Diavisor

Privacy Policy

Last updated: August 25, 2026

This Privacy Policy explains how Magma Company GmbH processes personal data in connection with Diavisor, our invitation-only, experimental diabetes data and insulin-dose calculation tool ("Diavisor" or the "Service").

Diavisor handles health data about your diabetes. That is among the most sensitive categories of personal data there is, and we treat it accordingly. This policy sets out exactly what we collect, why, who else sees it, and what you can do about it.


1. Controller

Magma Company GmbH is the controller for the processing described in this policy.

Magma Company GmbH Salvemattweg 11 6340 Baar (ZG) Switzerland

Email: support@diavisor.com

We have not appointed a data protection officer, as we are not required to. Privacy questions go to the address above.


2. Data we process

2.1. Account data

DataSourceWhy
Email addressYouAccount identity, sign-in, essential service messages
Password (hashed, never stored in readable form)YouAuthentication
Name and, optionally, first and last nameYouDisplaying your account
Invitation / access key used at sign-upYouEnforcing invitation-only access
Device nameYour deviceLabelling sign-in sessions so you can tell them apart

2.2. Health data

This is special category data under Article 9 GDPR and sensitive personal data under the Swiss Federal Act on Data Protection ("FADP").

DataSourceWhy
Blood glucose readings and trendsYou, or a CGM service you connectDisplaying your data; calculating corrections
Insulin doses, including food and correction components, and insulin on boardYou, or an insulin pen you scanCalculating doses; showing history
Carbohydrate and meal entries, and notesYouCalculating doses; showing history
Photographs of mealsYou, if you use the photo featureEstimating carbohydrates
Insulin settings — insulin-to-carbohydrate ratio, correction factor, target range, insulin duration, insulin type, increment, maximum dose, minimum glucoseYouPerforming calculations
Derived values — predicted glucose, statistics, time in range, estimated HbA1c, dose outcome analysisCalculated by usReports, trends, and setting suggestions
Glucose alerts raised and deliveredCalculated by usAvoiding repeat notifications; alert diagnostics

2.3. Connected service credentials

If you link a CGM provider or a Nightscout instance, we store the credentials needed to fetch your readings. These are stored encrypted at rest and are used only to retrieve your data.

2.4. Technical and log data

DataWhy
IP address and user agent, recorded with synchronisation eventsSecurity, abuse prevention, diagnosing sync failures
Timestamps and outcome of sync operations, record counts, durationDiagnosing data loss and sync defects
Application and server logs, including error diagnosticsKeeping the Service working and secure
Authentication tokens tied to your deviceKeeping you signed in

2.5. What we do not collect

We do not run analytics, advertising, tracking, session recording, or third-party marketing tools in Diavisor. We do not collect location data, contacts, or your device's advertising identifier. We do not buy or receive personal data about you from data brokers.


3. Why we process it, and on what legal basis

PurposeDataLegal basis (GDPR)
Creating and running your accountAccount dataPerformance of a contract, Art. 6(1)(b)
Storing, displaying, and calculating on your health dataHealth dataYour explicit consent, Art. 9(2)(a), together with Art. 6(1)(b)
Estimating carbohydrates from a meal photoMeal photosYour explicit consent, Art. 9(2)(a) — given by choosing to use the feature
Fetching readings from a service you connectCredentials, glucose dataYour explicit consent, Art. 9(2)(a), and Art. 6(1)(b)
Sending glucose alerts, including via a messaging service you linkHealth dataYour explicit consent, Art. 9(2)(a)
Sharing your data with a clinician you chooseHealth dataYour explicit consent, Art. 9(2)(a)
Security, abuse prevention, and debuggingTechnical and log dataLegitimate interests, Art. 6(1)(f) — keeping the Service secure and correct
Complying with legal obligationsAs requiredLegal obligation, Art. 6(1)(c)
Establishing, exercising, or defending legal claimsAs requiredLegitimate interests, Art. 6(1)(f); Art. 9(2)(f)

Under the Swiss FADP we rely on the corresponding grounds, including your consent for sensitive personal data.

You can withdraw consent at any time, by disconnecting the relevant feature or by deleting your account. Withdrawal does not affect processing carried out before it. Because health data is the substance of the Service, withdrawing consent to process it means we can no longer provide Diavisor to you.


4. Who else sees your data

We do not sell personal data, and we do not share it for anyone else's marketing.

We use a small number of processors and third parties to run the Service. The current list, with locations, is on our Sub-processors page. In summary:

  • Hosting and infrastructure — our servers and database, where all of the above is stored.
  • An AI provider — receives a meal photograph only when you use the photo carbohydrate feature, in order to return an estimate.
  • A messaging service — receives alert messages, which contain glucose values, only if you link it.
  • CGM and Nightscout providers you connect — we send your credentials to them to retrieve your data.

We may also disclose data where we are legally required to, to respond to a valid legal request, to enforce our terms, or to protect the rights, safety, or property of any person. If we are ever compelled to disclose your data, we will tell you unless legally prohibited.

If our business is transferred, personal data may transfer with it. We will tell you beforehand and you will be able to delete your account first.


5. International transfers

We are based in Switzerland. Some processors are outside Switzerland and the EEA, including in the United States. Where personal data is transferred out of the EEA, the UK, or Switzerland, we rely on an appropriate safeguard, being one or more of:

  • an adequacy decision of the European Commission and, where relevant, recognition by the Swiss Federal Council;
  • certification under the EU–US Data Privacy Framework and its Swiss and UK extensions; or
  • the European Commission's Standard Contractual Clauses, with the Swiss and UK addenda where applicable, together with supplementary measures where needed.

If you use the meal photo feature, the photograph is transferred to the United States. If that is not acceptable to you, do not use that feature; every other part of Diavisor works without it.

You may request a copy of the relevant safeguard by writing to us.


6. How long we keep it

DataRetention
Account and health dataFor as long as your account exists
Data after you delete your accountRemoved from normal use immediately; retained for up to 90 days to allow recovery from error or abuse, then deleted, except where longer retention is legally required
Meal photographsWith the calculation they belong to, until deleted
Connected service credentialsUntil you disconnect the service or delete your account
Sync and security logsUp to 12 months
Data needed for a legal obligation or an actual or anticipated legal claimFor as long as necessary for that purpose

Backups are rotated on a limited cycle. Data may persist in a backup for a short period after deletion, and is deleted when that backup expires.


7. Your rights

Under the GDPR, the Swiss FADP, and the UK GDPR as applicable, you have the right to:

  • access the personal data we hold about you, and receive a copy;
  • rectify data that is inaccurate or incomplete — much of which you can do directly in the app;
  • erase your data ("right to be forgotten") — you can delete your account from within the app at any time;
  • restrict processing in certain circumstances;
  • object to processing based on our legitimate interests;
  • data portability — receive data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
  • withdraw consent at any time, without affecting processing already carried out;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Diavisor's calculations are not such decisions: they are suggestions that you review and act on yourself, and no result is applied to you automatically;
  • complain to a supervisory authority — see Section 10.

To exercise any right, email support@diavisor.com. We will respond within one month, and will tell you if we need longer. We may ask you to confirm your identity before acting on a request. Exercising these rights is free, unless a request is manifestly unfounded or excessive.


8. Security

We take the security of health data seriously. Measures include:

  • encryption in transit using TLS for all traffic between your device and our servers;
  • encryption at rest for connected-service credentials;
  • passwords stored only as salted hashes, never in readable form;
  • authentication by per-device tokens that can be revoked individually, and are all revoked when you delete your account;
  • storing your sign-in token in your device's secure keychain, not in ordinary app storage;
  • clearing locally stored health data from the device when you sign out or a different account signs in;
  • rate limiting on sign-in, registration, and account deletion;
  • access to production data restricted to those who need it to operate the Service.

No system is completely secure. Diavisor is experimental software and has not been independently security audited. You should weigh that before entrusting health data to it. If we become aware of a personal data breach that is likely to result in a high risk to you, we will notify you and the competent authority as required by law.


9. Children

Diavisor is not intended for anyone under 18, and we do not knowingly collect personal data from children. Where a parent or legal guardian uses Diavisor in respect of a dependant, the guardian is responsible for that data and for the lawfulness of providing it. If you believe a child has provided us with personal data, contact us and we will delete it.


10. Complaints

If you think we have handled your personal data unlawfully, please tell us first — we would rather fix it.

You also have the right to complain to a supervisory authority:

  • Switzerland — Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, edoeb.admin.ch
  • EEA — the supervisory authority of your country of residence, place of work, or the place of the alleged infringement
  • United Kingdom — Information Commissioner's Office, ico.org.uk

11. Cookies

Our use of cookies and similar technologies is described in our Cookie Policy.


12. Changes to this policy

We may update this policy. The current version is always published at legal.diavisor.com/privacy-policy, with the revision date at the top. Where a change materially affects how we use your data, we will make reasonable efforts to notify you in advance, and where the law requires it, we will ask for your consent again.


Contact

Magma Company GmbH Salvemattweg 11 6340 Baar (ZG) Switzerland

Email: support@diavisor.com

Full company and registry details are in our Impressum.

Go back to Diavisor