function PrivacyPolicy() {
  const privacyStyles = {
    section: {
      padding: 'clamp(96px, 13vw, 160px) clamp(24px, 5vw, 64px)',
      maxWidth: '880px',
      margin: '0 auto',
    },
    h1: {
      fontFamily: 'inherit',
      fontWeight: 500,
      fontSize: 'var(--fs-h1)',
      lineHeight: 1.1,
      letterSpacing: 'var(--ls-tight)',
      marginBottom: '8px',
    },
    lastUpdated: {
      color: 'var(--grey-500)',
      fontSize: 'var(--fs-body-sm)',
      marginBottom: '64px',
    },
    h2: {
      fontFamily: 'inherit',
      fontWeight: 500,
      fontSize: 'var(--fs-h4)',
      lineHeight: 1.2,
      letterSpacing: 'var(--ls-tight)',
      marginTop: '56px',
      marginBottom: '16px',
    },
    h3: {
      fontFamily: 'inherit',
      fontWeight: 500,
      fontSize: 'var(--fs-body-lg)',
      lineHeight: 1.3,
      marginTop: '32px',
      marginBottom: '12px',
    },
    p: {
      fontSize: 'var(--fs-body)',
      lineHeight: 1.6,
      marginBottom: '16px',
      color: 'var(--grey-900)',
    },
    ul: {
      fontSize: 'var(--fs-body)',
      lineHeight: 1.6,
      color: 'var(--grey-900)',
      paddingLeft: '24px',
      marginBottom: '16px',
    },
    li: {
      marginBottom: '8px',
    },
    tableWrapper: {
      overflowX: 'auto',
      marginBottom: '24px',
    },
    table: {
      width: '100%',
      borderCollapse: 'collapse',
      fontSize: 'var(--fs-body-sm)',
    },
    th: {
      textAlign: 'left',
      fontWeight: 500,
      padding: '10px 16px',
      borderBottom: '2px solid var(--grey-300)',
      color: 'var(--grey-900)',
    },
    td: {
      padding: '10px 16px',
      borderBottom: '1px solid var(--grey-100)',
      color: 'var(--grey-900)',
      verticalAlign: 'top',
    },
    hr: {
      border: 'none',
      borderTop: '1px solid var(--grey-100)',
      margin: '0',
    },
    a: {
      color: 'var(--teal)',
      textDecoration: 'none',
    },
    strong: {
      fontWeight: 500,
      color: 'var(--grey-900)',
    },
  };

  return (
    <main>
      <div style={privacyStyles.section}>
        <h1 style={privacyStyles.h1}>Privacy Policy</h1>
        <p style={privacyStyles.lastUpdated}>Last updated: 25 June 2026</p>

        <p style={privacyStyles.p}>This Privacy Policy explains how <strong style={privacyStyles.strong}>Eivi Health OÜ</strong> ("Eivi", "we", "us", or "our") collects, uses, stores, shares, and protects your personal data when you use the Eivi mobile application (the "App"), our website at <a href="https://eivi.health" style={privacyStyles.a}>eivi.health</a>, and any related services (together, the "Service").</p>
        <p style={privacyStyles.p}>We are committed to protecting your privacy and handling your data transparently and lawfully. Because Eivi is a metabolic-health service, some of the information we process is <strong style={privacyStyles.strong}>health data</strong>, which is treated as a special category of personal data under European law and is given extra protection. This policy describes how we handle that data.</p>
        <p style={privacyStyles.p}>This policy is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Irish Data Protection Act 2018, and Apple's App Store requirements.</p>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>1. Who we are (Data Controller)</h3>
        <p style={privacyStyles.p}>The data controller responsible for your personal data is:</p>
        <ul style={privacyStyles.ul}>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Eivi Health OÜ</strong> (trading as "Eivi" / DBA Eivi)</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Registered address:</strong> Narva mnt 5, Kesklinna linnaosa, Tallinn, Harju maakond, Estonia</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Company registration number:</strong> 17433648 (registry code, Estonia)</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Contact email:</strong> <a href="mailto:privacy@eivihealth.com" style={privacyStyles.a}>privacy@eivihealth.com</a></li>
        </ul>
        <p style={privacyStyles.p}>If you have any questions about this policy or how we handle your data, you can reach us at the email above.</p>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>2. The data we collect</h3>
        <p style={privacyStyles.p}>We collect the following categories of personal data.</p>

        <h4 style={privacyStyles.h3}>2.1 Information you provide to us</h4>
        <ul style={privacyStyles.ul}>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Account information:</strong> name, email address, and password when you create an account.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Payment and billing information:</strong> Eivi subscriptions are purchased separately (for example, through our website) and payments are processed by our payment processor <strong style={privacyStyles.strong}>Stripe</strong>. The App itself does not offer any payment or subscription-purchase options. Eivi does not store your full card number; we retain only limited billing records (e.g. the fact and amount of a transaction) needed to manage your subscription.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Profile and health-context information:</strong> information you choose to enter such as date of birth, sex, height, weight, dietary preferences, and health goals.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Metabolic and glucose data (special category health data):</strong> continuous glucose monitor (CGM) readings, meal and food logs, activity, and other metabolic information you record or connect to the App.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Other biometric data from connected services (special category health data):</strong> if you choose to, you can link a third-party health aggregation service — such as <strong style={privacyStyles.strong}>Apple Health</strong>, <strong style={privacyStyles.strong}>Google Health Connect</strong>, or similar — to import additional biometrics like heart rate and step count. This integration is <strong style={privacyStyles.strong}>strictly opt-in</strong>: we only receive this data after you actively link the service and grant permission, and you can disconnect it at any time.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Photos and images you submit (may include special category health data):</strong> images you choose to upload — for example photos of meals — which we and our AI provider analyse to give you feedback. Such photos can reveal health-related information and are treated as special category data where they do.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Communications:</strong> the contents of messages, support requests, and feedback you send us.</li>
        </ul>

        <h4 style={privacyStyles.h3}>2.2 Information collected automatically</h4>
        <ul style={privacyStyles.ul}>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Device and technical data:</strong> device model, operating system version, app version, language settings, and a non-identifying device identifier used to keep the App working.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Usage data:</strong> which features you use and how you interact with the App, used to operate and improve the Service.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Diagnostics:</strong> crash logs and performance data.</li>
        </ul>

        <h4 style={privacyStyles.h3}>2.3 Information we do <em>not</em> collect</h4>
        <ul style={privacyStyles.ul}>
          <li style={privacyStyles.li}>We do <strong style={privacyStyles.strong}>not</strong> store your full payment card number. Where you purchase a subscription, payment is processed by <strong style={privacyStyles.strong}>Stripe</strong> (see Sections 2.1 and 5). The App itself contains no payment or in-app-purchase functionality.</li>
          <li style={privacyStyles.li}>We do <strong style={privacyStyles.strong}>not</strong> track you across other companies' apps or websites for advertising.</li>
        </ul>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>3. How we use your data, and our legal basis</h3>
        <p style={privacyStyles.p}>Under GDPR we must have a lawful basis for each use of your data. The table below sets out what we do and why.</p>
        <div style={privacyStyles.tableWrapper}>
          <table style={privacyStyles.table}>
            <thead>
              <tr>
                <th style={privacyStyles.th}>Purpose</th>
                <th style={privacyStyles.th}>Data used</th>
                <th style={privacyStyles.th}>Legal basis (GDPR)</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td style={privacyStyles.td}>Create and manage your account</td>
                <td style={privacyStyles.td}>Account information</td>
                <td style={privacyStyles.td}>Performance of a contract (Art. 6(1)(b))</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Provide the core metabolic-health features (display, analyse, and store your glucose and metabolic data)</td>
                <td style={privacyStyles.td}>Health data, profile data</td>
                <td style={privacyStyles.td}><strong style={privacyStyles.strong}>Your explicit consent</strong> (Art. 9(2)(a))</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Import and use biometrics from a service you have linked (e.g. Apple Health, Google Health Connect)</td>
                <td style={privacyStyles.td}>Connected biometric health data</td>
                <td style={privacyStyles.td}><strong style={privacyStyles.strong}>Your explicit consent</strong> (Art. 9(2)(a))</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Use AI to analyse your data and photos to generate insights, feedback, and features (see Section 6)</td>
                <td style={privacyStyles.td}>Health data, photos, profile and other inputs you provide</td>
                <td style={privacyStyles.td}><strong style={privacyStyles.strong}>Your explicit consent</strong> (Art. 9(2)(a))</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Process payments and manage your subscription</td>
                <td style={privacyStyles.td}>Payment and billing information</td>
                <td style={privacyStyles.td}>Performance of a contract (Art. 6(1)(b)) / legal obligation (Art. 6(1)(c)) for tax and accounting records</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Keep the Service secure and working, fix bugs</td>
                <td style={privacyStyles.td}>Device, usage, diagnostics</td>
                <td style={privacyStyles.td}>Legitimate interests (Art. 6(1)(f))</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Respond to your support requests</td>
                <td style={privacyStyles.td}>Communications, account info</td>
                <td style={privacyStyles.td}>Performance of a contract / legitimate interests</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Improve and develop the Service</td>
                <td style={privacyStyles.td}>Usage data (aggregated/de-identified where possible)</td>
                <td style={privacyStyles.td}>Legitimate interests (Art. 6(1)(f))</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Send service-related emails (e.g. security, account)</td>
                <td style={privacyStyles.td}>Account info</td>
                <td style={privacyStyles.td}>Performance of a contract</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Send marketing emails (if you opt in)</td>
                <td style={privacyStyles.td}>Account info</td>
                <td style={privacyStyles.td}><strong style={privacyStyles.strong}>Your consent</strong> (Art. 6(1)(a))</td>
              </tr>
            </tbody>
          </table>
        </div>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Health data and consent.</strong> Because your glucose and metabolic data is special category data, we rely on your <strong style={privacyStyles.strong}>explicit consent</strong> to process it (Article 9(2)(a) GDPR). You can withdraw that consent at any time (see Section 9); withdrawing it will not affect processing carried out before you withdrew, but may mean we can no longer provide core features of the App.</p>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>4. How and where we store your data, and security</h3>
        <p style={privacyStyles.p}>We store your data on secure servers operated by our infrastructure and service providers (see Section 5). Where possible we host and process EU users' data within the <strong style={privacyStyles.strong}>European Economic Area (EEA)</strong>.</p>
        <p style={privacyStyles.p}>We protect your data using measures including:</p>
        <ul style={privacyStyles.ul}>
          <li style={privacyStyles.li}>Encryption of data in transit (TLS) and encryption of data at rest;</li>
          <li style={privacyStyles.li}>Access controls limiting who within Eivi can access personal data;</li>
          <li style={privacyStyles.li}>Regular review of our security practices.</li>
        </ul>
        <p style={privacyStyles.p}>No system is perfectly secure, but we take reasonable and appropriate technical and organisational measures to protect your data, as required by Article 32 GDPR.</p>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>5. Third parties we share data with (processors)</h3>
        <p style={privacyStyles.p}>We do not sell your personal data. We share it only with service providers ("data processors") who help us run the Service, and only to the extent necessary. Each is bound by a data processing agreement requiring them to protect your data and use it only on our instructions.</p>
        <p style={privacyStyles.p}>Our processors currently include:</p>
        <div style={privacyStyles.tableWrapper}>
          <table style={privacyStyles.table}>
            <thead>
              <tr>
                <th style={privacyStyles.th}>Provider</th>
                <th style={privacyStyles.th}>Purpose</th>
                <th style={privacyStyles.th}>Location</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td style={privacyStyles.td}>Vercel</td>
                <td style={privacyStyles.td}>Website hosting (the public website only — not part of the App)</td>
                <td style={privacyStyles.td}>US</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Sanity</td>
                <td style={privacyStyles.td}>Content management</td>
                <td style={privacyStyles.td}>US</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Stripe</td>
                <td style={privacyStyles.td}>Payment and subscription processing</td>
                <td style={privacyStyles.td}>EU</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Apple</td>
                <td style={privacyStyles.td}>App distribution (App Store)</td>
                <td style={privacyStyles.td}>EU</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Loops (loops.so)</td>
                <td style={privacyStyles.td}>Opt-in marketing email</td>
                <td style={privacyStyles.td}>US</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>Resend (resend.com)</td>
                <td style={privacyStyles.td}>Transactional/in-product email (e.g. account, security, service notices)</td>
                <td style={privacyStyles.td}>US</td>
              </tr>
              <tr>
                <td style={privacyStyles.td}>OpenAI (openai.com)</td>
                <td style={privacyStyles.td}>AI analysis of health data, photos, and other inputs to power app features (see Section 6)</td>
                <td style={privacyStyles.td}>US</td>
              </tr>
            </tbody>
          </table>
        </div>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Health data integrations.</strong> Where you link a service such as Apple Health or Google Health Connect, that service acts as a <em>source</em> of data you choose to share with us, governed by that provider's own terms and your device permissions. We receive only the data you authorise, and we use it solely to provide the Service to you — never for advertising, marketing lists, or sale.</p>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>6. Use of artificial intelligence (AI)</h3>
        <p style={privacyStyles.p}>We use artificial intelligence to power parts of the Service — for example, to analyse your metabolic and health data, interpret photos you submit (such as meal photos), and generate insights, feedback, and other features for you.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Our AI provider.</strong> This processing is carried out using AI services provided by <strong style={privacyStyles.strong}>OpenAI</strong> (based in the United States). To do this, we send the relevant data — which may include your health and metabolic data, connected biometrics, photos you upload, and other content you provide — to OpenAI's API so it can be analysed and returned to you within the App.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Legal basis, and why AI is integral.</strong> AI analysis is a core, intrinsic part of how Eivi works — it is not an optional feature you can switch off while continuing to use the Service. When you sign up for and use Eivi, you provide your <strong style={privacyStyles.strong}>explicit consent</strong> (Article 9(2)(a) GDPR) to this processing of your health data. If you no longer wish your data to be processed in this way, your route to withdraw is to stop using the Service and delete your account; we cannot provide the Service without this processing.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>We minimise the data sent to AI.</strong> Before your information is sent to our AI provider, we strip out direct identifiers such as your name and email address, so that the content analysed by the AI is not labelled with details that name you. Because we still link the AI's output back to your account in order to give you your personal results, this data remains personal data under GDPR (a pseudonymisation measure, not full anonymisation) and stays protected under this policy. We do not send your account identity to the AI provider alongside your health data.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Photos.</strong> Photos are pseudonymised in the same way, and we remove technical metadata (such as EXIF and location data) before they are processed. However, we cannot strip out identifying details that you yourself choose to include in an image — for example, if your face, a document, or other personal information is visible in a photo you take and upload. Please avoid including such details in photos unless they are necessary.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>No use for model training.</strong> We use OpenAI through its business/API service, under terms which provide that data sent to the API is <strong style={privacyStyles.strong}>not used to train OpenAI's models</strong>. We do not permit OpenAI to use your data for any purpose other than performing the analysis we request.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>International transfer.</strong> Because OpenAI processes data in the United States, this involves an international transfer, which we safeguard as described in Section 7.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Not a substitute for medical advice, and no solely-automated decisions.</strong> AI-generated insights are provided to support and inform you. They are <strong style={privacyStyles.strong}>not medical advice</strong> and should not replace consultation with a qualified healthcare professional. We do not use AI to make decisions that produce legal effects concerning you, or similarly significant effects, without human involvement.</p>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>7. International transfers</h3>
        <p style={privacyStyles.p}>If any of our processors store or process data outside the EEA (for example, in the United States), we ensure an appropriate safeguard is in place as required by Chapter V of the GDPR — typically the European Commission's <strong style={privacyStyles.strong}>Standard Contractual Clauses (SCCs)</strong> or reliance on an <strong style={privacyStyles.strong}>adequacy decision</strong> (such as the EU–US Data Privacy Framework, where the provider is certified).</p>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>8. How long we keep your data</h3>
        <p style={privacyStyles.p}>We keep your personal data only for as long as necessary for the purposes set out in this policy:</p>
        <ul style={privacyStyles.ul}>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Account and health data:</strong> we retain your account and health data for <strong style={privacyStyles.strong}>12 months after you stop using the Service</strong> (for example, after your subscription ends or your last activity), so that you can return and resume with your data still available to you. If you ask us to delete your data sooner, we will delete or irreversibly anonymise it at that point. After the 12-month period, we delete or anonymise your data unless we are required to keep limited records to meet a legal obligation.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Billing records:</strong> where we are legally required to (for example, under Estonian and EU accounting and tax law), we retain limited transaction records for the period required by law, even after the rest of your data has been deleted.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Diagnostic and usage logs:</strong> retained for no longer than 12 months.</li>
        </ul>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>9. Your rights under GDPR</h3>
        <p style={privacyStyles.p}>If you are in the EU/EEA, you have the following rights over your personal data:</p>
        <ul style={privacyStyles.ul}>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Right of access</strong> — request a copy of the data we hold about you.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Right to rectification</strong> — correct inaccurate or incomplete data.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Right to erasure</strong> ("right to be forgotten") — request deletion of your data.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Right to restriction</strong> — ask us to limit how we use your data.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Right to data portability</strong> — receive your data in a structured, machine-readable format and have it transferred where technically feasible.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Right to object</strong> — object to processing based on our legitimate interests.</li>
          <li style={privacyStyles.li}><strong style={privacyStyles.strong}>Right to withdraw consent</strong> — where we rely on consent (including for your health data), you can withdraw it at any time.</li>
        </ul>
        <p style={privacyStyles.p}>To exercise any of these rights, email us at <a href="mailto:privacy@eivihealth.com" style={privacyStyles.a}>privacy@eivihealth.com</a>. We will respond within <strong style={privacyStyles.strong}>one month</strong>, as required by GDPR. We will not charge you for exercising your rights in normal circumstances.</p>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>10. Apple App Store and tracking</h3>
        <p style={privacyStyles.p}>The Eivi App is distributed through the Apple App Store. A link to this Privacy Policy is available both on the App Store listing and within the App, as required by Apple's App Review Guidelines (5.1.1).</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Tracking.</strong> We do not track you across other companies' apps and websites, and we do not use the App for advertising. If this changes, we will request your permission through Apple's <strong style={privacyStyles.strong}>App Tracking Transparency</strong> prompt before any such tracking, and you can decline.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Payments and subscriptions.</strong> The App does not offer any payment or subscription-purchase options; these are handled separately (for example, via our website). The App requires an active, pre-existing Eivi subscription to activate. Subscription payments are processed by <strong style={privacyStyles.strong}>Stripe</strong> (see Section 5).</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Health data on Apple devices.</strong> Where you grant the App access to Apple Health (HealthKit) data, we use that data only to provide the Service to you. In line with Apple's requirements, we do not use HealthKit data for advertising, marketing, or data-mining, and we do not share it with third parties except the processors listed in Section 5 who help us operate the Service.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Permissions.</strong> The App may ask for permission to access certain features or data (for example, to import glucose readings, link a health service, or send notifications). You can grant or refuse these in your device settings, and the App will continue to function as fully as possible without them.</p>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>11. Google Play Store and Android</h3>
        <p style={privacyStyles.p}>The Eivi App is also distributed through the Google Play Store. A link to this Privacy Policy is available on the Play Store listing and within the App.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Data Safety.</strong> Google Play requires us to declare the data our App collects and how it is used in its Data Safety section. Those declarations reflect this Privacy Policy. If you notice any discrepancy between the Play Store Data Safety section and this policy, this policy governs.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Tracking.</strong> We do not track you across other companies' apps and websites, and we do not use the App for advertising.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Health data on Android devices.</strong> Where you grant the App access to Google Health Connect data, we use that data only to provide the Service to you. In line with Google's Health Connect Permissions Policy, we do not use Health Connect data for advertising, marketing, or data-mining, we do not sell it, and we do not share it with third parties except the processors listed in Section 5 who help us operate the Service.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Permissions.</strong> The App may request permission to access certain features or data on your device (for example, to import glucose readings, link a health service, or send notifications). You can grant or refuse these in your device settings, and the App will continue to function as fully as possible without them.</p>
        <p style={privacyStyles.p}><strong style={privacyStyles.strong}>Payments and subscriptions.</strong> The App does not offer any in-app purchases or subscription options through Google Play Billing; subscriptions are handled separately (for example, via our website). The App requires an active, pre-existing Eivi subscription to activate. Subscription payments are processed by <strong style={privacyStyles.strong}>Stripe</strong> (see Section 5).</p>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>12. Children's privacy</h3>
        <p style={privacyStyles.p}>The Service is not available to anyone under the age of <strong style={privacyStyles.strong}>18</strong>. We verify age during the sign-up process and do not permit anyone under 18 to create an account or use the Service. We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has provided us with personal data, contact us and we will delete it.</p>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>13. Changes to this policy</h3>
        <p style={privacyStyles.p}>We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the App or by email. Please review this page periodically.</p>

        <hr style={privacyStyles.hr} />

        <h3 style={privacyStyles.h2}>14. Contact us and your right to complain</h3>
        <p style={privacyStyles.p}>If you have any questions, concerns, or requests regarding this policy or your data, please contact us first at:</p>
        <p style={privacyStyles.p}>
          <strong style={privacyStyles.strong}>Eivi Health OÜ</strong> (DBA Eivi)<br />
          Narva mnt 5, Kesklinna linnaosa, Tallinn, Harju maakond, Estonia<br />
          Email: <a href="mailto:privacy@eivihealth.com" style={privacyStyles.a}>privacy@eivihealth.com</a>
        </p>
        <p style={privacyStyles.p}>You also have the right to lodge a complaint with your data protection supervisory authority. As our users are based in Ireland and the EU, the relevant authority in Ireland is:</p>
        <p style={privacyStyles.p}>
          <strong style={privacyStyles.strong}>Data Protection Commission (DPC)</strong><br />
          6 Pembroke Row, Dublin 2, D02 X963, Ireland<br />
          Website: <a href="https://www.dataprotection.ie" style={privacyStyles.a}>www.dataprotection.ie</a><br />
          Email: <a href="mailto:info@dataprotection.ie" style={privacyStyles.a}>info@dataprotection.ie</a>
        </p>
        <p style={privacyStyles.p}>The DPC generally asks that you raise your concern with us first before lodging a formal complaint. If you are based in another EU member state, you may instead contact your local supervisory authority.</p>
      </div>
    </main>
  );
}

window.PrivacyPolicy = PrivacyPolicy;
