PRIVACY POLICY FOR USERS OF YUWELL ANYTIME APP, PROVIDED PURSUANT TO ARTICLES 13 and 14 OF (EU) REGULATION 2016/679 (“GDPR”)
Update Date: September, 2026
Yuwell Medtech Poland Sp. z o.o. (hereinafter referred to as the “Controller”, the “Company” or “Yuwell”), pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”), hereby provides information on the processing of personal data of users of the “Yuwell Anytime” app (the “App”), which is designed to operate in connection with the Continuous Glucose Monitoring (“CGM”) system.
The App is intended for users aged 18 and over and cannot be used by minors.
Users who have reached the age of 18 may independently provide, manage and withdraw their consent to the processing of their personal data within the App.
The Company may take reasonable steps to verify that such consent has been provided by the holder of parental responsibility.
Where the Company becomes aware that personal data relating to a user under the age of 18 has been collected without the required parental authorisation, it will take appropriate steps to delete such data without undue delay.
Data Controller and Data Protection Officer (DPO)
The Controller is Yuwell Medtech Poland Sp. z o.o., with registered office at ul. Nowogrodzka 64/43, 02-014 Warszawa, Poland. The Controller can be contacted at the following email address: privacy@yuwell-poctech.com.
The Controller has appointed a Data Protection Officer (“DPO”), who can be contacted at the following email address: privacy@yuwell-poctech.com for any matter relating to the processing of personal data.
1.Categories of personal data
The personal data processed by the Controller through the App include:
-
•Common data
-
oRegistration data, such as the user’s name, surname, email address, password, nickname, gender, date of birth, country or location, verification codes and privacy settings.
-
oAccount and profile data, such as avatar, account status and account creation date.
-
oDevice data, i.e. data relating to the device used to access the App, such as device ID, Bluetooth signals and IP address.
-
oAuthentication and security data, such as sign-in and sign-out timestamps, login status (e.g. auto-login), session tokens, device or phone used for login, and logout codes and their creation time.
-
-
•Special categories of personal data
-
oGlucose measurements and derived values, such as glucose readings, glucose trend information, forecast timing for low/high glucose events, measurement IDs and timestamps, calibration status, temperature, working and blank currents, and error or warning codes.
-
oHealth alert settings, such as alert thresholds and intervals (low, high, severe), measurement unit, BLE disconnection settings and related timers, rapid rise and rapid drop alerts, forecast alerts (low/high), and date and time of setting changes.
-
oUser-logged events, i.e. data manually entered by the user in the App, such as event type and date, food intake and calories (kcal), insulin dosage and units (IU), GLP-1RA medication and dose (mg), physical activity and duration/calories, other medications and dosage, and user notes.
-
oOptional health attributes, such as height, weight and diabetes type, used to provide personalised insights and alerts.
-
2.Personal data source
The Controller collects personal data from the following sources:
-
•Directly from users, including:
-
oPersonal data provided when creating and managing their account on the App.
-
oPersonal data generated through the use of the CGM system (including the transmitter and sensor) and the App.
-
-
•From third parties, where applicable, including:
-
oRelatives or caregivers authorised by the user to provide or manage personal data on the user’s behalf through the App.
-
3.Purposes of the processing
The personal data collected by the Controller through the App are processed for the following purposes:
-
a)Managing the user’s registration and account, including, where the user is under the age of 18, the collection and management of personal data relating to the holder of parental responsibility
-
b)Providing the core functionalities of the App, including the processing of glucose measurements, health alert settings and other data generated through the use of the CGM system, as well as the display and monitoring of such data.
-
c)Enabling the recording and management of user-entered information, including events manually logged in the App (e.g. food intake, insulin, medication, physical activity and related notes).
-
d)Providing personalised insights, alerts and functionalities, including those based on optional health attributes (e.g. height, weight and diabetes type), where applicable.
-
e)Providing support and technical assistance services.
-
f)With the user’s prior consent, sharing personal data with third parties selected by the user (e.g. doctors or relatives) for monitoring or care purposes.
-
g)Carrying out post-market surveillance, performance and safety monitoring, device traceability and incident reporting, as required under Regulation (EU) 2017/745 on medical devices, in the Controller’s capacity as a medical device manufacturer.
-
h)Ensuring the security of the App and preventing and detecting fraudulent or unlawful activities, including misuse of the App or of the Controller’s systems.
-
i)Establishing, exercising or defending legal claims in judicial or extrajudicial proceedings.
-
j)Complying with legal obligations to which the Controller is subject.
-
k)Enabling the display, at the user's request and for the user's own monitoring purposes, of glucose measurements, glucose trend information and alert notifications on a smartwatch paired with the user's mobile device via a Bluetooth connection.
4.Legal grounds
The legal grounds of personal data processing are the following.
For the purposes referred to under lett. a), b), c), d) and e), the legal basis for the processing is the performance of a contract to which the user is party (pursuant to Article 6(1)(b) GDPR).
Where such processing involves special categories of personal data (in particular data relating to health), the legal basis is the explicit consent of the user (pursuant to Article 9(2)(a) GDPR).
For the purpose referred to under lett. f), the legal basis for the processing is the user’s consent (pursuant to Article 6(1)(a) and Article 9(2)(a) GDPR).
For the purposes referred to under lett. g) and j), the legal basis for the processing is the need to comply with legal obligations to which the Controller is subject (pursuant to Article 6(1)(c) GDPR). Where applicable, the processing of personal data relating to health is also based on Article 9(2)(g) GDPR, as necessary for reasons of substantial public interest.
For the purposes referred to under lett. h) and i), the legal basis for the processing is the legitimate interest of the Controller (pursuant to Article 6(1)(f) GDPR), consisting in ensuring the security of the App and its systems, preventing fraudulent or unlawful activities, and establishing, exercising or defending legal claims.
For the purpose referred to under lett. k), the legal basis for the processing is the user's consent (pursuant to Article 6(1)(a) and Article 9(2)(a) GDPR). Such consent is given by activating the smartwatch connection within the App and may be withdrawn at any time by disabling the functionality in the App's settings or by unpairing the smartwatch.
5.Nature of the provision of data
The provision of personal data is necessary to the extent required to achieve the purposes described in Section 3 above.
The provision of personal data necessary for the creation and management of the user’s account (lett. a)) and for the provision of the core functionalities of the App (lett. b)) is required. Any refusal to provide such data, or to consent to the processing of data relating to health where required, would prevent the Controller from providing the App and its functionalities.
The provision of personal data relating to user-entered information (lett. c)) and to optional health attributes used to provide personalised insights and alerts (lett. d)) is optional. Failure to provide such data does not prevent the use of the App’s core functionalities.
The provision of personal data for the purpose of sharing with third parties designated by the user (lett. f)) is optional and subject to the user’s consent. Failure to provide such data does not affect the use of the App. Users may withdraw their consent at any time through the App’s privacy settings.
The provision of personal data for the purpose referred to under lett. k) (display on a smartwatch connected via Bluetooth) is optional and subject to the user's consent. Failure to provide such data, or the withdrawal of consent, does not affect the use of the App or of its core functionalities.
The processing of personal data for post-market surveillance, device traceability and incident reporting (lett. g)) is required in order to comply with applicable legal obligations under Regulation (EU) 2017/745. Such processing is necessary for the continued availability of the App and the associated device.
The processing of personal data for security purposes, including the prevention of fraudulent or unlawful activities (lett. h)), and for the establishment, exercise or defence of legal claims (lett. i)), does not require a specific act of provision by the user, as the relevant data are generated automatically in connection with the use of the App.
The provision of additional profile data (e.g. gender, avatar or nickname) is optional and does not affect the creation of an account or the use of the App.
6.Personal data retention period
Personal data are retained for the period necessary to achieve the purposes for which they are processed, as described in Section 3 above.
Personal data processed for the purposes referred to under lett. a) and b) are retained for the entire duration of the user’s account, as they are necessary for the provision of the App and its core functionalities. Upon account deletion — which can be performed by the user directly from the App — such data are retained only for the period necessary to comply with applicable legal obligations.
Personal data processed for the purposes referred to under lett. c) and d) (including user-entered data and optional health attributes) are retained for as long as they are actively maintained by the user within the App and, in any case, until they are deleted by the user or upon account deletion.
Personal data processed for the purpose referred to under lett. e) (support and technical assistance) are retained for the time strictly necessary to manage the request and, thereafter, for a period necessary to protect the Controller’s rights in connection with potential claims.
Personal data processed for the purpose referred to under lett. f) (data sharing with third parties) are retained for as long as the user maintains the sharing of personal data with the selected third parties active within the App and, in any case, until the user withdraws their consent or removes the relevant third party from the sharing settings.
Personal data processed for the purpose referred to under lett. g) (post-market surveillance, device traceability and incident reporting) are retained for the period required to comply with applicable legal obligations under Regulation (EU) 2017/745 and other applicable laws. Such data may be retained independently of the existence of an active user account.
Personal data processed for the purposes referred to under lett. h) and i) are retained for the duration of the relevant legal proceedings and, thereafter, for the applicable statutory limitation period.
Personal data processed for the purpose referred to under lett. j) are retained for the period required by the applicable legal obligation.
Personal data processed for the purpose referred to under lett. k) are not retained by the Controller on its servers. Such data are transmitted locally between the user's mobile device and the paired smartwatch and are only temporarily cached on the smartwatch for display purposes, as described in Section 8. Any data so cached are deleted when the functionality is disabled within the App or the smartwatch is unpaired.
7.Data recipients
Personal data may be shared, for the purposes referred to in Section 3 above, with the following categories of recipients:
-
a)Entities acting as data processors, including: (i) companies providing IT services necessary for the operation of the App (e.g. hosting, infrastructure, and monitoring services); (ii) entities providing technical maintenance and support services; (iii) distributors and other partners involved in the provision of support services to users and, where applicable, in the fulfillment of post-market surveillance, device traceability and incident reporting obligations under Regulation (EU) 2017/745; (iv) companies or professional firms providing assistance and consultancy in accounting, administrative, legal, tax or financial matters.
-
b)Public authorities or bodies, where required by applicable law or upon request by competent authorities, including regulatory and supervisory authorities in the medical device sector.
-
c)Third parties designated by the user within the App (e.g. doctors, relatives or caregivers) for monitoring or care purposes. Such third parties access the personal data under their own responsibility. Where such parties qualify as independent data controllers, they shall process personal data in accordance with their own privacy policies.
-
d)Third-party service providers offering services related to those of the Controller, where applicable, acting as independent data controllers.
For the avoidance of doubt, the smartwatch connectivity functionality referred to under lett. k) of Section 3 does not entail any disclosure of personal data to third parties. Reference is made to Section 8 below.
Authorised persons
Personal data may be processed by the Company’s personnel and by other persons acting under the authority of the Controller and involved in carrying out the purposes described above, who have been expressly authorised to process personal data, have received appropriate operating instructions and are subject to confidentiality obligations.
8. Connected smartwatch
Where the user so requests, the App may display on a smartwatch paired with the user's mobile device (the "Connected Device") a limited set of data, consisting of the current glucose value, the glucose trend indication and alert notifications. The data transmitted to the Connected Device are limited to the categories described in Section 1 under "Special categories of personal data" and are restricted to what is strictly necessary for their display on the Connected Device.
The transmission of data to the Connected Device takes place over a direct Bluetooth connection between the user's mobile device and the Connected Device, or over the synchronisation mechanism provided by the operating system of the Connected Device. Such data are not uploaded to, nor relayed through, any cloud service, server or network node, and are not transmitted over Wi-Fi or mobile networks. Where the Bluetooth connection is interrupted, or the Connected Device is unpaired, no further data are transmitted. Data temporarily cached on the Connected Device are limited to the most recent readings and are deleted when the functionality is disabled or the Connected Device is unpaired.
No account credentials are displayed on, or stored by, the Connected Device. The App does not transmit to the Connected Device the user's login name, email address, password or authentication tokens, and no Yuwell, Apple,Samsung or Google account is required in order to use the Connected Device functionality. The watch application is a mirror of the phone application: all glucose-related data are received and held by the Phone App, and the watch merely replicates and displays such data without independently collecting, analysing or generating any personal data, and without transmitting any data back to the Phone App, Yuwell or any external recipient. The Connected Device functionality supports paired smartwatches including Samsung smartwatches and Apple Watch (iOS Watch). Regardless of the operating system or brand of the Connected Device, the data processing method, scope and limitations described above apply equally, and the watch does not transmit any personal data to Apple, Samsung or any other third-party operating system provider.
The App does not integrate with, and does not transmit any personal data to, Samsung Health, Health Connect,Apple Health or any other health data platform made available by the manufacturer of the Connected Device or by the provider of its operating system. In connection with the Connected Device functionality, neither the manufacturer of the Connected Device nor the provider of its operating system receives any personal data from the Controller.
The Connected Device functionality is optional and is activated only at the user's request. The user may disable it at any time through the settings of the App or by unpairing the Connected Device, without any effect on the other functionalities of the App. The legal basis for the processing is the user's consent (Article 6(1)(a) and Article 9(2)(a) GDPR), which may be withdrawn at any time in the manner indicated above, without affecting the lawfulness of the processing carried out before withdrawal.
9.Transfer of personal data abroad
Some personal data is shared with Recipients that could be based outside the European Economic Area. Yuwell assures that the processing of personal data by the Recipients in question is carried out in compliance with the GDPR. Transfers can be based on an adequacy decision, on the Standard Contractual Clauses approved by the European Commission or on other appropriate safeguards or legal mechanisms under the GDPR. For further information please contact the Controller, by sending an email to the address privacy@yuwell-poctech.com.
10.Rights of the users
By contacting the Controller at the email address privacy@yuwell-poctech.com, users may request access to their personal data, its deletion, rectification of inaccurate data, completion of incomplete data, the restriction of processing in the cases provided for by art. 18 of the GDPR, as well as object to the processing, for reasons related to their specific situation, in case of legitimate interest of the Controller.
The Controller replies to the user's request without undue delay and, in any event, within one month of receipt of the request. Where the request is complex or numerous, such period may be extended by two further months; in that case the Controller shall inform the user of the extension, and of the reasons for it, within one month of receipt of the request.
Where processing is based on the user’s consent or on a contract to which the user is party and is carried out by automated means, the user has the right to receive personal data in a structured, commonly used and machine-readable format, as well as to transmit those personal data to another controller without hindrance, if technically feasible.
Users have the right to withdraw their consent at any time, as well as to object – for reasons connected with their particular situation – to processing carried out to pursue the legitimate interest of the Controller. Withdrawal and management of consents given may be exercised by users through the privacy settings available within the App, or by informing the Controller via e-mail at the address privacy@yuwell-poctech.com. Such withdrawal shall not affect the lawfulness of processing based on consent given before withdrawal.
Consent to the smartwatch connectivity functionality referred to under lett. k) of Section 3 and in Section 8 is withdrawn by disabling the functionality in the settings of the App or by unpairing the Connected Device.
Users also have the right to file a complaint with the competent Supervisory Authority, in accordance with art. 77 of the GDPR, if they believe that the processing of their personal data is contrary to the law in force.