Privacy Notice
The Seishin Academy mobile app and closed platform are for registered and approved students, therapists and staff of the private school operated by SEISHIN TEAM S.R.L.
Effective: 6 September 2026 · Version 1.1
1. Controller
- SEISHIN TEAM S.R.L. (Seishin Academy), CUI 29043905
- Registered office: Str. Garoafei nr. 30, Sfântu Gheorghe, Covasna County, Romania
- Privacy and support: info@seishinmassage.com
2. Service
- The app is not a public social network. Access requires an approved account linked to Seishin Academy training. It supports education, administration and communication in a closed community.
- Users are responsible for content they share. Special-category or health data about another person must not be uploaded without a proper legal basis and authorization.
3. Data we process
- Account/contact: name, email, phone, date of birth, address, language and role.
- Profile: professional title, services, biography, photos, optional link and visibility.
- Education: courses, enrolment, practice, attendance, tests, results and progress.
- Finance/orders: fees, payment status, instalments, vouchers, orders and product options; no payment-card data is processed by the app.
- Content: posts, images, comments, reactions, saves, chat, reports and blocks.
- Technical/security: user/device IDs, platform, device, OS/app versions, language, time zone, push token, sessions, last activity, IP/user-agent fingerprints and security events.
- Notifications: language/platform, delivery, errors and message-opening status.
4. Purposes and legal bases
- Contract – GDPR Art. 6(1)(b): account, education, practice, tests, fees, orders, support and community.
- Legal obligation – Art. 6(1)(c): accounting, tax and authority duties.
- Legitimate interests – Art. 6(1)(f): security, abuse prevention, diagnostics, access control, service measurement, moderation and necessary institutional communication.
- Consent – Art. 6(1)(a): optional public profile and non-essential marketing; consent can be withdrawn at any time.
5. Push, access and processors
- iOS push permission is optional. Apple Push Notification service processes the device token and technical notification data. Necessary messages may remain in the bell inbox and web account.
- Only authorized staff can access account/study data; activity statistics are not public. Hosting, email and IT providers may be used. Data is not sold or used for cross-app advertising tracking. EEA transfers require a GDPR safeguard.
6. Retention
- Online account data is kept while the account operates. The minimum student records needed to verify completed courses, examination results, and issued certificates later are retained long term in a separate school record; accounting records are retained as required by Romanian law.
- Chat generally cleans history older than 90 days, but the latest 20 messages per conversation may remain. Feed content stays until deletion or account-deletion processing.
- Persistent mobile sessions may last up to 365 days. Push delivery/read data is kept for no more than 24 months unless law or a claim requires longer.
7. Deletion and security
- Request deletion directly in Settings – Delete account with the password and “TÖRLÉS” confirmation. The request is processed within 30 days and may be cancelled until then. App and web-account access is removed; the public profile, sessions, push identifiers and unneeded app data are erased or anonymized. The minimum school records needed to verify studies and certificates later, and mandatory financial records, remain segregated and are not used to restore the account, for community features, or for marketing.
- We use HTTPS, roles, token sessions, password hashing, security logs, backups and iOS Keychain.
8. Rights
- You may request access, a copy, correction, deletion, restriction and portability where applicable; object; and withdraw consent. We generally respond within one month.
- You may complain to ANSPDCP, 28–30 G-ral Gheorghe Magheru Blvd, District 1, Bucharest; dataprotection.ro. We do not use solely automated legal decisions, advertising IDs or cross-app tracking.