In this document, the data collected from you (the User and the data Subject) is called “Personal Data”. We also collectively refer to collecting, handling, and storing Personal Data as “processing” such personal data.
1. Data controller
Oy Reagena Ltd (”Reagena”)
Business ID: 2495007-8
70900 Toivala, Finland
2. Name of the register
Oy Reagena Ltd’s register of users of its ReaScan Mobile application (“ReaScan App”)
3. Purpose and legal basis for processing personal data
ReaScan App provides a tool for its customers to collect and store test data in the cloud. The data contains basic identity information (including email address, app version, mobile phone model and operating system versions) of the users, but also the name, age, gender, sample identification, and test result from patients. The test result is health data and accordingly considered special category data.
The company will only store the data and has no direct interest in the individual data relating to specific users. The company may track usage statistics to understand and report product uptake, usage and assist with future planning, it will do so with anonymous aggregated data.
Personal data is processed for the following purposes:
- User data (name and email address) are required to guarantee a secure use of system.
- Device data (mobile phone model, OS version, App version) are required to guarantee correct technical support and for PMS purposes.
- Test results (Patient or Sample ID, test ID and batch number, test result, test image) are stored to guarantee the delivery of the offered service.
Personal data is processed for the performance of a contract between Reagena and the Customer and on the basis of Reagena’s legitimate interest created by the use of ReaScan App.
Reagena does not make any automated decisions or profiling.
4. Personal data collected
- first name and surname
- e-mail address
Personal data is obtained directly from the data subject as well as from other contact persons of the Customer.
5. Regular disclosure of data
Personal data may, if necessary, be disclosed to authorities upon their request.
6. Transfer of data outside the EU or EEA
Customer data may be transferred outside the EU or EEA when this is necessary to provide the service. If personal data is transferred outside the EU or EEA, we will take into account the requirements of the data protection legislation and the effects of the transfer of the data on the rights and freedoms of the data subject and will take the necessary precautions to carry out the transfer.
7. Data protection principles
Personal data is not disclosed to any other third parties. Only employees who need the personal data in the performance of their duties are entitled to use the system containing personal data. The collected personal data is stored in an encrypted database located on a password-protected cloud server.
8. Storage period of personal data
Reagena will store personal data for as long as is necessary to provide the ReaScan App for the use of the Customer.
9. Rights of the data subject
Data subject has the right to have access to their personal data and the right to data portability. In addition, the data subject has the right to request the correction of any inaccurate personal data. If the personal data is processed on the basis of data subject’s consent, the data subject has the right to withdraw his/her consent at any time, in which case we will remove the data subject’s consent. Data subject also has the right to request the deletion of his/her personal data from the register if the personal data is no longer needed for the purpose for which it was collected.
In addition, the data subject has the right to restrict the processing of personal data if the data subject considers that the processed personal data is inaccurate, the processing is unlawful or if the data subject has objected to the processing of personal data on grounds relating to his/her particular situation.
In order for the data subject to exercise the above-mentioned rights, the data subject shall contact Reagena in writing to: email@example.com.
The data subject also has the right to file a complaint with the Data Protection Ombudsman regarding Reagena’s processing of the personal data collected if he/she suspects that Reagena does not comply with the requirements and obligations of the Data Protection Regulation.