1. Subject of this Privacy Notice
AIRMID-MED Korlátolt Felelősségű Társaság (hereinafter: the "Controller" or "Operator") hereby informs users about its activities related to the data concerning persons using the HELIX+ Health Monitoring Station, HELIX+ APP- and HELIX+ APP by AIRMID-MED mobile application (hereinafter: the "HELIX+ Tool") and the HELIX+ services.
By using the HELIX+ Tool, users can, on the basis of voluntarily performed measurements uploaded to the HELIX+ system by themselves or by service providers connected to the HELIX+ system, as well as on the basis of data recorded by them in the HELIX+ Tool, become aware of and regularly monitor their current state of health. The measured values help in the development of individual health strategies, contribute to setting goals and achieving them quickly and effectively, and changes can be monitored by regular checks.
The HELIX+ Tool is a non-medical mobile application that displays data from measurements performed on various measuring devices for the purpose of assessing general fitness. The purpose of regular fitness measurements is to understand the general level of fitness and to monitor changes, in particular for planning activity programmes or for monitoring and demonstrating the effects of any activity and training system or weight-loss programme.
In the case of fitness measurements, the accuracy of some measurement results may be significantly influenced by the fact that a number of factors related to the individual measuring devices may affect the measurements. Therefore, fitness measurements cannot be considered as medical measurements; the assessment of these measurement results serves only the purposes of assessing general fitness and does not replace medical measurements.
Factors that may influence the measurement results include, for example, in the case of body weight measurement, the varying weight of clothing, in the case of body height the height of shoes and heels, and, in the case of several measurements, the use of fitness measurement methods differing from the medical measurement protocol.
Warning! The HELIX+ Tool is not a medical application. The HELIX+ Tool does not qualify as a medical device and does not provide any diagnosis or therapeutic recommendation.
Before making any health-related decision, please consult a doctor or healthcare professional in advance.
When the HELIX+ Tool is used anonymously, the Controller does not seek to identify users and does not process personal data. When the HELIX+ Tool is used, the Controller does not become a data controller in respect of the data collected and disclosed for the purpose of health status assessment.
2. Creation of a HELIX+ Programme User Account
At the express request of users, Partner Service Providers connected to the HELIX+ Programme may create a registered user account for users.
Once a HELIX+ user account has been created, users can access their previously recorded data even if they change their mobile device, and may use services of the HELIX+ Programme that are available only to users holding a HELIX+ user account, and can identify themselves when using such services.
By creating a HELIX+ Programme user account, the Controller becomes a data controller with regard to the registered user and, in accordance with this Privacy Notice, informs the data subject – in a clear, intelligible and detailed manner – about all facts related to the processing of his/her personal data, in particular about the purpose and legal basis of the processing, the categories of persons entitled to access the personal data, the period of processing, and about the fact that the Controller processes the data subject’s personal data for the performance of the contract, on the basis of the data subject’s consent and/or for compliance with a legal obligation to which the Controller is subject, or for the purposes of the legitimate interests of the Controller or a third party.
This information also covers the data subject’s rights and remedies in relation to the processing.
2.1. Information on data processing – General principles
The data processing principles of the HELIX+ Programme are in line with the applicable data protection legislation, in particular:
The personal data of the data subject are processed only to the extent necessary to achieve the purposes set out below. The Controller examines at all stages of the processing whether the processing complies with the purpose. The GDPR does not apply to anonymised statistical data or to statistical data that do not contain personal data.
2.2. Information on data processing – HELIX+ user account
Purpose of processing: creation of a HELIX+ Programme user account and enabling users holding a HELIX+ user account to use the services provided by Partner Service Providers of the HELIX+ Programme, and identification of the data subject when using such services.
Legal basis of processing: processing is based on the conclusion and performance of the HELIX+ Programme Contract (Article 6 (1) (b) GDPR).
Categories of processed data: name, date of birth, gender, e-mail address, phone number, optional supplementary data.
Duration of processing: 5 years from the termination of the contract. Accounting records are retained in accordance with the applicable statutory retention periods.
2.3. Services of Partners connected to the HELIX+ Programme
The concept of the HELIX+ Programme represents a radically new approach to the long-term preservation and maintenance of health. The Programme offers an alternative approach that treats health as a fundamental need and supports health management through proven, high-quality and effective methods, typically at lower cost. Its online platform connects the user with the Partners of the HELIX+ Programme and the services and opportunities provided by them.
On the basis of the data recorded on the platform, authorised Partner Service Providers of the HELIX+ Programme can monitor changes in the data subject’s physical characteristics and activity, which supports the provision of the service used and the development of further recommendations.
Purpose of processing: provision of services by Partner Service Providers of the HELIX+ Programme.
Legal basis of processing: processing is based on the performance of the contract and the data subject’s voluntary consent (Article 6 (1) (b) GDPR, and Articles 6 (1) (a) and 9 (2) (a) GDPR).
Categories of processed data: user account data, other personal data relating to physical activity and fitness recorded or measured by the user or by a Partner Service Provider of the HELIX+ Programme, as well as other personal data provided by the user.
The HELIX+ Programme Partner Service Provider is an independent data controller with regard to the above data. In connection with the processing of the above data within the HELIX+ Programme, the data subject may exercise the rights set out in Section 6 of this Privacy Notice.
The Controller hereby also informs the data subject that requests for rectification, withdrawal, erasure, restriction or objection concerning the above data can only be handled by the Controller in respect of data obtained from the data subject; requests concerning processing by a HELIX+ Programme Partner Service Provider must be submitted by the data subject to the relevant HELIX+ Programme Partner Service Provider.
Duration of processing: 5 years from the termination of the contract; for data processed on the basis of the data subject’s voluntary consent, until the consent is withdrawn, which the data subject may do at any time via the relevant menu item of the HELIX+ APP by AIRMID-MED mobile application. Accounting records are retained in accordance with the applicable statutory retention periods.
2.4. Services of Partners connected to the HELIX+ Programme
The concept of the HELIX+ Programme represents a radically new approach to the long-term preservation and maintenance of health. The Programme offers an alternative approach that treats health as a fundamental need and supports health management through proven, high-quality and effective methods, typically at lower cost.
3. Details of the Controller
4. Data recorded during anonymous use
When the HELIX+ Tool is used anonymously, users can see the following data provided by themselves:
When using the HELIX+ Measuring Devices, the user may also provide these data by scanning the QR code generated by the HELIX+ Tool. By using the HELIX+ Measuring Devices, users can perform measurements (body weight, body height, body composition, pulse, etc.), which they can link to the data recorded in the HELIX+ Tool.
Users can also upload measurements recorded with their own devices to the HELIX+ system by using their HELIX+ Tool, so that, in addition to measurements performed with HELIX+ Measuring Devices, measurements performed with their own devices and data relating to their recorded physical activity can also be displayed.
The purpose of recording the data is to assess the state of health and to provide health preservation and personal health management services available in the HELIX+ Tool and from HELIX+ Programme Partner Service Providers.
5. Processing and transfer of data, categories of persons entitled to access
The data subject’s data may be accessed, to the extent necessary to achieve the relevant processing purpose, by members and employees of the Controller who have the appropriate access rights, as well as by persons and organisations of HELIX+ Programme Partner Service Providers providing services to the data subject, to the extent and for the duration necessary for their activities.
Categories of processed data: the Controller may use data that do not contain personal data for the following purposes:
Measurement results recorded by the measuring devices are uploaded to the HELIX Smart Care Center central application. In the case of anonymous measurement initiation based on the HELIX+ Tool, the data are supplemented with the anonymous identifier of the HELIX+ Tool, so that they can be viewed in the initiating HELIX+ Tool.
Purpose of processing: creation of statistical databases free of personal data.
Legal basis of processing: in the case of use of a HELIX+ Programme user account, processing is based on the legitimate interests of the Controller (Article 6 (1) (f) GDPR). In the case of anonymous use, this is not applicable.
Duration of processing: the creation and use of the data set for statistical purposes is not subject to any time limitation, as the data do not contain personal data.
The Controller does not transfer data to a third country or to an international organisation.
6. Rights of users
In the case of anonymous use of the HELIX+ Tools, the Controller is not able to identify the data subjects; therefore, the exercise of certain data subject rights under the GDPR (right to information, right of access, right to rectification and completion, withdrawal of consent, right to object, remedies, etc.) cannot be ensured vis‑à‑vis the Controller. The user may, by using the functions of the HELIX+ Tool, delete or modify the data recorded by him/her in the HELIX+ Tool, access such data, and view or cancel any HELIX+ Programme user account registration.
When a HELIX+ Programme user account is used, the Controller informs the data subject below how he/she may request access to personal data relating to him/her, rectification, erasure or restriction of processing, and how he/she may object to the processing of his/her personal data.
6.1. Right of access
At the data subject’s request, the Controller shall inform him/her whether or not his/her personal data are being processed. Where, on the basis of the Controller’s response, it can be established that the data subject’s personal data are being processed, the Controller shall provide the following information:
6.2. Right to rectification
At the data subject’s request, the Controller shall, without undue delay, rectify inaccurate or incomplete personal data concerning the data subject, where the data were obtained from the data subject and the data subject has provided the correct data.
The Controller informs the data subject that if the data were not obtained from the data subject, the Controller is not able to rectify the data; in such a case, the data subject must request rectification from the HELIX+ Programme Partner Service Provider that recorded the data.
6.3. Right to withdraw consent
Consent to the processing of personal data may be withdrawn at any time without giving reasons. The withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
The Controller can only handle withdrawal requests in relation to data obtained from the data subject; requests concerning processing by a HELIX+ Programme Partner Service Provider must be submitted by the data subject to the relevant HELIX+ Programme Partner Service Provider.
6.4. Right to erasure (‘right to be forgotten’)
At the data subject’s request, the Controller shall, without undue delay, erase personal data concerning the data subject where one of the following grounds applies:
Personal data shall not be erased where processing is necessary for one of the following reasons:
The Controller can only handle requests for erasure in relation to data obtained from the data subject; requests concerning processing by a HELIX+ Programme Partner Service Provider must be submitted by the data subject to the relevant HELIX+ Programme Partner Service Provider.
6.5. Right to restriction of processing
At the data subject’s request, the Controller shall, without undue delay, restrict processing where one of the following grounds applies:
Where processing is restricted as described above, such personal data shall, with the exception of storage, only be processed with the data subject’s consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest.
The Controller can only handle requests for restriction in relation to data obtained from the data subject; requests concerning processing by a HELIX+ Programme Partner Service Provider must be submitted by the data subject to the relevant HELIX+ Programme Partner Service Provider.
6.6. Right to data portability
At the data subject’s request, the Controller shall provide the data subject with a copy of the personal data concerning him/her, which he/she has provided to the Controller, in a structured, commonly used and machine-readable format.
6.7. Right to object
At the data subject’s request in which the data subject objects to the processing, the Controller shall no longer process the personal data.
After the submission of the request, the Controller may demonstrate that compelling legitimate grounds for the processing override the interests, rights and freedoms of the data subject or are related to the establishment, exercise or defence of legal claims.
The Controller can only handle objections in relation to data obtained from the data subject; objections concerning processing by a HELIX+ Programme Partner Service Provider must be submitted by the data subject to the relevant HELIX+ Programme Partner Service Provider.
6.8. Exercising users’ rights
Requests under Sections 6.1–6.7 may be submitted by e-mail to gdpr@helixplus.app, indicating the data subject’s e-mail address and name. The Controller shall inform the data subject of the measures taken in response to the request by e-mail without undue delay and at the latest within one month of receipt of the request.
The Controller shall provide the requested information and communication free of charge. Where the data subject’s requests relating to Sections 6.1–6.7 are manifestly unfounded or – in particular because of their repetitive character – excessive, the Controller may, taking into account the administrative costs of providing the information or communication or taking the requested action, charge a reasonable fee or refuse to act on the request.
The Controller may refuse to act on a request concerning the exercise of the data subject’s rights referred to in Sections 6.1–6.7 if it can demonstrate that it is not in a position to identify the data subject. Where the Controller is able to identify the data subject but has reasonable doubts as to the identity of the person making the request, it may request that the requester provide additional information necessary to confirm his or her identity.
Where necessary, taking into account the complexity of the request and the number of requests, the one-month period referred to above may be extended by a further two months. The Controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay. If the data subject has submitted the request electronically, the information shall be provided by electronic means, unless the data subject requests otherwise.
If the Controller does not act on the data subject’s request, the Controller shall inform the data subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
The Controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with the data subject’s request to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. At the data subject’s request, the Controller shall inform the data subject about those recipients.
The Controller shall provide the data subject with a copy of the personal data undergoing processing. If the data subject submits the request electronically, the information shall be provided in a commonly used electronic form.
7. Data security
The Controller ensures the security of the data and takes the technical measures necessary to ensure that the data collected, stored and processed are protected, and takes all necessary steps to prevent their destruction, unauthorised use and unauthorised alteration.
8. Remedies
The data subject has the right to lodge a complaint with the competent supervisory authority if the Controller infringes the provisions of the GDPR when processing data concerning him/her. Complaints may be lodged with the Hungarian National Authority for Data Protection and Freedom of Information at the following contact details:
If the data subject’s rights are infringed, he or she may bring an action before a court against the Controller. The competent court shall be the tribunal having jurisdiction over the data subject’s place of residence or stay.
9. Other provisions
The Controller reserves the right to unilaterally amend this Privacy Notice.
This Privacy Notice is effective as of 1 June 2026.