Effective version: 17 July 2026
Nutricheck SAS, 87 rue de la Salicorne, 34470 Pérols, France
SIRET 93835823100018, Email: legal@nutricheck.eu
Nutricheck attaches fundamental importance to the protection and security of personal data. The confidentiality of such data and respect for privacy are among its priority commitments.
Nutricheck undertakes to protect personal data in accordance with applicable law, in particular Regulation (EU) 2016/679 of 27 April 2016, known as the "General Data Protection Regulation" (GDPR), and the French Data Protection Act (Law 78-17 of 6 January 1978, as amended).
Nutricheck's aim is to go beyond mere legal obligations by establishing a privacy policy grounded in ethics, transparency and security. For this reason, since the launch of its Solution, Nutricheck continuously ensures that it meets its personal data obligations and implements reinforced measures to protect its Users' data, including their health and wellness data.
Personal health data collected through the Nutricheck platform is hosted by an HDS-certified host (Hébergeur de Données de Santé, health data host), in accordance with the requirements of the French Digital Health Agency (ANS). This certification is intended to guarantee a high level of security in the processing of personal data in the health field.
Nutricheck also ensures that its practices comply with the reference frameworks and recommendations published by the French Data Protection Authority (CNIL).
In this personal data protection policy (hereinafter the "Policy"), the terms identified below with a capital letter have the following meaning, whether used in the singular or the plural:
GTU: means the general terms of use of the Solution and the Services.
Nutricheck Account: means the private personal space enabling a User to connect to the Solution in an authenticated and secure manner and to access the Services using their Credentials.
Content: means all texts, images, features, questionnaires, reports, recommendations and, more broadly, any element existing within the Solution and the Services.
Agreement: means the following contractual set: (i) the GTU and their appendices, and (ii) this Policy. These documents are made available to the User in electronic form (i) upon their first use of the Solution, (ii) upon creation of the Nutricheck Account, and (iii) at any time on the Solution.
Documents: means any document relating to the User or to their analysis results, transmitted securely to Nutricheck or uploaded by the User to their Nutricheck Account, such as reports, records, supporting documents, certificates and invoices, and more generally any medium (digital or scanned), whether or not containing Health-Related Personal Data.
Personal Data: means any data which, within the meaning of the Applicable Data Protection Regulations, makes it possible to identify, directly or indirectly, a natural person, in particular by reference to their civil status, an identifier, location data or one or more specific elements relating to their physical, physiological, genetic, mental, economic, cultural or social identity.
Health-Related Personal Data: means Personal Data relating to the physical or mental health of a natural person, including the provision of health or wellness services, which reveals information about that person's state of health, regardless of its source. This category includes wellness and physical-activity data liable to reveal information relating to health.
User Data: means (a) all Personal Data, including Health-Related Personal Data and the Documents: (i) provided by the User or the Guest through the Solution, (ii) recorded in the Nutricheck Account, (iii) shared voluntarily by the User, (iv) received or generated by a Laboratory or a Partner, (v) received from a Connected Device with the User's authorization, or (vi) processed by Nutricheck in connection with the Services, and (b) any Document or data uploaded, collected or distributed through the Solution.
Credentials: means the personal identifier associated with the Nutricheck Account, together with any password or confidential code assigned or modified by the User enabling access to the Solution.
Guest: means any natural person using the Solution or the Services without creating or logging into a Nutricheck Account, including in the context of spontaneous browsing or an initial non-authenticated interaction.
Laboratory: means any accredited or authorized entity carrying out analyses from a sample provided by the User, whether or not a partner of Nutricheck.
Connected Device: means any device, sensor, connected object or third-party application for tracking physical activity and wellness (for example Garmin, Google Fit, Apple Health, Fitbit, Withings, Oura or any equivalent service) that the User chooses to connect to the Solution in order to share all or part of the data associated with it.
Partner: means any legal entity having signed a partnership agreement with Nutricheck to offer Services or carry out analyses, under its own responsibility, which may be accessible from the Solution.
Policy: means this personal data protection policy.
Analysis Report: means any report of results produced following analyses carried out on a sample provided by the User, in particular a dried blood spot (DBS) test, a metabolic test or a urine test, made available to the User through the Solution or uploaded by the User on their own initiative.
Applicable Data Protection Regulations: means the GDPR, the French Data Protection Act and any national or European legislation in force applicable to the Processing of Personal Data.
Controller: means the natural or legal person that determines the purposes and means of the Processing of Personal Data, within the meaning of the GDPR.
Services: means all services made available by Nutricheck through the Solution, in particular the interpretation of analyses, the generation of indicators and scores, wellness and prevention recommendations, monitoring tools, and services providing access to Partners or Laboratories.
Solution: means the software solution developed and operated by Nutricheck, accessible via the website https://nutricheck.eu or any associated URL or application, available in SaaS (Software as a Service) mode and providing access to the Services.
Processor: means any natural or legal person processing Personal Data on behalf of the Controller, in accordance with Article 28 of the GDPR.
User: means any natural person holding a Nutricheck Account or accessing the Solution, whether authenticated or not, including any person authorized by the main User (family member, carer, legal representative, etc.).
Customer User: means any User who has purchased a Service, whether in the form of a subscription or a one-off order.
Unless otherwise stated, the terms defined in this Policy have the same meaning as those defined in the GTU.
The purpose of this Policy is to inform Users and Guests of the manner in which Nutricheck processes, protects and secures Personal Data in connection with the use of its Solution and Services.
It sets out how Nutricheck, together with, where applicable, the Laboratories and Partners involved in the service chain, collect, process, store, use and, where relevant, share Users' Personal Data, including Health-Related Personal Data, in compliance with the Applicable Data Protection Regulations.
This Policy sets out in particular:
The Policy applies to any natural person using the Solution, whether a User holding a Nutricheck Account, a Guest, or a representative of a Partner or Laboratory.
It forms an integral part of the GTU applicable to the Solution. It may be amended, updated or supplemented at any time by Nutricheck, in particular to take account of developments in the regulations, case law or CNIL recommendations. In the event of a substantial amendment, Nutricheck will inform Users by any appropriate means.
We invite you to read this Policy carefully and to refer to it regularly.
In connection with the provision of its Solution and the performance of its Services, Nutricheck acts, as a matter of principle, as Controller of Users' Personal Data.
Nutricheck thus determines the purposes and means of the processing relating in particular to:
Nutricheck may, in certain cases, act as Processor, on behalf of a Partner or a Laboratory that alone determines the purposes and means of a processing operation, under the conditions described in Section 6.2. In that case, Nutricheck acts solely on the documented instructions of the relevant Controller, in accordance with Article 28 of the GDPR.
Nutricheck takes all appropriate measures to ensure the protection and confidentiality of the Personal Data it processes, whether acting as Controller or as Processor. It complies with the reference frameworks adopted by the CNIL, in particular those relating to health data.
The use of the Solution and the Services offered by Nutricheck necessarily entails the collection and processing of certain Personal Data, including, in some cases, Health-Related Personal Data.
To enable the User or the Guest to access their analysis results, generate a personalized profile, benefit from wellness recommendations or access the Services, Nutricheck or its Partners and Laboratories must process Personal Data strictly necessary for the proper functioning of the Solution.
Such Data may be:
Without such collection, access to the essential features of the Solution, such as the delivery of results, analysis or recommendations, would be technically impossible or legally non-compliant.
By using the Solution, the User acknowledges that the processing of their Personal Data is necessary for the performance of the Services offered and for achieving the purposes described in this Policy. The failure to provide certain Personal Data may prevent Nutricheck from responding to a request or from providing all or part of the Services.
In connection with the provision of its Services, Nutricheck acts as Controller for a set of processing operations necessary for accessing, using, improving and securing its Solution. These processing operations are carried out in compliance with the GDPR, on the basis of determined legal grounds and for defined retention periods.
Where a processing operation concerns Health-Related Personal Data, it relies on a legal basis within the meaning of Article 6 of the GDPR as well as on an exception within the meaning of Article 9 of the GDPR, in practice the User's explicit consent (Article 9(2)(a)), unless another exception applies.
| Purpose of processing | Data concerned | Legal basis | Retention period in active use |
|---|---|---|---|
| Provision of the Solution and Services, management of the Nutricheck Account | Administrative, identification, contact and usage Data | Performance of the contract (Article 6(1)(b)) | Until deletion of the Account, or 5 years after the last activity |
| Delivery and analysis of results, generation of the profile, indicators and scores, wellness and prevention recommendations | Identification, usage and health Data | Explicit consent (Articles 6(1)(a) and 9(2)(a)) | Until deletion of the Account, or withdrawal of consent |
| Integration and processing of data from Connected Devices | Identification, usage and health and wellness Data | Explicit consent (Articles 6(1)(a) and 9(2)(a)) | For as long as the connection remains active and the Account exists |
| Provision of general or personalized information and prevention and wellness campaigns | Identification, contact and usage Data | Display of content: legitimate interest (Article 6(1)(f)); sending of emails or notifications: consent (Article 6(1)(a)) | Until deletion of the Account, withdrawal of consent or objection |
| Conduct of voluntary and optional surveys | Identification, contact and usage Data | Consent (Article 6(1)(a)) | Until withdrawal of consent, or 5 years after the last activity |
| Improvement of the Solution and Services, statistics | Usage Data; health data only after anonymization or with consent | Legitimate interest (Article 6(1)(f)); for health data: consent (Articles 6(1)(a) and 9(2)(a)) or anonymization | Until deletion of the Account, or anonymization |
| Prevention and detection of fraud | Identification, contact and usage Data | Legitimate interest (Article 6(1)(f)) | 3 years from the last login |
| Establishment of a data repository for research purposes | Identification, usage and health Data | Explicit consent (Articles 6(1)(a) and 9(2)(a)) and the CNIL reference framework on data repositories | Depending on the project and applicable authorization, within the limit set out in Section 8 |
| Provision of user support | Identification, contact and usage Data; health data where applicable | Performance of the contract (Article 6(1)(b)); consent for health data | Up to 6 years from the request |
| Exercise of Users' rights | Identification Data (including proof of identity) and contact Data | Legal obligation (Article 6(1)(c)) | 6 years from the request |
| Information on changes to the Solution and Services | Identification and contact Data | Performance of the contract (Article 6(1)(b)) or legal obligation (Article 6(1)(c)) | Until deletion of the Account |
| Commercial prospecting | Identification, contact and usage Data | Similar offers: legitimate interest (Article 6(1)(f)); third-party offers: consent (Article 6(1)(a)) | Up to 3 years after the last contact, or withdrawal of consent |
| Proposal to take part in studies | Identification, contact, usage and health Data | Explicit and specific consent for each study (Articles 6(1)(a) and 9(2)(a)) | Period defined for each study and the associated consent |
| Provision of a messaging service | Identification, contact, usage and health Data | Consent (Articles 6(1)(a) and 9(2)(a)) | Until deletion of the Account, or withdrawal of consent |
| Sale of products and Services | Identification, contact and usage Data | Performance of the contract (Article 6(1)(b)); accounting and tax obligations (Article 6(1)(c)) | Duration of the commercial relationship, then 10 years under accounting obligations |
In certain cases, Nutricheck makes its Solution available to Partners or Laboratories that alone determine the purposes and means of the processing and that are, as such, Controllers within the meaning of the Applicable Data Protection Regulations.
In this context, Nutricheck acts solely on the documented instructions of the Controller, in accordance with Article 28 of the GDPR and the agreement binding it to the latter. Nutricheck takes all technical and organizational measures necessary to guarantee the security, confidentiality, traceability and integrity of the Personal Data entrusted to it.
| Purpose of processing | Data concerned | Legal basis (defined by the Controller) |
|---|---|---|
| Making results and Analysis Reports available | Identification, contact, usage and health Data | Performance of the contract |
| Management of invoicing and collection of sums due | Identification, contact and usage Data | Performance of the contract |
| Hosting of Personal Data and access security | Identification, contact, usage and health Data | Legitimate interest or legal obligation |
| Sending Users information or notifications related to their analyses | Identification, contact and health Data | Legitimate interest |
| Anonymization or pseudonymization of data | Identification, usage and health Data | Legitimate interest or regulatory obligation |
| Improvement of the Solution on behalf of the Controller | Usage and health Data | Legitimate interest |
| Organization, management and maintenance of the digital tools made available | Identification, contact and usage Data | Legitimate interest |
When acting as Processor, Nutricheck undertakes to process the Data solely on the instructions of the Controller, not to make any improper or unauthorized use of it, and to inform the Controller without delay of any Data breach or any request from an authority.
In connection with the use of the Solution and the Services, Nutricheck may process, whether as Controller or as Processor, all or part of the following Personal Data, in order to enable the processing operations described in Sections 6.1 and 6.2.
Administrative data:
Identification data:
Contact data:
Usage data:
Health and wellness data:
Location data:
Data concerning third parties:
The Solution implements automated processing, including profiling operations, in order to generate indicators, scores and personalized wellness and prevention recommendations from the User Data, including Health-Related Personal Data and, where applicable, data from Connected Devices.
This automated processing has an informational, monitoring and prevention purpose. It does not constitute a diagnosis, does not replace the advice of a professional, and does not, on its own, produce legal effects concerning the User or similarly significantly affect the User within the meaning of Article 22 of the GDPR.
The User retains at all times the ability to request information on the logic underlying such processing, to express their point of view, to contest a result and to request human intervention, under the conditions set out in Section 12.
Subject to the User's express, free, informed and specific consent, certain Personal Data, including Health-Related Personal Data, may be reused by Nutricheck or on behalf of its Partners for the purposes of scientific studies, research or development, in strict compliance with the Applicable Data Protection Regulations and in accordance with the reference frameworks issued by the CNIL.
This reuse concerns only pseudonymized or anonymized data, where possible, and always takes place within a framework that is clearly defined and documented, limited in time and, where applicable, validated by an ethics committee or a competent authority.
The research projects are aimed in particular at:
A dedicated page on studies and research, available at https://nutricheck.eu, specifies for each ongoing project the identity of the project manager, the associated partners, the objectives pursued, the start and end dates, the categories of data concerned, and the procedures for withdrawal or objection. This page serves as information within the meaning of Articles 12 to 14 of the GDPR.
In the event of participation in a specific study, a dedicated consent document is presented to the User. The User is free to accept or refuse it, without any consequence for their access to the Services. In the event of withdrawal of consent to a reuse in an ongoing project, the User's Data is no longer included in the subsequent phases of the study, without retroactive effect on the processing already carried out. No data is transferred to a Partner without the User's prior authorization.
Nutricheck allows the User to connect, on a strictly optional basis, certain connected devices and third-party applications for tracking physical activity and wellness (for example Garmin, Google Fit, Apple Health, Fitbit, Withings, Oura or any equivalent service), in order to enrich their profile and refine the analyses and recommendations offered by the Solution. This connection is never mandatory and is not necessary to access the essential features of the Solution.
Prior authorization and User control. Access to the data of a Connected Device is activated only after the User's express authorization, by means of the secure authentication mechanism made available by the relevant provider (OAuth protocol). The User chooses the categories of data they wish to share and may, at any time, revoke this authorization, without affecting the lawfulness of the processing carried out before the withdrawal.
Categories of data concerned. Subject to the authorizations granted and the categories actually shared by the User, Nutricheck may receive from the Connected Device data such as physical activities and workout sessions, heart rate and heart rate variability, sleep, stress level, energy and recovery indicators, maximal oxygen uptake, respiration rate, oxygen saturation, energy expenditure, daily activity summaries, as well as location data and the GPS tracks associated with activities where the User chooses to share them. Nutricheck collects only the data necessary for the purpose for which the User has activated the connection.
Purposes. The data from Connected Devices is used exclusively to provide the User with a consolidated view of their data, to contextualize and put their results into perspective, to personalize the content, monitoring indicators and wellness and prevention recommendations offered by the Solution, and to enable longitudinal monitoring over time. The location data and GPS tracks may also be correlated with environmental data from third-party sources, in particular air quality indices (fine particulate matter PM10 and PM2.5, ozone), in order to offer the User prevention and wellness recommendations that take into account their environmental exposure. Location data is used for this sole purpose and is not subject to any other tracking of the User's movements. The User may enable or disable the sharing of their location independently of the other categories of data. This data is not used for any diagnostic purpose.
Legal basis. The processing of data from Connected Devices relies on the User's express consent (Article 6(1)(a) of the GDPR and, with respect to data relating to health or physical wellness, Article 9(2)(a) of the GDPR). The User may withdraw their consent at any time.
Controller. Nutricheck acts as Controller of the data from Connected Devices that it receives and processes in order to provide the Solution to the User. The provider of the Connected Device remains independently responsible for the processing it carries out in connection with its own services. The User's use of those services is governed by the privacy policy of the relevant provider.
No sale and no advertising. Nutricheck does not sell or rent the data from Connected Devices, does not use it for any advertising purpose, and does not transfer it to any third party for that third party's own purposes. This data is processed solely to provide the Solution to the User, in accordance with the purposes described above.
Security and hosting. The data from Connected Devices benefits from the same security measures as all Personal Data processed by Nutricheck and is hosted, where it constitutes health data, by an HDS-certified host located in the European Union.
Retention period. The data from Connected Devices is retained for as long as the connection remains active and the User's Account exists. It is deleted, or irreversibly anonymized, upon disconnection of the relevant source or deletion of the Account, subject to applicable legal retention periods.
Disconnection and deletion. The User may at any time disconnect a data source from their Nutricheck Account and from their account with the relevant provider. Disconnection stops any further receipt of data. The User may also request the deletion of the data already collected under the conditions set out in Section 12.
International transfers. Where a provider of a Connected Device is established outside the European Economic Area, in particular in the United States, the receipt of data by Nutricheck may involve a transfer outside the European Economic Area. Such a transfer takes place only where it benefits from an appropriate level of protection, in the following order of priority: (i) an adequacy decision of the European Commission, in particular the EU-US Data Privacy Framework where the provider is validly certified thereunder; (ii) failing that, the European Commission's Standard Contractual Clauses or any other instrument recognized by the Applicable Data Protection Regulations; (iii) as a residual basis, a derogation provided for in Article 49 of the GDPR. The data received is stored within the European Union.
Compliance with providers' terms. Nutricheck's use of data from Connected Devices is carried out in accordance with the applicable terms and requirements of each provider, in particular, with respect to Garmin, the Garmin Connect Developer Program Agreement.
Nutricheck retains Personal Data only for the period strictly necessary to achieve the purposes for which it was collected, in accordance with the principles of the GDPR and in compliance with applicable legal, regulatory or contractual obligations.
The Personal Data processed is retained in active use for the entire duration of use of the Solution and the Services, and thereafter, as the case may be, either permanently deleted, or irreversibly anonymized for research or statistical purposes, or archived in an intermediate archive under reinforced security conditions where retention is required by law or for the establishment, exercise or defense of a legal claim.
Data retained in active use:
| Type of data | Retention period in active use |
|---|---|
| Account Data (identification, contact, usage) | Until deletion of the Account, or 5 years after the last activity |
| Health data from tests and questionnaires | Retained for the entire duration of the Account to enable longitudinal monitoring, then deleted or irreversibly anonymized no later than 10 years after the User's last activity or the closure of the Account, unless an early deletion request is made or a legal retention obligation applies |
| Data from Connected Devices | For as long as the connection is active and the Account exists |
| Browsing data and technical logs | 12 months from collection |
| Data used for research purposes with consent | Depending on the nature of the project and applicable authorizations, within the limit set by the applicable CNIL reference framework |
| Data related to the sending of emails or notifications with consent | Until withdrawal of consent or deletion of the Account |
Data retained in an intermediate archive (secure archiving):
| Type of data | Maximum intermediate archiving period |
|---|---|
| Accounting and payment-related data | 10 years from the close of the financial year (legal obligation) |
| Data related to a claim or dispute | 5 years from the closure of the file |
| Data related to the exercise of Users' rights | 6 years from the request |
At the end of these periods, the Personal Data is permanently deleted or anonymized, unless a legal obligation to retain it for longer applies, a competent authority so requests, or retention is necessary for the defense of a legal claim.
Each User remains in control of their Personal Data. Nutricheck does not freely dispose of it and makes no use of it that is not provided for in this Policy.
In accordance with Article 28 of the GDPR, Nutricheck may use Processors, that is, technical or specialized service providers acting on its behalf under a strict contractual relationship. These Processors act only on Nutricheck's instructions and are subject to contractual obligations of security, confidentiality and compliance equivalent to those of Nutricheck.
Personal Data is accessible only to the following recipients, to the extent necessary:
The list of the main Processors and recipients of the Personal Data is kept up to date by Nutricheck and may be provided to the User on simple request sent to dpo@nutricheck.eu.
Nutricheck undertakes not to disclose the User's Personal Data to third parties for commercial or advertising purposes, except with the prior and explicit authorization of the data owner.
Nutricheck may be required to disclose Personal Data in order to comply with a legal or regulatory obligation, to comply with an injunction from an administrative, judicial or supervisory authority, or to protect its rights and prevent any fraudulent, abusive or unlawful conduct. Such disclosures are strictly framed and may take place only on a legal basis, within the limits provided for by law.
In accordance with Article L. 1111-8 of the French Public Health Code, Nutricheck uses an HDS-certified host (Hébergeur de Données de Santé) to store and secure the Health-Related Personal Data processed in connection with its Services. This host is located within the territory of the European Union and holds a certificate issued by the French Digital Health Agency. Nutricheck undertakes to maintain this certification and to inform its Users of any change of status or of provider.
Nutricheck stores Personal Data within the European Economic Area, subject to the framed transfers described below.
Where a processing operation involves a transfer of Personal Data to a country located outside the European Economic Area, in particular in connection with the connection of a Connected Device whose provider is established in a third country, Nutricheck proceeds only on condition that an appropriate level of protection is guaranteed, in the following order of priority: (i) an adequacy decision of the European Commission, in particular the EU-US Data Privacy Framework where the recipient is validly certified thereunder; (ii) failing that, the European Commission's Standard Contractual Clauses or any other legal instrument recognized as appropriate by the Applicable Data Protection Regulations; (iii) as a residual basis, a derogation provided for in Article 49 of the GDPR. Nutricheck verifies the validity of the applicable safeguard at the time each transfer is set up and throughout its duration.
The Personal Data to which the User has access through the Solution, in particular Health-Related Personal Data, is covered by respect for privacy and confidentiality. Accordingly, the User undertakes to act in a responsible and ethical manner and in compliance with the legislation in force on the protection of personal data.
Each User undertakes to:
Where a Partner or a Laboratory acts as Controller, it is responsible for complying with the formalities and obligations provided for by the Applicable Data Protection Regulations, informing the data subjects of the processing of their Personal Data, ensuring the effective exercise of their rights, and notifying, where applicable, any Personal Data breach to the CNIL and to the data subjects under the conditions provided for by law. Nutricheck accepts no liability in the event of non-compliance, by a Partner or a Laboratory, with its own obligations as Controller.
Nutricheck implements and continuously maintains a set of appropriate technical and organizational measures to guarantee a level of security appropriate to the risk inherent in its Personal Data processing activities, and in particular in respect of Health-Related Personal Data. These measures are intended to ensure the confidentiality, integrity, availability and resilience of the systems and data, and to prevent any unauthorized, accidental or unlawful access, use or disclosure.
By way of indication and without limitation, Nutricheck has in particular deployed the following mechanisms:
These mechanisms are regularly tested, assessed and updated to ensure their effectiveness, in accordance with Article 32 of the GDPR.
Each User is informed that it is their responsibility to implement, under their sole responsibility, all appropriate measures to ensure the confidentiality and security of their login credentials, of their personal device (computer, smartphone, tablet) and, more generally, of any medium enabling them to access the Solution.
The User undertakes never to disclose their credentials or access to third parties, not to record or reproduce a third party's Health-Related Personal Data without authorization, and to report to Nutricheck immediately any unauthorized access or any suspicious use of their Account. Nutricheck cannot be held liable for the consequences of fraudulent or unauthorized access to the Solution resulting from the User's negligence or lack of vigilance.
In accordance with the Applicable Data Protection Regulations, and in particular Regulation (EU) 2016/679 of 27 April 2016 (GDPR), each User or Guest has a set of rights over the Personal Data concerning them. These rights may be exercised at any time, under the conditions described below.
These rights are exercised free of charge for the User, except in the case of manifestly unfounded or excessive requests (Article 12(5) of the GDPR).
The User may exercise their rights by email at dpo@nutricheck.eu, or by post at: Nutricheck SAS, Data Protection Officer, 87 rue de la Salicorne, 34470 Pérols, France.
Any request must be clear and explicit and be accompanied, where applicable, by a copy of a valid proof of identity, in order to verify that the applicant is indeed the person concerned by the Data. Nutricheck undertakes to respond within a maximum period of 30 calendar days from receipt of the complete request. This period may be extended by a further 2 months in the event of particular complexity or a high number of requests, in accordance with Article 12(3) of the GDPR.
Where Nutricheck acts on behalf of a Controller (for example a Partner or a Laboratory), any request relating to the exercise of rights must be addressed directly to the relevant Controller, in accordance with Article 28 of the GDPR. Nutricheck will assist, upon express request and within the limits provided for contractually, the Controller in handling the request. Under no circumstances may Nutricheck be held liable for a failure to respond or a refusal to allow the exercise of rights where that decision falls within the Controller's remit.
In the event of a persistent difficulty or dissatisfaction relating to the processing of their Personal Data, the User may lodge a complaint with the competent supervisory authority: Commission nationale de l'informatique et des libertés (CNIL), Service des Plaintes, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.
The Nutricheck Solution and the associated Services are, as a matter of principle, intended for persons aged 18 years or over who are capable of entering into obligations in accordance with the legislation applicable in their country of residence.
Minors, or protected adults under a regime of guardianship, curatorship or judicial protection, must obtain the prior and express consent of their legal representative before creating an Account or transmitting Personal Data through the Solution.
Should Nutricheck find that an Account has been opened or used in breach of this rule, the necessary measures may be taken, including the suspension or deletion of the Account, after verification.
Where a minor is concerned by a test, an assessment or a recommendation carried out by the Solution, their data is collected, processed and made accessible only under the responsibility of their legal representative. Unless a legal obligation provides otherwise, Nutricheck may, in the context of a request made by a legal representative, inform the latter of the categories of Personal Data processed and enable them to exercise the rights provided for in Section 12 over that data.
This Policy applies from its date of publication and is binding on any User, Guest or any other person accessing or using the Solution or the Services offered by Nutricheck.
Nutricheck reserves the right to amend, supplement or update this Policy at any time, in particular to take account of any legislative, regulatory, case-law, technical or organizational development. In the event of a substantial amendment significantly affecting Users' rights, Nutricheck undertakes to inform Users by any appropriate means (email, notification within the Solution, alert banner) and to enable them, where applicable, to express their refusal or to withdraw their consent, where such consent is required.
The User acknowledges and accepts that only the version in force on the day of their access to the Solution or their use of the Services is authoritative. It is the User's responsibility to consult the Policy regularly, available online from the dedicated page of the https://nutricheck.eu website or from the interface of their Account. In the event of disagreement with an updated version of the Policy, the User may at any time request the deletion of their Account and the erasure of their Personal Data, under the conditions set out in Section 12.
When browsing the Solution or using the Services, cookies and other trackers may be placed or read on the terminal of the User or the Guest (computer, smartphone, tablet), subject to their consent, where such consent is required.
A cookie is a text file that may be stored in a dedicated area of the User's terminal when accessing an online service. It enables its issuer to identify the terminal in which it is stored, for the duration of the cookie's validity.
The cookies used by Nutricheck serve the following purposes:
Nutricheck does not use trackers for third-party advertising purposes, nor cross-site tracking mechanisms.
In accordance with the CNIL's requirements, the placement of cookies that are not strictly necessary is subject to obtaining the User's prior consent. An information banner is displayed on first connection, enabling the User to accept all cookies, to refuse all non-essential cookies, or to personalize their preferences, service by service.
The choice expressed is retained for a maximum period of 6 months, at the end of which consent is requested again. The User may modify their preferences at any time from the dedicated interface accessible at the bottom of the page.
The User may also configure their browser to refuse all or part of the cookies. However, refusing technical cookies may impair the proper functioning of the Solution or restrict access to certain essential features (login, history, access to results). To find out more, the User is invited to consult the privacy settings of their browser as well as the CNIL's information page: www.cnil.fr/cookies.
In accordance with Article 33 of the GDPR, Nutricheck undertakes to notify any Personal Data breach liable to result in a risk to the rights and freedoms of the data subjects to the competent supervisory authority as soon as possible and, where feasible, within 72 hours after becoming aware of it, as well as, where necessary, to the data subjects. When acting as Processor, Nutricheck undertakes to inform the Controller immediately of any breach of which it becomes aware, to provide all useful information and to assist it in implementing the corrective measures and the required communication obligations. This notification in no way constitutes an acknowledgment of liability or fault on the part of Nutricheck.
Nutricheck hosts health data on HDS-certified servers, located within the territory of the European Union, in accordance with Article L. 1111-8 of the French Public Health Code. Upon request by a User or by a Controller on whose behalf it acts, Nutricheck undertakes to provide evidence of the certification of its HDS host, and to notify any change of status or change of host within a maximum period of 30 calendar days.
Nutricheck has appointed a Data Protection Officer, responsible for overseeing compliance with the Applicable Data Protection Regulations. The Data Protection Officer may be contacted at dpo@nutricheck.eu or by post at the address indicated in Section 17.
Where the envisaged processing is likely to result in a high risk to the rights and freedoms of the data subjects, Nutricheck carries out a data protection impact assessment (DPIA), in accordance with Article 35 of the GDPR. Where Nutricheck acts as Processor, it may assist the Controller in assessing the risk, in drafting the DPIA or in any prior formality with the CNIL.
The Controller on whose behalf Nutricheck acts as Processor may, under the conditions provided for by contract, request to audit Nutricheck in order to verify its compliance, in accordance with the following principles: written notice of at least 30 calendar days; a maximum of one audit per calendar year, unless a legal requirement provides otherwise; performance by an independent auditor, jointly accepted by the parties; signature of a confidentiality undertaking by the auditor; limitation of the audit to the data or processing operations specifically related to the requesting Controller. The audit must not disrupt the normal functioning of the Solution. Information relating to other clients, to the overall security of the infrastructure or to trade secrets is not accessible without prior contractual derogation.
For any question relating to this Policy, to the exercise of your rights, to the reporting of a breach or to any difficulty relating to the processing of your Personal Data, you may contact Nutricheck by email at dpo@nutricheck.eu, or by post at: Nutricheck SAS, Data Protection Officer, 87 rue de la Salicorne, 34470 Pérols, France.
You also have the right to lodge a complaint with the competent supervisory authority: Commission nationale de l'informatique et des libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr.
©2025 - Nutricheck - All right reserved