DiaPrimaDiaPrima

Legal

Privacy Policy

DiaPrima helps you manage diabetes across food, movement and care. Because we process health data, we treat your privacy as core to the product, not an afterthought.

Last updated 20 June 2026

This is an engineering template, not final legal text. Before launch it will be reviewed by a qualified data-protection lawyer. It describes the practices actually implemented in the product today.

Who we are

DiaPrima (“we”, “us”) is the data controller for the personal data described here. Our data is hosted in the European Union (Frankfurt).

What we collect

Account & profile: your name, email, diabetes type, plan, language and — for partners — address, phone and payout details.

Health data (special category, GDPR Art. 9): glucose readings, meals and workouts you log. This is processed only with your explicit consent.

Usage & security: minimal audit records of privacy-relevant actions (consent changes, data exports, deletions) for accountability.

Why we use it, and our lawful basis

To provide the service you asked for (Art. 6(1)(b) contract) — your account, plan and the features you use.

To process your health data and give you insights (Art. 9(2)(a) explicit consent). You can withdraw this at any time, which pauses health features rather than deleting your account.

To keep the service secure and meet our legal obligations (Art. 6(1)(f) legitimate interest / Art. 6(1)(c)).

How long we keep it

We keep data only as long as needed. The full schedule and lawful basis per category is shown in-app under Privacy & data, and summarised in our related policies. Audit records are kept for 12 months, then automatically deleted.

Who we share it with

We do not sell your data. We use Supabase as our hosting and database processor (EU region) under a data-processing agreement. We share data with others only where you direct us to, or where the law requires it.

Your rights

You can access, export and permanently delete your data, and grant or withdraw consent, yourself at any time from Privacy & data inside the app. You also have the right to rectification, restriction and to lodge a complaint with your supervisory authority.

Security

Data is encrypted in transit (TLS) and at rest, access is restricted at the database layer (row-level security), and privacy-relevant actions are audited. We do not store bank account numbers: when payouts go live, a payment provider holds those details and we keep only a reference.

Contact

For any privacy request or question, contact privacy@diaprima.com. We will respond within the timeframes set by applicable law.