Privacy Policy

At SERETAKOS GEORGIOS TOU MARIOU, a sole proprietorship registered in Greece, with General Commercial Registry (GEMI) Number 187845603000 (hereinafter "Nutripal" or "we"), we prioritize transparency and the control you have over your personal data. This Privacy Policy informs you in a clear and simple manner about the data we collect, how we process it, and the purposes they serve through our website (URL: https://nutri-pal.gr/) and mobile application (collectively the "Platform").

1. Roles and Responsibilities

Depending on the nature of your interaction with the Platform, Nutripal's role is defined as follows:

  • As a Data Controller: Nutripal acts as a Data Controller for personal data related to your account management and subscription. These include information provided during your registration (e.g., name, email, credentials) and billing information for your subscription to our services. In this capacity, we determine the purposes and means of processing your account data to provide you with access to the Platform and its features.
  • As a Data Processor: For the processing of your personal data related to your nutritional profile such as weight, height, medical history, allergies, and meal plans, Nutripal acts primarily as a Data Processor on behalf of the nutrition professional (dietician) to whom you are linked, who remains the Data Controller for these data, as they are responsible for providing nutritional advice and professional consultation. Nutripal processes this data strictly according to the instructions of the dietician and the functionalities of the Platform to facilitate your nutritional monitoring.

2. What personal data we process

In the context of your use of the Platform and its services, we will collect and further process the following personal data, depending on the functionalities you use:

  • Information you provide directly to us: Identification data (such as name, surname), contact details (such as email address and phone number), and account credentials. Furthermore, given the nature of our services, we collect information regarding your physical characteristics (e.g., weight, height), lifestyle and habits (e.g., exercise frequency, sleep patterns, smoking habits), and special categories of data (health data), including allergies, gastrointestinal issues, current medications and nutritional goals.

3. Why we process personal data

Your aforementioned personal data are processed by us for the fulfillment of the following purposes and in accordance with the following legal bases:

  • Performance of a Contract
    Nutripal process your personal data related to your identification, contact, and subscription, as a Data Controller, as this is necessary for the provision and proper functioning of the Platform and the services offered through it.
  • Legitimate Interest
    It is in the Nutripal's legitimate interest to process your data in order to ensure the uninterrupted, proper, and secure operation of the Platform, to maintain data backups, and to ensure overall business continuity matters. Furthermore, it is in our legitimate interest to manage any general communication we receive from you, in order to respond to your queries regarding our services, as well as the operation of the Platform.
  • Consent
    Nutripal processes special categories of personal data (health data) solely in the case you have provided explicit consent, in accordance with Article 9(2)(a) of the GDPR. When Nutripal processes health data, it does so as a Data Processor on behalf of your dietician. These data are processed based on the explicit consent you provide to your dietician (the Data Controller). Nutripal facilitates this processing strictly for the purpose of enabling your dietician to provide their services to you. You may withdraw your consent at any time through the Platform or by contacting your dietician directly.
  • Legal Obligation
    Nutripal is legally obligated to cooperate with the competent authorities for the combatting of specific incidents, as well as to manage and respond to your requests concerning the protection of your personal data.

4. With Whom we share the personal data

Your personal data are collected and further processed by Nutripal with full respect for your privacy. In the context of the provision of services by Nutripal, recipients of your personal data may be the following categories of our partners:

  • Companies providing the servers and technical infrastructure required to host the Platform and store your data securely.
  • Third-party providers (such as OpenAI) that provide the underlying technology for the Platform's AI Assistant and chat functionalities.
  • Companies (such as Google) that facilitate the synchronization of appointments and schedules through external calendar services.
  • Authorized financial institutions or payment gateways used to process subscriptions for the use of the Platform.
  • Any administrative, judicial, or public authority, or generally any legal or natural person to whom Nutripal may be required by law or court order to disclose such data.
  • Your data is shared with the specific dietician to whom you are linked for the provision of your nutritional plans and consultations.

For our Google API data practices and Limited Use compliance, see our Google API Disclosure.

5. Data Retention

Personal data are kept for as long as necessary to fulfill the purposes for which they was collected or as required by law. After this period, data are deleted or anonymized unless required for the establishment or defense of legal claims.

6. Our Commitments

Nutripal takes appropriate technical and organizational measures, in accordance with the latest technological standards and applicable legislation, in order to ensure that the processing of your personal data—whether by us or by third parties on our behalf—are lawful, appropriate, and maintains the suitable level of security to prevent any unauthorized or accidental access, processing, deletion, alteration, or other use thereof.

7. Your Rights

In accordance with personal data protection legislation, you have and may exercise the following rights, provided that the conditions for their exercise are met:

  • The right of access: namely, the right to be informed as to whether your personal data is being processed by Nutripal and, furthermore, to receive additional information regarding the processing being carried out;
  • The right to request the rectification of any inaccurate personal data or the completion thereof;
  • The right to erasure of your personal data;
  • The right to portability: namely, the right to receive and transmit to another data controller the personal data you have provided to Nutripal in a suitable format;
  • The right to restriction of processing of your personal data;
  • The right to withdraw the consent you have given us at any time, without such withdrawal affecting the lawfulness of the processing of personal data carried out prior to said withdrawal.

In the event that you exercise your rights of rectification, erasure, or restriction of your data, such requests shall also be transmitted to any third-party recipients to whom this data may have been disclosed by us.

The exercise of your aforementioned rights is carried out by submitting a relevant written request to Nutripal, to which we undertake to respond within a period of one (1) month from its receipt. This deadline may be extended for an additional two (2) months due to the complexity of the request and/or the high volume of requests.

Please note that the entity you should contact to exercise your rights depends on the nature of your request:

  • For account and subscription data: If your request concerns your registration, login credentials, or subscription status (where Nutripal acts as the Data Controller), please contact us directly at nutripal.gr@gmail.com.
  • For personal data related to your nutritional profile: If your request concerns your nutritional profile, or any data provided for your consultation (where Nutripal acts as a Data Processor), you should primarily address your request to your dietician (the Data Controller). Nutripal will cooperate with and assist your dietician to ensure your request is fulfilled in accordance with the law.

8. Modifications to the Privacy Policy

Nutripal reserves the right to update or modify this Privacy Policy. Any changes will be published on the Platform, accompanied by an indication of the date of the last revision.

9. Contact Details

For any queries, clarifications, or requests regarding the protection of your personal data within the framework of the Platform's operation, you may contact us at the email address: nutripal.gr@gmail.com.

In the event that you consider the protection of your personal data to be affected in any way, you reserve the right to lodge a complaint with the Hellenic Data Protection Authority, using the dedicated digital complaint assistant available on the Authority's website | www.dpa.gr.

Version: 10/05/2026