Ciklo Mobile App Privacy Policy
1. Who we are
UAB Ciklo, registered at Paribio g. 14-20, LT-08101 Vilnius, Lithuania ("Ciklo", "we", "us"), provides the Ciklo mobile application (the "App"). For privacy questions, contact us at [email protected]. For product support, contact [email protected].
2. Purpose and nature of the App
Ciklo is a clinic-assigned educational and preventive environmental exposure assessment app. It helps users structure questionnaire answers, product-scan information and educational exposure insights before a follow-up consultation with a healthcare professional.
3. Data controller and clinic relationship
For App account administration, App operation, product scanning, consent management and educational exposure insights, UAB Ciklo acts as the data controller unless a separate clinic arrangement states otherwise.
If your account is activated through a clinic code, selected information may be made available to the clinic or healthcare professional that assigned Ciklo in order to support the follow-up consultation. The clinic's use of that information for clinical care, medical records or patient communication may be governed by the clinic's own privacy notice and legal obligations. Where required, Ciklo may process certain data on behalf of the clinic under a data processing agreement.
4. Data we collect
| Category | Examples | Why we collect it |
|---|---|---|
| Account data | Name, email address, password hash, date of birth or age range, gender, optional phone number, account ID, authentication provider ID where Apple or Google sign-in is used. | To create and manage your account, authenticate you, provide support and keep the App secure. |
| Activation and clinic-assigned service data | Activation code, clinic identifier or clinic name, assigned care flow, assigned healthcare professional if provided, next appointment or follow-up date where applicable. | To link your App account to the service flow assigned by the clinic and enable the clinic-based follow-up workflow. |
| Health-related and environmental-context data | Baseline questionnaire answers, health-related context you choose to provide, health conditions or concerns, life-stage information, environmental and lifestyle factors, goals and product-use habits. | To generate educational environmental exposure insights and prepare a structured summary for follow-up discussion. |
| Product and scan data | Barcodes, product names, product categories, ingredient lists, scan history, usage frequency, product markings such as keep/avoid/swap, and product-related educational risk indicators. | To identify products, evaluate ingredient profiles, calculate educational exposure indicators and show product-category summaries. |
| Ingredient-label images for OCR | Images of ingredient labels that you choose to scan. | To extract ingredient text. Unless otherwise stated in the App, images are processed only for OCR and are not retained after processing is complete. |
| Computed educational indicators | Environmental exposure index, EDC exposure indicators, product-category contributions, ingredient explanations and changes over time. | To provide educational, non-diagnostic exposure summaries and support follow-up preparation. |
| Device, technical and security data | Device type, operating system, app version, language, server logs, IP address, authentication logs and security events. | To operate the App, secure accounts, prevent abuse, troubleshoot issues and ensure service reliability. |
| App usage and analytics data | Screens viewed, features used, onboarding completion, scan flow events, button interactions and aggregated product-usage events. | To understand product performance, improve usability and maintain App functionality. Health-related content is not disclosed to analytics or marketing processors. |
| Notifications and communications data | Push notification token, notification preferences, support messages, email delivery and engagement information where applicable. | To send reminders, service messages, support communications and optional updates where consent is required. |
| Consent and audit records | Consent status, consent timestamps, privacy-policy version accepted, withdrawal records and account deletion requests. | To demonstrate compliance, manage privacy choices and respect consent withdrawal. |
5. Legal bases under GDPR
| Purpose | Data categories | Legal basis |
|---|---|---|
| Account administration and core App functionality | Account, activation, product and scan data | GDPR Art. 6(1)(b) - performance of a contract |
| Personalised educational environmental exposure insights | Health-related and environmental-context data; computed indicators | GDPR Art. 6(1)(a) and Art. 9(2)(a) - explicit consent |
| Clinic-based follow-up preparation | Selected questionnaire, product and educational summary data | GDPR Art. 6(1)(a) consent and/or Art. 6(1)(b) contract, depending on the clinic flow; health data under Art. 9(2)(a) explicit consent unless another lawful basis applies through the clinic |
| Notifications | Notification token and preferences | GDPR Art. 6(1)(a) - consent |
| Optional newsletters or educational emails | Email address and engagement data | GDPR Art. 6(1)(a) - consent; unsubscribe available in each message where applicable |
| Analytics and service improvement | Usage events and device/app data | GDPR Art. 6(1)(a) - consent where required |
| Security, fraud prevention and abuse prevention | Logs, IP address and security events | GDPR Art. 6(1)(f) - legitimate interest |
| Compliance and consent evidence | Consent records and audit trail | GDPR Art. 6(1)(c) - legal obligation |
6. App permissions
- Camera: used only to scan product barcodes and ingredient labels. Ciklo does not use the camera for biometric identification, surveillance, environment mapping, or unrelated image collection.
- Notifications: used only if you enable reminders, service notifications or educational tips.
- Sign in with Apple / Google sign-in, if enabled: used only for account authentication. Ciklo does not receive your Apple or Google password.
7. How we share data
We do not sell personal data. We do not display third-party advertising. We do not disclose health-related data to analytics or marketing processors.
| Recipient / processor | Function | Safeguards |
|---|---|---|
| Hosting and database provider | Servers, databases and secure infrastructure | EU/EEA preferred; data processing agreement |
| Iterable, Inc. or equivalent email provider | Service emails and optional communications | Data processing agreement; EU-US DPF and/or SCCs where applicable |
| Amplitude, Inc. | Product analytics and usage events | Usage analytics only; no health-related content disclosed; DPF and/or SCCs where applicable |
| Google Ireland Ltd. / Firebase | App analytics, performance and technical tooling where enabled | Usage and technical data only; no health-related content disclosed; DPF and/or SCCs where applicable |
| Apple / Google / Expo push services | Delivery of push notifications | Notification delivery only; DPF/SCCs where applicable |
| Apple or Google identity providers | Authentication where the user chooses a third-party sign-in method | Authentication identifiers only; no password received by Ciklo |
| Your clinic or healthcare professional | Clinic-assigned follow-up review, where enabled by the clinic flow | Shared only for the clinic-assigned service purpose and subject to consent/clinic legal notices where applicable |
8. International transfers
Your data is primarily stored in the EU/EEA. Where service providers process data outside the EU/EEA, Ciklo relies on appropriate safeguards, such as an adequacy decision, the EU-US Data Privacy Framework, Standard Contractual Clauses, and supplementary measures where required.
9. Tracking, advertising and sale of data
Ciklo does not sell personal data, does not share personal data with data brokers and does not use personal data for third-party advertising. Ciklo does not track users across apps or websites owned by other companies for targeted advertising or advertising measurement.
10. Data retention
- Account and App data: retained while your account is active and for the period necessary to provide the App and meet legal obligations.
- Health-related and environmental-context data: retained while your account is active or until consent is withdrawn and deletion/anonymisation is required, subject to legal retention obligations.
- Ingredient-label images: processed for OCR and not retained after processing is complete, unless the App clearly tells you otherwise and obtains the necessary consent.
- Consent records: retained as necessary to demonstrate compliance.
- Security logs: retained for a limited period needed for security, fraud prevention and system integrity.
- Analytics data: retained in aggregated or limited form for product improvement according to vendor settings and Ciklo retention rules.
11. Account deletion
You can request deletion of your account directly in the App through Settings → Account → Delete account. Account deletion deactivates your account immediately. Account data, questionnaire responses, product history, educational exposure indicators and notification tokens are irreversibly erased or anonymised after the stated grace period, unless Ciklo is legally required to retain limited records.
You may also contact [email protected] for support with deletion or privacy rights.
12. Your rights
Under the GDPR, you may have the right to access your data, receive a copy, rectify inaccurate data, request erasure, restrict processing, object to processing, withdraw consent, and exercise data portability. You may exercise your rights in the App where available or by contacting [email protected]. We respond within one month unless the law permits an extension.
You may lodge a complaint with the Lithuanian State Data Protection Inspectorate or with another EU supervisory authority based on your place of residence.
13. Minors
The App is intended for users aged 16 and over. We do not knowingly process data of persons under 16. If we become aware that such data has been processed, we will delete it without undue delay unless another lawful basis applies through a clinic or legal guardian process.
14. Security
We apply technical and organisational measures designed to protect personal data, including encryption in transit, password hashing, access controls, role-based access, consent-gated access to health-related data, logging, monitoring and restricted processor access. No system is completely secure. If a personal data breach is likely to pose a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.
15. Changes to this Policy
We may update this Policy. We will notify users of material changes in the App or by email before they take effect and request renewed consent where required. The current version will be published at myciklo.com/app-privacy.html.
16. Contact
UAB Ciklo
Paribio g. 14-20, LT-08101 Vilnius, Lithuania
Privacy: [email protected]
Support: [email protected]