Privacy Policy
the-key.health | ACW Consulting GmbH
Last updated: 29 July 2026
1. Controller and Contact Details
The controller for the processing of your personal data within the meaning of Art. 4(7) GDPR is:
ACW Consulting GmbH, Nördliche Hauptstraße 20, 83700 Rottach-Egern, Germany. Commercial register: Amtsgericht München, HRB 310263. Managing Director: Alexander Weinig. E-mail: privacy@the-key.health.
For all privacy-related enquiries and to exercise your data subject rights, please contact us at privacy@the-key.health or by post at the address above.
2. Applicable Law
We process personal data in accordance with: Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR); the German Federal Data Protection Act (Bundesdatenschutzgesetz — BDSG), in particular §§ 22 and 32 BDSG insofar as they apply to health data and automated decision-making; the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG) for cookies and tracking technologies; and all other applicable European and German data protection legislation.
3. Data Protection Officer
We have assessed whether the appointment of a Data Protection Officer (Datenschutzbeauftragter) is mandatory under Art. 37(1) GDPR and § 38 BDSG. Our assessment — documented internally as required — is that, at current user scale (under 1,000 users), the processing of special category data does not occur on a "large scale" within the meaning of Art. 37(1)(c) GDPR and Recital 91 GDPR, as clarified in the DSK guidelines on the DPO obligation. Accordingly, we are not currently required to appoint a mandatory DPO. We keep this assessment under review as the Platform scales. If you have privacy concerns, please contact us at privacy@the-key.health.
4. Scope of This Privacy Policy
This Privacy Policy describes how ACW Consulting GmbH ("we", "us", "The Key") collects, processes, stores, and shares personal data when you use the Platform (https://the-key.health and associated web and mobile application). It applies to all users of the Platform, whether based in Germany, the European Economic Area (EEA), or elsewhere.
5. Categories of Personal Data We Process
5.1 Account and contact data. First and last name, e-mail address, date of birth, password (stored in hashed form only), language preference, and communication preferences.
5.2 Health data (special category under Art. 9 GDPR / § 22 BDSG). Biometric and physiological data retrieved from connected wearable devices and health data sources, including — where you connect a WHOOP device — recovery data, strain data, sleep metrics (sleep stages, duration, disturbances), heart rate, heart rate variability, respiratory rate, blood oxygen levels, and body weight. Additionally: data you enter manually (e.g. dietary notes, symptom logs, mood entries); results from laboratory or blood tests you upload or permit us to import; and the AI-generated Data Analysis Reports and physician-authored Recommendations generated within the Platform.
5.3 Usage and technical data. IP address (anonymised or pseudonymised where practicable), browser type and version, operating system, referring URL, pages visited, timestamps, session duration, and clickstream data.
5.4 Payment data. Transaction metadata (amount, date, subscription tier). Full payment card data is processed exclusively by our payment service provider; we do not store or have access to full card numbers.
5.5 Communications data. Content of support requests and correspondence you address to us.
6. Purposes and Legal Bases for Processing
6.1 Provision of the Platform — contractual necessity and explicit consent. Legal bases: Art. 6(1)(b) GDPR (performance of a contract) for account and usage data; Art. 9(2)(a) GDPR and § 22(1) No. 1 lit. b BDSG (explicit consent) for health data. We process account data and health data to provide you with personalised Data Analysis Reports and physician-authored Recommendations through the Platform, to connect your health data sources, and to deliver the agreed service. Without this processing, the core service cannot be provided.
6.2 Explicit consent for health data — how it is obtained. Processing special category health data under Art. 9 GDPR requires your explicit, freely given, informed, and granular consent. Consent is obtained as follows: (a) during onboarding, via a separate, active tick-box (not pre-ticked) for each category of health data to be processed; (b) each time you connect a new Third-Party Source, via a further separate consent prompt specific to that data source. Each consent is purpose-specific and independently revocable. Consent is not bundled with acceptance of these Terms or any other consent. You may withdraw any consent at any time with effect for the future, via the in-Platform consent management settings — the withdrawal mechanism is as simple as the original consent (one click). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
6.3 Technical operation and security — legitimate interest. Legal basis: Art. 6(1)(f) GDPR. We process usage and technical data to maintain, secure, and improve the Platform, to detect and prevent fraud and abuse, and to diagnose technical errors. Our legitimate interest in secure and reliable Platform operation is balanced against users' privacy interests, and we apply appropriate technical and organisational minimisation measures (pseudonymisation, short retention periods for logs).
6.4 Legal compliance. Legal basis: Art. 6(1)(c) GDPR. We process data to the extent required by applicable law, including tax and commercial record-keeping obligations under §§ 147 AO and 257 HGB.
6.5 Anonymised and aggregated analytics. Fully anonymised and aggregated data from which no individual can reasonably be re-identified does not constitute personal data within the meaning of Art. 4(1) GDPR and falls outside the GDPR's scope. We may use such data to improve Platform functionality and for statistical analysis.
6.6 No use for advertising. We do not use health data for advertising, marketing, or profiling for commercial purposes. We do not sell personal data to any third party.
6.7 Server log files. When you access the Platform, our servers automatically record connection data in server log files. This data includes: date and time of access; requested URL and HTTP method; HTTP response status code; volume of data transferred; browser type and version; operating system; and referring URL. This data is not linked to your user account unless required for security investigations or to defend or assert legal claims. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is in the technically reliable, secure, and optimised operation of the Platform. Retention: up to 90 days, consistent with section 12.5.
6.8 Contact and enquiry processing. When you contact us by e-mail or through any contact function on the Platform (including at hello@the-key.health or privacy@the-key.health), we process your name, e-mail address, and the content of your message in order to respond to your enquiry and, where applicable, to perform our contractual obligations. Legal basis: Art. 6(1)(b) GDPR where the enquiry relates to your subscription or a pre-contractual request; Art. 6(1)(f) GDPR (our legitimate interest in handling enquiries effectively and maintaining service quality records) in all other cases. For enquiries relating to data subject rights, the legal basis is Art. 6(1)(c) GDPR (legal obligation). Communications data is retained for up to three years from the date of the enquiry, consistent with standard limitation periods under §§ 195, 199 BGB.
6.9 Mobile application. If you access the Platform via our mobile application, we collect additional technical data necessary to provide and maintain the app, including device type, operating system version, app version, anonymised device identifier, and crash reports. Legal basis: Art. 6(1)(b) GDPR (necessary for provision of the mobile app service). Where you have granted permission for push notifications, we also process your device push token to deliver in-Platform notifications (e.g. when a new Recommendation is available). Legal basis for push notifications: Art. 6(1)(a) GDPR (your consent). You may withdraw consent for push notifications at any time through your device operating system settings. Such withdrawal does not affect the availability of the Platform service.
7. AI-Generated Data Analysis and Physician-Authored Recommendations
7.1 How the service works. The Platform's AI engine aggregates, structures, and visually presents your health data in a structured Data Analysis Report. As part of this presentation, the AI system also: (a) statistically highlights data points that deviate materially from your personal historical baseline or from established laboratory reference ranges; and (b) sorts findings by the degree of statistical change since your previous report. This highlighting and prioritisation is based solely on statistical deviation from measurable reference points. It does not represent a clinical assessment, a risk classification, or a medical opinion. The AI system does not draw clinical conclusions, assess the significance of any finding, or generate recommendations of any kind. The Data Analysis Report — including the statistical highlights and prioritised presentation — is then transmitted to a licensed physician engaged by us. The physician independently reviews the complete Data Analysis Report, applies their own professional medical judgment, determines the clinical relevance of any highlighted or prioritised finding, draws their own conclusions from the data, and on that basis formulates a personalised Recommendation. This is not an automated approval process. No Recommendation is delivered to you before the physician has completed their independent review.
7.2 Automated processing, profiling, and Art. 22 GDPR. The AI-generated Data Analysis Report constitutes automated processing of personal data, including health data, for the purpose of analysing aspects of your physical health. Specifically, the statistical highlighting and prioritisation described in section 7.1 constitutes profiling within the meaning of Art. 4(4) GDPR, as it involves automated processing to evaluate aspects of your health based on your personal data. The logic applied is: data points are highlighted where they deviate by a statistically material margin from your own historical baseline or from published laboratory reference ranges; findings are then sorted by the magnitude of change since your previous report. No weighting by clinical significance is applied by the AI. The Data Analysis Report — including its highlights and prioritisation — is not itself a decision that produces legal effects or similarly significantly affects you within the meaning of Art. 22(1) GDPR: no Recommendation is delivered to you based on the automated report alone. The physician's independent assessment and Recommendation is the sole output delivered to you, and the physician independently determines the clinical relevance of any highlighted finding. Accordingly, Art. 22 GDPR does not apply to prevent this processing. You nonetheless have the right to obtain information about the logic involved in the automated analysis and statistical profiling, and to request human review of any Recommendation, by contacting privacy@the-key.health.
7.3 Physician as joint controller. The licensed physicians who independently review Data Analysis Reports and formulate Recommendations exercise independent professional judgment and, in doing so, act as joint controllers (gemeinsam Verantwortliche) with us within the meaning of Art. 26 GDPR with respect to the health data they access and the Recommendations they author. We have concluded joint controller agreements with the physicians engaged by us. The essence of this arrangement is: ACW Consulting GmbH is responsible for the collection, aggregation, AI analysis, and delivery infrastructure; the physician is responsible for the independent medical review and the Recommendation. You may exercise your data subject rights against either controller. The primary contact for data subject rights is privacy@the-key.health. The essence of the joint controller agreement is set out above; the full agreement is available to you on request by contacting privacy@the-key.health.
8. WHOOP API Data — Specific Processing Rules
8.1 Data retrieved via the WHOOP Developer API is accessed exclusively under OAuth 2.0 authorisation and is subject to the WHOOP API Terms of Use. You may revoke the API authorisation at any time via your WHOOP account settings or within the Platform.
8.2 WHOOP data is used solely for the purpose of generating your Data Analysis Report and Recommendation within the Platform. It is not sold, sublicensed, or shared with any third party beyond what is strictly necessary to provide the Platform service.
8.3 WHOOP data is processed on servers located within the European Economic Area. We do not use WHOOP data for competitive benchmarking or for any purpose other than delivering the Platform service to you.
8.4 Physician access. Physicians engaged by us as joint controllers access your WHOOP-sourced and other health data solely to generate personalised Recommendations. Physicians are bound by professional secrecy (ärztliche Schweigepflicht) and by joint controller agreements.
9. Cookies and Tracking Technologies
9.1 Technically necessary cookies. We use technically necessary cookies and similar technologies that are essential for the Platform to function (e.g. session cookies for login, security tokens). Legal basis: § 25(2) No. 2 TDDDG (strictly necessary for the telemedia service expressly requested). No consent is required for these technologies.
9.2 Analytics and optional cookies. We use analytics and optional cookies only with your prior, specific, and informed consent. Legal basis: § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. Consent is obtained via the cookie consent banner displayed on your first visit. You may update your preferences at any time through the cookie settings in the Platform footer. Withdrawal of consent for analytics cookies does not affect prior processing.
9.3 Analytics tools. Where we use third-party analytics tools (such as Google Analytics or privacy-focused alternatives), we list the specific tools in the cookie consent banner. Where tools involve transfers of data to third countries (e.g. Google Analytics involving US-based processing), we rely on the EU-US Data Privacy Framework (DPF) adequacy decision (July 2023) where the provider participates in the DPF, or on EU Standard Contractual Clauses (SCCs) as an alternative safeguard. We have concluded Data Processing Agreements under Art. 28 GDPR with all analytics providers. Where required by BayLDA guidance, IP anonymisation is enabled and full IP addresses are not transmitted.
10. Sharing and Disclosure of Personal Data
10.1 We share your personal data only to the extent necessary and on the following bases.
10.2 Service providers (processors under Art. 28 GDPR). We engage the following categories of processors: cloud hosting providers (servers in the EEA); payment service providers; e-mail delivery services; customer support tooling; IT security and monitoring services. All processors are bound by Data Processing Agreements and may process data only on our documented instructions and in accordance with GDPR.
10.3 Physicians (joint controllers under Art. 26 GDPR). As described in section 7.3, physicians engaged by us access your health data as joint controllers to generate Recommendations.
10.4 Legal requirements. We may disclose personal data where required to do so by law, court order, or governmental authority, or where necessary to assert or defend our legal rights.
10.5 Corporate transactions. In the event of a merger, acquisition, reorganisation, or sale of assets, personal data may be transferred to the relevant successor entity, subject to equivalent data protection obligations. You will be notified in advance where required by law.
10.6 No sale of data. We do not sell personal data. We do not share health data for advertising, profiling, or marketing.
11. International Transfers
Where we transfer personal data to third countries outside the EEA (e.g. where a sub-processor is US-based), we ensure that an appropriate safeguard under Art. 46 GDPR is in place: either an adequacy decision (e.g. the EU-US Data Privacy Framework for DPF-certified US recipients), EU Standard Contractual Clauses adopted by the European Commission, or another recognised mechanism. You may request details of the applicable transfer mechanism for specific processors by contacting privacy@the-key.health.
12. Retention Periods
12.1 Account and contact data. Retained for the duration of the contract (active account) and for up to three years thereafter, to handle claims within the applicable limitation periods under §§ 195, 199 BGB, unless a longer period is required by law.
12.2 Health data. Retained for the duration of your account. Following account closure or upon your valid deletion request, health data is deleted within 30 days. We do not invoke § 630f BGB (medical documentation obligation) as a general basis for retaining health data, as the physician-user interaction on this Platform does not ordinarily constitute a treatment relationship within the meaning of §§ 630a et seq. BGB. However, where a specific physician interaction constitutes telemedicine within the meaning of § 7(4) MBO-Ä, the documentation obligations of the applicable Ärztekammer rules may require retention of the relevant Recommendation beyond account closure; in such cases we will retain only the specific Recommendation concerned and will inform you at the time. If any other specific legal obligation requiring retention arises, we will communicate this to you at the time.
12.3 Physician Recommendations. Retained for the duration of your account and for 3 years thereafter, as evidence of the professional advice provided, consistent with general statutory limitation periods.
12.4 Payment and transaction data. Retained for 10 years in accordance with § 147 AO and § 257 HGB.
12.5 Usage and log data. Retained for up to 90 days for security and debugging purposes, then deleted or irreversibly anonymised.
12.6 Anonymised data. Fully anonymised and aggregated data may be retained indefinitely as it cannot be attributed to any individual.
13. Your Rights as a Data Subject
Under the GDPR and BDSG, you have the following rights. To exercise any of them, contact privacy@the-key.health. We will respond within one calendar month of receipt (extendable by a further two months where necessary, with notification to you).
- (a) Right of access (Art. 15 GDPR): You may request a copy of the personal data we hold about you and information about how we process it, including the logic of any automated processing affecting you.
- (b) Right to rectification (Art. 16 GDPR): You may request correction of inaccurate or completion of incomplete personal data.
- (c) Right to erasure (Art. 17 GDPR): You may request deletion of your personal data, subject to statutory exceptions (e.g. legal retention obligations under § 147 AO).
- (d) Right to restriction of processing (Art. 18 GDPR): You may request that we restrict processing in certain circumstances (e.g. while accuracy is disputed).
- (e) Right to data portability (Art. 20 GDPR): Where processing is based on consent or contract, you may request your data in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller.
- (f) Right to object (Art. 21 GDPR): You may object at any time to processing based on our legitimate interests (Art. 6(1)(f)). We will cease that processing unless we can demonstrate compelling legitimate grounds that override your interests. You also have the right to object to processing for direct marketing purposes, including profiling related to direct marketing, at any time and without giving reasons.
- (g) Rights regarding automated decision-making (Art. 22 GDPR / § 37 BDSG): You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. As explained in section 7.2, no such fully automated decision is made in our service; the physician's independent review ensures human involvement in every Recommendation. You may nonetheless request information about the logic of the automated analysis and ask for human review of any Recommendation.
- (h) Right to withdraw consent (Art. 7(3) GDPR): You may withdraw consent for the processing of health data at any time. Withdrawal is as simple as giving consent: use the one-click consent management settings within the Platform, or contact privacy@the-key.health. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- (i) Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with the competent supervisory authority. The authority competent for ACW Consulting GmbH (Bavaria) is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, Germany (www.lda.bayern.de). You may also lodge a complaint with the supervisory authority in your country of residence or place of work.
14. Children
The Platform is not directed at persons under the age of 18. We do not knowingly collect personal data from persons under 18. If we become aware that a user is under 18, we will suspend the account and delete the associated personal data without undue delay. If you believe a person under 18 has registered, please notify us at privacy@the-key.health.
15. Data Security
We implement appropriate technical and organisational measures (TOMs) in accordance with Art. 32 GDPR and § 22(2) BDSG to protect your personal data against unauthorised access, loss, destruction, or unlawful disclosure. Our measures include: end-to-end encryption in transit (TLS/HTTPS); encryption at rest for health data and Recommendations; strict access controls and least-privilege principles; regular security testing and vulnerability management; due-diligence vetting of processors. In the event of a personal data breach, we will notify the BayLDA within 72 hours of becoming aware of the breach (Art. 33 GDPR) and, where the breach is likely to result in a high risk to your rights and freedoms, notify you without undue delay (Art. 34 GDPR).
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes (including changes to the categories of data collected, processing purposes, or recipients) by e-mail and in-Platform notice at least 30 days before the changes take effect. Where a change requires new consent (e.g. a new purpose for processing health data), we will seek that consent separately before processing commences. The date at the top of this document indicates the version currently in force.
17. Contact
For all privacy-related enquiries or to exercise your data subject rights: ACW Consulting GmbH | Nördliche Hauptstraße 20 | 83700 Rottach-Egern | Germany | E-mail: privacy@the-key.health