Skip to content
Panko

Privacy policy

Draft: this text has not yet been reviewed by a lawyer and may change before launch.

Last updated: 2026-10-03

1. Who we are

The controller of your personal data is [Company name and legal form], [Registered address], registration number [Company registration number] (“Panko”, “we”, “us”).

Privacy questions and requests: [privacy contact email].

2. What this policy covers

This policy applies to the Panko website, the Panko apps and the Panko cloud service that connects the Panko pump with caregivers. It explains what personal data we process, why, who receives it and what rights you have under the EU General Data Protection Regulation (GDPR).

3. The data we process

  • Account data: your first and last name, email address, a password (stored only as a secure hash by our sign-in provider), your language and app settings, the alert limits you choose, and whether you use fingerprint unlock (the PIN and biometric data never leave your phone).
  • Health data about the person using the pump (the “patient”): glucose readings, the sensor and its age, trend and short-term prediction, insulin pump status (battery, reservoir, insulin on board, connection, firmware), insulin delivery and pump commands (such as boluses, suspends, reservoir fills and settings) with who sent them and the result, and the alerts raised.
  • Relationship data: who is linked to which patient and in which role (owner, admin, viewer), invitations, and the patient's display name.
  • Device and connection data: pump serial number, the pump's cloud credentials (never your phone's), network type and signal strength, and Wi-Fi network names saved for the pump. Wi-Fi passwords are encrypted and never sent back to any phone or website.
  • Notification data: a device token so we can send you push notifications, and your notification choices.
  • Activity and audit records: a log of commands and notifications, and a record of each time Panko staff open a patient's data for support (who, which patient, when).
  • Messages you send us through the support form: your name, email, the topic and your message.
  • Technical data: basic information needed to run and secure the service, such as request logs and error reports.

4. Why we use it and on what legal basis

  • To provide the service you ask for: creating your account, showing readings, sending alerts and commands (GDPR Art. 6(1)(b), performance of a contract).
  • To process health data (Art. 9 data): this is necessary to provide the service and is based on explicit consent (Art. 9(2)(a)), given when the account holder or the patient's guardian sets Panko up. You can withdraw consent at any time by closing the account or asking us to delete the data, which means the service can no longer work for that patient.
  • To keep the service safe and working: security, preventing abuse, fixing faults and keeping the audit log (Art. 6(1)(f), our legitimate interest, and, for health data, the substantial interest of keeping a medical-adjacent service safe).
  • To answer your messages and requests (Art. 6(1)(b) and (f)).
  • To meet legal obligations (Art. 6(1)(c)).
  • We do not use personal or health data for advertising, we do not sell it, and we do not make automated decisions about you with legal or similar effect.

5. Who can see the data

  • Caregivers linked to the patient, according to the role the owner gave them. The owner decides who is linked and can remove anyone.
  • Panko staff, only as far as needed to give support, fix a problem or keep the service safe. Staff access is read-only in the website, requires a verified staff account, and each time a patient is opened it is recorded in an audit log.
  • Service providers that process data for us, listed in section 6, under contracts that require them to protect it.
  • Authorities, only where the law requires it.

6. Service providers and where data is stored

  • Google Cloud / Firebase (Google Ireland Limited and Google LLC): sign-in, the main database (stored in the EU multi-region location “eur3”), cloud functions, website hosting and push notifications.
  • A virtual server provider (Hetzner) that runs the secure message broker linking the pump with our cloud.
  • Some processing, such as running our cloud functions, takes place in the United States. Transfers outside the EU rely on the safeguards offered by the provider, such as the EU-US Data Privacy Framework and standard contractual clauses.

7. How long we keep it

We keep account and health data while the account is active. When an account or a patient is deleted we remove the data within [retention period], except what we must keep by law. Audit records of staff access and support messages are kept for as long as needed for security and to deal with requests, and no longer than [retention period].

8. Your rights

Under the GDPR you have the right to:

  • access the data we hold about you and receive a copy;
  • have inaccurate data corrected;
  • have your data erased (the “right to be forgotten”);
  • restrict or object to certain processing;
  • receive your data in a portable, machine-readable format;
  • withdraw your consent at any time, without affecting earlier processing.

To use a right, write to [privacy contact email] (or use the support form with the topic “Privacy and my data”). We may ask you to prove who you are, and will answer within one month. Where the data concerns a patient, the request is handled together with the patient or their guardian.

9. Children and people who cannot consent

A patient may be a child or someone who cannot manage their own account. In that case a parent, guardian or other legal representative sets Panko up, gives consent on their behalf and exercises their rights. Caregivers must only add a patient they are entitled to care for.

10. Cookies and similar technologies

The website stores only what it needs to work: your sign-in session and your own choices, such as the glucose unit. We do not use advertising or analytics cookies. If that changes we will ask for your consent first.

11. Security

Data is encrypted in transit. Access to health data is restricted by role and enforced on the server, pump commands are authenticated and confirmed by the pump, staff access is logged, and secrets such as Wi-Fi passwords are encrypted and never returned to apps. No system is perfectly secure; if a breach affects your data we will notify you and the authorities as the law requires.

12. Changes to this policy

We may update this policy. We will change the date above and, for important changes, tell you in the app or by email.

13. Complaints

You can complain to the supervisory authority. In Bulgaria this is the Commission for Personal Data Protection (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, www.cpdp.bg. You may also complain to the authority in your own EU country.