Privacy Policy of the Dietarius Application

(version 1.1 – final wording, July 2026 | English translation)

This English version is a translation provided for convenience. In the event of any discrepancy between the Slovak and English versions, the Slovak version shall prevail.

1. Introductory Provisions and Controller Information

1.1. Equitya s. r. o., with its registered office at Silvánová 33, 902 01 Pezinok, Slovak Republic, registered in the Commercial Register of the Municipal Court Bratislava III, Section: Sro, Insert: 116366/B, Company ID (IČO): 50 337 963 (“We” or the “Controller”) hereby provides information on the manner and scope of processing of your personal data in the Dietarius application available for download via the App Store or Google Play (the “Application”), as well as on the rights you have in connection with the processing of your personal data (the “Policy”). Data protection contact: contact_us@dietarius.eu.

1.2. The protection of privacy and the processing of personal data is our priority and we treat the processing of your personal data as strictly confidential. Your personal data are handled in accordance with applicable data protection legislation, in particular the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and Act No. 18/2018 Coll. on Personal Data Protection and on Amendments to Certain Acts (the “Act”).

2. Data Subjects and Sources of Personal Data

2.1. As the operator of the Application, we obtain, store, use and otherwise process the personal data of persons using the Application (“you” or the “Data Subjects”), in particular upon registration in the Application in accordance with the General Terms and Conditions of the Dietarius application.

2.2. We process your personal data primarily where you provide them to us yourself, for example by completing the registration form, entering data into the Application or uploading a photograph to the Application. We also obtain personal data from other sources, in particular from your use of the Application, from pairing the Application with your Dietarius personal scale, and the like.

2.3. The provision of personal data to the extent necessary for registration and use of the Application (nickname, e-mail address, password) is a contractual requirement – without them, a personal account cannot be created and the Application cannot be used. The provision of other data (in particular health data, photographs and data for marketing purposes) is voluntary; not providing them does not affect the use of the basic functions of the Application, but may limit the availability of certain functions (e.g. body scan). When exercising the withdrawal from the contract via the withdrawal function in the Application, the provision of the name, surname, contract identification and e-mail address is a statutory requirement (Section 20a of Act No. 108/2024 Coll.) – without these data, the withdrawal cannot be processed via that function; this is without prejudice to the possibility of withdrawing from the contract by other means.

3. Purpose, Legal Basis, Scope of Processing and Retention Period of Personal Data

3.1. We always process your personal data in accordance with applicable law, for the purposes, on the legal bases, to the extent and for the periods set out in detail in the overview below:

Purpose of processing and legal basis Categories of personal data Retention period

Registration and administration of the personal account

Purpose: Carrying out registration, creating the account and making the content of the Application available on the basis of your registration

Legal basis: Art. 6(1)(b) GDPR (performance of a contract and pre-contractual steps); Art. 6(1)(f) GDPR (legitimate interest) – our legitimate interest in efficiently continuing the registration process in the case of incomplete registration. You may object at any time to processing based on legitimate interest (Article 5 of this Policy).

Identification and contact data (nickname/username, e-mail address, password in secured (hashed) form; name and surname if you provide them in your profile); information on the Application settings, the course of registration, account activation, etc. For the duration of the personal account and subsequently for three (3) years from its deactivation/cancellation; in the case of incomplete registration, for 72 hours from the provision of the data.

Use of the Application and its functions (including the processing of health data)

Purpose: Full use of the Application’s user interface and its functionalities and paid content, and informing about the need for updates, technical shortcomings, outages, etc.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract); Art. 6(1)(f) GDPR (legitimate interest in the proper functioning of the Application) – right to object under Article 5 of this Policy; Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR (explicit consent) – your consent to the processing of health data, where you provide it. You may withdraw your consent at any time (Article 5 of this Policy).

Identification and contact data; information on the use of the Application (in particular logins, selected language, logs, etc.); data from the Dietarius scale generated by the scale or Application functionality and data entered into the Application (e.g. height, weight, age, sex, lifestyle, activities), including health data (e.g. body fat percentage, etc.); content uploaded by the User to the Application, in particular images (photographs). For the duration of the personal account and subsequently for three (3) years from its deactivation/cancellation; health data processed on the basis of consent until withdrawal of consent, at the longest for the duration of the personal account.

Administration of payments and subscriptions

Purpose: Processing of subscriptions and the exercise of rights and obligations under the contractual relationship, primarily in relation to the premium content of the Application. Payments are made through the App Store (Apple) and Google Play (Google) payment systems, which act as independent controllers under their own terms when processing payments; for App Store purchases, Apple also acts as the seller of the premium content. The Controller has no access to your payment card data and processes only the transaction data made available to it by the application store

Legal basis: Art. 6(1)(b) GDPR (performance of a contract and pre-contractual steps)

Identification and contact data (e.g. nickname, e-mail address); invoicing data and information on transactions made available to the Controller by the application store (e.g. transaction identifier, subscription payment status); information on the purchased service and the form of its payment. For the duration of the contract and subsequently for three (3) years from its termination.

Compliance with legal obligations

Purpose: Compliance with the Controller’s obligations under applicable law, e.g. Act No. 108/2024 Coll. on Consumer Protection, Act No. 40/1964 Coll. the Civil Code, Act No. 595/2003 Coll. on Income Tax, Act No. 222/2004 Coll. on VAT, Act No. 431/2002 Coll. on Accounting

Legal basis: Art. 6(1)(c) GDPR (compliance with a legal obligation)

Personal data required by applicable law or necessary for compliance with the Controller’s statutory obligations, e.g. name, surname and others. As required by applicable law, e.g. ten (10) years under the Accounting Act.

Customer communication

Purpose: Handling customer requests, complaints and grievances, including the processing of a withdrawal from the contract exercised also via the withdrawal function in the Application

Legal basis: Art. 6(1)(b) GDPR (performance of a contract – handling complaints and requests related to the contract); Art. 6(1)(f) GDPR (legitimate interest) – our legitimate interest in handling other customer requests and questions, in particular from consumers

Contact data (in particular e-mail); the content of mutual communication. Three (3) years from the handling of the request, complaint, grievance or question.

Security of the Application and prevention of misuse

Purpose: Protection against misuse, security logs, updates

Legal basis: Art. 6(1)(f) GDPR (legitimate interest) – legitimate interest in achieving the above purposes. Right to object under Article 5 of this Policy.

Logs, IP address, technical data; contact data. For the period necessary to achieve the purpose (max. one (1) year).

Preparation and sending of marketing communications and personalised offers

Purpose: We will send you marketing communications to inform you about offers, services and news related to the Application and the Controller’s business. For the purposes of effective marketing, we may carry out data segmentation and profiling for marketing purposes and prepare and send automated personalised offers through the Controller’s own CRM system operated on the Controller’s own infrastructure in the EU.

Legal basis: Art. 6(1)(a) GDPR (consent). Consent is voluntary, is given separately (it is not a condition of using the Application) and is obtained in a two-step process (double opt-in): after ticking the relevant box, we send you a confirmation e-mail and consent is given only upon clicking the link in it. You may withdraw your consent at any time, including with one click on the “unsubscribe” link in every marketing message; withdrawal of consent also results in the immediate cessation of profiling for marketing purposes.

E-mail address, nickname, name and surname (if provided), information on services and functions purchased within the Application and on interactions with marketing communications. Until withdrawal of consent; at the longest for the duration of the active account in the Application and subsequently one (1) year from its cancellation, unless you withdraw your consent earlier.

Defence and protection of the Controller’s legal claims, demonstration of compliance with legal and other obligations

Purpose: The Controller processes your data for the purposes of demonstrating compliance with legal and other obligations, and of asserting and defending the Controller’s entitlements and claims in proceedings before courts and public authorities, enforcement and similar purposes.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest) – the Controller’s legitimate interest in the defence and protection of legal and similar claims. Right to object under Article 5 of this Policy.

The above categories of personal data to the extent necessary. For the duration of the limitation periods under applicable law.

Processing of data and photographs for AI training, improvement of the Application and statistics

Purpose: Usage analysis, development of new functions, training of artificial intelligence (AI) – including the Controller’s own AI models. We may use your data to obtain information about the individual functions of the Application and their use by you as users. For these purposes we primarily use anonymised and aggregated data from which you cannot be identified; the GDPR does not apply to such anonymous data. Where personal data that are not anonymised – in particular photographs uploaded by you or data that may contain health data – are to be used for AI training or improving the Application, we process them exclusively on the basis of your explicit, separately given consent, revocable at any time. If you withdraw your consent, we will no longer use your photographs and non-anonymised data for these purposes; the lawfulness of processing carried out before the withdrawal remains unaffected.

Legal basis: Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR (consent) – your explicit consent for non-anonymised data (including photographs and health data). You may withdraw your consent at any time (Article 5 of this Policy). Art. 6(1)(f) GDPR (legitimate interest) in improving the Application’s functions, developing new functions and business development – exclusively for the anonymisation process and for working with fully anonymised, aggregated statistics. Right to object under Article 5 of this Policy.

Data entered by you into the Application or generated by the Application; photographs, if you have given consent. For the period necessary for the anonymisation of the data; anonymised data – without limitation; until withdrawal of consent where processing is based on consent, at the longest for one (1) month from obtaining the data for this purpose.

4. Recipients of Personal Data, Transfers to Third Countries, Automated Decision-Making and Profiling

4.1. Personal data are accessible only to the Controller’s authorised employees and co-workers.

4.2. To the extent permitted by applicable law, your personal data may also be disclosed to third parties outside the Controller. These external recipients may include in particular:

  1. providers of IT and audit services, in particular Alfa-Audit s.r.o., and OVHcloud (OVH Groupe SA and its subsidiaries; hosting of the Controller’s server infrastructure, data centres exclusively in the EU) – a processor under Art. 28 GDPR;
  2. Apple (Apple Distribution International Ltd.) and Google (Google Ireland Ltd.) – in the distribution of the Application via the App Store/Google Play and in the processing of in-app payments, they act as independent controllers under their own privacy terms;
  3. providers of AI services, where external AI APIs are used for a specific function of the Application (Anthropic, PBC – Claude API; OpenAI) – processors under Art. 28 GDPR; the Controller’s own AI models are operated on the Controller’s own infrastructure and are not an external recipient; the Controller’s internal CRM system is operated as a self-hosted installation on OVHcloud infrastructure in the EU and the supplier of the CRM software has no access to personal data;
  4. public authorities, where required by applicable law or necessary for the exercise of the Controller’s rights;
  5. the Controller’s legal and other representatives and advisers.

4.3. We process your personal data primarily within the EU/EEA (the Controller’s infrastructure is operated in OVHcloud data centres in the EU). A transfer to a third country (USA) may occur (i) when external AI APIs are used (Anthropic, OpenAI) and (ii) to a limited extent in connection with the services of Apple and Google. Transfers rely on the European Commission’s adequacy decision for entities certified under the EU–US Data Privacy Framework and, subsidiarily, on standard contractual clauses under Art. 46(2)(c) GDPR together with supplementary measures. You may request a copy of the relevant safeguards at contact_us@dietarius.eu.

4.4. No automated individual decision-making producing legal effects or similarly significantly affecting you within the meaning of Art. 22 GDPR is carried out when processing personal data for the above purposes. However, on the basis of your marketing consent, we carry out profiling for marketing purposes (segmentation and personalisation of offers in our own CRM system, possibly with the support of AI tools); you may object to profiling for direct marketing purposes at any time free of charge under Art. 21(2) GDPR, and we will cease it immediately upon your objection or withdrawal of consent. The outputs of AI tools are subject to human oversight.

5. Rights of Data Subjects and How to Exercise Them

5.1. As a data subject, you have in particular the following rights in connection with the processing of your personal data, the exercise of which may be limited in accordance with applicable law:

  • the right of access to your personal data (information on whether such data are processed, and a copy of them);
  • the right to rectification or completion of inaccurate data;
  • the right to withdraw consent where your data are processed on the basis of consent. Withdrawal of consent takes effect on the day it is communicated to the Controller. The lawfulness of processing based on consent before its withdrawal remains unaffected;
  • the right to erasure of personal data where they are no longer needed or were processed unlawfully;
  • the right to restriction of processing;
  • the right to data portability (where processed on the basis of a contract or consent by automated means);
  • the right to object to processing based on legitimate interest; an objection to processing for direct marketing purposes, including profiling, is absolute – upon its lodging we will immediately cease processing for those purposes;
  • the right to lodge a complaint with the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky); contact details are available at https://dataprotection.gov.sk/uoou.

5.2. To exercise your rights or with any questions regarding the processing of your personal data, you may contact us at the e-mail address contact_us@dietarius.eu or at the address of the Controller’s registered office stated in the heading of this Policy. The Controller reserves the right to verify the identity of the Data Subject exercising the above rights in an appropriate manner; verification will always be proportionate to the nature of the request. We will respond to your request free of charge within one (1) month of its receipt; in complex cases we may extend this period by a further two (2) months, of which we will inform you.

6. Amendments to the Policy and Effectiveness

6.1. We may update this Policy from time to time, in particular in the event of changes in legislation, changes in our processing operations or changes in the recipients of personal data. We will inform you of material changes by e-mail and/or by a notice in the Application; the updated wording applies from its effective date stated in the Policy. Your rights under Article 5, in particular the right to withdraw consent at any time, remain unaffected.

6.2. The current version of this Policy is available in the Application and on the website www.dietarius.eu/ochrana-osobnych-udajov-aplikacie/.

6.3. This Policy is valid and effective from 1 February 2026, as amended by revision No. 1.1 effective from 1 August 2026.

Návrat hore

Kontakt

Equitya s.r.o.
Silvánová 33
902 01 Pezinok

+421 948 478 509

contact_us@dietarius.eu

Copyright 2026, Dietarius. All Rights Reserved.