Last updated: June 28, 2021
Interpretation and Definitions
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Account means a unique account created for You to access our Service or parts of our Service.
Application means the software program provided by the Organization downloaded by You on any electronic device, named OpenTeleRehab
Organization (referred to as either "the Organization", "We", "Us" or "Our" in this Agreement) refers to Fédération Handicap International, 138, avenue des Frères Lumière, 69371 Lyon, France. For the purpose of the GDPR, the Organization is the Data Controller.
Data Controller, for the purposes of the GDPR (General Data Protection Regulation), refers to the Organization as the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data.
Data Processors means any natural or legal person who processes the data on behalf of the Organization. It refers to companies or individuals facilitating or maintaining the Service, to provide the Service on behalf of the Organization, to perform services related to the Service or to assist the Organization in analyzing how the Service is used.
Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.
Personal Data is any information that relates to an identified or identifiable individual. For the purposes for GDPR, Personal Data means any information relating to You.
Service refers to the service provided by the Application.
Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
You means the individual accessing or using the Service. Under GDPR (General Data Protection Regulation), You can be referred to as the Data Subject or as the User as you are the individual using the Service.
Collecting and Using Your Personal Data
Types of Data Collected
Personally identifiable information
We may collect certain personally identifiable information that can be used to use our services, contact or identify You. Personally identifiable information may include
First name and last name
Date of birth
Mobile phone number
Text, image and video messages
Sensitive personal information
We may collect certain sensitive personal information concerning your health that can be used to use our services. Sensitive personal information may include
Usage Data is collected automatically when using the Service. Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data. When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data. We may also collect information that Your browser sends whenever You visit our Service or when You access the Service by or through a mobile device.
Use of Your Personal Data
The Organization may use Your Personal Data for the following purposes:
To provide and maintain our Service: Including but not limited to the access to activity planning provided by Your healthcare provider, monitoring the adherence and providing feedback to Your healthcare provider.
To manage and configure Your Account: To manage and configure Your account as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
To contact You: To contact You by audio or video calls, SMS, or other equivalent forms of electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
For other purposes: We may use Your Personal Data for generating anonymous statistical data for analysis and research, identifying usage trends and to evaluate and improve our Service, products, services and your experience.
We may share Your Personal Data in the following situations:
With Data Processors: We may share Your Personal Data with Data Processors to monitor and analyze the use of our Service, to provide support and maintenance, to contact You.
With Your Healthcare Providers: In order to make use of the Service, it is necessary that your healthcare Provider creates a personal Account for You. For this, it is required to enter certain information about yourself. See section “Types of Data Collected” for more information.
Retention of Your Personal Data
Transfer of Your Personal Data
Disclosure of Your Personal Data
Under certain circumstances, the Organization may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Other legal requirements
The Organization may disclose Your Personal Data in the good faith belief that such action is necessary to:
Comply with a legal obligation
Protect and defend the rights or property of the Organization
Prevent or investigate possible wrongdoing in connection with the Service
Protect the personal safety of Users of the Service or the public
Protect against legal liability
Security of Your Personal Data
The security of Your Personal Data is important to Us. The Organization will ensure that data processing is made with a level of security appropriate to the risk.
Detailed Information on the Processing of Your Personal Data
The Data Processors We use may have access to Your Personal Data. These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their Privacy Policies.
Usage, Performance and Miscellaneous
We may use third-party vendors to provide better improvement of our Service. We use Data Processors for:
Phone Verification API and SDKs
Legal Basis for Processing Personal Data under GDPR
We may process Personal Data under the following conditions:
Consent: You have given Your consent for processing Personal Data for one or more specific purposes.
The Organization undertakes to respect the confidentiality of Your Personal Data and to guarantee You can exercise Your rights.
Access to the Personal Data that We hold about You.
Obtain rectification the Personal Data that We hold about You.
Obtain the erasure of the Personal Data that We hold about You.
Receive the Personal Data that We hold about You.
Obtain restriction of the processing of the Personal Data that We hold about You.
Object to processing of the Personal Data that We hold about You.
Withdraw your consent for processing of Your Personal Data.
If the rights to object or to restrict the processing of the Personal Data that We hold about You or to erase the Personal Data that We hold about You are activated concerning information which are necessary for the provision of the service, the requesting person will no longer be able to use the service.
Exercising of Your GDPR Data Protection Rights
You may exercise Your rights of access, rectification, cancellation and opposition by contacting Us by email at firstname.lastname@example.org. Please note that we may ask You to verify Your identity before responding to such requests. If You make a request, We will respond to You as soon as possible. You have the right to complain to a Data Protection Authority about Our collection and use of Your Personal Data. This Policy and any dispute or claim arising out of or in connection with it or its subject matter shall be governed by and construed in accordance with the laws of France.
The competent court within the jurisdiction of the Paris Appeals Court shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this Policy or its subject matter or formation (including non-contractual disputes or claims).
Links to Other Websites
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Controller and data protection officer