Legal

Privacy Policy

Last updated: June 9, 2026

At PRIMEROX, we process the minimum data needed to generate your program and handle your purchase. This policy explains what data we collect, why, who it is shared with, how long we keep it and what your rights are (GDPR / Swiss nLPD).

1. Data controller

The data controller is the operator of the PRIMEROX website (https://primerox.co). For any question about your data or to exercise your rights: support@primerox.co.

2. Data we collect

Health-related information (injuries) is provided at your own initiative to tailor the program. You may leave it blank.

  • Questionnaire answers: goal, division, gender, age, level, HYROX experience, training days and duration, environment and equipment, running/strength level, any injuries, weight, free notes.
  • Email: to deliver the program and the purchase receipt.
  • Order data: chosen plan, amount, payment status and transaction identifiers (via Stripe).
  • Technical data: a visitor identifier, the assigned price variant and your cookie consent choice, plus technical logs.

3. Purposes and legal bases

  • Generate and deliver your program — performance of the contract.
  • Process payment and issue a receipt — performance of the contract / legal obligation.
  • Audience measurement and advertising (TikTok pixel) — only with your consent.
  • Security, fraud prevention and service improvement — legitimate interest.

4. Recipients and processors

We use providers (processors) who process data on our behalf:

Stripe

Purpose: Payment and subscription processing

Data involved: Email, transaction data (no card stored by us)

Anthropic (Claude) / OpenAI

Purpose: AI program generation

Data involved: Questionnaire answers (no email)

Resend

Purpose: Sending transactional emails

Data involved: Email, message content (program link, receipt)

Render (Render, Inc.)

Purpose: Website and database hosting

Data involved: All stored data, technical logs

TikTok (Pixel)

Purpose: Audience measurement / advertising

Data involved: Technical identifiers, browsing events (with consent)

5. Transfers outside the EU/Switzerland

Some providers may process data outside the EU/EEA or Switzerland (notably in the United States). Such transfers are framed by appropriate safeguards (standard contractual clauses and/or equivalent mechanisms).

6. Retention

  • Questionnaire answers and program: kept so you can access your program, then deleted or anonymized after 24 months.
  • Billing data: kept for the applicable legal period, up to 10 years.
  • Cookie consent: kept for up to 6 months.
  • Analytics data: per the TikTok pixel duration and our settings.

7. Cookies and trackers

Strictly necessary cookies (language, price variant, session, consent) are always on. The TikTok pixel and measurement cookies only fire after your consent, collected via the banner. You can change your choice at any time by clearing your cookies.

8. Your rights

To exercise your rights, email us at support@primerox.co. We may ask you to verify your identity.

  • Right to access, rectify and erase your data.
  • Right to restriction and portability.
  • Right to object to processing based on legitimate interest.
  • Right to withdraw consent at any time (without retroactive effect).
  • Right to lodge a complaint with the competent authority (e.g. CNIL in France, FDPIC in Switzerland).

9. Security

We implement reasonable technical and organizational measures to protect your data. As no system is infallible, we cannot guarantee absolute security.

10. Contact

For any question about this policy: support@primerox.co — https://primerox.co.