1. Company details
SmarteHealth GmbH, 3 Place Guillaume, L-9237 Diekirch is responsible for the processing of personal data as shown in this privacy statement.
2. Which personal data do we process?
PsyMate ™ App processes your personal data when you use our services and / or because you provide them to us by answering questions. In some circumstances, the PsyMate ™ App uses the functionality of your smartphone (for example, the camera or the GPS location). The user must always grant separate permission for this.
Below you will find an overview of the personal data that we process:
– Login data: the user can register with the Psymate ™ App in 3 ways:
• registration: via e-mail address and optionally the protocol (or module name): the e-mail address is not saved and is only used temporarily to send a one-time e-mail with login and password information. These can be used to view data;
• anonymous registration: a user can log in anonymously via a QR code provided by the PsyMate ™ help desk. The personal data is only available via a QR code on the reporting page that is used by the app as a sync key;
• login: via login and password provided by the PsyMate ™ help desk. With repeated incorrect logging in, a lock-out period of 60 minutes starts. Attempts are logged.
note: the PsyMate ™ App comes standard with a “start here” button that requires an “informed consent” prior to data collection; data collection starts after an affirmative answer;
note 2: the PsyMate ™ App has an “about” function with detailed information about the module and the person in charge with his affiliations.
– Device data: device data (device type, screen size and operating system), PsyMate ™ application version number, language and time zone are only processed upon registration and login and used to test the App on different platforms.
– Connection details:
• The IP address from which someone logs in is registered but not used. When logging in we create a session token (a UUID) that holds the data that the same person sends to the server together. The UUID is “anonymous” and contains no identification data, which means that we can no longer trace that data to individual IP addresses.
• communication with the PsyMate App is based on REST protocols via an SSL connection. No identification data is exchanged. The database is protected from the internet via a proxy and firewall.
– Log files of the PsyMate ™ App: are archived after 24 hours and after 14 days these archived log files are deleted;
– Personal answers to the ESM questions in the PsyMate ™ App are not encrypted and stored on the smartphone as long as there is no internet connection. When there is a connection (via WiFi or G3 / G4) the archived data on the smartphone is streamed to the server and the local database on the smartphone is deleted.
– personal answers take the form of numerical and structured data, time tags and open questions.
We do not process special or sensitive personal data.
Our PsyMate ™ App does not intend to collect data about persons under the age of 16. Unless they have permission from parents or guardian. However, we cannot check whether a young person under 16 downloads and uses the app. We therefore advise parents to be involved in their children’s online activities in order to prevent data about children being collected without parental consent. If you are convinced that we have collected personal data about a minor without that permission, please contact us at firstname.lastname@example.org and we will remove this information.
The PsyMate ™ App can register answers to open questions. It is possible that the user herein shares privacy-sensitive data about himself or others. In principle, open questions are not made visible outside the password-protected reporting module. The user is informed about this responsibility.
The PsyMate ™ App can be used for any form of data collection. This can also mean that privacy-sensitive information is collected. The data protection in the PsyMate ™ app and resources offer sufficient guarantees that this will be done in a manner that is in line with guidelines for handling sensitive data. The strategic choice lies with the responsible researcher who is also responsible for this.
3. For what purpose and on what basis do we process personal data?
The PsyMate ™ App was developed by the Psychiatry Department of Maastricht UMC + and Maastricht University as a means to get a grip on psychological complaints in everyday life. It is based on thorough research over the past 35 years. Specific modules on depression, bipolar disorder and psychosis have been extensively and scientifically tested. PsyMate ™ App processes your personal data for the following purposes:
– Offer you the option to create an account and log in to the PsyMate ™ App
– To collect structured personal measurement results
– To gain insight into your psychological symptoms in daily life by logging in to the reporting page
PsyMate ™ App does not use automated decision-making about personal aspects that can have (significant) consequences for these people. The PsyMate ™ App is therefore not registered as a medical device. Of course, the legal frameworks with regard to personal data, good research and, if used in clinical centers, legislation on the medical treatment agreement apply.
4. How long do we keep personal data?
PsyMate ™ App does not store your personal data for longer than is strictly necessary to achieve the purposes for which your data is collected.
We use the following retention periods for the following (categories) of personal data:
– Email address: will not be saved.
– IP address: we register the IP addresses that are used to log in. We then work with a session token (UUIDs), which means that we can no longer trace that data to individual IP addresses.
– Session data and measurement results are stored on the device until logged out and the measurement results are received and processed by the backend servers (4D);
– Log files are archived after 24 hours; these archived log files will be deleted after 14 days;
– The personal and structured measurement results are stored for a maximum of 5 years (see PsyRes Servers Privacy Statement).
5. Sharing personal data with third parties
PsyMate ™ App does not provide personal data to third parties. The collected personal data is also not used for commercial purposes.
6. Consult the collected PsyMate ™ App data
Measurement results and feedback can only be consulted on the reporting page by the user himself, by logging in with a separate log in with username and password via a web application via a REST protocol with SSL protection. This reporting module contains no identification data. The reporting module offers the client an individual overview of their own data.
Anyone can mandate a third party to view their data. This can be done by issuing a temporary mandate. Only the owner of the data can issue that mandate. This mandate is valid for 2 hours.
Only selected functional administrators can view session data including measurement results for debugging. A list is kept at the PsyMate ™ Help Desk. These people have signed a privacy statement and must adhere to a “code of conduct”.
PsyMate BV only uses technical and functional cookies. Analytical cookies are only used if they do not infringe on your privacy. A cookie is a small text file that is stored on your computer, tablet or smartphone when you first visit this website. The cookies we use are necessary for the technical operation of the PsyMate ™ App and the Reporting Module. They are there for your convenience. They ensure that the PsyMate ™ App and Report work properly and, for example, remember your preferences. We can also use it to optimize our reporting page. You can opt out of cookies by setting your internet browser so that it no longer stores cookies. In addition, you can also delete all information that was previously saved via the settings of your browser.
8. View, modify or delete personal data
You have the right to view, correct or delete your personal data. You can do this yourself via the personal settings of your account. In addition, you have the right to withdraw your consent for data processing or to object to the processing of your personal data by our company and you have the right to data transferability. This means that you can submit a request to us to send the personal data that we hold about you in a computer file to you or another organization mentioned by you. If you wish to make use of your right to object and / or the right to data transferability or if you have other questions / comments about data processing, please send a specified request to email@example.com. PsyMate ™ App will respond to your request as quickly as possible, but in any case within four weeks. PsyMate ™ App would also like to point out that you have the option to file a complaint with the national data protection authority, the Dutch Data Protection Authority. You can do this via this link.
PsyMate ™ App takes the protection of your data seriously and takes appropriate measures to prevent abuse, loss, unauthorized access, unwanted disclosure and unauthorized changes. If you have the impression that your data is not properly protected or there are indications of abuse, please contact us via: firstname.lastname@example.org