How we handle your data
This page explains, in plain language, what Fylax stores and why. Health information is a special category of personal data under the GDPR, and we process it only with your explicit consent.
Who is responsible
Fylax test server, panos.kar@gmail.com
What we store
- Your account: e-mail address, a hashed password, your language, when you gave consent, and the kinds of browser you signed in from (such as “Firefox on Windows”, no IP addresses), so we can warn you about a sign-in from a new one.
- Your emergency profile: the details you enter, such as conditions, medicines, allergies, implants and contacts.
- Your tags and a log of when your emergency page was opened, with the device type and a daily-changing visitor code. We don’t store IP addresses.
- Orders: what you bought, the engraving text, your shipping address and which version of the terms of sale you accepted. Payments are handled by Stripe; we never see your card.
- For the document assistant: the file name and the suggestions you review. The document itself is discarded after reading.
- Usual values (resting pulse, oxygen saturation, blood pressure, weight) that you enter or approve. An Apple Health export is read on your own device; only a summary of the last year is sent to us, and only to suggest these values and records.
- If you connect Withings or Oura: an encrypted access key, and the summaries we read from them once a month. Disconnecting deletes the key.
- Readings you add, and, only if you turn it on, each day’s value from your imports, for your charts.
- Lab results you add or confirm after the assistant reads them from a document: test, value, unit, the lab’s range, date and laboratory. Values the assistant read but you never checked are deleted after 90 days.
- Documents you keep in your library, encrypted with a key that is stored apart from everything else. They’re never on your emergency page.
- Links you make for a doctor: what each includes, when it expires, and when it was opened, from what kind of browser. Only a scrambled form of the link and its code is kept.
How long we keep it
- Your profile, medical details and tags: until you delete them or your account.
- The log of when your emergency page was opened: two years.
- Your readings, lab results and documents: until you delete them, or your account.
- Links for a doctor and the record of when they were opened: 90 days after they expire or you withdraw them.
- Suggestions you accepted or rejected, and the names of documents you sent to the assistant: one year.
- Accounts whose e-mail address was never confirmed and that never ordered anything: deleted after 30 days.
- Records of what our staff did (for example, who opened an order): two years. They never contain medical details.
- Payment notifications from Stripe: 90 days. Order and invoice records: as long as tax law requires, without your name or address once you delete your account.
- Encrypted backups: 14 days, then they are overwritten.
How we protect it
- Everything is stored on servers in the European Union and sent only over encrypted connections.
- Passwords are stored as one-way hashes. Access keys for Withings and Oura are encrypted.
- You can turn on two-step sign-in with an authenticator app. Our staff must use it.
- We e-mail you when your password or sign-in settings change, or someone signs in from a new kind of browser, so you notice if it wasn’t you.
- Backups are encrypted before they leave the server, with a key that isn’t kept on it.
Who can see it
- Anyone who scans or taps your tag sees your emergency profile. Private notes are never shown.
- The team making your tag sees your engraving text and shipping address, not your medical profile.
- If you use the document assistant, the document is sent to our AI provider to extract the details, only for that request.
- A doctor you give a link and its code to sees only what you chose for that link, until it expires or you withdraw it. You get an e-mail when it’s opened.
- Withings and Oura only share with us what you approve on their own consent page. We never send them your data.
E-mails
We e-mail you about your account and orders, and when your emergency page is opened (you can turn that off). We don’t send marketing.
Your rights
- Download everything we hold about you from Account and privacy.
- Correct your information at any time in your dashboard.
- Delete your account, which removes all health data and deactivates your tags. Order records are kept for accounting without your name or address.
- Withdraw consent by deleting your account, and complain to your data protection authority (in Greece, the Hellenic Data Protection Authority).
Cookies
We use one essential cookie to keep you signed in, and one to remember your language. There are no tracking or advertising cookies.