Legal
Privacy policy
How LuxArte Ltd handles personal data for MOTVIVO, under the GDPR and Cyprus law.
Last updated: 4 October 2026
This policy explains how LuxArte Ltd (“LuxArte”, “we”, “us”) handles personal data in connection with MOTVIVO: the website motvivo.com, the staff app (app.motvivo.com), the booking app for members (book.motvivo.com) and our administration console.
We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the Cyprus Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (Law 125(I)/2018), and, for cookies and similar technologies, the Cyprus law on electronic communications that implements the EU ePrivacy Directive.
1. Who is responsible
LuxArte Ltd
Michail Koutsofta, 17
Anarita 8502
Cyprus
Company registration no. HE 465325 · VAT ID 60097364M
Email: [email protected]
How responsibility is shared depends on whose data it is:
- Website visitors, demo requests and our business contacts (for example the owner of a club that uses MOTVIVO): LuxArte is the controller.
- Members and staff of a club that uses MOTVIVO: the club is the controller of this data and decides how it is used. LuxArte processes it on the club’s behalf as a processor, under a data processing agreement with the club. If you are a member of a club, please contact your club first about your data; we will help the club respond.
We have not appointed a data protection officer, as this is not required for our activities. All data protection questions can be sent to [email protected].
2. The website (motvivo.com)
Visiting the website
When you visit the website, our servers and Cloudflare process technical data that every browser sends (IP address, date and time, page requested, browser type) to deliver the pages and protect them against attacks. This is our legitimate interest in running a secure website (Art. 6(1)(f) GDPR). Server logs are kept for a short period and then deleted.
The website does not use analytics, advertising or tracking cookies, and fonts are served from our own server. WordPress sets technical cookies only for people who sign in to manage the website.
Demo requests
If you use the “Book a demo” form, we receive the details you enter (name, studio name, email, and optionally phone, city, studio size, the system you use today and your message) by email (sent through our email delivery provider to our mailboxes, see section 4). We use them to answer your request and arrange a demo (steps prior to a contract, Art. 6(1)(b) GDPR, and our legitimate interest in replying to business enquiries, Art. 6(1)(f)). We keep them for up to 12 months unless we start working together.
3. The MOTVIVO apps
What is processed for clubs and their members
- Account details: name, email address, optionally phone number; passwords are stored only in hashed form.
- Bookings, waitlist places, attendance and class ratings.
- Memberships, credit packs and their use, gift vouchers and challenge participation.
- Marketing consent (given or withdrawn, and when) and how the member heard about the club, where the club records this.
- Emails sent by the system (for example booking confirmations), and a record of important changes made by staff.
- Messages between a member and their club in the apps, including messages a club sends to everyone booked into a class. Each message from the club is also sent to the member by email.
- If the club uses them: the waiver a member signed (with their typed name and the time) and their answers to the club’s health questions. Health answers are sensitive data: they are only collected with the member’s explicit consent (Art. 9(2)(a) GDPR), only the club’s managers and front desk can see them, and trainers only see that a member asked to be checked on.
- Technical data needed to keep you signed in and to secure your account (session cookies, device and browser type).
Most of this data is entered by the member when signing up or booking; some is entered by the club’s staff (for example when they create a member’s account at reception, assign a membership or record attendance).
For members and club staff this is processed on behalf of the club (see section 1). For club owners and administrators, LuxArte also processes contact and account details to provide the service, support and invoicing (performance of a contract, Art. 6(1)(b) GDPR), and keeps invoicing records to meet its legal obligations (Art. 6(1)(c) GDPR).
A name and an email address are needed to create an account and to book; without them the apps cannot be used. Everything else (such as a phone number or marketing consent) is optional.
Cookies and storage in the apps
The apps use only cookies that are strictly necessary to keep you signed in securely. Your browser also stores a few preferences (for example the calendar or list view, or which club you last signed in to). There are no tracking or advertising cookies. Strictly necessary cookies and storage do not require consent under the ePrivacy rules; if we ever add optional cookies, we will ask for your consent first.
We do not sell personal data, do not use it for advertising, and do not make decisions about you based solely on automated processing, including profiling, that produce legal or similarly significant effects. The suggestions in a club’s dashboard (for example “members who have gone quiet”) are aids for the club’s staff, who decide what to do.
4. Service providers
We use these providers, each bound by a data processing agreement:
- Hetzner Online GmbH (Germany): hosting of the website, the apps and their databases on servers in Germany.
- Cloudflare, Inc. (USA): delivery and protection of our websites, and forwarding of emails sent to @motvivo.com addresses to our mailboxes (Cloudflare Email Routing). Transfers to the USA are covered by the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses.
- Sendinblue SAS (Brevo) (France): delivery of the emails sent by the MOTVIVO apps and by this website, such as booking confirmations, invitations, password resets and replies to demo requests. Data is processed in the EU.
- Zoho Corporation B.V. (Netherlands): our email mailboxes, where emails to us, including demo requests, are received and stored. Data is processed in Zoho’s EU data centres.
5. How long we keep data
Data in the apps is kept for as long as the club uses MOTVIVO and as the club decides. When a club stops using MOTVIVO, we delete or return its data as agreed with the club. When a member deletes their account (or the club erases it), their messages with the club and their health answers are deleted with it; the record that a waiver was accepted is kept without their name. Backups are kept for 14 days and then overwritten. Where the law requires us to keep records (for example invoices), we keep them for the legally required period.
6. Security
All connections are encrypted (HTTPS). Passwords are hashed, each club’s data is kept separate from every other club’s, the databases are backed up every night, and access by our own team requires two-factor sign-in and is logged.
7. Your rights
You have the right to access your data, to have it corrected or deleted, to restrict or object to its processing, and to receive it in a portable format. Where processing is based on your consent, you can withdraw it at any time. For data that a club controls, please contact the club; otherwise contact us at [email protected].
We answer requests within one month (extendable by two further months for complex requests, in which case we tell you). We may ask you to confirm your identity first.
You also have the right to lodge a complaint with a supervisory authority. In Cyprus this is the Office of the Commissioner for Personal Data Protection, Kypranoros 15, 1061 Nicosia, Cyprus (www.dataprotection.gov.cy, [email protected]). You can also contact the authority in the EU country where you live or work.
8. Children
MOTVIVO is not directed at children. In Cyprus, children under 14 cannot give valid consent to online services themselves (Law 125(I)/2018); clubs that register members under 14, or under the age set in the member’s own EU country, are responsible for obtaining the consent of a parent or guardian.
9. Changes
We update this policy when our services or the law change. The date at the top shows the latest version.