Privacy notice
Your account and health records are used only to operate Zokkor. There are no advertisements, marketing profiles, or optional analytics trackers. You can correct, export, or delete your records from inside the app.
1. Who is responsible
Data controller: REPLACE_WITH_LEGAL_OPERATOR_NAME
Address: REPLACE_WITH_FULL_POSTAL_ADDRESS
Privacy contact: privacy@zokkor.grown.mt
2. Data we process
3. Why and legal basis
Account data is processed to provide the service you request and secure it. Health data is processed on the basis of your explicit consent, requested separately during registration. The app performs no advertising, profiling, automated medical decision-making, or sale of personal information.
4. Storage and recipients
Data is stored in the database configured by the operator. It is disclosed only to infrastructure and email providers required to operate the service, where applicable, and to a recipient you choose when you download or share an export. The operator must document the actual host, subprocessors, locations, and transfer safeguards before a public launch.
5. Retention
Active-account records remain until you delete them. Account deletion removes the account, profile, glucose readings, export records, and active authentication tokens. Pseudonymized security audit events may be retained for up to 90 days. Encrypted backups, if configured by the operator, should expire within 30 days unless law requires longer retention.
6. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You can export CSV/JSON, correct readings and your profile, delete individual records, or delete the entire account directly. Contact privacy@zokkor.grown.mt for other requests. You may also complain to your local data protection authority.
7. Consent withdrawal
You may withdraw health-data consent by deleting your account, which stops processing and removes active records. Withdrawal does not affect processing that occurred before withdrawal.
8. Cookies and tracking
The service uses one strictly necessary, HttpOnly session cookie for authentication and security. If you select Remember me, that cookie can persist for up to 30 days. It contains no glucose readings. No consent banner is shown because no optional cookies or tracking technologies are included.
9. Security and changes
Controls include password hashing, email verification, access checks, CSRF protection, secure-session settings, input validation, prepared database queries, and security headers. No internet service can guarantee absolute security. Material notice changes require a new version and, where necessary, renewed acknowledgement or consent.