Publication date: 10/10/2024
Welcome to DeHealth – an app designed to monitor your health.
The Privacy Policy regulates the procedure for ensuring the security of Personal Data when using DeHealth Services.
In this document, we describe how we collect, process, store, disclose and transmit Personal Data when receiving DeHealth Company.
The provisions of this Privacy Policy apply only to Personal Data collected by the Company in the ways described in its terms and conditions.
References to the words “You” or “Your” (or words similar in content) means the User, depending on the context of the Privacy Policy.
References to “we”, “our” or “us” (or similar words) means the DeHealth Services.
1. Account is a functional part of the App, with the help of which the User can obtain Services and transfer his Data.
2. User is any person who installs the App to receive Services for the purpose of monitoring their health.
3. User consent (hereinafter referred to as “Consent”) is a voluntary, specific, informed and unambiguous expression of will in which the User, through a statement or clear positive action, agrees to the processing of his Personal Data and Data concerning health.
4. Personal Data is any information that is in the public domain, allowing you to directly or indirectly identify the User. For example, first name, last name, phone number, IP address.
5. Data concerning health means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status.
6. Data is a common name for Personal Data and Data concerning health
7. Doctor is a qualified specialist in the field of medicine, who is chosen by the User to receive Services for diagnosing his health or monitoring his condition.
8. DeHealth company (hereinafter referred to as the “Company” or “DeHealth”) is a DEHEALTH TECHNOLOGIES, INC, registered at 1049 El Monte Avenue, Ste C #846, Mountain View, CA 94040, United States, EIN: 36-5099713, which provides Services to Users.
9. DeHealth application (hereinafter referred to as the “App”) is a service created so that the User can check the state of his health and monitor the change in his health.
10. Services an algorithm of actions carried out by the Company to provide the User with the opportunity to install the App to check the state of his health and monitor its condition by contacting a Doctor.
11. Controller means a natural or legal person, government agency, institution or other body that independently determines the purposes and means of processing Personal Data.
12. Processor means a natural or legal person, public authority, agency or other body processing Personal Data on behalf of and on behalf of the Controller.
Cookie is a piece of information in the form of text or binary data used by the Company when you use the App to obtain additional information about you.
The Company may receive the following Personal Data about the User:
The Company may receive the User’s Personal Data during registration/authorization in the App, using the Google or Apple or Metamask service.
The Company uses additional conditions for processing Data concerning health:
Data concerning health specified in paragraph 3.3. necessary to provide the Services to the User and such data is processed exclusively by the Doctor.
The Company does not process Data concerning health for the purpose of identifying the User, but uses it solely for the purposes and in the ways specified in this Privacy Policy.
The Company does not process Data concerning health for illegal purposes and does not use Data concerning health for its own purposes. Data concerning health is processed solely on the basis of the active Consent of the User.
In the event of using Data concerning health in ways not provided for by this Privacy Policy and is not transferred to Third Parties without obtaining explicit Consent from the User and immediate notification of such User.
In the event of any changes in the terms of processing Data concerning health, the Company notifies the User of such changes within 24 hours from the moment of such changes.
The Company does not process Data concerning health for medical purposes, and the Company only collects and stores Data concerning health. Data concerning health is processed by a qualified employee – a Doctor.
The Company processes Data concerning health solely on the basis of explicit Consent, which the User provides in writing and actively.
The Company collects only the amount of Data concerning health that is required to provide the Services to the User.
The Company does not store Data concerning health longer than is necessary to provide the Services. After the Services are provided, Data concerning health will be deleted by the Company.
The User independently provides Data concerning health and is responsible for its accuracy. The Company does not change Data concerning health without a request on behalf of the User.
The Company stores Data concerning health using special security methods, using special access levels, in accordance with the Security Policy.
The Company does not perform profiling or automated decision-making regarding Data concerning health.
In the event of a high risk of disclosure/loss of the Data concerning health, the Company carries out a data protection impact assessment (DPIA).
The Company controls the level of access of its employees to Data concerning health.
The Company may receive information about the annual income per person in the family solely and/or User Profession for the selection of an appropriate specialist – Doctor.
The Company does not collect Data concerning health in ways not specified in this Privacy Policy.
The Company does not collect Data concerning health from open sources under any circumstances.
The Company informs that payment data (bank card number, date and CVV code, etc.) are processed exclusively by the payment service/bank that provides payment processing services to the Company.
The Company may collect Personal Data when communicating with the User and providing Services received through social networks, instant messengers, and email. In such a case, such data will be processed in accordance with this Privacy Policy.
The Company assigns a unique name and/or number to identify and track the User’s identity during the processing of his Data.
The Company may use your Personal Data for customized marketing and advertising based on the use of Personal Data obtained through your use of the App.
The Company protects the following Data in accordance with HIPAA:
In accordance with the rules and regulations of HIPAA during Data processing, the Company performs the following actions:
When using theApp or receiving Services, the Company may automatically collect the following Data:
The Company has the right to use Data concerning health for the following purposes to:
In the event of a breach of data processing security, resulting in the loss of Data concerning health, the Company shall notify the FTC by submitting the online form: Notice of Breach of Health Information.
The Company does not under any circumstances re-identify Data concerning health.The Company authenticates and identifies the User on the basis of the Company’s internal documentation. To ensure the authenticity of data changes, multi-factor authentication is used, and a detailed audit of changes is stored in logging systems (AWS CloudTrail).
The Company stores the hashes of each individual field of the User’s information in the blockchain, that is, any operation with the Data is performed exclusively by the User. For each Data field (for example, weight, height, blood type), a unique hash is created and written to a decentralized storage.
The Company processes Personal Data on the following legal grounds:
Bases for processing Data concerning health concerning health:
In cases where the basis for the processing of Data is your Consent, you have the right to withdraw it at any time. To revoke your Consent, you may send an email to: legal@dehealth.ngo. If your Consent is revoked, the Company has the right to stop providing the Services and terminate all relations with you. If Consent is revoked, your Data will be deleted permanently.
The Company undertakes to stop processing Personal Data within 15 (fifteen) business days from the date of receipt of the withdrawal of Consent.
One of the following actions by the User means Consent with the terms of this Privacy Policy:
By agreeing to the terms of this Privacy Policy, the User provides his Consent to:
transfer of his Personal Data to third-party services in accordance with the terms of this Privacy Policy.
The Company reserves the right to obtain User Consent through a pop-up form. The pop-up form may contain a Consent form in the form of a checkbox.
The Company uses all necessary security and Personal Data protection measures to ensure its confidentiality and prevent loss or unauthorized disclosure.
The Company stores Data concerning health using the following security methods:
DeHealth has the right to retain Personal Data for a period of 3 (three) years after termination of the relationship in the following cases:
The Company does not store Data concerning health in the event of termination of the Services under any circumstances, except for cases when the User unilaterally decides to store Data concerning health in User Account.
The Company assesses the adequacy of the security level of processing Data concerning health, taking into account the risks associated with processing, in particular the risks of accidental or unlawful destruction, loss, modification, unauthorized disclosure or access to transferred, stored or otherwise processed Data concerning health. More detailed information on the security conditions can be found in the Data concerning health Storing and Deleting Policy.
The Company applies a multi-level approach to data security, which includes data encryption both at the stage of storage and during processing/transmission.
The company uses the principles of Data minimization and pseudo-minimization during data processing. And also conducts an audit of Data processing.
The Company conducts safety and compliance audits with the relevant legislation every 6-12 months with the help of independent auditors. The audit includes checking employee and contractor access rights, activity logs, and checking the security of system connections and configurations. Identified issues are resolved in accordance with NIST guidelines.
The Company automatically backs up Data daily to Amazon S3 with multi-zone replication. Backups are stored encrypted using KMS, and regular recovery tests are performed to confirm that the copies are working.
The terms of this section apply to U.S. residents as contained in the Privacy Policy for specific requirements in accordance with:
The Company does not support Do Not Track mode. Do Not Track is a setting you can set in your web browser to inform websites that you do not want to be tracked. You can enable or disable Do Not Track by visiting your web browser’s settings page.
Rights granted to US residents:
The Company grants the following rights to Users regarding the processing of Data concerning health:
File a complaint with HIPAA.
When processing Personal Data, DeHealth provides the User with the following rights in accordance with the General Data Protection Regulation:
If the User exercises any of his rights provided for in paragraph 9.1. of this Privacy Policy, the Company notifies of any actions with the Data, in accordance with Art. 19 of the GDPR. The User informs the User of all Third Parties to whom the Data is transferred.
If you believe that the provisions of this Privacy Policy violate and/or in any way limit your Data processing rights, please contact us by email at legal@dehealth.ngo and we will do our best to resolve the problem within a reasonable time.
The Company is obliged to respond to the request or fulfill the conditions set forth in the request within 15 (fifteen) business days from the date of its receipt.
DeHealth is not responsible for:
Unfortunately, the transmission of information over the Internet cannot be completely secure. Although we make every effort to protect Personal Data, we cannot guarantee a secure transmission of Data to the App. In this regard, you are solely responsible for possible failures in the transfer of your Data to the Company.
Cookies do not transmit viruses and/or malware to your device because the data in Cookies does not change during transmission and does not affect the performance of the device. They are more like logs (i.e., they record User actions and remember status information) and are updated whenever You visit the App.
When providing the Services, we may use the following types of Cookies:
The Company uses Cookies for the following purposes:
The Company can use the following web analytics services:
In many cases, web browsers allow Cookies to be stored on the User’s end device by default. App Users can change Cookie settings at any time in such a way as to block the automatic processing of Cookies or to report each time they are placed on the App User’s device. Detailed information about the possibilities and methods of processing Cookies is available in your browser settings.
The User has the right to contact the Company support service at: office@dehealth.world to ensure his rights, in accordance with the terms of this Privacy Policy, or in case of violation of his rights, or to leave feedback or ask a question.
© 2024 DeHealth. All rights reserved