Privacy Policy
Last updated: March 2026
1. Introduction
At Numevo, we take the protection of your personal data seriously. This Privacy Policy explains what data we collect, why we collect it, how we use it, and what rights you have under the GDPR and applicable Estonian data protection law.
2. Data Controller
Numevo OÜ
Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551, Estonia
For any questions about how we handle your data, please contact us at the address above.
3. Data We Collect
Depending on how you use our platform, we may collect the following:
- Account data: name, email address, hashed password
- Profile data: age, goals, health targets (optional, user-entered)
- Supplement data: products and protocols you save or create
- Laboratory data: blood work values you voluntarily upload
- Usage data: pages visited, features used, session duration (analytics)
- Technical data: IP address (anonymised), browser type, operating system
- Cookie data: consent preferences, session identifiers
4. Purposes of Processing
We process your data for the following purposes:
- Providing and improving our platform and services
- Enabling account creation, authentication, and personalisation
- Allowing you to save and manage supplement stacks and protocols
- Sending transactional emails (email verification, password reset, reminders)
- Analysing anonymised usage patterns to improve user experience (with consent)
- Ensuring platform security and preventing abuse
5. Legal Bases (GDPR Art. 6)
- Art. 6(1)(b) – Performance of a contract: processing necessary to provide the services you signed up for
- Art. 6(1)(a) – Consent: analytics cookies and any optional processing you explicitly agree to
- Art. 6(1)(f) – Legitimate interests: platform security, fraud prevention, essential performance monitoring
- Art. 6(1)(c) – Legal obligation: where we are required to retain or share data by law
6. Cookies & Analytics
We use the following categories of cookies and tracking technologies:
Essential cookies (always active)
Required for the platform to function. These include authentication session cookies (NextAuth.js), locale preference cookies, and cookie consent storage. No consent is required.
Analytics cookies (require consent)
With your consent, we use PostHog to analyse platform usage. PostHog collects anonymised event data. You can withdraw consent at any time via Cookie Settings in the footer. We also use Vercel Analytics for aggregated performance metrics under our legitimate interest.
You can manage your cookie preferences at any time using the Cookie Settings link in the footer.
7. Data Transfers
Your data is primarily processed within the European Economic Area (EEA). Some service providers are based outside the EEA:
- Vercel Inc. (United States) – hosting and analytics. Transfers are governed by Standard Contractual Clauses (SCCs).
- PostHog – analytics, processed in the EU where our account is configured accordingly.
- MongoDB Atlas – database hosting within the EEA where applicable.
We ensure appropriate safeguards are in place for any transfers outside the EEA.
8. Data Retention
We retain your personal data for as long as your account is active or as necessary to provide our services. Upon account deletion, personal data is erased within 30 days, except where required by law. Analytics data is retained for up to 12 months.
9. Your Rights
Under GDPR, you have the following rights:
- Right of access – obtain a copy of the personal data we hold about you
- Right to rectification – correct inaccurate or incomplete data
- Right to erasure – request deletion of your data (right to be forgotten)
- Right to restriction – limit how we process your data
- Right to data portability – receive your data in a machine-readable format
- Right to object – object to processing based on legitimate interests
- Right to withdraw consent – withdraw any consent at any time without affecting prior processing
To exercise any of these rights, please contact us at contact@numevo.health.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data. Passwords are hashed and never stored in plain text. All connections use HTTPS encryption.
11. Supervisory Authority
If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the competent supervisory authority. In Estonia, this is:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Tatari 39, 10134 Tallinn, Estonia
12. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated via email or a notice on our platform.