Privacy Policy

Version 1.3 · Effective 2026-09-02

The short version. We collect only what we need to generate your personality profile. You decide which data sources to connect. We send your connected data to OpenAI (our AI processor in the United States) to generate the profile; under our API agreement, OpenAI is not authorised to train its models on it. We never sell your data. You can delete your account any time; your connected-service data and profiles are removed from our systems and a minimal pseudonymised record is retained only where law requires it (see §4 for the full retention table). We record basic in-app usage events (which screens you open, which buttons you tap) on our own servers to understand which parts of the app work and which confuse people; no third party receives them, and you can turn this off in the app at any time (see §1.4). Below is the long version, required by law.

This Privacy Policy explains how Eltria UG (haftungsbeschränkt) ("we", "us"), operator of the Vetraya mobile application (the "Service"), collects, uses, shares, and protects personal data. It applies whenever you use the Service.

We are the data controller for the personal data described below. For questions about this policy or your rights, contact us at privacy@eltria.de.

1. Information We Collect

1.1 Information you give us directly

1.2 Information from services you connect

You can optionally connect third-party services so the Service can analyse your digital footprint. We request only the minimum OAuth scopes needed and only fetch the data types listed:

SourceData fetchedScopes requested
Apple Music (iOS only) Your storefront (country), your recently-played tracks (up to 100), artists in your library (up to 100), and your "heavy rotation" content (up to 20 items). MusicKit media-library permission via Apple's on-device prompt (a Music User Token; no OAuth scopes). We never see your Apple ID credentials.
Reddit Your username, account age, the subreddits you subscribe to, and up to 100 of your most recent comments and posts (text content included). identity, read, history, mysubreddits
YouTube Your channel ID (if you have one), channels you subscribe to, and up to 100 of your most recent liked videos (titles only). youtube.readonly
Health (Apple Health on iOS, Google Health Connect on Android) The last 90 days of your sleep records (total time asleep per night) and activity records (steps, distance, active energy, exercise minutes, workout types). We do not read sleep stage detail (REM, deep, core), heart rate, HRV, mindfulness, or mental-health data. HealthKit permission on iOS (Apple's on-device prompt); Health Connect permission on Android (Google's on-device prompt). Same five categories on either platform.

You choose which sources to connect. None is required. You can disconnect any source at any time; on disconnect we (a) delete the data we have stored from that source, (b) wipe our stored copy of your access tokens, and (c) where the provider offers a token-revoke endpoint, call it so the token is invalidated at the provider too. Reddit and Google (YouTube) both offer such endpoints and we use them. Apple Music does not offer a server-side revoke — deleting our stored Music User Token is what we control; to withdraw the permission at the source, disable media-library access for the app in iOS Settings → Privacy & Security → Media & Apple Music. The Service only accesses the data types listed and does not post, modify, or delete anything on the source platform.

YouTube API Services. The YouTube connection uses YouTube API Services. By connecting YouTube you are also agreeing to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy. We access, use, and store only the YouTube data items listed in the table above (channel ID, subscribed channels, liked-video titles); we retain them as described in §4 (24-hour cache, deleted on disconnect or account deletion) and share them only with the processors listed in §3. In addition to disconnecting in the app, you can revoke our access to your YouTube data at any time via Google's security settings page at myaccount.google.com/permissions.

Sharing your analysis. You can share an analysis with another person in two ways. (1) In-app sharing: generate a one-time code and give it to someone you trust out-of-band (text, messaging app, in person). When they enter the code in their app while signed in, they see the specific analysis you chose to share, frozen at the time you generated the code — later analyses you run are not shared automatically. The recipient must have a Vetraya account to redeem; codes do not work without one. Unredeemed codes expire after 7 days. (2) Public link: generate a URL anyone can view in a browser without an account. We do not index public links and they are not searchable, but anyone with the URL can view it (including someone the recipient forwards it to). You can revoke either kind of access at any time. We record share, redeem, and revoke events in our internal audit log so we can answer support questions about who could see what and when. We also record opens of shared analyses, de-duplicated to at most one record per hour per session — enough to evidence that an open occurred without accumulating a row per scroll.

1.3 Information we generate

1.4 Technical data

Product analytics (first-party). The mobile app records basic usage events so we can understand which parts of the Service work and which confuse people — for example "connect screen opened", "first-run step 2 reached", "footprint sheet opened". Each event consists of an event name, a small set of non-content properties (for example the step number or the screen name), your pseudonymous account identifier, a per-launch session identifier, the app version, and timestamps. Events never include the content of your connected sources, your profile text, your messages, or your health records. This is entirely first-party: the events go only to our own API and are stored in our own database (AWS Ireland); we use no third-party analytics SDK or service, no advertising identifiers, and no cross-app tracking, and the events are never sold, shared, or used for advertising. We process these events on the basis of our legitimate interest in improving the Service (Art. 6(1)(f) GDPR; see §2). Analytics is on by default; you can turn it off at any time in the app under Profile → Settings → Privacy Preferences → Product analytics — the off switch is enforced on our servers, which then refuse to store events from your account. Receiving a Global Privacy Control signal for your account also turns it off (see below). Stored events are deleted when you delete your account.

Cookies and tracking technologies. The mobile Service does not use cookies, IDFA, the Android Advertising ID, or cross-app tracking identifiers. The hosted web pages where this Privacy Policy, the Terms of Service, the Consumer Health Data Privacy Policy, the Security page, and the Accessibility statement live (the legal-pages/ static site) set no cookies of any kind — no analytics, no advertising, no session, no consent-banner. We have a continuous-integration test that asserts the hosted-policy pages remain cookie-clean after every deploy; if you ever observe a cookie being set on these pages, please report it to security@eltria.de.

Global Privacy Control (GPC). The Service honours the Global Privacy Control signal (`Sec-GPC: 1`). When we receive this header on an authenticated request from your browser or operating system, we record the receipt against your account. The signal is processed once per account; subsequent requests with the same header have no additional effect. We do not sell or share personal information for cross-context behavioural advertising, and there is no advertising in the Service. The one processing the signal can disable is our first-party product analytics described above: when we receive a GPC signal on an authenticated request from your account, we turn product analytics off for your account, exactly as if you had used the in-app toggle. You can turn it back on afterwards in Profile → Settings → Privacy Preferences if the signal did not reflect your preference. We keep the GPC receipt on file so that if we ever add a further feature the signal could disable, your recorded preference will apply to it automatically. The mobile app does not send Sec-GPC by default (in-app webviews and native fetches are excluded by the GPC specification).

2. How We Use Your Information

We process personal data for the following purposes and legal bases (GDPR Article 6):

PurposeData usedLegal basis
Register and authenticate your accountEmail address, date of birth, refresh tokens. When you sign in with Apple or Google, their server-side verification of your identity token (email + stable user identifier).Performance of contract (Art. 6(1)(b))
Generate your personality profileData from connected sourcesConsent (Art. 6(1)(a)) — you choose to connect each source
Process paymentsBilling records via Apple App Store (iOS) or Google Play (Android)Performance of contract (Art. 6(1)(b))
Comply with legal obligationsAudit records, consent historyLegal obligation (Art. 6(1)(c)) — GDPR Art. 7, Art. 30
Diagnose crashes, improve the ServiceError traces, performance metricsLegitimate interests (Art. 6(1)(f))
Understand how the app is used (first-party product analytics, §1.4)In-app usage events: event name, screen or step, pseudonymous account identifier, session identifier, app version, timestamps. Never the content of connected sources, profiles, or health records.Legitimate interests (Art. 6(1)(f)) — you can object at any time via the in-app toggle (Profile → Settings → Privacy Preferences) or a GPC signal, and our servers then refuse to store events from your account
Compatibility reports between two consenting users (optional feature)Your personality profile themes and headline traits, compared with those of one other user who invited you or whom you invited. Never health data, never raw connected-source data.Consent (Art. 6(1)(a)) — creating an invite or redeeming one is the explicit consent of each participant; either participant can delete the joint report at any time
Detect abuse, prevent fraudRate-limit counters, IP addresses at signupLegitimate interests (Art. 6(1)(f))

For health data specifically, we rely on your explicit consent under GDPR Article 9(2)(a). You can withdraw this consent at any time from within the Service, which deletes all stored health data immediately.

We do not:

3. Who We Share Data With

We share the minimum data necessary with the following categories of recipient, each under a written agreement requiring confidentiality and GDPR-compliant processing:

RecipientRoleWhat they receiveLocation
OpenAI, L.L.C.AI processor (model provider)Structured prompts built from the data you connected — for Apple Music, Reddit, YouTube and your health data integration this includes the items listed in §1.2 (e.g. your recently-played tracks and library artists, your Reddit comment text, your liked-video titles, your daily sleep and activity records). Under our API agreement, OpenAI is contractually prohibited from training its models on our API inputs or outputs.United States
Amazon Web Services (AWS)Infrastructure provider (database, storage, messaging)All production data at restIreland (eu-west-1)
AppleSign in with Apple (identity verification) + App Store billing (iOS) + Apple Music (MusicKit, if you connect it)For sign-in: your Apple identity token (signed by Apple), which reveals to us your verified email address and a stable Apple-specific user identifier. For billing: subscription purchase records. For Apple Music: Apple issues the app a Music User Token on your device; Apple does not receive your analysis data from us.Ireland / US
GoogleGoogle Sign-In (identity verification) + Google Play billing (Android) + Health Connect (Android-side health-data store, on-device only)For sign-in: your Google identity token (signed by Google), which reveals to us your verified email address and a stable Google-specific user identifier. For billing: subscription purchase records. Health Connect is the on-device data store from which we read your health records on Android — Google does not receive the records we read; the data leaves your device only to reach our AWS-hosted database, the same way it does on iOS via HealthKit.Ireland / US
Amazon Web Services (SES)Delivers the sign-in link for the email magic-link optionYour email address and a single-use sign-in URL at the moment of sending. The link expires in 15 minutes and is single-use.Ireland (eu-west-1)
RevenueCatSubscription management / entitlement reconciliationPseudonymous user identifier, purchase receipts from Apple / GoogleUnited States
Expo (650 Industries, Inc.)Push-notification relay (forwards to APNs on iOS, FCM on Android) and over-the-air mobile app updatesPseudonymous device push token, push payload contents (e.g. "Your analysis is ready")United States
SentryError tracking (where enabled)Stack traces, device contextEuropean Union (Frankfurt region)

AI processor: OpenAI receives the structured prompts described in the table above. The prompt contains the content items listed in §1.2 (e.g. track and subreddit names, your Reddit comment text, liked-video titles, your per-night sleep records and per-day activity records). We do not include your email address, date of birth, account name, IP address, device identifiers, or any other account-level identifier in the prompt. Under our API agreement with OpenAI, OpenAI is not authorised to use our API inputs or outputs to train its models. Our ability to enforce this depends on the provider honouring its contractual commitments; we have no technical control over what happens inside the provider's systems. If we ever change our AI provider or add an additional one, we will update this policy and obtain your re-consent through the in-app flow described in §9 before the change takes effect. Link: OpenAI Privacy Policy.

International transfers: Some of the processors above are located in the United States. Transfers to these processors rely on the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR) and, where the recipient is certified, the EU–US Data Privacy Framework (adopted under Article 45(3) GDPR by Commission Implementing Decision (EU) 2023/1795), to provide an adequate level of protection under GDPR Chapter V. Sentry, our error-tracking provider, is configured for the European data region (Frankfurt), so error traces from EU users do not leave the EU; for users elsewhere, traces are imported into the EU region rather than exported, which does not require a transfer mechanism under GDPR.

If you use the Service from outside the EEA (for example from India, Singapore, Malaysia, Australia, New Zealand, or the Philippines), your data is transferred to and stored in the European Union (AWS Ireland) and processed by the US sub-processors listed above. The same written agreements described in this section — confidentiality, processing only on our documented instructions, GDPR-grade contractual clauses — are what we rely on to satisfy the cross-border transfer requirements of your local law (e.g. the Transfer Limitation Obligation under Singapore's PDPA, section 129 of Malaysia's PDPA, APP 8 in Australia, and IPP 12 in New Zealand). India's DPDP Act permits transfers to any country the Indian government has not restricted; we do not transfer personal data to any restricted country.

Sub-processor list freshness. The list above is the current set of sub-processors. We commit to keeping it accurate. When we add a new sub-processor that handles personal data in a materially new way, or remove one, we will update this policy at least 30 days in advance of the change taking effect (security-driven failover is the only carve-out where we may act first and disclose immediately after). Material changes to this list trigger a new policy version, which you will be asked to review and accept on next launch through the in-app re-consent flow described in §9. Previous versions of the sub-processor list are archived and available on request to privacy@eltria.de.

Sharing with another user (Compatibility): if you use the optional Compatibility feature, the joint report — a compatibility score and statements drawing on your profile themes and headline traits — is visible to both you and the other participant. Both of you consented to the comparison: one by creating the invite, one by redeeming it. Your underlying analysis, connected-source data and health data are never shared — only the joint report is. Either participant can delete the joint report at any time, which removes it for both; deleting your account removes it too. The comparison is generated by our AI processor (OpenAI, table above) from both participants’ profile themes and headline traits only.

Legal disclosures. We may disclose personal data when we are legally required to do so (e.g. a valid court order from a competent jurisdiction), and only the minimum data necessary. We will notify you unless legally prohibited.

4. How Long We Keep Data

CategoryRetention
Account profileUntil you delete your account
Connected-service data — Apple Music, RedditCached for 24 hours; re-fetched when you run an analysis. Deleted when you disconnect the source or delete your account.
Connected-service data — YouTubeStored in our database and refreshed when you run an analysis. Deleted when you disconnect the source or delete your account.
Health data (whether sourced from Apple Health on iOS or Google Health Connect on Android)Rolling 90-day window: records older than 90 days are deleted by a daily retention job. When you disconnect the health source or delete your account, your health data is removed from our live systems as part of that action; backup copies follow the rotation described under "Backups" below.
Personality profiles and analysis recordsUntil you delete your account
Billing recordsRetained as required by German tax and accounting law: invoices and accounting vouchers for 8 years, and books, inventories and commercial letters for the periods set by § 147 AO and § 257 HGB (up to 10 years). The record is kept in pseudonymised form and the personal link is severed on account deletion; we restrict rather than erase these records until the statutory period expires.
Audit logs (GDPR Art. 30, Art. 32)Differentiated by event class: authentication events (login, sign-in-link request, token refresh) 30 days; routine operational events (analysis lifecycle, cache invalidation, profile views) 90 days; rights-exercise evidence (consent records, deletion confirmations, Art. 22 human-review requests) and admin actions 7 years. Enforced by a daily retention-purge job.
Product analytics events (§1.4)Until you delete your account; removed by the same deletion cascade as the rest of your data. No events are stored at all while your analytics toggle is off.
Access tokens / refresh tokens30 min / 7 days respectively; stored only on your device
Crash reports (Sentry, where enabled)Per Sentry's retention (typically 90 days)

Backups. We take daily encrypted database backups and retain them for seven days before they are overwritten. When you delete your account or disconnect a source, the deletion runs across our live systems as part of that action; backup copies may remain for up to seven days until that backup cycle overwrites them. We do not selectively restore individual rows from backup; backups exist only to recover the whole database after a disaster. If we ever restore from a backup that still contains data you asked us to delete, we re-apply the deletion to the restored data.

5. Your Rights

If the GDPR applies to you (you are in the European Economic Area, the UK, or Switzerland), you have the following rights. These rights apply regardless of location to the extent required by local law:

To exercise any of these rights, contact privacy@eltria.de. We respond within one month as required by GDPR Article 12.

Users in the United States, Canada, India, Singapore, Malaysia, Australia, New Zealand, and the Philippines have rights described in §10 (Regional Addenda) below; those rights apply in addition to anything else in this policy that is more protective of you. If you live anywhere else, we voluntarily extend the rights in this §5 to you as a matter of policy (see §10.10).

5.1 How long we actually take to respond

We commit to the statutory turnaround windows above. We also commit to publishing our actual measured response time, annually, in this section. Until we have a full year of operating data after launch, the table below shows our target rather than our actuals; we will replace target with actual on the first anniversary of launch.

Request typeTarget turnaroundStatutory limit
Right to know / access (Art. 15)Within 14 days1 month (GDPR), 45 days (CCPA, MHMDA)
Right to delete (Art. 17)Within 7 days1 month (GDPR), 45 days (CCPA, MHMDA)
Right to correct (Art. 16)Within 14 days1 month (GDPR), 45 days (CCPA)
Right to portability (Art. 20)Within 14 days1 month (GDPR)
Withdraw consent (Art. 7(3))Immediate (in-app)"As easy to withdraw as to give"
Object to processing (Art. 21)Within 14 days1 month (GDPR)
Automated-decision human review (Art. 22(3))Within 14 days1 month (GDPR)

If we miss a target, we will tell you why and when we expect to respond, within the statutory window.

6. Security

We take security seriously. Technical and organisational measures include:

No system is perfectly secure. If we become aware of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Article 33.

7. Children

The Service is restricted to users 18 and older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us immediately and we will delete it.

8. Automated Decision-Making

The personality profile and, if you use the optional Compatibility feature, the joint compatibility report are generated by automated means (large language models). We consider that neither produces legal or similarly significant effects on you within the meaning of GDPR Article 22(1): both are framed and marketed for entertainment and self-reflection, are not shared by us with third parties for decisioning, and are not used by us to decide credit, employment, insurance, or other consequential matters. A compatibility score is a playful, AI-generated reading of two profiles, not a measurement, an assessment, or advice about any relationship decision. We are aware that the CJEU in SCHUFA Holding (Case C-634/21, 7 December 2023) read "similarly significant" broadly; out of an abundance of caution we nevertheless provide the full set of Article 22(3) safeguards below, and we encourage any user who believes an automated output has materially affected them to invoke them. You retain the right to (a) obtain human review of any automated output, (b) express your point of view on the output, and (c) contest the output. To exercise these rights, email privacy@eltria.de with the analysis date or share link, your view of the output, and what you would like us to reconsider. A reviewer will respond within one month as required by GDPR Article 12.

9. Changes to This Policy

We may update this policy to reflect changes in the Service, applicable law, or our practices. When we make material changes, we will notify you in-app and require you to review and accept the new version before continuing. You can always see the current version and effective date at the top of this page. Previous versions are archived and available on request.

10. Regional Addenda

This section is additive: everything elsewhere in the policy still applies. The items below spell out rights and interfaces required by specific jurisdictions.

10.1 United States — California (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you specific rights over the personal information we hold about you.

Categories of personal information we collect. We collect the categories listed in §1.1 and §1.2 (identifiers, internet or other electronic network activity, commercial information for billing, and where you connect a health source (Apple Health on iOS or Google Health Connect on Android), categories that qualify as sensitive personal information under CPRA §1798.140(ae)). We do not collect geolocation, precise location, genetic, or biometric data.

Sources, purposes, and sharing. Sources are you (account information, sign-in via Apple / Google / email magic link, uploaded data) and the third-party services you choose to connect. Purposes are generating your personality profile, authenticating you, and billing (see §2). Recipients are the sub-processors listed in §3.

We do not sell or share your personal information. CCPA defines "sale" as an exchange of personal information for monetary or other valuable consideration, and "sharing" as a transfer for cross-context behavioural advertising. We do neither. There is no advertising in the Service and we have no agreements that provide personal information to third parties for their own marketing or advertising.

Where we engage vendors to help us deliver the Service (the sub-processors listed in §3 — for example, OpenAI as our AI processor, AWS for infrastructure and email delivery, Apple and Google for sign-in and billing, RevenueCat for subscription reconciliation), those relationships fall within the CCPA service provider exception at §1798.140(ag). Each vendor processes your data only on our documented written instructions, under a contract that prohibits them from selling the data, from retaining or using it outside the scope of our instructions, or from combining it with data from other sources. Service-provider relationships are not a "sale" or "share" under California law.

Your California rights.

How to exercise. Email privacy@eltria.de with the subject line "California privacy rights — [right name]". We respond within 45 days as required by CCPA §1798.130. We verify your request by matching the email address to your account and, where the request is for sensitive information or deletion, by requiring you to authenticate in the app.

Do Not Sell or Share My Personal Information. We do not sell or share your personal information. This link exists because California law requires a clearly labelled control on our privacy policy. Clicking through records your opt-out preference; we will continue not to sell or share.

Limit the Use of My Sensitive Personal Information. The sensitive personal information we process is the health data you choose to connect through your device's health framework (see §1.2). To limit our use of that data, open the app, go to the Connect tab, find the health card (labelled Apple Health on iOS or Health Connect on Android), and tap Disconnect. This stops further processing and removes the stored health records as part of that action. If you cannot access the app, email privacy@eltria.de with "CCPA: limit sensitive" in the subject line and we will apply the limit on your behalf within 15 business days, as required by CPPA regulation §7027.

10.2 United States — Washington and Nevada (consumer health data)

If you connect your device's health source (Apple Health on iOS or Google Health Connect on Android), the resulting sleep and activity records qualify as consumer health data under Washington's My Health My Data Act (RCW 19.373) and Nevada's Consumer Health Data Privacy Act (NRS 603A.300–360). The full set of disclosures, rights, and procedures for consumer health data is in our Consumer Health Data Privacy Policy, which supplements this policy.

Headline commitments from that policy:

For consumer-health-data-specific requests, contact privacy@eltria.de.

10.3 United States — Other state privacy laws

Comparable rights exist under the state privacy laws of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), and other states as they take effect. To exercise rights under any of these laws, email privacy@eltria.de. We honour the Global Privacy Control (GPC) signal (`Sec-GPC: 1`) on authenticated requests, recording receipt against the affected user's account — see §1.4 for the full mechanism. We do not sell or share personal information for cross-context behavioural advertising and run no advertising of any kind. We do run first-party product analytics (in-app usage events, described in §1.4); receiving a GPC signal turns that off for your account, and the in-app toggle does the same.

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (Children's Online Privacy Protection Act — COPPA). The Service is additionally restricted to users 18 and older per §7.

10.4 Canada — PIPEDA (federal)

If you are a Canadian resident, the Personal Information Protection and Electronic Documents Act (PIPEDA) applies. Your rights include access to your personal information, correction, and the right to withdraw consent for further processing. Cross-border transfers to the United States for AI processing and sub-processors are disclosed in §3; you consent to those transfers by using the Service. PIPEDA requires that personal information transferred to another jurisdiction receives "comparable protection" — for our US transfers, this is established through contractual safeguards with each sub-processor.

To exercise PIPEDA rights, email privacy@eltria.de. If you are dissatisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada (OPC).

10.5 Quebec — not available at launch

The Service is not available to residents of the Canadian province of Quebec at this time. Quebec's Law 25 requires that user-facing services be presented in French first and includes specific provisions on automated decision-making; we will launch in Quebec in a future release with the full French-language surface. If you believe you received the Service in Quebec in error, contact privacy@eltria.de.

10.6 India — Digital Personal Data Protection Act (DPDP Act)

If you are in India, the Digital Personal Data Protection Act, 2023 and its rules apply to our processing of your digital personal data in connection with offering the Service to you. Under that Act, we are the Data Fiduciary and you are the Data Principal.

10.7 Singapore — Personal Data Protection Act (PDPA)

If you are in Singapore, the Personal Data Protection Act 2012 applies. This policy serves as the notification of purposes required by the PDPA, and the in-app connect flow is how we obtain your consent.

10.8 Malaysia — Personal Data Protection Act (PDPA 2010, as amended)

If you are in Malaysia, and to the extent the Personal Data Protection Act 2010 (including the 2024 amendments) applies to our processing, we act as the data controller. As required by section 7(3) of the PDPA, this notice is also available in Bahasa Malaysia: Notis Privasi (Bahasa Malaysia).

10.9 Australia and New Zealand

Australia. If you are in Australia, we handle your personal information consistently with the Australian Privacy Principles (APPs) under the Privacy Act 1988, whether or not the Act's small-business threshold makes them mandatory for us. This policy is our APP 1 privacy notice; APP 8 cross-border disclosures are described in §3; you may request access and correction (APPs 12–13) via privacy@eltria.de or the in-app tools; and we notify eligible data breaches under the Notifiable Data Breaches scheme. Complaints: Office of the Australian Information Commissioner (OAIC).

New Zealand. If you are in New Zealand, the Privacy Act 2020 applies. You may request access to and correction of your personal information (IPPs 6–7) via the in-app tools or privacy@eltria.de; cross-border disclosures rely on the contractual safeguards in §3 (IPP 12); and we report notifiable privacy breaches to the Office of the Privacy Commissioner, to whom you may also complain.

10.10 Philippines — Data Privacy Act, and all other jurisdictions

Philippines. If you are in the Philippines, the Data Privacy Act of 2012 (RA 10173) applies. We process your sensitive personal information (health-derived records) only with your consent. You have the rights to be informed, to access, to rectification, to erasure or blocking, to data portability, and to damages — exercisable via the in-app tools or privacy@eltria.de. Complaints: National Privacy Commission (NPC).

Everywhere else. If you use the Service from a jurisdiction not named in this §10, we voluntarily extend the rights described in §5 (access, correction, erasure, portability, objection, withdrawal of consent) to you as a matter of policy, exercisable through the same in-app tools and email contacts. Where your local law grants you additional non-waivable rights, nothing in this policy limits them.

10.11 Supervisory authorities

Complaints or inquiries may be directed to the following authorities depending on where you live:

11. Contact and Data Protection Officer

For any privacy question, request, or complaint, contact Eltria UG (haftungsbeschränkt):

WhatEmail
General privacy questions, GDPR rights requests, complaintsprivacy@eltria.de
Consumer health data (MHMDA / Nevada CHDPA) — see CHD Policyprivacy@eltria.de
Privacy escalations — appeals, complex mattersprivacy@eltria.de
Vulnerability reports — see Security pagesecurity@eltria.de
Accessibility issues — see Accessibility statementcontact@eltria.de

Postal address: Eltria UG (haftungsbeschränkt), Kolonnenstraße 8, 10827 Berlin, Germany.

Data protection responsibility. We have not appointed a formal Data Protection Officer: we are below the threshold of § 38 (1) of the German Federal Data Protection Act (BDSG) (fewer than 20 persons regularly engaged in processing personal data), and at our current scale our processing does not constitute large-scale processing of special-category data within the meaning of Article 37(1)(c) GDPR. Responsibility for data protection sits directly with our management. Our contact for all data-protection matters is privacy@eltria.de. We will appoint a Data Protection Officer, and update this policy, if and when either threshold is met.

Our EU/UK data-protection lead authority is Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI), Alt-Moabit 59–61, 10555 Berlin.