Legal
Privacy
How Gritmo handles account, activity and trainer data. Last updated: 22 July 2026.
1. Data controller
DRIPSPIN S.R.L., registered at Str. Ghiosesti nr. 325, Oras Comarnic, Prahova, Romania, CUI 52790239, is the controller of personal data processed through Gritmo. Privacy requests can be sent to hello@dripspin.ro.
2. Data we process
Depending on the features you use, we may process:
- account information, such as name, email address and authentication identifiers;
- rider profile information, including body mass and training preferences;
- cycling and performance data, including power, heart rate, cadence, speed, time, routes, location, elevation, workouts and derived performance estimates;
- activity files and data obtained from a service you choose to connect;
- trainer data needed during a session, such as connection state, capabilities, telemetry and control responses;
- technical, security and diagnostic data, such as browser, device, error and request information;
- messages and information you send when requesting support.
Cycling, heart-rate and performance data may reveal information about health and may qualify as special-category data under applicable law.
3. Why we use data
- to create and secure your account;
- to import, store, display and analyse rides and routes;
- to estimate rider performance and generate workout or pacing guidance;
- to connect to and control a compatible smart trainer when you request it;
- to diagnose failures, prevent abuse and improve reliability;
- to respond to support requests and meet legal obligations.
4. Legal bases
We process ordinary personal data where needed to provide the service you request, based on our legitimate interests in securing and improving Gritmo, with your consent where required, and to comply with legal obligations.
Where cycling or performance data is legally treated as health data, we will ask for your explicit consent before that processing. Consent must be collected separately; accepting the Terms or reading this notice does not itself provide consent. You may withdraw consent at any time, without affecting processing already carried out lawfully. Withdrawing consent may prevent the affected analysis features from working.
5. Connected services and device access
Connecting an external activity service is optional. When you connect one, Gritmo receives the profile, activity and stream data covered by the permissions shown during authorisation. Connection credentials are stored server-side and protected in transit and at rest. You can disconnect a service from your account settings and, where applicable, from the provider itself.
Web Bluetooth access requires a browser permission and a user action. Trainer communication occurs through the browser during the session. We store session or activity data only where a Gritmo feature expressly saves it.
6. Who receives data
We use service providers for hosting, databases, authentication, mapping, diagnostics and support. We share only the data needed for them to provide those services under contractual and confidentiality obligations. Data is also exchanged with a connected service when you request that integration.
We may disclose data when legally required, to protect users and the service, or as part of a corporate transaction subject to appropriate safeguards. We do not sell personal data.
7. International transfers
Some providers may process data outside Romania or the European Economic Area. Where required, we use an adequacy decision, standard contractual clauses or another lawful transfer safeguard.
8. Retention and security
We keep account and saved activity data while your account is active or as needed to provide Gritmo. Diagnostic and security records are retained only for a proportionate period. We may retain limited information longer where required for legal, fraud prevention or dispute purposes. Deleted data may remain temporarily in protected backups before scheduled removal.
We use reasonable technical and organisational measures to protect personal data, but no online service can guarantee absolute security.
9. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. You may also complain to the Romanian National Supervisory Authority for Personal Data Processing or the competent authority in your country of residence.
Send requests to hello@dripspin.ro. We may need to verify your identity before completing a request.
10. Changes to this notice
We may update this notice when Gritmo, our providers or legal requirements change. We will publish the new date and provide additional notice for material changes where required.