Global Privacy Policy
Last updated: 16 July 2026 Effective date: 16 July 2026
This Global Privacy Policy explains how Bay Technologies Limited (“Bay Technologies,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal data when you use our websites, mobile applications, smart devices, membership programmes, communities, events, customer support, and related products and services.
It applies to services offered under Xinera by FoodTrack, Xinera, FoodTrack, and any other Bay Technologies brand or service that links to this Policy (together, the “Services”). References to the Services include connected products such as smart rings, smart scales, and other wellness devices; AI-powered food, face, tongue, lifestyle, and wellness insights; subscriptions and memberships; community features; partner offers and benefits; and related websites and applications.
This Policy is a privacy notice. It is not a request for consent. Where consent is required—for example, for certain sensitive wellness data, device permissions, direct marketing, or international transfers—we will ask for it separately and allow you to withdraw it as required by law.
1. Who is responsible for your personal data
Unless a service-specific notice says otherwise, the controller, data user, business, regulated entity, personal information processor, or equivalent entity responsible for your personal data is:
Bay Technologies Limited No. 19 Science Park West Avenue Hong Kong Science Park, Pak Shek Kok New Territories, Hong Kong Email: info@gbat.ai
When we provide the Services through an employer, insurer, healthcare or wellness provider, university, school, merchant, distributor, event organiser, or other organisation, that organisation may also be responsible for some personal data. Section 17 explains these arrangements.
2. Key privacy commitments
We design the Services around the following commitments:
- We collect personal data for specified purposes and seek to limit collection to what is reasonably necessary.
- We treat health, wellness, device, face, tongue, and similar data as sensitive, whether or not local law uses that label.
- We do not sell consumer health data.
- We do not use sensitive wellness data for third-party targeted advertising.
- We do not use a face or tongue image to recognise your identity or create a facial-recognition identity template unless we clearly disclose that separate feature and obtain any legally required consent.
- We do not allow a third-party AI provider to use your identifiable sensitive wellness data to train its own general-purpose models unless we clearly disclose this and obtain any legally required consent.
- We use appropriate contractual, organisational, and technical safeguards for service providers and international transfers.
- We provide privacy choices and honour applicable rights without unlawful discrimination.
3. Personal data we collect
What we collect depends on the Services you use, the features you enable, your device permissions, and your location.
3.1 Account, identity, and profile data
We may collect your name, username, account identifier, password or authentication credential, date of birth or age range, sex or gender where relevant to a feature, profile photo, language, time zone, country or region, email address, telephone number, delivery address, membership status, referral information, and preferences.
Some fields are optional. If information is required to create an account, deliver a product, process a subscription, or provide a requested feature, we will identify it as required. Without it, we may be unable to provide that part of the Services.
3.2 Health, wellness, nutrition, and lifestyle data
Depending on your choices, we may collect:
- height, weight, body composition, body measurements, age, sex, and similar profile data;
- dietary preferences, allergies or intolerances, meal logs, food photographs, ingredients, estimated calories, macronutrients, micronutrients, sugar, cholesterol, purines, hydration, and other nutrition-related information;
- activity, exercise, steps, sedentary time, energy expenditure, recovery, habits, goals, and progress;
- sleep duration, timing, stages, regularity, and related signals;
- heart rate, heart-rate variability, blood-oxygen estimates, skin or body temperature where supported, stress or recovery indicators, and other measurements generated by a connected device;
- symptoms, health goals, self-reported conditions, medications or supplements, risk factors, menstrual or reproductive information if an optional feature collects it, and other information you choose to provide;
- tongue, face, meal, body, or other images you submit, together with characteristics, scores, classifications, or other inferences produced from them; and
- wellness insights informed by Western nutrition science, Traditional Chinese wellness concepts, behavioural data, or a combination of these.
The Services are intended for general wellness and informational purposes unless a specific regulated service expressly states otherwise. Some data described above may be considered health data, consumer health data, sensitive personal data, or special-category data under applicable law.
3.3 Smart-device and connected-platform data
If you pair a smart ring, smart scale, wearable, phone sensor, or third-party health platform, we may receive device identifiers, firmware and battery information, connection and synchronisation logs, sensor readings, calculated metrics, and the categories of wellness data you authorise the device or platform to share.
You can usually stop future collection by disconnecting the device or platform in the relevant settings. Disconnecting does not automatically delete data already imported into your account; you may use the controls described in Section 12.
3.4 Images, camera access, and derived data
If you use photo-based features, we may access the camera only after device-level permission and collect the images you submit. Our systems may analyse pixels, visual characteristics, metadata, and derived information to provide food recognition, tongue or face wellness analysis, progress tracking, or other requested functions.
Unless we tell you otherwise for a specific feature, we do not use these images to authenticate your identity or match you against a database of faces. Photographs themselves may still be personal data or sensitive data.
3.5 Purchases, subscriptions, membership, and benefits
We may collect information about products or memberships viewed, purchased, activated, delivered, returned, or redeemed; subscription tier and renewal status; smart-device serial number; delivery and fulfilment details; invoices; discount or referral codes; benefit eligibility; partner-benefit selection and redemption; and customer-service history.
Payment-card details are generally collected directly by a payment provider. We may receive limited payment information such as transaction identifier, payment status, card type, billing country, and the last digits of a card, but we do not need to store full card details when a payment provider processes them.
3.6 Community, event, and communications data
We may collect posts, comments, reactions, challenges, group participation, profile visibility, direct messages where the feature supports them, survey responses, event registrations, coaching or consultation bookings, referrals, testimonials, and communications with us.
Information you choose to post in a public or member-visible area can be seen, copied, or reshared by other people according to the feature’s visibility settings. Do not post sensitive information that you do not want others to see.
3.7 Device, usage, cookie, and diagnostic data
We may automatically collect IP address, approximate location derived from IP, device and advertising identifiers where permitted, browser type, operating system, app version, language, time zone, network information, referring URL, pages or screens viewed, taps and feature interactions, session times, crash reports, performance logs, security events, and cookie or software-development-kit data.
We collect precise geolocation only if a feature requires it, we explain the purpose, and you grant the relevant permission. We do not use geofencing around healthcare facilities to identify, track, or target people based on health status.
3.8 Support, research, and other information you provide
We may collect support requests, feedback, call or chat records, troubleshooting data, research or beta-test participation, and any documents or information you choose to provide. We will give additional notice and obtain consent where required for research involving identifiable sensitive data.
3.9 Data from other people and organisations
We may receive personal data from:
- smart devices, Apple Health, Health Connect, or other platforms you connect;
- a person who buys a device, membership, or gift for you;
- a coach, nutritionist, healthcare or wellness professional, or other person you authorise;
- membership, fulfilment, payment, event, merchant, referral, or benefits partners;
- an employer, school, insurer, client, or other sponsoring organisation, subject to its instructions and your applicable choices;
- identity, fraud-prevention, analytics, communications, and security providers; and
- public sources or partners where collection and use are permitted by law.
If you provide personal data about another person, you must have authority to do so and provide any notice or obtain any consent required by law.
4. How we use personal data and our legal bases
We use personal data only when we have a valid basis under applicable law. The bases below may not all apply in every jurisdiction.
| Purpose | Examples | Typical legal basis |
|---|---|---|
| Provide and administer the Services | Create and secure accounts; pair devices; synchronise data; provide food recognition and wellness insights; fulfil orders; administer subscriptions, memberships, benefits, and communities; respond to requests | Performance of a contract; steps requested before a contract; consent where required |
| Process sensitive wellness data | Analyse health, device, nutrition, face, tongue, or similar data to provide requested features | Explicit or separate consent where required; another exception expressly permitted by applicable law |
| Personalise recommendations | Generate meal, activity, sleep, recovery, and habit suggestions; tailor content, goals, reminders, and benefits | Performance of a contract; consent for sensitive data; legitimate interests where permitted |
| Operate AI-enabled features | Analyse user inputs, generate classifications and insights, evaluate quality, and detect errors | Performance of a contract; consent for sensitive data; legitimate interests for safety and non-sensitive improvement |
| Process transactions and benefits | Take payment, deliver devices, validate eligibility, prevent duplicate claims, and enable a selected partner redemption | Performance of a contract; legal obligation; consent where required for disclosure to a partner |
| Communicate with you | Service messages, security alerts, device notices, support responses, and administrative communications | Performance of a contract; legal obligation; legitimate interests |
| Send marketing | News, offers, events, surveys, and promotions for our brands or, where separately authorised, selected partners | Consent or indication of no objection where required; legitimate interests only where law permits |
| Run communities and events | Publish content according to visibility settings; moderate content; enforce community rules; administer challenges and events | Performance of a contract; legitimate interests; consent where required |
| Improve and develop the Services | Debugging, analytics, usability testing, quality evaluation, product research, and development of recognition and recommendation systems | Legitimate interests; consent where sensitive or otherwise required; deidentified or aggregated processing |
| Protect users, the Services, and others | Authentication, fraud and abuse prevention, security monitoring, incident response, investigations, and enforcement | Legitimate interests; legal obligation; protection of vital interests where applicable |
| Meet legal and corporate obligations | Tax, accounting, record-keeping, regulatory response, legal claims, audits, mergers, financing, or restructuring | Legal obligation; legitimate interests; establishment, exercise, or defence of legal claims |
Where we rely on legitimate interests, we consider whether the processing is necessary and proportionate and balance our interests against your rights and reasonable expectations. You may request information about the relevant assessment.
Where processing is based on consent, you may withdraw consent at any time through the available settings or by contacting us. Withdrawal does not affect processing already carried out lawfully. If the relevant data is necessary for a feature, withdrawing consent may mean that feature can no longer operate.
5. AI, inferences, and model improvement
Some Services use machine learning, computer vision, rules-based systems, or generative AI. These systems may analyse information you submit and produce estimates, classifications, scores, insights, or recommendations.
AI-generated outputs can be incomplete or incorrect and should not be treated as a medical diagnosis or a substitute for professional advice. We may use automated tools to personalise the Services, but we do not make decisions based solely on automated processing that produce legal or similarly significant effects on you unless we provide a specific notice, a lawful basis, and any rights required by law, including human review where applicable.
To test, validate, or improve our proprietary recognition and recommendation systems, we may use:
- deidentified or aggregated data that is not reasonably capable of being linked to you; and
- identifiable or pseudonymised images or sensitive wellness data only where we have an appropriate legal basis and obtain separate consent when required.
We apply access restrictions and data-minimisation measures to model-development datasets. We contractually restrict service providers from using personal data for their own purposes. We do not permit a third-party AI provider to use your identifiable sensitive wellness data to train its own general-purpose models unless we disclose that use and obtain any legally required consent.
6. When we disclose personal data
We may disclose personal data to the following categories of recipients for the purposes described in this Policy:
6.1 Service providers and processors
These may include cloud hosting, data storage, database, cybersecurity, authentication, analytics, customer support, communications, payment, logistics, fulfilment, warranty, device connectivity, AI infrastructure, software development, professional advisory, and similar providers. They may process personal data only under appropriate instructions, contracts, or legal duties.
6.2 Device and platform providers
When you connect a third-party device or health platform, data may flow between us and that provider as authorised by you. The provider’s own privacy policy applies to its independent handling of data.
6.3 Partners selected by you
If you choose a meal, fitness, spa, recovery, Traditional Chinese wellness, coaching, merchant, event, insurance, or other community or membership benefit, we may provide the minimum information reasonably needed to confirm eligibility, make a booking, fulfil the request, prevent fraud, or record redemption. We will obtain consent where required. A partner may act as an independent controller for data it receives directly or uses for its own service.
We do not disclose sensitive wellness data to a benefits partner merely because you are eligible for a benefit. If a requested service requires such data, we will identify the data and recipient before disclosure and obtain any required consent.
6.4 Sponsoring organisations and authorised professionals
If an organisation sponsors or administers your access, it may receive account-administration, eligibility, engagement, or aggregate reporting data as described in a service-specific notice. Individual-level wellness data is not shared with the sponsoring organisation unless necessary for the requested service, expressly disclosed, authorised by you, or otherwise permitted by law.
6.5 Affiliates and corporate transactions
We may disclose data to Bay Technologies affiliates that follow protections consistent with this Policy. We may also disclose data in connection with a proposed or completed financing, merger, acquisition, reorganisation, sale of assets, insolvency, or similar transaction, subject to confidentiality and applicable legal requirements.
6.6 Legal, safety, and rights-protection disclosures
We may disclose data when we reasonably believe disclosure is required by applicable law, legal process, or a valid government request, or is necessary to protect the rights, safety, and security of users, Bay Technologies, or others; investigate fraud or misuse; enforce agreements; or establish, exercise, or defend legal claims.
6.7 At your direction or with your consent
We may disclose information to any other recipient you direct or authorise.
7. Sale, targeted advertising, and sensitive data
We do not sell personal data for money. We do not sell consumer health data. We do not share sensitive wellness data for cross-context behavioural or third-party targeted advertising.
Some privacy laws define “sale” or “sharing” broadly and may cover certain advertising or analytics technologies even when no money changes hands. If we use a technology that triggers an opt-out right, we will provide a Your Privacy Choices mechanism, honour applicable browser-based opt-out preference signals such as Global Privacy Control, and describe the relevant practice in the applicable regional notice.
We do not use or disclose sensitive personal data to infer characteristics about you for purposes unrelated to providing or securing the Services. If we introduce a materially different use, we will provide notice and obtain consent where required.
8. Cookies, SDKs, and similar technologies
Our websites and applications may use cookies, pixels, local storage, software-development kits, and similar technologies to:
- keep you signed in and remember settings;
- provide requested functions and maintain security;
- understand performance, errors, and use of the Services;
- measure communications and campaigns; and
- provide advertising only where permitted and consistent with Section 7.
Strictly necessary technologies operate because they are required to provide or secure a requested service. Where required, non-essential analytics or advertising technologies operate only after consent. You can use our cookie banner or Cookie Settings, device settings, and browser controls to manage choices. Withdrawing consent does not remove strictly necessary technologies.
We maintain a separate Cookie Notice or consent interface that identifies material cookie and SDK providers, purposes, and durations where required.
9. International data transfers
Bay Technologies is based in Hong Kong, and recipients described in Section 6 may operate in other countries. As a result, personal data may be accessed, stored, or processed outside the country or region where you live.
Before making a restricted transfer, we use a lawful transfer mechanism where required. Depending on the jurisdiction and transfer, this may include an adequacy decision, contractual protections such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, ASEAN Model Contractual Clauses or comparable contractual safeguards, certification, consent for a specific transfer, or another legally recognised mechanism. We also assess supplementary technical and organisational measures where required.
For Mainland China, Vietnam, South Korea, and other jurisdictions with localisation, security-assessment, filing, certification, impact-assessment, or separate-consent requirements, we will implement the applicable mechanism before a covered transfer. You may contact us for information about relevant destinations and safeguards or to request a copy of an applicable contractual safeguard, subject to lawful redactions.
10. Data retention
We retain personal data for no longer than reasonably necessary for the purposes described in this Policy, including providing the Services, meeting legal obligations, resolving disputes, and protecting rights. Unless a different period is disclosed for a feature or required by law, our target periods are:
| Data category | Target retention period |
|---|---|
| Account and profile data | While the account is active; then deletion or anonymisation from active systems within 90 days, subject to the periods below |
| Wellness, nutrition, image, and connected-device data | While needed for the user-controlled history and Services; then deletion or anonymisation from active systems within 90 days after verified deletion or account closure |
| Raw images submitted for analysis | While needed to provide the feature and user history; earlier deletion where an image setting offers it; otherwise aligned with the related wellness-data period |
| Orders, invoices, payments, subscriptions, and tax records | Up to 7 years after the transaction or relationship ends, or longer if legally required |
| Customer-support and complaint records | Up to 3 years after the matter closes, unless needed longer for a dispute, safety issue, or legal obligation |
| Security, fraud-prevention, and technical logs | Normally up to 24 months; longer where needed to investigate an incident or meet legal obligations |
| Community content | Until deleted by you or the relevant community closes; moderation and enforcement records may be kept for up to 3 years |
| Marketing contacts | Until you opt out or the relationship becomes inactive under our retention rules; we may retain a minimal suppression record to honour the opt-out |
| Consent, privacy-request, and compliance records | Up to 7 years after the relevant action or relationship, where reasonably necessary to demonstrate compliance |
| Deidentified or aggregated data | For as long as it remains deidentified or aggregated and is used for legitimate research, analytics, security, or product-improvement purposes |
Deleted data may remain in encrypted, access-restricted backups until the backup cycle expires, normally within 180 days, unless law permits or requires a longer period. We do not restore deleted data to active use except for security, disaster recovery, or legal necessity.
11. Security
We use administrative, technical, and physical measures designed to protect personal data, taking into account its sensitivity and the risks of processing. Measures may include encryption in transit and at rest where appropriate, access controls, authentication, logging, secure development, vulnerability management, network and endpoint safeguards, employee confidentiality and training, vendor review, incident response, and data minimisation.
No system is completely secure. You are responsible for protecting your credentials and devices and should notify us promptly if you suspect unauthorised account access. If a security incident affects personal data, we will investigate and provide notices to individuals, regulators, or others as required by applicable law.
12. Your choices and privacy rights
Depending on your location and subject to lawful exceptions, you may have the right to:
- know whether we process your personal data and obtain information about collection, sources, purposes, and recipients;
- access or receive a copy of personal data;
- correct inaccurate or incomplete data;
- delete personal data;
- withdraw consent and stop future consent-based processing;
- object to or restrict certain processing;
- receive certain data in a portable format and, where feasible, transmit it to another provider;
- opt out of sale, sharing, targeted advertising, profiling, or direct marketing where applicable;
- limit certain uses or disclosures of sensitive personal data;
- obtain information about, object to, or request human review of certain automated decisions;
- appeal a refusal to act on a request; and
- complain to a privacy or data-protection regulator.
You may exercise available controls in the Services or contact info@gbat.ai. Please state your country or state of residence and the right you wish to exercise. We may verify your identity using information reasonably necessary to protect your account and data. We will not require you to create a new account merely to submit a request where prohibited.
You may use an authorised agent where applicable. We may ask for proof of the agent’s authority and may verify your identity directly. We respond within the period required by applicable law and provide an appeal method if required. We do not unlawfully discriminate against you for exercising a privacy right, although some features cannot function without the data they require.
13. Direct marketing and communications
You may opt out of promotional email by using the unsubscribe link, and may control push notifications in the application or device settings. You may also contact us. Opting out of marketing does not stop service, transaction, security, or legal notices.
We will not use personal data for direct marketing where consent or an indication of no objection is legally required unless we have obtained it. We will not provide personal data to another person for that person’s direct marketing without the specific notice and consent required by law. Opt-out requests are free of charge.
14. Children and teenagers
The general-audience Services are intended for adults aged 18 and over. We do not knowingly collect personal data from a child through the general-audience Services.
If we offer a service specifically for children or teenagers, we will provide an age-appropriate notice, use appropriate age assurance, limit data collection, and obtain verifiable parental or guardian consent where required. Relevant thresholds may include under 13 in the United States, under 14 in Mainland China, the locally specified digital-consent age in the EEA or UK, and under 18 in India and other jurisdictions where the law treats all minors as children for relevant processing.
If you believe a child has provided personal data without required authorisation, contact us. We will investigate and delete or otherwise address the data as required by law.
15. Third-party services and links
The Services may link to or interoperate with third-party websites, applications, devices, benefits, and services. This Policy does not govern a third party’s independent collection or use of personal data. Review that party’s privacy notice before providing data. A link or integration does not mean that we control or endorse the third party’s privacy practices.
16. Regional privacy notices
The provisions below supplement the rest of this Policy. If a regional provision conflicts with another provision, the regional provision controls for individuals protected by that law.
16.1 Hong Kong
Bay Technologies is a “data user” under the Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”).
Collection and consequences. Providing optional profile, community, marketing, research, or connected-device information is voluntary. Information identified as required is necessary to create or secure an account, deliver a purchase, administer a membership, or provide the requested feature. If you do not provide required information, we may be unable to provide that service.
Purposes and transfers. The purposes of use and classes of transferees are described in Sections 4 and 6. They include Bay Technologies affiliates; technology, payment, fulfilment, customer-service, professional, and security providers; benefit partners you select; sponsoring organisations as specifically disclosed; and authorities or transaction parties where legally appropriate.
Direct marketing. Subject to your consent or indication of no objection where required, we may use your name, contact details, profile and preference data, transaction or membership history, and non-sensitive engagement data to market wellness applications, smart devices, memberships, community events, nutrition or fitness services, and related Bay Technologies or selected partner offerings. We will not use sensitive wellness data for direct marketing. We will not provide personal data to another person for that person’s direct marketing without the written consent required by the PDPO. You may opt out free of charge.
Access and correction. You may request access to and correction of personal data under the PDPO by contacting us. We may use the statutory form and charge a fee permitted by law for an access request. You may also complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong.
16.2 European Economic Area, United Kingdom, and Switzerland
Bay Technologies is the controller unless a service-specific notice identifies another controller. Section 4 states the purposes and typical lawful bases. Health and similar data may be special-category data; where required, we generally rely on your explicit consent to process it for the requested wellness feature. We may rely on another exception only when applicable and disclosed.
You may have rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and complaint. Where processing is based on legitimate interests, you may object based on your particular situation. Where personal data is processed for direct marketing, you may object at any time.
We do not currently use solely automated decisions that produce legal or similarly significant effects as part of the general Services. If that changes, we will give specific information about the logic involved, significance and expected consequences, and available safeguards.
International transfers are handled as described in Section 9. You may lodge a complaint with the supervisory authority where you live or work or where an alleged infringement occurred. Where applicable law requires Bay Technologies to appoint a local representative, current representative contact details will be made available in the relevant service or Privacy Centre and may also be obtained from info@gbat.ai.
16.3 United States—state consumer privacy notice
This subsection provides additional information for residents of California and other US states with applicable comprehensive privacy laws. The terms “personal information,” “sensitive personal information,” “sale,” “sharing,” “targeted advertising,” and similar terms have the meanings given by applicable law.
During the preceding 12 months, we may have collected the categories below, depending on the Services used. We use them for the purposes in Section 4 and disclose them to the recipient categories in Section 6.
| Category | Examples | Main sources | Categories disclosed for operational/business purposes | Sold or shared for cross-context behavioural advertising |
|---|---|---|---|---|
| Identifiers and account data | Name, email, telephone, account ID, IP address, device ID | You; devices; sponsoring organisations; service providers | Cloud, authentication, communications, support, security, fulfilment, and professional providers | No |
| Customer records and transaction data | Address, membership, subscription, purchase, delivery, limited payment details | You; payment, commerce, and fulfilment providers | Payment, commerce, fulfilment, warranty, support, accounting, and professional providers | No |
| Commercial information | Products viewed or purchased, benefit eligibility and redemption | You; our Services; selected partners | Commerce, fulfilment, selected benefit, analytics, support, and professional providers | No |
| Internet or electronic activity | App and website use, interactions, cookies, crash and diagnostic data | Your browser, app, device, and service providers | Hosting, security, analytics, communications, and support providers | No, unless a separately disclosed optional technology is treated as sharing and an opt-out is provided |
| Approximate or precise geolocation | IP-derived region; precise location only for a permission-based feature | Device and network | Hosting, security, analytics, or feature provider as necessary | No |
| Audio, visual, or similar data | Food, face, tongue, and profile images; support recordings where disclosed | You; device camera; support interactions | Hosting, AI-processing, support, security, and professional providers | No |
| Sensitive personal information and consumer health data | Account credentials; wellness, nutrition, device, sleep, vital-sign, health, and derived data; precise location if used | You; connected devices and platforms; authorised persons | Hosting, device connectivity, AI-processing, security, and user-selected service or benefit providers | No |
| Inferences and preferences | Wellness insights, goals, classifications, recommendations, interests | Derived from the categories above | Hosting, AI-processing, analytics, support, and professional providers | No |
| Community and communications content | Posts, comments, messages, survey and support content | You; other community participants | Hosting, moderation, communications, support, security, and professional providers; other users according to visibility | No |
We retain these categories according to Section 10. We do not knowingly sell or share personal information of consumers under 16. We do not use sensitive personal information to infer characteristics for purposes outside those permitted by applicable law.
Eligible residents may request access, categories and specific pieces of data, correction, deletion, portability, or information about disclosures; may opt out of sale, sharing, targeted advertising, or certain profiling; may limit certain sensitive-data uses; and may appeal a denial where applicable. California residents may use an authorised agent and may receive information about categories collected, sources, purposes, recipients, and retention. Submit requests under Section 12. If an applicable practice is treated as sale or sharing, use Your Privacy Choices or a recognised opt-out preference signal.
We do not offer a financial incentive in exchange for personal information through the general membership programme. If a loyalty, referral, research, or benefits programme is considered a financial incentive or bona fide loyalty programme under applicable law, we will provide any separate notice and opt-in required for that programme.
16.4 United States—consumer health data privacy notice
This subsection is intended to operate as our Consumer Health Data Privacy Policy under Washington’s My Health My Data Act, Nevada’s consumer health data law, and similar US laws, where applicable.
Consumer health data collected. Depending on the Services and permissions you select, we may collect nutrition and meal data; activity, fitness, sleep, recovery, and stress data; heart rate, heart-rate variability, blood-oxygen estimates, temperature and other device measurements; height, weight and body-composition data; symptoms, goals, conditions and other self-reported information; face, tongue, meal and body images; health-related purchases and benefit use; reproductive or menstrual information if an optional feature collects it; data that identifies your attempt to obtain wellness services; and inferences drawn from these categories.
Sources. Sources include you; your phone, browser, smart device, connected platform, or sensor; a person or professional you authorise; a sponsoring organisation as specifically disclosed; and service or benefits partners involved in a transaction you request.
Purposes. We collect and use consumer health data to provide and personalise requested Services; connect devices; show history and progress; generate nutrition and wellness insights; administer user-selected benefits; maintain security; prevent fraud; comply with law; and conduct consented or deidentified research and product improvement. We will obtain affirmative consent before collecting or using additional consumer health data for a materially different purpose when required.
Sharing. We may share consumer health data with processors that provide hosting, device connectivity, AI processing, security, support, and other functions necessary for the Services; with a provider, professional, or benefits partner you select; with an affiliate subject to consistent protections; or for legal, safety, or corporate-transaction purposes described in Section 6. We require processors to follow contractual instructions. We do not sell consumer health data. If a future transaction legally constitutes a sale of consumer health data, we will obtain the separate signed authorisation required by law before it occurs.
Your rights. You may ask whether we collect, share, or sell consumer health data; access that data; obtain a list of applicable third parties and affiliates; withdraw consent; and request deletion, including notification to relevant processors and recipients, subject to lawful exceptions. You may appeal a denial. Submit a secure request under Section 12. Deletion from archived backups may take up to six months where permitted by applicable law.
16.5 Mainland China
For individuals in Mainland China, Bay Technologies acts as a personal information processor under the Personal Information Protection Law (“PIPL”) for the general Services. Health, biometric, financial-account, precise-location, and data of minors under 14 may be sensitive personal information.
We will provide specific purposes and necessity information and obtain separate consent where required for sensitive personal information, disclosure to another processor, public disclosure, or cross-border transfer. We will process sensitive personal information only for a specific purpose and when sufficiently necessary, and will adopt stricter safeguards. We do not treat an ordinary face or tongue photograph as an identity credential unless a separately disclosed feature uses it for identification.
You may have rights to know, decide, restrict or refuse processing; access and copy; correct; delete; and request an explanation of processing rules. A close relative may have rights concerning a deceased person’s data where the law permits. For children under 14, we require guardian consent and a child-specific privacy notice before covered processing.
Where the PIPL applies to an overseas service and requires a representative or designated organisation in Mainland China, or where a security assessment, standard contract, certification, impact assessment, or filing is required, we will complete the relevant step before the covered activity. Current local-contact information, if applicable, will be provided in the relevant service or may be requested from info@gbat.ai.
16.6 Other Asia-Pacific jurisdictions
If you are protected by one of the laws below, the following additional terms apply to the extent required:
- Singapore: Under the Personal Data Protection Act, you may request access and correction and may withdraw consent. Our contact in Section 1 handles data-protection enquiries. Overseas transfers will receive protection comparable to the PDPA through a legally recognised mechanism.
- Japan: Under the Act on the Protection of Personal Information, you may request disclosure of retained personal data and transfer records where applicable, correction, cessation of use or provision, and deletion as provided by law. We obtain consent for third-party or foreign transfers when required and provide required information about foreign protection arrangements.
- South Korea: Under the Personal Information Protection Act, required consents and overseas-transfer notices will be presented separately where necessary. You may request access, correction or deletion, suspension of processing, withdrawal of consent, and other applicable rights. A domestic representative will be designated and identified if statutory thresholds require one.
- Malaysia: Under the Personal Data Protection Act 2010, you may request access or correction, withdraw consent, prevent processing likely to cause damage or distress where applicable, and opt out of direct marketing. We use a lawful condition and safeguards for cross-border transfers and appoint or notify a data protection officer where required.
- Thailand: Under the Personal Data Protection Act, you may request access, correction, deletion, restriction, portability, objection, and withdrawal of consent, subject to legal conditions. We use a lawful basis for processing and an approved or otherwise lawful mechanism for restricted transfers.
- Taiwan: We provide notice of the identity of the collector, purposes, data categories, period, area, recipients and methods of use, rights, and consequences of not providing required data. You may exercise the rights provided under Taiwan’s Personal Data Protection Act.
- Indonesia: Under Law No. 27 of 2022 on Personal Data Protection, you may request information, access, correction, deletion or cessation, withdrawal of consent, portability, and review of certain automated decisions, subject to law. We appoint a local representative or officer and satisfy transfer conditions where required.
- Vietnam: Under the Law on Personal Data Protection effective in 2026 and its implementing rules, health information and other listed data may be sensitive. We obtain consent where required, maintain processing and cross-border impact-assessment documentation, and make required filings or notifications before or within the statutory period.
- India: The Digital Personal Data Protection Act 2023 and Rules 2025 apply according to their phased commencement. Where operative and applicable, you may access information, correct or erase data, withdraw consent, use grievance redressal, and nominate another person as provided by law. We use verifiable parental consent for a child under 18 unless an exemption applies and do not undertake prohibited tracking, behavioural monitoring, or targeted advertising directed at children.
- Australia: If the Australian Privacy Act 1988 applies, you may access and correct personal information and complain to us. We take reasonable steps required by the Australian Privacy Principles for overseas disclosures and provide information about likely destination countries where practicable.
Local law may provide additional rights or exceptions. Contact us and state your jurisdiction so that we can apply the correct process.
17. Organisation-sponsored and professional services
If you access the Services through an organisation, a service-specific notice or agreement will identify whether Bay Technologies acts as an independent controller, joint controller, or processor/service provider. The organisation controls personal data it submits to us and any data it receives from us under that arrangement.
Organisation administrators may be able to manage eligibility, invitations, licences, or group participation. They do not automatically receive your individual meal logs, images, wearable measurements, or wellness insights. Any individual-level disclosure must be necessary for the programme, described in the relevant notice, and supported by an appropriate legal basis.
If you interact with a coach, nutritionist, healthcare professional, or other practitioner through the Services, that practitioner may be independently responsible for professional records and advice. Ask the practitioner for their privacy notice.
18. Changes to this Policy
We may update this Policy to reflect changes in the Services, law, or our practices. We will post the revised Policy and update the date above. If a change materially affects your rights or how we use previously collected sensitive data, we will provide additional notice and obtain consent where required before the change applies.
19. Contact us
For questions, complaints, privacy requests, or appeals, contact:
Privacy Team Bay Technologies Limited No. 19 Science Park West Avenue Hong Kong Science Park, Pak Shek Kok New Territories, Hong Kong Email: info@gbat.ai
Please do not send sensitive wellness information by ordinary email unless we ask you to use a secure channel.
