Suth Performance is a Hyrox training platform operated from the United Kingdom. This policy explains what data we collect, why we collect it, where it lives, how long we keep it, and the rights you have over it under the UK GDPR and the Data Protection Act 2018.
We are the data controller. Our contact for data matters is privacy@suthperformance.com.
Suth Performance is operated by [REGISTERED COMPANY NAME TO BE CONFIRMED], a company registered in England and Wales, company number [COMPANIES HOUSE NUMBER TO BE CONFIRMED], registered office [REGISTERED OFFICE ADDRESS TO BE CONFIRMED].
What we collect
- Account data. Your email address, given at the email gate of the quiz so we can save your plan and send it back to you.
- Quiz answers. Your responses to the onboarding quiz: experience level, race date, training days, equipment, injuries. Used to generate your plan.
- Training data. The sessions you mark complete, the splits, weights, and RPE values you log, and any notes you attach. Used to recalibrate your plan each Sunday.
- Payment data. Processed by Stripe. We never see or store your card number; Stripe gives us a token plus the last 4 digits of the card for receipts and disputes.
- Usage analytics + session replay. Page views, quiz progress, click heatmaps, and session replay captured by PostHog after you give cookie consent. Input fields (email, password, anything with a
data-maskattribute) are masked at the recording layer, we never see what you typed into a form. Pseudonymous; no profile identifiers tied to your name. You can opt out at any time via the cookie banner or by setting Do Not Track in your browser. - Error reports. Captured by Sentry when something breaks. Includes the page you were on and a minimal stack trace. No payment data is ever sent to Sentry.
- Content drafts. If you are a Suth Performance editor with access to /studio, your drafts and revisions are stored in Sanity (our headless CMS).
Why we collect it
- Deliver your training plan and remember your progress.
- Process your subscription and send receipts.
- Improve the product. Find where the funnel breaks, where members get stuck, which workouts get skipped.
- Send the small number of transactional emails the product needs: welcome, trial-ending reminder, payment-failed, cancellation.
- Detect fraud and protect the service from abuse.
Legal basis
- Contract performance. We cannot deliver your plan without your quiz answers and email.
- Consent. Analytics cookies, session replay, marketing emails. You opt in; you can opt out anytime.
- Legitimate interest. Security, fraud prevention, error monitoring, product analytics in aggregate.
- Legal obligation. Payment records, retained 7 years for HMRC.
How long we keep it
- Account and training data. Kept while your subscription is active, plus 90 days after cancellation in case you come back. Then deleted.
- Quiz answers without an account. 30 days, then deleted.
- Session replay. 30 days rolling window. Then deleted.
- Analytics events. 12 months at row level. After 12 months we aggregate and the individual events are deleted.
- Payment records. 7 years per HMRC requirements.
- Support emails. 2 years, then deleted.
Who we share data with
We use a small number of trusted processors to deliver the service. We do not sell your data. We do not share it with marketing networks. The processors below are bound by data processing agreements and process only what they need to.
- Stripe (payments). Card processing, billing, customer portal, fraud screening. Data stays inside the EEA and UK regions. Privacy: stripe.com/privacy.
- Supabase (database + auth). Your account, quiz answers, and training data. EU regions (Frankfurt). Privacy: supabase.com/privacy.
- Resend (email). Transactional emails only (welcome, trial reminders, payment notices). EU sub-processors.
- PostHog (analytics + session replay). EU-hosted, only loaded after consent. Inputs and marked fields are masked at recording layer.
- Sentry (error monitoring). EU-hosted. Scrubs PII before storing. Used to find crashes.
- Sanity (CMS). Only touched by Suth Performance editors at /studio. Public visitors never interact with Sanity.
- Vercel (hosting + CDN). Serves the web app. Logs HTTP-level metadata (IP, user agent, referrer) for 30 days for security and abuse prevention.
- Upstash (rate limiting). Tracks request counts by IP to block abusive traffic. Keys expire within 24 hours.
- Crisp (live chat, when enabled). If you message us through the chat widget on /contact, your message and email are processed by Crisp. EU-hosted.
International transfers
Most of our processors run in the EEA or UK. Where any data leaves the UK (for example, a US-based sub-processor used by one of the providers above), the transfer is covered either by the UK adequacy regulations for the destination country, or by Standard Contractual Clauses (UK IDTA addendum) and supplementary technical measures. We do not permit transfers to jurisdictions without an adequate level of protection.
Cookies
We use a small set of cookies and similar storage. Strictly necessary items are always on; analytics and session replay are opt-in via the cookie banner. For the full list, including names, providers, and durations, see our Cookie policy.
Children
Suth Performance is intended for people aged 16 and over. We do not knowingly collect data from anyone under 16. If you believe a child has signed up, email privacy@suthperformance.com and we will delete the account.
Your rights under UK GDPR
You can ask us to:
- Show you the data we hold about you (subject access).
- Correct anything wrong.
- Delete your data (subject to legal retention rules above).
- Export your data in a portable format (JSON, CSV, your choice).
- Restrict what we do with it while a request is being processed.
- Object to processing based on legitimate interest. We will weigh and respond.
- Withdraw consent at any time for the things we asked consent for (analytics, marketing). Withdrawal does not affect processing that happened before the withdrawal.
To exercise any of these rights, email privacy@suthperformance.com from the address on your account. We reply within 24 hours and complete most requests within a calendar month, as the UK GDPR requires. There is no fee unless the request is manifestly unfounded or excessive.
If you are not happy with how we handled your request, you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint. We would rather you came to us first; almost every concern can be resolved faster directly than through a regulator.
Security
Data is encrypted in transit (TLS 1.2+) and at rest on Supabase and Vercel. Access to production systems is limited to a small number of named team members, gated by SSO with mandatory two-factor authentication, and audited. Card data never touches our servers, only Stripe sees it.
Passwords are hashed with bcrypt at a work factor that we review every 12 months in line with industry guidance. We do not store password hints, security questions, or any other recoverable secret material on our side. Account recovery uses one-time email links that expire within 15 minutes of being issued.
Our backups are encrypted and held within the UK and EU. Restores are rehearsed quarterly so that we can confirm both the technical recovery path and the recovery time objective. Deleted records are removed from backups within 30 days of the last scheduled backup that contained them, after which they are unrecoverable.
Automated decision-making
Suth Performance personalises your training plan automatically using the answers you give in the onboarding quiz and the sessions you log through the app. This is profiling for the purpose of delivering the service, not for any marketing, pricing, or credit decision.
No part of the personalisation has legal or similarly significant effects on you, and the output is always a training schedule that you can adjust, ignore, or override. If you would prefer a coach to set your week manually instead of the adaptive engine, email support@suthperformance.com and we will switch your account to manual planning at no extra cost.
Third-party processors in detail
We use a small number of named processors to deliver the service. Each one is contracted under a Data Processing Agreement that mirrors the GDPR Article 28 obligations and forbids them from using your data for any purpose other than delivering Suth Performance to you.
- Supabase (UK + EU regions). Hosts authentication, application database, and file uploads. Receives: account email, hashed password, training logs, quiz answers, partner application records.
- Vercel (global edge, primary region UK). Serves the marketing site and member app. Receives: HTTP request metadata (IP, user agent, referer) needed to route requests and mitigate abuse.
- Stripe (UK). Processes payments and stores card data on its own PCI-compliant systems. Receives: name, email, billing address, card details. Card details never touch Suth Performance servers.
- Resend (EU). Sends transactional and lifecycle emails. Receives: name, email, message content (welcome, payment receipts, password resets, partner status).
- Upstash (EU). Rate-limit counters and short-lived session tokens. Receives: hashed IP and request fingerprints; no personal data is stored long-term.
- Sentry (EU, optional). Error tracking. Receives: stack traces, browser metadata, the pseudonymous user ID associated with the session that errored. We do not send body content of requests.
If we add a new processor that handles personal data we will update this list and notify active members by email at least 14 days before the change takes effect.
How to exercise your rights, step by step
UK GDPR gives you the right to access, correct, delete, restrict, port, or object to processing of your data. Here is exactly how to do each, and what to expect.
- Access. Email privacy@suthperformance.com from your registered address. We acknowledge within 72 hours and reply in full within 30 days (UK GDPR Article 12(3)) with an export of all personal data we hold about you, formatted as JSON or CSV at your choice.
- Correction. Most fields are editable in-app under Account → Profile. For fields you cannot edit (legal name on receipts, historical training logs), email the same address with the correction and any supporting evidence; we update within 7 days.
- Deletion. In-app: Account → Close account. Within 30 days we delete personal data from production systems. Backup copies cycle out within a further 30 days, after which the record is unrecoverable. Some categories (invoices, partner payouts) we retain for the legally required period under tax law and explain in the next section.
- Restriction or objection. Email privacy@suthperformance.com. We will pause the relevant processing within 7 days and confirm when done.
- Portability. The access export is machine-readable JSON suitable for porting to another service. Specify your preferred format in the request if CSV is more useful.
We do not charge for any request, even repeat requests, unless the request is manifestly unfounded or excessive (UK GDPR Article 12(5)), in which case we will explain in writing first.
Incident notification
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, as required by UK GDPR Article 33. If the risk is high, we will also notify affected individuals by email without undue delay, explaining what happened, what data was involved, what we have done to contain the incident, and what (if anything) you need to do.
Changes to this policy
We may update this policy as the service evolves or as new processors come online. Material changes (a new processor handling personal data, a new category of data collected, a change to retention) are notified by email to active members at least 14 days before the change takes effect. The bottom of this page always shows the last updated date.
Contact
Data Protection contact: privacy@suthperformance.com.