Privacy Policy
Date of creation: November 20, 2025
Introduction
Limitless, as the data controller, prioritizes personal data protection and adheres to EU Regulation 2016/679 (GDPR) and Belgian data protection laws. This policy explains how your information is managed.
What data do we collect?
Limitless gathers personal information across several categories:
- Identification and contact data: Name, phone, gender, email, password, birth date, ID number, VAT number, and profile information
- Health data: Health status, blood test results, and AI-generated reports
- Financial data: Bank account information
- Direct marketing data: Contact details and communication preferences
- Service usage data: Device type, identifiers, and network information
- Cookies and tracking: IP address, browser type, OS, and visit patterns
- Communications: Messages, calls, and chat interactions
For what purposes do we use your data?
Data processing purposes include:
| Purpose | Legal Basis | Retention |
|---|---|---|
| Account creation and management | Contract | 5 years post-closure |
| Blood test analysis and reporting | Contract/Consent | Legal retention period |
| Personalized recommendations | Contract | 5 years post-use |
| Wellness guidance | Contract | 5 years post-use |
| Customer support | Legitimate interest | As needed |
| Billing | Legal obligation | 10 years |
| Marketing communications | Consent | Until withdrawal |
| Security and support | Legitimate interest | 5 years |
International data transfers
Personal data remains within the European Union.
Your data protection rights
Under GDPR, you have the right to: access, rectify, erase, restrict processing, data portability, object, withdraw consent, and lodge complaints with supervisory authorities.
Contact: contact@limitless.today
Data security measures
Limitless employs technical and organizational safeguards including: TLS encryption, restricted access with multi-factor authentication, tokenized payment processing through Stripe, rate limiting, and DDoS protection. Technology partners (Azure, Vercel, Crisp, Stripe) comply with GDPR.
Data recipients
Information may be shared with: Limitless contractors, authorized personnel, and healthcare professionals when necessary.
Cookies
Cookies track activity and store limited data. Browser settings allow configuration of cookie preferences through the platform's management tools.
Policy updates
Changes to this policy will be published with updated effective dates.