Privacy Notice
This privacy notice explains how ProNex Consulting s. r. o. processes the personal data of users of the DiaLog app and the related public website dia-log.sk.
DiaLog is a personal health diary. It is not a diagnostic, treatment, or emergency service and does not replace a healthcare professional. An account may exist without explicit health-diary consent.
1. Controller and contact
The controller of the DiaLog app and the related public website is ProNex Consulting s. r. o., Trieda KVP 1C, 040 23 Košice - Sídlisko KVP city district, Slovak Republic.
Company ID (IČO): 56685530. Tax ID (DIČ): 2122420256. VAT ID (IČ DPH): SK2122420256 (registration under § 7a of the Slovak VAT Act from 6 February 2025).
Email for privacy questions and exercising your rights: info@dia-log.sk. Canonical website: https://dia-log.sk (the www-prefixed address redirects to this canonical address).
For questions about personal data, explicit health-diary consent, withdrawal of consent, account deletion, or exercising your rights, contact us at info@dia-log.sk.
2. Data protection officer
No data protection officer (DPO) or special data-protection contact person is currently appointed.
Send questions and requests about personal data to the controller at info@dia-log.sk.
3. What personal data we process
When you use DiaLog, we may process in particular the following personal data.
3.1 Account data
- email address,
- data needed to create an account, sign in, and recover a password,
- display name / profile name, if you enter it,
- birth year and gender, if you enter them,
- technical data needed for sign-in, the session, and account protection.
3.2 Health-diary data
The health diary is voluntary. If you use it, we may process in particular glucose measurements, insulin records (catalogue and dose history), medication records (catalogue and intake history), estimates and stored HbA1c history, health-related notes, height and weight as health data in the profile, diary-related health reminder settings, and data needed for diary history, charts, summaries, and export.
Height and weight are not ordinary non-health profile fields. They are processed as health data.
- glucose measurements (value, date and time, category / time slot, and a note if you enter one),
- insulin records (catalogue and dose history),
- medication records (catalogue and intake history),
- estimates and stored HbA1c history, if you use this feature,
- health-related notes on records,
- height and weight as health data in the profile, if you enter them,
- diary-related health reminder settings,
- data needed for diary history, charts, summaries, and export.
3.3 Data on the device
A generated or exported PDF may contain health data. Once a copy leaves temporary storage controlled by DiaLog, it is under the control of the recipient or destination you choose. We do not promise instant deletion from external copies you have already exported or shared.
- data needed for sign-in and the session,
- app-lock settings, if you turn the lock on,
- temporary files created during export, if you use export,
- locally scheduled reminders, if you enable them,
- health data temporarily stored on the device for offline use.
3.4 Website
On dia-log.sk we may process ordinary hosting operational records and, only if you allow it, website analytics (see the Analytics section).
3.5 Service operational records
For operation, security, and support we may process limited first-party operational records, for example an account-activity signal or a record that you used a feature. These records are not advertising profiling and we do not combine them with marketing.
4. Health data
Health-diary data are health data, a special category of personal data under the GDPR. Where you use them, they include glucose measurements, insulin, medication, estimated HbA1c history, health-related notes, health reminders and diary settings, height, weight, and data needed for history, charts, summaries, and export.
DiaLog is a personal health diary. It is not a diagnostic, treatment, or emergency service. We do not use the data to determine a diagnosis, provide treatment, recommend a dose, or give health advice.
You use the health diary voluntarily. An account may exist without an active health diary.
5. Purposes and legal bases
Each purpose has its own legal basis. We do not use one legal basis for all processing.
We do not use personal data for marketing. We therefore do not state a marketing legal basis.
If you contact us with a support request, we process the data needed to handle that request.
- Creating an account, signing in, recovering a password, and providing the requested basic account service — Article 6(1)(b) GDPR, only to the extent objectively necessary for that service.
- Health diary (including height and weight as health data) — Article 6(1)(a) GDPR and Article 9(2)(a) GDPR — explicit consent. The health diary is not processed as performance of a contract.
- Account protection, abuse prevention, and service protection — Article 6(1)(f) GDPR — the controller’s legitimate interest in a safe and reliable service, only to the necessary and proportionate extent.
- Compliance with a legal obligation where such an obligation actually arises — Article 6(1)(c) GDPR, only where the law requires it.
- Website analytics on dia-log.sk — Article 6(1)(a) GDPR — consent given in the cookie banner, only after analytics is accepted.
6. Explicit health-diary consent
Processing of health data in the health diary is based on explicit consent.
Having an account is not the same as granted explicit health-diary consent. Adding and editing health-diary data require valid current explicit consent and fulfilment of the currently required privacy state.
You may withdraw consent at any time. Withdrawal must be as easy as giving consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Withdrawal of consent does not require account deletion. You may delete the account separately.
Consent cannot be withdrawn only by deleting the account or by email. In the product, withdrawal is available in the app as a standalone action. If you do not have the app available, you may contact us at info@dia-log.sk; email is an additional contact path, not the normal product withdrawal mechanism.
7. Eligibility — health diary for adults
The DiaLog health diary is intended for people who attest that they are at least 18 years old.
This is a product eligibility rule, not the GDPR child-consent age threshold.
To use the health diary you must attest that you are at least 18 years old. Birth year in the profile is not authoritative proof of age and is not an authoritative health-consent field. Gender is also not an authoritative health-consent field.
If you declare that you are under 18, the health diary is unavailable. DiaLog does not provide parent or legal-representative consent. The account may remain even when the health diary is unavailable.
8. Withdrawing health-diary consent
Withdrawal of consent and account deletion are two different things. Withdrawal is a standalone in-app action and does not require account deletion.
After a valid withdrawal, the account remains. Active health-diary data covered by that consent are deleted from the active service (glucose, insulin, medication, HbA1c history, related notes, treatment catalogues, and diary settings). Height and weight in the profile are deleted. Other profile data (for example name, birth year, gender) may remain if they are not health-diary data.
Relevant health reminders are removed from the currently reconciled device. Creating and editing health-diary data are not allowed until you later grant valid consent again.
Before confirmation you may optionally export available health data if export is available. PDF export is not a condition of withdrawal.
Previously deleted data are not restored later. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
If the app cannot verify whether the server recorded the withdrawal, it must not treat the withdrawal as confirmed and will request verification again. Try again with a stable connection or write to us at info@dia-log.sk.
If the server has already authoritatively recorded the withdrawal, the withdrawal remains valid even when subsequent local device reconciliation is not yet complete. Active server-side health-diary data covered by the withdrawal have already been purged under the withdrawal transaction. Later failure of local or device cleanup does not reactivate consent. The affected device may temporarily retain DiaLog-owned local health artifacts until cleanup succeeds. New health writes remain blocked, and the app requires a retry of local cleanup or reconciliation. Later re-grant remains unavailable until the required reconciliation completes successfully.
9. Granting consent again
If you meet the eligibility rule, you may grant explicit health-diary consent again. Granting consent again is not restoration of old data.
After a new valid consent, new health-diary entries may become available again if the currently required privacy state is met. Previously deleted health-diary data are not restored. Old offline-queue items are not restored. Old reminders are not automatically carried over or restored merely because you granted consent again.
After a later grant, the diary starts empty. You may begin entering new data.
10. Deleting individual records
Where the product allows it, you may delete individual health-diary records without withdrawing consent as a whole.
Deleting one record and withdrawing consent are separate actions.
11. Account deletion
Account deletion is a broader action than withdrawal of consent. It is not the prescribed way to withdraw health-diary consent.
When an account is deleted, the active account and active data bound to the account are removed under the product deletion procedure, including health-diary and profile data, unless a legal, security, or technical obstacle prevents us from doing so.
How to delete an account: in the app, Settings → Account deletion → Delete account (signed-in user, online). Fallback: https://dia-log.sk/delete-account.html or email info@dia-log.sk.
Successful in-app account deletion is a product action, not waiting for a formal GDPR request deadline.
We do not promise immediate physical deletion from every disk, an immediate zero of residual backup copies, or deletion of detached minimum consent evidence while an authorised retention period or a valid legal hold still applies.
12. Offline mode and multiple devices
If you use DiaLog on more than one device, a device that is offline will not learn about a withdrawal performed elsewhere until it reconnects and receives the current state from the server.
After reconnection and reconciliation, local health data and related reminders on that device are cleaned according to the product procedure. Until then, the offline device may still contain older local data.
We do not claim that data disappear instantly from a device that is physically offline, or from external copies you have already exported or shared.
13. Retention
We distinguish four situations.
A. Active health diary
We retain active health-diary data while they are needed for the requested health-diary service and while a valid health-data processing state continues.
After withdrawal of consent, the active diary is deleted according to the withdrawal section. It is not the case that every health record is retained for 3 years. It is not the case that all of your data are automatically deleted exactly after 3 years.
B. Active account and non-health account data
We retain account data while the account is active and they are needed for the account service and applicable purposes, or until you delete the account.
C. Minimum detached consent evidence
After active processing ends (withdrawal of consent and/or account deletion), we may retain only the minimum evidence of the granting and withdrawal of consent and the related consent history.
This evidence is not your health diary and does not contain glucose measurements, insulin doses, medication records, diary notes, height, weight, or export. It exists so that we can demonstrate consent and accountability, demonstrate withdrawal and the relevant consent history, and where needed protect or pursue legal claims.
It is retained for at most 3 years from the moment it enters the detached retention period, under the published retention policy. These 3 years are an internal product retention decision. They are not a statutory period that the GDPR prescribes as exactly three years.
Authorised detached minimum evidence is deleted automatically after the retention period expires, unless a valid legal hold applies.
D. Backups
See the backups section.
14. Backups
After deletion from active systems, residual copies may temporarily remain in the provider’s backup systems.
Those copies disappear through the provider’s ordinary backup expiry or overwrite cycle.
We do not promise an exact backup duration or selective deletion from historical backups if that is not technically supported.
15. Processors and services
We use the following verified providers. We also use device operating-system services for local notifications, sharing an export, and secure local storage.
We do not use a verified Expo Push remote push-notification service. We do not use verified third-party mobile analytics. We do not sell personal data.
- Supabase — authentication and storage of account and health-diary data; the production database is in the eu-west-1 region (EU). The Supabase database project for the DiaLog app is configured in the eu-west-1 region (West EU – Ireland).
- Vercel — hosting of the public website dia-log.sk; ordinary hosting operational records.
- Vercel Web Analytics — optional website analytics, only if you enable it on the website.
- Google Fonts — delivery of fonts on the website.
- Google Play — distribution of the mobile app.
- Expo / EAS — development and building of the app; not health-diary storage in ordinary operation.
16. Transfers outside the European Economic Area
The main Supabase database is in the EU.
Some providers or their subprocessors may also process limited data outside the EEA (for example in connection with website hosting, fonts, app distribution, or development tools).
If such a transfer occurs, the transfer safeguards required by the GDPR must be used.
17. Analytics
Mobile app
The mobile app has no verified third-party analytics and no advertising profiling.
First-party operational records serve operation and security, not advertising.
Ordinary technical infrastructure records may exist. We do not claim that no technical server records arise.
Website dia-log.sk
The website uses Vercel Web Analytics for basic traffic statistics (for example page views and device type) only if you allow it in the cookie banner. The analytics script is loaded only after an explicit accept in the cookie banner. If you reject analytics or make no choice, the script is not loaded.
These data are not linked to the in-app account or the health diary. You may later change your choice via Privacy settings in the website footer.
Rejecting website analytics does not affect use of the mobile app.
We do not use Meta Pixel, Google Analytics, or similar advertising measurement unless we expressly add them and update this notice.
18. Reminders and notifications
Reminders are local notifications on the device. We do not use a remote Expo push service for health reminders.
If you turn on a more detailed display mode, a notification may contain the catalogue item name and the dose.
Reminders are not health advice and not a prompt to take a specific treatment action. You may turn them off at any time in the app or in the device settings.
19. Automated decision-making
DiaLog does not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
Charts, averages, and HbA1c estimates are informational diary aids, not such decisions.
20. Your rights
To the extent and under the conditions set by the GDPR, you have in particular the right of access to personal data, to rectification, to erasure, to restriction of processing, to data portability where applicable, to object to processing where applicable, to withdraw consent at any time where processing is based on consent, and to lodge a complaint with the competent supervisory authority.
Not every right applies unconditionally to every processing purpose.
We handle requests without undue delay, as a rule within one month. We extend the period only if the GDPR allows it. This request-handling period is not the same as the immediate effect of in-app withdrawal of consent.
Contact for exercising rights: info@dia-log.sk. The competent supervisory authority in the Slovak Republic is the Office for Personal Data Protection of the Slovak Republic (https://dataprotection.gov.sk).
- right of access to personal data,
- right to rectification,
- right to erasure,
- right to restriction of processing,
- right to data portability, where applicable,
- right to object to processing, where applicable,
- right to withdraw consent at any time where processing is based on consent,
- right to lodge a complaint with the competent supervisory authority.
21. Security
We use appropriate technical and organisational measures to protect personal data, in particular access bound to an authenticated account, record-level access restriction, private server-side privacy records that the app as an ordinary client does not access directly, and local storage on the device for offline use and the app lock.
If you turn on the app lock, the PIN may be stored in the device’s secure storage. Biometrics, if you use them, run in the device operating system. DiaLog does not store your biometric templates.
We do not promise absolute security. Protect your sign-in details, your device, and your email inbox.
22. Medical disclaimer
DiaLog is a personal health diary (glucose, treatment, history, charts, export, reminders).
Do not use DiaLog for diagnosis, a medical decision, emergency help, or to determine an insulin or medication dose. DiaLog is not a substitute for a healthcare professional.
For health questions, contact a doctor or another qualified healthcare professional.
23. Changes to this notice
We may update this notice and consent texts. A new version will be published in the app and/or on the website, with an effective date.
If a new mandatory text version takes effect, before the next health-diary write it may be necessary to acknowledge the privacy information, attest eligibility (at least 18 years old), and grant or renew explicit health-diary consent.
Until the required current state is met, adding and editing health-diary data are unavailable. The account is not cancelled by that fact.
24. Contact
Controller: ProNex Consulting s. r. o.
Registered office: Trieda KVP 1C, 040 23 Košice - Sídlisko KVP city district, Slovak Republic
Company ID (IČO): 56685530
Tax ID (DIČ): 2122420256
VAT ID (IČ DPH): SK2122420256, registration under § 7a of the Slovak VAT Act from 6 February 2025
Email: info@dia-log.sk
Website: dia-log.sk