PRIVACY POLICY.

PRIVACY POLICY.

Through this privacy policy, and in compliance with the provisions of Regulation (EU) 2016/679, of 27 April 2016, on data protection and Organic Law 3/2018, of 5 December, on data protection and guarantee of digital rights, Doole Health SL (hereinafter Doole) informs users of the conditions for processing personal data in relation to the use of the LINA platform and other associated services.

I.- DEFINITIONS

Application / Platform/ LINA: Digital health software system based on conversational artificial intelligence owned by DOOLE HEALTH S.L., aimed at the automated and structured collection of clinical information provided by patients through mobile application, automated phone calls, video calls, virtual assistants, messaging and other enabled digital channels.

Personal Data: Any information relating to an identified or identifiable natural person.   Any person shall be considered a natural person where his or her identity can be determined, directly or indirectly, in particular by an identifier, such as a name, identification number, location data, an online identifier or one or more elements of the physical, physiological, genetic, mental, economic, cultural or social identity of that person.

Data collection: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, preservation, adaptation or modification, retrieval, consultation, use, disclosure by transmission, dissemination or any other way to enable access, matching or interconnection, restriction,  suppression or destruction.

Usage Data: This is data collected automatically, whether generated by your use of the App or the App infrastructure itself (e.g., the duration of a site visit).

Cookies: These are small files stored on your device (computer or mobile device).

Data controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing; if the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for its appointment may be set by Union or Member State law.

Data processor: the natural or legal person, public authority, service or other body that processes personal data on behalf of the data controller.

Conversational Artificial Intelligence: technology integrated into LINA intended exclusively to facilitate automated conversational interactions, question formulation, language adaptation and response structuring, without medical diagnostic capacity or autonomous clinical decision-making.

II.- INFORMATION COMMON TO ALL FORMS OF PROCESSING

1.- Identification

Doole with CIF B67450478 and registered office at Ctra. del Canyet s/n, Hospital Germans Trias i Pujol, Edificio Materna 2ª planta, CP 08916 – Badalona (Barcelona) is registered in the Mercantile Registry of Barcelona in Volume 46958, Folio 152, General Section, Entry 1, Sheet 536446 Province B.

2.- Rights

To exercise your rights of access, rectification, deletion, opposition, restriction of processing, data portability, not to be subject to automated individual decisions and revocation, you can contact the postal address where the company is domiciled, or you can send an email to info@doolehealth.com with the text “data protection in this area”.

3.- Customer service, queries and complaints.

For any queries or complaints, please contact info@doolehealth.com

The competent body to resolve conflicts arising from the application of this policy is the Spanish Data Protection Authority, domiciled at Calle Jorge Juan n. 6 in Madrid.

III.- INFORMATION WHEN DOOLE ACTS AS DATA CONTROLLER

When you contact Doole directly to request information or hire their services, you must provide us with all the information we request through the contact forms. In this case, Doole will be considered a data controller.

1.- Purpose of the processing. Doole will use the data you provide us with and those generated during the contractual relationship in order to provide you with the services you request from us and, in some cases, to send you commercial information about our company.

LINA is a technological tool to support clinical monitoring and structured collection of health information.

The Platform:

  • Does not make medical diagnoses
  • It does not replace the health professional
  • Does not make clinical decisions
  • Does not issue autonomous medical recommendations

The artificial intelligence embedded in LINA is used exclusively to:

  • Formulate questions in a conversational way
  • Adapting the language to the user
  • Facilitate structured information collection
  • Classify responses within predefined structures
  • Manage automated interactions

The data obtained may be used for studies, statistical analysis or research only after anonymisation or dissociation of the personal data.

2.- Types of data collected. Identification data, contact data, economic data, health data, clinical information, care follow-up information, technical data, usage data, browsing data, voice recordings, automatic transcriptions, conversation history, authentication data, mobile device data, photographs, videos, files and documents provided by the user or generated during the use of the Platform.

The Platform may process information from:

  • Mobile App
  • Automated phone calls
  • Video Calls
  • Conversational Voice Systems
  • WhatsApp or other messaging systems
  • Push notifications
  • Authentication and security services

3.- Use of data by third parties: The Platform uses certain technological providers necessary for the provision of the service, including cloud infrastructure services, telephony, notifications, authentication, conversational processing and other ancillary technological services.

These providers act in accordance with the instructions of DOOLE and in accordance with the corresponding data processing contracts concluded in accordance with the General Data Protection Regulation.

LINA’s architecture is designed so that clinical information and patient data are centrally managed by the Platform and the responsible healthcare professional.

The LINA mobile application is not designed to store complete medical records or persistent patient databases on the user’s device, except for such technical or temporary data strictly necessary for the operation of the application, authentication, notifications and session continuity.

4.- Storage: The data will be kept for as long as the legal relationship with Doole is maintained and once it has ended, for the period established by law, which, in some cases, may reach 15 years.

5.- Automated individual decisions: They are not made. Automated individual decisions are not adopted within the meaning of Article 22 of Regulation (EU) 2016/679 (GDPR) where such decisions produce legal effects concerning the user or similarly significantly affect the data subject.

The artificial intelligence integrated in LINA is only used to manage automated interactions, adapt conversational language and structure the information provided by the user, without replacing in any case the assessment, decision or intervention of the healthcare professional.

6.- The recipients of this information are: the personnel that the company’s management has previously authorized, the contracted suppliers who support us and the public administration within the scope of its competences.

7.- External systems: They are used to store data. All external data storage services are located within the European Union.

8.- Legal basis of the processing: Compliance with contractual and legal obligations and management of information applying the rules established in the General Data Protection Regulation.

IV.- INFORMATION WHEN DOOLE ACTS AS A DATA PROCESSOR.

When the user uses LINA as a patient of a healthcare professional or entity that is a Doole customer, we will have the status of a data processor, with the healthcare professional or healthcare entity being responsible for the treatment. In these cases:

1.- Purpose of the processing.

 

DOOLE will use the data entered on the Platform, and those generated during its use to:

  1. Maintain and technically manage the LINA Platform.
  2. Facilitate access to and use of the mobile application and other enabled channels.
  3. Manage authentication and security processes.
  4. Manage notifications and communications. Including changes made.
  5. Manage automated calls, conversational interactions, and follow-up flows.
  6. Provide technical support and attention to incidents.
  7. Ensure the safety, availability, and proper functioning of the LINA Platform
  8. Carry out maintenance, monitoring and technical audit tasks.
  9. Detect, prevent and solve technical and security incidents.
  10. Conducting clinical studies. In this case, it will proceed to the dissociation and prior anonymization of the data
  11. Comply with the contractual and legal obligations arising from the relationship with the responsible health professional or health entity. In order to use LINA in the different channels, you must put it in contact with the details of your health or social-health provider. By accepting these clauses, you consent to this data processing

The Platform acts exclusively as a technological tool to support clinical monitoring and structured collection of health information.

LINA:

  • does not make medical diagnoses,
  • it does not replace the health professional,
  • does not clinically interpret information,
  • and does not make autonomous clinical decisions.

2.- Types of data collected:

  • Personal Data: When using LINA, we may ask you to provide us with certain personally identifiable information that will be used to identify you. Personal information may include: email address; first and last names; telephone number or DNI/NIE, health data.
  • Usage Data: When you access LINA using a mobile device, we may collect certain information automatically, including, but not limited to, your mobile device’s unique identifier, your mobile device’s IP address, your mobile operating system, the type of mobile internet browser you use, unique device identifiers, authentication tokens, and other diagnostic data (hereinafter,  “Usage Data”).
  • Data Tracking and Cookies: We use cookies and similar tracking technologies to track our app activity, and we retain certain information.

Cookies are files with a small amount of data that may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Other tracking technologies, such as beacons, tags, and scripts, are also used to collect and track information, and to improve and analyze our app. You can instruct your browser to refuse all cookies or to notify you when a cookie is being sent. However, if you do not accept Cookies, you may not be able to use some sections of our Application. Access our cookies policy

3.-Storage: The data will be kept for as long as you maintain the legal relationship with Doole and, once it has ended, for the limitation period established by law, which can reach up to 15 years.

4.- Automated individual decisions: They are not made.

5.- The recipients of this information are: your health or social-health service provider, the personnel that the company’s management has previously authorized, the contracted suppliers who support us with whom a confidentiality contract has been signed and the Public Administration when requesting data within the scope of its competences.

6.- External systems: They are used to store data. All external data storage services are located within the European Union.

7.- Legal basis of the processing: Compliance with legal and contractual obligations and information management applying the rules established in the General Data Protection Regulation.

8.- Relationship between Doole and its customers

In compliance with articles 28 of the GDPR and 33 and the provisions of the LOPDGDD, there is a signed data processor contract between Doole and its suppliers with all the requirements contained in these regulations.

9.- Security

Doole applies the security measures defined in Article 32 of the GDPR, is equipped with the mandatory security document and has established all the technical means at its disposal to prevent the loss, misuse, alteration, unauthorized access and theft of the data provided.

Doole holds the following cybersecurity certifications:

  • National Security Scheme (High Level)
  • ISO 27001
  • Cyber Essentials

The security of your data is important to us, but remember that there is no impregnable security measure for computers.

V.- ENTRY INTO FORCE AND VALIDITY OF THIS POLICY.

This policy will take effect upon publication on our website. We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. We will inform you by email and/or by a prominent notice on our App before the change takes effect and you update the effective date at the top of this Privacy Policy. We encourage you to periodically review this Privacy Policy to be aware of any changes. Changes to this Privacy Policy are effective when posted on this page.