iNuba APP PRIVACY POLICY

Summary

This summary does not replace the full text, but sets out the essentials up front:

1. Data Controller

3DHealthAI, S.L. ("iNuba"), Polígono Industrial Los Vientos, C/ Levante, 1, 46119 Náquera (Valencia), Spain, NIF B-40644445.

Data Protection Officer: dataprotection@inuba.com.

2. When this text applies and who decides what

Versions under a third-party brand (white label). This policy applies equally when you use the App under the brand of a Partner Entity: iNuba remains the Data Controller for the processing of your information in the App. If you access it that way, part of your data does not come from you but from the Partner Entity (sections 3.1 and 7), and we inform you of this in accordance with Article 14 GDPR.

Allocation of roles within the iNuba ecosystem. iNuba acts as Data Controller for the information you generate using the App, the iNuba Hardware and your devices. When you link to a professional or clinic through iNuba Clinic, it is that professional who acts as Data Controller for the clinical information they manually add about you (clinical record, observations, protocols and the plans they assign to you), with iNuba acting as their Data Processor. Certain processing operations within the ecosystem - registration and linking, the activity history and the synchronisation between the App and the professional platform - are determined jointly; the essential terms of the agreement entered into between iNuba and your professional are available to you on request.

3. What information we process

3.1 Account and profile

Email address, password - held by our identity provider, Google Firebase, and never stored by iNuba -, language and device. If you register with Google or Apple: your email address and the basic profile data the provider passes on to us, including first name and surname, which we use to pre-fill your initial questionnaire. Profile photograph, which is optional.

If you access through a white label version, the Partner Entity passes on to us your identification data (name, email address, identity document and date of birth), your access status and, where it holds them, health profile data (ethnic origin, declared conditions, sex, height and weight), in order to register you and maintain your access.

3.2 Initial questionnaire and health profile

First name and surname, date of birth, sex, ethnic origin, country, height, weight, goal pursued, lifestyle, type and frequency of physical activity, and medical conditions. Ethnic origin and medical conditions are special category data: we process them on the basis of your explicit consent, in order to calibrate both the variables and the proposals you receive correctly.

3.3 Health variables recorded in the App

Every variable keeps a trace of its origin: entered by you, imported from the iNuba Hardware, received from a wearable, or added by your professional.

3.4 Wearables and health platforms on your device

Subject to your authorisation in the operating system:

Synchronisation may take place in the background even when the App is closed, through periodic operating system tasks. The transmission is authenticated with a technical key specific to your user account, which can be revoked. You can withdraw the permissions at any time from your device settings.

3.5 Scanning with iNuba Hardware

RGB images captured by three cameras, thermography, bioimpedance obtained from two scales, answers to the prior questionnaire (pregnancy, pacemaker and implants) - used at the very moment of the scan to determine whether the bioimpedance measurement should be taken - and the environmental variables of the session entered by your professional.

3.6 Questionnaires and protocols

Answers to the questionnaires sent to you by iNuba or your professional, their completion status and their history; and the record of the actions triggered by the automated protocols your professional may have configured (messages, measurement requests and reminders), with their date and their outcome.

3.7 Alerts

Record of the notices generated when a variable exceeds the margins set by your professional, stating the variable concerned, the value, the threshold and the time.

3.8 Subscription and billing

Subscription identifiers, amounts and payment status managed by the app stores, together with the tax details needed to issue an invoice where applicable. iNuba has no access to your card details.

3.9 Technical usage information

Device identifiers, App usage events for analytics purposes, error reports and consent records (date, IP address, device, language, version and digital fingerprint of the document accepted).

3.10 Demonstration accounts

There are "demo" accounts populated with synthetic data that does not correspond to real people, intended for clinics to evaluate the product. As they are not personal data, they fall outside the retention cycles.

Purpose Legal basis
Providing you with the service: account, health monitor, scan and avatar, plans, questionnaires, protocols and alerts Performance of the contract (Art. 6(1)(b) GDPR) and, for health data, your explicit consent (Art. 9(2)(a) GDPR)
Linking to your professional or clinic and their access to your information Your explicit consent (Arts. 6(1)(a) and 9(2)(a) GDPR), given when you accept the linking invitation. In white label versions of occupational health services or healthcare entities, the disclosure of your scan results to the entity relies on your explicit consent given at registration, and the entity processes them under its own legal basis (Art. 9(2)(h) GDPR and health surveillance legislation, where applicable)
Generation of nutrition and training plans by means of artificial intelligence systems Performance of the contract (Art. 6(1)(b) GDPR) and explicit consent for health data (Art. 9(2)(a) GDPR). See section 5
Billing, payment collection and compliance with tax obligations Legal obligation (Art. 6(1)(c) GDPR)
Operational and care-related communications Performance of the contract (Art. 6(1)(b) GDPR)
Commercial communications Your consent (Art. 6(1)(a) GDPR), revocable from Settings
Usage analytics and technical improvement (Firebase) Legitimate interest in improving the service (Art. 6(1)(f) GDPR), with minimised data; on iOS, additionally subject to tracking permission (ATT)
Security, fraud prevention and evidencing of consents Legitimate interest (Art. 6(1)(f) GDPR) and duty to demonstrate compliance (Art. 7(1) GDPR)
Aggregated statistics and improvement using anonymised data (variables, never images) Legitimate interest and compatibility with statistical purposes (Arts. 6(1)(f), 5(1)(b) and 89 GDPR), with the right to object. See section 6.2
Training of our technology with images and associated research; sharing of anonymised individual-level datasets Your specific consent, separate for each purpose (Arts. 6(1)(a) and 9(2)(a) GDPR, with the safeguards of Art. 89). See sections 6.3 and 6.4

5. Artificial intelligence

5.1. What it consists of. The nutrition and training plans you receive, as well as certain support functions of the automated protocols, are produced by artificial intelligence systems operated by iNuba. We inform you of this expressly in compliance with the transparency obligations of Regulation (EU) 2024/1689 on artificial intelligence and with Article 13 GDPR.

5.2. What information is used. To generate a proposal we use your profile data, your goals, your recorded health variables, the biometrics coming from wearables, the scan results and your questionnaire answers. Your body images and your thermographies are not used to generate plans.

5.3. No automated decisions with legal effects. These systems produce guidance recommendations. No decisions are taken based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Where there is a linked professional, they can review, adjust, replace or discard any proposal before assigning it to you, and their professional judgement remains intact.

5.4. Limitations. The output of an artificial intelligence system may be inaccurate. We apply reasonable validation and quality control measures, but this does not allow us to guarantee absolute accuracy. Consult your doctor or healthcare professional before incorporating any proposal into your routine, and especially so where there are medical conditions, pregnancy, breastfeeding, allergies, intolerances or ongoing medication.

5.5. What you can ask us for. You can request additional information at dataprotection@inuba.com about the general logic applied and, through your linked professional, human review of a specific proposal.

5.6. Model training. The use of your information to train and improve these systems is governed by sections 6.2 and 6.3, and it never takes place with identifiable images without your express and separate authorisation.

6. Your images and your data: ordinary operation and the decisions that are yours

6.1 Provision of the service, history and progress (ordinary operation)

Your scan images, three-dimensional avatars, thermographies and variables are stored and used to produce your results, your history and your progress comparison for as long as you keep the account. This includes the technical operations that are essential to run, maintain, ensure the quality of and technically improve the service you receive - error correction, calibration of results and security -, which form part of the service itself. Legal basis: performance of the contract and your explicit health consent given at registration (Arts. 6(1)(b) and 9(2)(a) GDPR). This information is only deleted if you exercise your right to erasure or delete your account, in which case the legal blocking periods in section 9 apply.

6.2 Aggregated statistics and improvement using anonymised data (ordinary operation, with the right to object)

We produce statistics, analyses and studies using irreversibly anonymised and aggregated data - health variables, never images - for the dual purpose of improving our services and of compiling reports and statistical datasets for the health sector, which may be shared with or sold to third parties. Such datasets no longer allow you to be identified and cease to be personal data (Recital 26 GDPR). The prior anonymisation step relies on our legitimate interest and on its compatibility with statistical purposes, with the safeguards of Article 89 (Arts. 6(1)(f) and 5(1)(b) GDPR), following an impact assessment and applying a minimum aggregation threshold.

You can object whenever you wish by writing to dataprotection@inuba.com: your information will stop being included in the datasets generated from that moment on, and those already anonymised can neither be reversed nor attributed to you. The information of minors is excluded.

6.3 Training and improvement of our technology with your images (requires authorisation)

This processing is not yet operational. Your body images and thermographies may contribute to training and improving our technology - the three-dimensional avatar and new health features - as well as to the associated scientific research, with the safeguards of Article 89 GDPR. Since images cannot be fully anonymised, this use will only be activated if you authorise it through a specific and separate checkbox (Arts. 6(1)(a) and 9(2)(a) GDPR), which we will ask you for at the appropriate time - for example, after your first scan - and which you will be able to manage from Settings → My consents.

What happens if you withdraw your authorisation. Your images are not deleted: they remain stored in order to provide you with the service under section 6.1. They simply stop being used in training and are excluded from subsequent model improvement cycles. Models already trained do not contain identifiable personal data and do not allow immediate individual extraction, a limitation we disclose to you transparently; those models may be licensed to third parties in the health sector. Your images are only deleted if you exercise your right to erasure. Retention for this purpose: for as long as your authorisation subsists and, in any event, within the periods in section 9. Before activating this processing, the impact assessment required by Article 35 GDPR will be completed.

6.4 Sharing anonymised individual-level datasets with third parties (requires authorisation)

Beyond the aggregated statistics in section 6.2, we may compile irreversibly anonymised individual-level datasets - person-level records that no longer allow you to be identified - and share them with third parties in the health sector (laboratories, insurers, academic institutions or medical device manufacturers) for research, statistical or health product and service development purposes. This processing is not operational either: its activation will be preceded by the corresponding impact assessment and by technical anonymisation controls with a minimum aggregation threshold, and you will be notified of it. The sharing will only be activated if you authorise it through a specific and separate checkbox, revocable whenever you wish from Settings → My consents or by writing to dataprotection@inuba.com. The information of minors and the data coming from third-party health platforms and wearables (Apple Health, Health Connect and any integrations added in future, such as Garmin or Whoop) are excluded, as the terms of those platforms prohibit sharing them. No image is shared with third parties.

None of the uses in this section conditions the ordinary operation of the App: the service is identical whether or not you tick the boxes and whether or not you exercise your right to object.

7. Who else accesses your information

8. Data location and international transfers

The servers and backups are located in the European Union (France). Certain providers - Google and Firebase, RevenueCat, ActiveCampaign and, where applicable, the artificial intelligence providers - may involve transfers to the United States, relying on the EU-US Data Privacy Framework or on standard contractual clauses. You can request additional information from the Data Protection Officer.

9. How long we keep your information

10. What you can require from us

You can exercise the rights of access, rectification, erasure, objection, restriction and portability, and withdraw any consent, at dataprotection@inuba.com or from the App itself:

Response time: one month (Art. 12(3) GDPR). You may lodge a complaint with the Spanish Data Protection Agency (AEPD) (aepd.es).

11. Security measures

We apply encryption in transit (TLS) for communications with the App, access control through authenticated identity and service keys, logical isolation per customer, verification of the cryptographic signature of the notifications from our payment provider, data aggregation in analytics processes, and daily encrypted backups of our databases, hosted on separate infrastructure within the European Union. No system is infallible; we will notify breaches in accordance with Articles 33 and 34 GDPR.

12. Minimum age

The App requires you to be sixteen (16) years old. We do not knowingly process information about children below that age; if we become aware of an account in that situation, we will delete it. The information of minors is excluded from the uses described in sections 6.2 and 6.4.

13. Updates to this text

We will publish successive versions stating their effective date and digital fingerprint, and we will obtain re-acceptance where the significance of the change requires it. The version history remains available at inuba.com/legal.