Lady I

Lady I · Legal

Draft — the fields in 【brackets】 are completed before the app is published. This is not the final text.

Contents
  1. 1. In short
  2. 2. Who the controller is and how to reach us
  3. 3. Profile without registration, registered profile, and what "anonymous" means
  4. 4. What data we process
  5. 5. Why and on what basis we process your data
  6. 6. Predictions, personalisation and automated decisions
  7. 7. Who has access to your data
  8. 8. Transfers outside North Macedonia
  9. 9. How long we keep data
  10. 10. Your rights
  11. 11. Children
  12. 12. How we protect your data
  13. 13. Cookies
  14. 14. Requests from authorities and foreign governments
  15. 15. Personal data breach
  16. 16. Changes to this Policy
  17. 17. Contact
  18. 18. Legal framework and definitions
  19. Annex A. List of processors
  20. Annex B. Supplement for the European Union, EEA and United Kingdom
  21. Annex C. Supplement for the United States
  22. Annex D. Data subject request form

Lady I Privacy Policy

Version 3.1 (internal; publishes as version 1.0) · Effective: 【publication date】

How this document works. The core sections apply to every user worldwide. The annexes add only what a particular region's law requires. The core gives you every right the General Data Protection Regulation provides, wherever you live.

Fields in 【brackets】 are completed before publication.


1. In short

Lady I is an app for tracking your menstrual cycle, fertility, pregnancy, the postpartum period and menopause. What you enter is data about your health, and we treat it as the most sensitive category there is. This Policy explains what we process, why, for how long, who we share it with and what rights you have.

What we never do:

  • we do not sell your data and we do not give it to advertising or analytics networks;
  • we show no advertising and use no advertising identifiers;
  • we do not share your health data with app stores or social networks;
  • we do not track your location;
  • we make no automated decisions with legal consequences for you, and we run no artificial intelligence over your data;
  • we do not disclose your data to domestic or foreign authorities without a legally binding order that is valid or recognised in North Macedonia (section 14).

The most important thing to know: to create a profile and use the app, we do not ask for your name, e-mail or phone number. We process those details only if you yourself choose to enter a name, register your profile, buy a membership, or send us a message or feedback.

Without registration we do not know who is behind the profile. The history you enter is kept only on your phone: if you lose or change the phone, or delete the app, the data cannot be recovered — not even at your request, because we hold no copy of it. With a registered profile (e-mail or Google account) a copy of the data is kept on the server and can be restored on a new phone.

What you can do at any time: download a complete copy of your data, delete it permanently, or withdraw your consent — all yourself, through the settings in your Profile, without asking us.


2. Who the controller is and how to reach us

The controller is 【full legal name and form】, 【address】, Skopje, Republic of North Macedonia, company number 【ЕМБС】 ("Lady I", "we").

Data Protection Officer: 【name】, e-mail support@ladyiapp.com, address as above. For any question about your data or to exercise your rights, contact the Officer.

Representative in the European Union (GDPR Article 27): 【name, address, e-mail】. Users resident in the European Union and the European Economic Area may contact the representative on any matter concerning the processing of their data, on the same footing as contacting us.

Representative in the United Kingdom (UK GDPR Article 27): 【name, address, e-mail】. Users resident in the United Kingdom may contact the representative on the same footing.

The medical and educational content in the app is written by Dr Irena Gosheva. The app does not provide a healthcare service and no doctor–patient relationship arises through it. Dr Gosheva is also an authorised person of Lady I; what she can see in that capacity is set out in section 7.


3. Profile without registration, registered profile, and what "anonymous" means

Profile without registration. The app can be used with no name, e-mail, phone or password. On first launch a random identifier is created on your device and the profile is tied to it. What you enter in the health diary is kept only on your device. On the server, under that identifier, we keep only the data in the categories "Profile", "Notifications" and "Consents" in section 4 — that is, your answers from the introduction and basic settings, the notification identifier and the record of your consents. This profile is reachable only from that device: if you uninstall, lose or change the device, the history cannot be recovered, because no copy of it exists.

Registered profile. To restore your data on a new device and to use paid services, you can register your profile by e-mail (with a one-time code) or with a Google account. We then also process your e-mail address or Google account identifier, and optionally your name. At registration we ask for your separate explicit consent to the copy on the server. From registration onwards, a copy of all the data you enter in the app — the health diary included — is kept on the server and is kept up to date while you use the app. When you sign in on a new device, the data is restored.

What "anonymous" means legally. Even without registration, what you enter is pseudonymised personal data of a special category (health data): it is linked to the identifier created on your device, and the profile data is also stored on our server in Frankfurt, Federal Republic of Germany. We do not know who is behind the identifier unless you yourself enter a name for the report or register your profile. That is why we process it only with your explicit consent and protect it as personal data.

What that means for your rights. For a profile without registration, without a name and without a purchase we cannot identify you. In that case we are not obliged to — and will not — collect additional data simply to link you to a profile (ЗЗЛП art. 15 / GDPR Article 11). Instead you exercise every right yourself, directly in the app, and it takes effect immediately — no request, no waiting, and no need to reveal yourself to us. If you do write to us and give us the profile identifier shown in Profile, we act on your request as described in section 10.


4. What data we process

Category
Profile
Data
year of birth, age at first menstruation, average cycle length, chosen mode (cycle tracking, conceiving, pregnancy, postpartum, menopause), life phase derived from year of birth, language; if you entered them — name, blood group and Rh factor, contraception method, whether you are breastfeeding, whether and since when you have been trying to conceive
Source
you enter it; life phase is calculated by the app
Category
Registration (optional)
Data
e-mail or Google account identifier, sign-in time
Source
you enter it
Category
Health diary
Data
menstruation start and end dates, bleeding intensity and bleeding diary (PBAC), mood and pain, ovulation tests, last menstrual period and due date, obstetric history, weight, height, blood pressure, fetal movements, contractions, breastfeeding, contraception, preventive check-ups and their dates
Source
you enter it
Category
Predictions
Data
expected menstruation, fertile window, gestational week, attention signals
Source
calculated by the app from your entries, using predetermined rules
Category
Payments (if you buy a membership)
Data
product, amount, date, status, transaction identifier
Source
the payment provider or the store; we never receive a card number
Category
Notifications
Data
the device's notification identifier, your notification settings, log of notifications sent
Source
created by the app
Category
Consents
Data
type of consent, version of the text, date, given or withdrawn
Source
you give them in the app
Category
Support
Data
your e-mail and the content of your message when you write to us
Source
you send it
Category
Technical data
Data
crash reports (device model, system and app version, error description)
Source
created by the app

We do not collect: location, contacts, photos, advertising identifiers, or data from other apps or smart watches.

Where the data is kept. For a profile without registration, the health diary and the predictions stay on your device only and are not sent to the server; the server holds the data in the categories "Profile", "Notifications" and "Consents". For a registered profile, the server also holds a copy of everything you enter in the app, together with your settings, so that it can be restored on a new device.

Device permissions. The app requests permission only for notifications (optional; without it there are no reminders). If you enable the app lock, the app uses the device's own unlock function. The fingerprint or face is compared solely by the operating system, inside the protected part of the device; the app receives from it only a "yes" or "no" answer — whether the check passed. No image, no template and no other biometric data reaches the app or Lady I. Lady I does not receive, store or process biometric data. The app requests no access to location, camera, contacts, microphone or files.


5. Why and on what basis we process your data

Purpose
Tracking and predictions in the app; for a registered profile also a copy on the server, so that you can restore your data
Data
profile, health diary, registration
Legal basis (ЗЗЛП / GDPR)
explicit consent for health data (ЗЗЛП art. 13(2)(1) / GDPR art. 9(2)(a)); contract for the profile and the registration (ЗЗЛП art. 10(1) indent 2 / GDPR art. 6(1)(b))
For how long
while you use the profile, until you delete it
Purpose
Reminders and notifications on the device
Data
settings, notification identifier, diary dates
Legal basis (ЗЗЛП / GDPR)
your consent (ЗЗЛП art. 10(1) indent 1 / GDPR art. 6(1)(a))
For how long
while enabled; the log of notifications sent — 60 days
Purpose
Messages from a gynaecologist and news about the app
Data
chosen mode, life phase, language, membership status
Legal basis (ЗЗЛП / GDPR)
your explicit consent, separate from the health-data consent (ЗЗЛП art. 96)
For how long
until you switch it off
Purpose
Membership and payments
Data
payment data, subscription status
Legal basis (ЗЗЛП / GDPR)
contract with you; statutory accounting and tax obligations
For how long
the period set by the applicable regulations
Purpose
Support and responding to your requests
Data
support, consents
Legal basis (ЗЗЛП / GDPR)
contract with you; statutory obligation
For how long
2 years from closing the request
Purpose
Security, abuse detection, crash reports
Data
technical data, server logs
Legal basis (ЗЗЛП / GDPR)
our legitimate interest in running the app securely (ЗЗЛП art. 10(1) indent 6 / GDPR art. 6(1)(f))
For how long
logs up to 30 days; crash reports up to 90 days
Purpose
Record of the consents you have given
Data
type and version of consent, date
Legal basis (ЗЗЛП / GDPR)
statutory obligation
For how long
while the profile exists
Purpose
Statistics on how the app performs
Data
aggregate counts only, no individual data
Legal basis (ЗЗЛП / GDPR)
legitimate interest
For how long
indefinitely, as this is not personal data

Providing data is not a statutory obligation; you do it by choice. Bear in mind, however, that without cycle data the app cannot produce predictions.

Purpose limitation. Personal data will not be processed for any purpose other than the one for which it was collected. Processing for a different purpose may be carried out only on the basis of your prior consent.

You can withdraw consent at any time (section 10), without affecting the lawfulness of processing before withdrawal.


6. Predictions, personalisation and automated decisions

Predictions (expected menstruation, fertile window, gestational week, attention signals) are calculated on your device from the dates you enter, using rules set in advance by a doctor. They are informational and are not a diagnosis.

The app uses no artificial intelligence and makes no automated decisions producing legal or similarly significant effects for you, and builds no profiles for other purposes. The calculations are deterministic: the same entries always give the same result.

Content and messages are adapted only to your chosen mode, life phase, language and membership status.


7. Who has access to your data

You. Only you see your health diary, on the device and through your profile.

Lady I. Authorised persons at Lady I, under a duty of confidentiality, can see only the data in the category "Profile" (section 4), whether the profile is registered, your membership status, and the messages you have sent to support. The health diary is not accessible to them — not even when a copy of it is kept on the server for a registered profile; for it only aggregate counts exist. Access is minimised and technically separated: the admin panel has no access to the health diary.

Dr Gosheva. She writes the medical and educational content and the messages. Messages are sent to all users in a chosen group (by mode, language or membership), never to an individual user; there is no correspondence between a user and the doctor in the app. As an authorised person of Lady I, Dr Gosheva sees the same limited set of data described above — not the health diary.

Processors. Service providers processing data on our behalf, on our instructions and under a processing agreement (ЗЗЛП art. 32 / GDPR art. 28). The full list with names, countries and safeguards is in Annex A.

Competent domestic or foreign authorities. Only under the conditions in section 14.

Beyond the above, your data is disclosed to no one.


8. Transfers outside North Macedonia

Data is stored on a server in Frankfurt, Federal Republic of Germany.

For transfers to European Union and NATO member states, including the United States, article 48 of ЗЗЛП requires no authorisation; Lady I always notifies the Agency for Personal Data Protection of the transfer before the transfer begins.

For any provider outside the European Union we apply standard contractual clauses or certification under the EU–US Data Privacy Framework. Lady I's own access from North Macedonia to the data held in Germany is covered by standard contractual clauses (module four) in the agreement with the cloud provider. A copy of the safeguards is available from the Data Protection Officer.

For users in the European Union and the European Economic Area the GDPR applies. We process your data under its rules and comply with its transfer provisions (art. 44–49). See Annex B.


9. How long we keep data

  • Profile, registration and health diary: while you use the profile, or until you delete the data yourself. We apply no automatic deletion after a period of inactivity; deletion is in your hands at any time, through Profile.
  • Deletion by you: in Profile you can permanently delete all data from the device and the server at any time. Deletion is immediate; backups at the cloud provider are deleted within 30 days, and our processors delete their copies within the same period. If you no longer have the app, you can request deletion at ladyiapp.com/delete-account.
  • Payment data: for the period required by accounting and tax rules, only to the extent needed for those purposes.
  • Notifications: in the app 3 days; log of notifications sent 60 days; the notification identifier while the device receives notifications.
  • Crash reports: 90 days. Server logs: up to 30 days.
  • Support: 2 years from closing the request.

10. Your rights

We grant these rights regardless of where you live. They follow the highest standard — that of ЗЗЛП and the GDPR — and we apply them equally to every user worldwide.

  • to be informed — this Policy;
  • access to your data and a copy of it — Profile → "Download my data" gives you a complete copy immediately;
  • rectification — you change every entry yourself in the app;
  • erasure ("right to be forgotten") — Profile → "Delete my data"; immediate through the app, within 30 days on request, and at ladyiapp.com/delete-account if you no longer have the app;
  • restriction of processing and objection to processing;
  • portability — the copy from Profile is in a structured, machine-readable format;
  • withdrawal of consent at any time, as easily as you gave it;
  • not to be subject to an automated decision with legal consequences.

Send requests to support@ladyiapp.com. We respond without delay and within one month at the latest, free of charge.

For a profile without registration we will ask you to confirm access to the device or the identifier shown in Profile, because otherwise we cannot connect you to the data. We will not ask for an identity document or a national ID number for a profile without registration — for such a profile the rights are exercised through the export and delete functions in the app itself, which give the same result immediately.

Complaints. Every user of the app has the right to lodge a request with the Agency for Personal Data Protection of the Republic of North Macedonia, or with another competent supervisory authority listed below, if she considers that in processing her personal data Lady I, as controller, has infringed ЗЗЛП or another applicable law.

Without prejudice to any available administrative or out-of-court remedy, including the right to lodge a request with the Agency, every data subject has the right to an effective judicial remedy, by bringing an action before the competent court, where they consider that their rights under ЗЗЛП have been infringed as a result of processing of their personal data contrary to that law.

  • North Macedonia — Agency for Personal Data Protection, bul. Goce Delcev 18 (MRTV building, 14th floor), PO Box 417, 1000 Skopje; +389 2 3230 635; info@privacy.mk; www.azlp.mk
  • European Union / EEA — the supervisory authority in the country where you live or work, or where the alleged infringement occurred (see Annex B);
  • United Kingdom — Information Commissioner's Office, ico.org.uk;
  • United States — the Attorney General of your state (see Annex C).

In the other jurisdictions too, independently of a complaint to the supervisory authority, you have the right to a judicial remedy before the competent court.


11. Children

The app is intended for female users aged 14 and over. Below the age of 14 the app may not be used, not even with the consent of a parent or legal guardian.

The age at which a person can consent on their own to information society services differs by country. For users who are at least 14 but below the age in the table, a parent or legal guardian consents through the app before features processing health data can be used.

Region
North Macedonia
Age of independent consent in the app
14
Basis
ЗЗЛП art. 12
Region
European Union / EEA
Age of independent consent in the app
16
Basis
GDPR art. 8 (13 to 16, depending on the country; the app does not determine the country, so it applies the highest limit)
Region
United Kingdom
Age of independent consent in the app
14
Basis
UK GDPR (from 13); the minimum age for the app is 14
Region
United States
Age of independent consent in the app
14
Basis
COPPA (children under 13); the minimum age for the app is 14
Region
All other countries
Age of independent consent in the app
16
Basis
our own rule

Where a parent or guardian consents, we take reasonable steps to confirm that the consent comes from the parent or guardian. If we learn we have collected data from a child without the necessary consent, we delete it without delay.


12. How we protect your data

Lady I applies technical and organisational measures appropriate to the risk of health data (ЗЗЛП art. 36 / GDPR art. 32):

  • encrypted transmission between the app and the server, and encrypted storage at the cloud provider;
  • data on the device is protected by the device's own lock and by the operating system's app isolation; optionally also by an additional fingerprint or face lock in the app;
  • on the server each profile is isolated: a technical rule permits access to your own data only;
  • access by authorised persons is minimised and constrained by database-level rules;
  • regular backups, updates and security reviews;
  • a data protection impact assessment (ЗЗЛП art. 39 / GDPR art. 35) before introducing new processing;
  • no advertising or analytics tooling in the app.

Part of the protection is yours: lock your device, enable the app lock if others use the device, and be aware that notifications can be visible on a locked screen (you control this in the device settings).


13. Cookies

The app uses no cookies or similar tracking technologies.

The website ladyiapp.com sets no cookies: neither strictly necessary ones, nor analytics, advertising or cross-site tracking cookies. No cookie consent is therefore requested on it.


14. Requests from authorities and foreign governments

Data about the menstrual cycle, fertility and pregnancy is particularly sensitive: in some countries it can be demanded by authorities in judicial, investigative or administrative proceedings. That is why we apply the rules below to every request for disclosure, without exception.

Our rule: we disclose data only on the basis of a legally binding order of a competent authority of the Republic of North Macedonia, or of a foreign authority where that order is recognised and enforceable under Macedonian law or under an international agreement binding on the Republic of North Macedonia. A request from a foreign authority sent directly to us, without such a basis, is not executed.

When we receive a request:

  • we check its basis and scope and challenge it if it is overbroad or unfounded;
  • we disclose only the data the order requires, never more;
  • we notify you before disclosure, unless expressly prohibited by law or by the order; where prohibited, we notify you as soon as the prohibition lapses;
  • we keep a record of every such request.

What we could actually disclose. For a profile without registration we do not know who is behind the identifier, and the health diary exists only on your device — we have no access to it, so an authority cannot reach it through us either. For a registered profile a copy of the data exists on the server, linked to your e-mail address. If you delete your data, it is unavailable to us as well.


15. Personal data breach

If a breach occurs that may result in a risk to your rights:

  • we notify the Agency for Personal Data Protection within 72 hours of becoming aware (ЗЗЛП art. 37 / GDPR art. 33), and the competent supervisory authority where you are in the EU;
  • we notify you without delay where the breach is likely to result in a high risk to your rights and freedoms (ЗЗЛП art. 38 / GDPR art. 34), through the app and, where we have one, by e-mail;
  • for users in the United States we also notify under the Federal Trade Commission's Health Breach Notification Rule, which applies to the app: affected users and the Commission within 60 days of discovery, and the media where 500 or more residents of one state are affected;
  • we keep an internal record of every breach and the measures taken.

16. Changes to this Policy

Lady I reserves the right to amend this Policy from time to time to reflect changes in how personal data is collected and processed, and changes in applicable legislation.

We will post a notice of any change in the app itself, and the changes will also be included in the updated text of the Policy. For material changes we will notify you at least 15 days before they take effect; if new processing requires consent, we will ask for it separately.

The current version is always available in Profile and at ladyiapp.com/privacy, with date and version.

Version history

Version
1.0
Date
【date】
What changed
first published version

17. Contact

Lady I, 【address】, Skopje, Republic of North Macedonia

  • Data Protection Officer and support: support@ladyiapp.com
  • Legal matters: info@ladyiapp.com
  • EU representative: 【name, address, e-mail】
  • UK representative: 【name, address, e-mail】

If you have any comments, questions or concerns about any information in this Policy or about the processing of personal data by Lady I, please contact us at the addresses above.


18. Legal framework and definitions

This Policy is drawn up under the Law on Personal Data Protection (Official Gazette of the Republic of North Macedonia nos. 42/20, 294/21 and 101/25, "ЗЗЛП") and its implementing regulations; for users in the European Union and the European Economic Area — also under Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"); and for users in the United Kingdom — also under the UK GDPR and the Data Protection Act 2018.

The terms "controller", "processor", "data subject", "special categories of personal data" and "pseudonymisation" have the meaning given in art. 4 ЗЗЛП and art. 4 GDPR.

Governing language. The Policy is available in Macedonian, Albanian and English. The Macedonian version of this Policy is the original. Translations are published for comprehension; in case of divergence, the Macedonian version governs for users in North Macedonia and the English version governs for all others.


Annex A. List of processors

Updated without amending the Policy; current list at ladyiapp.com/processors.

Provider
Supabase Inc.
Service
database, authentication, storage, server functions
Country of processing
Germany (EU)
Safeguard
processing agreement with standard contractual clauses (modules three and four); notification to the Agency for Personal Data Protection (АЗЛП)
Provider
Google LLC (Firebase Cloud Messaging)
Service
notification delivery to Android devices
Country of processing
EU/US
Safeguard
EU–US Data Privacy Framework; processing agreement
Provider
650 Industries, Inc. (Expo)
Service
notification relay and app updates
Country of processing
US
Safeguard
standard contractual clauses 【DPF certification to be confirmed before publication】
Provider
Vercel Inc.
Service
hosting of the admin panel and of the website ladyiapp.com
Country of processing
Germany (EU)
Safeguard
EU–US Data Privacy Framework; processing agreement
Provider
Internacionalen Kartichen Sistem AD Skopje (cPay)
Service
card payments
Country of processing
North Macedonia
Safeguard
PCI DSS; agreement
Provider
Google Ireland Ltd (Google Play)
Service
store membership, Google sign-in
Country of processing
EU
Safeguard
Google Play terms
Provider
【E-mail provider】
Service
one-time codes and support messages
Country of processing
【country】
Safeguard
【safeguard】
Provider
Functional Software, Inc. (Sentry)
Service
crash reports
Country of processing
Germany (EU) 【EU data region to be confirmed before publication】
Safeguard
processing agreement
Provider
RevenueCat, Inc.
Service
subscription management
Country of processing
US
Safeguard
standard contractual clauses

Annex B. Supplement for the European Union, EEA and United Kingdom

This annex applies if you live in the European Union, the European Economic Area or the United Kingdom. The core Policy applies to you in full as well.

1. Application of the GDPR. Lady I is established in North Macedonia but offers services to people in the Union, so the GDPR applies to that processing (art. 3(2)).

2. Article 27 representatives. In the European Union: 【name, address, e-mail】. In the United Kingdom (UK GDPR Article 27): 【name, address, e-mail】. You may address the representative on any processing matter, instead of or in addition to contacting us.

3. Legal bases under the GDPR. The table in section 5 states the bases in parallel under ЗЗЛП and the GDPR. For health data the basis is explicit consent under art. 9(2)(a).

4. Transfers. Data is stored in Germany. Where a provider processes data outside the EEA we apply standard contractual clauses adopted by the European Commission, and where applicable certification under the EU–US Data Privacy Framework. Lady I itself is established in North Macedonia, a country without an adequacy decision; its access to your data is covered by the standard contractual clauses (module four) in the agreement with the cloud provider. A copy of the measures is available on request.

5. Your rights and supervisory authority. The rights in section 10 correspond to art. 15–22 GDPR. You may lodge a complaint with the supervisory authority in the country where you live, work, or where the alleged infringement occurred (art. 77). The list of authorities is published at edpb.europa.eu. In the United Kingdom, the Information Commissioner's Office.

6. Impact assessment. A data protection impact assessment under art. 35 GDPR has been carried out for the processing of health data in the app.


Annex C. Supplement for the United States

This annex applies if you live in the United States.

1. Consumer health data notice. For the purposes of the Washington My Health My Data Act and comparable statutes, Lady I discloses the following:

Requirement
Categories of consumer health data collected
Response
section 4 — profile, health diary, predictions
Requirement
Sources
Response
exclusively you; we buy and ingest nothing from third parties
Requirement
Purposes of processing
Response
section 5
Requirement
Categories of third parties with whom it is shared
Response
only the processors in Annex A, acting on our instructions
Requirement
Sale of consumer health data
Response
we do not and will not sell it; we seek no authorization to sell because we conduct no sale
Requirement
How to exercise rights
Response
through Profile in the app, or support@ladyiapp.com
Requirement
Response time
Response
within 45 days, extendable by a further 45 days for complex requests
Requirement
Deletion
Response
from our systems immediately, from backups within 30 days; our processors delete within the same period
Requirement
Appeal
Response
if we refuse a request, you may appeal to support@ladyiapp.com; we answer in writing within 45 days and, if the appeal is refused, tell you how to contact the Attorney General of your state

This notice is also published as a separate page at ladyiapp.com/consumer-health-data.

2. Consent. Collection of health data takes place on the basis of your prior explicit consent given in the app. Sharing with a processor for the purpose of delivering the service itself is covered by that same consent and is limited to Annex A.

3. State-law rights. Depending on your state — among others California, Colorado, Connecticut, Virginia, Oregon, Texas, Delaware — you have rights of access, deletion, correction, portability and objection. Lady I grants these rights to all users in the United States, regardless of state, through the functions in Profile. In California the app is treated as a provider of health care under the Confidentiality of Medical Information Act for the reproductive-health information you enter, and we keep it confidential accordingly. In Virginia we collect reproductive or sexual health information only with your prior explicit consent (opt-in). In Connecticut your health data is sensitive data processed only with your consent.

4. We do not sell your data and do not share it for cross-context behavioral advertising. We receive no payment or other consideration for your data.

5. Breach notification. See section 15. Lady I is a vendor of personal health records for the purposes of the Federal Trade Commission's Health Breach Notification Rule and notifies as that rule requires.

6. Oversight. You may complain to the Attorney General of your state; in Washington you also have a private right of action under the My Health My Data Act.


Annex D. Data subject request form

This form is for users with a registered profile. For a profile without registration the form is not needed: rights are exercised immediately in the app, through Profile → "Download my data" and "Delete my data". If you nevertheless submit a request, we will ask for the identifier shown in Profile, because otherwise we cannot connect you to the profile (section 10).

On \_\_\_\_\_\_\_\_, I, the undersigned, with the following details:

  • Full name: \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_
  • Profile identifier (from Profile in the app): \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_
  • Contact (e-mail): \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_

request that the Controller enable me to exercise *(tick as applicable)*:

  • ☐ the right to be informed about the personal data processed, and the purposes and legal basis
  • ☐ the right of access to my personal data
  • ☐ the right to rectification
  • ☐ the right to erasure / to be forgotten
  • ☐ the right to restriction of processing
  • ☐ the right to data portability
  • ☐ the right to object to processing
  • ☐ the right to withdraw consent
  • ☐ the right not to be subject to a decision based solely on automated processing, including profiling

I submit this request because *(brief description)*:

\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_

Signature: \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_

↑ Back to top