Skip to content
Kusties
Latviski English
Log in

Legal

Kusties Privacy Policy

  • Version: 2026-10-01
  • Effective: 1 October 2026
  • Published at: https://kusties.com/en/privacy
  • This is the English translation of the Latvian text published at https://kusties.com/privatuma-politika. If the translation differs, the Latvian version prevails.
Contents
  • 1. Who is responsible for your data
  • 2. What this policy covers
  • 3. Our role: controller or processor
  • 4. What data we process, why, and on what basis
  • 5. How long we keep data
  • 6. Who receives data
  • 7. Transfers outside the European Economic Area
  • 8. Your rights and how to exercise them
  • 9. Automated decisions
  • 10. How we protect data
  • 11. Cookies and browser storage
  • 12. Signing in with third-party accounts
  • 13. E-mails and SMS
  • 14. Children and minors
  • 15. Changes to this policy
  • 16. Contact

1. Who is responsible for your data#

The Kusties service (the website kusties.com, the web app kusties.app and the Kusties player app for Android devices) is provided by:

NameSIA "Kusties.com"
Registration number50203259371
Legal addressĀbolu iela 14C, Mārupe, Mārupes nov., LV-2167
VAT numberLV50203259371
E-mail for privacy matters[email protected]

In this policy, "Kusties", "we", "us" and "our" mean SIA "Kusties.com".

Data protection officer. We have not appointed a data protection officer. Please send any question about personal data to the e-mail address above.

2. What this policy covers#

This policy explains how we process personal data under Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, "GDPR") and the Latvian Personal Data Processing Law (Fizisko personu datu apstrādes likums). It applies to:

  • specialists and other Kusties users (physiotherapists, masseurs, doctors, sports trainers and others) who have an account in the kusties.app app;
  • visitors to kusties.com and people who fill in the website's request forms;
  • people who contact us;
  • payer contacts, once the billing feature is switched on;
  • patients and clients, to the extent that we ourselves are the controller (see section 3).

If you are a specialist's patient or client, the data your specialist enters into Kusties (for example notes, clinical documents, exercise programmes and appointments) is processed by your specialist as the controller. We process it only on the specialist's behalf (see subsection 3.2). More information for patients is in the patient notice: https://kusties.com/en/patients.

3. Our role: controller or processor#

3.1. When we are the controller#

We are the controller (we decide the purposes and means of processing) for:

  • the accounts, profiles and sign-in of specialists and other users, including two-step sign-in;
  • sign-in sessions and devices;
  • the security audit log;
  • the record of which documents, and which versions of them, you have accepted;
  • billing and invoices (when the feature is switched on);
  • account and service e-mails to users, and tips and marketing e-mails (when switched on);
  • the website kusties.com and its request forms;
  • communication with us and support;
  • patients' IP addresses, which we use for rate limiting and the security of the service, and the delivery of exercise videos and images on patient pages (subsection 4.13);
  • showing published exercises to other specialists (subsection 4.14);
  • the client cabinet (patient accounts) part, when it is switched on: the patient's account, the link between the account and the specialist's client record, and the record of consents and access.

3.2. When we are a processor#

A specialist who uses Kusties in their work (later also a clinic) is the controller of the data about their patients and clients. We process that data as a processor (GDPR art. 28), only on the specialist's behalf and under the data processing agreement (https://kusties.com/en/dpa), which is an annex to the Terms of Service (https://kusties.com/en/terms). This data is:

  • the client record: first and last name, e-mail address, phone number, contact language and birthday (if entered);
  • patient notes, clinical documents and the forms a patient fills in before a visit (/f/… links); these may contain a personal identity code (personas kods) and health data;
  • patient alert flags (for example about a pacemaker);
  • exercise programmes, the programme's private note, and the patient's completion entries with feedback;
  • appointments, reminders and messages we send to patients on the specialist's behalf, and the log of those messages.

The specialist determines the legal basis for this processing, including the basis for processing health data.

If you are a patient and wish to exercise your rights over this data, please contact your specialist. If you send your request to us, we will pass it on to the specialist and help them respond.

Access by Kusties staff. For support and maintenance, Kusties administrators (our staff) can open in the app specialists' client records, programmes, patients' completion entries and feedback, and appointments, and the log of messages sent to patients, which contains the recipient's contact details and the message content. Patient notes, clinical documents, patient alert flags and the programme's private note are visible only to the specialist who created them; in the app, administrators have no access to them; see also point 7.2(d) of the data processing agreement (persons with access to the infrastructure are technically able to access all data).

4. What data we process, why, and on what basis#

This section describes the processing for which we are the controller. A summary of retention periods is in section 5. Features that are not yet switched on at the date of this version are marked "(when switched on)"; until then, this data is not collected.

Where processing is based on our legitimate interests (GDPR art. 6(1)(f)), those interests are stated with the purpose. You may object to such processing (see section 8).

Your first and last name, e-mail address and password are needed to enter into the contract: without them an account cannot be created. Billing details (when billing is switched on) are needed to issue an invoice and to meet accounting requirements; without them a paid plan cannot be activated. Giving any other data (for example a phone number or a professional registry number) is voluntary.

4.1. Account and profile#

  • Data: first and last name, e-mail address, phone number, preferred language and colour theme; profession (also as free text), professional registry number, the date the profession was verified and the administrator who verified it.
  • Source: you, or the Kusties administrator who created your account. At present, accounts are created by an administrator; self-registration by e-mail will be available once it is switched on.
  • Purpose: creating and maintaining the account; providing the service; showing your first and last name in messages we send to your patients on your behalf (for example in an SMS reminder); showing your name and profession to patients in the client cabinet (when switched on).
  • Legal basis: performance of a contract (GDPR art. 6(1)(b)).
  • Retention: while the account is active. When an account is closed, it is deactivated; at present the data of a deactivated account is not deleted automatically.

4.2. Sign-in and two-step sign-in#

  • Data: a hash of your password (bcrypt; we do not store the password itself) and the account's security version number; if two-step sign-in is on, the encrypted authenticator-app secret and hashes of the recovery codes; hashes and expiry times of set-password and password-reset links; during the second sign-in step, a short-lived challenge with your IP address and browser and device description (user agent).
  • Purpose: verifying your identity at sign-in and protecting the account.
  • Legal basis: performance of a contract (GDPR art. 6(1)(b)) and legitimate interests (GDPR art. 6(1)(f)): protecting accounts, and the patient data held in them, against unauthorised access. Two-step sign-in is mandatory for administrators and optional for all other users.
  • Retention: the password hash, while the account exists; two-step sign-in data, until you switch it off or replace it; the second-step challenge, 5 minutes; a password-reset link is valid for 1 hour and a set-password link for 72 hours, and both are deleted 7 days after they expire or are used.

4.3. Sign-in sessions and devices#

  • Data: sign-in time, time of last activity, expiry, sign-out time and reason, sign-in method, IP address, browser and device description (user agent), device type, browser and operating system.
  • Purpose: account security; the "My devices" section, where you can see where your account is open and sign out any device; support.
  • Legal basis: legitimate interests (GDPR art. 6(1)(f)): detecting and preventing unauthorised access to the account and letting you manage your devices.
  • Who sees it: you; Kusties administrators, for the sessions of the accounts they manage.
  • Retention: a session record is deleted automatically 90 days after the session ended. A session ends after 7 days without activity, and at the latest 30 days after sign-in.

4.4. Security audit log#

  • Data: who performed an action (user identifier and role), the action, the identifier of its subject, technical details (identifiers and codes only) and the request identifier. For a failed sign-in, a reused sign-in token, password-related events and administrator actions, the request's IP address is also stored. A successful sign-in is recorded without the IP address.
  • Purpose: security of the service, investigation of incidents and accountability.
  • Legal basis: legitimate interests (GDPR art. 6(1)(f)): protecting the service and being able to show who performed security-relevant actions, and when.
  • Retention: at least 3 years. Entries cannot be changed. Automatic deletion after the period has not yet been built, so at present entries are kept with no end date.

4.5. Record of document acceptance#

  • Data: which document (Terms of Service, Privacy Policy, data processing agreement, client cabinet terms) and which version of it you accepted, how and when, and your IP address and browser and device description (user agent).
  • Purpose: proving that the documents were accepted, and knowing when to ask you to accept a new version.
  • Legal basis: legitimate interests (GDPR art. 6(1)(f)): being able to prove the terms of the contract; where processing is based on consent, also the legal obligation to be able to demonstrate consent (GDPR art. 6(1)(c) and art. 7(1)).
  • Retention: at present with no end date.

4.6. Account and service e-mails to users#

  • Data: e-mail address, name, language, the kind of message and the time it was sent.
  • Messages: set-password and password-reset links; security alerts (password changed, two-step sign-in switched off or reset, a recovery code used); a notice that a patient submitted a form (it names only the patient's first name); when switched on, trial, billing, SMS quota and data export notices.
  • Legal basis: performance of a contract (GDPR art. 6(1)(b)); for security alerts, also legitimate interests (GDPR art. 6(1)(f)): warning you of possible unauthorised access.
  • Retention: we do not store the content of these e-mails in our system. For some automatic e-mails we keep a record of the kind of message and the time it was sent, so that it is not sent twice; this record is kept while the account exists. The e-mail service provider keeps its own sending logs under its own retention policy.

4.7. Tips and marketing e-mails (when switched on)#

  • Data: e-mail address, name, your choice about marketing messages, an unsubscribe identifier, and information about your progress in setting up the account (for example whether tips are switched off).
  • Marketing e-mails are sent only with your consent (GDPR art. 6(1)(a)). The box on the registration form is not pre-ticked. You can withdraw your consent at any time through the unsubscribe link in the e-mail or by writing to us.
  • Tips on using the service during the trial are sent on the basis of legitimate interests (GDPR art. 6(1)(f)): helping you get started. Every tips e-mail has an unsubscribe link.
  • Account notices (for example about the end of the trial or an invoice) are sent regardless of these choices, because they are needed to perform the contract.
  • Marketing and tips messages are never sent by SMS.
  • Retention: while the account exists, or until you withdraw consent.

4.8. Billing and invoices (when switched on)#

  • Data: payer type (company, self-employed or private person); name of the business or first and last name; registration number (required only for companies; we do not collect the personal identity code); VAT number, the result and time of its check; address; country; e-mail address for invoices; plan, subscription, invoice numbers, periods, amounts and status, credit notes, SMS usage; a copy of the data submitted with the request; acceptance of the Terms of Service and the data processing agreement, with IP address and user agent.
  • Purpose: activating the plan, preparing invoices, recording payments, reminders about overdue payments, checking the VAT number.
  • Legal basis: performance of a contract (GDPR art. 6(1)(b)) and legal obligation (GDPR art. 6(1)(c)): accounting and tax requirements.
  • Who sees it: the account owner and the Kusties super administrator.
  • Recipients: the European Commission's VIES system (VAT number only); the accountant and the provider of the accounting software.
  • Retention: for as long as accounting and tax legislation requires.

4.9. One trial per person (when switched on)#

  • Data: a hash (HMAC-SHA-256) calculated from the normalised e-mail address with a secret key. We do not store the address itself for this purpose.
  • Purpose: making sure that a free trial is granted only once per e-mail address.
  • Legal basis: legitimate interests (GDPR art. 6(1)(f)): preventing abuse of the trial.
  • Retention: with no end date, also after the account is closed.

4.10. Visiting kusties.com#

  • Data: IP address, browser and device description (user agent) and the requested address, in the hosting provider's technical logs.
  • Purpose: running the website, delivering its content and keeping it secure.
  • Legal basis: legitimate interests (GDPR art. 6(1)(f)): making sure the website runs securely.
  • Retention: the technical logs are kept by the website's hosting provider for as long as its retention policy provides.
  • The website itself sets no cookies and uses no analytics or tracking; fonts are loaded from our own server. The links to Facebook, Instagram and LinkedIn are plain links: those platforms receive data only if you click the link.

4.11. Request forms on kusties.com#

  • Data: the "Pieteikt demo" (request a demo) form: e-mail address; the "Saņemt piedāvājumu klīnikai" (get an offer for a clinic) form: name, organisation, e-mail address and number of specialists.
  • Purpose: contacting you about a demo, or preparing an offer.
  • Legal basis: steps taken at your request before entering into a contract (GDPR art. 6(1)(b)). We will send marketing messages to this address only with your consent.
  • Recipient: Mailchimp (Intuit); the data is stored in the USA (see sections 6 and 7). Submitting the "Pieteikt demo" form opens a Mailchimp page in a new tab. The "Saņemt piedāvājumu klīnikai" form sends its data to Mailchimp without opening another page.
  • Retention: for as long as we need the request to contact you about the demo or the offer; we delete it if you ask us to.

4.12. Contacting us and support#

  • Data: name, e-mail address, the content of your message and any attachments you send us, and records of how the request was handled.
  • Purpose: answering questions, supporting users, handling data subject requests, and handling requests to remove content (for example a video).
  • Legal basis: legitimate interests (GDPR art. 6(1)(f)): answering questions addressed to us; performance of a contract (point (b)): user support; legal obligation (point (c)): data subject requests (GDPR arts. 12–22).
  • Retention: for as long as the correspondence is needed to resolve the matter, and afterwards for as long as it may be needed to prove that a request was handled or to defend legal claims.

4.13. Technical operation and security of kusties.app#

  • Data: the IP address, which we use to limit the number of requests (for example sign-in attempts, forms and SMS sending); technical logs with the request method, address, status, duration and identifier. No IP addresses, user agents, e-mail addresses, phone numbers, tokens or message content are written to the logs.
  • Purpose: running the service, fixing errors and protecting against abuse.
  • Legal basis: legitimate interests (GDPR art. 6(1)(f)): keeping the service running securely.
  • Retention: request counters expire automatically after 1 minute to 24 hours (depending on the limit); technical logs are kept by the hosting provider DigitalOcean under its own retention policy.
  • Patient pages (the programme link /workout/… and the form link /f/…): exercise videos and images are loaded from Cloudflare, which receives the visitor's IP address and user agent.
  • Android app: the Kusties player app stores only the chosen colour theme on the device. It uses no analytics or crash reports and communicates only with the Kusties servers and Cloudflare Stream (video).

4.14. Own exercises and videos (when switched on)#

  • Data: exercise texts, videos and their original file names, review decisions and their reasons. People may be visible in the videos.
  • Purpose: storing and showing your exercises, reviewing them for publication and removing content.
  • Legal basis: performance of a contract (GDPR art. 6(1)(b)), including the licence set out in the Terms of Service. The uploader confirms that they have the consent of every person shown in the video; a video must not allow a patient to be identified.
  • Role: if the video of a private exercise is patient data, Kusties processes it as a processor under the data processing agreement; showing published exercises to other specialists is processing by Kusties as controller.
  • Removal: anyone, including a person shown in a video or their legal representative (parent or guardian), can ask for a video to be removed by writing to [email protected]. After removal, the video is no longer shown in exercises and its playback is blocked.
  • Retention: exercises and their history are kept; videos are stored on Cloudflare Stream until an administrator deletes them.

4.15. Client cabinet (when switched on)#

A specialist can invite their patient to create an account in the client cabinet. There, the patient sees their programmes and appointments.

  • Data: e-mail address, password hash, first and last name and language; the link between the account and the specialist's client record (when and how it was made); invitation data (a hash of the link, the channel, partly masked contact details, a hash of the address, the number of attempts and the time of the birth-year check); invitation confirmation data (IP address and user agent); acceptance of the client cabinet terms and the privacy policy; completion entries the patient made; sessions, the audit log and optional two-step sign-in as in subsections 4.2–4.4.
  • Visible in the cabinet: programmes (without the specialist's private note), the patient's own completion entries, appointments (time, status and specialist, without the appointment title and description), the specialist's name and profession. Notes, clinical documents, alert flags and messages are never shown in the cabinet.
  • Unlinking: the patient or the specialist can remove the link between the account and the record at any time.
  • Legal basis: performance of a contract (GDPR art. 6(1)(b)) under the client cabinet terms.
  • Retention: an invitation link is valid for 14 days; a confirmation link for 24 hours, and its data is deleted 7 days after it expires. Other data: as in section 5.
  • More: the client cabinet terms (https://kusties.com/en/cabinet-terms) and the patient notice (https://kusties.com/en/patients).

5. How long we keep data#

We keep data only as long as needed for its purpose or as required by law. The current periods:

DataPeriod
Access token15 minutes
Sign-in session (refresh cookie)ends after 7 days without activity, at the latest 30 days after sign-in
Session records (IP address, device)90 days after the session ended, then deleted automatically
Security audit log (IP address on security events)at least 3 years; automatic deletion not yet built
Document acceptance records (IP address, user agent)at present with no end date
Password-reset / set-password linkvalid 1 hour / 72 hours; deleted 7 days after expiry or use
E-mail verification link (when registration is switched on)valid 24 hours; an unfinished registration is deleted 7 days after the link expired
Two-step sign-in datauntil switched off or replaced
Second-step challenge in the cache (IP address, user agent)5 minutes
Request counters (by IP address, e-mail hash or user)1 minute to 24 hours
Account and profile datawhile the account is active; at present not deleted after deactivation
Marketing choice and unsubscribe identifier (when switched on)while the account exists, or until consent is withdrawn
Trial-check hash (when switched on)no end date, also after the account is closed
Billing data and invoices (when switched on)for as long as accounting and tax legislation requires
Client cabinet invitation (when switched on)link valid 14 days; the record is kept
Invitation confirmation (when switched on)link valid 24 hours; deleted 7 days after expiry
Form link for a patient (/f/…)valid 14 days
A patient's unsent form answers in the patient's browseruntil the link expires
Requests from the kusties.com forms (Mailchimp)while needed to contact you about the request; deleted if you ask us to
Correspondence with uswhile needed to resolve the matter and to prove that the request was handled
Hosting and app technical logsunder the hosting provider's retention policy
Database backupswhile they are needed to restore data; deleted afterwards

Data we process as a processor (subsection 3.2) is kept according to the specialist's instructions and the data processing agreement. At present the app does not delete this data automatically: client records, notes, appointments and document drafts that a specialist deletes are marked as deleted, but the record remains; finalised clinical documents cannot be deleted; programmes are finished, not deleted; patient alert flags that a specialist deletes are deleted permanently; the log of messages sent to patients is kept with no end date. After the specialist's contract ends, this data is deleted manually under section 13 of the data processing agreement.

6. Who receives data#

We do not sell personal data and do not use it for advertising. We share data only with service providers that help us provide the service, and only as far as necessary:

RecipientRoleWhat dataLocation
DigitalOceanhosting: app, database, app logsall kusties.app dataEU, Frankfurt (Germany); company registered in the USA
Redis Cloud (Redis)short-lived cachehashes of sign-in tokens, request counters keyed by IP address, second-step challenges with IP address and user agent (5 minutes); no health dataEU, Frankfurt (Amazon Web Services)
Brevosending SMS and e-mailphone numbers, e-mail addresses, message contentFrance (EU); some of Brevo's sub-processors may be outside the EEA (see section 7)
Cloudflareexercise videos (Stream) and images (Images), delivery of kusties.com, and DNSvideos and images; the visitor's IP address and user agent when videos, images or the website loadglobal network; company registered in the USA
Mailchimp (Intuit)the kusties.com request formsthe data listed in subsection 4.11USA
VIES (European Commission), when billing is switched onVAT number checkthe VAT number onlyEU
Accountant and accounting software, when billing is switched onpreparing invoices and bookkeepinginvoice dataunder the accounting services agreement
Mailbox provider ([email protected])communicationcorrespondenceunder the mailbox provider's terms
Mobile network operators and recipients' e-mail providersdelivering messagesphone number or e-mail address, and the messagethe recipient's operator or provider
Sign-in providers, when switched onsee section 12
Public authorities and courtsonly where required by lawthe data requestedLatvia or another EU country

The full list of sub-processors for data we process on specialists' behalf is in the data processing agreement (https://kusties.com/en/dpa).

Backups. Database backups are currently made by hand before every database change is deployed, and are stored on the computer of the person responsible at Kusties; each copy is verified by restoring it into a separate temporary environment.

7. Transfers outside the European Economic Area#

The app's database and cache are located in the EU (Frankfurt, Germany). Some of our service providers are, however, connected with countries outside the European Economic Area (EEA):

ProviderConnection with a country outside the EEA
DigitalOceanUS company; data stored in the EU
CloudflareUS company; its global network handles requests in the nearest data centre
Mailchimp (Intuit)data stored in the USA
Redis Cloudthe provider's group of companies is outside the EEA; data stored in the EU (Frankfurt)
BrevoEU company; its sub-processors may be outside the EEA

When data goes to these providers, we rely on the mechanisms of Chapter V of the GDPR: a European Commission adequacy decision (GDPR art. 45), where a US company is certified under the EU-U.S. Data Privacy Framework, or standard data protection clauses adopted by the Commission (GDPR art. 46(2)(c)), included in the provider's data processing terms. You can request information about the specific safeguard, and a copy of it, by writing to [email protected].

8. Your rights and how to exercise them#

8.1. Your rights#

Under the GDPR you have the right:

  • to access your data (art. 15): to get confirmation of whether we process your data, and a copy of it;
  • to rectification (art. 16): you can correct most profile data yourself in the app; we make other corrections on request;
  • to erasure (art. 17), where there is no ground to keep the data;
  • to restriction of processing (art. 18), for example while we check the accuracy of the data;
  • to data portability (art. 20): to receive the data you provided to us in a structured, commonly used and machine-readable format. Once the "Lejupielādēt manus datus" (download my data) feature is switched on, you can do this in your profile; until then, we prepare the export on request;
  • to object (art. 21) to processing based on our legitimate interests. You can object to direct marketing at any time, and we will then stop sending such messages;
  • to withdraw consent at any time (art. 7(3)). This does not affect the lawfulness of processing before the withdrawal;
  • not to be subject to a decision based solely on automated processing (art. 22); see section 9.

8.2. How to exercise your rights#

  • Write to [email protected], preferably from the e-mail address linked to your account. If we have doubts about the requester's identity, we may ask for additional information (GDPR art. 12(6)).
  • We will reply without undue delay and at the latest within one month. If the request is complex or there are many requests, we may extend this by a further two months; we will tell you so within the first month (GDPR art. 12(3)).
  • Exercising your rights is free of charge. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on it (GDPR art. 12(5)).
  • In the app you can yourself: correct your profile; see and sign out devices in the "My devices" section; manage two-step sign-in; when switched on, unsubscribe from tips and marketing e-mails.

8.3. Closing and deleting an account#

At present an account is closed by a Kusties administrator at your request. A closed account is deactivated, and its data is not deleted automatically. We will assess a request to delete data under GDPR art. 17, taking into account our obligations to keep certain data (for example accounting records and the security audit log) and, for patient data, the instructions of the specialist as the controller. We will tell you our decision and the reasons for it.

8.4. For patients#

For data your specialist has entered into Kusties, please contact your specialist, who is the controller. If you write to us, we will pass your request on to the specialist and help them respond. You may also have rights to information about your treatment and your medical records under the Patients' Rights Law (Pacientu tiesību likums); your specialist provides for these. Once the client cabinet is switched on, you can remove the link between your account and the specialist's record yourself.

8.5. Complaint to the supervisory authority#

If you believe we process your data unlawfully, you have the right to lodge a complaint with the Data State Inspectorate (Datu valsts inspekcija, www.dvi.gov.lv) or with the supervisory authority of another EU member state where you live or work or where the alleged infringement took place (GDPR art. 77). We encourage you to contact us first, so that the matter can be resolved sooner.

9. Automated decisions#

We do not make decisions based solely on automated processing, including profiling, that produce legal effects for you or similarly significantly affect you (GDPR art. 22). We do not carry out profiling.

The service runs automatic rules that are needed for its operation and security:

  • limits on the number of requests, and limits on sign-in attempts;
  • automatically ending a programme on the day after its end date;
  • a daily limit on sending SMS;
  • when switched on: a plan change after the trial or a paid period ends; one trial per e-mail address; refusal of client cabinet invitations for minors, and a birth-year check with a limited number of attempts.

If you believe one of these rules has affected you unfairly, write to us, and a person will review the situation.

10. How we protect data#

We use technical and organisational measures appropriate to the sensitivity of the data (GDPR art. 32). The main ones:

  • Location. The app's database and cache are in the EU (Frankfurt).
  • Encrypted connection. Connections to kusties.app and kusties.com are encrypted (HTTPS).
  • Encryption of the most sensitive data. Patient notes, clinical documents, patient alert flags, the programme's private note and two-step sign-in secrets are stored in the database encrypted (AES-256-GCM) with a key that is not stored in the database. Other data, for example client names and contact details, birthdays, appointment titles and descriptions, programme names, patient feedback and the message log, is not separately encrypted.
  • Passwords and links. We store passwords only as hashes (bcrypt). For one-time links (setting and resetting a password, forms, invitations) we store only a hash, and each link is valid for a limited time.
  • Two-step sign-in is mandatory for administrators and available to all users. Sensitive administrator actions and the data export require a sign-in within the last 10 minutes (with the second step if two-step sign-in is on or the role requires it); the export also requires the password to be entered again.
  • Access control. Each specialist sees only their own records. In the app, notes, clinical documents and alert flags can be opened only by their author, and administrators have no access to them; see also point 7.2(d) of the data processing agreement (persons with access to the infrastructure are technically able to access all data). For administrator access, see subsection 3.2.
  • Session control. In the "My devices" section you can sign out any device. After a password change, an account block, or a change of role or e-mail address, all sessions are closed.
  • Limits against abuse. Sign-in attempts, forms, and e-mail and SMS sending are limited in number.
  • Personal data in logs. The technical logs contain no IP addresses, e-mail addresses, phone numbers, tokens or message content.
  • Message content. SMS and reminders contain no appointment title, patient name or health data (for appointment e-mails, see section 13).
  • Backups are made before every database change is deployed, and each is verified (see section 6).

The patient link is personal. Anyone who has a programme link can open the programme and record a completion. Specialists should therefore send the link only to the patient, and patients should keep it safe.

Breaches. If a personal data breach occurs, we will act under GDPR arts. 33 and 34: where required, we will notify the Data State Inspectorate within 72 hours at the latest, and inform the people affected if the breach is likely to result in a high risk to their rights and freedoms. As a processor, we will inform the specialist without undue delay.

11. Cookies and browser storage#

11.1. kusties.com#

The website kusties.com itself sets no cookies and uses no browser storage. It uses no analytics, advertising or tracking tools. When you submit the "Pieteikt demo" form, a Mailchimp page opens, where Mailchimp may set its own cookies under its own privacy policy. The "Saņemt piedāvājumu klīnikai" form sends its data to Mailchimp without opening another page. Cloudflare, which runs and delivers the website, may set strictly necessary cookies for security purposes.

11.2. kusties.app#

kusties.app uses only cookies and browser storage that are needed for the service to work or that remember your choices. None of them is used for analytics or advertising.

NameTypeWhat it holdsHow longWhy
refresh_tokencookie (HttpOnly, Secure)the refresh token7 daysto keep you signed in
__Host-oauth_statecookie (HttpOnly, Secure)the sign-in state10 minutesprotection when signing in with a third-party account; only when that option is switched on
localecookiethe language code1 yearinterface language
workout (legacy)cookiea workout draft from older app versionsdeleted on the next visitmigration to browser storage
accessTokenlocalStoragethe access token (valid 15 minutes)until sign-outrequests to the app
kusties-sessionlocalStoragethe flag "1"until sign-outshows that a session may exist
theme, workout-theme, locale, videos-paused, billing-banner-dismissedlocalStorageyour choicesuntil storage is clearedremembering choices
workoutlocalStoragethe workout being built (exercises, name, description)until saved or signed outso the draft is not lost
kusties-form-draft:…localStorage in the patient's browserunsent form answers, which may include health datauntil the form link expiresso the answers are not lost when the page reloads
kusties-doc-unsaved:…, kusties-doc-open:…sessionStorage in the specialist's browserunsaved changes to a clinical document; which sections are openuntil the tab is closedautosave
kusties-registrationsessionStoragethe e-mail address and time sentuntil the tab is closedonly when registration is switched on
kusties-mfasessionStoragethe second-step challengeuntil the tab is closedtwo-step sign-in
Cloudflare Stream video playerthird partytechnical data needed to play the videounder Cloudflare's termsvideo playback

A tip for patients. If you fill in a form on a shared computer, close the browser or clear its data after submitting, because unsent answers stay in the browser until the link expires.

11.3. Android app#

The Kusties player app stores only the chosen colour theme (workout-theme) on the device.

11.4. Analytics#

At present neither kusties.com nor kusties.app uses analytics, advertising or tracking cookies or scripts. If we ever want to add them, we will first update this policy and add a consent banner: such tools will load only after you consent, and never on patient, client cabinet or sign-in pages.

12. Signing in with third-party accounts#

At the date of this version, signing in with third-party accounts is not available. This section will apply to users who choose this option once it is switched on:

  • we will receive from the provider your unique identifier with that provider, your e-mail address, your name and a link to your profile picture;
  • we do not receive your password for that provider;
  • the provider learns that you sign in to Kusties and processes that data as a separate controller under its own privacy policy;
  • legal basis: performance of a contract (GDPR art. 6(1)(b));
  • during sign-in, the cookie __Host-oauth_state is set for 10 minutes (see subsection 11.2);
  • when you add a new sign-in method to your account, we send a security notice to your e-mail address;
  • you can remove the link with the provider in your profile; the data is kept while the link or the account exists.

13. E-mails and SMS#

All e-mails are sent from [email protected]. SMS messages and e-mails are sent by Brevo (see section 6).

13.1. Messages to users (Kusties is the controller)#

Account and security e-mails and, when switched on, trial, billing, tips and marketing e-mails, as described in subsections 4.6 and 4.7. No SMS is sent to specialists.

13.2. Messages to patients on the specialist's behalf (Kusties is a processor)#

MessageChannelContent
Appointment created, changed or cancellede-mailthe appointment time, status, the specialist's name, and the appointment title and description written by the specialist; a calendar file (.ics) with the specialist's and client's names and the appointment title and description may be attached to the created and changed e-mails. Sent by default if the patient has an e-mail address; the specialist can choose not to send it.
Appointment series created, changed or cancellede-maildates, times and the specialist's name only
Appointment reminder 24 hours beforeSMS; e-mail when switched ondate, time and the specialist's name; no appointment title, patient name or health data
Form to fill in before a visite-mail or SMSthe specialist's name and a link valid for 14 days
Invitation to the client cabinet (when switched on)e-mail or SMSthe specialist's name and a link valid for 14 days

Every message sent to a patient is recorded in the message log: the channel, the recipient's e-mail address or phone number, the message content (without one-time links), language, purpose, status and cost. The log serves as proof of sending and for cost accounting, and is kept with no end date (see section 5).

14. Children and minors#

  • Specialist accounts may be created only by adults (clause 4.2 of the Terms of Service); age is not checked when an account is created.
  • The website kusties.com is not directed at children.
  • Patients may be minors. Their data is entered by, and is the responsibility of, the specialist as the controller, including through the parent or guardian (legal representative) consent form, which holds their name, personal identity code, status and contact details.
  • Client cabinet (when switched on): an invitation needs the patient's birthday. No invitation can be sent to a person under 14. At present no invitation can be sent to a person aged 14 to 17 either.

15. Changes to this policy#

We update this policy when the service, our service providers or the law change. Each version has a number and an effective date, shown at the top of the document. The app records which version of the policy you accepted. We will inform registered users of material changes by e-mail or in the app before the changes take effect. If a change needs your consent (for example adding analytics), we will ask for it separately.

16. Contact#

SIA "Kusties.com"
Registration number: 50203259371
Legal address: Ābolu iela 14C, Mārupe, Mārupes nov., LV-2167
VAT number: LV50203259371
E-mail: [email protected]

Supervisory authority: Data State Inspectorate (Datu valsts inspekcija), www.dvi.gov.lv.

Kusties

Exercise programmes that patients actually do. Built for physiotherapists, coaches and clinics.

Product

  • Home page (in Latvian)
  • Create your first programme

Legal

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement
  • For patients
  • Client cabinet terms

Contact

  • [email protected]
  • +371 22 322 885
  • Log in
© 2026 Kusties. All rights reserved. SIA "Kusties.com", reg. No. 50203259371, VAT LV50203259371, Ābolu iela 14C, Mārupe, Mārupes nov., LV-2167