Privacy Statement
Yehu Health B.V. (“Yehu”, “we”, “us”, “our”) respects your privacy and handles your personal data with care, in line with the EU General Data Protection Regulation (GDPR) and the Dutch implementation act (UAVG). This statement explains what we collect, why, who we share it with, and the rights you have.
1. Who we are (data controller)
Yehu Health B.V. is the controller responsible for your personal data. We are a private limited company registered in Dordrecht, the Netherlands. For any privacy question or request, contact us atmike@yehu.health — please include “Privacy Request” in the subject line so we can route it quickly.
2. Data we collect
2.1 Website — waitlist & reservations
- Email address when you join the waitlist or reserve a spot.
- Reservation & payment data when you place a refundable founding-member deposit: your email, the amount paid, and payment/transaction identifiers. Card details are entered directly with our payment processor (Stripe) and are never received or stored by Yehu.
2.2 Website — partner programme
- When you apply as a partner (e.g. a doula), the details you submit:email, and optionally your name, practice, location, message and language preference.
2.3 Correspondence & technical data
- Correspondence. If you email us, we keep your message and contact details so we can reply.
- Technical/usage data. Our hosting and infrastructure providers automatically process limited technical information (such as IP address, browser type and request logs) to serve and secure the site.
- Cookies. The website sets a single functional cookie (
yehu_locale) to remember your language choice. See section 6.
2.4 App — health & account data when you use the app
Through integrations you authorise, the Yehu app processes:
- CGM data: continuous glucose readings, trends and related metrics from Freestyle Libre or other compatible CGM devices.
- Account information: email, name (if provided), profile and preferences.
- Technical information: device identifiers, app usage analytics, error logs and diagnostics.
Health and biometric data are a special category of personal data under the GDPR and receive additional protection — we process them only with your explicit consent.
3. How we collect it
- Directly from you — forms on the website, and entries or notes you make in the app.
- Via Stripe — when you complete a reservation checkout, we receive confirmation and limited payment metadata from Stripe (not your card number).
- From your CGM provider (app only) — when you connect a device, you authenticate directly with your CGM provider, which passes your glucose data to the app. Your CGM login credentials are never stored or accessed by Yehu.
4. Why we use it, and our legal bases
We process your data for these purposes, on the GDPR legal bases shown:
- Manage your waitlist spot, reservation or partner application — performance of a contract, or steps taken at your request prior to a contract (Art. 6(1)(b)).
- Contact you about Yehu, your reservation, your application, and our launch — consent, or our legitimate interest in responding to you (Art. 6(1)(a)/(f)).
- Provide app functionality & insights — displaying and analysing your glucose, recovery and other health data — on your explicit consent (Art. 6(1)(a) + Art. 9(2)(a)).
- Operate, secure and improve our website and app — legitimate interest (Art. 6(1)(f)).
- Comply with legal obligations — e.g. tax and accounting for payments (Art. 6(1)(c)).
Where we rely on consent, you can withdraw it at any time (see section 8); this does not affect processing already carried out.
5. Who we share it with
We do not sell, rent or trade your personal data. We share it only with service providers (“processors”) that help us run Yehu, under data processing agreements and only for the purposes we specify:
- Stripe — payment processing for reservations.
- Supabase — our cloud database (PostgreSQL) storing waitlist, reservation, partner-application and app data.
- Resend — sending transactional email (reservation confirmations, magic links, notifications).
- Vercel — website and API hosting.
- Your CGM provider — when you authorise the connection, it provides your glucose data to the app (app only).
We may also disclose data where required by law, court order or regulation, or to protect our rights, prevent fraud or abuse, or protect user safety.
6. Cookies
The website uses one functional cookie, yehu_locale, to remember your selected language. It is strictly necessary for that feature and is not used for advertising or cross-site tracking. We do not currently run third-party advertising or analytics cookies on the website; if that changes, we will update this statement and request consent where required.
7. Storage, security & retention
Your data is stored using Supabase and our other processors, with encryption in transit (HTTPS/TLS) and at rest, access controls, token-based API authentication, and limited staff access (only when needed for support or technical issues).
How long we keep it. We retain personal data only for as long as needed for the purposes above or as the law requires. Waitlist and partner-application data are kept while we are in contact with you about the programme; reservation and payment records are kept for the period required by Dutch tax law. App account and health data are kept while your account is active; when you delete your account we delete or anonymise your personal data within 90 days, except where retention is legally required.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to our processing;
- receive your data in a portable format;
- withdraw consent at any time (including by disconnecting app integrations or deleting your account).
To exercise any of these, emailmike@yehu.health. We aim to respond within one month. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens(autoriteitpersoonsgegevens.nl).
9. International data transfers
Some of our processors may store or process data outside the European Economic Area. Where that happens, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses — to protect your data to an equivalent standard.
10. Children
Yehu is not intended for children. In the Netherlands, the age of digital consent is 16; we do not knowingly collect data from anyone under that age (or the applicable age in your jurisdiction). If you believe a child has provided us data, contact us and we will delete it.
11. California residents (CCPA)
If you are a California resident, you also have the right to know what personal information is collected, used and shared; to request deletion; to opt out of any “sale” of personal information (we do not sell it); and to non-discrimination for exercising these rights.
12. HIPAA
Yehu is not a “covered entity” under the U.S. Health Insurance Portability and Accountability Act (HIPAA). We nonetheless protect your health data with a high standard of care. Data from your CGM provider is also governed by their own privacy policy.
13. Changes to this statement
We may update this statement from time to time. The date at the top shows when it was last revised, and we will communicate material changes where appropriate (for example by email or an in-app notice).
14. Contact
Yehu Health B.V., Dordrecht, the Netherlands.
Privacy contact: mike@yehu.health