Health Data Processing Information
Last Updated: January 2025
Transparency about how we use your sensitive health information
Why We Process Health Data
To provide you with personalized health recommendations and insights, we process certain health data. This page explains what data we collect, how we use it, and what rights you have.
What Health Data We Collect
- Blood test results and biomarker values (if provided by you)
- Physical measurements (height, weight, age, gender)
- Health questionnaire responses
- Activity and sleep data from wearables (if connected)
- Dietary preferences and restrictions
- Medications and allergies (if specified)
How We Use Your Health Data
- Calculating your biological age
- Generating personalized supplement recommendations
- Creating individualized nutrition and training plans
- Providing AI-powered health insights
- Tracking your health progress over time
Legal Basis (Article 9 GDPR)
Article 9 GDPR - Special Categories of Personal Data
Health data is a special category of personal data under GDPR. We process this data exclusively based on your explicit consent pursuant to Article 9(2)(a) GDPR.
Data Security
Your health data is protected with industry-standard security measures, including encryption in transit and at rest, access controls, and regular security audits.
- Encryption of all data in transit (TLS 1.3)
- Encryption of all data at rest (AES-256)
- Strict access controls and authentication
- Regular security audits and penetration testing
- EU data centers for EU users
Retention Periods
We retain your health data for as long as your account exists or until you withdraw your consent. If you delete your account, your health data is removed from our live systems immediately and permanently — there is no recovery or grace period. It may remain in rotating database backups until the backup cycle in question expires. Invoicing and payment records are retained longer because of commercial and tax law obligations; they contain no health data.
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion |
| Health data | Immediately on account deletion (afterwards only in rotating backups) |
| Consent records | 3 years (legal requirement) |
| Transaction data | 10 years (tax law) |
Your Rights
Your Rights Under GDPR
- Right to access your health data
- Right to rectify inaccurate data
- Right to erasure ("right to be forgotten")
- Right to data portability
- Right to withdraw your consent at any time
- Right to lodge a complaint with a supervisory authority
Withdrawing Consent
You can withdraw your consent to health data processing at any time in your account settings or by contacting us. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Note: Withdrawing your consent may result in certain app features becoming unavailable, as we rely on your health data for personalized recommendations.
Supervisory Authority
You have the right to lodge a complaint with the competent data protection supervisory authority. In Germany, this is the State Data Protection Commissioner of your federal state.
Example for Germany:
A list of state data protection commissioners can be found at: www.bfdi.bund.de
Contact
For questions about the processing of your health data, please contact us:
E-Mail: support@inself.io
or
Inself UG (haftungsbeschränkt)
Madame-Blanc-Straße 2i
61381 Friedrichsdorf, Deutschland
See also: Privacy Policy