Privacy Policy of the DIAGME Application
Information Form
Note: The DIAGME application provides general information and suggestions supporting health prevention, such as laboratory tests, blood pressure measurement, or dietary supplementation. DIAGME is not a medical device within the meaning of EU Regulation 2017/745 and the Act of May 20, 2010, on medical devices, and is not intended for diagnosing, treating, monitoring, or preventing diseases. All health decisions should be made after consulting with a physician.
1. Personal Data Administrator
The administrator of personal data is DIAGME SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (LIMITED LIABILITY COMPANY), registered in the National Court Register (KRS) maintained by the District Court for Kraków-Śródmieście in Kraków, Commercial Division of the National Court Register, with the following details:
| KRS number | 0001233091 |
| NIP (Tax ID) | 5130310747 |
| REGON | 544436288 |
| Service | DIAGME.ONLINE |
| Headquarters | ul. Topolowa 22, 32-082 Więckowice, Poland |
2. Contact Information
You can contact the data administrator regarding all matters related to the processing of personal data or exercising rights related to data processing:
- Email: contact@diagme.online
- Post: ul. Topolowa 22, 32-082 Więckowice, Poland
3. Data Source
Personal data is voluntarily provided by you directly at the time of registration or while using the service. Data may also be obtained automatically in the following cases:
- Wearable sensors — if you consent to connecting your account with a service managing data from wearable devices (e.g., Garmin, Samsung), data is retrieved via secured manufacturer APIs after your authentication and consent.
- Medical laboratories — if you consent, data is automatically retrieved from entities performing medical tests (e.g., laboratories cooperating with the badania.pl service, such as complete blood count or lipid profile) — only after displaying a message and obtaining your consent.
Providing personal data is voluntary, but failure to provide it or limiting its scope may result in inability to deliver the services, or delivering them incompletely.
4. Scope of Personal Data Processed
For the purpose of suggesting general preventive actions — such as laboratory tests, blood pressure measurement, doctor consultations, or dietary supplementation — the following data is processed:
- Email address
- First and last name
- Gender
- Date of birth
- Phone number
- Information regarding health status, including chronic diseases of the user and their family, as well as pregnancy information
- Medical test results (provided directly by the user or automatically retrieved from testing entities)
- History of performed tests, including price and laboratory location
- Information about the user's lifestyle (provided directly or automatically retrieved from authorised entities)
- Uploaded meal photos and related measurements
- Data related to dietary supplement purchases (e.g., delivery address, payment data)
If you have consented to marketing communication, your email address is also used for that purpose.
These suggestions are informational in nature and do not constitute medical advice, diagnoses, or a replacement for consultation with a doctor. The data is also used to verify identity during registration and to fulfil dietary supplement orders.
5. Purposes and Legal Bases for Processing
| Purpose | Legal Basis |
|---|---|
| Providing application services — delivering health prevention suggestions, storing test results, generating informational health reports | Consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) or performance of a contract (Art. 6(1)(b) GDPR) |
| Meal photo analysis — anonymized photos (no identifying data) transmitted to external AI providers (including OpenAI) to obtain nutritional information | Consent (Art. 6(1)(a) GDPR) or legitimate interest (Art. 6(1)(f) GDPR) |
| Fulfilling dietary supplement orders — processing data for purchasing and delivering supplements | Performance of a contract (Art. 6(1)(b) GDPR) |
| Accounting and tax settlements — e.g., issuing invoices | Legal obligation (Art. 6(1)(c) GDPR) in connection with the Accounting Act and tax legislation |
| Defending rights and pursuing claims | Legitimate interest (Art. 6(1)(b) and (f) GDPR) |
| Marketing communication (if consented) | Consent (Art. 6(1)(a) GDPR) |
6. Data Storage Period
- Account deletion: Data is deleted within 30 days of request, unless law requires longer storage (e.g., for accounting purposes).
- Health data: Can be deleted at any time; deletion may limit available services.
- Inactivity: Data is deleted if the user stops using the service or is inactive for more than 36 months.
- Accounting data (e.g., supplement invoices): Stored for 5 years from the end of the calendar year, in accordance with the Accounting Act.
- Marketing data: Processed until consent is withdrawn.
7. Data Recipients
Your data may be shared with the following categories of recipients:
- IT service providers, hosting, payment and logistics companies — based on data processing agreements (Art. 28 GDPR)
- Medical laboratories cooperating with badania.pl — only for performing tests, after your consent
- Dietary supplement suppliers — for order fulfilment (contact details and delivery address)
- AI service providers (including OpenAI) — exclusively anonymized meal photos, without any user-identifying data, for nutritional analysis
- Public authorities (e.g., tax office) — if required by law (Art. 6(1)(c) GDPR)
- Marketing agencies — only if you have consented to marketing communication
8. Transfer of Data Outside the EEA
Your personal data may be transferred to recipients outside the European Economic Area only in exceptional cases, such as when using IT or AI service providers (e.g., OpenAI for meal photo analysis) based outside the EEA.
Such transfers are based on:
- Standard data protection clauses adopted by the European Commission, or
- Adequacy decisions issued by the European Commission.
In the case of meal photos sent to AI providers, only anonymized images are transmitted — no data enabling user identification.
For detailed information, contact: contact@diagme.online
9. Your Rights
You have the right to:
- Access your personal data (Art. 15 GDPR)
- Rectify inaccurate or incomplete personal data (Art. 16 GDPR)
- Delete your personal data when conditions in Art. 17 GDPR are met
- Restrict processing of your personal data (Art. 18 GDPR)
- Data portability — receive your data in a structured, machine-readable format and transfer it to another controller (where processing is based on consent and carried out by automated means)
- Object to processing in cases specified in Art. 21 GDPR
- Lodge a complaint with the supervisory authority responsible for personal data protection
To exercise these rights, contact the data administrator using the details in Section 2. We will respond within one month, or within 3 months in complex cases, in accordance with Art. 12 GDPR.
10. Voluntary Nature of Data Provision
- Providing personal data is a necessary condition for the proper functioning of the service. Withholding consent is equivalent to resignation from using the service.
- Providing data is also required to issue a receipt or invoice for supplement purchases.
- Uploading meal photos is entirely voluntary. Users may use all other application features without sharing meal photos.
11. Automated Decision-Making
Your personal data may be automatically analyzed to present general preventive suggestions (e.g., laboratory tests, blood pressure measurement, dietary supplementation). These suggestions are informational only — they do not constitute a diagnosis or medical advice and do not replace a doctor's consultation.
Meal photos may be automatically analyzed by AI systems to recognize ingredients and estimate nutritional values. This analysis is purely informational and does not lead to automated decision-making with legal effects (Art. 22 GDPR).
12. Data Safeguards
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption during transmission (SSL/TLS) and storage (AES-256)
- Data stored on EU-based servers meeting GDPR requirements
- Access limited to authorized employees only
- Regular security audits and penetration tests
- Anonymization of meal photos before transmission to AI providers (removal of all metadata and identifying information)
Where required by Art. 35 GDPR, processing of health data is subject to a Data Protection Impact Assessment (DPIA) to minimize risk.
13. Dietary Supplements and Consumer Rights
Through DIAGME, you can order dietary supplements — these are food products, not medications, and are not intended to treat or prevent diseases (Act of August 25, 2006, on food and nutrition safety). We recommend consulting a doctor or dietitian before use.
When purchasing supplements:
- Your delivery address and payment data are processed to fulfil the order (Art. 6(1)(b) GDPR)
- You will receive full information about composition, dosage, and contraindications
- You have the right to withdraw from the contract within 14 days of receiving the product (Act of May 30, 2014, on consumer rights)
Order data is transferred to supplement suppliers solely for the purpose of completing the purchase.
14. User Traffic Tracking
We collect data about your activity in the DIAGME app and on diagme.online (e.g., visited sections, time spent, clicks, feature interactions). This data may be anonymized or linked to your user identifier if you have consented. Cookies and similar technologies may be used.
Purposes:
- Improving application quality (UI and functionality optimization)
- Technical diagnostics (detecting and fixing errors)
- Marketing (adapting advertising content, if consent given)
Legal basis: Consent (Art. 6(1)(a) GDPR) for data linked to your identifier; legitimate interest (Art. 6(1)(f) GDPR) for anonymized data.
You can manage tracking preferences in the application settings or on the website. Data linked to your identifier is stored until consent is withdrawn or for up to 36 months from last activity. Anonymized data may be stored indefinitely.
15. Privacy Policy Updates
The administrator reserves the right to update this Privacy Policy in response to changes in legislation, technology, or data processing practices. Users will be notified of any changes through the application or website with appropriate advance notice.
DIAGME Sp. z o.o. — contact@diagme.online — ul. Topolowa 22, 32-082 Więckowice, Poland