Oyama is a mental well-being app provided at www.getoyama.com (the “Webpage”), (collectively the “Services”) which is provided by the software company Oyama Health AB, company registration number 559063-1965 having its registered address at c/o Maria 01, Lapinlahdenkatu 16, 00180 Helsinki, Finland (“we” or “us”).
Your privacy is important to us. Under the General Data Protection Regulation (2016/679), we are liable for the processing of personal data for which we decide the purposes and the means of processing. With “personal data” we mean information which is directly or indirectly referable to a natural living person, e.g. name and address but also possibly location data or IP addresses. We may collect the information set out below, which include your personal data.
This document contains a policy statement regarding our collection, use and processing of personal data, with whom we may share such data and your rights in relation to your personal. When you use the Services, we will process personal data as stated below.
PURPOSES OF PROCESSING AND LEGAL BASIS
The register is composed of the data contained in instances of Oyama. We process your data for the following purposes:
To provide Oyama Services in accordance with our Terms of Service Agreement.
User agreement agreed to by you and our legal obligations related to the agreement.
To communicate with you, including notifying you of any important changes to the Services and answering any messages you may send to us.
For statistics and analytics in order to improve and further develop our service.
Our legitimate interest in developing our services, as assessed in accordance with applicable data protection laws.
For direct marketing within our Services or via other communication channels, if explicitly consented by you.
Your voluntary, explicit consent. You have the right to refuse your personal data being used for direct marketing and you may at any time recall your prior consent.
HEALTH DATA SUBMITTED BY YOU
If you decide to submit us through the Services or through other channels any data related to your health, we will treat submission as your explicit consent for Oyama to process such health data.
WHAT PERSONAL DATA IS PROCESSED
Oyama processes the following information:
Name and contact information:
Name (Through newsletter sign-up on our https://getoyama.com)
Personal data generated and stored during use of Oyama:
Forms filled in by the user on https://getoyama.com and in the Oyama app,
Other information that is either communicated through Oyama or fetched by Oyama, which may include user surveys, user interviews and user feedback on separate request/sign-up
Technical logs (including IP-address) and audit logs are stored
Oyama administrators use logs for troubleshooting only when necessary
The sources of personal data
The personal data is collected from the following sources:
Information entered by the user
User-specific information (automatically generated user ID for each user) entered by the Oyama administrators
Information imported from other records by the data controller, such as usage analytics and device details when user provides feedback through the Oyama app.
AGGREGATED AND ANONYMIZED DATA
We may aggregate and anonymize data collected via the Services. Such anonymous data cannot be connected to you and it no longer qualifies as personal data. We may use anonymous data for statistics, analytics, statistics, research and development and other legitimate purposes related to our Services.
RETENTION AND ERASURE OF PERSONAL INFORMATION
We store your personal data for as long as the user account exists i.e., until a user deletes its account and with it, its data. You may, however, request deletion of your data at any time.
DISCLOSURE OF PERSONAL DATA
We may disclose your personal data outside our organization in the following instances:
The recipient is another company belonging to the same group of companies.
The recipient is our authorized service providers, such as IT service and data storage providers . Our service providers are obligated to safeguard your data.
Disclosing your data is necessary for legal reasons, such as preventing or investigating crime or security incidents or complying with a court order. If possible, we will inform you of such disclosure.
You give us your explicit consent for sharing your data with a third party.
Unless one of the above applies, we will not share your personal data with anyone else.
We do not transfer personal data outside the European Economic Area.
YOUR PRIVACY UNDER EU LAW
You have an absolute right to object to the processing of your personal data for direct marketing. You also have the right to recall your prior given consent. The withdrawal of your consent does not affect the lawfulness of the processing based on the consent before its withdrawal, and we may continue processing your personal data based on other legal grounds, except for direct marketing.
You have the right to request access and further information concerning the processing of your personal data, or request that we correct, rectify, complete, erase or restrict the processing of your personal data. You have the right to obtain a copy of the personal data that we process relating to you free of charge once (1) every calendar year. For any additional copies requested by you, we may charge a reasonable fee based on administrative costs.
If the processing is based on the legal grounds consent or fulfillment of contract you have the right to data portability. Data portability means that you can receive the personal data that you have provided to us, in a structured, commonly used and machine-readable format, and have the right to transfer such data to another data controllers.
To exercise the aforementioned rights, or if you have any questions about our sharing practices, your rights under EU law, or wish to have your personal information removed, please contact us at the following address: firstname.lastname@example.org or Oyama Health AB, c/o Maria 01, Lapinlahdenkatu 16, 00180 Helsinki, Finland. In order to ensure that you receive a swift response, please state your full name and, if applicable, your address, username and the email address used for registration. Note that you should sign the request to receive information of the processing of your personal data yourself.
If you have any complaints regarding our processing of your personal data, you may file a complaint to the competent data protection authority. You can find out more about the local data protection authorities under the following link http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm.