Platform Privacy Notice
CalorieScience Nutrition Platform
Last updated: June 2026
1. Who We Are
CalorieScience provides a cloud-based nutrition platform used by professional nutritionists to manage their clients and deliver dietary guidance.
|
|
|
|
Legal entity |
CalorieScience Healthtech Private Limited (Pte Ltd) |
|
Registered office |
160 Robinson Road, #14-04 Singapore Business Federation Center, Singapore 068914 |
|
UK Representative (UK GDPR Art 27) |
DataRep (Data Protection Representative Limited) - UK contact location: 85 Great Portland Street, London, W1W 7LT, United Kingdom |
|
EU Representative (EU GDPR Art 27) |
DataRep (Data Protection Representative Limited), 77 Camden Street Lower, Dublin, D02 XE80, Ireland |
|
EU Digital Services Act representative (Art 13) |
DataRep (Data Protection Representative Limited), 77 Camden Street Lower, Dublin, D02 XE80, Ireland |
|
General contact |
info@caloriescience.ai |
|
Data Protection Officer |
Sunil R - sunil@caloriescience.ai |
|
Website |
https://www.caloriescience.ai |
2. Scope of This Notice
This notice applies to:
• Nutritionists who register for and use the CalorieScience platform
• Clients and patients whose personal data and health data are processed through the platform
• Other individuals who interact with platform-related services
This notice covers processing in connection with services offered in the United Kingdom and the European Union. It should be read alongside any privacy information provided by your nutritionist, who acts as the data controller for your health data.
3. Roles and Responsibilities
Understanding who is responsible for your data is important. The platform operates under a shared-responsibility model:
|
Role |
Who |
Responsible For |
|
Data Controller |
Your nutritionist |
Deciding why and how your health data is processed; obtaining your consent; providing you with privacy information; responding to your rights requests regarding your health data |
|
Data Processor |
CalorieScience |
Providing the technology platform and processing your health data on the instructions of your nutritionist; implementing technical and security measures to protect your data |
|
Data Controller (platform data) |
CalorieScience |
Nutritionist account information, billing and subscription records, platform security logs, service operations and diagnostics data, and support communications |
If you have questions about how your health data is used, you should contact your nutritionist in the first instance. For questions about how CalorieScience operates the platform, contact us at sunil@caloriescience.ai.
4. What Personal Data We Process
|
Category |
Examples |
Special Category? |
|
Identity data |
Name, date of birth, gender, age |
No |
|
Contact data |
Email address, phone number |
No |
|
Account credentials |
Username, hashed password, MFA tokens |
No |
|
Billing and subscription data |
Payment details, invoices, subscription plan |
No |
|
Health data |
Medical conditions, biomarkers (e.g. HbA1c, fasting glucose), physical symptoms, health questionnaire responses |
Yes - Art 9 GDPR |
|
Dietary information |
Dietary preferences, restrictions, allergens, meal logs, activity logs |
Yes - treated as health data where linked to health conditions |
|
Nutrition notes and meal plans |
Nutritionist notes, AI-assisted meal plans, dietary recommendations |
Yes - treated as health data |
|
Platform usage data |
Login records, feature usage, session data |
No |
|
Security and audit logs |
Access logs, authentication events, system events |
No |
|
Support communications |
Support tickets, correspondence with CalorieScience |
No |
5. How We Collect Your Data
We collect personal data from the following sources:
• Directly from you - when you create an account, complete health questionnaires, log meals, or communicate with us through the platform or support channels
• From your nutritionist - when your nutritionist enters or uploads information about you into the platform (e.g. biomarker data from uploaded lab reports, clinical notes, dietary assessments)
• Generated by the platform - through your use of the platform (login records, feature usage) and through AI-assisted analysis tools (nutritional suggestions, pattern identification)
• From payment providers - transaction confirmation data for billing purposes
6. Purposes and Lawful Bases
The following table sets out each purpose for which we process personal data, the lawful basis under Article 6 of the UK GDPR / EU GDPR, and where applicable the condition under Article 9 for processing special category (health) data.
|
Purpose |
What This Involves |
Lawful Basis (Art 6) |
Art 9 Condition (if applicable) |
|
Nutritionist account management |
Creating and maintaining nutritionist accounts, managing login credentials and profile settings |
Performance of contract - Art 6(1)(b) |
N/A |
|
Client onboarding |
Registering clients on the platform at the nutritionist’s instruction, storing identity and contact data |
Performance of contract - Art 6(1)(b) (between you and your nutritionist) |
N/A |
|
Client health data processing |
Storing and managing health records, biomarkers, clinical notes, questionnaire responses, and dietary information entered by or on behalf of the nutritionist |
Performance of contract - Art 6(1)(b) |
Provision of health or social care or treatment - Art 9(2)(h) (UK DPA 2018 Sch 1 Pt 1 §2; Appropriate Policy Document in place) |
|
Meal plan generation |
Using health parameters and dietary constraints to generate personalised meal plans, including AI-assisted suggestions |
Performance of contract - Art 6(1)(b) |
Provision of health or social care or treatment - Art 9(2)(h) |
|
AI nutritional analysis |
Analysing biomarkers, dietary patterns, and health conditions to provide nutritional insights and identify potential dietary adjustments |
Performance of contract - Art 6(1)(b) |
Art 9(2)(h) primary; Art 9(2)(a) explicit consent supplementary for the AI-assisted processing layer only |
|
Billing and subscriptions |
Processing subscription payments, generating invoices, managing payment records |
Performance of contract - Art 6(1)(b); Legal obligation - Art 6(1)(c) |
N/A |
|
Platform diagnostics and support |
Monitoring platform performance, resolving technical issues, providing user support, maintaining security logs |
Legitimate interests - Art 6(1)(f) |
N/A |
7. Health Data and Special Category Data
Health data, dietary information linked to health conditions, and nutrition notes constitute special category personal data under Article 9 of the UK GDPR and EU GDPR. Your nutritionist (the data controller) processes this data as part of the nutritional care they provide to you, under their professional duty of confidentiality. The platform applies the following framework:
• It is processed only on the documented instructions of your nutritionist (who is the data controller); CalorieScience and any sub-processor personnel who handle this data are bound by contractual confidentiality of an effect equivalent to professional secrecy (Article 9(3) UK/EU GDPR)
• The Article 9 condition relied on is Article 9(2)(h) UK/EU GDPR (provision of health or social care or treatment), supported - where you are in the United Kingdom - by Schedule 1 Part 1 paragraph 2 of the Data Protection Act 2018 and an Appropriate Policy Document maintained by CalorieScience
• Where your nutritionist enables AI-assisted features for your care, the AI-assisted processing layer is additionally supported by your explicit consent under Article 9(2)(a) UK/EU GDPR (see Section 8 and Section 14)
• Your underlying nutritional care does not depend on AI-features consent. If you do not give, or you withdraw, AI-features consent, your nutritionist can continue to provide services through the platform without using AI-assisted features
• Additional technical measures apply, including encryption at rest and in transit, access controls, data masking, and audit logging
8. AI-Assisted Processing
The platform includes AI-assisted tools that support nutritional analysis, dietary pattern identification, and meal-planning suggestions. Where your nutritionist enables AI-assisted features for your care, the AI-assisted processing layer relies on your explicit consent under Article 9(2)(a) UK/EU GDPR as a supplementary condition (in addition to the primary Article 9(2)(h) condition described in Section 7). You should be aware of the following:
|
Aspect |
Detail |
|
Purpose |
To assist your nutritionist with dietary analysis and meal plan suggestions - not to replace professional judgment |
|
How it works |
The AI processes health parameters (conditions, biomarkers, dietary constraints) against nutritional databases and clinical guidelines to suggest nutrient targets, identify gaps, and propose meal templates |
|
What data is sent to the AI |
De-identified health parameters only. Your name, contact details, and other direct identifiers are stripped before any data is sent to the AI provider |
|
Human oversight |
All AI outputs must be reviewed, validated, and approved by your nutritionist before they are made available to you. The AI cannot independently alter your dietary plan or provide advice directly to you |
|
Safety constraints |
The AI enforces hard constraints including allergen blocking and condition-specific nutrient limits (e.g. renal-safe, low-FODMAP) |
|
Data retention by AI provider |
The AI provider operates under enterprise terms with zero data retention - your data is not stored or used for model training by the AI provider |
|
Your right to object |
You may ask your nutritionist not to use AI-assisted features for your care. Your nutritionist can provide services without AI assistance. |
For further detail, see our Statement of AI Transparency, available on request.
9. Who We Share Data With
|
Recipient |
Purpose |
Location |
Safeguards |
|
AWS (Amazon Web Services) |
Hosting infrastructure, storage, key management |
Frankfurt, Germany |
Standard AWS DPA; data remains in Frankfurt |
|
MongoDB Atlas |
Database services (dedicated tier) |
Frankfurt, Germany |
Standard MongoDB DPA; PrivateLink (no public endpoint) |
|
Stripe |
Payment processing |
Global / US |
Stripe DPA with SCCs; PCI-DSS certified |
|
Google Vertex AI (Google Cloud EMEA Limited) |
AI-assisted nutritional analysis and meal planning |
European Union (Frankfurt / Google Cloud europe regions) |
Google Cloud DPA (EU SCCs + UK IDTA) with zero-data-retention terms; PII stripping before API calls |
|
CalorieScience engineering and support (India) |
Technical support, platform maintenance |
India |
AWS Session Manager access only; data masking; session logging; no local download; transfer mechanism required |
We do not sell your personal data. We do not share your health data with any third party for their own purposes. Data is shared only to the extent necessary to operate the platform and provide the services described above.
10. International Transfers
CalorieScience operates through a Singapore contracting entity and may involve access by engineering or support personnel located in India.
Your data is stored in Frankfurt, Germany, which is within the EEA. But where India-based personnel access data for support or engineering purposes, this may constitute a restricted transfer under the UK GDPR or EU GDPR.
Where restricted transfers occur, the following safeguards apply or will apply:
• For UK data subjects: the UK International Data Transfer Addendum (IDTA) or UK Addendum to the EU SCCs
• For EU/EEA data subjects: the EU Standard Contractual Clauses (SCCs), Module 2 (Controller to Processor)
• A Transfer Impact Assessment has been conducted for the India access path
• Supplementary technical measures include encryption, AWS Session Manager access controls (no local download), data masking, and session logging
11. How Long We Keep Your Data
We retain personal data only for as long as necessary for the purposes described in this notice, or as required by law. The specific retention periods are:
|
Data Category |
Retention Period |
Basis |
|
Nutritionist account profile |
Active period + 90 days after account closure |
Contract performance; reasonable wind-down period |
|
Client health records, meal plans, questionnaire responses, nutrition notes, messages |
7 years after last interaction, or an alternative duration configured by the Practitioner in line with national law. |
Clinical record-keeping norms; potential professional liability claims |
|
Minor records (where age is known) |
Until age 25 or 7 years after last interaction, whichever is later (or an alternative duration configured by the Practitioner in line with national law). |
Extended limitation period for minors |
|
Billing and invoice records |
7 years from financial year-end |
Legal obligation (accounting and tax requirements) |
|
Authentication and security logs |
12 months |
Security monitoring and incident investigation |
|
Application logs |
90 days |
Operational diagnostics |
|
Support tickets |
24 months after closure |
Service quality and dispute resolution |
|
Backups |
35-day rolling retention, overwritten on rotation |
Disaster recovery; backups are encrypted and overwritten automatically |
|
Encryption keys |
Retained as long as the encrypted data they protect is retained |
Necessary for data accessibility |
When the retention period expires, personal data is securely deleted or anonymised. Where data is held in encrypted backups, the backup overwrite cycle (35 days) ensures data is removed within the next rotation period.
12. Your Rights
Under the UK GDPR and EU GDPR, you have the following rights. Some of these rights apply only in certain circumstances and may be subject to limitations.
|
Right |
What This Means |
How to Exercise |
|
Right of access (Art 15) |
You can ask for a copy of the personal data we hold about you, together with information about how it is processed. |
Contact your nutritionist for health data (they are the controller). Contact sunil@caloriescience.ai for platform/account data. |
|
Right to rectification (Art 16) |
If your personal data is inaccurate or incomplete, you can ask for it to be corrected or completed. |
Contact your nutritionist or update your profile directly in the platform. |
|
Right to erasure (Art 17) |
In certain circumstances, you can ask for your personal data to be deleted. This right is not absolute and may be limited by legal obligations or legitimate grounds for continued processing. |
Contact your nutritionist for health data. Contact sunil@caloriescience.ai for platform data. |
|
Right to restrict processing (Art 18) |
You can ask us to temporarily stop processing your data in certain situations, for example while we verify accuracy or assess an objection. |
Contact sunil@caloriescience.ai |
|
Right to data portability (Art 20) |
Where processing is based on consent and carried out by automated means, you can request your data in a structured, commonly used, machine-readable format. |
Contact your nutritionist or sunil@caloriescience.ai |
|
Right to object (Art 21) |
Where processing is based on legitimate interests, you can object. We will stop processing unless we can demonstrate compelling legitimate grounds. |
Contact sunil@caloriescience.ai |
|
Right to withdraw consent |
Where processing is based on your consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. |
Use the consent management feature in the platform, or contact your nutritionist. |
|
Right not to be subject to solely automated decisions (Art 22) |
You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. CalorieScience does not make such decisions - all AI outputs require human review by your nutritionist. |
Contact sunil@caloriescience.ai if you have concerns. |
We will respond to valid requests within one month. In complex cases, this may be extended by a further two months, in which case we will inform you of the extension and the reasons for it. There is no charge for exercising your rights.
13. How to Make a Request or Complaint
To exercise your rights or raise a concern:
• For health data: contact your nutritionist, who is the data controller
• For platform and account data: contact our DPO at sunil@caloriescience.ai
• General enquiries: info@caloriescience.ai
If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority:
|
Jurisdiction |
Authority |
Contact |
|
United Kingdom |
Information Commissioner’s Office (ICO) |
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF |
|
European Union |
The supervisory authority in your EU member state of residence |
A list of EU data protection authorities is available at: |
14. Consent and Withdrawal
Where AI-assisted features are enabled for your care, the AI-assisted processing layer relies on your explicit consent under Article 9(2)(a) UK/EU GDPR as a supplementary condition. You can withdraw your AI-features consent at any time. Withdrawal of AI-features consent stops AI-assisted processing for your care; it does not stop the underlying nutritional care, which continues under Article 9(2)(h). Withdrawal is as easy as giving consent:
• Use the consent management feature in the platform
• Contact your nutritionist directly
• Contact us at sunil@caloriescience.ai
Withdrawing AI-features consent does not affect the lawfulness of AI-assisted processing carried out before withdrawal. Your nutritionist can continue to provide nutritional care through the platform without AI-assisted features.
15. Children and Minors
The platform may be used by nutritionists who serve clients under the age of 18. In those circumstances:
• The nutritionist (as data controller) is responsible for obtaining appropriate consent from a parent or guardian where required
• Minor records are retained under the extended retention rule: until the individual reaches age 25 or 7 years after the last interaction, whichever is later
• CalorieScience does not offer information society services directly to children under the meaning of Article 8 UK/EU GDPR. Any personal data relating to minors is entered and maintained on the platform by the nutritionist, who, as the controller, is responsible for obtaining verifiable parental consent where required under Article 8 and applicable national age-of-consent rules (13–16, depending on Member State).
16. Security
We take the security of your data seriously. Key measures include:
• Encryption at rest (AES-256) and in transit (TLS 1.2+)
• Multi-factor authentication for all administrative and production access
• Role-based access control with least-privilege principles
• Data masking by default on support dashboards
• Immutable audit logging of all data access
• No local storage of data on devices outside the hosting environment
• Regular vulnerability scanning and dependency patching
• Penetration testing prior to production launch
For more detail, see our Security and Vendor Baseline document, available on request.
17. Changes to This Notice
We may update this notice to reflect changes in our platform, services, processing activities, or legal requirements. When we make changes, we will update the "Last updated" date at the top of this notice. Where changes are significant, we will take reasonable steps to notify you (for example, through the platform interface or by email).