1. Introduction Daosium ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share information when you use the Daosium application. By using the App, you agree to the practices described in this policy.

Data Controller: Daosium. This policy complies with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the UK Data Protection Act 2018. Where this policy refers to GDPR rights, those rights apply equally to users in the UK under the UK GDPR.

  1. Information We Collect Account information: Name, email address, and profile details you provide when registering. Usage data: Recipes viewed, favourites saved, cooking logs, meal plans, and pantry items you create. Purchase data: Order history, shipping addresses, and payment information (processed by Stripe — we do not store card details). User content: Recipes, comments, and photos you submit. Device data: Device type, operating system, and app version for diagnostics and performance.
  2. How We Use Your Information To provide and improve the App's features and services. To personalise your recipe recommendations and cooking experience. To process your orders and send order confirmations. To communicate updates, promotions, or important notices (you may opt out at any time). To moderate user-submitted content and maintain community standards. To comply with legal obligations.
  3. Legal Basis for Processing (GDPR) We process your personal data only where we have a lawful basis under Article 6 of the GDPR. The specific basis depends on the purpose:

Performance of a contract (Art. 6(1)(b)): Creating and managing your account, processing orders and payments, fulfilling deliveries, and providing the core features of the App (recipes, meal plans, pantry, shopping lists). Legitimate interests (Art. 6(1)(f)): Improving our services, analysing usage patterns, generating personalised recommendations, securing the platform against fraud and abuse, and providing customer support. These interests are balanced against your rights and you may object to this processing (see Section 7). Consent (Art. 6(1)(a)): Optional features such as marketing communications, optional AI-powered recipe generation, and uploading photos or user-generated content. You may withdraw consent at any time without affecting the lawfulness of processing already carried out. Legal obligation (Art. 6(1)(c)): Retaining order and tax records, responding to lawful requests from authorities, and meeting regulatory requirements. For special category data (e.g. health-related dietary preferences you voluntarily disclose), we rely on your explicit consent under Article 9(2)(a) of the GDPR.

  1. Data Sharing We do not sell your personal data. We may share data with:

Stripe: For payment processing. Shipping carriers (DHL, FedEx): To fulfil your orders. Service providers: Cloud hosting and analytics partners who process data on our behalf under data processing agreements. Legal authorities: Where required by law or to protect our rights. 6. Data Retention We retain your personal data only for as long as necessary to fulfil the purposes set out in this policy, unless a longer retention period is required by law:

Account data: Retained while your account is active. Deleted within 30 days of account deletion request, except where legal obligations require otherwise. Order and payment records: Up to 7 years for legal, tax, and accounting compliance. User-generated content: Retained while your account is active or until you delete the content. Usage and diagnostics data: Aggregated/anonymised data may be retained indefinitely; identifiable usage data is deleted with your account. Marketing consent: Retained until you withdraw consent or request deletion. When data is no longer needed, we either delete it or anonymise it so it can no longer identify you.

  1. Your Rights (GDPR Articles 13–22) If you are in the EEA, UK, or Switzerland, you have the following rights regarding your personal data:

Right of access (Art. 15): Request a copy of the personal data we hold about you. Right to rectification (Art. 16): Request correction of inaccurate or incomplete data. Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten"), subject to legal exceptions (e.g. tax record retention). Right to restriction (Art. 18): Request that we limit processing of your data in certain circumstances. Right to data portability (Art. 20): Receive your data in a structured, machine-readable format and have it transmitted to another provider where technically feasible. Right to object (Art. 21): Object to processing based on legitimate interests or for direct marketing. Right to withdraw consent (Art. 7(3)): Withdraw consent at any time for processing based on consent, without affecting the lawfulness of prior processing. Right to lodge a complaint (Art. 77): Lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk. To exercise any of these rights, email us at [email protected]. We will respond within one month, extendable by two months for complex requests. We will not charge a fee unless your request is manifestly unfounded or excessive.

  1. Cookies and Tracking The App uses local storage and session storage to save your preferences (e.g. language, theme). We do not currently use third-party advertising cookies. Analytics data may be collected to improve performance.
  2. Children's Privacy The App is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
  3. Security We implement industry-standard technical and organisational measures to protect your data, including encrypted data transmission (HTTPS) and secure cloud infrastructure. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
  4. International Data Transfers (GDPR Chapter V) Your personal data may be transferred to and processed in countries outside the EEA/UK, including the United States (e.g. Stripe, Base44, and other service providers). We ensure such transfers comply with GDPR requirements by one or more of the following safeguards:

The European Commission's adequacy decision for the receiving country; Standard Contractual Clauses (SCCs) approved by the European Commission and/or UK Information Commissioner, entered into with our service providers; The EU-U.S. Data Privacy Framework (and the UK Extension), where the recipient is certified; Binding Corporate Rules where applicable. You may request a copy of the safeguards we rely on by contacting us.

  1. Changes to This Policy We may update this Privacy Policy from time to time. The date at the top of this page reflects the most recent update. We encourage you to review this policy periodically.
  2. Data Protection Officer & Contact For any privacy-related questions, requests to exercise your rights, or complaints, please contact our Data Protection Officer / privacy team:

Email: [email protected] Website: www.daosium.com Subject line: "Privacy Request — GDPR" Response time: Within one month of receipt (extendable by two months for complex requests). You also have the right to lodge a complaint with the ICO (UK) or your local data protection authority if you believe our processing of your personal data infringes the GDPR. You can do so without first contacting us, though we encourage you to reach out so we can resolve any concerns.