Privacy notice.

Effective date: 18 September 2026. Version 2.0.

1. Introduction and scope

1.1 ReAble Labs Ltd ("ReAble Labs", "we", "us" or "our") is committed to protecting the personal data of every person who visits or corresponds with us through the website located at reablelabs.ie (the "Website").

1.2 This Privacy Notice explains what personal data we collect through the Website, the purposes for which we process it, the legal bases on which we rely, the parties with whom we share it, the periods for which we retain it, the safeguards we apply to any transfer of personal data outside the European Economic Area, and the rights available to you as a data subject.

1.3 This Privacy Notice applies exclusively to personal data processed through the Website and to correspondence arising from it. It does not apply to:

  • (a) personal data processed in the course of any clinical investigation, clinical evaluation or clinical observation conducted by or with ReAble Labs, which is governed by the participant information and consent documentation provided to participants by the relevant investigating site;
  • (b) personal data processed by any device, application or software developed by ReAble Labs, including the Diego hand and the ReMould application, which is or will be governed by separate device and application privacy documentation supplied to users and to clinics;
  • (c) personal data processed in the context of employment, engagement or recruitment, which is governed by separate notices supplied to candidates and personnel;
  • (d) personal data processed by third parties whose services or websites are accessible through links from the Website.

1.4 Capitalised terms not otherwise defined in this Privacy Notice bear the meanings given to them in Article 4 of the General Data Protection Regulation (Regulation (EU) 2016/679) (the "GDPR").

2. Identity and contact details of the controller

2.1 The data controller in respect of the processing described in this Privacy Notice is:

A private company limited by shares, incorporated in Ireland
Company registration number: 797644
Registered office: Dogpatch Labs, Unit 1, The CHQ Building, Custom House Quay, Dublin 1, Ireland
Electronic mail: sean@reablelabs.ie

2.2 ReAble Labs has not appointed a Data Protection Officer, not being an undertaking to which Article 37(1) of the GDPR applies. All enquiries concerning this Privacy Notice, and all requests made under Chapter III of the GDPR, should be directed to the electronic mail address at clause 2.1 and marked for the attention of the Chief Executive Officer.

3. Categories of personal data processed

3.1 Data you provide through the enquiry form. Where you submit the enquiry form published on the Website, we process the name you supply, the electronic mail address you supply, the name of the organisation you supply where you elect to supply one, the enquiry category you select, and the content of the message you compose.

3.2 Data generated by your correspondence with us. Where an exchange of correspondence follows your enquiry, we process the content of that correspondence together with associated metadata, including the dates and times of transmission and the electronic mail addresses of the parties to the exchange.

3.3 Analytics data. Where, and only where, you have signified your consent through the mechanism described in the Cookie notice, we process data generated by your interaction with the Website, comprising the pages requested, the dates and times of those requests, the approximate geographic region derived from your internet protocol address, and technical information concerning the device, operating system and browser used. Google Analytics 4 does not retain internet protocol addresses in a form accessible to us.

3.4 Technical log data. The web server on which the Website is hosted records, for each request, the internet protocol address from which the request originated, the date and time of the request, the resource requested, the response code returned, and the browser user agent string. These logs are rotated automatically and are retained for the period stated at clause 8.1. Our electronic mail provider separately records, for each message sent through the Website, the recipient address, the subject, the delivery status and the message content, for the period stated at clause 8.1.

3.5 Special categories of personal data. We do not solicit, and we have no wish to receive, personal data falling within Article 9(1) of the GDPR, including data concerning health. You are asked not to include information concerning your health, diagnosis, prognosis, clinical history or medical treatment in any message sent through the Website. Where such information is nonetheless volunteered by you, we process it solely for the purpose of responding to your correspondence, in reliance on Article 9(2)(a), and we erase it upon conclusion of the exchange or within six months of receipt, whichever occurs first.

3.6 We do not process personal data relating to criminal convictions or offences. We do not knowingly process personal data relating to children. We do not acquire personal data relating to you from data brokers, list vendors or other third-party sources.

5. Provision of data and consequences of failure to provide it

5.1 The provision of the personal data described at clause 3.1 is neither a statutory nor a contractual requirement. You are under no obligation to provide it. The consequence of not providing it is that we will be unable to respond to you, the enquiry form being the mechanism by which correspondence is initiated.

5.2 The provision of consent to the processing described at clause 3.3 is entirely voluntary. Refusal has no consequence for your use of the Website, no part of which is conditioned upon that consent.

6. Recipients and categories of recipient

6.1 Personal data processed through the Website is disclosed only to the following categories of recipient:

  • (a) Processors. The service providers identified at Schedule 1, each of which processes personal data solely on our documented instructions under a written agreement satisfying Article 28(3) of the GDPR.
  • (b) Professional advisers. Our legal advisers, accountants, auditors and insurers, where disclosure is necessary for the purposes of obtaining professional advice or of establishing, exercising or defending a legal claim.
  • (c) Public authorities. Any court, regulator, supervisory authority or law enforcement agency, where disclosure is required by law or by a validly issued order, including the Data Protection Commission, the Health Products Regulatory Authority and the Revenue Commissioners. A public authority receiving personal data in the framework of a particular inquiry in accordance with law is not treated as a recipient under Article 4(9) of the GDPR.
  • (d) Successors in title. Any person to whom we transfer, or propose to transfer, the whole or part of our business or assets, in which case personal data may be disclosed subject to appropriate confidentiality undertakings.

6.2 We do not disclose personal data to any other person. In particular, no personal data collected through the Website is disclosed to any clinical partner, research institution, investor or robotics undertaking except where you have expressly asked us to make an introduction.

7. Transfers to third countries

7.1 The Website, its database and its server logs are hosted exclusively in Ireland. Personal data is stored within the European Economic Area save where a transfer is described at Schedule 1.

7.1A The single routine transfer outside the European Economic Area arises from the transmission of electronic mail. Our mail delivery provider, Resend, Inc., stores customer data in the United States of America. That transfer is governed by the provider's data processing agreement, which incorporates the standard contractual clauses adopted by the European Commission.

7.2 Where a transfer of personal data to a third country is necessary, we effect that transfer only where one of the following conditions is satisfied:

  • (a) the European Commission has decided under Article 45 of the GDPR that the third country ensures an adequate level of protection, including, in the case of certified recipients in the United States of America, under the EU to US Data Privacy Framework;
  • (b) the transfer is subject to the standard contractual clauses adopted by the European Commission under Article 46(2)(c) of the GDPR, supplemented where necessary by such technical, contractual and organisational measures as our transfer impact assessment identifies; or
  • (c) a derogation under Article 49 of the GDPR applies.

7.3 You may obtain a copy of the safeguards relied upon in respect of any particular transfer by writing to the address at clause 2.1.

8. Retention

8.1 We retain personal data only for so long as is necessary for the purposes for which it was collected, subject to any longer period required by law. The periods applied are set out below.

CategoryRetention periodCriterion
Enquiry form submissions and associated correspondence which do not lead to a continuing relationship3 years from the date of the final message in the exchangeThe period within which a related enquiry or complaint may reasonably be expected to arise
Correspondence forming part of, or evidencing, a contract, partnership, letter of intent or other commercial or clinical arrangement7 years from the end of the accounting period to which it relatesSection 886 of the Taxes Consolidation Act 1997 and section 286 of the Companies Act 2014
Special category data volunteered contrary to clause 3.5Until the conclusion of the exchange, and in any event not more than 6 monthsData minimisation under Article 5(1)(c)
Analytics data held in Google Analytics14 months from collection, after which automatic deletion occursThe shortest period permitting year on year comparison
Records of consent given or withheld under the Cookie notice6 months from the date the choice was recordedThe interval at which consent is refreshed
Web server access and error logs14 days, by automatic rotationThe period necessary to investigate an availability or security incident
Electronic mail sending records held by our mail delivery provider, comprising recipient address, subject, delivery status and message content30 days, after which they are deleted automatically by the providerThe retention period applied by the provider across all plans
Records evidencing compliance with this Privacy Notice, including records of data subject requests3 years from the date of the requestAccountability under Article 5(2)

8.2 Upon expiry of the applicable period, personal data is erased or irreversibly anonymised. Where erasure is not immediately practicable because data is held in backup media, the data is isolated from further processing and erased upon the expiry of the backup cycle.

9. Rights of the data subject

9.1 Right of access. You have the right under Article 15 of the GDPR to obtain confirmation as to whether personal data concerning you is being processed and, where that is so, to obtain a copy of that data together with the information specified in Article 15(1).

9.2 Right to rectification. You have the right under Article 16 to obtain without undue delay the rectification of inaccurate personal data concerning you, and to have incomplete data completed.

9.3 Right to erasure. You have the right under Article 17 to obtain the erasure of personal data concerning you where one of the grounds in Article 17(1) applies, subject to the exceptions in Article 17(3).

9.4 Right to restriction. You have the right under Article 18 to obtain the restriction of processing where one of the grounds in Article 18(1) applies, including while the accuracy of data is contested or while an objection under Article 21 is being considered.

9.5 Right to data portability. You have the right under Article 20 to receive personal data which you have provided to us, where processing is based on consent or on contract and is carried out by automated means, in a structured, commonly used and machine-readable format, and to transmit that data to another controller.

9.6 Right to object. You have the right under Article 21(1) to object, on grounds relating to your particular situation, to processing based on Article 6(1)(f). Upon receipt of such an objection we will cease processing unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.

9.7 Right to withdraw consent. Where processing is based on consent, you have the right under Article 7(3) to withdraw that consent at any time. Withdrawal is as straightforward as the giving of consent and is effected through the mechanism described in the Cookie notice. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

9.8 Exercise of rights. Requests should be made in writing to the address at clause 2.1. We will respond without undue delay and in any event within one month of receipt. That period may be extended by two further months where necessary, taking into account the complexity and number of requests, in which case we will inform you of the extension and of the reasons for it within one month of receipt.

9.9 Verification. Where we entertain reasonable doubts concerning the identity of the person making a request, we may request the provision of additional information necessary to confirm identity, in accordance with Article 12(6). We request no more information than is necessary for that purpose.

9.10 Fees. No fee is charged for the exercise of any right. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may charge a reasonable fee reflecting the administrative costs of compliance, or refuse to act on the request, and in either case we will explain our reasoning and inform you of your right to complain.

9.11 Right to lodge a complaint. Without prejudice to any other administrative or judicial remedy, you have the right under Article 77 to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The supervisory authority in Ireland is:

Data Protection Commission
6 Pembroke Row, Dublin 2, D02 X963, Ireland
Telephone: +353 1 765 0100 or 1800 437 737
Website: dataprotection.ie

9.12 We would be grateful for the opportunity to address any concern before you approach the Data Protection Commission, but you are under no obligation to contact us first.

10. Security

10.1 Having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as to the risks of varying likelihood and severity for the rights and freedoms of natural persons, we implement appropriate technical and organisational measures under Article 32 of the GDPR, including:

  • (a) transmission of all Website traffic over Transport Layer Security, with HTTP Strict Transport Security enabled;
  • (b) multi-factor authentication on the electronic mail accounts and administrative accounts through which personal data is accessible;
  • (c) restriction of access to personal data to those personnel who require it in order to perform their duties;
  • (d) selection of processors which provide sufficient guarantees to implement appropriate technical and organisational measures, and the imposition upon them of obligations under Article 28(3);
  • (e) minimisation of the personal data collected, such that no account, customer database or payment mechanism exists on the Website; and
  • (f) periodic review of these measures and of their effectiveness.

10.2 Personal data breaches. In the event of a personal data breach we will, where the breach is likely to result in a risk to the rights and freedoms of natural persons, notify the Data Protection Commission without undue delay and, where feasible, not later than 72 hours after becoming aware of it, in accordance with Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will communicate it to you without undue delay in accordance with Article 34. We maintain an internal record of all personal data breaches, their effects and the remedial action taken.

10.3 No method of transmission over the internet, and no method of electronic storage, is entirely secure. While we apply the measures described above, we cannot guarantee absolute security, and transmission of data to us over the internet is at your own risk.

12. Amendment of this Privacy Notice

12.1 We may amend this Privacy Notice from time to time in order to reflect changes in our processing activities or in applicable law. The effective date and version number at the head of this document will be updated accordingly.

12.2 Where an amendment materially alters the purposes or manner of processing, we will bring the amendment to your attention by a prominent notice on the Website, and, where the amendment requires it, we will obtain fresh consent.

12.3 The version of this Privacy Notice in force at the time of a given processing operation governs that operation.

Schedule 1: processors and international transfers

ProcessorPurpose of processingCategories of dataPlace of processingTransfer safeguard
Blacknight Internet Solutions Ltd, a company registered in Ireland under number 370845, of Unit 12A, Barrowside Business Park, Sleaty Road, Graiguecullen, Carlow, R93 X265Hosting of the Website, provision of domain services, and the operational logging incidental to themClause 3.4Ireland, in data centres operated by the provider and certified to ISO/IEC 27001Not applicable, no transfer outside the European Economic Area occurs
Resend, Inc.Transmission of electronic mail generated by the Website, and the associated sending recordsClauses 3.1, 3.2 and 3.4United States of AmericaStandard contractual clauses incorporated in the provider's data processing agreement under Article 46(2)(c), together with the supplementary measures identified in our transfer impact assessment
Google Ireland Limited, with onward processing by Google LLCProvision of Google Analytics 4 measurement servicesClause 3.3Ireland, with processing in the United StatesEU to US Data Privacy Framework adequacy decision, together with standard contractual clauses