Privacy & Cookie Policy

Last updated: 21 August 2026

This privacy and cookie policy describes how Cue Life DK ApS, CVR 45653110, Grønnegade 41A, 1107 Copenhagen K, Denmark (hereinafter ”Cue Life”, “we”, “our” or “us”), as data controller, collects, processes and discloses personal data about you in connection with you registering as a user and subsequently using our app, Cue (”Cue”).

The processing is carried out in accordance with applicable law, including:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (”GDPR”).
  • Consolidated Act No. 289 of 8 March 2024 on supplementary provisions to the regulation on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the ”Danish Data Protection Act”).
  • Executive Order No. 1361 of 24 November 2025 on authorised healthcare professionals’ patient records (record keeping, storage, disclosure, transfer, etc.) (the ”Danish Records Keeping Order”).
  • Act No. 700 of 24 May 2022 on bookkeeping (the ”Danish Bookkeeping Act”).
  • Executive Order No. 1148 of 9 December 2011 on requirements for information and consent for the storage of or access to information in end users’ terminal equipment (the ”Danish Cookie Order”).

About cookies

What are cookies

Cookies are small data files stored on your device that allow our website to function, remember your choices and – if you give your consent – help us measure usage and personalise content.

Overview of cookie use/cookie list

We use cookies in four categories: strictly necessary, functional/preference, statistics and marketing, as described in the cookie banner. The always up-to-date list of the specific cookies — name, provider, purpose, legal basis and retention period — is available via “Cookie Settings” in the footer of our website, where you can also change your choices.

How to change or withdraw your consent

You can change your choices or withdraw your consent at any time via “Cookie Settings”, which is always available in the footer of our website. Your changes take effect immediately and apply going forward. If you wish to remove cookies already stored in your browser, you can delete them via your browser settings.

Overview of processing activities

  • We process your personal data for the purposes set out below
  • We process the categories of personal data about you set out below to the extent necessary
  • We process your personal data on the legal bases set out below
  • We potentially disclose your personal data to the recipients set out below
  • We store your personal data in accordance with the periods set out below

1. Registration and ongoing user activity in Cue

including creation and subsequent use of your profile as well as ongoing payments.

Categories of personal data:

  • Ordinary personal data: Contact details (name, address, e-mail address, telephone number).
  • Confidential personal data: CPR number (identification data), family circumstances, social relations, employment and education data, administrative/financial data (payment details, contract data, communication metadata).
  • Sensitive personal data: Health data, sexual orientation (only where clinically relevant), racial or ethnic origin, religious beliefs.

Legal basis for the processing:

  • Article 6(1)(b) of the GDPR.
  • Section 11(2)(2) of the Danish Data Protection Act.

Disclosure of personal data: N/A

Retention period:

  • We store your personal data for ten (10) years (calculated from the most recent record entry), cf. Section 35 of the Danish Records Keeping Order.
  • We delete your data when you have deleted your profile.

2. Health advisory services

including advice on hormone balance, preparation of individual action plans and advice on lifestyle factors such as nutrition, exercise and recovery, with a view to prevention and long-term health optimisation.

Categories of personal data:

  • Ordinary personal data: Contact details (name, address, e-mail address, telephone number).
  • Confidential personal data: CPR number (identification data), family circumstances, social relations, employment and education data
  • Sensitive personal data: Health data, sexual orientation (only where clinically relevant), racial or ethnic origin, religious beliefs.

Legal basis for the processing:

  • Article 6(1)(a) of the GDPR.
  • Article 9(2)(a) of the GDPR.
  • Section 11(2)(2) of the Danish Data Protection Act.

Disclosure of personal data:

  • Healthcare actors
  • Relevant authorities

Retention period:

  • We store your personal data for ten (10) years (calculated from the most recent record entry), cf. Section 35 of the Danish Records Keeping Order.

3. Health monitoring

including ongoing measurement and follow-up on biomarkers with regular testing, as the app continuously records and analyses health data about you to follow your development over time.

Categories of personal data:

  • Ordinary personal data: Contact details (name, address, e-mail address, telephone number).
  • Sensitive personal data: Health data, sexual orientation (only where clinically relevant), racial or ethnic origin, religious beliefs.

Legal basis for the processing:

  • Article 6(1)(a) of the GDPR.
  • Article 9(2)(a) of the GDPR.

Disclosure of personal data:

  • Healthcare actors
  • Relevant authorities

Retention period:

  • We store your personal data for 10 years (calculated from the most recent record entry), cf. Section 35 of the Danish Records Keeping Order.

4. Product and quality development

including statistical analysis and quality assessment of our health services, improvement of algorithms and biomarker analyses, development of new features in the app and feature analysis.

Categories of personal data:

  • Ordinary personal data: Contact details (name, address, e-mail address, telephone number), usage data, activity data, preferences and behavioural data.
  • Sensitive personal data: Health data, sexual orientation (only where clinically relevant), racial or ethnic origin, religious beliefs.

Legal basis for the processing:

  • Article 6(1)(a) of the GDPR.
  • Article 9(2)(a) of the GDPR.

Disclosure of personal data: N/A

Retention period:

  • We store your personal data for ten (10) years (calculated from the most recent record entry), cf. Section 35 of the Danish Records Keeping Order.

5. Marketing and newsletters

including for marketing and for sending newsletters, including sending offers and recommendations.

Categories of personal data:

  • Ordinary personal data: Contact details (name, address, e-mail address, telephone number).

Legal basis for the processing:

  • Article 6(1)(a) of the GDPR.

Disclosure of personal data: N/A

Retention period:

  • We only store personal data for as long as necessary for the purpose for which the personal data was collected or otherwise processed.
  • Upon withdrawal of consent to direct marketing, we immediately stop all processing for this purpose and delete marketing data.
  • We only retain minimal data (e.g. name and e-mail) on a suppression list and for documentation of consent/unsubscription for a maximum of two (2) years from the last marketing contact, unless longer retention is necessary to comply with legal requirements or to establish or defend legal claims.

6. Data analysis

including analysis of correlations between biomarkers and health development, usage patterns and product engagement.

Categories of personal data:

  • Ordinary personal data: Contact details (name, address, e-mail address, telephone number), usage data, activity data, preferences and behavioural data.
  • Sensitive personal data: Health data, sexual orientation (only where clinically relevant), racial or ethnic origin, religious beliefs.

Legal basis for the processing:

  • Article 6(1)(a) of the GDPR.
  • Article 9(2)(a) of the GDPR.

Disclosure of personal data: N/A

Retention period:

  • We only store personal data for as long as necessary for the purpose for which the personal data was collected or otherwise processed.

7. Security monitoring

including processing of personal data to protect our services, systems and users against unauthorised access, misuse, fraud and security incidents, including through technical monitoring (e.g. logging of access attempts, incident logs, IP addresses, device and session data) and subsequent analysis for troubleshooting and incident handling.

Categories of personal data:

  • Ordinary personal data: Technical usage and event data (e.g. timestamps, user/account IDs, role data, IP address, browser/device, application and server logs), as well as internal metadata about changes, configuration and administration (including actions performed by user administrators).

Legal basis for the processing:

  • Article 6(1)(f) of the GDPR.

Disclosure of personal data: Only authorised employees with a legitimate need have access. Data may be shared with trusted suppliers

Retention period:

  • We only store personal data for as long as necessary for the purpose for which the personal data was collected or otherwise processed.

8. Clinical audit

including ensuring that patient care follows recognised standards, strengthening patient safety by identifying and preventing risks, documenting quality responsibly and supporting continuous learning and development.

Categories of personal data:

  • Ordinary personal data: Contact details (name, address, e-mail address, telephone number).
  • Confidential personal data: CPR number (identification data), family circumstances, social relations, employment and education data
  • Sensitive personal data: Health data, sexual orientation (only where clinically relevant), racial or ethnic origin, religious beliefs.

Legal basis for the processing:

  • Article 6(1)(a) of the GDPR.
  • Article 9(2)(a) of the GDPR.
  • Section 11(2)(2) of the Danish Data Protection Act.

Disclosure of personal data:

  • Healthcare actors
  • Relevant authorities

Retention period:

  • We store your personal data for ten (10) years (calculated from the most recent record entry), cf. Section 35 of the Danish Records Keeping Order.

9. AI features (assistance, recommendations and improvements)

including to deliver AI-supported features in the app (e.g. conversation assistant, suggestions and summaries), to maintain and improve these features, and to protect them against misuse and security incidents.

In addition, in connection with AI features being used as part of health advisory services and health monitoring.

Categories of personal data:

  • Ordinary personal data: Contact details (name, address, e-mail address, telephone number).
  • Sensitive personal data: Health data, sexual orientation (only where clinically relevant), racial or ethnic origin, religious beliefs.

Legal basis for the processing:

  • Article 6(1)(a) and (b) of the GDPR.
  • Article 9(2)(a) of the GDPR.

Disclosure of personal data: N/A

Retention period:

  • We only store personal data for as long as necessary for the purpose for which the personal data was collected or otherwise processed
  • We store your personal data for ten (10) years (calculated from the most recent record entry), cf. Section 35 of the Danish Records Keeping Order.

10. Retrieval of medical record data (sundhed.dk)

including that our healthcare professionals – where you have given your consent – may retrieve health information about you from your patient record, including via lookups on sundhed.dk through a third-party system, for use in health advisory and health monitoring.

Source: The data is obtained from your patient record, including via sundhed.dk, and therefore does not originate directly from you.

Categories of personal data:

  • Confidential personal data: CPR number (identification data), used to perform the lookup.
  • Sensitive personal data: Health data (medical record data).

Legal basis for the processing:

  • Article 6(1)(a) of the GDPR.
  • Article 9(2)(a) of the GDPR.
  • Section 42d of the Danish Health Act (retrieval of information from patient records).

Disclosure of personal data: N/A

Retention period:

  • We only store personal data for as long as necessary for the purpose for which the personal data was collected or otherwise processed
  • We store your personal data for ten (10) years (calculated from the most recent record entry), cf. Section 35 of the Danish Records Keeping Order.

The consent is voluntary and can be withdrawn at any time in the app, after which we will no longer perform new lookups.

Sources and voluntariness

When we collect personal data directly from you, you provide personal data about yourself voluntarily.

We collect personal data directly from you, including via questionnaires, consultations and documents that you may upload yourself.

In addition, we may obtain data from other healthcare actors and relevant authorities in Denmark where permitted or required under applicable law, or where you have given valid consent, if such consent is required, including medical record data via sundhed.dk (see purpose 10).

Transfers of personal data to countries outside the EU/EEA

Any transfer of personal data to recipients in countries outside the EU/EEA or to international organisations will be based on a legal basis in Chapter V of the GDPR, and will typically take place because the transfer is necessary for the establishment, exercise or defence of legal claims, cf. Article 49(1)(e). Transfers may also take place on the basis of the European Commission’s standard contractual clauses. You can access the standard document on the European Commission’s website.

Some of our suppliers (for example those providing our IT infrastructure) may process personal data outside the EU/EEA, including in the USA. Where this happens, we ensure that a valid transfer basis exists under Chapter V of the GDPR. For suppliers in the USA, we rely on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework, to the extent the relevant supplier is certified and the transfer is covered by the certification. In other cases, we rely on the European Commission’s standard contractual clauses or another relevant transfer basis under the GDPR, where relevant supplemented by additional technical, organisational or contractual measures. Further information about the specific suppliers and cookies can be found in the cookie list (via “Cookie Settings” in the footer of our website) and the suppliers’ privacy and data-processing information.

Your rights

You have – subject to the limitations that follow from applicable law – the following rights:

  • The right of access to the personal data
  • The right to have incorrect and incomplete personal data rectified
  • The right to have the personal data erased
  • The right to have the processing of the personal data restricted
  • The right to object, where the legal basis for the processing is ’legitimate interests’, cf. Article 6(1)(f) of the GDPR.

You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet), which can be contacted here:

Datatilsynet

Carl Jacobsens vej 35

2500 Copenhagen

Telephone: +45 33193200

E-mail: dt@datatilsynet.dk

Contact details

If you have questions about this privacy policy, or about our processing of personal data about you, or if you wish to exercise your rights, you can contact us here:

Cue Life DK ApS

CVR: 45653110

Grønnegade 41A

1107 Copenhagen K

Telephone: +45 25725551

E-mail: legal@cuelife.com

Updates to this policy

We update this privacy policy when legal, technical or business changes make it necessary. In the event of material changes, we will notify you via the app or by direct message.