Privacy Policy

Last updated: June 23, 2025

English version • Version française ci-dessous

Privacy Policy

Last updated: June 23, 2025

This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.

We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy. This Privacy Policy has been created with the help of the Free Privacy Policy Generator and updated to comply with applicable privacy laws, including the General Data Protection Regulation (GDPR), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and Loi 25 (Québec).

Interpretation and Definitions

Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

  • Account means a unique account created for You to access our Service or parts of our Service.
  • Affiliate means an entity that controls, is controlled by or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
  • Application refers to Nouri, the software program provided by the Company.
  • Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to Nouri Health Inc., 25 Ch Cedar Cliff Georgeville, Quebec J0B 1T0 Canada.
  • Country refers to: Quebec, Canada
  • Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.
  • Personal Data is any information that relates to an identified or identifiable individual.
  • Service refers to the Application.
  • Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
  • Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
  • You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.

Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:

  • Email address
  • First name and last name
  • Usage Data

Usage Data

Usage Data is collected automatically when using the Service.

Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.

Data from Third-Party Devices

With your consent, we collect wellness and health-related data from third-party wearables, such as Whoop or Oura, to provide personalized nutrition and lifestyle recommendations. This may include metrics such as:

  • Heart Rate Variability (HRV)
  • Resting Heart Rate (RHR)
  • Sleep duration and quality
  • Physical strain and recovery indicators

This data is processed securely and exclusively for providing tailored advice within the app.

Use of Your Personal Data

The Company may use Personal Data for the following purposes:

  • To provide and maintain our Service, including to monitor the usage of our Service.
  • To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
  • For the performance of a contract: the development, compliance and undertaking of the purchase contract for the products, items or services You have purchased or of any other contract with Us through the Service.
  • To contact You: To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
  • To provide You with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless You have opted not to receive such information.
  • To manage Your requests: To attend and manage Your requests to Us.
  • For business transfers: We may use Your information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about our Service users is among the assets transferred.
  • Tracking Technologies and Analytics: We and our service providers (e.g., Firebase, Mixpanel) may use SDKs, cookies, or similar technologies to collect usage and device information (IP address, crash logs, engagement metrics). This data is processed under our legitimate interests to improve the Service. You can opt out in your device settings or by contacting our Privacy Officer.
  • For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Service, products, services, marketing and your experience.

Legal Basis for Processing Personal Data

If you are located in the European Economic Area (EEA), we process your personal data in accordance with the General Data Protection Regulation (GDPR). If you are located in Canada, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA), and if you reside in Québec, also with Loi 25.

Your data is processed based on one or more of the following legal bases:

  • Your consent
  • The performance of a contract
  • Our legitimate interests
  • Compliance with legal obligations

Right to Lodge a Complaint

If you believe that we have not complied with applicable privacy laws, you may file a complaint with:

Commission d'accès à l'information du Québec (CAI): https://www.cai.gouv.qc.ca

or, if you're in the EEA, your local data protection authority.

Security Measures

We take the security of your data seriously and implement industry-standard safeguards, including:

  • SSL encryption for data in transit
  • Secure password and login systems
  • Role-based access controls for staff
  • Network monitoring software and firewalls
  • Routine data backups
  • Limited access to personal data based on necessity

While no system is fully immune to risks, we continuously evaluate and upgrade our infrastructure to maintain a high level of security.

Notification of Confidentiality Incidents

In the event of a privacy breach posing a serious risk of harm, we will:

  • Notify the Commission d'accès à l'information du Québec (CAI) as soon as feasible, and
  • Communicate without undue delay to affected users the nature of the breach, the likely consequences, and measures taken to mitigate harm.

If you have questions about a notification, contact our Privacy Officer.

Children's Privacy

Our Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If you are a resident of the European Union, you must be at least 16 years old to use the Service, unless your country allows for a lower age with parental consent.

If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 13 without verification of parental consent, We take steps to remove that information from Our servers.

Person Responsible for Privacy

For any questions regarding the protection of personal information, you may contact our Privacy Officer:

Name: Lambert Lefebvre

Role: CEO & Privacy Officer

Email: support@nourihealth.com

Address: 25 Ch Cedar Cliff, Georgeville, Quebec, J0B 1T0, Canada

Politique de confidentialité de Nouri

Dernière mise à jour : 23 juin 2025

Cette politique de confidentialité décrit nos pratiques concernant la collecte, l'utilisation et la divulgation de vos renseignements personnels lorsque vous utilisez notre service. Elle vous informe de vos droits ainsi que des protections légales dont vous bénéficiez.

En utilisant le Service, vous consentez à la collecte et à l'utilisation de vos données personnelles telles que décrites ci-dessous. Cette politique a été élaborée avec l'aide du Free Privacy Policy Generator et mise à jour pour se conformer au Règlement général sur la protection des données (RGPD), à la Loi sur la protection des renseignements personnels et les documents électroniques (LPRPDE) et à la Loi 25 du Québec.

Définitions

  • Account : compte unique créé pour vous permettre d'accéder à notre Service ou à certaines parties de celui-ci.
  • Affiliate : entité qui contrôle, est contrôlée par, ou est sous contrôle commun avec une partie, où "contrôle" signifie la propriété de 50 % ou plus des actions ou titres donnant droit de vote.
  • Application : Nouri, le programme fourni par la Société.
  • Société : Nouri Health Inc., 25 Ch Cedar Cliff, Georgeville (Québec) J0B 1T0, Canada.
  • Pays : Québec, Canada.
  • Device : tout appareil pouvant accéder au Service (ordinateur, téléphone, tablette).
  • Données personnelles : toute information se rapportant à une personne physique identifiée ou identifiable.
  • Service : l'Application.
  • Prestataire de services : personne physique ou morale traitant des données pour le compte de la Société.
  • Données d'utilisation : données collectées automatiquement, générées par l'utilisation du Service ou son infrastructure (durée de visite, diagnostics, etc.).
  • Vous : l'utilisateur accédant ou utilisant le Service.

Types de données collectées

  • Données personnelles : prénom, nom, adresse courriel.
  • Données d'utilisation : adresse IP, type/version de navigateur, pages visitées, date et heure de visite, durée, identifiants d'appareil, autres données de diagnostic.

Données issues de dispositifs tiers

Avec votre consentement explicite, nous recueillons des données de bien-être provenant de dispositifs connectés (Whoop, Oura), telles que :

  • Variabilité de la fréquence cardiaque (VFC)
  • Fréquence cardiaque au repos (FCR)
  • Durée et qualité du sommeil
  • Niveaux d'effort physique et de récupération

Ces données sont traitées de façon sécurisée et exclusivement pour la personnalisation des recommandations.

Utilisation de vos renseignements personnels

Nous pouvons utiliser vos données pour :

  • Fournir et maintenir le Service
  • Gérer votre compte utilisateur
  • Exécuter un contrat (achats, abonnements)
  • Vous contacter (e-mail, SMS, notifications push)
  • Vous envoyer des informations ou offres promotionnelles, si vous y avez consenti
  • Répondre à vos demandes
  • Réaliser des analyses internes et améliorer notre Service

Responsable de la protection des renseignements personnels

Nom : Lambert Lefebvre

Fonction : PDG & Responsable de la protection des renseignements personnels

Courriel : support@nourihealth.com

Adresse : 25 Ch Cedar Cliff, Georgeville, Québec, J0B 1T0, Canada