Privacy Policy

Last updated: June 28, 2021
 

This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.

The English language version of this Privacy Policy shall be controlling in all respects and shall prevail in case of any inconsistencies with translated versions, if any.

We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.

Interpretation and Definitions

Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

Account means a unique account created for You to access our Service or parts of our Service.

Application means the software program provided by the Organization downloaded by You on any electronic device, named OpenTeleRehab

Organization (referred to as either "the Organization", "We", "Us" or "Our" in this Agreement) refers to Fédération Handicap International, 138, avenue des Frères Lumière, 69371 Lyon, France. For the purpose of the GDPR, the Organization is the Data Controller.

Data Controller, for the purposes of the GDPR (General Data Protection Regulation), refers to the Organization as the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data.

Data Processors means any natural or legal person who processes the data on behalf of the Organization. It refers to companies or individuals facilitating or maintaining the Service, to provide the Service on behalf of the Organization, to perform services related to the Service or to assist the Organization in analyzing how the Service is used.

Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.

Personal Data is any information that relates to an identified or identifiable individual. For the purposes for GDPR, Personal Data means any information relating to You.

Service refers to the service provided by the Application.

Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

You means the individual accessing or using the Service. Under GDPR (General Data Protection Regulation), You can be referred to as the Data Subject or as the User as you are the individual using the Service.

Collecting and Using Your Personal Data

Types of Data Collected
 

Personally identifiable information

We may collect certain personally identifiable information that can be used to use our services, contact or identify You. Personally identifiable information may include

  • First name and last name

  • Date of birth

  • Gender

  • Language

  • Location (country/region/state)

  • Mobile phone number

  • Text, image and video messages

  • Usage Data
     

Sensitive personal information

We may collect certain sensitive personal information concerning your health that can be used to use our services. Sensitive personal information may include

  • Diagnosis

  • Activity planning

  • Adherence details

  • Outcome measures
     

Usage Data

Usage Data is collected automatically when using the Service. Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data. When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data. We may also collect information that Your browser sends whenever You visit our Service or when You access the Service by or through a mobile device.

Use of Your Personal Data

The Organization may use Your Personal Data for the following purposes:

To provide and maintain our Service: Including but not limited to the access to activity planning provided by Your healthcare provider, monitoring the adherence and providing feedback to Your healthcare provider.

To manage and configure Your Account: To manage and configure Your account as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.

To contact You: To contact You by audio or video calls, SMS, or other equivalent forms of electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.

For other purposes: We may use Your Personal Data for generating anonymous statistical data for analysis and research, identifying usage trends and to evaluate and improve our Service, products, services and your experience.

We may share Your Personal Data in the following situations:

  • With Data Processors: We may share Your Personal Data with Data Processors to monitor and analyze the use of our Service, to provide support and maintenance, to contact You.

  • With Your Healthcare Providers: In order to make use of the Service, it is necessary that your healthcare Provider creates a personal Account for You. For this, it is required to enter certain information about yourself. See section “Types of Data Collected” for more information.
     

Retention of Your Personal Data

The Organization will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. The Organization will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, no longer than 8 years, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods.

Transfer of Your Personal Data

Your information, including Personal Data, is processed at the Organization's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from Your jurisdiction. The Organization will be strictly compliant with local regulations on Transfer of Personal Data. Your consent to this Privacy Policy represents Your agreement to that transfer.

The Organization will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other personal information.

Disclosure of Your Personal Data

Law enforcement

Under certain circumstances, the Organization may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

Other legal requirements

The Organization may disclose Your Personal Data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation

  • Protect and defend the rights or property of the Organization

  • Prevent or investigate possible wrongdoing in connection with the Service

  • Protect the personal safety of Users of the Service or the public

  • Protect against legal liability
     

Security of Your Personal Data

The security of Your Personal Data is important to Us. The Organization will ensure that data processing is made with a level of security appropriate to the risk.

Detailed Information on the Processing of Your Personal Data

The Data Processors We use may have access to Your Personal Data. These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their Privacy Policies.
 

Usage, Performance and Miscellaneous

We may use third-party vendors to provide better improvement of our Service. We use Data Processors for:

  • Phone Verification API and SDKs

  • Maintenance

  • Hosting

GDPR Privacy

Legal Basis for Processing Personal Data under GDPR

We may process Personal Data under the following conditions:

Consent: You have given Your consent for processing Personal Data for one or more specific purposes.
 

The Organization undertakes to respect the confidentiality of Your Personal Data and to guarantee You can exercise Your rights.

You have the right under this Privacy Policy, and by law if You are within the EU, to:

  • Access to the Personal Data that We hold about You.

  • Obtain rectification the Personal Data that We hold about You.

  • Obtain the erasure of the Personal Data that We hold about You.

  • Receive the Personal Data that We hold about You.

  • Obtain restriction of the processing of the Personal Data that We hold about You.

  • Object to processing of the Personal Data that We hold about You.

  • Withdraw your consent for processing of Your Personal Data.

If the rights to object or to restrict the processing of the Personal Data that We hold about You or to erase the Personal Data that We hold about You are activated concerning information which are necessary for the provision of the service, the requesting person will no longer be able to use the service.

Exercising of Your GDPR Data Protection Rights

You may exercise Your rights of access, rectification, cancellation and opposition by contacting Us by email at privacy@opentelerehab.com. Please note that we may ask You to verify Your identity before responding to such requests. If You make a request, We will respond to You as soon as possible. You have the right to complain to a Data Protection Authority about Our collection and use of Your Personal Data. This Policy and any dispute or claim arising out of or in connection with it or its subject matter shall be governed by and construed in accordance with the laws of France.

The competent court within the jurisdiction of the Paris Appeals Court shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this Policy or its subject matter or formation (including non-contractual disputes or claims).
 

Links to Other Websites

Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.

We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
 

Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page and by asking you to consent again with the latest version of Our Privacy Policy.
 

Controller and data protection officer

If you have any questions about this Privacy Policy, You can contact us by email: privacy@opentelerehab.com