EatBeat – Healthy meal planning app

EATBEAT PRIVACY POLICY

Effective from [10.12.2023]

 

1.SCOPE OF THIS POLICY

  • The following privacy policy (hereinafter: Privacy Policy) applies to all cases where Eat Beat OÜ (hereinafter: EatBeat) processes personal data of natural persons (hereinafter: Data Subject) as a controller when operating and managing its mobile application EatBeat (hereinafter: App).

 

  • The App operated by EatBeat allows the registered users (hereinafter: User) to use AI-based software for analysing and monitoring their dietary The User can keep a food diary (hereinafter: Food Diary) of the food and drinks which they consume. The App analyses data from the Food Diary and assists in creating a dietary plan and health goals. The App also has a database of recipes (hereinafter: Recipes) and restaurant recommendations made by the assistant (hereinafter: Assistant).
  • EatBeat is committed to protecting and respecting the Data Subjects’ Please read this Privacy Policy carefully to understand EatBeat’s rules and practices regarding processing personal data.

 

  • This Privacy Policy applies from the date as set above. EatBeat has the right to unilaterally make amendments to the Privacy Policy. In such case the amended Privacy Policy shall be uploaded to the App and/or will be sent to the Data Subject by e-mail.

 

2.DATA CONTROLLER

  • For the purpose of clarity, the data controller for the purposes of this Privacy Policy is Eat Beat OÜ, registry code 16102062, registry address Estonia, Ranniku tee 14, Tallinn, Harju County, 12112. EatBeat can be contacted any time by writing an e- mail at [info@eatbeat.ee].

 

3.WHY AND WHAT CATEGORIES OF PERSONAL DATA IS PROCESSED

  • EatBeat collects and processes personal data for the following purposes:

 

  1. providing services (hereinafter: Services) to the User via the App, which includes communicating with the User and providing the User customer support;
  2. communicating with a potential User in relation to providing the Services in the future if the potential User has so requested;

 

  1. sending news, special offers and general information about the Services to the User, unless the User has opted-out from receiving such information;

 

  1. providing subscription services for the User and to enable payment via a selected payment service;
  2. improving the App and the Services;

 

  1. enforcing and defending EatBeat’s legal rights;
  2. complying with legal or regulatory obligations or requests which EatBeat is subject to.

 

  • EatBeat may collect and process the following personal data:
    1. for provision of the Services (purpose stated in clause 1.a)):
      1. the User’s phone number, username, e-mail address, location data, photo (if provided by the User);

 

  1. the User’s age, gender, weight, activity level for the purpose of calculating

the User’s daily recommended intake of calories and nutrients;

  • data about the User’s eating habits and preferences with the purpose of improving the accuracy of the Assistant’s recommendations – this may include any data submitted or created by the User, e.g., answers to the Assistant’s questions etc.;
  1. data about meals eaten by the User as entered by the User to their Food Diary;
  2. technical usage data (e.g., unique device identifiers, browser type and version, device type and operating system);

 

  1. any other personal data the User may voluntarily provide as regards to the Services – g., personal data that may be included in Recipes created by the User, personal data provided by the User via User support etc.
  1. for communicating with the potential Users (purpose stated in clause 1.b)): any data the person makes voluntarily available, usually being first and last name, e-mail address;

 

  1. for sending news, special offers and general information about the Services (purpose stated in clause 1.c)): e-mail address, DRI data such as age, gender, weight, activity level; Food Diary data;
  2. for providing subscription services (purpose stated in clause 1.d)): the User’s name and method of payment. The App uses third party payment providers such as Apple Store and Google Play;

 

  1. for improving the App and the Services (purpose stated in clause 1.e)): any of the categories of personal data listed above, depending on the exact development works done for the Services and/or the App. Usually, the personal data is pseudonymised for development works;

 

  1. for enforcing and defending EatBeat’s legal rights (purpose stated in clause 1.f)): any of the categories of personal data listed above, determined case- by-case according to the legal right EatBeat is entitled to execute;
  2. for complying with legal or regulatory obligations or requests (purpose stated in clause 1.g)): any of the categories of personal data listed above, determined case-by-case according to the obligation or request EatBeat is subject to.
  • If the entry of any personal data has been made mandatory upon account registration (e.g., entering e-mail) or after registration when using the functions of the App, then the submission of the respective personal data is required for concluding the agreement between EatBeat and the User or for performing the respective agreement. As such, in these cases the submission of personal data is mandatory

 

and if it is not submitted, it is impossible either to enter into this agreement or perform this agreement. If the entry of personal data has not been made mandatory on the App and the submission of personal data is not required from the Data Subject in any other way, the submission of personal data is voluntary and non-submission does not have any direct adverse consequences for the Data Subject. However, failure to provide personal data may limit the use of the functions of the App.

 

  • Moreover – if the Data Subject uses their Google or Apple (or any other) account for logging in, then the respective entity submits to EatBeat the Data Subject’s name and possibly e-mail address, and language preference.

4.LEGAL BASIS FOR PROCESSING PERSONAL DATA

  • EatBeat processes personal data because it is necessary for the fulfilment of a contract concluded between EatBeat and the User for provision of the Services (clause 1.a)); or for taking steps at the User’s request prior to entering into a contract (clause 3.1.b)). In such a case the legal basis for processing data is the contract concluded between EatBeat and the User; or the User’s request prior to entering into a contract.
  • Where EatBeat processes personal data for sending news, special offers and general information about the Services (clause 1.c)), the legal basis is EatBeat’s legitimate interest to keep the User in loop of any information, advancements or offers available regarding the Services. The User has always the possibility to opt-out from receiving such data (e.g., unsubscribe button below each e-mail). If the User opts-out, EatBeat shall no longer send such information.

 

  • If EatBeat processes personal data to provide subscription services for the User (clause 1.d), the legal basis for processing personal data is the contract concluded between EatBeat and the User.
  • If EatBeat processes personal data to improve the App and the Services (clause 1.e)), the legal basis for processing personal data is EatBeat’s legitimate interest to improve and develop the functions of the App, provision of the Services and its quality. EatBeat cannot provide the best and most modern App and Services without doing any development works.

 

  • EatBeat processes personal data also for enforcing and defending EatBeat’s legal rights under the legitimate interest pursued by EatBeat (clause 1.f)). It is EatBeat’s legitimate interest to enforce and defend its legal rights if EatBeat sees it as necessary.

 

  • Where EatBeat processes personal data for complying with legal or regulatory obligations or requests, the legal basis is the necessity to comply with the legal obligations to which EatBeat is subject to (clause 1.g)).

5.PERSONALISED EXPERIENCE

 

Based on the information and preferences submitted to EatBeat by the User (e.g., age, gender, food preferences etc.), each User may be shown a different dietary plan, health goals and recommendations. In any case, EatBeat assures that such activity does not entail any legal or otherwise significant effects concerning the User.

 

6.DISCLOSING PERSONAL DATA

  • EatBeat shall not transfer the Data Subject’s personal data to third parties except for

the following cases:

 

  1. to companies for payment processing on the App (e.g., Apple Distribution International Limited and Google Ireland Limited, registered in Ireland).

 

  • All authorized third-party processors to whom EatBeat transmits personal data shall ensure the protection of personal data as required by the legislation regulating the protection of personal data.
  • Furthermore, EatBeat shall send personal data to a relevant institution requiring personal data, if EatBeat is under a duty to disclose or share such personal data in order to comply with any legal or regulatory obligation or request deriving from the

 

7.HOW LONG IS PERSONAL DATA PROCESSED

  • EatBeat only processes and stores the personal data for as long as it is necessary to fulfil the purpose for which it is processed – once the purpose has ceased, the personal data will be erased or anonymised.
  • The personal data will be processed:
    1. up to 30 days after the deletion of the User’s account, where EatBeat processes personal data in relation to providing the Services (clause 1.a));

 

  1. up to 30 days after the last contact with the potential User, where EatBeat processes personal data in relation to providing the Services in the future (clause 1.b));
  2. up to 30 days after the deletion of the User’s account or until opt-out (whichever happens earlier), where EatBeat processes personal data regarding sending news, special offers and general information about the Services to the User (clause 1.c));

 

  1. up to 2 months after the deletion of the User’s account, where EatBeat processes personal data regarding providing subscription services (clause 1.d));

 

  1. up to 30 days after the deletion of the User’s account, where EatBeat processes personal data regarding improving the App and the Services (clause 1.e));

 

  1. up to 3 years after the deletion of the User’s account, where EatBeat processes personal data regarding enforcing and defending EatBeat’s legal rights (clause 1.f));
  2. up to 3 years from the end of the agreement between EatBeat and the User, where EatBeat processes personal data regarding complying with legal or regulatory obligations (see clause 1.g)).

 

  • Personal data contained in any accounting documents shall be stored for 7 years from the end of the last financial year they relate to.

8.DATA SUBJECT’S RIGHTS

 

  • The Data Subject has the right to contact EatBeat by writing an e-mail at info@eatbeat.ee to exercise the Data Subject’s rights concerning processing of personal data. Such rights include the:

 

  1. right to request access of personal data;
  2. right to request rectification of personal data;

 

  1. right to request erasure of personal data;
  2. right to request restriction of processing of personal data;
  3. right to object to processing of personal data;
  4. right to request portability of personal data;

 

  1. right that decisions are not taken concerning the Data Subject which are based on automated decision-making, if applicable;
  2. right to withdraw a consent;

 

  1. right to lodge a complaint with a supervisory authority (Estonian Data Protection Inspectorate – https://www.aki.ee/en).

9.THIRD PARTY SITES

 

  • The App may, from time to time, contain links to and from the websites of EatBeat’s partner networks, advertisers and affiliates (including, but not limited to, websites of the restaurants). If the Data Subject follows a link to any of these websites, it must be considered that these websites and any services that may be accessible through them have their own privacy policies and that EatBeat does not accept any responsibility or liability for these policies or for any personal data that may be collected through these websites or services. EatBeat recommends checking these policies before submitting any personal data to these websites or using any of these