A sleep log, a supplement list and a blood panel draw an extremely precise portrait of a person. That is why GDPR places this information in the special categories of data.
The four rights that matter day to day
- Access: obtain a copy of what is stored about you.
- Portability: export your data in a readable, reusable format.
- Rectification: correct wrong data.
- Erasure: request deletion, without justification in most cases.
Questions to ask before signing up
- 1
Where is the data hosted?
Country and jurisdiction determine who can legally access it, including outside any contractual relationship with you.
- 2
Which processors access it?
The list must be public and current, with each purpose stated. An analytics vendor has no business inside a biomarker database.
- 3
How long is it kept?
A retention period must be announced for after account closure. «Indefinitely» is not a duration.
- 4
Is there a reachable DPO?
A dedicated email address and a public processing register are worth more than any trust badge.
- 5
Is the data used for advertising?
If the answer is not a plain no, it is a yes with intermediate steps.
Minimisation: collect less to risk less
The best protection is the data never collected. A well designed app asks only for what the service requires, not one field more. Consent must be granular: accepting the service should never force you to accept a newsletter or analytics.
« Data sovereignty is not a legal checkbox, it is an architecture decision. »
Where Helix stands
Helix is built in Europe, with European hosting, a public processing register, granular consent for non essential cookies and a direct DPO contact. Sensitive data stays local-first on your device. No advertising, no data resale.
Want to check for yourself before signing up?
Read the processing register