← Back to Legal Documents

Health Data Processing Notice

Version: 1.0.0 | Effective Date: 2025-01-01 | Document Status: Standalone | Governing Law: EU GDPR (Lithuania), global applicability | Contact: legal@motiw8.com

1. Introduction

This Health Data Processing Notice ("Notice") supplements the Motiw8 Privacy Policy and explains in full detail how Motiw8 UAB ("we", "us") processes health-related data, including:

Under the GDPR, this data is classified as Special Category Personal Data (Article 9), subject to enhanced protection and explicit consent. This document expands on the Privacy Policy and provides transparency into every aspect of processing.


2. Categories of Health Data We Collect

2.1 Data Users Provide Directly

2.2 Data From Device Integrations

Apple HealthKit (iOS)

If the user grants permission, we collect:

HealthKit permissions are granular and controlled by the user.

HealthKit data never leaves the device unless explicitly approved by the user.

Google Fit (Android)

If user consents, we collect:

Wearables / Integrations

If user connects:

We may receive:

2.3 Derived Data

We also create derived health data:

This data is mathematically derived from raw health data and still considered health data under GDPR.


3. Purposes of Processing Health Data

Each purpose below is a direct expansion of what appears in your Privacy Policy.

3.1 Challenge Participation (Primary Purpose)

Health data is necessary to:

This is contractual necessity (GDPR Art. 6(1)(b)) and requires explicit consent (Art. 9(2)(a)).

3.2 Fair Play & Integrity

We use health data to:

3.3 Syncing With Health & Fitness Providers

We process synced data to:

3.4 Analytics (Strictly Aggregated/Anonymous)

We may use anonymized, aggregated data to:

No identifiable health data is used for analytics.

3.5 Dispute Handling

If a user disputes results:

3.6 Safety & Abuse Prevention

Health data helps detect:

3.7 Laboratory Verification for Premium Challenges

For premium challenges requiring lab documents, we process health data to:

The scope of this processing is limited to verification purposes only. We do not request broader medical records or any information beyond what is necessary to confirm the authenticity and identity verification of the submitted document.


4. Legal Basis for Processing

4.1 Explicit Consent (GDPR Art. 9(2)(a))

You provide explicit consent before:

For lab documents: Uploading lab documents containing body fat % test results requires explicit consent before submission. This consent must be:

Consent can be withdrawn anytime. However, withdrawing consent for lab document processing may make verification impossible and may result in disqualification from the challenge.

4.2 Contract (GDPR Art. 6(1)(b))

To participate in challenges, certain health data is required.

4.3 Legitimate Interests (GDPR Art. 6(1)(f))

For:

This does not override user fundamental rights.


5. How Health Data Is Stored

5.1 Storage Infrastructure

Health data is stored in:

5.2 Security


6. Data Retention Policy for Health Data

This expands the retention periods from the main Privacy Policy.

Data Type Retention Reason
Health metrics Until account deletion Needed for challenge history
Steps history Until deletion Required for integrity
Weight history Until deletion Needed for ranking, fraud detection
Photos/videos 90–180 days after challenge end Necessary evidence retention
Derived metrics 3 years Auditability
Lab documents (body fat % reports) Until user requests deletion or account deletion User control over health data, verification and dispute resolution

Users may request deletion of lab documents at any time. However, deletion during an active challenge may affect verification and challenge participation.

6.1 Third-Party Contact for Verification

For premium challenges requiring lab documents, we may contact the issuing laboratory to verify the authenticity of submitted documents. This contact is limited to:

We do not:

This contact is for verification purposes only and is necessary to ensure the integrity of premium challenges. By participating in a premium challenge requiring lab documents, you consent to this limited contact with the laboratory.


7. Access to Health Data

7.1 Internal

7.2 External

No health data is sold or shared with advertisers.


8. Automated Decision-Making & Example Scenarios

Some decisions are machine-evaluated:

8.1 Automated

8.2 Human Review Required

Example: Baseline Rejection

If your baseline appears manipulated:

Example: Step Fraud Detection

If 25,000 steps appear in a 5-minute interval:


9. Your Rights Regarding Health Data

You may request:

Exercise via: legal@motiw8.com


10. Revocation & Consequences

If you revoke consent:

You may re-enable consent anytime.


11. Special Notes for HealthKit (Apple Rules)

Apple requires:

Motiw8 fully complies.