Privacy Statement

ABOUT THIS PRIVACY STATEMENT

At Zest, we take the protection of your personal data seriously. This privacy statement applies to processing of personal data by Zest Longevity LTD.

Our products, like the Mobile Application, enable you to track your lifestyle choices and longevity focused interventions. We understand that data does not get much more personal than this, and the protection of your personal data is of paramount importance to us. Please take a moment to carefully review this statement.

PROCESSING PURPOSES

Zest collects and processes the personal data of Users only for the following purposes:

To provide Zest services

  • We process personal data to provide Zest services and app features, such as to provide you with daily insights about your longevity-focused lifestyle interventions.

To provide customer service

  • We process personal data for the purpose of providing customer service and managing our customer communication. If you contact our support with questions regarding your app data, we may use the provided information to answer your questions and for solving any issues you may have.

To develop our products and services

  • We process data regarding your use of the Zest platform to improve our services and features, such as in the Zest app. When possible, we will do this using only pseudonymized, aggregated, or non-personally identifiable data.

To market our products and services

  • We process marketing-related data to provide online advertising and Zest marketing communications. For example, as explained more fully in our Cookie Policy, we use cookies on our website in order to create targeted audiences for online advertisement. You can always opt out of marketing communications, and we will only send you our newsletter if you have requested it.

To enable third party integrations

  • We process data to provide Users who request that we share their data with certain third parties, such as research partners. This is only done with your express consent.

To comply with statutory obligations

  • In certain cases, we must process certain data when it is required by applicable laws and regulations. Such statutory obligations are related, for example, to accounting and tax requirements, legal claims, or other legal purposes.

LEGAL BASIS FOR PROCESSING

Data protection law in Europe requires a "lawful basis" for collecting and retaining personal information from residents of the European Economic Area. Our lawful bases for processing your data depends on the particular processing purposes, including:

Contract: when processing personal data for the purpose of providing Zest services we process it on the basis of a user contract, which is formed when you create your account and accept of our terms and conditions.

Consent: we process your health-related data only with your consent. In some cases, you can provide your consent to us for processing your data through your actions, such as by inserting health data into your notes, or by adding health related tags in the Zest app.

Legitimate Interest: we process your personal data based on our legitimate interests when we process it for the purposes of marketing our products and services, providing our customer service and improving our products and services. When choosing to use your data on the basis of our legitimate interests, we carefully weigh our own interests against your right to privacy, in compliance with applicable law.

Legal obligation: Zest must process certain information to comply with statutory obligations which may vary in each country. For example, such obligations can relate to consumer protection or tax laws.

PROCESSED DATA AND DATA SOURCE

In most cases, Zest collects personal data directly from you, such as when you register for an account or use your wearables to collect measurement data via the tracking functions of the Zest app. We may also process data that is produced from the information you provide to us.

Zest processes the following personal data categories about device and application Users:

  • Contact information such as email address or country of residence
  • User information such as gender, height and weight, User ID, and other information you may provide to us about yourself or your account
  • Device information such as IP address and location data
  • User activity and context information such as activities, notes and tags
  • Measurement data such as heart rate, movement data, and temperature data
  • Calculated user, sleep and activity data, such as sleep phases (deep, light, REM, awake), activity levels throughout the day, readiness level, body mass index (calculated based on height and weight).

Please note that some of the personal data we process, including any data concerning your health, is considered special or sensitive personal data. Under applicable law, such data is processed only if you have given your consent for processing. If you access or use any of Zest’s location-based services, such as by enabling GPS-based activity tracking through your app, Zest may process the approximate or precise location of your device while the service is active. This data may be obtained via your device's service provider network ID, GPS, and/or Wi-Fi data. Zest does not process such location data without first obtaining your consent. You may disable such location processing at any time using your device's location permission settings.

PERSONAL DATA SHARING

Zest does not and will never share your personal information with third party organisations without your explicit consent. The only exception to this is the use of anonymised and deidentified data for research purposes. In this case, we require any partner research organisations or service providers to protect your personal information to at least the same standards that we do.

Zest stores personal data on secure cloud-based servers and we always ensure your personal data is protected with appropriate safeguards in accordance with applicable privacy laws. We also use industry standard data protection measures to safeguard all international transfers of personal data through data protection agreements with our service providers.

Personal Data Disclosures

We also reserve the right to disclose personal information under certain specific circumstances, including:

  • When we have your express consent to do so;
  • When it is reasonably necessary for our legitimate interests in conducting our business, such as in the event a merger, acquisition, or sale;
  • To protect Zest’s legal rights and property; and
  • To comply with valid legal requirements. Zest will oppose any request to provide legal authorities with access to user data for surveillance or prosecution purposes, and will notify users if we receive any such request.

Otherwise, your personal information is never shared with any individual or other organization.

SAFEGUARDING YOUR DATA

Zest uses technical and organizational safeguards to keep your data safe and secure. These safeguards include measures such as anonymization or pseudonymization of personal data, strict access control, and the use of encryption to protect the data we process.

We also ensure that our staff receives adequate training to ensure personal data is processed only in accordance with our internal policies, consistent with our obligations under applicable law. We also limit access to your sensitive personal data to personnel that have specifically been granted such access.

Online services that we provide, such as the Zest online store and Zest on the Web, protect your personal data in-transit using encryption and other security measures. We also regularly test our service, systems, and other assets for possible security vulnerabilities.

We update the Zest firmware regularly. We recommend that you make sure that you always have the latest app version installed in order to maximize protection of your data.

DATA RETENTION

Your personal data is retained for the duration of your subscription with Zest. If your subscription is no longer active, your personal data will be fully anonymised, deidentified, and stored for potential use in future scientific research. If you do not wish your data to be used for this purpose, you can contact us at the time of the end of your subscription, and we can remove your data from our database. After the process of anonymisation, we will no longer be able to identify your data, and so cannot remove it from the database after this time.

Zest also has legal obligations to retain certain personal data for a specific period of time, such as for tax purposes. These required retention periods may include, for example, accounting and tax requirements, legal claims, or for any other legal purposes. Please note that obligatory retention periods for personal data vary based on the relevant law.

YOUR RIGHTS AS A DATA SUBJECT

Whenever Zest processes your data, you have certain rights that enable you to control how your personal data is being processed. This section provides you with information about each of those rights.

Right to access data

You have the right to know what personal data is processed about you. You may contact us to request access to the personal data we have collected about you, and we will confirm whether we are processing your data, and provide you with information about the personal data we have collected and processed about you.

Please note that by using the Zest App, you can easily access the sleep, readiness and activity data that we process about you.

Right to erasure

You have the right to request the deletion of your personal data in certain circumstances. We will comply with such requests unless we have a valid legal basis or legal obligation to preserve the data

Right to rectification (of inaccurate data)

You have the right to request correction of any incorrect or incomplete personal data we have stored about you.

Right to data portability

You have the right to request receipt of the personal data you have provided to us in a structured and commonly used format. The right to data portability only applies when we process your personal data for certain reasons, such as by contract or by your consent.

Right to object to processing

You have the right to object to the processing of your personal data under certain circumstances. In the event that we do not have legitimate grounds to continue processing such personal data, we will no longer process your personal data after we have received and verified your objection. You also have the right to object processing of your personal data for direct marketing purposes at any time.

Right to restrict processing

You have the right to request that we restrict processing of your personal data under certain circumstances. For example, if you contest the accuracy of your data, you can make a restriction request that we do not process your data until Zest has verified the accuracy of your data.

Right to withdraw consent

If we have requested your consent in order to process your personal data, you have the right to withdraw your consent for such processing at any time. It should be noted, however, that withdrawing your consent may lead to issues or restrictions on your ability to fully utilize Zest services.

Please note that you can always unsubscribe from receiving our newsletter and other marketing emails by using the ‘Unsubscribe'-link provided in the emails you receive from us.