Angelo Life App Privacy Notice
Last updated: 8 April 2026
Looking for the website privacy notice? View the Website Privacy Notice.
Looking for the Angelo Life app terms of use? View the Angelo Life App Terms of Use.
Data Controller
Empaco Healthcare Technologies SRL Registered office: PiaΘa Unirii 3, TimiΘoara, Romania Contact: contact@empaco.eu
This Privacy Notice explains how Empaco Healthcare Technologies SRL, "Empaco", processes personal data in connection with the Angelo Life smartwatch, the Angelo Life mobile application, and the related monitoring services.
This Notice applies to:
- βClients who enter into a contract with Empaco,
- βBeneficiaries who wear the Angelo Life device (Device Users),
- βDesignated persons who receive notifications or alerts through the app (App Users).
1. Categories of Personal Data
We may collect and process the following categories of personal data:
- βIdentity and contact data, such as name, surname, postal address, telephone number, WhatsApp number, email address, identification details provided for contracting, and details relating to the contractual relationship.
- βAccount and onboarding data, such as account credentials, client number, contract number, service package information, device allocation details, and records relating to activation and onboarding.
- βHealth and wellbeing related data generated by the device and the service, such as heart rate, heart rhythm regularity, blood pressure, blood oxygen saturation, movement patterns, number of steps, fall related events, sleep patterns, and other indicators generated by the device in connection with the contracted monitoring service.
- βLocation data, such as GPS coordinates and related location events of the Device User while the device is in use and location functions are enabled.
- βDevice, SIM, and technical data, such as smartwatch identifier, SIM number, assigned phone number, app version, operating system information, connectivity status, and technical logs necessary for service operation, maintenance, and troubleshooting.
- βPayment and billing data, such as invoicing details, payment status, payment method, and related accounting records.
- βSupport and communication data, such as emails, WhatsApp messages, complaints, service requests, and records of interactions with our support team.
- βData received from other persons, where the Client provides information about the Device User or an App User, or where an App User is added for alerting and monitoring purposes.
2. Purposes of Processing and Legal Basis
We process personal data for the following purposes:
- βTo conclude, perform, and manage the contractual relationship, including delivery of the device, activation of the SIM subscription, account setup, access management, billing, renewals, support, maintenance, and handling of contractual communications. Legal basis: Article 6(1)(b) GDPR, performance of a contract or steps prior to entering into a contract.
- βTo provide the Angelo Life monitoring service, including transmission of device data through the app, display of alerts, communication of emergency related events to the Client or Designated Person, and provision of the functions included in the selected service package. Legal basis: Article 6(1)(b) GDPR. For health-related data, special category processing is carried out on the basis of Article 9(2)(a) GDPR, explicit consent, unless Empaco documents and applies another Article 9 condition that is more appropriate for the specific service model.
- βTo process location data necessary for location-based alerts, safety monitoring, and related service functions. Legal basis: Article 6(1)(b) GDPR for the core service, together with device level permissions granted by the user where required.
- βTo provide customer service, resolve complaints, repair or replace devices, investigate incidents, and ensure service continuity. Legal basis: Article 6(1)(b) GDPR and, where appropriate, Article 6(1)(f) GDPR, Empaco's legitimate interest in maintaining the security and reliability of its services.
- βTo comply with legal obligations, including accounting, tax, consumer protection, and responding to lawful requests from competent authorities. Legal basis: Article 6(1)(c) GDPR.
- βTo ensure network, platform, and device security, prevent misuse, document incidents, and protect the integrity of our systems and services. Legal basis: Article 6(1)(f) GDPR.
- βTo send strictly service-related notifications, such as activation messages, technical notices, payment reminders, device replacement information, and security notices. Legal basis: Article 6(1)(b) GDPR and, where appropriate, Article 6(1)(f) GDPR.
Empaco does not use health or location data for advertising purposes.
3. Source of Personal Data
We may obtain personal data:
- βdirectly from the Client, Device User, or App User,
- βduring face-to-face sales and onboarding,
- βfrom the device and mobile application during use of the service,
- βfrom the Client where the Client provides personal data about the Device User or an App User.
Where personal data are not obtained directly from the person concerned, Empaco will provide the information required by applicable data protection law within the applicable time limits.
4. Data Retention
We keep personal data only for as long as necessary for the purposes for which they were collected and as required by applicable law.
As a general rule:
- βcontract, account, and service data are kept for the duration of the contractual relationship and for the period necessary to establish, exercise, or defend legal claims;
- βbilling and accounting data are kept for the retention period required by applicable financial and tax law;
- βhealth and location data are kept for the duration necessary to provide the service and for a limited period thereafter according to Empaco's retention schedule and legal obligations;
- βtechnical logs and support records are kept only for as long as necessary for security, troubleshooting, and audit purposes.
5. Recipients of Personal Data
Personal data may be accessed by:
- βauthorised Empaco personnel on a need-to-know basis,
- βtechnical and hosting providers acting on Empaco's behalf,
- βthe mobile network operator providing SIM connectivity,
- βcourier or logistics providers where needed for delivery, repair, replacement, or return of devices,
- βprofessional advisers or competent public authorities where disclosure is required by law.
Personal data may also be disclosed through the service to the Client and to any App User selected for monitoring and alerts, in accordance with the contract and the service configuration.
6. International Transfers
Empaco stores and processes personal data on servers located in the European Union (EU). Based on the information currently provided, personal data processed in connection with the Angelo Life app and monitoring services are hosted in the EU through Hetzner.
Empaco does not transfer personal data outside the European Economic Area unless this becomes necessary in connection with a specific service provider or legal obligation. If such transfers occur, Empaco will implement the safeguards required by Chapter V GDPR and will update this Notice accordingly.
7. Security Measures
Empaco implements appropriate technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, destruction, alteration, or unlawful disclosure. These measures include access controls, confidentiality obligations, role-based access, secure hosting, and other safeguards appropriate to the nature of the data processed.
8. Rights of the Data Subject
Under the GDPR, you may have the right to:
- βobtain access to your personal data,
- βrequest rectification of inaccurate or incomplete data,
- βrequest erasure of your personal data in the cases provided by law,
- βrequest restriction of processing,
- βobject to processing where the legal basis is legitimate interest,
- βreceive your personal data in a structured, commonly used, and machine-readable format, where applicable,
- βwithdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal,
- βlodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing, ANSPDCP, or with another competent supervisory authority in the EU.
9. Exercise of Rights
You may exercise your rights by contacting Empaco at: contact@empaco.eu
Empaco will handle requests in accordance with the GDPR and may request information necessary to verify the identity of the requester.
10. Provision of Data
Some personal data is necessary in order to conclude and perform the contract and to provide the monitoring service. If the required data is not provided, Empaco may be unable to activate the account, deliver the service, provide monitoring functions, or respond properly to alerts and support requests.
11. Automated Processing
The service uses automated event detection and alert logic, such as threshold-based alerts and fall related event detection, in order to notify the Client or App User. These automated functions are intended to support monitoring and do not by themselves produce legal effects or similarly significant effects within the meaning of Article 22 GDPR.
12. Changes to this Notice
Empaco may update this Privacy Notice from time to time. The latest version will be made available in the app and on the relevant website or onboarding materials.
