{{ t.eyebrow }}

Consumer Health Data Privacy Policy

Delta Auxilium AI Fitness Application — standalone policy for consumer health data

DELTA-CHD-001 • Version 1.1 • Effective Date: May 1, 2026 • Required under: MHMDA (RCW Ch. 19.373) • SB 370 (Nevada) • GDPR Art. 9 • FTC Act § 5

{{ t.enOnly }}

Controller Delta Auxilium Sp. z o.o., Ul. Bonarka 19/5, Kraków, Malopolskie, 30-415, Poland
Privacy Officer (DPO) privacy@aiadvisor.fitness
DPO@aiadvisor.fitness
Separate from General Privacy Policy This Policy is a standalone document required by MHMDA RCW 19.373.020 and SB 370 Sec. 21. It supplements and must be read together with the Delta General Privacy Policy (DELTA-PP-001).
Scope Washington State (MHMDA) • Nevada (SB 370) • All users whose consumer health data is processed by Delta

1. Overview

This Consumer Health Data Privacy Policy ("Policy") is published by Delta Auxilium Sp. z o.o. ("Delta," "we," "our," or "us") in compliance with the Washington My Health My Data Act ("MHMDA," RCW Ch. 19.373), the Nevada Consumer Health Data Law ("SB 370"), and other applicable consumer health data privacy laws (collectively, "Applicable State Laws").

This Policy describes how Delta collects, uses, and shares Consumer Health Data in connection with the Delta Auxilium AI fitness mobile application ("App"), and explains the rights available to consumers under Applicable State Laws. It supplements our General Privacy Policy (DELTA-PP-001) and, where the two documents address the same subject matter, should be read together with it. Capitalised terms not defined here have the meanings given in the General Privacy Policy.

For EU and EEA residents: your health data is additionally protected as Special Category Data under GDPR Article 9. EU-specific rights and protections are described in the General Privacy Policy and in our Data Subject Rights Procedures (DELTA-DSR-001).

2. What Is Consumer Health Data?

For purposes of this Policy and Applicable State Laws, "Consumer Health Data" means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status. This includes:

  • individual health conditions, treatment, diseases, or diagnoses;
  • social, psychological, behavioural, and medical interventions;
  • health-related surgeries or procedures;
  • use or purchase of prescribed medication;
  • bodily functions, vital signs, symptoms;
  • diagnoses or diagnostic testing, treatment, or medication;
  • gender-affirming care information;
  • reproductive or sexual health information;
  • biometric data used to identify or diagnose a health condition or a mental health condition;
  • precise geolocation data that could reasonably indicate a consumer's attempt to acquire health care services or supplies;
  • any information that Delta processes to associate or identify a consumer with the above data that is derived or extrapolated from non-health information (such as proxy, derivative, inferred, or emergent data produced by algorithms or AI).

The last category above is particularly significant for the App: because Delta's AI analyses multiple data inputs simultaneously to generate personalised recommendations, outputs and inferences derived by the AI from user data can themselves qualify as Consumer Health Data even if the underlying inputs were not individually health-related.

3. Categories of Consumer Health Data We Collect

The following categories of Consumer Health Data may be collected by the App. All collection is voluntary. Providing this data is not required to create an account, but improves the accuracy and personalisation of AI-generated plans.

Data Category What We Collect How Collected
Bloodwork and Laboratory Results Results of blood tests and other medical analyses uploaded by the user in file or image format (e.g. PDF, JPG, PNG), including hormonal panels, biochemical markers, and other lab values. Manually uploaded by you
Medication Information Information about prescription or over-the-counter medications currently taken by you. Processed exclusively for harm-reduction purposes — identifying potential interactions between medications, training, and recovery. Delta does not prescribe, sell, or recommend medications. Manually entered by you
Sleep Data Sleep duration and sleep quality indicators. Manually entered by you; or via Apple Health / Google Fit (where enabled)
Nutrition and Hydration Data Caloric intake, macronutrient breakdown (protein, fats, carbohydrates), and daily fluid intake. Manually entered by you
Supplement Information Information about dietary supplements, vitamins, and sports nutrition products you use. Manually entered by you
Workout and Activity Data Training history, workout preferences, fitness goals, and step count / daily activity level. Manually entered by you; or via Apple Health / Google Fit (where enabled)
Self-Reported Health and Medical History Health conditions, injuries, past surgeries, or other health limitations voluntarily disclosed during onboarding or at any time to help personalise your plan. Manually entered by you during onboarding or in profile settings
AI-Derived Health Insights Personalised inferences, correlations, risk-awareness insights, and recommendations generated by the App's AI based on the data categories above. These derived outputs qualify as Consumer Health Data under MHMDA and SB 370 definitions. Generated automatically by Delta's AI based on data you provide

Data categories not listed above — including email address, name, device information, and usage analytics — are personal information but do not constitute Consumer Health Data under Applicable State Laws. They are covered by the General Privacy Policy (DELTA-PP-001).

4. Sources of Consumer Health Data

Delta collects Consumer Health Data from the following sources:

Directly from you The primary source. You voluntarily enter or upload Consumer Health Data through the App's data entry forms, file upload features, and onboarding intake. All such collection is based on your active input.
Apple Health and Google Fit (where integrated) Where you have granted explicit permission through your device operating system settings, the App may receive step count, burned calories, and sleep data from Apple Health (iOS) or Google Health Connect (Android). This integration is conditional on your device-level permission and can be revoked at any time through your device settings. You are not required to enable this integration.
NOT from corporate affiliates Delta does not have affiliated entities, subsidiaries, or a corporate group from which it receives Consumer Health Data. All Consumer Health Data is collected directly from you or via the permitted integrations described above.

5. How We Use Consumer Health Data

Delta collects and uses Consumer Health Data solely for the following purposes. We do not use Consumer Health Data for any purpose not listed below without first obtaining your separate, specific consent.

AI Plan Generation (Primary Purpose) To generate your personalised workout plan, nutrition and supplementation plan, and lifestyle optimisation recommendations. This is the core purpose for which all Consumer Health Data is processed. The AI analyses the data categories in Section 3 in combination to produce plans tailored to your individual profile.
Harm Reduction and Risk Awareness To identify potential interactions between your medications, training intensity, bloodwork indicators, and recovery patterns. This analysis is informational and does not constitute medical advice. Delta does not prescribe, recommend, or discourage any medication.
Plan Adaptation and Recalibration To continuously update and improve your personalised plans as you add or modify data. The AI adapts recommendations in near real-time as new information is provided.
Account Management To maintain your account, link your Consumer Health Data to your user profile, and enable you to access, correct, or delete your data.
Security and Fraud Prevention To protect the integrity and security of the App and your account, including detecting and responding to unauthorised access or anomalous activity.
Legal and Regulatory Compliance To fulfil Delta's obligations under Applicable State Laws, GDPR, the FTC Health Breach Notification Rule, and other applicable law, including responding to your rights requests.
AI Model Improvement (with separate consent only) Where you have provided separate, specific, affirmative opt-in consent through the in-app AI training consent screen (described in Section 6 and in DELTA-AID-001), your Consumer Health Data may be used on an anonymised or aggregated basis to train, test, or improve Delta's AI models. This use requires your explicit consent and you may withdraw it at any time without affecting your access to the App.

7. Sharing and Disclosure of Consumer Health Data

Delta shares Consumer Health Data only in the limited circumstances described below. We do not sell Consumer Health Data. We do not share Consumer Health Data with third parties for their own commercial purposes.

AI / LLM Providers (Service Providers) Delta uses one or more Large Language Model (LLM) providers — which may include services such as Google (Gemini), OpenAI, Meta (LLaMA), or comparable platforms — to process Consumer Health Data for the purpose of generating AI recommendations. These providers act as data processors under signed Data Processing Agreements (DELTA-DPA-001). They are contractually prohibited from using Consumer Health Data for their own purposes, including model training, without separate user consent obtained by Delta.
Cloud Infrastructure Providers Delta uses cloud hosting and storage providers to store Consumer Health Data securely. These providers act as processors and do not access or use Consumer Health Data beyond the scope of their service delivery obligations.
Analytics and Crash Reporting (limited) Crash logs and performance data are sent to analytics processors (e.g. Firebase Crashlytics). These are pseudonymised and do not contain Consumer Health Data categories listed in Section 3. Health data is explicitly excluded from analytics transmissions.
Legal Obligations Where required by applicable law, a court order, or lawful regulatory authority request — including orders from US regulators such as the FTC, and Polish/EU authorities including UODO.
Safety and Fraud Prevention Where necessary to prevent imminent harm, fraud, or a security incident affecting user safety.
Business Transfers In the event of a merger, acquisition, or sale of assets, Consumer Health Data may be disclosed to the relevant parties. However, in accordance with MHMDA, Consumer Health Data will not be shared in connection with a business transfer without your prior affirmative consent, unless the transfer is to an entity that assumes all obligations of this Policy and Applicable State Laws with respect to your data. You will be notified of any such transfer.

In all sharing scenarios above, Delta does not share Consumer Health Data with: advertising networks, data brokers, supplement vendors, commercial partners for promotional purposes, or any third party for their own independent commercial use.

8. AI Processing Disclosure

All Consumer Health Data processed under this Policy is analysed exclusively by automated AI systems. No human professional (doctor, dietitian, trainer, pharmacist, or other specialist) reviews, supervises, or validates the processing of your Consumer Health Data or the recommendations generated from it. This is consistent with the disclosures in our AI Disclosure Statement (DELTA-AID-001) and Terms of Service (DELTA-TOS-001).

This automated processing constitutes automated decision-making within the meaning of GDPR Article 22. Delta's position is that the AI does not make legally significant or consequential decisions about healthcare access, eligibility, or treatment. You have the right to receive meaningful information about the logic involved in AI processing and to contest AI-generated outputs. Contact privacy@aiadvisor.fitness with any query.

9. Data Security

Delta implements appropriate technical and organisational security measures to protect Consumer Health Data, consistent with MHMDA RCW 19.373.050, GDPR Article 32, and the standards described in our Information Security Policy (DELTA-ISP-001) and Access Control Policy (DELTA-ACP-001). These measures include:

  • Encryption of Consumer Health Data at rest (AES-256) and in transit (TLS 1.2 or higher);
  • Separate encrypted storage for the most sensitive data categories (bloodwork, medications, laboratory results);
  • Role-based access controls limiting staff access to Consumer Health Data on a need-to-know basis;
  • Zero standing privileged access to production health data — all administrative access is time-limited and requires dual approval;
  • Mandatory multi-factor authentication for all staff with any system access;
  • Data Processing Agreements with all processors that access Consumer Health Data;
  • Pre-deployment review of all third-party SDKs and pixels to confirm no unauthorised access to Consumer Health Data.

In the event of a breach of Consumer Health Data, Delta will notify affected individuals and regulators in accordance with applicable law, including MHMDA, the FTC Health Breach Notification Rule, GDPR Article 33/34, and Delta's Incident Response Plan (DELTA-IRP-001) and FTC HBNR Compliance Procedure (DELTA-HBNR-001).

10. Your Rights Regarding Consumer Health Data

Subject to applicable law, you have the following rights in relation to your Consumer Health Data. These rights apply to Washington and Nevada residents under MHMDA and SB 370 respectively, and to all users under GDPR where applicable. Full procedures are set out in DELTA-DSR-001.

Right to Know / Confirm You have the right to confirm whether Delta collects or shares your Consumer Health Data, and to receive a list of the categories of Consumer Health Data collected, the purposes for which it is used, and the categories of third parties with whom it is shared. (MHMDA RCW 19.373.040(1); SB 370 Sec. 24(1); GDPR Art. 15)
Right of Access You have the right to obtain a copy of the Consumer Health Data we hold about you in a readily usable format. A significant portion of your Consumer Health Data is accessible directly within the App through your profile and plan history. (MHMDA RCW 19.373.040(1); GDPR Art. 15)
Right to Deletion You have the right to request deletion of your Consumer Health Data. Upon a verified request, Delta will delete your Consumer Health Data from its systems and instruct all processors (including LLM providers) to delete it. Delta will confirm deletion in writing, including disclosure of any data that cannot be deleted due to legal obligations or technical limitations (such as data already incorporated into AI model weights). (MHMDA RCW 19.373.040(3); SB 370 Sec. 24(3); GDPR Art. 17)
Right to Withdraw Consent You may withdraw your consent to the collection or sharing of Consumer Health Data at any time, for any or all data categories, through Settings → Privacy in the App or by contacting us at privacy@aiadvisor.fitness. Withdrawal does not affect processing prior to withdrawal. (MHMDA RCW 19.373.030; SB 370 Sec. 18; GDPR Art. 7(3))
Right to Cease Sharing You may request that Delta cease sharing your Consumer Health Data with third parties. Upon receipt of a verified request, Delta will cease all sharing not required for App functionality and instruct processors to cease use. (MHMDA RCW 19.373.040(3); SB 370 Sec. 24(3))
Right Not to Be Discriminated Against Delta will not penalise you, deny you service, or provide a lower quality of service as a result of your exercising any right under this Policy. (MHMDA RCW 19.373.040(5); SB 370 Sec. 24(5); GDPR Art. 21)
EU Additional Rights (GDPR) EU/EEA users additionally have the right to rectification (Art. 16), restriction of processing (Art. 18), data portability (Art. 20), and to lodge a complaint with UODO (the Polish data protection authority at https://uodo.gov.pl) or the supervisory authority in their country of habitual residence. See DELTA-DSR-001 for full procedures.

To exercise any of the above rights, use one of the following channels:

  • In-App: Menu 'More' → Profile → Legal and Privacy → Data Subject Access Request (recommended — identity verified by existing authentication);
  • Email: privacy@aiadvisor.fitness;
  • Post: Delta Auxilium Sp. z o.o., Ul. Bonarka 19/5, Kraków, Malopolskie, 30-415, Poland, Attn: Privacy Team.

Response timeline: Delta will respond to verified requests within 45 days (MHMDA / SB 370 standard; may be extended by a further 45 days with notice) or within 30 days (GDPR standard; may be extended by up to 2 additional months for complex requests). Full procedures are in DELTA-DSR-001.

11. Appeals

If Delta declines to act on your rights request, in whole or in part, you may submit an appeal within 30 days of receiving our response. Submit your appeal to:

Email privacy@aiadvisor.fitness (subject line: "Consumer Health Data Rights Appeal")
DPO DPO@aiadvisor.fitness
Post Delta Auxilium Sp. z o.o., Ul. Bonarka 19/5, Kraków, 30-415, Poland, Attn: Data Protection Officer

Delta will respond to your appeal in writing within 45 days, explaining the basis for any continued denial and your further options. If your appeal is not resolved to your satisfaction, you may escalate to:

12. Retention of Consumer Health Data

Delta retains Consumer Health Data for as long as your account is active and for a period necessary to fulfil the purposes described in this Policy. Specifically:

While your account is active All Consumer Health Data categories are retained to provide the App and maintain your personalised plans.
Following account deletion Consumer Health Data is deleted from production systems within 30 days of account deletion. Backup deletion is completed within 90 days. Certain data may be retained longer where required by law (see below).
Legal retention obligations Financial and billing records: 5 years (Polish accounting law). Incident and breach records: 6 years (per DELTA-HBNR-001). Consent records: retained for the duration of the applicable limitation period.
AI model training data If your data was incorporated into AI model weights with your consent: this data cannot be extracted from trained model parameters. We will disclose this to you upon a deletion request and take all feasible steps to exclude your data from future training runs.
Upon withdrawal of consent Where consent is the sole legal basis for processing a data category and you withdraw consent: data in that category is deleted within 30 days.

13. Children

The App is exclusively for users aged 18 and over. Delta does not knowingly collect Consumer Health Data from individuals under 18. If you believe a person under 18 has submitted Consumer Health Data to the App, please notify us immediately at privacy@aiadvisor.fitness, and we will delete such data promptly.

14. Updates to This Policy

Delta may update this Policy from time to time to reflect changes in our data practices, applicable law, or regulatory guidance. Any changes will be reflected by publishing an updated version within the App and on our website, together with a revised effective date and a clear summary of material changes.

Where changes are material — including any expansion of the categories of Consumer Health Data collected, any new third-party sharing, or any change to how consent is obtained — Delta will provide advance notice of at least 30 days through the App or by email before changes take effect, and will obtain fresh consent where required by law. If you do not agree with the updated Policy, you may withdraw your consent and delete your account as described in Sections 6 and 10.

15. Contact Us

Privacy Team privacy@aiadvisor.fitness
Data Protection Officer (DPO) DPO@aiadvisor.fitness
Postal Address Delta Auxilium Sp. z o.o., Ul. Bonarka 19/5, Kraków, Malopolskie, 30-415, Poland, Attn: Privacy / Legal
Washington AG (complaints) https://ago.wa.gov • (360) 753-6200
UODO — Polish DPA (EU complaints) https://uodo.gov.pl • kancelaria@uodo.gov.pl • +48 22 531 03 00
Related Policies DELTA-PP-001 (General Privacy Policy) • DELTA-DSR-001 (Data Subject Rights Procedures) • DELTA-AID-001 (AI Disclosure Statement) • DELTA-HBNR-001 (FTC HBNR Procedure) • DELTA-IRP-001 (Incident Response Plan)

Delta Auxilium Sp. z o.o. • DELTA-CHD-001 v1.1 • Effective: May 1, 2026 • Public — User-Facing Document
Published separately from DELTA-PP-001 as required by MHMDA RCW 19.373.020 and SB 370 Sec. 21