Privacy Policy for myQiu/BioSign HRV



Version 1.1 of September 2026


1. General Information

This Privacy Policy explains how BioSign GmbH processes personal data when you use myQiu.

myQiu enables the collection, storage, evaluation, and presentation of heart rate variability (HRV) data. Measurement data can be transmitted to myQiu from a measurement device connected via Bluetooth and processed on our server systems.

The measurement and evaluation data processed in this context may allow conclusions to be drawn about a person's state of health. We therefore treat these data as health data and thus as special categories of personal data within the meaning of Article 9(1) GDPR.


2. Controller

BioSign GmbH
Brunnenstr. 21
85570 Ottenhofen
Germany
 
Managing Director: Dr. Reinhard D. Beise
Telephone: +49 8121 923894
Email: info@biosign.de
Website: www.biosign.de
Register Court: Local Court of Munich
Commercial Register No.: HRB 135220
VAT Identification No.: DE 213294143


3. Data Protection Officer

Dr. Markus Hofer
Data Protection Officer
BioSign GmbH
Brunnenstr. 21
85570 Ottenhofen
Germany
Email: datenschutz@biosign.de


4. What Data Do We Process?

4.1 Account and Registration Data

For the creation and administration of a myQiu account, the following data in particular may be processed:

·        Username and authentication data,

·        Email address,

·        Form of address and title, where provided,

·        First and last name or a pseudonym selected by the User,

·        Date of birth or year of birth,

·        Gender, where provided,

·        Height, where provided,

·        Address data, where stored for the account,

·        Language and time zone,

·        License and account status.

Where technically possible and compatible with the desired use, a pseudonym may be used instead of first and last name. Age or year of birth may be required for the calculation and interpretation of certain HRV values.


4.2 Measurement, HRV, and Health Data

When measurements are performed and evaluated, myQiu processes in particular:

·        Interbeat intervals (IBI, i.e. intervals between heartbeats),

·        For the Qiu+ measurement system, additionally the pulse waveform signal,

·        HRV parameters and evaluations calculated from the measurement data,

·        Time, duration, and historical trends of measurements,

·        Where applicable, further information associated with the measurement.

These data are treated as health data pursuant to Article 9(1) GDPR.


4.3 Coach Data and Coach Releases

Coach Accounts may be used only by adults. For registered Coaches, the account and contact data required to create and administer the Coach Account are processed. Registration as a Coach does not automatically grant a Coach access to a User's measurement or health data. Access is granted solely on the basis of an active release by the User or, in the case of minor Users, through the designated consent process.

myQiu also stores information about which Coach a User has released data to. A User may release data to no more than two Coaches at the same time. While a release is active, the Coach may view, download, and analyze the designated measurement and evaluation data. A release may be withdrawn at any time; the relevant Coach's access via myQiu then ends immediately. Data already lawfully downloaded are not automatically deleted when the release is withdrawn.


4.4 Technical Login and Application Logs

Technical login and application logs are generated during login processes. They are used for technical security, error analysis, and detection of unauthorized access. The regular retention period is 28 days; these log data are then deleted.


4.5 Support and Communication Data

If you contact us, we process the contact data you provide, information concerning the User Account, and the content of your inquiry to the extent necessary to handle your request.


4.6 Minor Users

myQiu may also be used for minor Users. In this case, the User Account is created or managed by an adult who has the necessary parental responsibility, authority to represent, and authority to consent.

A Coach may create a User Account for a minor User only on behalf of an adult who has the corresponding authority to represent the minor.

Before health data of a minor User are processed, the consents and declarations required under applicable law are obtained. The minor's age and capacity for understanding are taken into account. When a minor User reaches the age of majority, the User makes data protection decisions and Coach releases independently from that point onward.


5. Purposes and Legal Bases of Processing

5.1 Provision and Administration of the User Account

Account and registration data are processed to create and administer your myQiu account and to provide the agreed functions. The legal basis is Article 6(1)(b) GDPR.


5.2 Performance and Evaluation of HRV Measurements

Measurement data are processed to perform the HRV measurements initiated by you, calculate HRV parameters, evaluate and store results, and display historical trends. Where health data are processed in this context, the processing is based on your explicit consent pursuant to Article 9(2)(a) GDPR. For the general data processing required to provide the agreed myQiu functions, Article 6(1)(b) GDPR also applies.


5.3 Optional Data Release to a Coach

Adult Users decide for themselves whether to grant a Coach registered with myQiu access to the designated data. For minor Users, the release is carried out through the designated consent process, taking into account the required declarations of the minor and of the adult authorized to represent the minor. Access is granted only on the basis of the active release. Where health data are disclosed, the release is based on explicit consent pursuant to Article 6(1)(a) and Article 9(2)(a) GDPR. The Coach release is voluntary and is not a prerequisite for the general myQiu functions.


5.4 Technical Operation and IT Security

We process technical log data to ensure secure and functional operation of myQiu, to analyze errors, and to detect and defend against unauthorized access and other security incidents. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the security, stability, and functionality of myQiu and in protecting the data processed.


5.5 Support and Legal Obligations

Depending on the subject matter of the request, we process support and communication data on the basis of Article 6(1)(b) or (f) GDPR. Where statutory retention, evidentiary, or other obligations apply, processing is carried out on the basis of Article 6(1)(c) GDPR.


6. Requirement to Provide Data

Certain account and authentication data are required in order to create a myQiu account and provide the agreed services. Without the measurement data required for an HRV measurement, the corresponding measurement, calculation, and evaluation functions cannot be provided. Release to a Coach is voluntary.


7. Access by Coaches

A registered Coach initially has no access to the health or measurement data of other Users. Adult Users decide for themselves whether and to which Coach they grant access; for minor Users, the release is carried out through the designated consent process. No more than two Coaches may be released at the same time. Within the scope of a release, the Coach may view, download, and analyze the designated measurement and evaluation data. A release may be withdrawn at any time. Access via myQiu ends immediately after the Coach is deselected. Data already lawfully downloaded are not automatically deleted when a release is withdrawn.

Where a Coach subsequently processes data made available to or downloaded by the Coach for the Coach's own advisory, coaching, or other professional purposes and independently determines the purposes and means of such further processing, the Coach is independently responsible under data protection law for that further processing.


8. Hosting, Data Backup, and Processing on Behalf of the Controller

For the operation of myQiu's server and backup infrastructure, we use IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, as a processor pursuant to Article 28 GDPR. A data processing agreement is in place with IONOS.

The production server infrastructure for myQiu is operated in Germany. IONOS Cloud Backup is used for data backups. Europe is configured as the target region for backups.

The current backup configuration provides for full and differential backups, a maximum retention period of three weeks, and AES-256 encryption. Recoverability is verified by test restores.

According to the currently documented status, Arsys Internet S.L.U. in Spain and Acronis Germany GmbH in Germany are particularly relevant as further processors used by IONOS for the server and backup services employed.

Under the applicable agreement, processing by IONOS generally takes place within the European Union or the European Economic Area, unless a transfer to a third country is required for an individual service. Any such transfer may take place only in compliance with the requirements of Articles 44 et seq. GDPR.


9. Bluetooth and Location Permission on Android

myQiu uses Bluetooth exclusively to communicate with compatible measurement devices. On certain Android versions, the operating system may require a permission described as a location permission in order to search for Bluetooth devices.

myQiu does not read location data on the basis of this permission. In particular, no GPS or other location coordinates are collected or stored, no location information is derived from Bluetooth data, and no location data are transmitted to the myQiu server.


10. Processing on the Smartphone

Health and measurement data are not stored permanently on the smartphone. Local processing takes place only to the extent necessary for the respective measurement and transmission to the myQiu server system.


11. Pseudonymization and Separation of Data

Health and measurement data are stored separately from directly identifying master data. IBI data, the pulse waveform signal recorded with Qiu+, and HRV parameters calculated from these data are stored under a pseudonymous internal identifier. Assignment to the User Account takes place through a separate technical link.

Because assignment remains possible, the data are pseudonymized rather than anonymized. The data remain personal data and continue to be subject to the GDPR. Directly identifying master data are stored in encrypted form.


12. Data Security

We use appropriate technical and organizational measures to protect personal data. These include in particular HTTPS/TLS for communication between the application and server, separate and pseudonymized storage of health data, encrypted storage of directly identifying master data, restricted administrative access rights, firewall and update procedures, and encrypted and tested backups.


13. Retention Period and Deletion

13.1 User Account and Health Data

Health and measurement data are stored for as long as the User Account exists, to the extent required for myQiu's historical measurement and evaluation functions. After expiry of the most recently activated license, the User Account may initially remain in existence so that it can be used again if a new license is activated later. If no new license is activated within two years after expiry of the last activated license and the User Account has not already been deleted, the User Account, master data, assignment keys, and the associated health and measurement data will be deleted from the production systems no later than the end of that period, unless statutory retention obligations or other legal grounds prevent deletion. If the Customer deletes the User Account earlier, the corresponding production data are deleted without waiting for that period to expire. Data still contained in backups are removed in accordance with Section 13.4 as part of the backup rotation.


13.2 Coach Releases

A Coach's access authorization via myQiu ends when the User deselects the Coach and no later than when the User Account is deleted. Data already lawfully downloaded are not automatically deleted when the release is terminated.


13.3 Login and Application Logs

Login and application logs are stored for 28 days and then deleted.


13.4 Backups

Backups are retained for no more than three weeks and are then removed as part of the backup rotation. Data still contained in backups that were previously deleted from the production system are not used for regular production purposes. Following a restore, deletions that occurred in the meantime are implemented again.


14. Withdrawal of Consent

Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. This applies in particular to the processing of health data and the voluntary release to a Coach. A Coach release may be ended by deselecting the relevant Coach. For other data protection matters, you may contact datenschutz@biosign.de.

The lawfulness of processing carried out before withdrawal remains unaffected. Where the processing of certain health data is technically required in order to provide a requested HRV measurement or evaluation function, withdrawal may result in that function no longer being available thereafter.


15. Newsletter

If you subscribe to a newsletter from BioSign GmbH, we process your email address for the purpose of sending the newsletter. The newsletter is currently administered by BioSign GmbH itself; according to the current status, no separate external newsletter service provider is used.

The legal basis is your consent pursuant to Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future, in particular using the unsubscribe option provided in the newsletter or by sending us a message. Following unsubscribe, your email address is removed from the newsletter distribution list unless another legal basis permits further storage.


16. No Use for Advertising or AI Training

Under the current processing concept, health and measurement data stored in myQiu are not used for personalized advertising, for training AI or other models, or for other unrelated purposes.


17. Automated HRV Evaluations

myQiu automatically calculates HRV parameters from the measurement data collected and provides evaluations and presentations derived from them. These calculations form part of the analysis functions offered. Under the current processing concept, no decision is made solely by automated means within the meaning of Article 22 GDPR that produces legal effects concerning a User or similarly significantly affects the User.


18. Rights of Data Subjects

Subject to the applicable statutory requirements, you have in particular the following rights:

·        Right of access pursuant to Article 15 GDPR,

·        Right to rectification pursuant to Article 16 GDPR,

·        Right to erasure pursuant to Article 17 GDPR,

·        Right to restriction of processing pursuant to Article 18 GDPR,

·        Right to data portability pursuant to Article 20 GDPR,

·        Right to object pursuant to Article 21 GDPR,

·        Right to withdraw consent with effect for the future.

To exercise your data protection rights, you may contact our Data Protection Officer at datenschutz@biosign.de.


19. Right to Object

Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right under Article 21 GDPR to object at any time, on grounds relating to your particular situation. Following a justified objection, we will no longer process the relevant data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.


20. Right to Lodge a Complaint with a Supervisory Authority

Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection law.

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
Telephone: +49 981 180093-0
Email: poststelle@lda.bayern.de
Website: www.lda.bayern.de

You may also contact any other data protection supervisory authority competent under the GDPR.


21. Changes to this Privacy Policy

We review this Privacy Policy regularly and update it if the functions of myQiu, data processing activities, technical systems, service providers used, or legal requirements change. The version most recently published applies.