Back to home

    Privacy Policy

    Last updated: December 2024

    1. Introduction

    huuman ("we", "us", or "our") operates the huuman platform and is committed to protecting your personal data. This privacy policy explains how we collect, use, and protect your information in compliance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

    2. Data Controller

    The data controller responsible for your personal data is:

    [Your Company Name]
    [Street Address]
    [Postal Code, City]
    Germany

    Email: [email protected]

    3. Data We Collect

    We collect the following categories of personal data:

    • Account Data: Email address, name, and password when you create an account
    • Health Data: Data you upload from wearables and health apps, including activity metrics, sleep data, heart rate variability, and other biometric information
    • Usage Data: Information about how you interact with our platform, including features used and coaching interactions
    • Technical Data: IP address, browser type, device information, and cookies

    4. Legal Basis for Processing

    We process your personal data based on:

    • Contract Performance (Art. 6(1)(b) GDPR): To provide the huuman platform and coaching services
    • Explicit Consent (Art. 9(2)(a) GDPR): For processing health data, which requires your explicit consent
    • Legitimate Interest (Art. 6(1)(f) GDPR): For improving our services and ensuring platform security
    • Legal Obligation (Art. 6(1)(c) GDPR): To comply with applicable laws

    5. How We Use Your Data

    We use your data to:

    • Provide and personalize the huuman Dashboard and coaching recommendations
    • Analyze your health metrics to deliver actionable insights
    • Communicate with you about your account and our services
    • Improve our platform and develop new features
    • Ensure the security and integrity of our services

    6. Data Security

    We implement industry-standard security measures to protect your data:

    • All data is encrypted in transit using TLS 1.3
    • Data at rest is encrypted using AES-256 encryption
    • Access to personal data is strictly limited and logged
    • Regular security audits and penetration testing
    • Data is stored on servers located within the European Union

    7. Data Retention

    We retain your personal data only as long as necessary to provide our services or as required by law. Account data is retained for the duration of your account plus 30 days after deletion. Health data is deleted immediately upon your request or within 30 days of account deletion.

    8. Data Sharing

    We do not sell your personal data. We may share data with:

    • Service Providers: Trusted partners who assist in operating our platform (e.g., cloud hosting, analytics), bound by data processing agreements
    • Legal Requirements: When required by law or to protect our legal rights

    9. Your Rights Under GDPR

    You have the following rights regarding your personal data:

    • Right of Access (Art. 15): Request a copy of your personal data
    • Right to Rectification (Art. 16): Correct inaccurate data
    • Right to Erasure (Art. 17): Request deletion of your data
    • Right to Restriction (Art. 18): Limit how we process your data
    • Right to Data Portability (Art. 20): Receive your data in a machine-readable format
    • Right to Object (Art. 21): Object to processing based on legitimate interest
    • Right to Withdraw Consent: Withdraw consent at any time without affecting prior processing

    To exercise these rights, contact us at [email protected]. We will respond within 30 days.

    10. Cookies

    We use essential cookies required for the platform to function. We do not use advertising or tracking cookies. You can manage cookie preferences in your browser settings.

    11. International Transfers

    Your data is primarily processed within the European Economic Area (EEA). If data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

    12. Changes to This Policy

    We may update this privacy policy from time to time. We will notify you of significant changes via email or through the platform. Continued use of huuman after changes constitutes acceptance of the updated policy.

    13. Supervisory Authority

    If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. In Germany, you may contact the data protection authority of the federal state where we are located or where the alleged violation occurred.

    14. Contact

    For questions about this privacy policy or your personal data, contact us at:

    Email: [email protected]
    Address: [Street Address], [Postal Code] [City], Germany