← Back to KinetiqAF.com
Legal · Privacy

Privacy Policy

Last updated: May 13, 2026 · Effective: May 13, 2026
About this document. This Privacy Policy describes how KinetiqAF (operated by James Kennedy & Associates LLC, "we", "us", or "our") collects, uses, stores, and shares information from people who visit our website, submit our contact form, or use our Client Portal. It is written to satisfy the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), and reflects the way we actually handle data — not boilerplate. If a section is unclear, contact us at james@kinetiqaf.com.
Contents
  1. Notice at collection (summary)
  2. Who we are
  3. Information we collect
  4. How we use information
  5. When we share information
  6. Health information
  7. Children and minors
  8. How we store and protect information
  9. How long we keep information
  10. Your privacy rights
  11. Communications and opt-out
  12. Cookies, tracking, and Global Privacy Control
  13. Automated decision-making
  14. Accessibility of this policy
  15. Residents of other U.S. states
  16. International users
  17. Changes to this policy
  18. How to contact us

1. Notice at collection (summary)

This summary is provided at or before the point of collection, as required by Cal. Civ. Code § 1798.100(a) and 11 CCR § 7012:

2. Who we are

KinetiqAF is the trade name of James Kennedy & Associates LLC, a California limited liability company (EIN 33-1440054) operating an adaptive fitness and personal training practice in San Diego. The business is a sole-operator practice owned and run by James Kennedy.

We can be reached at:

We are the data controller for the information we collect about you.

3. Information we collect

We collect only what we need to run our practice and provide training services. The categories below match the categories defined in California Civil Code § 1798.140.

Category (CCPA §1798.140) Examples of what we collect How we collect it
Identifiers Name, email address, phone number, postal address, Client Portal account ID You provide it (contact form, intake form, account signup)
Customer records (Cal. Civ. Code §1798.80(e)) Emergency contact, primary care physician name and phone, signature image, signed agreement copy You provide it during onboarding or in the Client Portal
Protected classification information Date of birth (used to determine the correct agreement variant for minors). For Adaptive / SDP clients: primary diagnosis or disability classification, if you choose to disclose it. You provide it during PAR-Q intake
Commercial information Sessions purchased, invoices issued, payment status, training package history Generated as you use the service
Internet or network activity Login timestamps, basic IP address (logged with signed agreements for legal-record purposes per UETA §1633.7), browser type for security and debugging Automatically when you use the Client Portal
Geolocation (general) Service area (San Diego County); the address where you receive in-home training, if applicable You provide it
Sensitive personal information (CPRA §1798.140(ae)) Health-related information from your PAR-Q (medications, injuries, surgeries, allergies, activity restrictions, sensory sensitivities for adaptive clients) You provide it during PAR-Q intake
Professional / education information Funding source (SDP, Private Pay, Regional Center), FMS provider name, Service Coordinator name, authorized hours — only for SDP / Regional Center clients You provide it during PAR-Q intake
Inferences We do not draw or sell inferences about you. We do not profile.

We do not collect:

4. How we use information

We use the information we collect only for these purposes:

We do not use your information for advertising, profiling, automated decision-making, or any purpose unrelated to providing training services.

5. When we share information

We share information only as needed to run the practice. We do not sell information, and we do not share it for cross-context behavioural advertising. Specifically:

RecipientWhat we shareWhy
Supabase (Postgres database + auth, hosted in the U.S.) All Client Portal data: account, PAR-Q, agreement, sessions, invoices, messages Service provider — they store and serve our application data
Netlify (web hosting + serverless functions, hosted in the U.S.) Web traffic to KinetiqAF.com and the Client Portal; form submissions before they reach Supabase Hosting provider
Stripe (payments processor) Your name, email, and invoice amount when you pay for a session package. Card data is collected by Stripe directly — we never see it. Payment processing
OneSignal (push notifications) Your push-notification token only, if you enable Client Portal push alerts. No PII. To send schedule and message notifications
Google (Google Apps Script for the contact-form auto-reply) Your name, email, and the service you selected on the contact form — for the single auto-reply email To send a confirmation email after you submit the contact form
Anthropic (for document OCR) When we file paper documents you give us (PAR-Q, service agreement, doctor's note, etc.), we send the photographed image to Anthropic's API to extract the text and structured fields. We use zero-data-retention mode so Anthropic does not retain the image after the API call returns. The image and the extracted text remain in our Supabase database under our control. To file paper documents into your client record without manually retyping every field
San Diego Regional Center / Financial Management Services (FMS) provider For SDP / Regional Center clients only: client name, service authorization details, session dates and durations, and signed forms required for reimbursement To bill your FMS for covered services. You authorize this when you sign your service agreement.
Government or law enforcement Information specifically requested by valid subpoena, court order, or where required by mandated reporting laws (e.g., suspected abuse or neglect involving a vulnerable adult, per Cal. Welf. & Inst. Code §15630) To comply with applicable law
Insurance carrier Only the minimum information required to process a claim, in the event of an incident at a training session Insurance administration

We sign Data Processing Agreements (or equivalent) with our service providers. We do not give them permission to use your information for their own purposes.

6. Health information

We collect health information through the Physical Activity Readiness Questionnaire (PAR-Q) and intake forms because a fitness practice that does not know your medical history cannot keep you safe.

We are not a HIPAA-covered entity — we are a personal training business, not a healthcare provider, and we do not bill insurance for medical services. However, because of the sensitivity of the information, we follow practices similar to HIPAA's:

If you are uncomfortable disclosing certain medical conditions, we would rather know about a gap than have incomplete information — please tell us, and we will work with you to design around it.

7. Children and minors

We work with clients of all ages, including minors. When the client is a minor:

8. How we store and protect information

Our security posture:

No system is perfectly secure. If we discover a breach of unencrypted personal information, we will notify affected California residents "in the most expedient time possible and without unreasonable delay" as required by Cal. Civ. Code § 1798.82, and will notify the California Attorney General if the breach affects more than 500 California residents. The notice will describe the categories of information involved, the date or estimated date of the breach, and the steps we have taken or recommend you take in response.

9. How long we keep information

We keep different categories of information for different periods, based on the purposes for which we collected them:

You may request earlier deletion at any time — see your rights below. Note that signed legal records (agreements, PAR-Qs) may be retained even after a deletion request to the extent required to defend a legal claim, comply with tax law, or meet a records-retention obligation.

10. Your privacy rights

If you are a California resident, you have the following rights under the CCPA / CPRA:

How to make a request

Submit any privacy request by emailing james@kinetiqaf.com with the subject line "Privacy request." We will verify your identity by confirming the email matches one we already have on file, or by asking a question only the account holder could answer.

We will respond within 45 days as required by Cal. Civ. Code § 1798.130(a)(2). If we need an additional 45 days (allowed by the statute), we will notify you within the first 45 days and explain why.

An authorized agent may submit a request on your behalf. We will require proof that you authorized them (a signed letter is sufficient) and may still ask you to verify directly.

11. Communications and opt-out

We send three kinds of email or text messages, and you have the right to control each:

You may also email james@kinetiqaf.com at any time to update your communication preferences.

12. Cookies, tracking, and Global Privacy Control

KinetiqAF.com uses the minimum cookies needed for the site to function. Specifically:

We do not use:

Because we don't track you, there is no "Do Not Sell or Share My Personal Information" link on our site — there is nothing to opt out of.

Global Privacy Control (GPC) and Do Not Track (DNT). Our site does not sell or share personal information for cross-context behavioural advertising, so there is no opt-out signal to honour. However, if your browser sends a GPC signal (per 11 CCR § 7025) or a legacy DNT header, we will continue to refrain from any such selling or sharing — the GPC signal will never cause us to increase data collection or be ignored.

Aggregated and de-identified data. We may produce aggregated or de-identified statistics (for example, total number of sessions delivered in a month) for internal planning. Once data is aggregated or de-identified per CCPA § 1798.140(h) and (m), it is no longer "personal information" and is not covered by this Privacy Policy. We will not attempt to re-identify it and will require contractually that any recipient also not attempt to re-identify it.

13. Automated decision-making and profiling

We do not use automated decision-making technology (ADMT) as defined by the CPRA regulations (11 CCR § 7200 et seq.) to make decisions about you. We do not profile, score, rank, sort, or evaluate you using software. Every decision about your training program, scheduling, or service eligibility is made by a human (James Kennedy) based on a direct conversation with you. Because we do not use ADMT, the related rights to access and opt out of ADMT do not arise in our practice.

14. Accessibility of this policy

We want this Privacy Policy to be understandable by everyone we serve, including clients with cognitive disabilities, low vision, or limited English proficiency. If any part of this policy is unclear, you may contact us and we will explain it in plain language, read it aloud, translate it, or provide it in a larger font or alternative format at no cost. The site itself is designed to meet WCAG 2.1 Level AA where reasonably achievable for a small-business website, and the Client Portal includes a dedicated accessibility mode.

15. Residents of other U.S. states

This policy is primarily written for California residents. We serve clients only in San Diego County, California, so almost all data subjects are California residents. If you are a resident of another U.S. state with a comprehensive privacy law (e.g., Colorado, Connecticut, Virginia, Utah, Texas, Oregon, or Montana) and you interact with us, we will honour the equivalent rights that state's law grants you (access, correction, deletion, portability, opt-out of sale/targeted advertising, opt-out of profiling). Submit any such request using the contact information in §18 and we will treat it as a privacy request under your state's law.

16. International users

KinetiqAF.com is operated from California, United States. Our services are intended for California residents. If you access our site from outside the United States, you understand that your information will be processed in the United States, which may have different data-protection laws than your jurisdiction. We do not offer services to residents of the European Economic Area or the United Kingdom from this website.

17. Changes to this policy

We update this Privacy Policy as our practices change or as the law requires. The "Last updated" date at the top of this page tells you when we last made a substantive change. We will email active Client Portal users about material changes at least 30 days before they take effect.

Prior versions of this Privacy Policy are kept on file. You can request a copy of any prior version at any time.

18. How to contact us

For any privacy question, request, complaint, or concern:

Email: james@kinetiqaf.com

Phone: 442-375-5090

James Kennedy & Associates LLC, San Diego, California