. “Personal Data” means any information relating to an identified or identifiable natural person, whether directly or indirectly. Personal Data may include name, contact details, documents, photographs, videos, payment data, device data, location data, identifiers, account data, messages, identity verification data, and other information that may be linked to a specific person.

2.2. “Personal Data Subject” means the natural person to whom the Personal Data relates.

2.3. “User” means any person who visits the Platform, registers on the Platform, uses the Platform, contacts support, undergoes identity verification, receives services, provides services, or otherwise interacts with the Operator in connection with the Platform.

2.4. “Processing of Personal Data” means any operation performed on Personal Data. Processing includes collection, recording, organization, accumulation, storage, clarification, updating, modification, retrieval, use, transfer, provision of access, disclosure, dissemination, cross-border transfer, anonymization, blocking, restriction of processing, deletion, and destruction of Personal Data.

2.5. “Controller” or “Operator” means the person that determines the purposes and means of processing Personal Data. For the purposes of this Policy, Deggex FZE is the Controller, unless otherwise expressly provided by a specific Platform feature, applicable law, or an agreement with a third party.

2.6. “Processor” means a person that processes Personal Data on behalf of the Controller and in accordance with the Controller’s instructions. Processors may include cloud infrastructure providers, payment providers, identity verification providers, analytics services, support services, marketing platforms, and other contractors.

2.7. “Special Categories of Personal Data” or “Sensitive Data” means data that requires enhanced protection under applicable law. Such data may include biometric data, health data, data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, intimate life, genetic data, data of minors, and other data recognized as sensitive under applicable law.

2.8. “Biometric Datameans personal data relating to the physical, physiological, or behavioral characteristics of a natural person that is used, or is capable of being used, to identify that person. Photographs, videos, selfies, facial images, liveness check data, and data relating to the matching of a facial image with a document shall not be deemed Biometric Data unless they are used to identify or verify the identity of a specific person as a unique identifier, except where applicable law provides otherwise.

2.9. “Anonymized Data” means data that does not allow a specific User to be identified without the use of additional information.

2.10. “Cross-Border Transfer of Personal Data” means the transfer of Personal Data to another country or the provision of access to Personal Data from another country, where such operation is recognized as a cross-border transfer under applicable law.

2.11. “Competent Authority” means a government authority, court, regulator, law enforcement authority, tax authority, migration authority, financial monitoring authority, personal data protection authority, or any other authority that has lawful powers to issue requests, conduct inspections, or require disclosure of information.

3. Operator Contacts

3.1. For matters relating to the processing of Personal Data, the exercise of rights, withdrawal of consent, deletion of data, restriction of processing, filing a complaint, or obtaining information about this Policy, the User may contact the Operator by email at support@leko.sport.

3.2. For matters relating to technical support, account access, correction of profile data, operation of the Platform, or user inquiries, the User may also contact the Operator through the Platform interface or by email at support@leko.sport.

3.3. If applicable law requires the appointment of a representative, responsible person, local contact person, or data protection officer in a particular jurisdiction, the Operator shall make such appointment or provide another legally permitted communication mechanism to the extent required by law.

4. Categories of Personal Data

4.1. The Operator may process data provided by the User, data generated when the User uses the Platform, data received from third parties, and data necessary to comply with the law, perform a contract, ensure the security of the Platform, and protect the Operator’s rights.

4.2. The Operator may process the User’s first name, last name, patronymic, alias, account name, date of birth, age, gender, email address, phone number, country, city, residential address, registered address, actual location, and other contact or identifying information.

4.3. The Operator may process photographs, videos, selfies, facial images, and other data used to prevent fraud and ensure the security of the Platform.

4.4. The Operator may process bank details, payment identifiers, payment instrument data, and information on transactions, payments, refunds, accruals, payouts, fees, debts, and other financial operations.

4.5. The Operator may process data on education, qualifications, certificates, courses, training sessions, seminars, sports activities, types of sports, training schedules, training locations, and other information that the User provides in the profile or uses within Platform features.

4.6. The Operator may process messages, inquiries, complaints, reviews, comments, support requests, dispute materials, and other communications between the User and the Operator or between the User and other Platform users.

4.7. The Operator may process technical data. Such data includes IP address, cookies, pixels, web beacons, device identifiers, advertising identifiers, information about the browser, operating system, device model, language, time zone, network, telecommunications operator, date and time of login, session duration, actions in the interface, errors, failures, and other Platform events.

4.8. The Operator may process device geolocation data if the User has granted access to such data or if such data is necessary for the operation of the relevant Platform feature.

4.9. The Operator may process security data. Such data includes access logs, authentication data, password hashes, tokens, information about suspicious activity, two-factor authentication data, and other data necessary to protect the Platform.

4.10. The Operator collects only strictly defined health and fitness metrics from Apple Health/HealthKit and Google Health Connect with the User’s prior permission, specifically: step count, heart rate, and sleep duration. This information is used solely to visualize the User’s workout history within the Platform interface and to adapt physical activity plans directly for the User’s benefit, fitness level, condition, and goals. These metrics are not collected for hidden analytics, abstract performance improvement purposes, advertising, marketing, retargeting, behavioral profiling, or use-based data mining.

4.11. The Operator may process data relating to marketing preferences, subscriptions, opt-outs from mailings, consents, and the history of interactions with messages and advertising offers.

4.12. The Operator does not seek to collect excessive data. The Operator processes data only to the extent reasonably necessary for the specific purposes of processing, the operation of the Platform, performance of a contract, compliance with the law, and protection of the Operator’s rights.

4.13. The User must provide true, accurate, and up-to-date data. If the User provides data relating to a third party, the User confirms that they have the right to transfer such data to the Operator and that such third party has been notified of the transfer, where required by applicable law.

5. Sources of Data

5.1. The Operator receives Personal Data directly from the User during registration, profile completion, use of the Platform, submission of requests, or use of other Platform features.

5.2. The Operator receives certain data automatically when the Platform is used. Such data includes technical data, device data, Platform usage data, cookies, event logs, and security data.

5.3. The Operator may receive data from other Platform users if such users interact with the User, send messages, leave reviews, create requests, participate in a dispute, or use Platform features in which information about the User is indicated.

5.4. The Operator may receive data from government, judicial, public, sanctions, tax, migration, corporate, professional, and other registers, where such receipt is permitted under applicable law.

5.5. If data is not obtained directly from the User, the Operator provides the User with information about the processing to the extent and within the time limits required by applicable law, where such notice is required and no lawful exception applies.

6. Purposes of Data Processing

6.1. The Operator processes Personal Data for the following purposes:

  • registering the User, creating an account, providing access to the Platform, and ensuring the operation of Platform features;
  • entering into, performing, amending, and terminating the user agreement, other agreements, service rules, payment terms, terms of service, and other documents governing the use of the Platform;
  • arranging interactions between users, placing orders, providing services, receiving services, communicating, resolving disputes, processing reviews, and performing other Platform functions;
  • visualizing the User’s training and workout history within the Platform interface, displaying the dynamics of the User’s physical activity, and adapting physical activity plans directly for the User’s benefit, level, condition, and goals, including where the User has permitted the Platform to read step count, heart rate, and sleep duration from Apple HealthKit or Google Health Connect.
  • ensuring the security of the Platform, preventing unauthorized access, identifying technical failures, investigating suspicious activity, preventing violations, protecting accounts, and protecting data;
  • reviewing the User’s inquiries, requests, complaints, claims, disputes, and messages;
  • improving the Platform, developing new features, conducting analytics and testing, correcting errors, improving service quality, and personalizing the user experience, provided that Apple HealthKit data, Google Health Connect data are not used for advertising, marketing, retargeting, behavioral profiling, use-based data mining, or purposes unrelated to the permitted health or fitness functionality described in this Policy.
  • sending service, technical, legal, operational, and other mandatory notices;
  • sending marketing messages, advertising offers, personalized offers, event invitations, and product information, where such processing is permitted by law and where consent has been obtained when required, provided that Apple HealthKit data, Google Health Connect data are not used for such marketing purposes;
  • complying with legal requirements, court orders, requests from competent authorities, regulatory requirements, and mandatory procedures;
  • protecting the rights, legitimate interests, property, security, and business reputation of the Operator, users, partners, and third parties.

7. Legal Bases for Processing

7.1. The Operator processes Personal Data only where there is a legal basis provided by applicable law.

7.2. The legal basis for processing may be the User’s consent. If processing is based on consent, the User has the right to withdraw consent in the manner provided by this Policy and applicable law.

7.3. The legal basis for processing may be the necessity to enter into, perform, or terminate a contract with the User. Such processing may be necessary for registration, provision of the Platform, payment processing, arrangement of services, and performance of obligations to the User.

7.4. The legal basis for processing may be the legitimate interest of the Operator or a third party. Such interest may include ensuring the security of the Platform, preventing fraud, protecting rights, improving the service, internal control, resolving disputes, and defending against claims. The Operator relies on this basis only to the extent that the rights and freedoms of the User do not override such interest under applicable law.

7.5. The legal basis for processing may be the protection of the vital interests of the User or another person, where processing is necessary to prevent harm to life, health, or safety.

7.6. The legal basis for processing may be the necessity to establish, exercise, or defend legal claims.

7.7. The legal basis for processing may be the performance of a task carried out in the public interest, compliance with a court order, compliance with a lawful request from a competent authority, or another basis provided by applicable law.

7.8. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Withdrawal of consent also does not prevent further processing if the Operator has another lawful basis for such processing.

8. Identity Verification

8.1. The Operator may conduct anti-fraud checks and other compliance procedures. Such checks are carried out to verify the User’s identity, prevent fraud, protect the Platform, and reduce legal risks.

9. Sensitive and Biometric Data

9.1. Except for the limited Apple HealthKit and Google Health Connect metrics expressly described in this Policy and processed only with the User’s permission, the Operator does not process Sensitive Data or Biometric Data.

9.2. If the Operator processes Sensitive Data, such processing is carried out only where there is an appropriate legal basis and only to the minimum extent necessary.

9.3. If applicable law requires separate, explicit, or written consent to the processing of Sensitive Data or Biometric Data, the Operator requests such consent unless another legally permitted basis applies.

9.4. The Operator does not use Sensitive Data or Biometric Data for unlawful discrimination, unjustified restriction of the User’s rights, or purposes incompatible with this Policy.

9.5. Personal data obtained from Apple HealthKit and Google Health Connect frameworks will never, under any circumstances or in any form, be sold, leased, or transferred to commercial organizations, advertising brokers.

9.6. The Platform’s use of information received from Google Health Connect will strictly comply with the Health Connect Permissions Policy, including the Limited Use Requirements.

9.7. The Operator shall ensure that a current link to this Policy is included in the Platform’s App Store Connect and Google Play metadata where required by Apple or Google and that this Policy is easily accessible within the Platform, including before or at the time the User is asked to grant access to Apple HealthKit or Google Health Connect data.

9.8. The Platform requests access to Apple HealthKit or Google Health Connect data only through Apple’s or Google’s permission mechanisms and only for the health and fitness data types expressly stated in this Policy: step count, heart rate, and sleep duration. The Platform does not collect Apple HealthKit or Google Health Connect data unless the User grants permission.

9.9. Apple HealthKit and  Google Health Connect data is used only to visualize workout history within the Platform interface and to adapt physical activity plans directly for the User’s benefit. The Operator does not use Apple HealthKit  or Google Health Connect data for advertising, marketing, retargeting, creation of behavioral or marketing profiles, use-based data mining, or other purposes not directly related to providing health or fitness functionality to the User.

9.10. The Operator does not disclose Apple HealthKit or Google Health Connect data to third parties without the User’s express permission. Even where the User grants such permission, the Operator discloses Apple HealthKit or Google Health Connect data only to third parties that provide a health or fitness service directly to the User, to service providers acting on the Operator’s behalf under confidentiality and data protection obligations for the permitted health or fitness functionality, or where disclosure is otherwise required by law.

9.11. The Platform will not write false, inaccurate, misleading, or fabricated data into Apple HealthKit or Google Health Connect.

10. Data of Minors

10.1. The Platform is not intended for use by persons who have not reached the age required to independently enter into a contract and give consent to the processing of personal data in the relevant country, unless otherwise expressly provided by the Platform rules.

11. Cookies and Similar Technologies

11.1. The Operator may use cookies, SDKs, pixels, web beacons, local storage, device identifiers, and similar technologies. These technologies are used for the operation of the Platform, authentication, saving settings, ensuring security, preventing fraud, analytics, service improvement, measuring advertising effectiveness, content personalization, and marketing.

11.2. Cookies are small files or data fragments that are stored on the User’s device or read from it when the User uses the Platform. Essential cookies are used for the operation of the Platform and cannot be disabled without affecting its functionality. Optional analytics, advertising, or marketing technologies are used where there is a legal basis, including consent where required by applicable law.

12. Marketing Messages

12.1. The Operator may send the User service, technical, legal, operational, and other mandatory messages without separate marketing consent if such messages are necessary for the operation of the Platform, performance of a contract, security, notification of changes, or compliance with the law.

12.2. The Operator may send marketing messages, advertising communications, personalized offers, and information about events only where there is a legal basis. If applicable law requires consent, the Operator sends such messages only after obtaining the User’s consent.

12.3. The User has the right to opt out of marketing messages at any time.

12.4. It is strictly prohibited to use Apple HealthKit data, Google Health Connect data for advertising, marketing, advertising targeting, retargeting, behavioral profiling, use-based data mining, or the creation of behavioral or marketing profiles.

13. Automated Processing

13.1. The Operator may use automated processing for registration, fraud prevention, security, interface personalization, analytics, detection of violations, and improvement of the Platform.

13.2. Automated processing means data processing using software tools without continuous human involvement in each individual operation.

13.3. The Operator does not make decisions based solely on automated processing where such decisions produce legal effects for the User or similarly significantly affect the User’s rights, unless the Operator complies with the requirements of applicable law.

13.4. If applicable law grants the User the right to request review of an automated decision, express their position, or challenge the decision, the Operator provides such opportunity in the manner prescribed by law.

13.5.  Where required by applicable law, the User has the right to request information about the criteria and procedures used for decisions based solely on automated processing of personal data that affect the User’s interests. The Operator shall provide such information to the extent and in the manner required by applicable law, subject to trade secrets, confidential information, Platform security considerations, and other lawful restrictions.

14. Transfer of Data to Third Parties

14.1. The Operator may transfer Personal Data to third parties if such transfer is necessary for the operation of the Platform, performance of a contract, compliance with the law, protection of rights, or other purposes specified in this Policy.

14.2. The Operator may transfer data to affiliates, group companies, cloud infrastructure providers, hosting providers, payment systems, banks, financial institutions, and other service providers.

14.3. The Operator may transfer data to other Platform users to the extent necessary for the operation of the relevant feature, placing an order, providing a service, receiving a service, communication, dispute resolution, or performance of a contract between users.

14.4. The Operator requires Processors to maintain confidentiality and security and to process Personal Data only within the scope of the contract, mandate, the Operator’s instructions, and applicable law.

15. Disclosure of Data to Government Authorities

15.1. The Operator may disclose Personal Data to competent authorities if such disclosure is required by law, a court order, a mandatory request, instruction, resolution, regulatory procedure, or other lawful requirement.

15.2. The Operator may also disclose data to competent authorities if this is necessary to prevent, detect, or investigate fraud, money laundering, terrorist financing, sanctions violations, tax violations, illegal activity, security breaches, or other offences.

15.3. The Operator may disclose data if this is necessary to protect the rights, legitimate interests, property, security, and business reputation of the Operator, users, partners, or third parties.

16. Cross-Border Transfer of Data

16.1. The Platform is an international service. Therefore, Personal Data may be transferred, stored, processed, or made accessible in different countries.

16.2. The Operator carries out Cross-Border Transfers of Personal Data only where there is a legal basis and in compliance with applicable requirements. Depending on the jurisdiction, such basis may include performance of a contract, the User’s consent, compliance with the law, protection of rights, the existence of an adequate level of protection, contractual safeguards, standard contractual clauses, corporate rules, the need to bring or defend legal claims, or another mechanism provided by applicable law.

16.3. Cross-Border Transfers are carried out only to the extent necessary to achieve lawful, specific, and defined processing purposes.

17. Special Provisions for the Russian Federation

17.1. If the processing of Personal Data falls within the scope of the laws of the Russian Federation, the Operator complies with Federal Law No. 152-FZ “On Personal Data” and other applicable regulations.

17.2. When collecting Personal Data of citizens of the Russian Federation via the Internet, the Operator complies with the requirements for recording, organizing, accumulating, storing, updating, and retrieving such data using databases located in the Russian Federation, to the extent such requirements apply to the Operator and to the specific processing operation.

17.3. Further processing of data, including Cross-Border Transfer, may be carried out where there is a legal basis and in compliance with the applicable requirements of the laws of the Russian Federation.

17.4. A User to whom the laws of the Russian Federation apply has the right to receive information about the processing of their Personal Data, request clarification, blocking, or destruction of incomplete, outdated, inaccurate, unlawfully obtained, or unnecessary data, withdraw consent, request cessation of processing or dissemination of data in cases provided by law, and challenge the actions or omissions of the Operator before the authorized authority or a court.

17.5. Withdrawal of consent does not prevent further processing if such processing is necessary for the performance of a contract, compliance with the law, enforcement of a court order, protection of the Operator’s rights, or another basis provided by the laws of the Russian Federation.

18. Special Provisions for the United Arab Emirates

18.1. If the processing of Personal Data falls within the scope of the laws of the United Arab Emirates, the Operator complies with Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data and other applicable acts.

18.2. The Operator ensures the lawfulness, transparency, confidentiality, security, minimization, accuracy, purpose limitation, and storage limitation of Personal Data to the extent such requirements apply.

18.3. A User to whom the laws of the United Arab Emirates apply may have the right to receive information about processing, access data, correct data, delete data, restrict processing, data portability, object to processing, withdraw consent, and contact a competent authority.

18.4. The Operator may process Personal Data without separate consent where such processing is necessary or permitted by applicable law. Such cases may include performance of a contract, compliance with the law, protection of rights, performance of legal procedures, protection of the public interest, or other grounds provided by law.

18.5. In the event of a security incident, the Operator assesses the risk and notifies competent authorities or data subjects in the cases and within the time limits required by applicable law.

19. Special Provisions for Brazil

19.1. If the processing of Personal Data falls within the scope of the laws of the Federative Republic of Brazil, the Operator complies with the Lei Geral de Proteção de Dados Pessoais, Law No. 13,709 of August 14, 2018, and applicable regulations of the Autoridade Nacional de Proteção de Dados.

19.2. A User to whom the laws of the Federative Republic of Brazil apply has the right to obtain confirmation of the existence of processing, access the data, correct incomplete, inaccurate, or outdated data, request anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data, request data portability, obtain information about data recipients, obtain information about the possibility of refusing consent and the consequences of such refusal, withdraw consent, request review of decisions made solely on the basis of automated processing, and lodge a complaint with the authorized authority.

19.3. International transfers of Personal Data from Brazil are carried out only where there is a permissible transfer mechanism.

19.4. The Operator designates a contact person for data protection matters and ensures that requests can be submitted through the contacts specified in this Policy.

20. Special Provisions for the Kingdom of Thailand

20.1. If the processing of Personal Data falls within the scope of the laws of Thailand, the Operator complies with the Thailand Personal Data Protection Act B.E. 2562 (2019) and other applicable acts.

20.2. The Operator provides the User with a notice on the collection and processing of Personal Data before or at the time of data collection, where required by applicable law.

20.3. The Operator processes Personal Data on the basis of consent, contract, legal obligation, legitimate interest, vital interests, public interest, or another lawful basis.

20.4. A User to whom the laws of Thailand apply may have the right to withdraw consent, access data, obtain a copy of the data, request data portability, object to processing, request deletion, destruction, or anonymization of data, request restriction of processing, request correction of data, and lodge a complaint with a competent authority.

20.5. Cross-Border Transfer of Personal Data from Thailand is carried out where there is adequate protection in the recipient country, an applicable exception, the User’s consent, contractual safeguards, binding corporate rules, or another mechanism recognized by applicable law.

21. Special Provisions for the European Union

21.1. If a User is located in the European Union or if the processing of personal data is subject to the General Data Protection Regulation (GDPR), the User has the rights provided under the GDPR and applicable European Union law, including the right to request access to personal data, receive information about the processing, obtain a copy of personal data, export personal data and receive it in a structured, commonly used and machine-readable format for transmission to another controller, request restriction of processing, and require the complete, irreversible and final deletion of personal data where such deletion is required or permitted by applicable law. The Operator shall handle such requests in the manner and within the time limits provided by the GDPR, subject to lawful exceptions, including where further processing or retention is necessary to comply with a legal obligation, perform a contract, establish, exercise or defend legal claims, prevent fraud, ensure the security of the Platform or carry out mandatory compliance procedures.

22. Special Provisions for the United States of America

22.1. If a User is a California resident or if the processing of personal data is subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), the User has the rights provided under the CCPA/CPRA and other applicable United States or California law, including the right to request information about the categories of personal data collected, the categories of sources of such data, the purposes for collecting, using, disclosing, selling or sharing personal data, the categories of third parties to whom personal data is disclosed, and the right to request deletion of personal data in the cases provided by applicable law. A California resident also has the unconditional right at any time to opt out of the sale or sharing of personal data. The Operator shall not discriminate against a User for exercising rights under the CCPA/CPRA, except as permitted by applicable law.

23. Data Retention Periods

23.1. The Operator stores Personal Data for no longer than is necessary to achieve the purposes of processing, unless a longer retention period is required or permitted by applicable law. Apple HealthKit data and Google Health Connect data are retained only for as long as necessary to provide the permitted health or fitness functionality directly to the User, to comply with applicable law, to ensure Platform security, or to establish, exercise, or defend legal claims.

23.2. After the applicable retention period expires, or after the User validly revokes consent or requests deletion where deletion is required or permitted by applicable law, the Operator deletes, destroys, anonymizes, or archives Personal Data in accordance with applicable law and internal procedures. Revocation of Apple HealthKit or or Google Health Connect permissions stops future collection from Apple HealthKit or or Google Health Connect; the User may separately request deletion of data already collected by contacting support@leko.sport.

24. Data Security

24.1. The Operator takes legal, organizational, and technical measures to protect Personal Data against unauthorized, unlawful, or accidental access, destruction, loss, alteration, blocking, copying, disclosure, dissemination, use, and other unlawful actions.

24.2. Such measures may include access control, authentication, account management, encryption, pseudonymization, logging, monitoring, backup, network protection, restriction of access by employees and contractors, contractual confidentiality obligations, vendor due diligence, staff training, internal policies, incident response, and regular assessment of security measures.

24.3. The User must observe reasonable security measures. The User must use a strong password, not disclose login credentials to third parties, keep the device and software updated, log out of the account on public devices, and immediately notify the Operator of any suspected unauthorized access.

24.4. Users’ personal data is protected through organizational and technical security measures designed to prevent unauthorized access, loss, alteration, disclosure, copying, dissemination, or other unlawful use of the data. The transfer of personal data is carried out using secure connections, including HTTPS/TLS protocols. Personal data stored on the Operator’s servers is encrypted using modern cryptographic standards, including AES-256, where applicable to the relevant type of data and storage infrastructure. In developing, operating, and maintaining the Platform, the Operator takes into account leading mobile application security practices, including the OWASP MASVS recommendations.

25. Security Incidents

25.1. If the Operator identifies a security incident affecting Personal Data, the Operator takes reasonable measures to assess, contain, remediate, and minimize the consequences of such incident. If applicable law requires notification of a competent authority or the User, the Operator sends such notification in the manner and within the time limits required by law.

26. User Rights

26.1. Depending on applicable law, the User may have the right to obtain information about the processing of Personal Data, access data, obtain a copy of the data, correct inaccurate or incomplete data, delete data, restrict processing, object to processing, exercise data portability rights, withdraw consent, stop dissemination of data, request anonymization, blocking, or destruction of data, request review of an automated decision, and lodge a complaint with a competent authority.

26.2. To exercise their rights, the User may submit a request to support@leko.sport.

26.3. The Operator reviews User requests within the time limits established by applicable law. If no time limit is established by law, the Operator reviews the request within a reasonable period.

26.4. To stop the collection of data from Apple HealthKit and Google Health Connect, the User may disable the relevant permissions at any time in the smartphone’s system settings (under “Privacy” → “Health” on iOS, or in the “Health Connect” app settings on Android). To fully and irreversibly delete all previously collected medical data, the User may submit a request by email to support@leko.sport.

27. Updating and Accuracy of Data

27.1. The User must keep their Personal Data up to date and accurate.

27.2. The User may update some data independently in their personal account or submit a request through support.

28. Account Deletion

28.1. The User may request deletion of their account through the Platform features or by contacting the Operator.

29. Anonymized and Aggregated Data

29.1. The Operator may create, use, store, and disclose anonymized, aggregated, statistical, or analytical data if such data does not allow the User to be identified. Such data may be used for analytics, Platform development, reporting, research, marketing, security, improvement of service quality, commercial purposes, and other lawful purposes. Apple HealthKit data, Google Health Connect data are not used, even in aggregated or derived form, for advertising, marketing, retargeting, behavioral profiling, use-based data mining, or sale to advertising platforms, data brokers, or information resellers.

30. Third-Party Services

30.1. The Platform may contain links, integrations, or redirects to third-party websites, applications, payment services, social networks, maps, messengers, analytics services, and other services.

30.2. If such third parties act as independent controllers, the Operator does not control their processing of Personal Data and is not responsible for their policies, actions, or omissions, unless otherwise provided by mandatory law.

30.3. The User should review the privacy policies of the relevant third parties before using their services.

31. Changes to the Policy

31.1. The Operator may amend this Policy at any time if this is necessary due to changes in the Platform, legislation, business processes, technologies, regulatory requirements, case law, or approaches to Personal Data processing.

31.2. The current version of this Policy is posted on the Platform or on the official website of the service. Where the Platform is distributed through the Apple App Store or Google Play, the Operator shall include a current link to this Policy in App Store Connect or Google Play metadata where required by Apple or Google and shall make this Policy easily accessible within the app.

31.3. If the changes are material, the Operator takes reasonable measures to notify the User through the Platform, email, push notification, or another available channel.

31.4. Continued use of the Platform after the changes take effect means that the User has read the updated Policy. If applicable law requires separate consent, the Operator requests such consent.

32. Governing Law and Disputes

32.1. This Policy is governed by the laws of the United Arab Emirates, excluding its conflict of laws rules, provided that nothing in this Policy limits the effect of mandatory provisions of the law of the User’s country of residence where such provisions apply. Any dispute, difference, controversy or claim arising out of or in connection with this Policy, including (but not limited to) any question regarding its existence, validity, interpretation, performance, discharge and applicable remedies, shall be subject to the exclusive jurisdiction of the Courts of the Dubai International Financial Centre.

32.2. Nothing in this Policy deprives the User of the protection provided by mandatory provisions of personal data protection laws that cannot be excluded by agreement of the parties.

32.3. Disputes related to the processing of Personal Data shall be resolved in the manner provided by the user agreement, this Policy, and applicable law.

33. Contacts

For matters relating to the processing of Personal Data, the exercise of rights, withdrawal of consent, deletion of data, complaints, requests from competent authorities, and other privacy matters, the User may contact the Operator.

The Operator is Deggex FZE, registered at THUB Building, Dubai Silicon Oasis, Dubai, United Arab Emirates, license number 30380.

Privacy contact email: support@leko.sport.

clck (1)

Download App

We collect cookies for analytics and proper functioning of the website. We also use recommendation technologies.