Legal

Privacy Policy

The protection of your personal data is our highest priority. Here you will learn what information we process, on what basis this occurs, and what rights you can exercise at any time.

1. Data Controller

Lab2go – Maritta Schmid
Forststraße 24 · 73529 Schwäbisch Gmünd, Germany
Show email

2. Data Collected

  • Master data (name, email address, payment details)
  • Health and biomarker data that you actively record in the app
  • Log data (logfiles, device information, cookies)

3. Purposes of Processing

  • Provision and personalization of the Lab2go platform including analyses and reminders
  • Communication with users, support and product updates
  • Compliance with legal documentation and retention requirements

4. Legal Basis

Processing according to Art. 6(1)(a) (consent) and (b) (contract performance) GDPR as well as Art. 9(2)(a) GDPR for health data.

5. Storage Duration & Deletion

We store personal data only as long as necessary for the respective purpose or due to legal retention periods. You can delete data at any time directly in the app or request complete deletion.

6. Disclosure to Third Parties

Transfer only occurs to contractually bound processors (hosting, payment providers). No disclosure for advertising purposes takes place.

7. Your Rights

  • Information, correction, deletion and restriction of processing
  • Revocation of previously granted consents with effect for the future
  • Data portability and right to lodge a complaint with the competent supervisory authority

8. Security

  • Storage exclusively on servers in Germany
  • Encryption of sensitive data at rest and in transit
  • Role-based access control, logging and regular security audits

9. Web Analytics

We use the privacy-friendly analytics tools Plausible Analytics and Umami to evaluate the usage of our website anonymously. Both services are integrated server-side via Cloudflare Zaraz.

No cookies are set and no personal data is collected. IP addresses are neither stored nor shared with third parties. There is no cross-site tracking.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in anonymised audience measurement). No consent is required as no personal data is processed.

Privacy Contact

For questions, please contact us at Show email .