Legal
Privacy Policy
DiaPrima helps you manage diabetes across food, movement and care. Because we process health data, we treat your privacy as core to the product, not an afterthought.
Last updated 20 June 2026
Who we are
DiaPrima (“we”, “us”) is the data controller for the personal data described here. Our data is hosted in the European Union (Frankfurt).
What we collect
Account & profile: your name, email, diabetes type, plan, language and — for partners — address, phone and payout details.
Health data (special category, GDPR Art. 9): glucose readings, meals and workouts you log. This is processed only with your explicit consent.
Usage & security: minimal audit records of privacy-relevant actions (consent changes, data exports, deletions) for accountability.
Why we use it, and our lawful basis
To provide the service you asked for (Art. 6(1)(b) contract) — your account, plan and the features you use.
To process your health data and give you insights (Art. 9(2)(a) explicit consent). You can withdraw this at any time, which pauses health features rather than deleting your account.
To keep the service secure and meet our legal obligations (Art. 6(1)(f) legitimate interest / Art. 6(1)(c)).
How long we keep it
We keep data only as long as needed. The full schedule and lawful basis per category is shown in-app under Privacy & data, and summarised in our related policies. Audit records are kept for 12 months, then automatically deleted.
Who we share it with
We do not sell your data. We use Supabase as our hosting and database processor (EU region) under a data-processing agreement. We share data with others only where you direct us to, or where the law requires it.
Your rights
You can access, export and permanently delete your data, and grant or withdraw consent, yourself at any time from Privacy & data inside the app. You also have the right to rectification, restriction and to lodge a complaint with your supervisory authority.
Security
Data is encrypted in transit (TLS) and at rest, access is restricted at the database layer (row-level security), and privacy-relevant actions are audited. We do not store bank account numbers: when payouts go live, a payment provider holds those details and we keep only a reference.
Contact
For any privacy request or question, contact privacy@diaprima.com. We will respond within the timeframes set by applicable law.