Privacy policy
1. Purpose and data controller
This policy explains how Singular processes your data when you browse our sites, use your member or professional space, order a product or contact our team. The nutritional personalization service is intended for adults and does not replace a medical consultation.
Singular Lab SAS, registered with the Paris Trade and Companies Register under number 999 248 701, with its registered office at 60 rue François 1er, 75008 Paris, France, is the controller for the processing described below, except for the professional's private address book described in section 6.
For any questions or to exercise your rights, you can contact our Data Protection Officer at dpo@singularlab.com or write to Singular Lab SAS, DPO, at the registered office address. Our general contact is contact@singularlab.com.
2. Data processed and its sources
We process the data you enter or correct, the documents you upload, information arising from your use of the service and results calculated by Singular. We also receive information from our providers as needed for payment, delivery and message transmission.
- Identity and contact: email, first name, last name, language, delivery and billing addresses, delivery phone number. Your email is needed for an account; delivery and billing details are needed for an order. Your name and phone number may be requested depending on the delivery process;
- Health profile: sex at birth, year of birth, current pregnancy or breastfeeding, current hormonal contraception or menopause hormone therapy, declared health conditions and treatments, lifestyle declarations (smoking, how often you drink alcohol, access to a sauna, a red light device, whether you want skin care advice), and changes to these answers;
- Blood tests and results: documents uploaded temporarily, blood test date, biomarker values and units extracted, entered or corrected, result history, calculated indicators, Singular Score and interpretations;
- Personalization: composition and dosages of your formula, versions and personal reports, lifestyle guidance and product preferences, including flavour choice;
- Transactions and shipments: orders, subscriptions, payments, invoices, delivery references and tracking, referral benefits. Full payment details are processed directly by the payment provider; Singular retains the references and limited information needed to track transactions;
- Support and contact: name, email, company if provided, subject, content and language of your request; messages exchanged with the chatbot, exchange date and browsing or progress context useful for its response, linked to your account when you are signed in;
- Technical data: IP address, browser, operating system, access times and logs, functional cookies and measurement data described in section 10. Security information linked to an individual is not treated as anonymous statistics;
- Professional space: identity and professional contact details, country, profession and professional identifier where required, account status, access authorization checks, acceptance records, invitations, sharing permissions and access logs.
Your health profile, blood test results, interpretations and personalized formulations are health data within the meaning of Article 9 of the GDPR. Answers required to personalize your formula are identified during the process. We cannot provide this personalization without the necessary information and your consent to health data processing. Uploading a blood test is optional: a formula can be prepared using the questionnaire alone.
We do not ask for your social security number (NIR) or full date of birth in the profile fields. This information may nevertheless appear on an uploaded blood test and be processed temporarily with the document. You may mask unnecessary identifying details before uploading, while preserving the results, units and information needed to read them. Originals are retained during processing and its limited automatic retries, then purged; they do not form a lasting document archive of your record.
The chatbot and contact form are not channels for submitting your health record. Do not enter blood tests, biomarker values or personal medical information there. The text you write is processed to answer your request, including when you voluntarily include such information.
3. Purposes and legal bases
Each processing activity serves a defined purpose. Consent to health data processing, professional sharing permission and measurement choices are separate. Reading this policy does not constitute general consent to all processing and is distinct from accepting the terms of sale or use.
Nutritional personalization. Questionnaire, optional blood tests, indicators and interpretations, formula and guidance, corrections and updates. Legal basis: Consent, GDPR Articles 6(1)(a) and 9(2)(a).
Account and orders. Account creation, sign-in, orders, subscriptions, payment and delivery; communications necessary for the service. Legal basis: Performance of a contract or pre-contractual steps you request, Article 6(1)(b).
Billing and legal records. Accounting records and documents whose retention is required by law; evidence needed to defend a legal claim. Legal basis: Legal obligation, Article 6(1)(c); legitimate interest in establishing and defending our rights, Article 6(1)(f), depending on the record.
Chatbot support. Answering your questions about the service, maintaining continuity of the conversation and handling reported difficulties; transmitting recent context to the AI provider and review by authorized personnel. Legal basis: Service you request, Article 6(1)(b); legitimate interest in investigating reported errors and securing support, Article 6(1)(f). These bases do not, by themselves, authorize the processing of health data.
Contact and call booking. Answering your customer service or pre-contractual request; arranging a requested appointment. Other requests, including press enquiries, are handled according to their purpose. Legal basis: Article 6(1)(b) for the service or pre-contractual steps you request; Article 6(1)(f) for our legitimate interest in responding to other enquiries.
Professional account and sharing. Account verification and management, permissions, access to data authorized by the member and access logs. Legal basis: Article 6(1)(b) for the professional account; member consent, Articles 6(1)(a) and 9(2)(a), for sharing; Article 6(1)(f) for access security.
Referrals. Linking a referrer and a referred person, calculating, allocating and tracking requested benefits. Legal basis: Legitimate interest in managing the programme and allocating its benefits, Article 6(1)(f); Article 6(1)(c) for the corresponding accounting records.
Security and measurement. Preventing abuse and incidents, logging; limited audience measurement and campaign attribution described in section 10. Legal basis: Legitimate interest in protecting the service and measuring its use, Article 6(1)(f); consent, Article 6(1)(a), for individual attribution. Article 32 governs security measures.
If you book a call before subscribing, the booking service receives your first name, last name, email, chosen time slot and booking status. The form contains no free-text field; no health data should be transmitted through this channel. The call is neither recorded nor transcribed.
To send messages necessary for the service, the email provider processes your contact details, message content, operational references, secure links and delivery metadata. Our notifications do not reproduce your biomarker values or health questionnaire answers. Free-text messages you send to our team are handled as part of your request.
4. Automated calculations and control over your data
We automatically apply rules to your declared profile and, if you upload them, your blood test results to calculate indicators and the Singular Score, suggest guidance and determine the ingredients and dosages of your formula. These rules may result in including, reducing or excluding an ingredient based on the available information. This assessment of your situation constitutes automated personalization of your nutritional profile.
Results may change when you add or correct data, or when Singular updates its reference data and rules. The chatbot separately uses an artificial intelligence system to answer your questions about the service; it does not replace the rules used to calculate your formula.
You can review and correct information in your record through the available processes, report an error, ask for an explanation or request a review by our team by contacting the DPO. When a solely automated decision produces legal effects concerning you or similarly significantly affects you, you benefit from the safeguards provided by Article 22 of the GDPR. Where applicable, these include the rights to human intervention, to express your point of view and to contest the decision.
5. Sharing with the professional of your choice
You can authorize a named person to view your Singular data. This sharing relies on explicit consent separate from consent to personalization. The professional is responsible for the processing they carry out to support you in their own practice; they must inform you of their practices, retention periods and how to exercise your rights with them.
The scope presented when you authorize access includes:
- your identity and email;
- your declared profile: year of birth, sex at birth, health conditions, treatments, pregnancy or breastfeeding, hormonal contraception or menopause hormone therapy, and your lifestyle declarations;
- your validated blood tests, their dates, values, units and zones within the Singular Score, and their evolution;
- lifestyle guidance, formula composition and dosages, regulatory statements and explanations already available in your space;
- shipment regularity: dispatch dates, progress, cadence and next due date.
The professional has read-only access to this data in a dedicated space. They cannot change your health profile, blood tests or formula. They cannot access any amounts, invoices, delivery addresses or payment methods. No clinical alert is sent to them; they decide when to consult your record.
You can withdraw this access directly through shared access management in your profile, or contact the DPO. Withdrawal blocks future access; it does not erase what the professional has already viewed or retained under their own responsibility. Access is logged for one year, and you can request a record of it. As long as access remains open, an annual reminder explains how to end it; your silence does not constitute fresh consent.
6. Recipients
Within Singular, only authorized personnel access the information needed for their duties: support, service management, production, delivery, security or the exercise of your rights.
We use the following categories of processors, within the scope of their assigned tasks:
- hosting and infrastructure: servers, databases and storage;
- document reading and artificial intelligence: extracting blood test data or responding to chatbot conversations, depending on the service used;
- email delivery and messaging: transmitting and tracking messages, handling requests addressed to the team;
- logistics and printing: delivery address and operational information needed for preparation, label printing and dispatch, without your biomarkers or their interpretations;
- appointment booking: only the organizational information described in section 3.
Our processors are governed by the contracts required under Article 28 of the GDPR. Some recipients also act to fulfil their own obligations: the payment provider, particularly for financial and fraud prevention duties, the professional you choose, or competent authorities when disclosure is legally required. Their role and obligations differ from those of a processor. The payment provider does not receive your blood tests or health questionnaire.
In the professional space, Singular is responsible for account management, permissions and the operation of sharing. For the identifying details a professional enters in their private address book to recognize their contacts, the professional determines their use and Singular processes them on the professional's behalf. The professional can manage these details without changing the member's record.
Professional account information comes from the professional or is entered by our team using the information received to open and verify their access. If a professional invites you, they provide us with your email and may enter your title, first name and last name to recognize you in their address book. The invitation identifies the professional who sent it and gives them no access to your record before you authorize it. The details in their address book are separate from the identity you enter in your own account.
For referrals, the abbreviated identities of the referrer and the referred person may be shown to those concerned to identify the benefit. The referrer may therefore learn that a referred person has completed the action that qualifies for credit; this does not give them access to that person's health record or payment information.
We do not sell your personal data or transmit it to enable third parties to carry out their own advertising or direct marketing.
7. Location and international transfers
Storage of your personalization record (biomarkers, health questionnaire, interpretations and formulations) and extraction of your blood tests are configured in regions within the European Economic Area (EEA). A service's location does not necessarily mean that its provider is headquartered in the EEA.
Some auxiliary services, particularly messaging or booking, may involve processing outside the EEA, including in the United States. The information concerned includes contact details, content needed for messages, operational references, booking data and certain technical data.
Where the GDPR requires a transfer mechanism, the transfer must rely on an adequacy decision applicable to the recipient or appropriate safeguards, including the European Commission's standard contractual clauses, together with the necessary assessment and supplementary measures. You can ask the DPO for information about transfers concerning you and a copy of the applicable safeguards, subject to protecting confidential information and the rights of others.
8. Retention
Devices and notifications. With your permission, Singular displays service reminders and, if you choose, reminders for your next recommended blood test on your device. Permission is managed for each device in “My profile”, under “Notifications”. Opting out of advice emails also pauses these blood test reminders. Formula and payment reminders contain no health data, names or amounts. Blood test reminders by email and on your device may include the recommended date shown in your account. They include no previous blood test date, biomarker or result. They stop when you upload a new blood test file. Browser notification providers, including Apple and Google, deliver an encrypted payload to the device. Singular stores a random identifier, platform, language, opening dates, technical subscription and your choices. Devices and their subscriptions are deleted after 180 days without an opening, when you remove them or with your account. Technical keys are excluded from your data export.
Use of the installed application. When you use the installed application while signed in to your account, Singular records the first observed opening of each installation and the days of use, by platform. These observations support internal aggregate statistics on adoption and use of the application. They contain no health content, and no account or device identifier is sent to Umami. This history is separate from the notification device register and is retained for the lifetime of the account: forgetting a device or deleting its subscription after 180 days does not erase it. It is deleted when the account is erased or anonymized. Your data export includes platforms, first observed opening dates and days of use, without technical installation identifiers. A first observed opening does not establish the exact installation date or whether the application remains on the device.
The periods and criteria below distinguish data use, retention of evidence and the validity of sign-in methods. The expiry of a link does not, by itself, mean that all records of its creation have been deleted.
An account with no action from you for 2 years may be considered inactive when no subscription or order is in progress. Any sign-in or use of your account is enough to reset this period. We notify you by email, at your last known address, and allow 30 days before deletion so that you can keep your account; if that address permanently stops accepting our messages, deletion takes place after the same period. A documented dispute or legal risk may justify a temporary hold of only the strictly necessary data in a separate archive with restricted access; such a hold is never applied automatically to all accounts.
Original blood test files. During processing and its bounded automatic retries, then purged.
Health questionnaire, biomarkers, interpretations, formulations and personal reports. While the account is used and consent remains valid; deletion with the account, when consent is withdrawn, or after 2 years of inactivity with no current subscription or order, following prior notice.
Account data. While the account is used; after its deletion or the end of the relationship, separate archiving of only the necessary contractual evidence for no more than 5 years.
Billing. 10 years under Article L123-22 of the French Commercial Code.
Record of an electronic contract worth at least EUR 120. 10 years from the applicable statutory starting point under Articles L213-1 and D213-1 to D213-2 of the French Consumer Code.
Chatbot conversations. Conversations linked to an account follow its retention period and are deleted with it. For a conversation without an account, the criterion is handling the request and, where applicable, resolving an error or complaint related to that conversation.
Contact requests. For the time needed to handle the request and its follow-up. If the exchange forms part of a contractual file or dispute, only the necessary records follow that file's retention period.
Call bookings. No more than 12 months from the appointment or its cancellation. Periodic checks of bookings due for deletion do not extend this maximum.
Professional account and access. While the space is used; necessary evidence follows its contractual or security purpose. Contact and identifying details in an invitation are deleted 90 days after its creation; if sharing is accepted, details carried over to the address book follow the duration of the sharing.
Professional access logs and health data access audit logs. 1 year for processing security and under the security policy, without storing blood test content in these logs.
Connection logs. One year under our security policy. Only records needed for an identified incident may be retained during its investigation and any subsequent legal proceedings. The validity of links and sessions does not determine retention of their records.
Referrals. For the time needed to allocate and manage the benefit; necessary accounting entries and contractual evidence follow their own retention periods.
Audience measurement and attribution. Audience statistics: 13 months. Individual attribution: during the window for linking registrations and purchases, then for the period needed to account for refunds and disputes. Choice records linked to a member are deleted with their account.
Sign-in links can be used for 20 minutes. Member, professional and administrator sessions expire after 30 minutes of inactivity or, at the latest, eight hours after the initial sign-in, even if you remain active. These validity periods are not retention periods for the associated logs or evidence. Cookies and local settings are detailed in section 10.
9. Your rights and choices
Subject to the conditions set out in the GDPR, you have the following rights:
- Access: obtain confirmation of processing, a copy of your data and information about its use, including results concerning you;
- Rectification: have inaccurate or incomplete data corrected or completed;
- Erasure and restriction: request deletion or restriction of processing in the circumstances provided by Articles 17 and 18. Certain records may remain necessary for a legal obligation or the defence of a legal claim;
- Portability: receive data you have provided, including data observed during your use, where it is processed automatically on the basis of consent or a contract, in a structured, machine-readable format such as JSON. You can request direct transmission to another controller where technically feasible. This scope is distinct from the right of access to results calculated by Singular;
- Objection: object to processing based on legitimate interest for reasons relating to your particular situation; object to direct marketing at any time without having to justify your request;
- Withdrawal of consent: withdraw consent without affecting the lawfulness of earlier processing. Withdrawing professional sharing does not withdraw your consent to personalization;
- Directives after death: define instructions concerning the retention, erasure and disclosure of your data.
To withdraw your consent to health data processing, send your request to the DPO. Personalization and new processing of your health profile stop when you withdraw your consent. Your request is handled by erasing the personalization record and closing the account, subject to records retained as required by law. Withdrawing consent and cancelling the subscription are separate steps: our team reviews the consequences for ongoing services with you. Before the account is closed, you can pause the subscription from your member space; orders already in progress are handled under the applicable contractual terms.
You can exercise your rights by email at dpo@singularlab.com or by writing to the DPO at the registered office address. We facilitate these requests, and they are normally free of charge. If there is reasonable doubt about your identity, we may request only the additional information needed to confirm it.
We respond without undue delay and no later than one month after receiving your request. This period may be extended by two months, taking into account the complexity or number of requests; we inform you of the extension and its reasons within the first month.
You can lodge a complaint with the CNIL, particularly if you believe your rights are not being respected. Contacting Singular first is not a condition for lodging a complaint.
10. Cookies and measurement
Signing in with a code uses a request cookie valid for 10 minutes on the requesting device. Using either the link or the code invalidates the other. The application stores a random device identifier and your choices about installation and notification invitations locally. Dismissing an invitation postpones it for 30 days; three dismissals stop it appearing. The offline fallback stores only an information page and its static files, without copying your personal data.
Sign-in, security and language cookies enable the service to function. You can block them in your browser, but some features may then stop working.
We distinguish limited audience measurement, aggregate campaign counts and individual attribution of registrations and purchases:
- Audience measurement: a tool self-hosted in the EEA, without audience tracking cookies. Pages are represented by controlled categories; language, source category and performance measurements are used for statistics, without linking them to your account or transmitting them to a third party for its own use. This limited measurement falls within the consent exemption applicable to audience measurement;
- Aggregate counts: total arrivals by day, campaign and landing page, without an individual identifier or linkage to an account;
- Individual attribution: linking a campaign to a registration and the corresponding purchases to measure its effectiveness. This processing is separate from anonymous statistics and requires consent. It uses a browser identifier stored in a cookie for 30 days; server-side attribution data and choice records follow the criteria in section 8. No blood tests or questionnaire answers are used for this attribution;
- Referrals: a 30-day cookie allows us to take account of the requested referral and link the benefit during registration.
The Cookie Policy page allows you to disable audience measurement and manage your choice regarding campaign attribution. The audience setting applies to the browser you use and disappears if you clear its local data. Withdrawing attribution blocks new corresponding links; you can contact the DPO to exercise your rights over data already linked to your account.
11. Security and hosting
We use measures appropriate to the sensitivity of the data: encryption of storage and communications, checks on uploaded files, access limited by function, enhanced authentication for administrative access, logging and staff awareness training. These measures reduce risks without providing a guarantee of absolute security.
Hosting health data collected during prevention, diagnosis, care, or social or medical-social monitoring activities is subject to Article L1111-8 of the French Public Health Code where its conditions are met. The services used to host our health records and extract blood test data fall within the relevant HDS-certified scopes of our providers. Singular is not itself HDS-certified; a provider's certification covers defined activities and services.
Blood tests transmitted to the extraction provider are not used to train its models. To learn more about our measures, see the Security, quality & traceability page.
12. Updates to this policy
We may update this policy to reflect changes in the service or applicable law. The update date appears below. If a substantial change affects the use of your data, we inform you by email or in your space and obtain fresh consent where necessary before the processing concerned.