Αυτό το έγγραφο είναι διαθέσιμο μόνο στα αγγλικά, και η αγγλική έκδοση είναι αυτή που ισχύει.

This policy explains what personal information Ramo Pro Cycling collects, why, who else sees it, and what you can do about it. It covers this website and the coaching we deliver through it.

Last updated 14 September 2026.

1.Who is responsible

Ramo Pro Cycling is the data controller. 285 Protaras Avenue, Nichropa Court 4, Shop 4, 5291 Paralimni, Famagusta, Cyprus. Email [email protected], telephone +357 97 941 140.

For anything about your data, email us at that address and say what you want. There is no separate form to fill in.

2.What we collect

When you browse. Your IP address, browser and the pages you request, in ordinary server logs, plus what our hosting and security providers record to keep the site up. Only if you say yes to the cookie question on your first visit, Google Analytics records which pages you visit and how you found us, Brevo connects your visit to an email address you type into the site, and the shop notes which website or campaign brought you so an order can be credited to it (section 10). Until you choose, and if you refuse, neither sets a cookie; Google Analytics then receives only a signal with no identifier that cannot connect one visit to another.

When you buy or book. Your name, email, telephone, billing and delivery address, what you booked and when, and any answers you gave on the booking form — frame size, delivery town and time, rider names on a tour. If you accept the rental waiver we record which version you accepted, when, and the IP address it came from, because that is what makes it evidence.

When you pay. Card details go straight to Stripe and are never stored on this website. We see the last four digits, the card type and whether the payment worked.

When you have an account. Your username, password (stored hashed, never in readable form), your order history and anything you save in the members’ area.

When you contact us. Emails, WhatsApp messages, and anything you type into the chat assistant on this site.

3.Health information — and why it is treated differently

To coach you safely we ask for information about your health. Under data protection law this is a special category of personal data and it gets stricter treatment than the rest.

  • The health screening you complete before coaching or an in-person session: date of birth, existing conditions, medications, injuries, and the pre-exercise screening questions about chest pain, dizziness, breathlessness and medical advice you have been given.
  • What you record as you train: sessions, activity files from your bike computer or watch, body measurements, resting and threshold heart rates, VO2 max, training zones and BMI.
  • Photographs you choose to upload to track your own progress. These are stored outside the public part of the website and are not reachable from a web address.
  • For a rider under 18, the same information, provided with the involvement of a parent or guardian.

We rely on your explicit consent for all of it, which you give when you complete the screening, and which you can withdraw at any time by emailing us. Withdrawing it means we can no longer plan your training safely, so it ends the coaching — but it is your decision and it is always available to you.

This information is used to plan and deliver your coaching, and for nothing else. It is never published, never sold, and never used for marketing.

4.Why we use it, and on what legal basis

  • To perform our contract with you — taking and fulfilling bookings, hiring you a bike, running a tour, delivering coaching, handling payments, and sending the confirmations and reminders that go with them.
  • Because you consented — health information (section 3), the newsletter, the chat assistant, and analytics and Brevo tracking cookies (section 10).
  • Because we have a legitimate interest — keeping the site secure and available, preventing fraud, keeping records of what was agreed, and improving what we offer. We have weighed this against your rights and it does not override them.
  • Because the law requires it — tax and accounting records.

5.Where artificial intelligence is involved

Parts of this service use OpenAI, a provider in the United States.

  • The chat assistant on this website. What you type into it, and the answer it gives, are processed by OpenAI. Do not put health details or anything confidential into it — it is there to answer questions about opening hours, prices and what we offer.

OpenAI processes this on our instructions and does not use it to train its models. Because this involves sending information to the United States, see section 7.

6.Who else sees your information

We do not sell your data. We share it only with the providers who make the service work, and only with what they need:

  • Stripe — card payments, subscriptions and renewals.
  • Brevo (Sendinblue) — sends all of our email, both order and booking messages and the newsletter, and, if you allow it, recognises an email address you type into the site.
  • Google — Google Analytics, if you allow it, to count visits and see which pages are used.
  • OpenAI — as described in section 5.
  • komoot (Photon) and the OpenStreetMap Foundation — when you ask us to deliver or collect a bike, the map on the booking form is drawn from OpenStreetMap, and what you type into the address search is sent to komoot’s Photon service in Germany to find the place. Neither sets a cookie.
  • Vultr — hosts this website, in Frankfurt, Germany.
  • Cloudflare — sits in front of the site for speed and security.
  • Professional advisers, and public authorities where the law requires it.

7.Sending information outside the EEA

The website and its database are hosted in Germany, inside the EEA. Three of the providers above — Stripe, OpenAI and Google — can process data in the United States. Those transfers are made under the EU–US Data Privacy Framework where the provider is certified under it, and otherwise under the European Commission’s Standard Contractual Clauses — the safeguards the law provides for them. You can ask us for details of the safeguards that apply to you.

8.How long we keep it

  • Health screening answers — 24 months after your last activity with us, then deleted.
  • Orders, bookings and accepted waivers — seven years, because tax law and the possibility of a dispute both require it.
  • Your account and training records — while your account is open. Close it and ask us, and we delete them.
  • Progress photographs — until you delete them or ask us to.
  • Newsletter — until you unsubscribe.
  • Server logs — a short period, for security.
  • Google Analytics — detailed visit data for 2 months, and data tied to a returning visitor for 14 months after their last visit; after that only anonymous totals remain.
  • Your cookie choice — 6 months, then we ask again.

9.Your rights

Under the GDPR you can ask us to:

  • give you a copy of what we hold about you;
  • correct anything wrong;
  • delete it;
  • stop or limit what we do with it;
  • hand it to you, or to someone else, in a machine-readable file;
  • stop relying on legitimate interest, where you object to it;
  • withdraw a consent you gave, at any time, without affecting what we did before you withdrew it.

Email [email protected]. We answer within one month and it costs you nothing. If you have an account you can download or delete much of this yourself from your account page.

If you think we have got it wrong, you can complain to the Office of the Commissioner for Personal Data Protection in Cyprus, or to the authority where you live. We would rather you told us first.

10.Cookies

Always, because the site needs them: keeping your basket, keeping you signed in, letting our security and caching providers tell one visitor from another, and ramo_consent, which remembers your answer to the cookie question for 6 months.

Only if you choose “Accept”:

  • Google Analytics (_ga, _ga_…) — tells one visit from another so we can count visitors and see which pages help. We do not use it for advertising, and advertising storage stays switched off.
  • Brevo (tracking_email and Brevo’s own tracking cookies) — remembers an email address you type into the site, so our email service can connect it to your visit.
  • The shop itself (sbjs_…) — notes which website, search or campaign brought you, and saves it with an order you place. It stays on this site and is not shared.

Nothing is set until you choose, and “Reject” is as easy as “Accept”. You can change your answer at any time with Cookie settings at the bottom of every page; refusing after accepting deletes those cookies. Nothing here follows you to other websites. Your browser can also block or delete any cookie, though the basket and sign-in stop working without theirs.

11.Keeping it safe

The site runs over HTTPS. Passwords are stored hashed. Card details never reach our server. Health information and progress photographs are held where the public part of the website cannot serve them, and are readable only by Ramo and the site administrator. No system is perfectly secure, but if a breach ever put you at serious risk we will tell you and the Commissioner.

12.Children

Our youth coaching is for riders under 18. Where a rider is a child, a parent or guardian gives the health information and the consent for it, and we deal with the parent or guardian on anything concerning that data. We do not knowingly collect information from a child any other way. If you believe we hold something we should not, email us and we will remove it.

13.Changes to this policy

If we change how we use your information we will update this page and change the date at the top. If the change matters to you — a new provider seeing your health data, for instance — we will tell you directly rather than expecting you to re-read this page.

Κλείστε τώρα