Privacy

Privacy Policy

Last updated: April 22, 2026

Who we are

VYTAL Group is the data controller for your personal data under GDPR.

Contact: hello@vytal-med.com. DPO: dpo@vytal-med.com.

What we collect

Identifiers (name, email, phone), health (weight, BMI, GLP-1-relevant history), and payment (tokenised via Stripe — we never store your card number).

Browsing data (IP, user-agent, cookies) — only with consent.

Why we process it

To deliver the medical service, support, billing and legal compliance. Product improvement and marketing are opt-in.

Legal basis

Contract performance, legal obligation (billing, clinical retention), and consent (marketing).

Third parties

Partner pharmacies (prescription dispatch), telemedicine platforms, Stripe (payments), Resend (email), AWS (infrastructure), Anthropic (AI agent — encrypted).

International transfers

Some processors are outside the EEA (e.g. AWS US). We rely on EU Standard Contractual Clauses.

Retention

Clinical data: 10 years (medical obligation). Marketing: until you withdraw consent. Billing: 10 years.

Your rights

Access, rectification, erasure, marketing objection, portability. Email dpo@vytal-med.com or use the options in your account.

Privacy Policy · VYTAL