Legal
Privacy Policy
Last updated: 22 May 2026
This translation is provided for convenience; the Italian version prevails.
1. What information we collect
We collect personal data in three main ways:
Information you provide to us directly. When you join the waitlist, choose a plan or upload documents, we collect your name, email address, OAuth provider identifier if you use Google sign-in, the plan you select and any details you add to your profile (date of birth, sex, country, lifestyle fields).
Health data and special category data. Blood test results, genomic files, gut flora reports, laboratory values, clinical notes, diagnostic images and any other health document you choose to upload. Together with the values, scores and reports we generate from them, this is special category data under Article 9 of the GDPR and receives the highest level of protection.
Information collected automatically. IP address, device and browser characteristics, operating system, language, pages visited on our site, timestamps of actions and basic interaction logs needed to keep the service secure, troubleshoot problems and measure aggregate usage.
2. How we use your information
We process personal data for the following purposes:
- To create and manage your INNER account and provide the service you signed up for.
- To analyse the health data you upload and produce your personalised insights, scores and reports.
- To send transactional emails (verification, plan confirmation, file received, report ready, account alerts).
- To respond to your requests via email or the contact form.
- To keep the service secure, prevent fraud and abuse, and resolve technical problems.
- To improve the quality of our analyses, measured against aggregated and anonymised statistics and not against your individual data.
- To comply with legal obligations (tax, accounting, regulatory requests).
We do not sell your personal data, and we do not use it for behavioural advertising or third-party marketing profiling.
3. Legal bases we rely on (Articles 6 and 9 of the GDPR)
Under Article 6 of the GDPR, we rely on different legal bases depending on the activity:
- Performance of a contract (Art. 6(1)(b)) — to provide the INNER service you sign up for and to handle payments and customer support.
- Legitimate interest (Art. 6(1)(f)) — to keep the platform secure, prevent fraud, troubleshoot and improve the service. We balance these interests against your rights and rely on this basis only when the balance is in your favour.
- Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting or regulatory obligations.
- Vital interests (Art. 6(1)(d)) — only in the rare case where someone's life is at risk.
For health data and other special category data (Article 9 of the GDPR), we rely specifically on:
- Your explicit consent (Art. 9(2)(a)) — given when you upload health documents or connect health data sources during the early access flow. You can withdraw consent at any time by contacting us; withdrawal does not affect processing carried out before the withdrawal.
- Where applicable, processing necessary for the provision of healthcare (Art. 9(2)(h)) carried out by, or under the responsibility of, professionals subject to an obligation of professional confidentiality.
Access to your health data within INNER is limited on a strict need-to-know basis and is governed by written confidentiality obligations.
4. Automated decision-making and artificial intelligence
We use machine learning models and large language models to extract values from your documents, group values into categories and present insights in plain language. These are presentation and analysis tools, not medical decisions. INNER does not make decisions that produce legal effects or similarly significant effects concerning you based solely on automated processing under Article 22 of the GDPR. Any clinical interpretation involves qualified human review.
5. When and with whom we share your data
We do not sell your personal data. We share it only with processors and trusted partners who help us run the service, under contracts (Data Processing Agreements compliant with Article 28 of the GDPR) that protect your data:
- Hosting and cloud storage providers who host our application, database and uploaded files.
- Laboratory, genetics and gut flora partners who run the tests you opt into and return the results to us.
- Transactional email providers (currently Brevo) used to send service emails.
- AI and analytics providers used to extract values and generate insights from your documents.
- Authentication providers (Google) when you use a social login.
- Payment processors for handling subscriptions and test fees.
- Public authorities or courts, where strictly required to comply with a binding legal order.
- A successor entity, in the event of a corporate transaction, provided the same level of protection is maintained.
The information shared is limited to what each partner needs to perform its specific function.
6. International data transfers
INNER is established in the European Economic Area (EEA). Some of our processors and sub-processors operate outside the EEA. When personal data is transferred to a country that has not received an adequacy decision from the European Commission, we rely on appropriate safeguards under Article 46 of the GDPR — typically the European Commission's Standard Contractual Clauses (SCCs), supplemented by additional technical and organisational measures (such as encryption in transit and at rest, role-based access control and audit logging).
You can request a copy of the safeguards in place for a specific transfer by writing to [email protected].
7. Cookies and tracking technologies
We use a minimal set of strictly necessary cookies to keep you logged in, remember your language and protect the site from abuse. These do not require consent under the ePrivacy Directive.
We may use first-party analytics cookies to understand aggregate usage and improve the site. Where analytics cookies are not strictly necessary, we will ask for your consent before setting them and you can withdraw consent at any time via the cookie banner.
We do not use third-party advertising cookies or cross-site tracking pixels.
8. How long we keep your information
We keep your personal data only for as long as necessary to fulfil the purposes described in this policy, including the time needed to meet our legal, tax and accounting obligations. In practice:
- Account data — for the lifetime of your account, plus a short closure period.
- Uploaded health files and generated reports — for the lifetime of your account or until you ask us to delete them, whichever is sooner.
- Invoices and tax records — for the period required by applicable tax law (typically 10 years in the EU).
- Server and security logs — for a limited time window needed for security monitoring.
Where immediate deletion is technically impossible (for example, encrypted backups not yet rotated), the data remains protected and isolated until deletion becomes possible.
9. How we keep your data secure
We implement appropriate technical and organisational measures to protect your data from unauthorised access, accidental loss or destruction (Article 32 of the GDPR). These include:
- Encryption in transit (HTTPS/TLS) and at rest.
- Role-based access control with the principle of least privilege.
- Strong authentication for staff accounts and infrastructure.
- Audit logging of access to sensitive data.
- Regular backups, isolated from the production environment.
- Secure development practices and dependency monitoring.
No electronic system can be 100% secure. In the unlikely event of a personal data breach that could result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform you without undue delay (Articles 33–34 of the GDPR).
10. Minors
INNER is not intended for persons under 16 years of age. We do not knowingly collect personal data from minors. If you believe that a minor has provided us with personal data, contact us at [email protected] and we will investigate and delete the data.
11. Anonymised and aggregated data
We may produce anonymised and aggregated statistics (for example, value distributions or feature-usage metrics) that cannot identify any individual. Genuinely anonymised data is no longer personal data under the GDPR and may be used to improve the service or for research. Pseudonymised data, where a re-linking key exists, remains personal data and is protected by this policy.
12. Your rights under the GDPR
You have the following rights regarding your personal data:
- Access (Art. 15) — obtain confirmation of whether we process your data and receive a copy.
- Rectification (Art. 16) — correct inaccurate or incomplete data.
- Erasure (Art. 17) — the "right to be forgotten", subject to legal retention obligations.
- Restriction (Art. 18) — suspend certain processing while a dispute is resolved.
- Portability (Art. 20) — receive your data in a machine-readable format and transmit it to another controller.
- Objection (Art. 21) — object to processing based on legitimate interest.
- Withdraw consent at any time, where processing is based on consent. Withdrawal does not affect processing carried out before the withdrawal.
- Lodge a complaint with your local supervisory authority (in Italy, the Garante per la protezione dei dati personali), or with the supervisory authority of the EU member state where you live or work, or where the alleged breach took place.
To exercise these rights, write to [email protected]. We respond within one month and may extend by a further two months for complex or numerous requests (Article 12 of the GDPR), notifying you within the first month. We may request proof of identity to protect your privacy. Exercising your rights is free of charge in the normal case.
13. Do-Not-Track signals
Most browsers offer a Do-Not-Track (DNT) setting. There is currently no agreed standard on how websites should respond to DNT, so we do not act on these signals for the time being. Your control over cookies via the banner nonetheless remains effective.
14. Updates to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated by email or via a banner on the site at least 14 days before they take effect.
15. How to file a privacy complaint
If you have privacy concerns, please contact us first at [email protected]. We acknowledge receipt of complaints within 5 business days and aim to provide a substantive response within 30 days. If you are not satisfied, you can turn to the supervisory authority of your EU member state, as described in section 12.
16. Contact us
For any privacy question or to exercise any right described above:
- By email: [email protected]
- By post: INNER Health — Data Protection, [registered office address to be added after registration].
This policy is provided as a working draft adapted for the European Economic Area and the GDPR. The details of INNER's legal entity and the appointment of a Data Protection Officer (where required) will be added once the formal registration of the company is complete. We recommend a final review by qualified legal counsel before public launch.
