Juridisch

Privacybeleid

Versie 1.0

This policy applies to the Josie mobile application. It does not yet have an effective date: it takes effect on the date Josie is first made available to the public, which is recorded when this version is published.

Deze pagina is momenteel alleen in het Engels beschikbaar. De Engelse versie is juridisch bindend.

1. Who we are

Josie is provided by Health Surfers BV, a company incorporated in Belgium.

  • Data controller: Health Surfers BV
  • Enterprise number: BE 1039.918.687
  • Registered office: Blauwhuisstraat 31, 8531 Hulste (Harelbeke), Belgium
  • Privacy contact:privacy@josie.care

For the purposes of the EU General Data Protection Regulation (GDPR), Health Surfers BV is the controller of the personal data described in this policy. Where we refer to “we”, “us”, “our” or “Josie”, we mean Health Surfers BV.

2. What this policy covers

This policy explains what personal data the Josie mobile app collects, why we process it, the legal bases we rely on, who we share it with, how long we keep it, and the rights you have.

The josie.care website is a separate surface with a different processing profile. It is covered by our Website Privacy and Cookie Notice, not by this policy.

3. What Josie is

Josie is a self-tracking and education app for people managing PMOS (formerly known as PCOS). It lets you record your own health information, learn about PMOS through reviewed educational content, and prepare for and document conversations with your healthcare professionals.

Josie does not diagnose any condition, does not provide clinical decision support, and does not recommend, prescribe or modify any treatment. It does not interpret your individual measurements or results. Clinical decisions remain with your healthcare professional. This affects how we handle your data: we store and organise what you enter, and we do not draw clinical conclusions from it.

4. The personal data we process

Nearly everything you record in Josie is data you actively enter or choose to connect. We process the following categories of personal data:

4.1 Account and identity data

Your first and last name, email address, and password (which we store only in hashed form). We also hold basic profile and device attributes: your chosen plan tier, preferred language, platform (iOS or Android), app version and time zone.

4.2 Health data (special category data)

Most of what you record in Josie concerns your health and is treated as special category data under Article 9 GDPR. This includes:

  • Daily symptom check-ins and full symptom logs
  • Menstrual cycle data, including period dates, flow and cycle-related observations
  • Medications and supplements, dosage and adherence records
  • Test results and body measurements you enter, such as bloodwork and ultrasound findings, including any results you import from a standard health file
  • Your PMOS phenotype and diagnosis stage or status, where you provide them
  • PMOS Wellbeing Tracker responses
  • Appointment notes and the preparation and evidence reports generated from your data, and any Building My Case documentation
  • Food allergens and nutrition preferences you set
  • Wearable data, if you connect Apple Health (HealthKit) or Android Health Connect: we read sleep duration, daily steps and active minutes, resting heart rate and workouts, and store only daily aggregates. We do not store the raw samples from your device.

Journal entries you write in the app are stored only on your device and are not sent to our servers, unless you choose to enable server backup for them.

4.3 Subscription data

When you subscribe, the purchase is processed by the Apple App Store or Google Play, which act as merchant of record. We do not receive or store your card or bank details. Our subscription provider (RevenueCat) processes a store purchase token and a pseudonymous app-user identifier to manage your entitlement. No health data is shared with it.

4.4 Usage and analytics data

If you consent to analytics, we collect product usage events to understand how the app is used and to improve it. These events are keyed to your account identifier and carry business and device attributes only (plan tier, locale, platform, app version, time zone). They are usage data linked to your account. They are never sold and never used for advertising. Until you grant analytics consent, no analytics event leaves your device; if you refuse or later withdraw, queued events are discarded. Analytics is off unless you turn it on.

4.5 Diagnostic and security data

To keep the service reliable and secure, we process limited technical data: crash and error reports that carry your account identifier only, with a filter that removes health-related text before it is sent; and a hashed device fingerprint used to detect sign-ins from a new device or country so we can alert you.

4.6 Consent records

We keep a record of each consent decision you make: the category, the timestamp, and the version of the Terms and this policy you accepted. This is how we demonstrate that processing is lawful.

5. Why we process your data, and our legal bases

We rely on the following legal bases under the GDPR:

PurposeData usedLegal basis
Create and run your account, and provide the core appAccount and identity dataPerformance of a contract (Art. 6(1)(b))
Record, organise and display your health information so you can track and review itHealth data (special category)Your explicit consent (Art. 9(2)(a)), together with performance of a contract (Art. 6(1)(b))
Product analytics to understand and improve the appUsage and analytics dataYour consent (Art. 6(1)(a)); optional and off by default
Marketing emails and product newsEmail addressYour consent (Art. 6(1)(a)); optional and off by default
Contributing anonymised, aggregated data to a future clinical validation studyAggregated data derived from health dataYour consent (Art. 6(1)(a)); optional and off by default
Reading wearable aggregates from Apple Health or Health ConnectWearable daily aggregates (health data)Your explicit consent (Art. 9(2)(a)); optional and off by default
Send transactional and security emails (verification, password changes, deletion confirmations, policy updates)Account and identity dataPerformance of a contract (Art. 6(1)(b))
Manage subscriptions and entitlementsSubscription dataPerformance of a contract (Art. 6(1)(b))
Crash and error reporting to keep the service reliableDiagnostic data (id only, health-scrubbed)Our legitimate interests in a reliable service (Art. 6(1)(f))
Detect suspicious sign-ins and prevent fraud and abuseSecurity dataOur legitimate interests in securing accounts (Art. 6(1)(f))
Keep consent records and comply with legal retention dutiesConsent records; transaction recordsLegal obligation (Art. 6(1)(c))

6. Your consent, and how to withdraw it

Because Josie processes special category health data, we ask for your explicit consent to process it. During onboarding you are asked to agree to the Terms and this policy, and separately to the processing of your health data. These two consents are required to use the app. Analytics, marketing, research participation and wearable access are each optional, are off by default, and are asked for separately.

You can review and change your consents at any time in Profile > Privacy. You can withdraw consent at any time; withdrawal does not affect the lawfulness of processing carried out before you withdrew.

Withdrawing your consent to health data processing means we can no longer provide the core service, so it starts the account deletion flow described in section 12.

If we make a material change to this policy or the Terms, we will ask you to review and agree again before you continue to use the app.

7. Who we share your data with

We do not sell your personal data, and we do not use it for advertising. We share it only with the service providers (“processors”) that we rely on to run Josie, and only as far as each needs to perform its function. Each processor is bound by a data processing agreement that restricts it to acting on our instructions. Our current processors are:

ProviderWhat it does for usLocationSafeguard
SupabaseHosting, database, authentication, file storage and backend functionsEU (Ireland, eu-west-1)EU data residency; data processing agreement; Standard Contractual Clauses / EU-US Data Privacy Framework where applicable
PostHogProduct analytics (only if you consent)EU (Frankfurt)EU data residency; data processing agreement; SCCs / DPF where applicable
SentryCrash and error reportingEU regionEU region hosting; data processing agreement; SCCs / DPF where applicable
ResendSending transactional and, if you opt in, marketing emailUnited StatesData processing agreement; SCCs / DPF
RevenueCatManaging subscriptions and entitlements (no health data)United StatesData processing agreement; SCCs / DPF
Apple, GoogleApp distribution and in-app purchase as merchant of record; access to Apple Health / Health Connect where you enable itGlobalProcessed under their own privacy terms as independent controllers of the payment and platform relationship

Our content management provider (Sanity) and our translation provider process the app’s editorial and interface text, not your personal data. We may also disclose personal data where we are required to do so by law, or in connection with a merger, acquisition or reorganisation, in which case we will tell you and this policy will continue to protect your data.

8. Health data export and sharing features

Josie includes features that let you move or share your own health record. You are in control of these, and they are governed by an in-app disclosure that tells you exactly what a file contains before you confirm.

  • Data export. You can export your data as JSON and PDF, and your health record as a standard HL7 FHIR file. When you download a file, Josie generates it for you to save; we do not keep a copy on our servers.
  • Import. You can import a standard FHIR lab file into your record.
  • Sharing with a provider. You can generate a time-limited, encrypted Smart Health Link (for example a QR code) to share your summary with a clinician. The link is limited in how long it lasts and how many times it can be opened. The encryption key travels only inside the link you share and is never stored on our servers, so only someone you give the link to can open it. You choose what the link contains.

Once you share a file or link with someone, what they do with it is outside our control and outside this policy, so please share only with people you trust.

9. International data transfers

Your core data is held in the EU. Supabase hosts your data in Ireland, and our analytics and error-reporting providers are configured to EU regions. Some providers are established in the United States or may access data from outside the European Economic Area to provide support. Where that happens, the transfer is protected by an appropriate safeguard: the European Commission’s Standard Contractual Clauses, and the EU-US Data Privacy Framework where the provider is certified under it. You can ask us for a copy of the safeguards that apply by writing to privacy@josie.care.

10. How long we keep your data

DataRetention
Your health and account dataKept while your account is active
Data you delete inside the app (soft-deleted)Permanently purged 30 days after deletion
Your whole account, after you request deletionA 30-day grace period, then permanent erasure within 30 days
Consent recordsKept for 6 years after your account closes, to meet our record-keeping duties
Email logsPurged after 90 days
Data export filesDeleted 7 days after they are generated
BackupsDaily, kept on a rolling 30-day cycle
Subscription and transaction recordsKept for 7 years where Belgian accounting law requires
Analytics events (if consented)Kept in line with our analytics provider’s retention, and deleted when you delete your account
Crash and error reportsAge out under our provider’s 30 to 90 day retention

11. Your rights

Under the GDPR you have the following rights, which you can exercise in the app or by contacting us at privacy@josie.care:

  • Access: get a copy of your data. You can export all of it as JSON and PDF from Profile > Privacy > Export my data.
  • Portability: receive your data in a machine-readable format. We provide JSON and standard HL7 FHIR R4.
  • Rectification: correct your data. You can edit your data in the app at any time. Health entries become fixed 7 days after you add them, to keep an accurate record; within that window you can delete and re-add an entry to correct it.
  • Erasure: delete your account and data, as described in section 12.
  • Restriction and objection: ask us to restrict processing, or object to processing we carry out on the basis of our legitimate interests.
  • Withdraw consent: for any processing based on consent, at any time, in Profile > Privacy.
  • Complain: lodge a complaint with a supervisory authority (see section 17).

We aim to respond to any request within one month.

12. Deleting your account

You can delete your account at any time. When you do, we schedule permanent deletion after a 30-day grace period, during which you can cancel by following the link in the email we send you. When the grace period ends, we permanently erase your data and pass the deletion on to the providers that hold data about you, so that your data is removed from PostHog, RevenueCat, Resend and Sentry as well as from our own systems.

One limit is worth stating plainly: some of our error-reporting data sits in shared records alongside other users. Where an error record is shared, we delete the parts unique to you but cannot delete the shared record without affecting other people, so any remaining parts age out under our provider’s 30 to 90 day retention rather than being deleted immediately.

For step-by-step instructions, see how to delete your account and data.

13. Automated decision-making

Josie surfaces patterns in the data you enter using fixed, rule-based logic that runs on your device. This is not a decision that produces legal or similarly significant effects for you, and we do not carry out solely automated decision-making of that kind within the meaning of Article 22 GDPR. We do not send your health data to any external artificial intelligence system, and we do not use your health data to train any AI model.

14. Children

Josie is intended for adults and is only for people aged 18 or over. We ask your age at onboarding and do not permit registration by anyone under 18. If we become aware that someone under 18 has created an account, we will delete it.

15. How we protect your data

We use encryption in transit (TLS 1.3) and at rest (AES-256), certificate pinning, and database-level access controls (row-level security) so that you can only reach your own data. Authentication tokens are held in your device’s secure store, and on-device data is encrypted. We keep health data out of our server logs, apply rate limiting, and alert you to sign-ins from an unfamiliar device or location.

16. Data breaches

If a personal data breach occurs that is likely to present a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and we will inform you without undue delay where the breach is likely to result in a high risk to you.

17. How to contact us, and your right to complain

For any privacy question or to exercise your rights, contact us at privacy@josie.care.

You also have the right to lodge a complaint with a data protection supervisory authority. Our lead authority is the Belgian Data Protection Authority:

You may also complain to the authority in the EU country where you live or work.

18. Changes to this policy

We may update this policy from time to time. When we do, we will change the version below and, for material changes, ask you to review and agree again in the app before you continue.

Health Surfers BV · Enterprise number BE 1039.918.687 · privacy@josie.care · Version 1.0