Privacy Policy

Health-Data GmbH – for the NumaSense application at our partners and our website

1. Controller

Health-Data GmbH
Maria-Goeppert-Straße 5
23562 Lübeck
Germany

Represented by:
Managing Director Alexander Nelles

Commercial register: Local Court of Lübeck, HRB 26668 HL
VAT ID: DE458964386

Email: info@health-data.ai

2. Data Protection Officer

Guido Eicheler
c/o Health-Data GmbH
Maria-Goeppert-Straße 5
23562 Lübeck
Germany

Email: info@health-data.ai (subject line “Data Protection Officer”)

3. General information on the processing of personal data

3.1 Scope of the processing of personal data

We process personal data of our users only to the extent necessary to provide a functioning website as well as our content and services.

3.2 Legal basis for the processing of personal data

Where we obtain the consent of the data subject for processing operations involving personal data, Art. 6(1)(a) GDPR serves as the legal basis. For the processing of personal data required to fulfil a contract, Art. 6(1)(b) GDPR serves as the legal basis. Where processing is necessary to safeguard a legitimate interest, Art. 6(1)(f) GDPR serves as the legal basis. For the processing of health data within the scope of the NumaSense application, Art. 9(2)(a) GDPR in conjunction with explicit consent serves as the legal basis.

3.3 Data erasure and storage period

The personal data of the data subject will be erased or blocked as soon as the purpose of storage no longer applies. Storage may also occur beyond this point if required by statutory provisions.

4. Data collection as part of the NumaSense breath pattern analysis at our partners

4.1 Description and scope of data processing

As part of the use of our NumaSense system at our partners, the NumaSense tablet collects breath patterns as well as anamnesis data such as age, sex, height, weight and smoking status. This data is linked with the medical diagnosis. Collection only takes place after explicit consent has been given by the data subject.

4.2 Legal basis

The legal basis for the processing is Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR.

4.3 Purpose of data processing

The data is used to train our models, for scientific and clinical studies, and within the scope of MDR certification.

4.4 Recipients or categories of recipients and processors

As a processor, we use Hetzner Online GmbH, which provides hosting in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with this provider. No transfer to third countries currently takes place.

4.5 Storage period and erasure

The collected data is stored in pseudonymised form. The assignment to the identity of the data subject is stored separately.

4.6 Withdrawal of consent

Consent can be withdrawn at any time and informally by email.

5. Use of our website www.health-data.ai

5.1 Provision of the website and creation of log files

Each time our website is accessed, our hosting provider Hetzner automatically collects information that is stored briefly in log files. The legal basis for this is Art. 6(1)(f) GDPR. The data is deleted after a few days.

5.2 Cookies

Our website does not use cookies.

5.3 Contact

Contact can be made by email to info@health-data.ai. No contact form is offered.

5.4 Web analytics tools

We do not use any web analytics tools.

6. Rights of the data subjects

If your personal data is processed, you have the following rights:

Right to information (Art. 15 GDPR)
Right to rectification (Art. 16 GDPR)
Right to erasure (Art. 17 GDPR)
Right to restriction of processing (Art. 18 GDPR)
Right to data portability (Art. 20 GDPR)
Right to object (Art. 21 GDPR)
Right to withdraw consent given (Art. 7(3) GDPR)
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

The competent supervisory authority is the Independent Centre for Privacy Protection Schleswig-Holstein (ULD), www.datenschutzzentrum.de.

7. Data security

In accordance with Art. 32 GDPR, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk. These include, in particular, pseudonymisation, TLS encryption, access restrictions, confidentiality obligations for our staff, and regular review of our security measures. Documentation of the technical and organisational measures (TOMs) is maintained separately.

8. Timeliness and amendment of this privacy policy

This privacy policy is dated 4 September 2026. The current version is always available at www.health-data.ai.