GDPR Compliance at Gluroo

Gluroo is committed to the privacy and security of our users’ health data. We adhere to the General Data Protection Regulation (GDPR), ensuring that our users in the European Economic Area (EEA) have full control over their personal data.

Because Gluroo processes health data under GDPR Article 9, we apply our highest standards of privacy and consent to all users globally.

Lawful Basis for Processing

We process your personal health data based on Explicit Consent (Article 9(2)(a)). When you create an account, you must explicitly consent to the processing of your blood glucose and health logs. You may withdraw this consent at any time by deleting your account.

We process non-health data (such as technical logs and subscription status) to maintain the security and functionality of our service.

Your Data Rights

Under GDPR, you have specific rights regarding your data. Here is how you can exercise some of them within the Gluroo app:

1. Right to Erasure (“Right to be Forgotten”)

You can request the permanent deletion of all your data.

  • How to exercise: Navigate to Settings > GluCrew > Delete This GluCrew in the Gluroo app. Note that only the last member left in the GluCrew can delete it.
  • Timeline: Once initiated, your data will be permanently wiped from our primary databases and backups within 7 days.

2. Right to Data Portability

You have the right to receive your personal data in a structured, machine-readable format.

  • How to exercise: Navigate to Menu > Insights > Data Export.
  • Format: We provide a full export of your logs, readings, and history in a CSV via email.

Data Retention Policy

We do not hold your data indefinitely.

  • Active Accounts: We retain your health history for as long as your account remains active to provide historical trends and analytics (e.g., HbA1c estimates).
  • Inactive/Churned Accounts: If you cancel your subscription or your account becomes inactive, we retain your data for 90 days to allow for reactivation. After 90 days, your personal health data is automatically anonymized or permanently deleted.

For further questions about Gluroo and GDPR, please contact us directly at help@gluroo.com.