Privacy Policy
Last updated: 24 August 2026
Who we are
Platos Health B.V. is the controller responsible for your data. We use your health and metabolic data, with your explicit consent, to generate the personalized insights and protocols that are the core of the service. The sections below explain this in more detail. Platos Health provides a metabolic intelligence platform: a consumer app, the Platos Plus subscription, and the Platos Monitor devices (the PS08 and PS04 body-composition monitors, with further devices planned).
For users in the European Economic Area and the United Kingdom, the controller of your personal data is Platos Health B.V., Haparandaweg 594, 1013 BD Amsterdam, Netherlands (Chamber of Commerce / KvK no. 78632277).
For users in Nigeria, the controller is Platos Health Africa Integrated Services Limited (RC 1725224), operating under the Nigeria Data Protection Act and NDPR.
You can reach our privacy team at compliance[at]platoshealth.com. Our Data Protection Officer (DPO) is Promise U. A DPO is required under the GDPR because our core activity involves large-scale processing of special-category health data, and under the NDPR because we process sensitive personal data and expect to exceed its subject thresholds. The NDPR also requires the DPO to be named in this public notice. Because we process special-category health data on a large scale, we have carried out a Data Protection Impact Assessment (DPIA) under Article 35 GDPR to identify and mitigate the risks of this processing.
Scope of this policy
This policy explains how we collect, use, share, and protect your personal data when you use the Platos app, the Platos Plus subscription, the Platos Monitor and connected hardware, and our websites. It applies across all markets in which we operate. Where local law gives you additional rights, those rights also apply.
The data we collect
Account and identity data. Name, email, phone number, password credentials, country, and, where relevant, age or date of birth.
Health and metabolic data (special-category data). This is the core of the service and includes:
- Self-reported inputs: meals, sleep, alcohol, caffeine, hydration, activity, stress, and similar behaviours.
- Stable health context: age band, biological sex, ethnicity, family history, existing conditions, pregnancy status, and medications.
- Wearable and device signals connected through Apple Health or Google Health Connect, such as heart-rate variability, resting heart rate, and sleep.
- Laboratory markers you add by photographing a report (Optical Character Recognition (OCR) upload) or through a connected laboratory partner. When you connect a laboratory partner, we receive this data directly from that partner at your instruction. We do not obtain health data from public sources.
- Body-composition and blood-pressure readings from the Platos Monitor and connected hardware.
- The informational readings and personalised protocols the platform generates from the above.
Shared and guest device use. Some Platos Monitor devices are used as shared devices in a shop or an office, or are offered by a partner as an in-store scan for a small fee, rather than being owned by you. However you are measured, your readings sync to your own Platos account. If you are measured as a guest, we ask for your explicit consent on the device screen before the measurement begins. We then hold that scan data for 30 days so you can claim it to your account using a code. If it is not claimed within 30 days, we delete it.
Payment data. Where you subscribe to Platos Plus, payment is processed by our payment providers. We receive confirmation of payment and limited billing details; we do not store full card numbers.
Technical and usage data. Device type, operating system, app version, IP address, identifiers, language, approximate location derived from IP, and how you interact with the app, collected in part through cookies and similar technologies (see our Cookie Notice).
Providing your data. Providing your account and health data is not a legal or contractual requirement, but it is necessary to create an account and to use the features that rely on that data. If you choose not to provide it, we will not be able to offer you those specific features.
Why we use your data and our lawful bases
For health data, we rely on your explicit consent under Article 9(2)(a). You give this consent during onboarding, separately from accepting our Terms, and you can withdraw it at any time, as easily as you gave it (see Section 9). If you withdraw consent, the features that depend on health data will stop, but you can still use the parts of the service that do not.
For users in Nigeria, we rely on the equivalent consent and lawful-processing grounds under the Nigeria Data Protection Act and NDPR.
How the platform generates insights (automated processing)
Platos uses a rule-based inference engine to produce informational readings of your metabolic data, shown with an indication of how reliable each reading is. While the engine is in Beta, we tell you so.
These outputs are informational. They are not a medical diagnosis, they do not decide anything about you that produces legal or similarly significant effects, and they do not replace advice from a qualified clinician. This does involve profiling of your metabolic data within the meaning of Article 4(4) GDPR, but because it does not produce legal or similarly significant effects, it is not the kind of solely automated decision-making that Article 22 GDPR restricts. In brief, each reading compares your input data (biomarkers, wearable signals, self-reported behaviours) against population-based reference ranges and applies our inference rules to flag potential areas of concern; the reliability indicator shows how much weight the underlying data carries. You can also ask us for more detail about any specific reading.
Who we share data with
We do not sell your personal data. We share it only in these situations:
Service providers (processors and subprocessors). We use carefully selected providers to run the service, each bound by a data processing agreement that limits them to our instructions. They fall into these categories:
- Hosting and infrastructure (secure cloud hosting and databases in Europe);
- AI text generation, to produce written summaries such as your weekly brief;
- Lab-photo text extraction (OCR), to read the values from a lab report you upload;
- Analytics, to understand how the app and website are used and to improve them;
- Email and messaging, for service and account communications;
- Payment providers, to process Platos Plus subscriptions;
- Laboratory and hardware partners, where you choose to connect them.
The specific providers, the data they handle, where they process it, and the safeguards in place are listed in our Subprocessor Register, which we keep up to date.
Wearable and laboratory data connect through Apple Health, Google Health Connect, and direct integrations. We do not use a separate third-party data-aggregation service for this.
Clinical Partners. If you are enrolled through one of our clinical partners under our Platos console offering, we share relevant data with that partner to support your care. This is separate from our standard consumer service and is subject to the following terms:
- Independent data controller: Your clinical partner acts as a separate, independent data controller for the medical care and remote monitoring services they deliver.
- Independent processing: They determine what data they require and how it is processed within their clinical workflows.
- Separate privacy notice: Your clinical partner has an independent duty to inform you about their data practices and maintains their own privacy notice governing your medical records under applicable law (including GDPR Articles 13 and 14).
Corporate and legal. We may share data with our affiliates within the Platos group under this policy, and with authorities, advisers, or acquirers where the law requires it or a corporate transaction makes it necessary.
International transfers
We operate in the Netherlands and Nigeria and use providers that may process data outside your country. Where we transfer personal data out of the EEA or the UK, for example when a US-based analytics provider processes data in the United States, we rely on an adequacy decision or on Standard Contractual Clauses, supplemented by additional safeguards such as encryption and pseudonymisation where the destination country's law does not provide equivalent protection. For users in Nigeria, cross-border transfers are handled under the Nigeria Data Protection Act and NDPR. You can ask us for details of the safeguards in place.
How long we keep your data
We keep your personal data for as long as your account is active and for as long as we need it for the purposes in this policy. Guest scan data that is not claimed is deleted after 30 days (see “Shared and guest device use”). When you delete your account or withdraw consent, we delete or de-identify your health data within 30 days, except where we must keep limited records to meet a legal obligation. Backups are purged on our standard cycle. For users in Nigeria, the NDPR default periods also apply (broadly, three years after you last use the platform, or six years after your last transaction under a contract).
Your rights
Wherever you are, you can ask us to:
- access the personal data we hold about you and receive a copy;
- correct data that is wrong or incomplete;
- delete your data (“right to be forgotten”);
- restrict the processing of your data in specific circumstances (for example while we verify a correction request or if you contest the accuracy of your data), and object to processing based on our legitimate interests on grounds relating to your particular situation;
- receive your data in a portable, machine-readable format and have it sent to another service where technically feasible;
- withdraw any consent you have given, without affecting processing that already happened;
- object at any time, without needing to give a reason, to processing of your data for direct marketing purposes; not be subject to decisions based solely on automated processing that produce legal or similarly significant effects about you (Section 5 explains why our processing does not trigger this right).
To exercise any of these rights, email compliance[at]platoshealth.com. We respond within the time the law allows (one month under the GDPR, which may be extended by up to two months for complex or numerous requests, in which case we will inform you of the extension and the reasons). If you are in the EEA or UK you can also complain to your data protection authority (in the Netherlands, the Autoriteit Persoonsgegevens). If you are in Nigeria you can complain to the Nigeria Data Protection Commission.
Children
Platos is not intended for anyone under 18. We do not knowingly collect data from children under 18, and we take reasonable steps to verify age at registration. If we learn that we have, we will delete the account and the data. If you believe a child has given us data, contact compliance[at]platoshealth.com.
Security
We use technical and organisational measures to protect your data. Our platform is hosted on Google Cloud Platform in Europe, and we use encryption in transit and at rest, least-privilege access controls, and elevated controls and audit logging for the most sensitive categories of health data. No system is perfectly secure, but we work to protect your data, and if a breach occurs that is likely to put your rights at risk we will notify the relevant authority (within 72 hours of becoming aware, as the GDPR and NDPR require) and, where the risk is high, notify you. Our security approach is summarised in our Security and Data Handling Summary.
Not a medical device; no medical advice
Platos helps you understand your own health data. It does not diagnose, treat, cure, or prevent any disease, it is not a medical device, and it does not replace advice from a qualified clinician. Always seek professional advice for medical concerns, and call your local emergency number in an emergency.
Changes to this policy
We may update this policy. When we make material changes we will update the date above and, where appropriate, notify you in the app or by email. Please review it from time to time.
Contact
Privacy team: compliance[at]platoshealth.com. Postal: Platos Health B.V., Haparandaweg 594, 1013 BD Amsterdam, Netherlands.