01Introduction
This document explains how we collect, use, and protect your personal data in connection with your use of the App. It applies globally to all users regardless of location, and we comply with applicable data protection and privacy laws in each jurisdiction where the App is made available, including but not limited to:
| Jurisdiction | Applicable law / framework |
|---|---|
| European Union / EEA | EU General Data Protection Regulation (GDPR) |
| United Kingdom | UK GDPR & Data Protection Act 2018 |
| United States — California | CCPA / CPRA |
| United States — Other States | Applicable state privacy laws (VA CDPA, CO CPA, TX TDPSA, etc.) |
| Canada | PIPEDA & provincial equivalents (PIPA, Law 25 Québec) |
| Brazil | Lei Geral de Proteção de Dados (LGPD) |
| Australia | Privacy Act 1988 & Australian Privacy Principles (APPs) |
| India | Digital Personal Data Protection Act 2023 (DPDPA) |
| South Africa | Protection of Personal Information Act (POPIA) |
| Singapore | Personal Data Protection Act (PDPA) |
| Japan | Act on Protection of Personal Information (APPI) |
| South Korea | Personal Information Protection Act (PIPA) |
| UAE / GCC | UAE Federal Data Protection Law (No. 45 of 2021) |
| All other jurisdictions | Most protective applicable local law |
Where local law provides greater protection than outlined in these terms, the more protective standard applies. By using the App, you acknowledge that you have read and understood these terms. You may withdraw consent at any time.
02Types of Data We Collect
2.1 Personal identification data
- Email address
- Username
- Optional demographic information (e.g., age range, country of residence)
2.2 Special category / sensitive health data
Collected only with explicit consent, including:
- Menopause or perimenopause symptoms
- Basal body temperature
- Weight, blood pressure
- Mood, sleep, cycle tracking
- Any notes you voluntarily enter
2.3 Technical & device data
- Device type, operating system version
- IP address (for security & fraud prevention)
- Crash logs and usage analytics
- App interactions to improve performance
2.4 Data from third-party integrations
Only if voluntarily connected by you (e.g., Apple HealthKit, Google Fit, or equivalent regional health platforms).
03Legal Bases for Processing
We process your data under lawful bases recognised in applicable jurisdictions. The sections below map our processing purposes to commonly recognised legal bases.
3.1 Explicit consent
Required for processing health data and for optional features (notifications, personalised insights, analytics, and anonymised research contributions). You may withdraw consent at any time via in-app settings or by emailing our DPO. Withdrawal does not affect the lawfulness of prior processing.
3.2 Contractual necessity
To provide the core functionality of the App including account creation, symptom tracking, and the core user experience.
3.3 Legitimate interests
For app security, generic performance analytics, and preventing fraud or misuse. A balancing assessment ensures your rights override these interests wherever appropriate.
3.4 Legal obligations
Where we must comply with legal, regulatory, or court-ordered requirements in any applicable jurisdiction.
3.5 Public interest / scientific research (anonymised data)
Where permitted under applicable law, we may process anonymised, de-identified data in the public interest for medical research purposes (see Sections 4.2 and 15).
04How We Use Your Data
4.1 Core service purposes
We process your data to:
- Provide symptom-tracking and wellness services
- Generate non-medical trends and personalised insights
- Improve app performance and user experience
- Provide technical and customer support
- Safeguard the platform from fraud and misuse
- Fulfil legal and regulatory requirements in applicable jurisdictions
We do not make decisions based solely on automated processing that produce legal or significant effects on you.
4.2 Anonymised medical research
With your separate, explicit consent, anonymised and de-identified versions of your health data may be used to support medical research into menopause, perimenopause, and related health conditions. This use is subject to the following strict conditions:
- Your identity will never be disclosed to any research partner, institution, or third party. All data is irreversibly de-identified prior to any research use and cannot be used to identify you.
- Research use is limited to scientific, academic, or public health purposes only. It will never be used for commercial profiling, advertising, or insurance assessment.
- You may opt in to or opt out of research data sharing at any time through in-app settings, without affecting your access to the App's core features.
- Where required by law (e.g., under EU GDPR Article 89, UK GDPR, or equivalent provisions), appropriate safeguards including data minimisation, pseudonymisation, and access controls are applied.
- Research partners who access anonymised data are bound by contractual obligations requiring compliance with applicable ethical and legal research standards.
05Data Sharing & Disclosure
We do not sell your personal data. We may share data only with:
5.1 Service processors
Carefully vetted service providers operating under binding data processing agreements, such as:
- Cloud hosting services
- Security monitoring services
- Analytics providers
- Authentication services
5.2 Anonymised research partners
Academic institutions, public health bodies, or medical research organisations may receive anonymised, de-identified datasets under strict contractual and ethical obligations (see Section 4.2). No personal or identifiable information is ever shared for this purpose.
5.3 Legal or regulatory authorities
Only when required by applicable law, regulation, or valid legal process in any jurisdiction where we operate.
5.4 No unauthorised third parties
Your data is never shared with advertisers, marketers, employers, insurance companies, or any third party not described in these terms.
06International Data Transfers
We are a global service and your data may be processed in countries outside your country of residence. Wherever your data is transferred, we implement legally recognised safeguards appropriate to your jurisdiction, which may include:
- EU/UK Standard Contractual Clauses (SCCs)
- EU Commission or UK Adequacy Decisions
- Binding Corporate Rules (BCRs)
- Supplementary technical and organisational safeguards
- Equivalent mechanisms recognised under LGPD, PIPEDA, the Privacy Act, DPDPA, POPIA, or other applicable laws
You may request information about the specific transfer mechanisms applicable to your region by contacting our DPO.
07Data Security
We implement appropriate technical and organisational security measures proportionate to the sensitivity of the data and applicable legal requirements, including:
- Encryption in transit (HTTPS/TLS)
- Encrypted storage
- Role-based access controls and authentication
- Data minimisation and pseudonymisation where appropriate
- Regular vulnerability assessments and penetration testing
- Staff training and confidentiality obligations
- Data breach notification procedures in accordance with applicable law
08Data Retention
We retain personal data only as long as necessary for the purposes described in these terms, or as required by applicable law. Our standard retention periods are:
- Account data: retained until you delete your account
- Health data: deleted immediately upon account deletion
- Anonymised research data: retained indefinitely by research partners in de-identified form, as it cannot be linked back to you
- Backups: purged according to secure rotation schedules
- Legal records: retained per applicable statutory retention periods in each jurisdiction
09Your Rights
Depending on your jurisdiction, you may have some or all of the following rights regarding your personal data. We honour these rights for all users globally, to the extent applicable under local law:
You also have the right to lodge a complaint with your national or regional Data Protection Authority.
To exercise any of these rights, contact us at nutrexlimited@gmail.com. We will respond within the timeframe required by applicable law (generally 30 days, or 45 days for CCPA requests).
10Children's Data
This App is not intended for individuals under 18 years of age (or the applicable age of digital consent in your jurisdiction, if higher). We do not knowingly collect personal data from minors. If we become aware that data has been collected from a minor, it is deleted immediately.
11Medical Disclaimer
The App is not a medical device and does not constitute medical advice, diagnosis, or treatment. It provides informational wellness tracking only. Always consult a qualified healthcare professional for any medical concerns.
12Data Protection Impact Assessments (DPIA)
Because the App processes special category health data, Data Protection Impact Assessments are conducted where required under applicable law to assess risks, implement organisational safeguards, and ensure ongoing compliance. A summary of any relevant DPIA can be made available upon written request.
13California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including:
- The right to know what personal information is collected, used, shared, or sold
- The right to delete personal information
- The right to opt out of the sale or sharing of personal information
- The right to correct inaccurate personal information
- The right to limit use and disclosure of sensitive personal information
We do not sell personal information as defined under CCPA. To submit a CCPA request, contact us at nutrexlimited@gmail.com or through in-app settings.
14Additional Regional Rights
14.1 Brazil (LGPD)
Brazilian users have rights equivalent to those described in Section 9, including the right to confirmation, access, correction, anonymisation, portability, deletion, and information about sharing, under the Lei Geral de Proteção de Dados (LGPD).
14.2 Canada (PIPEDA)
Canadian users may access, correct, or withdraw consent for their personal information in accordance with PIPEDA and applicable provincial privacy legislation.
14.3 Australia (Privacy Act 1988)
Australian users have rights under the Australian Privacy Principles, including access to and correction of their personal information, and the right to make privacy complaints to the Office of the Australian Information Commissioner (OAIC).
14.4 India (DPDPA 2023)
Indian users have rights under the Digital Personal Data Protection Act 2023, including the right to access, correction, erasure, and grievance redressal through our designated contact.
14.5 South Africa (POPIA)
South African users have rights under the Protection of Personal Information Act (POPIA), including the right to be notified of collection, the right to access, and the right to object to processing of personal information.
15Anonymised Medical Research — Detailed Provisions
This section supplements Section 4.2 and sets out the full terms governing the use of anonymised data for medical research.
15.1 What "anonymised" means
Data is anonymised when it has been irreversibly processed so that you cannot be identified, directly or indirectly, whether by us, a research partner, or any third party. We apply industry-standard de-identification techniques including generalisation, noise addition, and k-anonymity where appropriate.
15.2 Governance and ethics
Research use of anonymised data is subject to:
- Internal review and approval prior to any new research use
- Ethical oversight appropriate to the nature and sensitivity of the research
- Contractual safeguards binding all research partners to applicable legal and ethical standards
- Prohibition on any attempt to re-identify data subjects
15.3 No commercial exploitation of identifiable data
Anonymised research data will never be used to make decisions about individual users, to target advertising, or to assess eligibility for insurance, employment, financial services, or any other individual benefit or detriment.
15.4 Your control
You may opt in to or withdraw from research data sharing at any time through in-app settings. Withdrawal will prevent future data from being included in research datasets but does not retroactively affect anonymised data already provided to research partners, as such data cannot be identified or retrieved.
16Changes to These Terms
We may update these terms from time to time to reflect changes in law, our services, or our practices. Where changes materially affect your rights, we will notify you via:
- In-app alert
- Email notice (where applicable)
Continued use of the App following notification constitutes acceptance of the updated terms. If you do not agree, you may delete your account at any time.
17Contact Information
Nutrex Ltd
Nutrex Ltd • Data Protection Terms & Conditions • v2.0, April 2026
↑ Back to top