Privacy Policy of the DIAGME Application

Information Form


Note: The DIAGME application provides general information and suggestions supporting health prevention, such as laboratory tests, blood pressure measurement, or dietary supplementation. DIAGME is not a medical device within the meaning of EU Regulation 2017/745 and the Act of May 20, 2010, on medical devices, and is not intended for diagnosing, treating, monitoring, or preventing diseases. All health decisions should be made after consulting with a physician.


1. Personal Data Administrator

The administrator of personal data is DIAGME SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (LIMITED LIABILITY COMPANY), registered in the National Court Register (KRS) maintained by the District Court for Kraków-Śródmieście in Kraków, Commercial Division of the National Court Register, with the following details:

KRS number 0001233091
NIP (Tax ID) 5130310747
REGON 544436288
Service DIAGME.ONLINE
Headquarters ul. Topolowa 22, 32-082 Więckowice, Poland

2. Contact Information

You can contact the data administrator regarding all matters related to the processing of personal data or exercising rights related to data processing:


3. Data Source

Personal data is voluntarily provided by you directly at the time of registration or while using the service. Data may also be obtained automatically in the following cases:

Providing personal data is voluntary, but failure to provide it or limiting its scope may result in inability to deliver the services, or delivering them incompletely.


4. Scope of Personal Data Processed

For the purpose of suggesting general preventive actions — such as laboratory tests, blood pressure measurement, doctor consultations, or dietary supplementation — the following data is processed:

If you have consented to marketing communication, your email address is also used for that purpose.

These suggestions are informational in nature and do not constitute medical advice, diagnoses, or a replacement for consultation with a doctor. The data is also used to verify identity during registration and to fulfil dietary supplement orders.


5. Purposes and Legal Bases for Processing

Purpose Legal Basis
Providing application services — delivering health prevention suggestions, storing test results, generating informational health reports Consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) or performance of a contract (Art. 6(1)(b) GDPR)
Meal photo analysis — anonymized photos (no identifying data) transmitted to an external AI service (Amazon Bedrock, operated by Amazon Web Services) to obtain nutritional information Consent (Art. 6(1)(a) GDPR) or legitimate interest (Art. 6(1)(f) GDPR)
Fulfilling dietary supplement orders — processing data for purchasing and delivering supplements Performance of a contract (Art. 6(1)(b) GDPR)
Accounting and tax settlements — e.g., issuing invoices Legal obligation (Art. 6(1)(c) GDPR) in connection with the Accounting Act and tax legislation
Defending rights and pursuing claims Legitimate interest (Art. 6(1)(b) and (f) GDPR)
Marketing communication (if consented) Consent (Art. 6(1)(a) GDPR)

6. Data Storage Period


7. Data Recipients

Your data may be shared with the following categories of recipients:


8. Transfer of Data Outside the EEA

Your personal data may be transferred to recipients outside the European Economic Area only in exceptional cases, such as when using IT or AI service providers (e.g., Amazon Web Services, whose Amazon Bedrock service performs meal photo analysis) based outside the EEA.

Such transfers are based on:

In the case of meal photos sent to AI providers, only anonymized images are transmitted — no data enabling user identification.

For detailed information, contact: [email protected]


9. Garmin Data

If you choose to connect your Garmin account, you authorise the connection directly with Garmin (OAuth 2.0) and can disconnect it at any time in the Application. From Garmin we receive only a technical account identifier and the health and activity data you permit Garmin to share (such as activity, sleep, heart-rate and other wellness measurements), including historical data recorded before the connection. We do not receive your name or e-mail address from Garmin.

Use. Garmin data is used solely to provide the Application's features: displaying your measurements, computing derived metrics and wellness scores, and generating recommendations and notifications about your lifestyle and progress. To generate such insights, Garmin data may be processed by an artificial-intelligence service (Amazon Bedrock), operated by our hosting provider Amazon Web Services as our processor; your data is not used to train AI models. Garmin data is never used for advertising and never sold.

Storage. Garmin data is stored on Amazon Web Services (AWS) infrastructure; Garmin access credentials are additionally encrypted with dedicated keys.

Sharing. Garmin data is not shared with third parties for their own purposes. It is processed only by our sub-processors: Amazon Web Services (hosting and the AI service described above). If the same Garmin account is connected to more than one Application account, data from that Garmin account is available to each of them.

Deletion. When you disconnect Garmin or delete your Application account, your Garmin connection and the stored Garmin records are deleted. Revoking access on Garmin's side has the same effect.


10. Your Rights

You have the right to:

To exercise these rights, contact the data administrator using the details in Section 2. We will respond within one month, or within 3 months in complex cases, in accordance with Art. 12 GDPR.


11. Voluntary Nature of Data Provision


12. Automated Decision-Making

Your personal data may be automatically analyzed to present general preventive suggestions (e.g., laboratory tests, blood pressure measurement, dietary supplementation). These suggestions are informational only — they do not constitute a diagnosis or medical advice and do not replace a doctor's consultation.

Meal photos may be automatically analyzed by AI systems to recognize ingredients and estimate nutritional values. This analysis is purely informational and does not lead to automated decision-making with legal effects (Art. 22 GDPR).


13. Data Safeguards

We implement appropriate technical and organizational measures to protect your data, including:

Where required by Art. 35 GDPR, processing of health data is subject to a Data Protection Impact Assessment (DPIA) to minimize risk.


14. Dietary Supplements and Consumer Rights

Through DIAGME, you can order dietary supplements — these are food products, not medications, and are not intended to treat or prevent diseases (Act of August 25, 2006, on food and nutrition safety). We recommend consulting a doctor or dietitian before use.

When purchasing supplements:

Order data is transferred to supplement suppliers solely for the purpose of completing the purchase.


15. User Traffic Tracking

We collect data about your activity in the DIAGME app and on diagme.online (e.g., visited sections, time spent, clicks, feature interactions). This data may be anonymized or linked to your user identifier if you have consented. Cookies and similar technologies may be used.

Purposes:

Legal basis: Consent (Art. 6(1)(a) GDPR) for data linked to your identifier; legitimate interest (Art. 6(1)(f) GDPR) for anonymized data.

You can manage tracking preferences in the application settings or on the website. Data linked to your identifier is stored until consent is withdrawn or for up to 36 months from last activity. Anonymized data may be stored indefinitely.


16. Privacy Policy Updates

The administrator reserves the right to update this Privacy Policy in response to changes in legislation, technology, or data processing practices. Users will be notified of any changes through the application or website with appropriate advance notice.


DIAGME Sp. z o.o. — [email protected] — ul. Topolowa 22, 32-082 Więckowice, Poland