Privacy policy - Sidekick Health

Approved: 02.02.2022

Published: 02.02.2022

Will be reviewed: 02.02.2024

General

Sidekick Health takes your privacy very seriously and is committed to protecting your personal information. In this privacy policy, we explain what information we collect from you as a user of the Concierge Care website and why we collect it. Here we explain who receives your personal information, our legal basis for processing that personal data, how long we retain it, what your rights are as a user of the application, and other important facts relating to data protection laws.

Personal data collected and how that data is used

1. Information you provide when you sign-up for Concierge Care

We receive certain information from you when you sign-up for a Concierge Care account. To create an account, you have three different options:

1.1. Sign-up process

When signing up for Concierge Care, you need to provide the following: Full name, Date of birth, your health plan Member ID, Mobile Number, Email, and Confirmation that you have the relevant health condition.

We store your information using the Google Cloud SQL service until you delete your Concierge Care account or are inactive for two years. This deletion involves only personally identifiable data, including username, password, all images, GPS data, and entered programs. Your health plan will store a copy of the data for record-keeping purposes.

1.2. Recipients and data retention regarding account registration

We use the Google Cloud SQL service to store account registration information. Google's role is limited to storing information on our behalf; Google does not use the information for any other reason.

We store your information using the Google Cloud SQL service until you delete your Concierge Care account or are inactive for two years. This deletion involves only personally identifiable data, which includes for example (username, password, all images, GPS data and entered programs). Your health plan will maintain a copy of the data for record-keeping purposes.

If you do not log any activity in the application for a period of two years, we remove all personal data and anonymize your account automatically. This removal of personal data includes all personally identifiable information, that includes for example (username, password, all images, GPS data and entered programs).

The registration and usage data are stored using the Google Cloud SQL, whose databases are located in the US. Images are stored on the Google Cloud Storage, whose databases are located in multiple regions of the US.

2. Outgoing emails and text messages (SMS)

2.1. Sign-up

If you have input the relevant information for sign up, you will receive an email or SMS with a link to download the Concierge Care application. Whether you get an email or an SMS text message depends on if you went through the onboarding process via smartphone or a computer. Those individuals that use smartphones will receive an SMS, and those that use computer web browsers to onboard will receive an email.

2.2. Sending links to enable onboarding

There are two ways to onboard Members to the Concierge Care application. Those are as described in 2.1. above and importing Members from our Members list.

2.3. Changes to Terms and Conditions

Our terms may change in the future. When we change them, we will send you information about those changes by email.

2.4. Changes to this privacy policy regarding how we handle personal data

The privacy policy may change in the future. We believe it is important that users of the Concierge Care website are aware of how the company handles their personal data. Therefore, we will send you an email if, or when, our privacy policy changes regarding how we handle personal data.

2.5. Recipients of information and the retention period for outgoing emails

We use MailChimp to email you and to store information about our email communication with you. MailChimp's role is limited to complying with our instructions on how the information should be used. MailChimp does not use the information for any other reason. MailChimp's databases are located in the U.S.

3. Legal basis for processing personal data

The personal information referred to in sections 1.1. to 1.3. mentioned above is processed based on your consent.

The personal information referred to in sections 2.1. and 2.2. is also processed based on your consent.

Emails described in sections 2.3. and 2.4. will also be sent to you based on our legitimate interest in demonstrating that the company has informed users about changes to our Terms and Conditions or our handling of users´ personal information.

4. Protection of Personal Data

Sidekick Health takes precautions, including administrative, technical and physical measures, to safeguard your personal data against loss, theft and misuse, as well as against unauthorised access, disclosure, alteration and destruction. We store the personal data you provide encrypted on computer servers that are located in controlled facilities. We restrict access to personal data to our employees, contractors and agents who need access in order to operate, develop, or improve our services and the application.

When you enter sensitive personal data in the application we encrypt the transmission of such data using secure socket layer technology. We follow generally accepted standards to protect the personal data submitted to us, both during transmission and once we receive it.

5. Your rights as a user of the Concierge Care Website

If you have granted your consent for processing certain personal data, you are entitled to withdraw your consent at any time according to data protection laws. However, that right does not affect the legitimacy of any data processing carried out before you withdrew your consent. You also enjoy other rights, such as the right to access your data, the right to have wrong or misleading information about you rectified, the right to have your personal data deleted, the right to restrict the processing of your personal data, the right to object, and your right to data portability. Please note that some of your rights may be subject to certain conditions.

Users are never under any obligation to provide personal data. The consequences of not providing personal data are that the user will not be able to enjoy the application fully and what it has to offer.

6. Cookies

Cookies are small text files that are placed on your computer by websites that you visit. They are widely used to make websites work, or work more efficiently, and provide information to the owners of the site.

6.1. Necessary cookies

Some cookies are required to provide core functionality. The website won't function properly without these cookies, and they are enabled by default.

6.2. Analytical cookies

Analytical cookies help us improve our website by collecting and reporting information on its usage.

6.3. Marketing cookies

Marketing cookies track visitors across websites to allow publishers to display relevant ads.

7. Name and contact details of Sidekick Health

Name: Sidekick Health

Org. no 556946-1766,

Address: Medicinaregatan 8A,

413 90 Gothenburg, Sweden.

Email: contact@sidekickhealth.com

8. Data Protection Officer

If you have further questions about how Sidekick Health handles your personal data, or if you want to exercise your rights, you may contact our data protection officer:

Email: privacy@sidekickhealth.com

9. Right to file a complaint with the Data Protection Authority

If you have any concern that Sidekick Health handles your personal data legitimately, you have the right to file a complaint with the regulatory authority.