Her-Medical-Aid GmbH | Last updated: April 2026 | Version 2.0
hermaid App
Last updated: May 2026
1. Data Controller & Contact
Below we inform you, in accordance with Art. 13 GDPR, about the processing of personal data when using the hermaid app (a CE-certified medical device for women in perimenopause and menopause).
4. General Notes on Data Processing
We process personal data only to the extent necessary to provide the app, perform contractually owed services, fulfill legal obligations, or based on your consent.
To the extent we process health data, this occurs only on the basis of a separate legal basis under Art. 9 GDPR, generally your explicit consent.
To the extent information is stored on or read from your device for certain features and this is not technically strictly necessary, this occurs only based on your consent under § 25 para. 1 TDDDG.
5. Data Processing in Detail
5
5.1 Downloading the App and Using App Stores
When you download the app from the Apple App Store or Google Play Store, the respective store operator processes personal data under its own data protection responsibility. We have no influence over this. The privacy notices of the respective store operator apply.
5.2 Providing the App and Technical Logs
When using the app, we process technically necessary data, in particular:
IP address
Timestamp
Device and operating system
App version
Error messages and technical log data
This processing serves to provide the app, ensure stability and security, analyze errors, and prevent misuse.
Legal bases: Art. 6 para. 1 lit. b GDPR, to the extent processing is necessary to provide the app, and Art. 6 para. 1 lit. f GDPR for IT security, stability, and misuse prevention.
5.3 User Account and Registration
To set up and manage your user account, we process in particular:
Email address
Password or password hash
Registration timestamp
Login and account status data
Voluntary profile data, to the extent provided by you
This processing serves to set up, authenticate, and manage your user account and to communicate with you regarding your account.
Legal basis: Art. 6 para. 1 lit. b GDPR.
5.4 Sign-In via Apple or Google (Single Sign-On)
You may optionally sign in using a single sign-on service from Apple or Google. In this case, we receive from the respective provider the information necessary for sign-in, in particular a platform-specific identifier as well as your email address and, where applicable, your display name.
This processing occurs exclusively to carry out the login procedure you have chosen.
Legal basis: Art. 6 para. 1 lit. b GDPR.
Please note that Apple and Google process personal data related to the login procedure under their own responsibility.
5.5 Health Features of the App
Within the app, you can provide health-related information, in particular regarding symptoms, complaints, cycle or hormonal changes, mood, sleep, diagnoses, or other health-related circumstances. This information constitutes health data within the meaning of Art. 4 no. 15 GDPR.
We process this data in particular for:
the onboarding questionnaire,
symptom tracking and journaling,
trend visualizations,
deterministic displays of the data you enter within the app,
preparing and carrying out optionally booked medical or consulting services.
Legal bases: Art. 6 para. 1 lit. b GDPR as well as Art. 9 para. 2 lit. a GDPR based on your explicit consent.
Without this information or without your explicit consent, health-related core features of the app may be wholly or partially unavailable.
5.6 AI-Powered Chat Function
If you use the optional chat function, we process the content of your inputs, the system's responses, and technical metadata to provide the feature.
The chat function serves general usage assistance and support in using the app. Its responses do not constitute a medical diagnosis, treatment, or individual medical advice. Medical inquiries are blocked through technical measures.
To the extent the chat function is provided via the external AI service provider OpenAI (EU), we transmit exclusively pseudonymized or generic text inputs without diagnostic or treatment context and without identifying features. Health data is not transmitted to OpenAI. We recommend that you do not enter directly identifying information such as names, addresses, or email addresses in the chat.
Legal basis: Art. 6 para. 1 lit. b GDPR for providing the chat function you requested.
5.7 Consultation Appointments and Teleconsultations
If you book consultation appointments or telemedicine services, we process in particular:
Booking and appointment data,
Contact data,
Information for preparing the appointment,
Health-related information, to the extent you provide it,
Communication and connection data for conducting the teleconsultation.
Recordings of video or audio consultations are only made if you have given separate prior consent.
Legal bases: Art. 6 para. 1 lit. b GDPR as well as Art. 9 para. 2 lit. a GDPR, to the extent health data is affected.
5.8 Payment Processing
Depending on the type of service booked, payment processing takes place via different payment channels:
for purchases via the Apple App Store or Google Play Store, through the respective store provider,
for teleconsultations or other direct payments, via our payment service provider Stripe Payments Europe Ltd. (EU),
for employer license programs, via the respective employer, to the extent no payment is made by you.
Health data is not transmitted to payment service providers, unless this is exceptionally, technically necessary, or legally required.
Legal basis: Art. 6 para. 1 lit. b GDPR.
5.9 Employer License Programs
If you use the app as part of an employer license program, we process the data necessary to verify eligibility and assign licenses, in particular:
Company email address,
Voucher or access code,
Assignment to a license program,
Activation or usage status in license-related form.
We generally do not disclose health data, chat content, or individual usage profiles to the employer. The employer only receives aggregated or license-related information, such as the number of activated licenses.
Legal bases: Art. 6 para. 1 lit. b GDPR and Art. 6 para. 1 lit. f GDPR.
5.10 Push Notifications
If you enable push notifications, we process the technical data necessary for sending them, in particular push tokens, device or app instance identifiers, and delivery information.
You can disable push notifications at any time in the app or device settings.
Legal bases: Art. 6 para. 1 lit. a GDPR as well as § 25 para. 1 TDDDG, where required.
5.11 Newsletter, Email Marketing, and Transactional Emails
If you consent to receiving marketing emails, we process your email address as well as, where applicable, information about opened emails or clicked links, provided you have also consented to corresponding performance measurement.
In addition, we send transactional or system-related emails, such as for registration, account security, password reset, appointment confirmation, or contract-related communication.
Legal bases:
Marketing emails: Art. 6 para. 1 lit. a GDPR
System and transactional emails: Art. 6 para. 1 lit. b GDPR
5.12 User Surveys and Feedback
If you voluntarily participate in surveys or feedback requests, we process the information you provide there to improve the app.
Legal basis: Art. 6 para. 1 lit. a GDPR.
5.13 Usage Analysis
To the extent you have given consent, we process pseudonymized usage data for statistical evaluation and optimization of the app. Health data is not used for this purpose.
Legal bases: Art. 6 para. 1 lit. a GDPR as well as § 25 para. 1 TDDDG, where required.
5.14 Scientific Studies
To the extent we offer scientific studies, you only participate if you actively sign up and give separate, study-specific consent. Depending on the study design, anonymized or pseudonymized data may be transmitted to research partners.
Legal bases: Art. 6 para. 1 lit. a GDPR as well as Art. 9 para. 2 lit. a GDPR.
5.15 Support and Communication
If you contact us, we process the data you provide, in particular contact details, the content of your message, and communication and processing data, in order to handle your inquiry.
Legal bases: Art. 6 para. 1 lit. b GDPR, if your inquiry is related to your contract, otherwise Art. 6 para. 1 lit. f GDPR.
6. Recipients and Categories of Recipients
Depending on the feature used, your data may be shared with the following recipients:
Hosting and infrastructure providers (Hetzner DE, AWS DE, Cloudflare EU)
Email and communication providers (Brevo EU, AWS SES DE)
Push and notification services (OneSignal EU)
Analytics and monitoring providers (Mixpanel EU, Appsflyer EU, Bugsnag EU)
AI service provider (OpenAI EU) — exclusively pseudonymized, non-medical inputs
Payment service provider (Stripe Payments Europe Ltd. EU)
Apple and Google as providers of the respective app stores and login services
Data protection and compliance consulting (heyData GmbH DE) — no operational data access
Research partners in the case of voluntary study participation
Employers as part of license programs, but only to the extent related to licensing or billing
Authorities, courts, and legal advisors, to the extent legally required
7. Service Providers Used
Depending on the app's feature scope, we use in particular the following service providers:
Hosting: Hetzner Online GmbH (DE), Amazon Web Services EMEA SARL (DE), Cloudflare (EU routing)
Push notifications: OneSignal Inc. (EU)
Analytics and monitoring: Mixpanel Inc. (EU), Appsflyer (EU), Bugsnag (EU)
User surveys: Formbricks (EU)
AI service provider: OpenAI (EU) — only pseudonymized, non-medical text inputs
Email delivery: AWS SES (DE), Brevo (EU)
Payment service provider: Stripe Payments Europe Ltd. (EU)
Data protection and compliance consulting: heyData GmbH (DE) — no operational data access
User management and authentication: internal service, self-hosted (DE)
Support systems: internal service, self-hosted (DE)
Billing: DMZR (DE), Stripe Payments Europe Ltd. (EU)
All service providers listed act as data processors within the meaning of Art. 28 GDPR and have been contractually bound accordingly.
8. Third-Country Transfers
To the extent we use service providers outside the European Economic Area, or these cannot rule out access from third countries, personal data may be transferred to third countries.
In such cases, we ensure an adequate level of protection permitted under the GDPR, in particular through:
an adequacy decision by the European Commission, in particular the EU-US Data Privacy Framework, to the extent a provider is certified under it, or
Standard Contractual Clauses of the European Commission together with supplementary safeguards.
Further information on the transfer mechanisms used for a specific service provider is available upon request.
9. Storage Period
We store personal data only as long as necessary for the respective purposes, in particular:
Account data, generally until your user account is deleted,
Health data, generally until the account is deleted or your consent is withdrawn, unless legal obligations require otherwise,
Contract, booking, and payment data for the duration of statutory commercial and tax retention periods (generally 6 to 10 years),
Technical log data for a limited period for error analysis and IT security,
Marketing consents and evidence thereof until withdrawal and as part of statutory documentation obligations,
Support inquiries for the duration of processing and beyond, to the extent necessary for documentation or legal defense.
10. Obligation to Provide Data
Providing certain personal data is necessary for concluding and performing the user agreement as well as for individual features of the app. Without this data, we may not be able to provide certain services.
Providing health data is voluntary. However, without this data or without your consent, health-related features of the app may be unavailable or only partially available.
11. Your Rights
Under the GDPR, you have in particular the following rights:
Right of access
Right to rectification
Right to erasure
Right to restriction of processing
Right to data portability
Right to object to processing based on Art. 6 para. 1 lit. f GDPR
Right to withdraw any consent given at any time with future effect
Right to lodge a complaint with a supervisory authority
To exercise your rights, you can contact support@hermaid.me or datenschutz@heydata.eu.
12. Right to Object
To the extent we process your data based on Art. 6 para. 1 lit. f GDPR, you have the right to object at any time to this processing for reasons arising from your particular situation.
We will then no longer process your data for these purposes unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims.
13. No Automated Decisions within the Meaning of Art. 22 GDPR
We do not make any decisions based solely on automated processing within the meaning of Art. 22 GDPR that produce legal effects concerning you or similarly significantly affect you.
AI-generated responses within the app serve for support and information, not for a legally significant automated individual decision.
14. Changes to this Privacy Notice
We may amend this privacy notice if this becomes necessary due to new features, changes in data processing, or changed legal requirements. The current version is available at all times in the app and on our website.