Terms and Privacy

NestEgg Health – Terms of Service & Privacy Policy (v1.6)
Last Updated: February, 2026

1. Introduction

Welcome to NestEgg Health. By creating an account, joining a Nest, or participating in any NestEgg Challenge(“Challenge”), you (“Participant”,“Egg”,“you”) agree to these Terms of Service and PrivacyPolicy (“Terms”).

These Terms form a legally binding agreement between you and NestEgg Health Ltd. (“NestEgg”,“we”,“us”).

NestEgg provides a community-based exercise experience that uses wearable-generatedactivity data to calculate scores, leaderboards, and feedback.

NestEgg is not a medical service and does not provide healthcare, diagnosis, treatment, supervision, or medical advice.

2. What Data We Collect and Why

We collect only the data necessary to operate the NestEgg Challenge and related services.

Data Collected:

Data Type
Purpose
Source
Name & Organisation
Identify participants and Nests
Provided by you
Email Address
Login and challenge communications
Provided by you
Date of Birth
Calculate estimated maximum heartrate for scoring
Provided by you
Workout Type & Duration
Calculate Exercise Points
Fitness wearable
Heart Rate Data (average, peak,resting)
Calculate workout intensity and scoring
Fitness wearable
Device & App Metadata
Performance, security and troubleshooting
Automatically collected

We do not collect medical records, diagnoses, treatment information, or clinical health data.

3. Legal Basis for Processing (GDPR)

NestEgg processes personal data in accordance with the General Data Protection Regulation (GDPR) and equivalent UK and international data-protection laws.

3.1 Article 6 – Personal Data

We process personal data under Article 6(1)(b) GDPR (performance of a contract), asprocessing is necessary to operate the Challenge you choose to join.

3.2 Article 9 – Health & Biometric Data

Health-related and biometric data (including heart rate metrics) are processed under Article 9(2)(a) GDPR based on your explicit consent.

Participation in a NestEgg Challenge requires this consent. You may withdraw consent as described below.

4. How We Use Your Data

We use your data only to:

  • Calculate Exercise Points, scores, levels, and rankings

  • Display progress and team contributions

  • Display workout summaries and heart-rate metrics within Challenges

  • Provide challenge-related notifications and insights

  • Operate and improve the NestEgg platform

We do not sell personal data. We do not use personal data for advertising.

5. Consent, Withdrawal & Health Pause

By joining a Challenge and connecting a wearable, you explicitly consent to processing of activity and heart-rate data for scoring and community display purposes.

You may withdraw consent at any time.

If consent is withdrawn during an active Challenge:

  • Your participation will be paused using the Health Pause function

  • Scoring and leaderboard participation will stop

  • Historical Challenge data may remain visible where required for team integrity

After a Challenge ends, you may request deletion of your account and data (see Section 10).

6. Controller Roles & Employer Involvement

NestEgg Health Ltd. is the data controller for participant personal data.

If you join a workplace Challenge:

  • Your employer does not control how your data is processed

  • Employers access only the data made visible within the Challenge

  • Employers are not joint data controllers

NestEgg does not supervise, direct, or manage your physical activity on behalf of your employer.

Participation remains voluntary and self-directed at all times.

7. Participant Visibility & Community Data

NestEgg is a social, team-based experience.

Participants within the same Challenge can see challenge-relevant activity information of other participants, including:

  • Scores and rankings

  • Workout summaries (type and duration)

  • Contribution toward team results

  • Heart rate metrics (average, peak, and resting heart rate associated with logged workouts)

Continuous raw biometric traces (such as second-by-second heart-rate graphs) are not shared.

By participating in a Challenge, you acknowledge and accept that your activity summaries and heart-rate metrics will be visible to other participants in that Challenge.

8. Data Security

We use industry-standard security measures including:

  • Encryption in transit and at rest

  • Role-based access controls

  • Secure cloud infrastructure

  • System monitoring and backups

Third-party providers are assessed for security and data-protection standards.

No system can guarantee absolute security. Participants acknowledge this inherent risk of digital services.

9. International Data Transfers

Some service providers may process data outside the European Economic Area.

Where this occurs, NestEgg relies on appropriate safeguards including Standard Contractual Clauses or equivalent lawful transfer mechanisms.

10. Data Retention & Deletion

We retain personal data only for as long as necessary to:

  • Operate Challenges

  • Maintain participation history

  • Meet legal or contractual obligations

Inactive accounts are periodically reviewed.

You may request deletion of your account and personal data by contacting privacy@nestegghealth.com, subject to Challenge integrity and legal requirements.

11. Your Rights (GDPR)

You have the right to:

  • Access your personal data

  • Correct inaccurate information

  • Request deletion

  • Withdraw consent

  • Lodge a complaint with a supervisory authority

Requests may be sent to privacy@nestegghealth.com.

12. Health Acknowledgement & Assumption of Risk

By participating in NestEgg, you acknowledge that:

  • You are solely responsible for selecting, performing, and supervising your own physical activity

  • Exercise involves inherent risks including injury, illness, or adverse health events

  • You should consult a qualified healthcare professional if you have medical concerns

You voluntarily assume all risks associated with your participation.

NestEgg:

  • Is not a medical service

  • Does not provide medical advice

  • Does not diagnose, treat, supervise, or prevent disease

All insights and feedback are informational only.

13. HIPAA & US Healthcare Disclaimer

NestEgg Health is not a healthcare provider, health plan, or HIPAA-covered entity.

Data processed by NestEgg is not subject to HIPAA and is not intended for clinical or medical decision-making.

14. Liability & Participation Waiver

Participation is voluntary.

To the maximum extent permitted by law:

  • You release and discharge NestEgg Health Ltd., its directors, officers, employees, contractors, and partners from liability for injury, illness, or damages arising from participation.

  • You agree that NestEgg is not liable for misinterpretation of Challenge data, insights, rankings, or heart-rate metrics.

  • You acknowledge that technical issues or wearable syncing errors may occur.

Nothing in these Terms excludes liability for death or personal injury caused by gross negligence or wilful misconduct where such exclusion is unlawful.

15. Limitation of Liability

To the fullest extent permitted by law:

  • NestEgg’s total liability arising out of or related to participation shall not exceed the total fees paid (if any) by you for participation in the preceding twelve months.

  • NestEgg shall not be liable for indirect, incidental, consequential, special, or punitive damages, including loss of profits, business interruption, or reputational harm.

16. Indemnity

You agree to indemnify and hold harmless NestEgg Health Ltd. from claims, damages, or expenses arising from:

  • Misuse of the platform

  • Falsification of activity data

  • Violation of these Terms

  • Conduct that harms other participants

17. Acceptable Use & Conduct

Participants must not:

  • Falsify or manipulate activity data

  • Abuse manual workout entry

  • Harass, intimidate, or disrupt others

NestEgg may suspend or remove accounts for misuse.

18. Governing Law & Jurisdiction

These Terms are governed by the laws of Ireland.

Any disputes arising under these Terms shall be subject to the exclusive jurisdiction of the Irish courts.

19. Changes to These Terms

We may update these Terms periodically.

Material changes will be communicated via the app or email. Continued participation constitutes acceptance.

20. Contact

Privacy enquiries:
privacy@nestegghealth.com

General enquiries:
info@nestegghealth.com