Recipients of your data

Version of 4 September 2026 · List 2026-09-04.1 · Part of the privacy policy · The German version is the binding one; this is a courtesy translation.

Contents
  1. What this list belongs to
  2. How to read the table
  3. The recipients
  4. Who is not on this list, and why
  5. Transfers outside the EEA
  6. Version, changes and superseded editions
  7. Names on request

1. What this list belongs to

Section 7 of the privacy policy names the categories of recipient. This page names the companies behind them. It belongs to the privacy policy and does not replace it: the categories and the legal bases are there, the names are here.

The split is deliberate. Vendors change, categories do not. A separately versioned list stays current without the policy being rewritten every time. It is lawful because Art. 13(1)(e) GDPR accepts categories, while Art. 15(1)(c) GDPR requires the actual names on request (CJEU, judgment of 12 January 2023, C-154/21, para. 36; EDPB Guidelines 01/2022, Example 20). You get both halves here without having to ask.

2. How to read the table

The rows are grouped by the categories of recipient that section 7 of the privacy policy uses. A company that does several jobs for us still appears once only, with all of its jobs in one row. These roles appear:

The last column describes what our software does, not what a vendor promises. “Our software refuses any endpoint outside its EU list” is a statement about us and stays true even when a vendor edits its pages. Where we cannot establish a place of processing, the cell says exactly that instead of a guess. Coordinates are rounded to four decimal places before they leave us, for the weather service, the timezone service and the place-name service alike.

3. The recipients

Name and legal entity What it does for us Personal data that reaches it Role Where it processes
A · AI providers for the coach
Mistral AI SAS
15 rue des Halles, 75001 Paris, France
Answers the coach’s requests. The coaching context: your profile with maximum and resting heart rate and heart-rate zones, timezone, goals and race names, training plan, coach notes, your chat text. Through tool calls also sleep, HRV, recovery, training status, GPS tracks, current location and calendar entry titles. Your name and email address are not included. Processor The company is French, and our software calls its EU regional endpoint, which the provider documents as processing in the EU and the EFTA countries. It called the provider's location-uncommitted general endpoint until 4 September 2026. The provider excludes account and billing data from that guarantee, and in its data processing agreement reserves temporary transfers to sub-processors outside the EU on standard contractual clauses.
Microsoft Ireland Operations Limited
One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (Azure OpenAI Service)
Answers the coach’s requests. As for Mistral. The provider states that prompts and answers are held in an abuse-monitoring data store, separated by customer resource, and that authorised employees of the provider can read what its abuse system has flagged; for a resource in the European Economic Area it states that those employees are located in the EEA. The provider also states that prompts and answers are not used to train, retrain or improve the base models and are not made available to OpenAI or other providers. Processor Our software accepts Azure OpenAI hostnames only and refuses every other endpoint. The deployment we run is Data Zone Standard in the provider's EU data zone, which is the setting that decides where inference happens and where content rests. That data zone is the European Union together with the EFTA states Liechtenstein, Iceland, Norway and Switzerland, so it is wider than "the EU".
Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy, L-1855 Luxembourg
Answers the coach’s requests, both for Claude and for the open-weight models. As for Mistral. Processor Our software refuses any AWS region outside its EU list. Default: eu-central-1 (Frankfurt). The open-weight models are pinned per model, two in eu-central-1 (Frankfurt) and two in eu-north-1 (Stockholm).
Google Cloud EMEA Limited
70 Sir John Rogerson’s Quay, Dublin 2, D02 R296, Ireland
Answers the coach’s requests (Vertex AI, Gemini). As for Mistral. Processor Our software calls only the European Vertex endpoint and eight European regional hosts, and refuses every other one.
B · Your own connected accounts
intervals.icu Ltd
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
Supplies your activities, wellness values and sport settings once you connect the source. We write planned sessions into your calendar there while the plan push is switched on. Inbound: nothing from us beyond the request itself. Outbound: planned sessions with title, date, duration and intensity. Independent controller United Kingdom as the seat of the company. The provider states that it transfers the data to Germany and Finland and processes it there, and that the data may in addition be stored in the cloud with Google, Backblaze and Wasabi. A transfer to the United Kingdom rests on the Commission’s adequacy decision (Art. 45 GDPR).
Strava Ireland Limited
Magennis Court, Pearse Street, Dublin 2, D02 FK76, Ireland (Strava provides the service in the EEA through this entity)
Supplies activities, profile and zones once you connect the source, and can serve as a sign-in method. Only on your explicit instruction do we upload an activity there or change its name, description and sport type. Outbound only what you upload or edit. Activities recorded on Strava are never put before the coach, never exported to another platform, and are left out of the calendar feed. Independent controller United States. Strava states that information of users outside the United States is transferred there, processed and stored there, and that it uses legal mechanisms such as standard contractual clauses for international transfers. Strava Ireland Limited is the entity that provides the service in the EEA.
Polar Electro Oy
Professorintie 5, 90440 Kempele, Finland
Supplies workouts, sleep, Nightly Recharge and daily activity once you connect the source. On connecting, our server registers your account with Polar; on disconnecting, it deregisters it. Your Polar account identifier as part of that registration. Otherwise requests only. Independent controller Polar states itself that its service data sits on servers in Ireland and Sweden and that processing may also take place outside the EEA. For transfers out of the EEA it names the EU-U.S. Data Privacy Framework, its UK and Swiss counterparts, and the European Commission’s standard contractual clauses.
Suunto Oy
Tammiston Kauppatie 7 A, 01510 Vantaa, Finland
Supplies workout summaries once you connect the source. On request we place a SuuntoPlus guide there, which you transfer to the watch yourself. Outbound only the guide you generate. Independent controller Finland. Suunto states itself that some subcontractors, vendors and group companies process personal data outside the EEA under standard contractual clauses, and it names a China leg with supplementary measures. Suunto also publishes joint controllers in China and Hong Kong: Dongguan Liesheng Electronic Co., Ltd, Liesheng HK Limited and Suunto Sports Technology entities.
C · Sign-in, purchases through the app stores, and delivery of notifications
Apple Distribution International Limited
Hollyhill Industrial Estate, Hollyhill, Cork, Ireland
Three things: Sign in with Apple, the sale of the subscription in the App Store, and delivering push notifications to iPhones. Sign-in: Apple user identifier, email address, and your name the first time. Purchase: your payment identity, which we never see ourselves. Push: your iPhone’s device address, our app identifier, and either one fixed sentence from our text catalogue in your language or, for an announcement the operator sends by hand, that announcement’s text. Independent controller for sign-in and purchase; processor for push delivery Apple states itself that its transfers of personal data out of the EEA are governed by standard contractual clauses. Apple publishes no processing location for its push service.
Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland (Sign in with Google, Google Calendar, Firebase Cloud Messaging)
Sign-in, reading your Google calendar if you allow that separately, and delivering push notifications to Android devices. Sign-in: Google user identifier, email address, display name. Calendar: requests only, we write nothing there. Push: your device’s registration identifier, our project identifier, and either one fixed sentence from our text catalogue or, for an announcement the operator sends by hand, that announcement’s text. The provider states that it keeps the installation identifier until we call its deletion interface, and removes it from live and backup systems within 180 days of that call. Independent controller for sign-in and calendar; processor for push delivery Google names Google Ireland Limited as the controller for users in the EEA, which settles the sign-in and calendar roles. For Cloud Messaging it does not: that service is governed by separate Firebase terms and Google publishes no counterparty for it, so we do not assert one. For transfers Google states that Google LLC and its US subsidiaries are covered by the adequacy decision on the EU-U.S. Data Privacy Framework (Art. 45 GDPR), and for Cloud Messaging that the service is global and could process data at any of the Google Cloud Platform locations or Google data centre locations.
Google Commerce Limited
70 Sir John Rogerson’s Quay, Dublin 2, D02 R296, Ireland
Sells you the subscription when you buy it on Google Play. Your payment identity and your purchase history in the store. All we see of it is which product is active and until when. Platform, independent controller for the purchase See the Google row above.
RevenueCat, Inc.
1032 E Brandon Blvd #3003, Brandon, FL 33511, United States
Validates and manages store purchases so the app knows which tier you are entitled to. Your internal account number as the identifier, the store, the product purchased and the subscription state. The module runs inside the app process on your phone and additionally transmits device and app attributes of its own choosing; it is not open source, so we do not claim an exhaustive list here. Our app does not call any advertising or attribution identifier. Processor United States. The provider states that personal data is stored on Amazon Web Services in the USA, and its data processing agreement applies the EU standard contractual clauses, governed by Irish law.
D · Payment processing on the web
Stripe
For Managed Payments, the rail our website uses, two Irish Stripe companies are in play and Stripe’s own documents do not agree which is ours: its data processing agreement names Stripe Payments Europe, Limited for an account outside the Americas, while our account documents and the Terms name Stripe Technology Europe, Limited. We are confirming it against the countersigned account documents before stating one here as settled, rather than swapping one assertion for another.
Runs the checkout page, the subscription and the customer portal. From us: your internal account number, the tier chosen, the price and the version of the terms. From you directly: the email address and payment method you enter on Stripe’s own page. No health or training data is included. Processor for the payment flow Not settled: it follows from which of the two acquiring affiliates holds our account. Stripe operates group companies in Ireland and in the United States.
Link, LLC
“Sold through Link, LLC”, the entity through which Stripe provides its merchant-of-record service
Appears as the seller on your statement, on the receipt and on the invoice, which carries that company’s name and tax details rather than ours. That is the merchant-of-record role, which is a payment and tax role: the seller of the service remains us, and our duties towards you do not move with it (Terms, section 1). The order details of the purchase. Merchant of record, independent controller for the payment Stripe publishes no address and no place of processing for this entity.
E · Email delivery
Mailjet
Mailjet’s own privacy notice defines the party as Sinch AB (publ) or any of its subsidiaries and gives dpo@sinch.com as the contact. Which entity is our counterparty is being confirmed against the contract documents before we state it here as settled.
Takes outbound mail from our own mail server as a relay and delivers every transactional message. The recipient address, subject and full body of every mail we send you, including a data export if you ask for it as an attachment. Open and click tracking is switched off in each individual message, so there is no counting pixel and no redirected link. Processor The provider states that data is stored in its secure data centres with Google Cloud Platform in Frankfurt (Germany) and Saint-Ghislain (Belgium), that its data centres are located exclusively within the European Union, and that daily encrypted backups are held in geographically separated environments within the EU. The group notice says a platform is hosted from data centres in the United States or in Europe according to the deployment selected, and the group’s data processing agreement reserves transfers within the group. For transfers out of the EEA the group names the EU standard contractual clauses unless another mechanism applies, among them the EU-U.S. Data Privacy Framework.
F · Server hosting, backup, name resolution and app delivery
Hetzner Online GmbH
Industriestr. 25, 91710 Gunzenhausen, Germany
Rents us the server Milewise runs on: application, database and our mail server. Everything that is stored sits on that machine. Processor Falkenstein, Germany. The company is seated in Germany and the server we rent stands in its Falkenstein data centre.
Hetzner Online GmbH
Storage Box, the off-site backup target
Receives the nightly encrypted backup. The complete database, our mail store and the server configuration, encrypted with a key that is not held on the destination system. Seven daily, four weekly and six monthly snapshots are kept, which is why deleted data survives there for up to about seven months. Processor Falkenstein, Germany, the same site as the server it backs up.
Cloudflare, Inc.
101 Townsend St., San Francisco, CA 94107, United States
Operator of our authoritative DNS zone
Answers name lookups for our domains and validates our TLS certificates. Only the name lookups your network’s resolver makes. No content of a request reaches it on our own path: no upstream proxy is configured in our server configuration. The map tiles run a path of their own, and the map provider states that it may use Cloudflare as a content delivery network; whether our tiles travel it we have not established. Recipient of name-resolution data Cloudflare states that it primarily stores information in the United States and the European Economic Area, that it certifies under the EU-U.S. Data Privacy Framework, and that it falls back on the standard contractual clauses should that certification lapse.
Expo (EAS Update), operated by 650 Industries, Inc.
624 University Ave FL1, Palo Alto, CA 94301, United States
Operator of our app’s update service
Builds the app and, on each launch of an installed app, answers whether a newer version exists. On each launch: your device’s IP address, the platform, the app’s runtime version, the release channel, and a randomised token per installation, which the provider uses to tell whether an update has already been downloaded. Processor United States. The provider states that data is transferred there for processing and that it has self-certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR).
G · Map tiles, weather, timezone and place names
OpenFreeMap, operated by Hyperknot Software Kft.
Petofi Sandor utca 48., Ujlengyel, 2724, Hungary
Supplies the map tiles your browser and the app fetch directly whenever you open a map. Your own IP address and the coordinates of the tiles you look at, which reveal the area of your home and your routes. No account identifier and no cookie goes with them. Independent controller The provider makes no statement about where its servers are and states that it may use Cloudflare as a content delivery network. It states that by default no IP addresses are logged, and that logs switched on for a security incident are deleted after 30 days at the latest.
Meteorologisk institutt (MET Norway)
Norway
Supplies the weather forecast for where you train. Coordinates rounded to four decimal places and our server’s IP address. No account identifier. Independent controller Norway. Norway is an EEA state in which the GDPR applies through the EEA Agreement, so a transfer there is not a transfer to a third country.
OpenMeteo GmbH
Hintere Schilligmatte 6, 6463 Bürglen (UR), Switzerland
Derives the timezone from coordinates and supplies historical weather for past sessions. Coordinates rounded to four decimal places, a date range and our server’s IP address. The provider states that it retains webserver logs containing IP addresses and coordinates for 90 days. Independent controller Switzerland, covered by the European Commission’s adequacy decision (Art. 45 GDPR).
OpenStreetMap Foundation (Nominatim)
a company limited by guarantee registered in England and Wales, no. 05912761, St John’s Innovation Centre, Cowley Road, Cambridge CB4 0WS, United Kingdom
Turns a coordinate into a place name so the coach can refer to where you are. Coordinates rounded to four decimal places and our server’s IP address. No account identifier. Independent controller The provider states that personal data other than data associated with a tile request is stored in the United Kingdom and the Netherlands, and that backups are stored in the EU. The United Kingdom is covered by the Commission’s adequacy decision (Art. 45 GDPR).
H · The owner’s AI coding assistant, and operational alerts
Anthropic, provider of the AI development tool Milewise is built and supported with
The contracting entity, the region and the retention terms are not settled; we write that down rather than assert one. We hold no processor contract with this provider, and no other instrument governs what it may do with what it reads.
Only for accounts the owner explicitly enables for support: diagnosing and fixing a problem on that account. For an enabled account, a second, restricted copy: coach conversations, health values pushed from the phone, the device calendar and stored activities. Every credential marked secret is left out of that copy, and Strava connection data too. Changes to your data can be requested back through the same channel, and the owner can additionally issue the assistant a device credential that lets it act in your account exactly as one of your own paired devices does, with your entitlements, your consents and your rate limits. That device appears under its own name in Settings under Devices, and you can revoke it there. There is no switch for the support copy itself: the owner sets the flag, and the flag appears in your Art. 15 data export. Not settled Not settled.
ntfy
The notification service our server posts the owner’s operational alerts to
Tells the owner about operational events, for example an account deletion or a billing event. As a rule the event category and the endpoint only, with no account identifier and no message content. One alert is an exception, and we name it rather than average it away: when a customer declares a withdrawal, the alert carries the internal account number, the time of the declaration, the date of the contract and whether the subscription could be stopped, because the repayment has a fourteen-day deadline and nothing else would tell the operator. We have not checked line by line that every other alert keeps to the rule, which is why the service appears here and not in section 4 of this page. Processor for the operator's alerts. We hold no processor contract with this service. Not established by us.
I · The calendar service you choose yourself
The calendar service you subscribe with
Apple, Google, Microsoft or another, depending on where you add the feed
Polls the calendar feed on your behalf once you have set it up. Your past sessions and your plan, with title, distance and exact local times. Activities recorded on Strava are excluded. The feed hangs on a long secret address: whoever holds it can fetch it. You can regenerate it in Settings. Recipient chosen by you Determined by the service you choose.

4. Who is not on this list, and why

5. Transfers outside the EEA

Every leg out of the EEA that this table carries, and what the recipient names for it itself:

The backup destination needs none of these: it is the same German company at the same German site as the server, so nothing leaves the EEA on that leg. For the remaining recipients on this page, among them the notification service ntfy, Link, LLC and the support channel, we have not yet settled which instrument carries a transfer out of the EEA, and we say that rather than assert one.

Which instrument carries an individual transfer, and how to obtain a copy of it, we will tell you on request at contact@milewise.de (Art. 13(1)(f) GDPR).

6. Version, changes and superseded editions

This list carries its own version number, a date plus a running number. The current one is at the top of the page. Superseded versions are kept and handed out on request, so you can establish who received your data at a given time.

There are two kinds of change, and they are handled differently:

We do not ask you to check this page periodically. Information you have to go and fetch yourself is not fair information.

7. Names on request

On an access request under Art. 15 GDPR we name the actual recipients that received your data, not just the categories. That is usually a shorter list than this page: the sources you never connected do not appear on it.

Moritz Niedermann, Milewise
Essenweinstr. 37, 76131 Karlsruhe, Germany
contact@milewise.de

The legal bases, the retention periods and your right to complain to the supervisory authority are in the privacy policy. The German version of this page is the binding one.