Privacy draft

Privacy policy & data practices

Draft — pending legal review
This document is a working draft and has not yet been reviewed by a qualified lawyer. Treat it as informational only. Every entity-identifying fact and every retention/deletion period below is marked [PENDING LEGAL VERIFICATION] until confirmation.

1. Scope of this policy

This policy covers the hemavoy.com website and the Hemavoy analyzer. It addresses the personal data we collect when you use the site, when you upload a lab report or enter values manually, when you create an account, when you save a report to your account history, and when you write to us.

2. Who is the data controller

The data controller for the Hemavoy service is the legal entity identified in the footer of every page. Email privacy@hemavoy.com for any privacy request.

3. What personal data we collect

We collect the minimum personal data needed to deliver the service. The list below describes each category.

  • Account identifiers — your email address, your first name (where you choose to provide one), and a password you set. We do not collect a username that is publicly displayed.
  • Authentication session — a session cookie used to recognise you across requests once you sign in. The session expires when you sign out or after a period of inactivity.
  • Uploaded lab files — photographs, scanned PDFs, or other files you send to the analyzer to be read. Hemavoy treats an uploaded lab file as containing personal health data; it is processed to extract biomarker values and is not retained long-term on Hemavoy's own servers.
  • Manually-entered biomarker values — the values you type into the analyzer row by row, alongside the age and gender you provide for scoring.
  • Extracted interpretation outputs — the per-marker scoring results and the plain-language explanations produced from your inputs, including any saved reports on your account history.
  • Language preference — the locale you pick on the language switcher (Romanian or English). Stored in a cookie called NEXT_LOCALE so the whole site reads in the language you chose.
  • Newsletter and waitlist submissions — if you opt in, your email address and (for the waitlist) your first name, used to keep you posted about new language launches and major feature releases.
  • Support correspondence — any email you send to office@hemavoy.com or privacy@hemavoy.com, plus the replies we send back.

We process your personal data on the following legal bases (Art. 6 GDPR; for special-category health data, we also rely on Art. 9(2)(h)).

  • Contract — to provide the Hemavoy analyzer, your saved reports history, and the account features you sign up to (Art. 6(1)(b)).
  • Consent — for the newsletter, the waitlist, and any optional features we add later. You can withdraw consent any time (Art. 6(1)(a)).
  • Legitimate interests — to keep the site secure, prevent fraud, debug issues, and respond to your support emails, where these interests are not overridden by your rights (Art. 6(1)(f)).
  • Legal obligation — to comply with accounting, tax, and consumer-rights obligations (Art. 6(1)(c)).

5. Special category data — health information

An uploaded lab file contains personal health data. We process that data only to produce the plain-language interpretation you asked for (Art. 9(2)(h) — preventive medicine / occupational medicine / assessment of working capacity, by or under the responsibility of a health professional), and we do so without ever establishing a clinical relationship. We do not store the raw file long-term. We do not use your health data to train any model, and we do not sell it.

6. How long we keep your data

We keep different categories of data for different periods. Every period below is a working placeholder pending lawyer confirmation and is marked accordingly.

Uploaded lab files

[PENDING LEGAL VERIFICATION] — Retention period for the raw file on Hemavoy-owned infrastructure.

Saved interpretation reports (account holders)

[PENDING LEGAL VERIFICATION] — Retention period for the per-marker interpretation rows tied to your account history.

Account data and authentication records

[PENDING LEGAL VERIFICATION] — Retention period for your email, name, session records, and the email-to-account mapping.

7. How to delete your data

You can ask us to delete your account and the data we hold. The process below describes the path.

  1. Sign in and open your account page. Use the Delete account action to trigger an immediate account deletion request tied to your session.
  2. If you no longer have access to your account, write to privacy@hemavoy.com from the email address used at signup. We confirm the request over a verified channel before acting on it.
  3. Once the request is verified we delete your account row, the saved interpretation history tied to it, and your authentication session. We also instruct our subprocessors to delete any data they hold for this account within their respective retention windows.
  4. We send a confirmation email when the deletion is complete. The retention periods for the data we hold on your behalf are listed in section 6 — each is a working placeholder pending legal review.

8. Subprocessors we share data with

To run Hemavoy we use a small number of subprocessors. Each is listed below with the data they receive and the role they play.

AI extraction (lab-file reading and interpretation)

When you upload a lab file we send it to a Cloudflare Worker running the Hemavoy-AI extractor. The worker reads your file, returns anonymised biomarker values to the Hemavoy app, and does not retain the file beyond the request. [PENDING LEGAL VERIFICATION] — Verified processor name and data-processing agreement reference.

Payments (Stripe Connect)

Paid tiers are processed by Stripe via the Polsia Stripe Connect integration. Stripe receives your card details on its hosted checkout page and returns only a payment confirmation to Hemavoy. Hemavoy does not see or store your card number. [PENDING LEGAL VERIFICATION] — Verified Stripe entity, region, and the data-processing addendum reference.

Other infrastructure

  • Hosting — Polsia-managed hosting on the Polsia platform. [PENDING LEGAL VERIFICATION] — Verified hosting region and data-processing agreement reference.
  • Email delivery (transactional + newsletter) — the Polsia-managed email proxy. [PENDING LEGAL VERIFICATION] — Verified processor name and data-processing agreement reference.
  • Authentication — session cookies and account records are managed by the Polsia auth module (better-auth). [PENDING LEGAL VERIFICATION] — Verified processor name and data-processing agreement reference.

9. Your rights under the GDPR

You have the following rights over the personal data we hold. To exercise any of them, write to privacy@hemavoy.com.

  • Access — request a copy of the personal data we hold on you (Art. 15).
  • Rectification — ask us to correct inaccurate data (Art. 16).
  • Erasure — ask us to delete your data (Art. 17), subject to the obligations in section 7.
  • Restriction and objection — restrict processing or object to processing based on legitimate interest (Art. 18, 21).
  • Portability and complaint — receive your data in a portable format (Art. 20) and complain to your national supervisory authority (Art. 77).

10. Contact for privacy questions

For any privacy question, request, or complaint, write to privacy@hemavoy.com. We aim to reply within 30 days.