MYHIXEL HUB - Privacy Policy
1. Introduction and Commitment to Health Data Privacy
This Privacy Policy governs the processing of personal data carried out by NEW WELLNESS CONCEPT S.L. (hereinafter, “Myhixel”) through its digital ecosystem, which comprises the website, the Myhixel Hub mobile application and its interaction with the Myhixel Trainer device.
At Myhixel, we recognise that men’s intimate health is an exceptionally sensitive area. We have therefore designed our platform in accordance with the principles of Privacy by Design and by Default, complying not only with the General Data Protection Regulation (“GDPR”) and Spanish Organic Law 3/2018 on Personal Data Protection and the Guarantee of Digital Rights (“LOPDGDD”), but also with the international ISO 27001 information security standard and the regulations applicable to Class I medical devices.
2. Types and Categories of Data Processed
In accordance with the principle of transparency, Myhixel informs users that it processes the following categories of data, depending on each user’s specific interaction with the platform:
- Identification and contact data: This includes first name, surname, email address, postal address for physical deliveries and, optionally, a pseudonymous nickname for use within the App, thereby minimising the direct association between the App profile and the user’s civil identity.
- Profile and contextual data: Information relating to age, gender, weight, sleep quality and general wellbeing habits, which is required to segment and personalise the user experience.
- Special categories of personal data relating to health and sex life: These data form the core of the digital therapy and include responses to validated clinical questionnaires, such as IELT and TLEI, levels of sexual satisfaction, perceived ejaculatory control and sexual orientation.
- Telemetry and IoT data: Information collected by the sensors embedded in the Myhixel Trainer device during use, including acceleration, speed, temperature and vibration patterns. These data are essential for objectively measuring adherence to and progress within the treatment programme.
3. Detailed Overview of Data Processing Activities
The following sections describe how your data are governed, grouping the purposes, lawful bases and retention periods applicable to each processing activity.
A. Digital Therapy and Use of the Myhixel Hub App
- Purpose: To provide a personalised intimate-health service, monitor clinical progress and dynamically adapt therapeutic programmes.
- Lawful basis: The processing of identification data is necessary for the performance of a contract under Article 6(1)(b) of the GDPR. The processing of health data, data relating to sex life and telemetry data is based on your explicit consent under Article 9(2)(a) of the GDPR, specifically obtained through the App.
- Retention period: Account data will be retained for the duration of the contractual relationship. Health data will be retained for five years following the user’s last activity, by analogy with the applicable patient autonomy legislation, after which they will be retained in legally restricted or blocked form.
B. Purchase and Logistics Management
- Purpose: To process orders and payments, issue invoices, deliver physical devices and manage product warranties.
- Lawful basis: Performance of the contractual relationship under Article 6(1)(b) of the GDPR and compliance with applicable tax and commercial legal obligations.
- Retention period: Data will be processed for as long as necessary to complete delivery and will subsequently be retained in blocked form for the applicable statutory limitation periods: six years for commercial documentation and four years for tax documentation.
C. Newsletter Subscriptions and Communications
- Purpose: To send news, health-related studies and commercial offers concerning the Myhixel ecosystem.
- Lawful basis: Your consent under Article 6(1)(a) of the GDPR, provided when subscribing.
- Retention period: Until you withdraw your consent. An immediate unsubscribe option will be available in every communication.
D. Anonymisation for Research and Commercial Use of Aggregated Data
- Purpose: To subject your profile, telemetry and health data to an irreversible anonymisation process. This processing is intended to generate aggregated datasets that, once they no longer constitute personal data, may be used by Myhixel for scientific research, market trend analysis and new product development, as well as for commercial exploitation, licensing or sharing with strategic partners, such as health connectivity platforms, and research groups.
- Lawful basis: Your explicit consent under Articles 6(1)(a) and 9(2)(a) of the GDPR, obtained separately through the App. Access to the main service is not conditional upon providing this consent, ensuring that your decision will not affect your ability to use the Myhixel Trainer device or participate in your therapy.
- Retention period: Data may be anonymised while your account remains active or until you withdraw your consent for this specific purpose. Once the data have been effectively and irreversibly anonymised, the GDPR will no longer apply to the resulting dataset. Myhixel may therefore retain and use the anonymised information indefinitely.
4. Advanced Digital Health and Data Governance Provisions
4.1. Safeguards Governing the Anonymisation Process
Myhixel is committed to advancing medical science and innovation in sexual health while providing robust privacy safeguards.
The anonymisation process described in Section 3.D is therefore carried out in accordance with a strict cohort-size threshold policy of N ≥ 20 and using data aggregation techniques.
Myhixel ensures that the process is irreversible and that the re-identification of an individual user is mathematically impossible. This process has been assessed through a Data Protection Impact Assessment (“DPIA”) conducted in accordance with Article 35 of the GDPR.
As the resulting information is fully anonymous, the aggregated datasets fall outside the scope of the GDPR pursuant to Recital 26.
4.2. Artificial Intelligence Governance
Our platform uses artificial intelligence exclusively for analytical purposes and for personalising the user interface.
Myhixel ensures that AI is not used to make automated diagnoses that produce legal effects or similarly significant consequences for users without professional human oversight.
All therapeutic recommendations are based on predefined and validated medical protocols.
4.3. Interaction with Health Ecosystems such as Apple Health and Google Fit
Myhixel Hub currently operates independently to ensure the highest possible level of separation and protection for your intimate-health data.
We neither share data with nor retrieve data from Apple Health, Google Fit or other third-party health data aggregators. This prevents your intimate-health information from being combined with general activity profiles without your full knowledge and control.
5. Processing Security, Technical Resilience and Cybersecurity Culture
In strict compliance with Article 32 of the GDPR, Myhixel has implemented a hospital-grade security ecosystem designed to protect the integrity, confidentiality and availability of the health information it processes.
Our technical infrastructure is hosted within the AWS Ireland region, in the European Union, and is based on the following advanced security principles:
- Military-grade data encryption: We apply robust encryption protocols to data in all states. Data at rest within our Amazon RDS databases and S3 storage volumes are protected using AES-256 encryption managed through AWS Key Management Service (“AWS KMS”). All communications between the Myhixel Hub mobile application and our servers are secured using TLS 1.2 or later, helping to prevent information from being intercepted or altered by unauthorised third parties while in transit.
- Identity governance and granular access controls: We apply the principle of least privilege through highly restrictive identity and access management (“IAM”) controls. Access to production environments is protected by mandatory multi-factor authentication (“MFA”) for all authorised personnel. We have also implemented strict segregation of duties, ensuring that only essential technical personnel may interact with data systems, always subject to strict confidentiality obligations and ongoing auditing.
- Resilience, availability and disaster recovery: Myhixel safeguards service continuity and protects data against physical and technical incidents. We operate automated daily backup systems with geographical replication within the European Union availability zone. Monthly restoration tests are conducted to validate our disaster recovery plans (“DRP”), helping to ensure that your therapeutic history can be restored promptly in the event of an incident.
- Proactive monitoring and continuous auditing: Our systems incorporate observability tools that monitor anomalous access attempts and suspicious behaviour in real time. We regularly conduct security audits and penetration testing to identify and mitigate vulnerabilities before they can be exploited. This cybersecurity culture is reinforced through continuous team training and the adoption of the ISO 27001 standard, consolidating Myhixel as a secure environment for managing your digital health information.
6. Deletion of Personal Data and/or Account Cancellation
Users may request the deletion of their personal data and/or the permanent cancellation of their Myhixel account at any time.
Such a request constitutes a specific exercise of the right to erasure established under the GDPR. This is without prejudice to circumstances in which Myhixel is required to retain certain data in duly restricted or blocked form in order to comply with legal, contractual, healthcare, tax, commercial, warranty or security obligations, or to establish, exercise or defend against legal claims.
6.1. Available Channels for Requesting Deletion
To request the deletion of personal data and/or the cancellation of an account, users may use either of the following channels:
- Send an email to Myhixel’s Data Protection Officer at dpd@myhixel.es, using the subject line “Request for data/account deletion”; or
- Use the specific privacy, account settings or support functionality within the Myhixel Hub App, when available.
The request must contain sufficient information to identify the user, including at least the email address associated with the account and a clear indication of whether the user is requesting the deletion of specific data, the complete cancellation of the account or both.
Myhixel may request reasonable additional information where necessary to verify the identity of the requester and prevent unauthorised access to or deletion of personal data.
6.2. Scope of Deletion and Effects on the Service
Once the request has been verified, Myhixel will delete or anonymise, as appropriate, the personal data associated with the user’s active account. This may include identification data, profile data, App usage data and information associated with therapeutic monitoring, provided that no legal basis requires or permits its continued retention.
The account will also cease to be operational, and the user will lose access to their history, programmes, metrics, settings and any other features associated with Myhixel Hub.
Account cancellation will not necessarily affect the separate retention of the minimum information required in connection with purchases, invoicing, warranties, customer support, security, fraud prevention or regulatory compliance, where such retention is required or otherwise lawful under the applicable legislation.
In relation to commercial communications, unsubscribing will result in the cessation of promotional messages, except for transactional communications or communications that Myhixel is legally required to send.
6.3. Blocked Data, Backups and Anonymised Data
Where data must be retained to comply with a legal obligation or to address potential liabilities, they will no longer be available for the platform’s ordinary operations. Instead, they will be retained in blocked form and processed exclusively for those restricted purposes for the applicable statutory periods. Once these periods have expired, Myhixel will permanently delete the data.
Deletion from backup copies may not take effect immediately due to technical requirements relating to integrity, service continuity and disaster recovery. However, any data contained in backups will remain subject to appropriate security measures and will not be restored for ordinary processing purposes unless restoration is strictly necessary for technical, legal or security reasons.
Where a backup is restored, Myhixel will reapply the relevant deletion request to the affected data.
Data that have previously been irreversibly anonymised for statistical, scientific, service improvement, research or commercial purposes in accordance with Section 3.D will no longer allow the user to be identified. Consequently, such data cannot be reassociated with the user’s account or individually deleted.
6.4. Response Periods and Confirmation
Myhixel will respond to a deletion or account cancellation request within a maximum period of one month from receipt.
This period may be extended by an additional two months where the request is particularly complex or where Myhixel has received a large number of requests. The user will be informed of any extension and the reasons for it within the initial one-month period.
Once the deletion or cancellation process has been completed, Myhixel will send confirmation to the user through the same channel used to submit the request or to the email address associated with the account.
Where Myhixel is unable to comply with all or part of a request due to a legal obligation, an exception under applicable data protection legislation or a legitimate need to retain the data, Myhixel will provide the user with a reasoned explanation. This explanation will identify the affected data, the purpose of the retention, the applicable retention period and the rights that the user may exercise before the Spanish Data Protection Agency (“AEPD”).
7. Amendments to this Privacy Policy
Myhixel may update this Privacy Policy to reflect technical, legal or product-related changes.
Users will be notified of any material amendment through the App or by email sufficiently in advance. Continued use of the service following such notification will constitute acceptance of the updated terms, without prejudice to your right to request the deletion of your personal data.
8. Your Rights and Contact Details
You may exercise your rights of access, rectification, erasure, restriction of processing, data portability and objection. You may also request the deletion of your personal data and/or the cancellation of your account in accordance with the procedure described in Section 6.
To exercise these rights, please contact our Data Protection Officer by email at dpd@myhixel.es.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (“AEPD”).