Legal

Misura Privacy Policy

  • Document: Privacy Policy (privacy-policy)
  • Canonical version: Spanish (it prevails in case of conflict with any translation, unless mandatory law in your jurisdiction requires otherwise).
  • Available translation: English (this document).
  • Data controller: Rafael Antonio Berrios Cuneo
  • Address: Tacna, Perú
  • Privacy contact: rafoantoni@gmail.com
  • Website: misura-app.com
  • Effective date: August 7, 2026
  • Governing law (primary): Peru, without prejudice to the mandatory rights of your jurisdiction (see Section 25).

This Privacy Policy (the "Policy") forms part of, and is incorporated by reference into, the Misura Terms of Service (the "Terms"). Capitalized terms not defined here have the meaning given to them in the Terms. In the event of a conflict between this Policy and the Terms regarding privacy and data protection matters, this Policy prevails.


1. Introduction and Scope

1.1. Who we are. Misura ("Misura", "we", "us" or "our") is a nutrition and training (running and gym) tracking application available as a mobile app for iOS and Android and as a website and web app at misura-app.com (together, the "Service"). The controller of the personal data described in this Policy is Rafael Antonio Berrios Cuneo, with its address at Tacna, Perú.

1.2. What this Policy covers. This Policy describes what personal data we process, for what purposes, on what legal bases, with whom we share it, how long we retain it, how we protect it, how we perform international transfers, and what rights you have depending on your jurisdiction, and how to exercise them.

1.3. Worldwide scope. The Service is available worldwide. This Policy is intended to comply, to the maximum extent permitted by applicable law, with a range of data protection regimes, including: the EU General Data Protection Regulation (GDPR) and the UK GDPR; the California Consumer Privacy Act and the California Privacy Rights Act (CCPA/CPRA); Brazil's Lei Geral de Proteção de Dados (LGPD); Canada's Personal Information Protection and Electronic Documents Act (PIPEDA); Peru's Law No. 29733, Personal Data Protection Law, and its regulations (Law 29733); and Australia's Privacy Act and the Australian Privacy Principles (Privacy Act / APPs). Section 13 details the specific rights under each regime.

1.4. What this Policy does NOT cover. This Policy does not cover the processing of data by third parties whose services you voluntarily connect (e.g. intervals.icu, Strava, Garmin, Hevy, Apple, Google), which are governed by their own privacy policies. See Sections 4.7, 16 and 21.

1.5. Acceptance. By creating an account, accessing or using the Service, you confirm that you have read and understood this Policy. Where the law requires consent (in particular for special-category/sensitive data, see Section 7), we will obtain it separately and expressly; use of the Service does not substitute for such consent where it is legally required.


2. Definitions

2.1. "Personal data" (or "personally identifiable information", "personal information", depending on the applicable regime): any information relating to an identified or identifiable natural person.

2.2. "Health, fitness and nutrition data" or "special-category data": data concerning physical health, physical condition, sporting activity and dietary intake, including body weight, muscle composition and volume, workouts, heart rate (where applicable via integrations), running GPS routes, food intake, hydration, goals and derived metrics. We treat this data as special category under Article 9 GDPR and as sensitive personal information under the CPRA, LGPD, Law 29733 and other applicable regimes, even where a particular regime does not formally classify it as such.

2.3. "Processing": any operation performed on personal data (collection, recording, organization, storage, adaptation, consultation, use, disclosure, transfer, restriction, erasure or destruction).

2.4. "Processor" / "service provider" / "sub-processor": a third party that processes personal data on behalf of and under the instructions of Misura.

2.5. "UGC" / "user-generated content": content that you create, upload or submit through the Service (see Section 4.4).

2.6. "You" / "User": the natural person who uses the Service.


3. Summary (non-binding)

This summary is indicative and does not replace the full text:

  • You can use much of the Service with an offline-first model: much of the data is stored first on your device and syncs when there is connectivity (Section 8).
  • We treat your health, fitness and nutrition data as special-category/sensitive and, where the law requires it, on the basis of your explicit consent (Section 7).
  • Analytics (Mixpanel) and error reporting (Sentry) are enabled by default but are opt-out: you can disable them in settings (Sections 4.6 and 17).
  • We do not sell your personal data nor do we "share" it for cross-context behavioral advertising (Section 9.4).
  • Data that Misura obtains from Apple Health / Health Connect is not used for advertising and is not shared with third parties for advertising purposes (Section 16).
  • You have rights over your data and can exercise them by writing to rafoantoni@gmail.com (Sections 13 and 14).

4. Data We Collect

We collect the following categories of data. Not all apply to every user: they depend on the features you use and the integrations you connect.

4.1. Account and authentication data

  • Name or alias, email address, password (stored only as a salted hash), language and account preferences.
  • If you sign up via Sign in with Apple or Google, we receive a unique provider identifier and your email address (or a private relay email if Apple offers it); we do not receive your provider password.
  • Account metadata: creation date, verification status, session and refresh tokens, and login history relevant to security.

4.2. Health, fitness and nutrition data (special-category/sensitive)

Entered by you or derived from your use, including:

  • Physical profile: age or date of birth, sex or gender, height, weight and weight history, activity level, goals (loss/gain/maintenance), declared allergies and intolerances.
  • Nutrition: foods and meals logged, quantities, macronutrients and micronutrients, hydration, saved recipes and calculated calorie and macro goals.
  • Training (running and gym): sessions, sets, reps, loads, volume and muscle groups, performance and load metrics (e.g. acute/chronic training loads), and personalized plans generated by Misura's planning engine.
  • Derived metrics and estimates calculated from the above.

We treat all this data as special-category data (Article 9 GDPR) and sensitive personal information under the other regimes.

4.3. Location / GPS data (runs)

  • When you record a GPS run, we collect precise location data (coordinates, route, distance, pace, altitude and timestamps) to calculate and display the activity.
  • Location collection only occurs when you explicitly start an activity that requires it, or when you import an activity with a track from a connected integration.
  • You can revoke the location permission in your operating system settings at any time; doing so may limit route-tracking features.

4.4. User-generated content (UGC)

The Service allows you to create and submit content, including:

  • User-created foods and "request a food" submissions (so that we expand the catalog).
  • Custom recipes and saved routines.
  • Shareable activity image-cards (images summarizing an activity or progress) that you can share within or outside the Service.
  • Comments, ratings, reports and support communications.

Please note that:

  • UGC may contain health, fitness or nutrition data; you decide what you include and with whom you share it.
  • If you share an activity card or other content outside the Service (social media, messaging, etc.), that content becomes subject to those platforms' policies and may fall outside our control.
  • UGC that you submit to improve shared catalogs (e.g. "requested" or created foods that are incorporated into the shared database) may be processed in anonymized or aggregated form and dissociated from your identity. Deletion of your account does not require the withdrawal of already-anonymized or aggregated contributions that do not allow you to be re-identified, to the maximum extent permitted by applicable law (see Section 11).
  • Content complaints (including intellectual-property claims and takedown notices) are handled in accordance with the Terms and through the designated agent: Rafael Antonio Berrios Cuneo, rafoantoni@gmail.com, Tacna, Perú.

4.5. Device and technical data

  • Device and app-installation identifiers, device type and model, operating system and version, app version, language and locale, time zone and carrier or network type (where applicable).
  • IP addresses and connection data, processed for security, fraud prevention and diagnostic purposes.
  • Technical logs and diagnostic and performance data.

4.6. Usage and analytics data (opt-out)

  • We collect usage events and interaction metrics to understand how the Service is used and to improve it. We use Mixpanel (product analytics) and Sentry (error and performance reporting).
  • This collection is enabled by default but is opt-out: you can disable it in the Service settings. Where applicable law requires prior (opt-in) consent for non-essential analytics, we will honor that requirement in your jurisdiction.
  • We aim to minimize and, where possible, pseudonymize or anonymize this data. Data strictly necessary for the security and operation of the Service may be processed even if you disable analytics, on the basis of legitimate interest or performance of the contract (Section 7).

4.7. Data from third-party integrations

If you connect an integration, we process the data you authorize to exchange:

  • intervals.icu (via OAuth): when you sign in or sync, we may import and/or export training metrics, activities, weight and load data. Data originating from Strava and Garmin may flow through intervals.icu if you have connected them there. Misura sends to intervals.icu only the data you authorize (e.g. weight).
  • Hevy: import of strength workouts and associated data.
  • Apple Health (HealthKit) and Android Health Connect: exchange of data such as weight (read/write), nutrition (write, one-way) and workouts (import, with deduplication). See the special handling in Section 16.

The exact scope of each integration depends on the permissions you grant and may vary. Data imported from these sources is processed in accordance with this Policy once incorporated into the Service; its processing on the source platform is governed by the third party's policy.

4.8. Communications and support data

  • When you write to us (e.g. at rafoantoni@gmail.com), we retain the content of your message, your email address and associated metadata to handle your request and for security and record-keeping.
  • Notification and communication preferences.

4.9. Payment data (applies once subscriptions are activated)

Note: As of the effective date, Misura does not process payments or offer subscriptions. The following provisions apply only once in-app purchases (IAP) or subscriptions are activated.

  • Once activated, payments will be processed through Apple App Store, Google Play and/or Stripe. Misura does not store full card numbers or payment credentials.
  • We may process subscription-status data (plan, active/canceled status, renewal dates, transaction identifiers) to provide and manage the payment service and to comply with accounting and tax obligations.

4.10. Data we do not require

  • We do not require special-category data unrelated to the purpose of the Service, nor do we deliberately collect data from minors (Section 15).
  • We do not ask you to enter identity-document numbers, except where strictly necessary to comply with a legal obligation.

5. Sources of Data

We obtain personal data from: (a) you directly (registration, use, UGC, communications); (b) your device (technical data and, with your permission, camera and location); (c) sign-in providers (Apple, Google); (d) integrations you connect (Section 4.7); and (e) our own systems (derived metrics, security and diagnostic logs).


6. Purposes of Processing

We process your data for the following purposes:

6.1. Provision of the Service: create and maintain your account; calculate calorie, macro and micro goals; generate personalized meal suggestions and training plans; log nutrition, weight, workouts and runs; sync your history across devices.

6.2. Image- and text-based features: food recognition from photos (processed on the device via a local vision model and/or on our servers) and interpretation of natural-language food descriptions.

6.3. Integrations: import and export data to and from the services you connect (Section 4.7).

6.4. User-generated content: process and, where applicable, publish or incorporate your UGC (Section 4.4).

6.5. Service improvement: product analytics, debugging, performance measurement and development of new features (opt-out, Section 4.6).

6.6. Security and fraud prevention: protect the integrity of the Service, detect and prevent abuse, unauthorized access and incidents.

6.7. Communications: send you transactional and service messages (verification, password changes, important notices) and, only with your consent where the law requires it, marketing communications (Section 19).

6.8. Legal compliance: comply with legal obligations, respond to valid requests from authorities, and establish, exercise or defend legal claims.

6.9. Billing (once subscriptions are activated): manage subscriptions, payments and accounting and tax obligations.

We will not process your data for purposes incompatible with the above without informing you and, where applicable, obtaining your consent.


7. Legal Bases for Processing (GDPR/UK GDPR and equivalents)

Where the GDPR, the UK GDPR or equivalent regimes apply, we process your personal data on the following bases (Article 6 GDPR) and, for special-category data, on the conditions of Article 9 GDPR:

Purpose (Section 6) Legal basis (Art. 6) Special-category data (Art. 9)
Provision of the Service (6.1) Performance of the contract (Art. 6(1)(b)) Explicit consent (Art. 9(2)(a))
Food image/text (6.2) Performance of the contract (Art. 6(1)(b)) Explicit consent (Art. 9(2)(a))
Integrations (6.3) Consent (Art. 6(1)(a)) and/or performance of the contract Explicit consent (Art. 9(2)(a))
UGC (6.4) Performance of the contract and/or consent Explicit consent where it includes health data
Service improvement / analytics (6.5) Consent (Art. 6(1)(a)) or legitimate interest (Art. 6(1)(f)) depending on jurisdiction Explicit consent if health data is processed
Security and anti-fraud (6.6) Legitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) Where applicable, vital interest or defense of claims
Communications (6.7) Performance of the contract (transactional); consent (marketing) Not applicable unless the content includes it
Legal compliance (6.8) Legal obligation (Art. 6(1)(c)); defense of claims Art. 9(2)(f) (claims) where applicable
Billing (6.9) Performance of the contract and legal obligation Not applicable

7.1. Explicit consent for health data. Because Misura processes health, fitness and nutrition data as special category, we will obtain your explicit consent for its processing where the law requires it. You may withdraw your consent at any time (Section 14); withdrawal does not affect the lawfulness of prior processing or other applicable legal bases, and may prevent the provision of features that depend on such data.

7.2. Legitimate interest. Where we invoke legitimate interest, we have balanced that interest against your rights and freedoms and only apply it where the latter do not prevail. You may object to processing based on legitimate interest (Section 13.1).


8. Offline-First Nature and On-Device Processing

8.1. Misura is offline-first: much data is generated and stored first on your device and syncs with our servers when there is connectivity. While it remains only on your device, control of that data also depends on your own device's security measures.

8.2. Certain features (e.g. food recognition from photos via a local vision model) may run wholly or partially on the device. Where processing requires our servers, images are handled only for as long as necessary for the purpose and are not stored permanently (Section 11).


9. Processors and Sub-processors (Who We Share With)

9.1. Principle. We share personal data only with providers that render essential technical services to us, under contract and with adequate protection safeguards (including data-processing clauses and, where applicable, standard contractual clauses), and only to the extent necessary for the described purposes.

9.2. Main processors and sub-processors (the list may be updated; consult the current version):

Provider Function Location (indicative) Transfer safeguard
Supabase Database, authentication, storage (incl. images during processing) EU (Ireland) and/or other regions Adequacy / SCCs by region
Sentry Error and performance reporting USA SCCs / adequacy frameworks
Mixpanel Product analytics (opt-out) USA SCCs / adequacy frameworks
Apple App distribution, Sign in with Apple, HealthKit, and (once activated) IAP payments USA / global SCCs / adequacy frameworks
Google App distribution, sign-in, Health Connect, and (once activated) payments USA / global SCCs / adequacy frameworks
Stripe (once payments are activated) Payment processing USA / global SCCs / adequacy frameworks
intervals.icu Training integration (per your connection) Per the provider User-initiated connection
Hevy Strength-workout integration Per the provider User-initiated connection
Anthropic Interpretation of natural-language food descriptions (Claude model) USA SCCs
Embeddings / compute providers (e.g. OpenAI, Modal) Semantic search and supporting AI features USA SCCs
Public food databases (e.g. OpenFoodFacts, FatSecret) Food catalog Global Anonymous lookups; they do not receive your personal data

9.3. Other recipients. We may disclose personal data: (a) to professional advisers (legal, accounting) bound by confidentiality; (b) to public authorities where required by a legal obligation or a valid request; (c) in the context of a corporate transaction (merger, acquisition or asset sale), in which case the acquirer will be bound by privacy commitments no less protective; and (d) with your consent or following your instructions.

9.4. We do not sell your data. Misura does not sell personal data for money or other valuable consideration, and does not "share" it for cross-context behavioral advertising, within the meaning of the CCPA/CPRA and equivalent regimes. Nor do we use health data for advertising (Section 16).


10. International Transfers

10.1. Given the worldwide scope of the Service, your data may be processed and stored in countries other than yours, including the USA and others outside the European Economic Area (EEA), the UK, Brazil, Canada, Peru or Australia, whose laws may offer a different level of protection.

10.2. When we transfer data from the EEA, the UK or Switzerland to countries without an adequacy decision, we rely on adequate safeguards, principally the European Commission's Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum where applicable), together with supplementary measures where necessary. For transfers from other jurisdictions we use the transfer mechanisms required by local law.

10.3. You may request information about the applicable safeguards by writing to rafoantoni@gmail.com.


11. Data Retention

11.1. General principle. We retain personal data only for as long as necessary for the purposes for which it was collected, to comply with legal obligations, resolve disputes and enforce our agreements.

11.2. Active account. We retain your account data and your content while your account is active.

11.3. Account deletion. If you request deletion of your account (in the Service settings or by writing to rafoantoni@gmail.com), we will delete or anonymize your personal data within a target period of up to 30 days, except for data we must retain by legal obligation (e.g. billing records once payments are activated) or to establish, exercise or defend claims.

11.4. Food images. Not stored permanently; retained only for as long as necessary for processing (Section 8.2).

11.5. Technical logs and analytics. Error logs and telemetry are retained for limited periods (indicatively, up to 90 days for diagnostic logs), unless they must be retained longer for security or by legal obligation.

11.6. Backups. Data may persist in encrypted backups for a limited additional period until rotation, after which it is deleted or rendered inaccessible.

11.7. Anonymized or aggregated UGC. Contributions incorporated in anonymized or aggregated form into shared catalogs (Section 4.4) may be retained indefinitely where they no longer allow you to be re-identified.


12. Security

12.1. We apply reasonable technical and organizational measures appropriate to the risk, including: encryption in transit (TLS 1.2 or higher); encryption at rest in the database; Row-Level Security (RLS) to isolate each user's data; authentication via rotatable tokens; role-based access control and least privilege; and audit logging of sensitive changes.

12.2. No security measure is infallible. To the maximum extent permitted by applicable law, we do not guarantee absolute security. You contribute to security by protecting your credentials and your device.

12.3. Responsible disclosure. If you discover a vulnerability, write to us at rafoantoni@gmail.com and we will treat it as a priority.

12.4. Breach notification. In the event of a security breach affecting personal data, we will notify the authorities and affected users within the deadlines and under the conditions required by applicable law (Section 20).


13. Your Rights Depending on Your Jurisdiction

Regardless of your location, we aim to offer you the basic rights of access, rectification and deletion with respect to your personal data, to the maximum extent permitted by applicable law. In addition, depending on your jurisdiction, you have the following rights.

13.1. EEA and United Kingdom (GDPR / UK GDPR)

You have the right to: (a) access; (b) rectification; (c) erasure ("right to be forgotten"); (d) restriction of processing; (e) portability (receive your data in a structured, commonly used and machine-readable format); (f) objection to processing based on legitimate interest or for direct marketing; (g) not to be subject to solely automated decisions with legal or similarly significant effects (Section 18); and (h) to withdraw consent at any time. You may lodge a complaint with your supervisory authority (e.g. the AEPD in Spain or the ICO in the UK).

13.2. California (CCPA/CPRA)

If you are a California resident, you have the right to: (a) know/access the categories and specific pieces of personal information collected, the sources, the purposes and the recipients; (b) delete personal information; (c) correct inaccurate information; (d) opt out of the sale or sharing ("Do Not Sell or Share My Personal Information") — although Misura does not sell or share personal information (Section 9.4), so this option is not necessary; (e) limit the use and disclosure of sensitive personal information — Misura does not use or disclose sensitive information beyond the permitted purposes that do not trigger this right; and (f) to non-discrimination for exercising your rights.

  • Categories of personal information collected (under California Civil Code §1798.140): identifiers (e.g. name, email, device identifiers); customer records information; protected characteristics (e.g. age/sex, to the extent you provide them); commercial information (subscription status, where applicable); network/usage activity; precise geolocation (GPS runs); sensory data (food images during processing); and inferences. Sensitive personal information includes health data and precise geolocation.
  • Verifiable and authorized requests: see Section 14. California residents may use an authorized agent.

13.3. Brazil (LGPD)

You have the right to: confirmation of the existence of processing; access; correction; anonymization, blocking or deletion of unnecessary data or data processed in breach; portability; deletion of data processed with consent; information about the entities with which data was shared; information about the possibility of not consenting and the consequences thereof; and revocation of consent. You may contact our data protection officer (see Section 22) and lodge a complaint with the ANPD.

13.4. Canada (PIPEDA)

You have the right to access your personal information and to request its correction, and to know how it is used and disclosed. You may withdraw consent subject to legal or contractual restrictions. You may file a complaint with the Office of the Privacy Commissioner of Canada (OPC).

13.5. Peru (Law No. 29733)

You have the ARCO rights: access, rectification, cancellation and objection, in addition to the rights of information and objective processing. The processing of sensitive data (including health data) requires your prior, express, informed and unequivocal consent. You may exercise your rights before Rafael Antonio Berrios Cuneo and, where applicable, turn to the National Authority for the Protection of Personal Data of Peru.

13.6. Australia (Privacy Act / APPs)

You have the right to access your personal information and to request its correction under the Australian Privacy Principles. You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

13.7. Other jurisdictions

If your jurisdiction recognizes additional or different rights (e.g. other US states or other countries), we will honor them to the extent they apply to us. Write to us at rafoantoni@gmail.com.


14. How to Exercise Your Rights

14.1. Primary channel. Write to rafoantoni@gmail.com indicating the right you wish to exercise. Some actions (e.g. correcting your profile or deleting your account) can be performed directly in the Service settings.

14.2. Verification. To protect your data, we may request reasonable information to confirm your identity before processing the request. We will not use such information for other purposes.

14.3. Authorized agents. Where the law permits, you may act through an authorized agent, with due proof of their authorization.

14.4. Timelines. We will respond within the timelines required by applicable law (generally, up to 30 days; in California, within the CCPA/CPRA timelines; under other regimes, per their rules), which may be extended where the law permits, informing you accordingly.

14.5. Free of charge and limits. Exercising rights is, as a general rule, free of charge. We may charge a reasonable fee or refuse to act on manifestly unfounded or excessive requests, to the maximum extent permitted by law.

14.6. Non-discrimination. We will not treat you in a discriminatory manner for exercising your rights.


15. Minors and Age Verification

15.1. The Service is not directed to persons under 16 years of age (or the higher minimum age required by your jurisdiction). We do not knowingly collect data from minors below the applicable age without the verifiable consent of the holder of parental responsibility where the law requires it.

15.2. If we become aware that we have processed a minor's data without an appropriate legal basis, we will promptly delete the account and associated data. If you believe a minor has provided us with data, contact us at rafoantoni@gmail.com.

15.3. For US users, we do not knowingly collect data from children under 13 (COPPA).


16. Special Handling of Apple Health and Health Connect

16.1. Data that Misura obtains from Apple Health (HealthKit) and from Android Health Connect is used exclusively to provide you with health and fitness features within the Service (e.g. syncing weight, importing workouts or writing nutrition data that you authorize).

16.2. In accordance with Apple's and Google's policies, data obtained from these sources:

  • is not used for advertising or marketing purposes;
  • is not shared or sold to third parties, data brokers, or for advertising;
  • is not used for data mining unrelated to your health and fitness; and
  • is disclosed to third parties only with your consent or where required by law.

16.3. You can revoke Apple Health or Health Connect permissions at any time from your operating-system settings; doing so will stop future data exchange with those platforms.


17. Cookies and Analytics on the Website

17.1. The website misura-app.com may use cookies and similar technologies strictly necessary for its operation, as well as analytics cookies or identifiers (opt-out) to measure usage and improve the site.

17.2. Where the law requires it (e.g. in the EEA/UK), we will request your prior consent for non-essential cookies via a consent-management mechanism, and you may withdraw it at any time.

17.3. You can configure your browser to reject cookies; some site features may not function correctly.


18. Automated Decisions and Profiling

18.1. Misura generates personalized nutrition and training plans from your data and physiological formulas. These features involve profiling for personalization purposes, but they do not produce legal effects or similarly significantly affect you within the meaning of Article 22 GDPR.

18.2. Plans and suggestions are indicative and do not constitute medical advice. Consult a health professional before starting any program (see the Terms and the Health Disclaimer).

18.3. Where the law grants you rights regarding automated decisions, you may request human intervention, express your point of view and contest the decision by writing to rafoantoni@gmail.com.


19. Marketing and Communications

19.1. We will send you transactional and service communications (verification, security, relevant changes) because they are necessary for the provision of the Service.

19.2. We will only send you marketing if you have given your consent where the law requires it, or where another valid basis exists. You may unsubscribe at any time via the corresponding link or by writing to rafoantoni@gmail.com.


20. Security Breach Notification

In the event of a personal-data security breach, we will assess the risk and, where the law requires it, notify the competent supervisory authority and affected users without undue delay and within the applicable legal timelines, indicating the nature of the incident, the likely consequences and the measures taken.


21. Third-Party Links and Services

The Service may contain links to, or integrations with, third-party sites and services (Section 4.7). We are not responsible for the privacy practices of such third parties. We recommend that you review their policies before providing them with data.


22. Data Protection Officer and Representatives

22.1. Privacy contact / DPO. For data protection matters you can write to rafoantoni@gmail.com or, where applicable, to our data protection officer: rafoantoni@gmail.com.

22.2. EU / UK Representative (Art. 27 GDPR / UK GDPR). We have not currently designated a representative in the European Union or the United Kingdom. If we process data of users in those territories in a manner that makes the designation of a representative legally required, we will designate one and publish their contact details here. In the meantime, you can exercise your rights and direct any inquiries to rafoantoni@gmail.com.

22.3. Brazil (data protection officer / encarregado, LGPD Art. 41). Contact: rafoantoni@gmail.com.

If any of these roles is not legally required in your case, the corresponding provision may not be applicable.


23. Changes to this Policy

23.1. We may update this Policy to reflect legal, technical or business changes. The "effective date" in the header indicates the current version.

23.2. If the changes are material, we will notify you with reasonable advance notice by appropriate means (e.g. in the app, by email or via notice on misura-app.com) before they take effect, and, where the law requires it, we will obtain your consent again.

23.3. Continued use of the Service after the changes take effect constitutes acceptance of the revised Policy, to the maximum extent permitted by law and without prejudice to any consents that must be obtained separately.


24. Severability and Maximum Extent Permitted

24.1. If any provision of this Policy is held to be invalid, illegal or unenforceable in any jurisdiction, that provision will be construed, limited or, if necessary, severed to the minimum extent required, with the remainder remaining in full force and effect (severability).

24.2. All limitations, exclusions and waivers in this Policy apply to the maximum extent permitted by applicable law and are not intended to exclude or limit any right that cannot be lawfully excluded or limited.


25. Governing Law and Mandatory Local Rights

25.1. Governing law. This Policy is governed by the law of Peru, without prejudice to the provisions of Section 25.2 and to what the Terms establish regarding governing law and dispute resolution.

25.2. Mandatory-rights carve-out. Nothing in this Policy limits, reduces or deprives you of the non-waivable rights granted to you by the mandatory data-protection and consumer-protection legislation of your country or place of habitual residence. Where a conflict exists between this Policy and such mandatory rights, your mandatory local rights prevail, and this Policy will apply in all other respects to the maximum extent permitted.


26. Contact and Supervisory Authorities

You have the right to lodge a complaint with the supervisory authority of your jurisdiction (e.g. AEPD, ICO, ANPD, OPC, the National Authority for the Protection of Personal Data of Peru, or OAIC, as applicable). We would appreciate it if, where possible, you contact us first at rafoantoni@gmail.com to try to resolve your concern.


End of the Privacy Policy.