Applicable from 2021-04-25
1.1 DefinitionsThese concepts, with capital letters, are used consistently in the policy and are defined as follows:
- User: a natural person using the Itchy service.
- Itchy AB: supplier of the Service.
- The service: the cloud service and the mobile application Itchy.
- Personal Data: any information relating to an identified or identifiable natural person, a User, in which an identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, a location task or an online identifier or one or several factors specific to the physical person's physical, physiological, genetic, mental, economic, cultural or social identity.
- Processing: a measure or combination of actions regarding personal data or sets of personal data, whether automated or not, such as collection, registration, organization, structuring, storage, processing or modification, generation, reading, use, transmission by transmission, dissemination or other means, adjustment or assembly, limitation, deletion or destruction,
1.2 Purpose and General
Itchy AB's ("We") personal data processing follows the data protection("GDPR"), and this policy explains how We collect, use, protect and share the personal data We process about our users. We take all appropriate technical and organizational security measures required to protect your personal information from improper access, change or destruction.
If you can’t find the answer to a question, please contact us at: email@example.com
- Data processing and integrity for the User
The service is an application on mobile phones that should serve as a tool for the User to manage their chronic skin condition..
If you as a User do not agree to this policy, you will not be able to access the service. Please contact Itchy AB to discuss alternative terms, via firstname.lastname@example.org.
1.3 Changes to the policy
Itchy AB continuously updates this policy to reflect:
- (1) Changes in legislation or practice, or
- (2) Improvements or additions to the Service
We from Itchy AB will notify you through the Service when the policy is updated. With this, we will request a renewed consent to continue processing your personal data in accordance with the updated policy.
2 Data processing and integrity
2.1 Personal data
Itchy AB processes the personal data that you, as a User, enter into the Service. The categories of personal data processed are:
- Contact information, such as e-mail address
- User data, such as treatments, prescribed medicines, PASI, DLQI, images, personal reflections and demographic data
- Customer support information, such as conversations with support for the Service
- Deliver the Service - For Itchy to support you in your chronic skin disease self-management, the Service uses your personal data, e.g. treatments, prescribed medicines, images, DLQI and PASI scores.
- Create market insights - In order to help as many people as possible, Itchy creates statistics and market insights based on your contact information. You will not be contacted for marketing purposes, but Itchy will be able to find others who are similar to you.
- Contact Users via email - You will occasionally get tips and support sent to your email, as a complement of the service. You can choose to unsubscribe at any time.
All of the above processing of data rely on the user's explicit consent.
For the above purposes, Itchy AB may hire personal data assistants to produce statistical data and market insights. If this involves a transfer to a third country or an international organization, Itchy AB will always ensure that there is a commission decision on the adequate level of protection or alternatively that the assistant through agreements or otherwise can guarantee appropriate protective measures.
You always have the right to:
- Access your personal data. You can request a copy of the information you would like to have and verify the information we have about you. A copy is free to request. In order to ensure that it is the right person who requests information, such a request must come from the email address that you have previously used to communicate with us.
- Get corrected from incorrect or incomplete personal information. Request for correction is sent to us via email address below.
- Have your data deleted in some cases, such as if your personal information is no longer necessary for the purposes for which they were collected.
- Restrict processing of your personal data in some cases - e.g. if you have objected to the processing of your personal data, which is done after balancing interest - in the meantime, control of whether our reasons weigh heavier than your interests, rights and freedoms.
- Get out and transfer personal data to another person responsible for personal data in some cases (data portability).
- You have the right to object to the processing of your personal data based on a balance of interests. Continued processing of your personal data requires, in such a case, that We may display mandatory justifications that outweigh your interests, rights and freedoms or whether it is for the purposes of the determination, exercise or defense of legal claims.
- You have the right to file a complaint regarding the processing to The Swedish Data Protection Authority or another data protection authority within the EU.
- At any time withdraw your consent to the processing of your personal information.
- If you request access to your information, you can send an email to email@example.com.
2.2 Collection of information
Itchy AB collects anonymised information in the Service via automated data collection tools. Itchy AB collects and uses such information in order to secure, maintain and improve the Service and to create reports based on statistics of anonymised user data. The information can also form the basis for market and customer analyzes, market surveys, business follow-up and business and method development, which takes place in the light of Itchy AB's interest in monitoring and analyzing the use of the Service.
2.3 How we use information we collect
Information we collect from our services is used to provide, maintain, protect and improve our services, to develop new services and to protect Itchy AB and our users.
We may use your username and public description to describe you to other users of our service, for example when you are actively contacting another user or when writing a review.
When you contact us, we save your messages in order to solve any problems you face. We may use your email address to inform you about our services, for example to inform you of upcoming changes or improvements.
The information we collect using cookies and other technology, e.g. pixel tags, are used to improve the user experience and the overall quality of our services. One of the products we use for that purpose in our own services is Google Analytics. By saving your language settings, we can, for example, display our services in the language you use. If / when we display customized ads, we will not link identifiers from cookies or similar technologies to sensitive categories of personal information, such as those based on ethnicity, religion, sexual orientation or health status.
2.4 Storage of user data
If the User chooses to stop using the Service, the User's data is stored for sixty (60) days, after which Itchy AB is entitled to delete the User's remaining material from Itchy AB's servers. At the request of the User, all data shall be deleted immediately after the termination of the agreement.
The user's data will not be deleted if, due to current legislation or other authority decisions, there would be obstacles to Itchy AB doing so.
2.5 Data security
For access to the Service, login with user name and activation code or password is required. It is the user's responsibility to ensure that login information to the Service is kept safe.
The login process is completely encrypted, which means that no information is sent in non-encrypted form.
3. Access and update information
We want you to be able to access your information regardless of when you use our services. If the information is incorrect, we want to give you the opportunity to easily update or delete it, provided that the information does not have to be saved for valid business purposes or for legal reasons.
We aim to keep our services in such a state that information is not destroyed by mistake or through harmful processes. When you delete information in our services, it may therefore take a while before copies of the deleted information disappear from our active servers. In addition, the information may remain in our backup systems.
4. Information we share
We do not share personal information with companies, organizations or individuals outside Itchy AB and necessary third party suppliers except in the following situations:
4.1 With your consent
We share personal information with companies, partners, organizations or persons outside Itchy AB if you have allowed us to do so. We must have your active consent to be able to share sensitive personal information with others.
4.2 For external treatment
4.3 For legal reasons
We share personal information with companies, organizations or persons outside Itchy AB if we have good reason to believe that access, use, preservation or disclosure of such information is reasonably necessary to:
comply with applicable laws, regulations, legal processes or mandatory requests from authorities
- detect, prevent or otherwise resolve fraud, security or technical issues
protect against damage to rights, property, security, users or the public as required or permitted by law.
We can share information that cannot be linked to a specific individual publicly and with our partners - e.g. publishers, advertisers or linked websites. For example, we can share information publicly to show trends in how our services are used in general.
5. Information security
We are constantly working to protect Itchy AB and our users from unauthorized access or unauthorized changes that may reveal or destroy information we hold.
- We use best practices for encrypting traffic between our services.
- We review our procedures for the collection, storage and processing of data, including physical security measures, in order to protect against unauthorized access to systems.
- We restrict access to personal data to our employees, suppliers and agents who need the data to be able to process it on our behalf. They are bound by strict confidentiality under contract and may be disciplined or terminated if they do not meet the requirements.