This policy applies in two distinct contexts: (a) the azuvida.com website (waiting list) and (b) the Azuvida mobile application (iOS and Android). Sections relating specifically to the mobile application are indicated where relevant.
1. Data Controller
BizzKeys SRL
14 Rue de Loyers, 5340 Gesves, Belgium
Company number (CBE): BE 0465.536.058
Contact: support@azuvida.com
2. Data Collected
Website — waiting list
When registering for the waiting list, we collect:
- Email address
- User segment (patient, caregiver, healthcare professional)
- Registration date
- Frequency with which the medication question arises (optional)
Mobile application — account and profile
- Email address and password hash (if registered by email)
- Google identifier (if signed in via Google Sign-In)
- Role (patient, caregiver, healthcare professional)
- Interface language
- Email address verification status
Mobile application — tasks and tracking
- Name and description of configured tasks
- Frequency, schedule and recurrence days
- Status of each occurrence (to do, validated, missed, snoozed)
- Validation timestamp
- Validation photos (automatically deleted after 7 days)
Mobile application — subscription and notifications
- Active subscription plan and expiry date (via RevenueCat)
- Transaction identifier (Google Play / App Store)
- Firebase push notification token (FCM)
- Device time zone
3. Purposes and Legal Bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Sending launch communications (waiting list) | Consent — Art. 6.1.a |
| Creating and managing user accounts | Performance of contract — Art. 6.1.b |
| Providing application features (tasks, alerts) | Performance of contract — Art. 6.1.b |
| Processing health data (medication tasks) | Explicit consent — Art. 9.2.a |
| Sending push notifications (reminders, alerts) | Performance of contract — Art. 6.1.b |
| Managing subscriptions and billing | Performance of contract — Art. 6.1.b |
| Security, abuse and fraud prevention | Legitimate interest — Art. 6.1.f |
| Retention of accounting and tax records | Legal obligation — Art. 6.1.c |
4. Health Data
Tasks configured in the application may constitute health-related data within the meaning of Article 9 of the GDPR (e.g. medication intake, injections, treatments). Such data are processed on the basis of your explicit consent, collected at the time of account creation.
This consent may be withdrawn at any time by deleting your account from within the application. Withdrawal of consent results in the permanent deletion of all your data.
These data are never sold, transferred to third parties for commercial purposes, or used for advertising profiling.
5. Processors
BizzKeys SRL uses the following processors, all bound by a data processing agreement compliant with the GDPR:
| Processor | Role | Location |
|---|---|---|
| OVH SAS | Server hosting (VPS) and storage of validation photos | France (EU) |
| Brevo (formerly Sendinblue) | Transactional email and waiting list communications | France (EU) |
| Google Firebase | Push notifications (FCM) and Google Sign-In authentication | USA — SCC* |
| RevenueCat | In-app subscription management | USA — SCC* |
* SCC = Standard Contractual Clauses adopted by the European Commission (Implementing Decision 2021/914).
6. Retention Periods
| Data category | Retention period |
|---|---|
| Account and profile data | Until account deletion by the user |
| Tasks and occurrences | Until account deletion |
| Validation photos | 7 days (automatic deletion) |
| Technical logs (access, errors) | 30 days |
| Billing and transaction data | 10 years (Belgian legal obligation — Companies Code) |
| Waiting list (website) | Until unsubscription or application launch |
Deleting your account from the application results in the immediate and permanent deletion of all your personal data, with the exception of billing data retained for legal obligations.
7. Transfers outside the European Union
The services of Google Firebase (push notifications, authentication) and RevenueCat (subscriptions) involve processing of data in the United States. These transfers are governed by Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), ensuring an adequate level of protection for your data.
Data hosted on the primary servers (account, tasks, photos) remains exclusively within the European Union (OVH, France).
8. Your Rights
Under the GDPR, you have the following rights:
- Right of access — obtain a copy of your personal data.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure — request deletion of your data ("right to be forgotten").
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interest.
- Right to restriction — request the temporary suspension of processing.
- Withdrawal of consent — withdraw your consent at any time (health data and waiting list).
Via the application: deleting your account (Profile section → Delete my account) directly exercises your rights to erasure and withdrawal of consent.
By email: send your request to support@azuvida.com. We respond within one month (Art. 12 GDPR).
Waiting list unsubscription: via the unsubscribe link in each email, or by writing to support@azuvida.com.
9. Security
BizzKeys SRL implements the following technical and organisational measures to protect your data:
- Encryption of all communications in transit (HTTPS / TLS 1.2+).
- Passwords stored as hashes (bcrypt).
- Access to production data restricted to the technical director.
- Servers hosted in ISO 27001-certified data centres (OVH).
- Validation photos automatically deleted after 7 days.
- Authentication tokens with limited lifetime and secure refresh.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, BizzKeys SRL undertakes to notify the Data Protection Authority within 72 hours and to inform you as soon as possible.
10. Contact and Complaints
For any questions regarding this policy or your personal data, contact us at: support@azuvida.com
If you believe that the processing of your data does not comply with the GDPR, you have the right to lodge a complaint with the competent supervisory authority:
-
Belgium — Data Protection Authority (DPA):
www.autoriteprotectiondonnees.be -
France — Commission Nationale de l'Informatique et des Libertés (CNIL):
www.cnil.fr
You may also use the European Online Dispute Resolution platform: ec.europa.eu/consumers/odr.