Legal Documentation

Privacy Policy.

Last Updated: July 9, 2026

"Your privacy is critically important to us. This Privacy Policy explains how DYALR ("we", "us", or "our") collects, uses, and protects your information when you use our training platform."

1

Data Controller

Under the GDPR, the Data Controller responsible for your personal information is:

DYALR (operated by Giulio Castagnara)

Location: Italy

support@dyalr.com

2

Information We Collect

To provide you with a high-performance training experience, we collect only the data necessary for the algorithm and user experience:

Account Info

Name, email, and secure credentials managed by Firebase Auth.

Golf Profile

Handicap, equipment, and availability used to calibrate the algorithm.

Performance

Drill scores, practice stats, and historical progress.

3

How We Use Your Data

We use your information for strictly functional purposes:

  • Algorithmic generation of your weekly training plan.
  • Visualization of your performance trends and ROI.
  • Communication regarding technical notices or security alerts.
  • Anonymized trend analysis to improve our coaching methodology.

Legal Basis for Processing

Under GDPR Article 6, we process your personal data based on the following legal grounds:

Contract Performance

Art. 6(1)(b)

Account creation, algorithm-based plan generation, drill score tracking, and overall service delivery.

Legitimate Interest

Art. 6(1)(f)

Platform security, abuse prevention, anonymized improvement of our coaching methodology.

Consent

Art. 6(1)(a)

Analytics cookies (Google Analytics 4), marketing communications, and push notifications. You can withdraw consent at any time.

4

Third-Party Services

We do not sell your data. We use industry-standard providers to host and secure DYALR:

Hosting & InfrastructureGoogle Cloud Platform (GCP)
Authentication & DBFirebase (Google)
AnalyticsGoogle Analytics 4 (GA4)
Transactional EmailResend

All providers are vetted for GDPR compliance and data processing security. Resend processes email addresses solely for delivering transactional messages (e.g., beta invitations) and does not retain personal data beyond delivery.

Where personal data is transferred outside the European Economic Area (EEA), we rely on the EU-US Data Privacy Framework (DPF) adequacy decision and/or Standard Contractual Clauses (SCCs) to ensure adequate protection. Google LLC is a certified participant under the DPF.

5

Cookies & Analytics

DYALR uses cookies and similar technologies to provide, secure, and improve the service:

Essential Cookies

Required for authentication, session management, and security. These cannot be disabled.

Analytics Cookies

Google Analytics 4 (GA4) helps us understand how users interact with DYALR to improve the experience. Data is anonymized and never sold.

Preference Cookies

Store your UI preferences such as theme selection (dark/light mode) and display settings.

Non-essential cookies (analytics) are only activated after you provide explicit consent via our cookie consent banner, displayed on your first visit. You can withdraw or change your consent at any time by clicking "Cookie Settings" in the page footer. Essential cookies required for authentication and security cannot be disabled.

6

Your GDPR Rights

Access

Request a copy of your personal data.

Rectification

Update your profile or request data correction.

Erasure

The 'Right to be Forgotten' — delete your account.

Portability

Request data in a structured digital format.

To exercise any of these rights, please contact our legal desk at support@dyalr.com.

7

Data Security

We implement professional technical and organizational measures to protect your data. Your password is never stored in plain text and all transmissions are encrypted via SSL/TLS.

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy:

Account DataRetained while your account is active. Deleted within 30 days of an account deletion request.
Training & PerformanceRetained while your account is active and deleted upon account deletion.
Analytics DataAnonymized and retained per Google Analytics defaults (14 months).
Server LogsRetained for 30 days for security and debugging, then automatically purged.

International Data Transfers

Your personal data is primarily stored and processed within the European Union:

Primary StorageGoogle Cloud Platform — europe-west1 (Belgium, EU)
AuthenticationFirebase Auth — Google-managed, EU-US DPF certified
AnalyticsGoogle Analytics 4 — EU-US DPF certified (loaded only with your consent)
Email DeliveryResend — US-based, processes email addresses transiently for delivery only

Where data is transferred outside the EEA, we rely on the EU-US Data Privacy Framework adequacy decision (adopted July 10, 2023) and/or Standard Contractual Clauses (SCCs) approved by the European Commission.

Information for US Residents

If you are a resident of the United States, the following applies:

  • We do not sell, share, or rent your personal information to third parties for monetary or other valuable consideration.
  • At our current operating scale, the California Consumer Privacy Act (CCPA/CPRA) and similar US state privacy laws do not apply. If our operations reach the applicable thresholds, we will update this policy and provide all required disclosures.
  • You may contact us at any time to request information about the personal data we hold about you.

Confused about how your data is used? We're here to help.