1. Who we are and what this policy covers
Health Compass For You ("we", "us", "our") operates the website at healthcompassforyou.com — an independent, medically reviewed health library published in English, German, French and Dutch.
For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for the personal data described in this policy. You can reach us at any time at privacy@healthcompassforyou.com, or through the support page if you have an account.
This policy explains what personal data we collect when you use this website, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It applies to every language version of this site.
2. The short version
We have tried to keep this policy readable. If you only read one section, read this one.
- We collect as little as we can. You can read most of this library without giving us anything at all.
- We only ask for an email address and password when you choose to create a free account.
- We never sell your personal data, and we do not run advertising networks or third-party ad trackers on this site.
- We only send you marketing email if you explicitly opted in, and you can withdraw that at any time in one click.
- We do not ask for, and do not want, your medical history. Reading an article is not a medical record.
- You can request a copy of your data, correct it, or have it deleted, at any time, free of charge.
3. The data we collect
Account data. When you create a free account we store your email address, a securely hashed version of your password (we never see or store the password itself), your display name if you provide one, your preferred language, and your country if you select one. If you sign in with Google, we receive your email address and name from Google instead of a password.
Consent records. If you tick the newsletter box at signup, we store the fact that you consented, the date and time, and the exact wording you agreed to. We are legally required to be able to prove consent, which is why this record exists.
Support messages. If you contact us through the support page, we store your message, our replies, and the ticket status, so the conversation is still there when you come back.
Interaction data. We store an anonymous, randomly generated identifier in your browser's local storage so that liking an article works and so a single visitor is not counted twice in an article's view count. This identifier is not linked to your name or email address and cannot be used to identify you.
Technical data. Like every website, our hosting infrastructure automatically processes your IP address and browser user-agent in order to deliver pages to you and to protect the site against abuse and attacks. This data is handled by our hosting provider and is not used by us to build profiles of individual readers.
What we do not collect. We do not collect your medical history, symptoms, diagnoses, prescriptions, or any other health information about you. We do not ask for your date of birth, postal address, phone number, or payment details, because we do not need them.
4. Why we process your data, and our legal basis
Under the GDPR, every use of personal data needs a legal basis. Here is ours, purpose by purpose.
- To provide your account and give you access to the full library — legal basis: performance of a contract (GDPR Art. 6(1)(b)). Without an email address and password we cannot create an account or let you sign back into it.
- To answer your support messages — legal basis: performance of a contract and our legitimate interest (Art. 6(1)(b) and 6(1)(f)) in providing a functioning service to our readers.
- To send you our health newsletter and information about partner services — legal basis: your consent (Art. 6(1)(a)). This is entirely optional, is never bundled into account creation, and can be withdrawn at any time without affecting your account.
- To keep article view and like counts accurate — legal basis: legitimate interest (Art. 6(1)(f)) in understanding which topics readers find useful, using anonymous identifiers rather than personal profiles.
- To keep the site secure, available, and free of abuse — legal basis: legitimate interest (Art. 6(1)(f)) in protecting our infrastructure and our readers.
- To comply with legal obligations — legal basis: legal obligation (Art. 6(1)(c)), for example keeping consent records or responding to a lawful request from a supervisory authority.
Where we rely on legitimate interest, we have weighed our interest against your rights and freedoms, and we have limited what we process accordingly. You can object to that processing at any time — see section 9.
5. Cookies and similar technologies
We keep this deliberately minimal.
- Strictly necessary cookies. When you log in, our authentication provider sets a session cookie so that you stay logged in as you move between pages. Without it, accounts cannot work. These cookies do not track you across other websites.
- Language preference. Your chosen language is reflected in the page address (for example
/de/or/fr/), so we do not need a tracking cookie to remember it. - Local storage. As described in section 3, an anonymous random identifier is stored in your browser so that likes and view counts behave correctly. You can clear it at any time by clearing your browser's site data.
- No advertising trackers. We do not embed third-party advertising pixels, social media tracking scripts, or cross-site behavioural advertising networks.
6. Service providers who process data for us
We use a small number of specialist providers to run this website. Each of them acts as a processor on our instructions, under a data processing agreement, and may only use the data to provide their service to us.
- Supabase — database, authentication, and file storage. Stores account data, consent records, and support messages.
- Vercel — website hosting and content delivery. Processes technical connection data in order to serve pages.
- DeepL — machine translation of our published articles and legal pages into German, French and Dutch. Only editorial content is sent to DeepL, never your personal data.
- Email delivery provider — used to send transactional email (such as password reset links) and, if you opted in, our newsletter.
If we add or change a provider in a way that affects your personal data, we will update this section and, where the change is significant, the "last updated" date at the top of this page.
We do not sell, rent, or trade your personal data to anyone, and we do not share it with third parties for their own marketing purposes.
7. Where your data is stored, and international transfers
We ask our providers to store personal data on servers located in the European Union or the European Economic Area wherever that option is available.
Some of our providers are established outside the EEA. Where personal data is transferred outside the EEA, that transfer takes place on the basis of an adequacy decision by the European Commission, or, where no adequacy decision applies, on the basis of the European Commission's Standard Contractual Clauses together with additional safeguards such as encryption in transit and at rest. You can ask us for more detail about a specific transfer at privacy@healthcompassforyou.com.
8. How long we keep your data
- Account data — for as long as your account exists. If you delete your account, we delete the associated personal data within 30 days, except where we are legally required to keep something longer.
- Consent records — for as long as the consent is active, and then for a limited period afterwards so that we can demonstrate that consent was validly obtained and later withdrawn.
- Support conversations — up to 24 months after the ticket is closed, so we have context if you contact us again about the same issue.
- Anonymous interaction identifiers — these are not personal data once separated from your browser, and are not retained in an identifiable form.
- Server and security logs — kept by our hosting provider for a short retention window and then automatically deleted.
9. Your rights under the GDPR
You have the following rights over your personal data. All of them are free to exercise, and we will respond within one month of receiving your request.
- Right of access — obtain confirmation of whether we process your data, and receive a copy of it.
- Right to rectification — have inaccurate data corrected and incomplete data completed.
- Right to erasure ("right to be forgotten") — have your data deleted where there is no overriding reason for us to keep it.
- Right to restriction of processing — ask us to pause processing while a dispute about accuracy or legitimacy is resolved.
- Right to data portability — receive the data you gave us in a structured, commonly used, machine-readable format.
- Right to object — object to processing based on legitimate interest, and object at any time to direct marketing.
- Right to withdraw consent — withdraw consent for anything based on consent, such as the newsletter, at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
- Right not to be subject to automated decision-making — see section 14; we do not carry out automated decision-making with legal effects.
To exercise any of these rights, email privacy@healthcompassforyou.com or open a ticket on the support page. We may ask you to confirm your identity before acting on a request, in order to protect your data from someone else impersonating you.
Right to complain. If you believe we have handled your data unlawfully, we would like the chance to put it right first. You also have the right to lodge a complaint directly with the data protection supervisory authority in the EU or EEA country where you live, work, or where the alleged infringement took place.
10. Marketing and the newsletter
Our newsletter is strictly opt-in. We will only email you marketing content if you actively ticked the consent box, and the box is never pre-ticked.
If you opted in, you agreed to receive a health newsletter and information about specialised medical services from trusted partners. We do not hand your email address to those partners — where partner information is included, we send it ourselves from our own mailing list.
Every marketing email contains a one-click unsubscribe link. You can also withdraw consent by emailing us. Withdrawing marketing consent never affects your account or your access to the library.
11. A note about health data
Health data is a special category of personal data under GDPR Art. 9 and deserves particular care. Our position is simple:
- We do not ask you to tell us about your health, symptoms, or medical history, and we ask that you do not include such details in support messages.
- We do not build health profiles of readers, and we do not infer health conditions from the articles you read in order to target you.
- The articles you read are not stored against your account as a browsing history.
If you voluntarily send us health information anyway — for example in a support message — we will only use it to answer you, and we will delete it in line with section 8.
12. Children and young people
This website is intended for readers aged 16 and over. We do not knowingly create accounts for children under 16, and we do not knowingly collect their personal data. If you believe a child under 16 has created an account, contact us and we will delete it and the associated data promptly.
13. How we protect your data
We apply technical and organisational measures appropriate to the risk, including:
- Encryption in transit — the entire site is served over HTTPS/TLS.
- Password hashing — passwords are stored only as salted cryptographic hashes and are never recoverable, even by us.
- Row-level access control — our database is configured so that one account cannot read another account's data.
- Least privilege — administrative credentials are restricted to a small number of accounts and are never exposed to your browser.
- Data minimisation — the strongest protection is not holding data we do not need in the first place.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform you without undue delay where the law requires it.
14. Automated decision-making and profiling
We do not make decisions about you based solely on automated processing that produce legal effects or otherwise significantly affect you. We do not carry out behavioural profiling for advertising purposes.
We do use machine translation (see section 6) to produce the German, French and Dutch versions of our editorial content. That process handles article text, not your personal data.
15. Changes to this policy
We may update this policy as the site develops or as the law changes. The date at the top of this page always shows when the current version took effect.
If we make a change that materially affects how we use your personal data, we will take reasonable steps to inform you — for example by email or a notice on the site — before the change takes effect. Continuing to use the site after a change means you accept the updated policy.
16. How to contact us
For any question about this policy, or to exercise any of your rights:
- Email: privacy@healthcompassforyou.com
- Support page: open a ticket at /support and we will reply in the same thread
- General enquiries: support@healthcompassforyou.com
We read every message, and a real person will answer you.
