OptimealHealth
← Back to home

Privacy Policy

Last updated: March 2025 · GDPR compliant

1. Data Controller

The data controller for personal data collected through the site is OptiMealHealth. Contact: privacy@optimealhealth.com

2. Data Collected

DataPurposeLegal BasisRetention
Email addressAccount creation, communicationContract performanceAccount duration + 3 years
Password (hashed)Secure authenticationContract performanceAccount duration
Profile data (BMI, allergies, goals)Personalised coachingConsentAccount duration
AI conversation historyCoaching continuityLegitimate interest12 months
Payment data (Stripe)Subscription managementContract performanceManaged by Stripe
Connection logsSecurity, fraud preventionLegitimate interest6 months

3. Data Sharing

Your data is never sold to third parties. It may be shared with:

4. Cookies

The site uses a strictly necessary session cookie (optimeal_token) for authentication. No advertising or third-party tracking cookies are used.

5. Your Rights (GDPR)

Under GDPR, you have the right to: access, rectify, erase, port your data, object to processing, and request restriction of processing.

To exercise these rights: privacy@optimealhealth.com. Response within 30 days.

6. Security

We implement appropriate technical measures: bcrypt password hashing, HTTPS connections, JWT authentication, restricted database access.

7. International Transfers

Groq Inc. and Stripe Inc. are US companies. Transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission.