Privacy Policy
Current privacy terms for Digestia GLP-1, including account data, self-reported health data, first-party analytics, payments, rights and international transfers.
Product Discovery analytics are deliberately separated from health content: medication, dose, symptoms, weight and free-text health notes are not stored in those product events.
Digestia GLP-1 Privacy Policy — version 2.1
Effective: 2026-09-12
1. Controller and contact
Digestia GLP-1 is operated from Amsterdam, the Netherlands. For privacy, support and data-rights requests, use the Contact page or support@digestiaglp1.com.
2. Account and service data
We may process email, language, user identifier, preferences, legal acceptances, subscription status and technical security records needed to create, protect and operate the account.
3. Self-reported health data
If you choose to use tracking features, you may log medication dose, weight, symptoms, meals, hydration, check-ins and other routine-related information. These data receive enhanced protection and we do not require health information unnecessary for the feature you chose.
4. Purposes and lawful bases
Account data is used to provide the service and administer the contractual relationship. Self-reported health data is processed, where applicable, with explicit consent. Minimal technical records may be processed for security, abuse prevention and legal defence. Payment and tax data may be retained for legal obligations.
5. Health-data consent
Consent must be specific, informed and withdrawable. Withdrawal does not invalidate lawful prior processing but may prevent features that depend on those data. Features that do not require health data are not conditioned on unnecessary consent.
6. Analytics and Product Discovery
First-party minimised telemetry measures stages such as visit, signup, first log, summary, Premium offer and payment. It does not store medication, dose, symptom, weight or free-text health content. Pseudonymous identifiers and coarse acquisition labels are used without search terms or full referrer URLs.
7. Educational AI
When users choose an educational AI feature, information necessary to generate the response may be processed by the corresponding technical infrastructure. The interface explains when personal logs are used. AI is not used for diagnosis, prescription or emergency decisions.
8. Payments
Checkout uses third-party infrastructure. Account identifiers, email, plan, price, currency, status and transaction identifiers may be processed to create and reconcile a purchase. Health records are not sent to checkout and Digestia does not store full card details.
9. Providers and recipients
We may use providers for hosting, database, authentication, transactional email, payments, security and AI infrastructure. We share only what is necessary and do not sell or rent personal data.
10. International transfers
Where data is processed outside the EEA or the country of residence, we apply safeguards required by applicable law, such as adequacy decisions, Standard Contractual Clauses and supplementary measures.
11. Retention
Personal records are kept while the account is active or until a valid deletion request, unless legal retention is required. Payment, security, consent and legal-defence records may be kept for the period necessary for their respective purposes and legal obligations.
12. Rights
Depending on applicable law, users may request access, confirmation, correction, export/portability, deletion, restriction, objection, information about sharing and consent withdrawal. Requests can be initiated in the privacy dashboard or through the Contact page.
13. Complaints
In the EU/EEA, users may complain to the competent authority; in the Netherlands, the Autoriteit Persoonsgegevens. In Brazil, LGPD rights and the ANPD apply where relevant.
14. Automated decisions
Digestia does not make solely automated decisions producing legal or similarly significant effects on users.
15. Security
We apply authentication, access controls, server-side validation, minimisation, separation of duties, abuse limits and security records. Relevant incidents will be handled and notified as required by applicable law.
16. Changes
Material changes will be communicated and renewed acceptance requested where required.