Privacy Policy
Your privacy matters to us. This policy explains what personal data Threshold Performance Labs collects, why we collect it, how we use it, and what rights you have over it. We keep this plain and specific: no filler.
1. Who We Are
Threshold Performance Labs ("TPL", "we", "us", "our") operates the software platform at app.thresholdperformancelabs.com and the marketing site at thresholdperformancelabs.com.
For the purposes of applicable data protection laws, TPL is the data controller in respect of data collected directly from you through our websites. Where a Clinic uses our platform to process data about their Athletes, the Clinic is the data controller and TPL acts as a data processor on the Clinic's behalf.
You can contact us at any time at [email protected].
2. What We Collect
2.1 Data You Give Us Directly
| Category | Examples | Source |
|---|---|---|
| Account data | Full name, email address, password (hashed) | Signup form |
| Clinic profile | Clinic name, logo, brand colour, tagline | Onboarding & settings |
| Athlete data | Name, email, date of birth, sport, training goals | Entered by Clinic users |
| Physiological test data | Lactate values, heart rate, speed/power, VO₂max, RMR readings | Entered by Clinic users during testing |
| Contact enquiries | Name, email, clinic name, message | Contact form |
2.2 Data We Collect Automatically
| Category | Examples | Purpose |
|---|---|---|
| Usage data | Pages visited, features used, actions taken within the app | Service improvement |
| Technical data | IP address, browser type, device type, operating system | Security & debugging |
| Session data | Login timestamps, session tokens | Authentication & security |
We do not use third-party advertising cookies or tracking pixels on our platform. We do not sell your data to any third party.
3. How We Use Your Data
| Purpose | Data used |
|---|---|
| Providing and operating the Service | Account data, clinic profile, test data |
| Generating and delivering Reports to Athletes | Athlete data, test data, clinic branding |
| Authentication and account security | Email, password hash, session tokens |
| Communicating with you about your account | Email address |
| Responding to support enquiries | Name, email, message content |
| Improving the Service | Aggregated, anonymised usage data only |
| Complying with legal obligations | As required by applicable law |
We do not use your data for automated decision-making that produces legal or similarly significant effects on you.
4. Legal Basis for Processing
Where data protection law requires us to identify a legal basis for processing personal data, we rely on the following:
- Contract performance: processing necessary to provide the Service to you under our Terms of Service (account data, test data, report generation).
- Legitimate interests: processing for security, fraud prevention, and service improvement, where our interests do not override your rights.
- Legal obligation: processing required to comply with applicable law.
- Consent: where we rely on consent (e.g. marketing communications), you may withdraw it at any time without affecting the lawfulness of prior processing.
Where a Clinic processes Athlete personal data through our platform, the Clinic is responsible for establishing a lawful basis for that processing under applicable law.
6. Data Retention
We retain personal data for as long as your Account remains active or as necessary to provide the Service. Specific retention periods:
- Account and clinic data: retained for the duration of your Account plus 30 days following closure, to allow for data export requests.
- Test data and Reports: retained for the duration of your Account. Deleted within 30 days of Account closure on request.
- Usage and technical logs: retained for up to 90 days for security and debugging purposes.
- Contact enquiry data: retained for up to 2 years or until no longer required to respond to your enquiry.
After the applicable retention period, data is securely deleted or anonymised. You may request early deletion at any time (see Section 7).
7. Your Rights
Depending on your jurisdiction, you may have the following rights in respect of your personal data. To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate or incomplete data.
- Deletion: request deletion of your personal data, subject to legal retention obligations.
- Portability: request your data in a structured, machine-readable format.
- Restriction: request that we restrict processing of your data in certain circumstances.
- Objection: object to processing based on legitimate interests.
- Withdrawal of consent: where processing is based on consent, withdraw it at any time.
If you are located in Singapore, you may also make a request under the Personal Data Protection Act 2012 (PDPA). If you are located in the EU or UK, you have the right to lodge a complaint with your local data protection authority.
We will not discriminate against you for exercising any of these rights.
8. Security
We implement commercially reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These include:
- Encrypted data transmission via HTTPS/TLS
- Hashed password storage (we never store passwords in plaintext)
- Row-level security on our database
- Multi-factor authentication available for Clinic accounts
- Access controls limiting which staff can access which data
No system is completely secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected parties and relevant authorities as required by applicable law.
9. International Data Transfers
TPL is based in Singapore. Your data may be processed by our service providers in other countries, including the United States and the European Union. Where data is transferred outside your home jurisdiction, we take steps to ensure appropriate safeguards are in place, including relying on service providers that are certified under recognised frameworks or that have executed standard contractual clauses where required.
10. Children's Data
The Service is intended for use by qualified adult professionals and is not directed at individuals under the age of 18. We do not knowingly collect personal data directly from children. However, Clinics may enter Test Data relating to Athlete clients who are minors. In such cases, the Clinic is solely responsible for obtaining appropriate parental or guardian consent before submitting any such data to the Service.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by displaying a prominent notice within the Service at least 14 days before the changes take effect. We encourage you to review this page periodically. Your continued use of the Service after the effective date of any updated Privacy Policy constitutes your acceptance of the changes.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Threshold Performance Labs
Email: [email protected]
Singapore
We take privacy concerns seriously and will respond to all requests within 30 days.