DorfHealthSign in

Data privacy

Last updated: 31 August 2026

Dorf Health takes your privacy seriously. This Policy explains how we collect, use, share, and protect your personal and health data.

1. Who We Are

This Privacy Policy explains how Dorf Health, trading as Dorf (“Dorf”, “we”, “us”, “our”), collects, uses, shares, and protects information about you when you use our website, mobile application, and related services (together, the “Services”).

We are the data controller for the personal data described in this Policy, unless stated otherwise.

Contact for privacy matters: hello@dorf-health.com

2. Scope and Who This Policy Covers

This Policy applies to anyone who visits Dorf's website or app, creates an account, subscribes to our magazine or newsletter, or otherwise interacts with our Services, regardless of location. Because we serve users in the EU/EEA, UK, and other regions including the US, this Policy is written to meet GDPR as a baseline, with additional notices for UK and US (state-law) users where their rights differ. Where local law gives you stronger rights than described here, local law prevails.

3. Information We Collect

3.1 Information you give us directly

Account data: name, email address, username, password (hashed), date of birth, profile photo (optional).

Health and wellness data: information you choose to share such as symptoms, conditions, dietary preferences, mood or wellbeing logs, goals, or responses to in-app assessments or quizzes. This is “special category” / “sensitive” data under GDPR Art. 9 and receives extra protection (see Section 5).

Content you submit: comments, articles, community posts, reviews, or messages to our editorial or support team.

Subscription and payment data: billing name, billing address, and payment details — processed by our payment processor; we do not store full card numbers ourselves.

Communications: emails, support tickets, or survey responses you send us.

3.2 Information collected automatically

Device and usage data: IP address, browser type, device identifiers, operating system, pages viewed, referring URLs, and interaction timestamps.

App usage analytics: features used, session length, crash logs, and in-app navigation paths.

Location data: approximate location inferred from IP address; precise device location only if you separately grant permission.

Cookies and similar technologies: see Section 8 (Cookies).

3.3 Information from third parties

If you sign up or log in via a third-party account (e.g. Google or Apple sign-in), we receive basic profile information you authorise that provider to share.

Aggregated or de-identified data from analytics and advertising partners.

4. How We Use Your Information

We use personal data for the following purposes:

Providing, operating, and personalising the Services, including health/wellness content recommendations.

Creating and managing your account and subscription.

Processing payments and preventing fraud.

Sending service communications, newsletters, and — with your consent — marketing communications.

Improving and developing the Services, including through aggregated analytics.

Maintaining the security and integrity of our Services.

Complying with legal obligations and responding to lawful requests.

Editorial purposes — e.g. anonymised or aggregated user insights informing magazine content.

5. Our Legal Basis for Processing (GDPR)

Where GDPR applies, we rely on the following legal bases:

Contract (Art. 6(1)(b)): to create your account, deliver subscriptions, and provide the Services you request.

Consent (Art. 6(1)(a)): for marketing communications, optional cookies, and any processing of health/wellness data.

Legitimate interests (Art. 6(1)(f)): for core analytics, service security, and fraud prevention, balanced against your rights.

Legal obligation (Art. 6(1)(c)): for tax, accounting, and regulatory record-keeping.

Health and wellness data is “special category data” under Art. 9 GDPR. We process it only on the basis of your explicit, freely given, and specific consent (Art. 9(2)(a)), which you may withdraw at any time without affecting the lawfulness of processing before withdrawal. We do not condition access to core, non-health features on providing health data.

6. Who We Share Information With

We do not sell your personal data. We share information with:

Service providers / processors acting on our instructions, including: [Stripe] (payments), [Google Analytics] (usage analytics), [Mailchimp] (email/newsletter delivery), and hosting/infrastructure providers. Each is bound by a data processing agreement.

Professional advisers (legal, accounting) where necessary.

Regulators or authorities, where required by law.

A successor entity in the event of a merger, acquisition, or asset sale, subject to equivalent privacy protections.

We do not share health/wellness data with advertising or ad-tech partners, and we do not use it for interest-based advertising.

7. International Data Transfers

Some of our service providers (e.g. Stripe, Google Analytics, Mailchimp) process data outside the EEA/UK, including in the United States. Where we transfer personal data internationally, we rely on the EU Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, where relevant), adequacy decisions where available, or other lawful transfer mechanisms.

8. Cookies and Similar Technologies

We use cookies and similar technologies for: (a) strictly necessary functions (e.g. login, security); (b) analytics (e.g. Google Analytics); and (c) — only with your consent — marketing/personalisation. On first visit, EU/UK users are shown a cookie banner allowing acceptance or rejection of non-essential cookies before they are set, consistent with the ePrivacy Directive/GDPR. You can manage preferences at any time via your browser settings.

9. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy, including to meet legal, accounting, or reporting obligations. As a general framework:

Account data: retained while your account is active, plus 12 months after closure.

Health/wellness data: retained only while you actively use the relevant feature, or until you withdraw consent, deleted within 12 days thereafter.

Payment records: retained per statutory bookkeeping requirements (in Germany, generally 6–10 years under HGB/AO).

Marketing data: retained until you unsubscribe.

10. Your Rights

10.1 If you are in the EEA or UK (GDPR / UK GDPR)

You have the right to:

Access the personal data we hold about you.

Rectify inaccurate or incomplete data.

Erasure (“right to be forgotten”), subject to legal exceptions.

Restrict or object to processing, including processing based on legitimate interests.

Data portability, for data you provided under consent or contract.

Withdraw consent at any time, including for health/wellness data.

Lodge a complaint with your local supervisory authority.

10.2 If you are a US resident

Depending on your state of residence (e.g. California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws), you may have rights to know what personal data is collected, request deletion or correction, opt out of the sale or “sharing” of personal data and of targeted advertising, and not be discriminated against for exercising these rights. We do not sell personal data. Some states classify health-related data as “sensitive” and require opt-in consent before processing — consistent with our global approach in Section 5, we already obtain explicit consent for health/wellness data.

10.3 Exercising your rights

To exercise any right, contact us at hello@dorf-health.com. We will respond within the time limit required by applicable law (generally one month under GDPR, extendable by two further months for complex requests). We may need to verify your identity before actioning a request.

11. Children's Privacy

Our Services are not directed to children under 16 (or the applicable age of consent for information society services in your jurisdiction). We do not knowingly collect personal data, and in particular health data, from children below this age. If we become aware that we have done so, we will delete it promptly, unless the parent has confirmed and this has taken place under exceptional circumstances.

12. Data Security

We implement technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, and regular security review, with particular attention to the sensitivity of health/wellness data. No system is completely secure, and we cannot guarantee absolute security.

13. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required by Art. 33 GDPR, and will notify affected individuals without undue delay where the breach is likely to result in a high risk, per Art. 34 GDPR.

14. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes — particularly any change affecting how we use health/wellness data — will provide prominent notice and, where required, seek renewed consent.

15. Contact Us

Questions about this Policy or our data practices can be directed to:

Dorf Health Team

Email: hello@dorf-health.com

Responsible party:Natasha ThomsonContact:hello@dorf-health.com