← Back to Metabolic Twin
Privacy Policy
Last updated: 8 May 2026
This Privacy Policy explains how SK Solutions SIA ("we", "us", "our") processes personal data when you use Metabolic Twin (https://metabolic-twin.eternix.ai), a wellness planning service operated by SK Solutions SIA. This policy is written to meet GDPR Articles 13–14, the Latvian Personal Data Processing Law, and applicable EU Member State requirements.
1. Data controller
SK Solutions SIA
Kipsalas iela 4, LV-1048, Riga, Latvia
Email: info@eternix.ai
Operating brand: Eternix · Product: Metabolic Twin
2. What data we collect
At €1 reservation (current pre-launch stage)
- Email address — to confirm reservation, send onboarding instructions, and notify of refund if applicable.
- Stripe payment metadata — country of card issuance, last 4 digits of card number, name on card, billing address (collected by Stripe for VAT/OSS compliance and fraud screening). We do not store full card numbers; Stripe is the payment processor.
- Reservation tier (Core or Premium founder).
- Marketing attribution (UTM parameters from referring source) — to measure campaign effectiveness.
No health data is collected at the €1 reservation stage.
At onboarding (post-launch — not yet active)
- Self-reported weight, waist measurement, meals, activity
- Optional integration data: continuous glucose monitor (Libre, Dexcom), wearables (Oura, Whoop, Apple Watch)
- Optional self-reported labs (cholesterol, HbA1c, etc.)
- Treatment timeline and goal information
This data is special category personal data under GDPR Article 9 (data concerning health) and is processed only on the basis of your explicit consent (Art. 9(2)(a)).
3. Legal bases for processing
- Contract performance (Art. 6(1)(b)): for €1 reservation, founder subscription, refund processing.
- Legal obligation (Art. 6(1)(c)): tax records (Latvian Commercial Code, EU OSS VAT), accounting (7-year retention).
- Legitimate interests (Art. 6(1)(f)): fraud prevention, service security, product improvement (anonymous aggregate analytics only).
- Explicit consent (Art. 9(2)(a)): all health-related data processing at and after onboarding.
4. Sub-processors and where data is stored
We use the following sub-processors to deliver the service. Each is bound by Data Processing Agreements that meet GDPR standards:
- Stripe Payments Europe Ltd (Ireland) — payment processing. Some data may transit to Stripe Inc. (USA) under EU Standard Contractual Clauses. Privacy: stripe.com/privacy
- Cloudflare, Inc. (USA) — content delivery, hosting, email routing. Data is processed under Standard Contractual Clauses; static assets served from EU edge nodes (Frankfurt, Amsterdam, Stockholm). Privacy: cloudflare.com/privacypolicy
- Namecheap PrivateEmail — inbound email for
info@eternix.ai and reserve@eternix.ai.
For the post-launch product (health data), we will use EU/EEA-only infrastructure and update this policy with named sub-processors before the first health-data ingestion.
5. International transfers
Where data is transferred outside the EU/EEA (Stripe USA, Cloudflare USA), we rely on the European Commission's Standard Contractual Clauses (2021/914) and applicable supplementary safeguards (e.g., encryption at rest and in transit, access controls).
6. Retention
- Reservation data (email, plan choice): retained until refund completion, OR for 24 months after subscription ends, whichever is later.
- Tax and accounting records: 7 years per Latvian Commercial Code.
- Stripe payment records: per Stripe's retention schedule (typically 7 years for tax compliance).
- Health data (post-launch): retained while subscription is active; deleted within 30 days of cancellation unless you request earlier deletion.
7. Your rights
Under GDPR you have the right to:
- Access your personal data (Art. 15)
- Request rectification (Art. 16)
- Request erasure / "right to be forgotten" (Art. 17)
- Restrict processing (Art. 18)
- Data portability (Art. 20) — receive your data in machine-readable format
- Object to processing based on legitimate interests (Art. 21)
- Withdraw consent at any time (Art. 7(3)) — without affecting the lawfulness of prior processing
- Lodge a complaint with a supervisory authority — for Latvia: Datu valsts inspekcija (dvi.gov.lv)
To exercise any of these rights, email info@eternix.ai. We respond within 30 days (Art. 12(3)).
8. Cookies and tracking
We use Cloudflare Web Analytics, which is cookieless and does not track individual users. No third-party advertising cookies are set. The site sets only essential cookies needed for core functionality (none currently — this section will be updated if essential cookies are introduced).
9. Children
Metabolic Twin is intended for adults aged 18 and older. We do not knowingly collect data from children. If you believe a child has submitted data, contact info@eternix.ai and we will delete it.
10. Security
We use TLS 1.3 for data in transit, encryption at rest for any health data we store, role-based access controls for staff (currently a one-person organization; staff = founder), and incident response procedures. We will notify the Latvian supervisory authority within 72 hours of any personal data breach (Art. 33) and notify affected users without undue delay if the breach is likely to result in high risk to their rights (Art. 34).
11. Changes to this policy
We may update this policy as the product evolves. Material changes (new sub-processors, new categories of data) will be notified by email to active users at least 30 days before the change takes effect.
12. Contact
Data protection contact: info@eternix.ai
Postal address: SK Solutions SIA, Kipsalas iela 4, LV-1048, Riga, Latvia