
The portal supports a way of living; it does not diagnose and does not prescribe. Health data is processed under GDPR — on the guest's explicit consent, on an EU server.
Wellness & Lifestyle Intelligence is a class of product that supports a way of living: sleep, movement, water, food and the hotel's procedures. It works with the same figures medicine does, but it claims no medical purpose and promises no therapeutic result.
What the portal does: it takes the daily states from a watch and the weigh-ins from a scale, compares them with the guest's own average, shows the picture to the guest in their account and to the doctor on the panel, and keeps and displays what the doctor prescribed.
What it never does: name a disease, prescribe either a medicine or a diet, override or replace a doctor's prescription, or promise that a procedure will cure anything.
The difference shows where the algorithm touches the plan. What is free and ours — a walk, a sauna included in the room — the portal moves by itself. A paid procedure it only proposes to move, and the doctor decides (how that works).
What makes software a medical device is not the sophistication of its algorithm but the purpose its manufacturer gave it: diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease (Regulation (EU) 2017/745 on medical devices, Article 2). The portal claims no such purpose — and that is not a declaration but three places in the product itself:
The hotel's kit is an ordinary Garmin Forerunner 165 Music and an ordinary Garmin Index S2 scale, bought in a shop. The portal takes none of their medical features: Garmin ships the ECG app enabled only where it is approved as a medical device, and a watch bought in another country may not carry it at all.
Pulse, its variability, sleep phases, breathing and blood oxygen are the readings of a consumer optical sensor on a wrist. That is how the portal presents them: as the movement of this guest's own body, not as the result of a test (what the watch actually measures).
The classification is held up by promises, not by a line in a document. A hotel's marketing that says «we will diagnose you from your watch» or «we will cure you in a week» breaks the frame faster than any change in the code.
The GDPR roles fall out like this, and how they fall matters more than any wording about partnership: it is the hotel that answers to the guest and to the supervisory authority.
| Role | Who that is | What they do |
|---|---|---|
| Controller | the hotel as a legal entity | decides why the data is collected; answers to the guest and to the supervisory authority; its details stand in the portal's notice |
| Processor | longev.eu | runs the code and the server, under a data-processing agreement and on the hotel's instructions |
| The doctor | the hotel's chief physician, named | sees the figures of the stay, prescribes the cure and the procedures; bound by medical confidentiality |
| The hosting | the provider, datacentre in the EU | keeps the server running; a processor too, under contract |
| Garmin | the Garmin cloud | receives what the watch records: either the guest's own account or the hotel's account behind a lent kit |
| sign-in and the model | sign-in with Google is the guest's choice; the model works while the hotel keeps the feature switched on | |
| Maps | OpenStreetMap, mapy.com | the guest's browser requests map tiles directly; the walk's track is never sent to them |
The platform is not multi-tenant in the usual sense: the guests of different houses are not kept apart by a column in a shared table. Every hotel has its own process on the server, its own directory and its own database, while the code is one and the same.
The difference is practical. A mistake in a query cannot show one hotel another hotel's guests — they are simply not in its database. A hotel that leaves takes its file whole, not a selection out of a shared store.
Health data is a special category (Article 9 GDPR), and for it «I agree to the terms» at sign-up is not legally enough. So there are two consents: the general one at sign-up and an explicit one for the processing of health data, asked before the questionnaire.
The order is held by the server, not by the interface: a request for the second consent while the notice has not been accepted is refused.
Both consents are stored together with the version number of the notice and the time. The version goes up when the meaning changes, not for a typo — and then the portal asks everybody again, in a window that stands over any screen.
That has happened three times already: version 1.5 added the scales in the room and body composition, 1.6 named the AI model and the three exits from the EEA, 1.7 the food diary and the photograph of a plate. Every time, every guest was asked again.
The portal's notice is separate from the hotel's and covers the portal only: the account, the questionnaire, the walks and the watch. Booking a room and the hotel's newsletter live in the hotel's own policy.

A right that is promised but performed by writing to the hotel is, in practice, not performed. So the «Account» page carries a «My data» block, and in it four buttons.

A staff account is not deleted by them. A doctor's signature stands under other people's prescriptions and morning sheets, so an administrator removes such an account — that a signature is never silently detached.
The two depths of erasure, and what survives a deletion, are laid out in Your personal data: it also explains why the journal of kit handovers stays while the staff's notes about a guest go.
The server stands in the European Union; the country of the datacentre is named in each house's own notice. Data leaves it in exactly three cases, and all three are listed in the notice by name:
The portal has no advertising and no analytics counters. The guest's browser holds only the session token and the chosen language.
The daily history in a Garmin account, though, cannot be deleted: Garmin offers no way to do it. Those days stay with Garmin under Garmin's own terms even after our copy has been erased. The portal only ever reads from such an account the days of the stay during which the guest held that kit — but saying so is more honest than keeping quiet.
Each kind of data has a term of its own, and deletion within it means rows removed from the database, not hidden from the interface.
One record outlives the guest on purpose — the billing line for an active stay: its link to the account is nulled, so the month remembers that the stay happened but no longer names anybody (how an active guest is counted).
| What | How long |
|---|---|
| The account | until the guest deletes it |
| Questionnaires, walks, profile, drinking cure | three years after the last activity — or until consent is withdrawn |
| The food diary and the photographs in it | the same three years; a photograph goes off the disk with its entry, not only out of the list |
| Daily states from a lent watch | they stay on the guest's card between stays, the same three years |
| A password reset link | 60 minutes |
| Server logs | up to 90 days |
Some of the portal's texts are put into words by an artificial-intelligence model: the wording of the morning summary, the translation of a message from the doctor, the background of a walk postcard, the estimate of the calories on a photographed plate.
It does not compute the risk level, does not choose the heart-rate zone and does not change the programme — it is handed what the portal has already worked out. There is no automated decision with a legal effect (Article 22 GDPR) in the portal at all.
That a text was written by a model is said to the guest in the notice itself: Article 50 of the EU regulation on artificial intelligence requires it.
And the main safety catch: not one request carrying personal text goes out until the super-admin has confirmed that a data-processing agreement with the provider exists. The switch is off by default — silence is not consent. A free tier will not do for this: by the provider's own terms it learns from what it is sent.
Calories read off a photograph are shown with a range and can be corrected: it is an estimate from a picture, not a measurement.
Regulation (EU) 2016/679 — GDPR · Regulation (EU) 2017/745 on medical devices · Regulation (EU) 2024/1689 on artificial intelligence · Úřad pro ochranu osobních údajů
Your personal data: two consents, an export and a deletion — the same rights from the guest's side, button by button.
How the platform assigns procedures — where the algorithm stops and the doctor begins.
Pricing: Setup, Base and Active Guest — what the launch includes and how an active guest is counted.
What the watch measures — the figures that actually arrive from the wrist.
The desk: working with the apps — why a kit is erased before it goes to the next guest.
The full notice is open without signing in, on the privacy page.
← All articles