Privacy Policy
WhiiStudio Pro and WhiiStudio Lite
Last updated: 19 August 2026
1. Scope
This Privacy Policy explains how TraniVerse Sports Technology Inc. (“TraniVerse”, “we”, “us”, “our”) collects, uses, discloses and protects personal data in connection with the WhiiStudio desktop applications — WhiiStudio Pro and WhiiStudio Lite (each, and together, the “App”) — and the online services the App connects to (the “Service”).
This Policy applies only to the WhiiStudio applications. Our other products, including the WhiizU application and the WhiizU website, are governed by their own separate privacy policies.
WhiiStudio is a business-to-business product. Accounts are issued under a service agreement with an organization such as a training studio, gym or club (the “Customer Organization”). The App does not offer public self-registration.
2. Who is responsible for your data
Because the App is operated by Customer Organizations on behalf of the individuals who train with them, responsibility for personal data is split:
| Personal data | Role |
|---|---|
| Account holder data — the login credentials and account records of the Customer Organization and its staff. | TraniVerse acts as controller. |
| Participant data — the profiles and training records of the individuals (“Participants”) whom the Customer Organization enters into the App. | The Customer Organization is the controller. TraniVerse acts as processor and handles this data only on the Customer Organization’s documented instructions, under its agreement with us. |
If you are a Participant and you wish to exercise your rights over your training data, please contact the organization that enrolled you. You may also contact us at official@whiizu.com and we will forward your request to that organization.
Controller details
TraniVerse Sports Technology Inc.
5 F., No. 552, Sec. 5, Zhongxiao E. Rd., Xinyi Dist., Taipei City 110039, Taiwan
Unified Business No.: 00110729
Managing director: Scottie Chen
Email: official@whiizu.com
3. What we collect
We collect only what the App needs in order to work. We do not collect data for advertising, profiling or resale.
| Category | Data | Why |
|---|---|---|
| Account data | Account identifier (an email address), password (stored only in hashed form), organization name. | To create and authenticate the account and to associate it with the correct Customer Organization. |
| Participant profile | Name, email address (optional), date of birth, gender, height, body weight. | To identify the Participant in class rosters and reports, and to calculate training metrics such as power-to-weight ratio and training zones. |
| Training data | Power, cadence, speed, distance, duration, heart rate, and derived values such as FTP, TSS and W/kg; the session, route or workout performed. | To display live data during a session, produce the training report, and let Participants and coaches review past sessions. |
| Device identifier | A hardware identifier of the computer on which the App is signed in. | Solely to enforce the one-device-at-a-time sign-in rule, so that an account cannot be used on several computers simultaneously. It is not used to build a profile, to recognise you across other apps or services, or for any analytics or advertising purpose. |
| Technical and log data | IP address, timestamps and error records generated when the App communicates with our servers. | To operate and secure the Service and to diagnose faults. |
Heart rate, body weight and the training metrics derived from them are health-related data, and are treated as a special category of personal data. Where consent is the basis for processing such data, the Customer Organization is responsible for obtaining the Participant’s explicit consent before entering the Participant into the App. As the controller of that data, the Customer Organization is responsible for the lawfulness of its collection.
Data from sensors
The App connects over Bluetooth Low Energy to training equipment such as smart trainers, power meters, cadence sensors and heart rate monitors. Bluetooth is used only to discover and communicate with these devices. It is not used for location, presence detection or advertising. Sensor readings are processed on your computer during a session and are stored as part of the training record described above.
4. What we do not collect or do
To be explicit, the App:
- does not display advertising and does not collect advertising identifiers or ad interaction data;
- does not track you across apps or websites operated by other companies, and does not share data with data brokers;
- does not offer sign-in through Apple, Google, Strava, WeChat or any other third-party or social login;
- does not offer in-app purchases and does not collect payment card or other financial data through the App;
- does not collect your location;
- does not include chat, messaging, public profiles or any other user-to-user or user-generated content feature;
- does not include any third-party analytics, advertising or crash-reporting software development kit;
- does not sell personal data.
5. How we use the data, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing the App and the Service to the Customer Organization and its Participants. | Performance of a contract; for Participant data, processing on behalf of the Customer Organization as controller. |
| Authenticating accounts and enforcing the one-device-at-a-time rule. | Performance of a contract; our legitimate interest in protecting accounts against misuse. |
| Emailing a training record to a Participant, when a coach chooses to send it. | Performance of a contract, on the instruction of the Customer Organization. |
| Processing health-related data (heart rate, body weight and derived metrics). | The Participant’s explicit consent, obtained by the Customer Organization. |
| Operating, securing and troubleshooting the Service. | Our legitimate interest in a functioning and secure service; legal obligation where applicable. |
We do not use personal data for automated decision-making that produces legal or similarly significant effects.
6. Who we share data with
We do not sell personal data and we do not disclose it for the marketing purposes of others. We share personal data only:
- with the Customer Organization that holds the account, which is the controller of Participant data;
- with the service providers (processors) listed below, each under a written contract that limits them to processing on our instructions;
- where required by law, or to establish, exercise or defend legal claims;
- in connection with a corporate transaction, such as a merger or acquisition, in which case we will give notice before personal data becomes subject to a different privacy policy.
Service providers
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Application servers and database | Asia Pacific (Tokyo), ap-northeast-1 — Japan |
| Amazon Web Services, Inc. — Amazon Simple Email Service (SES) | Delivery of training-record emails to Participants | US West (Oregon), us-west-2 — United States |
The App contains no third-party analytics, advertising or crash-reporting components, so no personal data is disclosed to providers of that kind.
7. International transfers
We are established in Taiwan, and we use Amazon Web Services to run the Service. Our application servers and database are located in Japan (Asia Pacific (Tokyo), ap-northeast-1). Emails containing training records are sent through Amazon Simple Email Service in the United States (US West (Oregon), us-west-2). Using the Service therefore involves the transfer of personal data to, and its processing in, Japan and the United States, whichever country you are in.
These transfers are governed by written data protection terms agreed with our service providers, including the standard contractual clauses those providers make available. If you would like more information about the safeguards applied to a particular transfer, write to us at official@whiizu.com.
8. How long we keep data
| Data | Retention |
|---|---|
| Account data | For the duration of the service agreement, then deleted or anonymised within 90 days. |
| Participant profiles and training records | Retained on the instruction of the Customer Organization; deleted on its instruction, or within 90 days of the end of the service agreement. |
| Technical and log data | 12 months. |
We may retain data for longer where a statutory retention period requires it, or where it is needed to establish, exercise or defend legal claims.
9. Security
We apply technical and organisational measures appropriate to the risk, including:
- encryption of personal data in transit between the App and our servers;
- storage of account passwords in hashed form only — we cannot read or recover your password;
- access control on a least-privilege, need-to-know basis for our personnel;
- the one-device-at-a-time sign-in rule, which limits the effect of a leaked credential.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your rights
Subject to the conditions and exceptions in applicable law, you have the right to be informed about and obtain a copy of the personal data we hold about you; to have inaccurate data corrected; to have data erased; to have processing restricted; to receive your data in a portable format; to object to processing based on our legitimate interests; to withdraw consent at any time, without affecting processing carried out before the withdrawal; and to lodge a complaint with a supervisory authority.
If you are a Participant, address these requests to the Customer Organization that enrolled you, as it is the controller of your training data. If you are an account holder, contact us directly. Either way, you may write to official@whiizu.com and we will respond, or route the request to the responsible controller, without undue delay and in any event within one month.
Account deletion
The App does not create accounts, and accordingly it does not delete them. Accounts are issued and withdrawn under the service agreement with the Customer Organization. To request that an account and its associated data be deactivated and erased, write to official@whiizu.com. We will act on the request in accordance with the service agreement and applicable law.
11. Children and minors
Minors may be enrolled as Participants — for example by a training studio or a school. Where a Participant is a minor under the law applicable to them, the Customer Organization is responsible for obtaining the consent of the parent or legal guardian before entering the minor’s personal data into the App, and for the lawfulness of that data’s processing as controller.
Accounts themselves are issued only to organizations and their staff, and are not made available to children.
12. Changes to this Policy
We may update this Policy from time to time. The current version is always available at this address, and the date at the top of the page shows when it was last changed. Where a change is material, we will give notice to Customer Organizations by email before it takes effect.
13. Contact
For any question about this Policy or about how we handle personal data:
TraniVerse Sports Technology Inc.
Email: official@whiizu.com