This policy covers the website. It does not replace the separate privacy information you receive as a patient, client, or research participant once a care or client relationship begins.
1. Data controller
Sweden Precision Health Science Institute AB, org. no. 559579-5476, is the data controller for the processing described in this policy.
- Postal address: Stora Gatan 64, 193 30 Sigtuna, Sweden
- Email: info@sphsi.se
- Website: sphsi.se
2. When this policy applies
This policy applies when you visit our website, contact us, submit an expression of interest, sign up for information, or otherwise communicate with us through the website. Once a care or client relationship begins, different rules and separate privacy information apply, including for medical records, laboratory results, health data, and genetic data.
3. What personal data we process
- Contact details, such as name, phone number, and email address.
- Information you provide yourself in a message or an expression of interest.
- Booking, order, and payment details, where such features are used on the website.
- Technical data, such as IP address, device information, browser, timestamps, and security logs.
- Information about how the website is used, if you have consented to statistics or analytics cookies.
- Information about your consent, for example consent to a newsletter or to non-essential cookies.
Please do not enter health data, genetic data, your personal identity number, or other sensitive information into an ordinary contact field unless we have explicitly directed you to a secure form for that purpose.
4. Purpose, legal basis, and retention
| Purpose | Legal basis | Retention |
|---|---|---|
| Answering questions and handling expressions of interest | Necessary to take steps at your request prior to a contract, or our legitimate interest in responding to enquiries. | Normally no more than 12 months after the last contact, unless an ongoing relationship is established. |
| Administering bookings, orders, and payment | Performance of a contract, or steps prior to a contract. | For the duration of the contractual relationship, and afterward for as long as required for legal claims and administration. |
| Bookkeeping and payment records | Legal obligation. | Under applicable Swedish bookkeeping law, normally seven years. |
| Sending newsletters or information | Consent. | Until you withdraw consent. A limited suppression record may be kept to respect your unsubscribe. |
| Protecting the website and preventing misuse | Legitimate interest in information and system security. | Security logs are normally kept 6–12 months, unless a longer period is required to investigate an incident. |
| Web statistics and analytics | Consent to non-essential cookies. | Per the retention period of the relevant cookie or analytics tool. Not currently in use — see our cookie policy. |
5. Sensitive personal data and genetic data
Health data and genetic data are sensitive personal data. Such data is not collected through ordinary contact or marketing forms. Where it needs to be processed as part of our clinical operations, this happens through a dedicated, secure flow, with its own information about purpose, legal basis, access, retention, and recipients.
6. Recipients and processors
We use a small number of named service providers who process data on our behalf. Only the data needed for each provider's task is shared.
- Netlify, Inc. — website hosting, content delivery, and the contact/booking/onboarding form-submission tool (Netlify Forms). No web analytics or advertising script is installed.
- Fly.io — hosts the report-generation application used in the onboarding and My Health flows. The application instance runs in Stockholm, Sweden.
- BankID (Svensk e-legitimation) — electronic identity verification and signing, used when you complete onboarding or sign in to My Health.
- A payment service provider — only once online payment is enabled on the website. Not yet active at the time of writing.
- A public authority or other recipient, where disclosure is required by law.
7. Transfers outside the EU/EEA
We aim to keep processing within the EU/EEA. The report-generation application (Fly.io) runs in Stockholm, within the EU/EEA. Netlify, Inc., our website host, is a United States company; static hosting, content delivery, and form submissions may involve processing in the US, safeguarded by the European Commission's Standard Contractual Clauses. If a payment provider or other processor outside the EU/EEA is added, this section will be updated with the same safeguard before that feature goes live.
8. Your rights
- The right to information about, and access to, your personal data.
- The right to request correction of inaccurate or incomplete data.
- The right, in some cases, to request erasure or restriction of processing.
- The right to object to processing based on legitimate interest.
- The right to data portability where the conditions are met.
- The right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- The right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
Some rights may be limited where we are required to retain data under, for example, patient-data legislation, bookkeeping rules, or to establish, exercise, or defend legal claims.
9. Security
We use technical and organizational security measures suited to the sensitivity of the data and the risks the processing involves. Access to personal data is limited to people who need it for their work.
10. Cookies
Information about which cookies and similar technologies are used is in our separate cookie policy. Non-essential cookies are used only after your consent.
11. Changes and contact
We may update this policy as our operations, the website, or applicable rules change. The latest version is always published on the website.
Questions about personal data can be sent to info@sphsi.se. Feel free to write "Data protection" in the subject line.
Policyn gäller webbplatsen och ersätter inte separat integritetsinformation för patienter, klienter eller forskningsdeltagare, som gäller när en vård- eller klientrelation inleds.
1. Personuppgiftsansvarig
Sweden Precision Health Science Institute AB, org.nr 559579-5476, är personuppgiftsansvarig för den behandling av personuppgifter som beskrivs i denna policy.
- Postadress: Stora Gatan 64, 193 30 Sigtuna
- E-post: info@sphsi.se
- Webbplats: sphsi.se
2. När gäller policyn?
Policyn gäller när du besöker vår webbplats, kontaktar oss, skickar en intresseanmälan, anmäler dig till information eller på annat sätt kommunicerar med oss via webbplatsen. När en vård- eller klientrelation inleds kan andra regler och en separat integritetsinformation gälla, bland annat för journaluppgifter, laboratorieresultat, hälsodata och genetiska uppgifter.
3. Vilka personuppgifter behandlar vi?
- Kontaktuppgifter, exempelvis namn, telefonnummer och e-postadress.
- Uppgifter som du själv lämnar i ett meddelande eller en intresseanmälan.
- Boknings-, beställnings- och betalningsuppgifter, om sådana funktioner används på webbplatsen.
- Tekniska uppgifter, exempelvis IP-adress, enhetsinformation, webbläsare, tidsstämplar och säkerhetsloggar.
- Uppgifter om hur webbplatsen används, om du har samtyckt till statistik- eller analyscookies.
- Uppgifter om ditt samtycke, exempelvis samtycke till nyhetsbrev eller icke nödvändiga cookies.
Lämna inte hälsouppgifter, genetiska uppgifter, personnummer eller annan känslig information i ett vanligt kontaktfält om vi inte uttryckligen har anvisat ett säkert formulär för detta ändamål.
4. Ändamål, rättslig grund och lagring
| Ändamål | Rättslig grund | Lagringstid |
|---|---|---|
| Besvara frågor och hantera intresseanmälningar | Nödvändigt för att vidta åtgärder på din begäran innan avtal, eller vårt berättigade intresse av att besvara förfrågningar. | Normalt högst 12 månader efter senaste kontakten, om inte en fortsatt relation etableras. |
| Administrera bokning, beställning och betalning | Fullgörande av avtal eller åtgärder innan avtal. | Under avtalsförhållandet och därefter så länge det krävs för rättsliga anspråk och administration. |
| Bokföring och betalningsunderlag | Rättslig förpliktelse. | Enligt tillämplig bokföringslagstiftning, normalt sju år. |
| Skicka nyhetsbrev eller information | Samtycke. | Till dess att du återkallar samtycket. En begränsad spärruppgift kan sparas för att respektera avregistreringen. |
| Skydda webbplatsen och förebygga missbruk | Berättigat intresse av informations- och systemsäkerhet. | Säkerhetsloggar sparas normalt 6–12 månader, om inte längre lagring krävs för att utreda en incident. |
| Webbstatistik och analys | Samtycke till icke nödvändiga cookies. | Enligt lagringstiden för respektive cookie och analysverktyg. Används inte för närvarande — se vår cookiepolicy. |
5. Känsliga personuppgifter och genetiska uppgifter
Uppgifter om hälsa och genetiska uppgifter är känsliga personuppgifter. Sådana uppgifter samlas inte in genom vanliga kontakt- eller marknadsföringsformulär. När de behöver behandlas inom vår kliniska verksamhet sker det i ett särskilt och säkert flöde, med egen information om ändamål, rättslig grund, åtkomst, lagring och mottagare.
6. Mottagare och personuppgiftsbiträden
Vi anlitar ett fåtal namngivna leverantörer som behandlar personuppgifter för vår räkning. Endast uppgifter som behövs för respektive uppdrag lämnas ut.
- Netlify, Inc. — webbhotell, drift och verktyget för formulärinskick (kontakt, bokning, anmälan). Inget webbanalys- eller annonseringsskript är installerat.
- Fly.io — driftar rapportmotorn som används vid anmälan och i Min hälsa. Applikationen körs i Stockholm.
- BankID (Svensk e-legitimation) — elektronisk identitetskontroll och signering, när du fullföljer anmälan eller loggar in i Min hälsa.
- Betaltjänstleverantör — först när betalning online aktiveras på webbplatsen. Inte aktiverat vid publiceringstillfället.
- Myndighet eller annan mottagare när utlämnande krävs enligt lag.
7. Överföring utanför EU/EES
Vi eftersträvar att behandlingen sker inom EU/EES. Rapportmotorn (Fly.io) körs i Stockholm, inom EU/EES. Vårt webbhotell Netlify, Inc. är ett amerikanskt bolag; drift, leverans av statiskt innehåll och formulärinskick kan innebära behandling i USA, vilket skyddas av EU-kommissionens standardavtalsklausuler. Om en betaltjänstleverantör eller annan leverantör utanför EU/EES läggs till uppdateras detta avsnitt med motsvarande skyddsåtgärd innan funktionen aktiveras.
8. Dina rättigheter
- Rätt att få information och tillgång till dina personuppgifter.
- Rätt att begära rättelse av felaktiga eller ofullständiga uppgifter.
- Rätt att i vissa fall begära radering eller begränsning av behandlingen.
- Rätt att invända mot behandling som grundas på berättigat intresse.
- Rätt till dataportabilitet när förutsättningarna är uppfyllda.
- Rätt att när som helst återkalla ett samtycke. Återkallelsen påverkar inte lagligheten av behandling som redan har skett.
- Rätt att lämna klagomål till Integritetsskyddsmyndigheten (IMY).
Vissa rättigheter kan vara begränsade när vi måste behålla uppgifter enligt exempelvis patientdatalagstiftning, bokföringsregler eller för att fastställa, göra gällande eller försvara rättsliga anspråk.
9. Säkerhet
Vi använder tekniska och organisatoriska säkerhetsåtgärder som är anpassade till uppgifternas känslighet och de risker som behandlingen innebär. Åtkomst till personuppgifter begränsas till personer som behöver uppgifterna för sitt arbete.
10. Cookies
Information om vilka cookies och liknande tekniker som används finns i vår separata cookiepolicy. Icke nödvändiga cookies används först efter ditt samtycke.
11. Ändringar och kontakt
Vi kan uppdatera denna policy när verksamheten, webbplatsen eller tillämpliga regler förändras. Den senaste versionen finns alltid publicerad på webbplatsen.
Frågor om personuppgifter skickas till info@sphsi.se. Ange gärna ”Dataskydd” i ämnesraden.