Privacy Policy
Last updated: August 25, 2026
This Privacy Policy explains how Magma Company GmbH processes personal data in connection with Diavisor, our invitation-only, experimental diabetes data and insulin-dose calculation tool ("Diavisor" or the "Service").
Diavisor handles health data about your diabetes. That is among the most sensitive categories of personal data there is, and we treat it accordingly. This policy sets out exactly what we collect, why, who else sees it, and what you can do about it.
1. Controller
Magma Company GmbH is the controller for the processing described in this policy.
Magma Company GmbH Salvemattweg 11 6340 Baar (ZG) Switzerland
Email: support@diavisor.com
We have not appointed a data protection officer, as we are not required to. Privacy questions go to the address above.
2. Data we process
2.1. Account data
| Data | Source | Why |
|---|---|---|
| Email address | You | Account identity, sign-in, essential service messages |
| Password (hashed, never stored in readable form) | You | Authentication |
| Name and, optionally, first and last name | You | Displaying your account |
| Invitation / access key used at sign-up | You | Enforcing invitation-only access |
| Device name | Your device | Labelling sign-in sessions so you can tell them apart |
2.2. Health data
This is special category data under Article 9 GDPR and sensitive personal data under the Swiss Federal Act on Data Protection ("FADP").
| Data | Source | Why |
|---|---|---|
| Blood glucose readings and trends | You, or a CGM service you connect | Displaying your data; calculating corrections |
| Insulin doses, including food and correction components, and insulin on board | You, or an insulin pen you scan | Calculating doses; showing history |
| Carbohydrate and meal entries, and notes | You | Calculating doses; showing history |
| Photographs of meals | You, if you use the photo feature | Estimating carbohydrates |
| Insulin settings — insulin-to-carbohydrate ratio, correction factor, target range, insulin duration, insulin type, increment, maximum dose, minimum glucose | You | Performing calculations |
| Derived values — predicted glucose, statistics, time in range, estimated HbA1c, dose outcome analysis | Calculated by us | Reports, trends, and setting suggestions |
| Glucose alerts raised and delivered | Calculated by us | Avoiding repeat notifications; alert diagnostics |
2.3. Connected service credentials
If you link a CGM provider or a Nightscout instance, we store the credentials needed to fetch your readings. These are stored encrypted at rest and are used only to retrieve your data.
2.4. Technical and log data
| Data | Why |
|---|---|
| IP address and user agent, recorded with synchronisation events | Security, abuse prevention, diagnosing sync failures |
| Timestamps and outcome of sync operations, record counts, duration | Diagnosing data loss and sync defects |
| Application and server logs, including error diagnostics | Keeping the Service working and secure |
| Authentication tokens tied to your device | Keeping you signed in |
2.5. What we do not collect
We do not run analytics, advertising, tracking, session recording, or third-party marketing tools in Diavisor. We do not collect location data, contacts, or your device's advertising identifier. We do not buy or receive personal data about you from data brokers.
3. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Creating and running your account | Account data | Performance of a contract, Art. 6(1)(b) |
| Storing, displaying, and calculating on your health data | Health data | Your explicit consent, Art. 9(2)(a), together with Art. 6(1)(b) |
| Estimating carbohydrates from a meal photo | Meal photos | Your explicit consent, Art. 9(2)(a) — given by choosing to use the feature |
| Fetching readings from a service you connect | Credentials, glucose data | Your explicit consent, Art. 9(2)(a), and Art. 6(1)(b) |
| Sending glucose alerts, including via a messaging service you link | Health data | Your explicit consent, Art. 9(2)(a) |
| Sharing your data with a clinician you choose | Health data | Your explicit consent, Art. 9(2)(a) |
| Security, abuse prevention, and debugging | Technical and log data | Legitimate interests, Art. 6(1)(f) — keeping the Service secure and correct |
| Complying with legal obligations | As required | Legal obligation, Art. 6(1)(c) |
| Establishing, exercising, or defending legal claims | As required | Legitimate interests, Art. 6(1)(f); Art. 9(2)(f) |
Under the Swiss FADP we rely on the corresponding grounds, including your consent for sensitive personal data.
You can withdraw consent at any time, by disconnecting the relevant feature or by deleting your account. Withdrawal does not affect processing carried out before it. Because health data is the substance of the Service, withdrawing consent to process it means we can no longer provide Diavisor to you.
4. Who else sees your data
We do not sell personal data, and we do not share it for anyone else's marketing.
We use a small number of processors and third parties to run the Service. The current list, with locations, is on our Sub-processors page. In summary:
- Hosting and infrastructure — our servers and database, where all of the above is stored.
- An AI provider — receives a meal photograph only when you use the photo carbohydrate feature, in order to return an estimate.
- A messaging service — receives alert messages, which contain glucose values, only if you link it.
- CGM and Nightscout providers you connect — we send your credentials to them to retrieve your data.
We may also disclose data where we are legally required to, to respond to a valid legal request, to enforce our terms, or to protect the rights, safety, or property of any person. If we are ever compelled to disclose your data, we will tell you unless legally prohibited.
If our business is transferred, personal data may transfer with it. We will tell you beforehand and you will be able to delete your account first.
5. International transfers
We are based in Switzerland. Some processors are outside Switzerland and the EEA, including in the United States. Where personal data is transferred out of the EEA, the UK, or Switzerland, we rely on an appropriate safeguard, being one or more of:
- an adequacy decision of the European Commission and, where relevant, recognition by the Swiss Federal Council;
- certification under the EU–US Data Privacy Framework and its Swiss and UK extensions; or
- the European Commission's Standard Contractual Clauses, with the Swiss and UK addenda where applicable, together with supplementary measures where needed.
If you use the meal photo feature, the photograph is transferred to the United States. If that is not acceptable to you, do not use that feature; every other part of Diavisor works without it.
You may request a copy of the relevant safeguard by writing to us.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and health data | For as long as your account exists |
| Data after you delete your account | Removed from normal use immediately; retained for up to 90 days to allow recovery from error or abuse, then deleted, except where longer retention is legally required |
| Meal photographs | With the calculation they belong to, until deleted |
| Connected service credentials | Until you disconnect the service or delete your account |
| Sync and security logs | Up to 12 months |
| Data needed for a legal obligation or an actual or anticipated legal claim | For as long as necessary for that purpose |
Backups are rotated on a limited cycle. Data may persist in a backup for a short period after deletion, and is deleted when that backup expires.
7. Your rights
Under the GDPR, the Swiss FADP, and the UK GDPR as applicable, you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectify data that is inaccurate or incomplete — much of which you can do directly in the app;
- erase your data ("right to be forgotten") — you can delete your account from within the app at any time;
- restrict processing in certain circumstances;
- object to processing based on our legitimate interests;
- data portability — receive data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- withdraw consent at any time, without affecting processing already carried out;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Diavisor's calculations are not such decisions: they are suggestions that you review and act on yourself, and no result is applied to you automatically;
- complain to a supervisory authority — see Section 10.
To exercise any right, email support@diavisor.com. We will respond within one month, and will tell you if we need longer. We may ask you to confirm your identity before acting on a request. Exercising these rights is free, unless a request is manifestly unfounded or excessive.
8. Security
We take the security of health data seriously. Measures include:
- encryption in transit using TLS for all traffic between your device and our servers;
- encryption at rest for connected-service credentials;
- passwords stored only as salted hashes, never in readable form;
- authentication by per-device tokens that can be revoked individually, and are all revoked when you delete your account;
- storing your sign-in token in your device's secure keychain, not in ordinary app storage;
- clearing locally stored health data from the device when you sign out or a different account signs in;
- rate limiting on sign-in, registration, and account deletion;
- access to production data restricted to those who need it to operate the Service.
No system is completely secure. Diavisor is experimental software and has not been independently security audited. You should weigh that before entrusting health data to it. If we become aware of a personal data breach that is likely to result in a high risk to you, we will notify you and the competent authority as required by law.
9. Children
Diavisor is not intended for anyone under 18, and we do not knowingly collect personal data from children. Where a parent or legal guardian uses Diavisor in respect of a dependant, the guardian is responsible for that data and for the lawfulness of providing it. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Complaints
If you think we have handled your personal data unlawfully, please tell us first — we would rather fix it.
You also have the right to complain to a supervisory authority:
- Switzerland — Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, edoeb.admin.ch
- EEA — the supervisory authority of your country of residence, place of work, or the place of the alleged infringement
- United Kingdom — Information Commissioner's Office, ico.org.uk
11. Cookies
Our use of cookies and similar technologies is described in our Cookie Policy.
12. Changes to this policy
We may update this policy. The current version is always published at legal.diavisor.com/privacy-policy, with the revision date at the top. Where a change materially affects how we use your data, we will make reasonable efforts to notify you in advance, and where the law requires it, we will ask for your consent again.
Contact
Magma Company GmbH Salvemattweg 11 6340 Baar (ZG) Switzerland
Email: support@diavisor.com
Full company and registry details are in our Impressum.