PRIVACY POLICY FOR USERS OF YUWELL ANYTIME APP, PROVIDED PURSUANT TO ARTICLES 13 and 14 OF (EU) REGULATION 2016/679 (“GDPR”)

Update Date: September, 2026

Yuwell Medtech Poland Sp. z o.o. (hereinafter referred to as the “Controller”, the “Company” or “Yuwell”), pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”), hereby provides information on the processing of personal data of users of the “Yuwell Anytime” app (the “App”), which is designed to operate in connection with the Continuous Glucose Monitoring (“CGM”) system.

The App is intended for users aged 18 and over and cannot be used by minors.

Users who have reached the age of 18 may independently provide, manage and withdraw their consent to the processing of their personal data within the App.

The Company may take reasonable steps to verify that such consent has been provided by the holder of parental responsibility.

Where the Company becomes aware that personal data relating to a user under the age of 18 has been collected without the required parental authorisation, it will take appropriate steps to delete such data without undue delay.

Data Controller and Data Protection Officer (DPO)

The Controller is Yuwell Medtech Poland Sp. z o.o., with registered office at ul. Nowogrodzka 64/43, 02-014 Warszawa, Poland. The Controller can be contacted at the following email address: privacy@yuwell-poctech.com.

The Controller has appointed a Data Protection Officer (“DPO”), who can be contacted at the following email address: privacy@yuwell-poctech.com for any matter relating to the processing of personal data.

1.Categories of personal data

The personal data processed by the Controller through the App include:

2.Personal data source

The Controller collects personal data from the following sources:

3.Purposes of the processing

The personal data collected by the Controller through the App are processed for the following purposes:

4.Legal grounds

The legal grounds of personal data processing are the following.

For the purposes referred to under lett. a), b), c), d) and e), the legal basis for the processing is the performance of a contract to which the user is party (pursuant to Article 6(1)(b) GDPR).

Where such processing involves special categories of personal data (in particular data relating to health), the legal basis is the explicit consent of the user (pursuant to Article 9(2)(a) GDPR).

For the purpose referred to under lett. f), the legal basis for the processing is the user’s consent (pursuant to Article 6(1)(a) and Article 9(2)(a) GDPR).

For the purposes referred to under lett. g) and j), the legal basis for the processing is the need to comply with legal obligations to which the Controller is subject (pursuant to Article 6(1)(c) GDPR). Where applicable, the processing of personal data relating to health is also based on Article 9(2)(g) GDPR, as necessary for reasons of substantial public interest.

For the purposes referred to under lett. h) and i), the legal basis for the processing is the legitimate interest of the Controller (pursuant to Article 6(1)(f) GDPR), consisting in ensuring the security of the App and its systems, preventing fraudulent or unlawful activities, and establishing, exercising or defending legal claims.

For the purpose referred to under lett. k), the legal basis for the processing is the user's consent (pursuant to Article 6(1)(a) and Article 9(2)(a) GDPR). Such consent is given by activating the smartwatch connection within the App and may be withdrawn at any time by disabling the functionality in the App's settings or by unpairing the smartwatch.

5.Nature of the provision of data

The provision of personal data is necessary to the extent required to achieve the purposes described in Section 3 above.

The provision of personal data necessary for the creation and management of the user’s account (lett. a)) and for the provision of the core functionalities of the App (lett. b)) is required. Any refusal to provide such data, or to consent to the processing of data relating to health where required, would prevent the Controller from providing the App and its functionalities.

The provision of personal data relating to user-entered information (lett. c)) and to optional health attributes used to provide personalised insights and alerts (lett. d)) is optional. Failure to provide such data does not prevent the use of the App’s core functionalities.

The provision of personal data for the purpose of sharing with third parties designated by the user (lett. f)) is optional and subject to the user’s consent. Failure to provide such data does not affect the use of the App. Users may withdraw their consent at any time through the App’s privacy settings.

The provision of personal data for the purpose referred to under lett. k) (display on a smartwatch connected via Bluetooth) is optional and subject to the user's consent. Failure to provide such data, or the withdrawal of consent, does not affect the use of the App or of its core functionalities.

The processing of personal data for post-market surveillance, device traceability and incident reporting (lett. g)) is required in order to comply with applicable legal obligations under Regulation (EU) 2017/745. Such processing is necessary for the continued availability of the App and the associated device.

The processing of personal data for security purposes, including the prevention of fraudulent or unlawful activities (lett. h)), and for the establishment, exercise or defence of legal claims (lett. i)), does not require a specific act of provision by the user, as the relevant data are generated automatically in connection with the use of the App.

The provision of additional profile data (e.g. gender, avatar or nickname) is optional and does not affect the creation of an account or the use of the App.

6.Personal data retention period

Personal data are retained for the period necessary to achieve the purposes for which they are processed, as described in Section 3 above.

Personal data processed for the purposes referred to under lett. a) and b) are retained for the entire duration of the user’s account, as they are necessary for the provision of the App and its core functionalities. Upon account deletion — which can be performed by the user directly from the App — such data are retained only for the period necessary to comply with applicable legal obligations.

Personal data processed for the purposes referred to under lett. c) and d) (including user-entered data and optional health attributes) are retained for as long as they are actively maintained by the user within the App and, in any case, until they are deleted by the user or upon account deletion.

Personal data processed for the purpose referred to under lett. e) (support and technical assistance) are retained for the time strictly necessary to manage the request and, thereafter, for a period necessary to protect the Controller’s rights in connection with potential claims.

Personal data processed for the purpose referred to under lett. f) (data sharing with third parties) are retained for as long as the user maintains the sharing of personal data with the selected third parties active within the App and, in any case, until the user withdraws their consent or removes the relevant third party from the sharing settings.

Personal data processed for the purpose referred to under lett. g) (post-market surveillance, device traceability and incident reporting) are retained for the period required to comply with applicable legal obligations under Regulation (EU) 2017/745 and other applicable laws. Such data may be retained independently of the existence of an active user account.

Personal data processed for the purposes referred to under lett. h) and i) are retained for the duration of the relevant legal proceedings and, thereafter, for the applicable statutory limitation period.

Personal data processed for the purpose referred to under lett. j) are retained for the period required by the applicable legal obligation.

Personal data processed for the purpose referred to under lett. k) are not retained by the Controller on its servers. Such data are transmitted locally between the user's mobile device and the paired smartwatch and are only temporarily cached on the smartwatch for display purposes, as described in Section 8. Any data so cached are deleted when the functionality is disabled within the App or the smartwatch is unpaired.

7.Data recipients

Personal data may be shared, for the purposes referred to in Section 3 above, with the following categories of recipients:

For the avoidance of doubt, the smartwatch connectivity functionality referred to under lett. k) of Section 3 does not entail any disclosure of personal data to third parties. Reference is made to Section 8 below.

Authorised persons

Personal data may be processed by the Company’s personnel and by other persons acting under the authority of the Controller and involved in carrying out the purposes described above, who have been expressly authorised to process personal data, have received appropriate operating instructions and are subject to confidentiality obligations.

8. Connected smartwatch

Where the user so requests, the App may display on a smartwatch paired with the user's mobile device (the "Connected Device") a limited set of data, consisting of the current glucose value, the glucose trend indication and alert notifications. The data transmitted to the Connected Device are limited to the categories described in Section 1 under "Special categories of personal data" and are restricted to what is strictly necessary for their display on the Connected Device.

The transmission of data to the Connected Device takes place over a direct Bluetooth connection between the user's mobile device and the Connected Device, or over the synchronisation mechanism provided by the operating system of the Connected Device. Such data are not uploaded to, nor relayed through, any cloud service, server or network node, and are not transmitted over Wi-Fi or mobile networks. Where the Bluetooth connection is interrupted, or the Connected Device is unpaired, no further data are transmitted. Data temporarily cached on the Connected Device are limited to the most recent readings and are deleted when the functionality is disabled or the Connected Device is unpaired.

No account credentials are displayed on, or stored by, the Connected Device. The App does not transmit to the Connected Device the user's login name, email address, password or authentication tokens, and no Yuwell, Apple,Samsung or Google account is required in order to use the Connected Device functionality. The watch application is a mirror of the phone application: all glucose-related data are received and held by the Phone App, and the watch merely replicates and displays such data without independently collecting, analysing or generating any personal data, and without transmitting any data back to the Phone App, Yuwell or any external recipient. The Connected Device functionality supports paired smartwatches including Samsung smartwatches and Apple Watch (iOS Watch). Regardless of the operating system or brand of the Connected Device, the data processing method, scope and limitations described above apply equally, and the watch does not transmit any personal data to Apple, Samsung or any other third-party operating system provider.

The App does not integrate with, and does not transmit any personal data to, Samsung Health, Health Connect,Apple Health or any other health data platform made available by the manufacturer of the Connected Device or by the provider of its operating system. In connection with the Connected Device functionality, neither the manufacturer of the Connected Device nor the provider of its operating system receives any personal data from the Controller.

The Connected Device functionality is optional and is activated only at the user's request. The user may disable it at any time through the settings of the App or by unpairing the Connected Device, without any effect on the other functionalities of the App. The legal basis for the processing is the user's consent (Article 6(1)(a) and Article 9(2)(a) GDPR), which may be withdrawn at any time in the manner indicated above, without affecting the lawfulness of the processing carried out before withdrawal.

9.Transfer of personal data abroad

Some personal data is shared with Recipients that could be based outside the European Economic Area. Yuwell assures that the processing of personal data by the Recipients in question is carried out in compliance with the GDPR. Transfers can be based on an adequacy decision, on the Standard Contractual Clauses approved by the European Commission or on other appropriate safeguards or legal mechanisms under the GDPR. For further information please contact the Controller, by sending an email to the address privacy@yuwell-poctech.com.

10.Rights of the users

By contacting the Controller at the email address privacy@yuwell-poctech.com, users may request access to their personal data, its deletion, rectification of inaccurate data, completion of incomplete data, the restriction of processing in the cases provided for by art. 18 of the GDPR, as well as object to the processing, for reasons related to their specific situation, in case of legitimate interest of the Controller.

The Controller replies to the user's request without undue delay and, in any event, within one month of receipt of the request. Where the request is complex or numerous, such period may be extended by two further months; in that case the Controller shall inform the user of the extension, and of the reasons for it, within one month of receipt of the request.

Where processing is based on the user’s consent or on a contract to which the user is party and is carried out by automated means, the user has the right to receive personal data in a structured, commonly used and machine-readable format, as well as to transmit those personal data to another controller without hindrance, if technically feasible.

Users have the right to withdraw their consent at any time, as well as to object – for reasons connected with their particular situation – to processing carried out to pursue the legitimate interest of the Controller. Withdrawal and management of consents given may be exercised by users through the privacy settings available within the App, or by informing the Controller via e-mail at the address privacy@yuwell-poctech.com. Such withdrawal shall not affect the lawfulness of processing based on consent given before withdrawal.

Consent to the smartwatch connectivity functionality referred to under lett. k) of Section 3 and in Section 8 is withdrawn by disabling the functionality in the settings of the App or by unpairing the Connected Device.

Users also have the right to file a complaint with the competent Supervisory Authority, in accordance with art. 77 of the GDPR, if they believe that the processing of their personal data is contrary to the law in force.