Privacy Policy
Last updated: April 22, 2026
Who we are
VYTAL Group is the data controller for your personal data under GDPR.
Contact: hello@vytal-med.com. DPO: dpo@vytal-med.com.
What we collect
Identifiers (name, email, phone), health (weight, BMI, GLP-1-relevant history), and payment (tokenised via Stripe — we never store your card number).
Browsing data (IP, user-agent, cookies) — only with consent.
Why we process it
To deliver the medical service, support, billing and legal compliance. Product improvement and marketing are opt-in.
Legal basis
Contract performance, legal obligation (billing, clinical retention), and consent (marketing).
Third parties
Partner pharmacies (prescription dispatch), telemedicine platforms, Stripe (payments), Resend (email), AWS (infrastructure), Anthropic (AI agent — encrypted).
International transfers
Some processors are outside the EEA (e.g. AWS US). We rely on EU Standard Contractual Clauses.
Retention
Clinical data: 10 years (medical obligation). Marketing: until you withdraw consent. Billing: 10 years.
Your rights
Access, rectification, erasure, marketing objection, portability. Email dpo@vytal-med.com or use the options in your account.