Havio Care Privacy Policy (Integritetspolicy)
Last updated: 10 August 2026 · English master draft for review — a Swedish version is published alongside this one.
This policy explains how Havio Care handles your personal data when you are our patient. Havio Care is a digital specialist clinic for Long COVID — and because we are a licensed healthcare provider (vårdgivare), your data is protected not only by the GDPR but also by Swedish healthcare law: patientdatalagen (2008:355), patientsäkerhetslagen (2010:659), and the duty of confidentiality (tystnadsplikt) that binds all of our clinical staff.
1. Who is responsible for your data?
Havio Health AB, org. no. 559430-1250, Birger Jarlsgatan 57C, 113 65 Stockholm, Sweden [⚠️ verify this is the entity registered with IVO as vårdgivare] is the data controller (personuppgiftsansvarig) and the registered healthcare provider. We are registered in IVO's provider register (vårdgivarregistret) and operate under the supervision of the Health and Social Care Inspectorate (IVO).
Our Data Protection Officer (dataskyddsombud): [DPO — to be appointed and notified to IMY before launch], dataskyddsombud@haviohealth.com.
2. What data do we process?
- Identity and contact details — name, personal identity number (personnummer), contact details, verified through e-identification (BankID).
- Your patient record (patientjournal) — everything documented in your care: intake questionnaires, symptom history, consultation notes (video and text), assessments, care plans, prescriptions, referrals, and lab results.
- Health information you submit — questionnaires, tracked symptoms and data you choose to share with your care team.
- Payment and administrative data — bookings, invoices, payment status.
- Technical data — the minimum required to run the service securely (secure session data, access logs required by law).
3. Why do we process your data, and on what legal grounds?
| Purpose | Legal basis |
|---|---|
| Providing you medical care: assessment, diagnosis, treatment, prescriptions, referrals | GDPR Art. 9(2)(h) (provision of health care by professionals bound by confidentiality) with Art. 6(1)(c)/(e); patientdatalagen |
| Keeping your patient record (journalföring) | Legal obligation — patientdatalagen requires us to document your care. This is a statutory duty, not something we ask consent for |
| Quality assurance, quality development and statistics: following up the care we deliver, understanding trends and outcomes across our patients, planning and organizing the clinic, and improving medical quality, safety and availability | Art. 6(1)(e) with Art. 9(2)(h) GDPR and patientdatalagen 2 kap. 4 § — quality assurance, planning and statistics are express statutory purposes; patientsäkerhetslagen incl. SOSFS 2011:9 |
| Improving the platform itself (usage patterns, feedback) — performed on pseudonymized data, with direct identifiers removed before analysis | Legitimate interest (Art. 6(1)(f)) — you can object (opt out) at any time |
| Billing and accounting | Contract (Art. 6(1)(b)) and legal obligation (bokföringslagen) |
| Marketing our own services to you as an existing patient (e.g. clinic news) — never based on your health data | Legitimate interest (Art. 6(1)(f)) with the marknadsföringslagen "soft opt-in" for existing customers — every message carries an opt-out, and your objection always stops it |
| Newsletters and marketing to anyone who is not a patient | Your consent — always separate, always withdrawable |
| Establishing, exercising or defending legal claims | Legitimate interest (Art. 6(1)(f)) |
| Corporate transactions (merger, acquisition, restructuring): continuity of your care and records | Legitimate interest (Art. 6(1)(f)); your record remains protected by patientdatalagen with any successor healthcare provider |
Important: because healthcare documentation is a legal duty, we do not — and may not — base your medical record on consent. What IS always your choice: optional features, whether to receive marketing (one click stops it), research contact and quality registries (see §8), and whether other care providers may access your records (see §7). Note that processing required or permitted by patientdatalagen — care, record-keeping, quality assurance and statistics — may continue even if you object: there, the law rather than your consent governs.
4. Your patient record — your rights and their limits
- Retention: we are required to keep your patient record for at least 10 years after the last entry (patientdatalagen 3 kap. 17 §).
- Access: you have the right to read your record and receive a copy.
- Correction: you can have factual errors noted and corrected in the record.
- Deletion: the GDPR right to erasure does not apply to the patient record. Removal of journal content requires an application to IVO (patientdatalagen 8 kap. 4 §) — we will explain how if you wish to apply.
- Access logging (loggutdrag): every electronic access to your record is logged. You have the right to a list of who has accessed your record — ask us.
- Inner secrecy (inre sekretess): our staff may only open your record if they take part in your care or need it for their work. Access rights are role-based and log reviews are performed systematically.
5. Who can see your data?
All clinical staff are bound by statutory confidentiality (tystnadsplikt, patientsäkerhetslagen 6 kap.). Beyond your care team, data leaves the clinic only:
- To processors (personuppgiftsbiträden) under data-processing agreements — our electronic health record system The Patient Company AB, and supporting IT services [LIST — video platform, booking, payment, hosting]. Processors act only on our instructions.
- To laboratories — when we order tests: [LAB PARTNER(S)]. [⚠️ state processor vs independent-provider role per the lab contract.]
- To E-hälsomyndigheten (the Swedish eHealth Agency) — when we issue an e-prescription, we are legally required to transmit it to the National Medication List (Nationella läkemedelslistan, NLL). E-hälsomyndigheten is its own data controller for NLL. Your prescriber generally needs your consent to view your full medication list; you can see your list and manage consents and blocks in Läkemedelskollen (ehalsomyndigheten.se).
- To authorities when the law requires it — e.g. reporting duties under patientsäkerhetslagen or smittskyddslagen.
- Insurance — if you claim patient-injury compensation, relevant records go to our patient insurer (see the Terms).
Your patient record and identifiable health data are always stored within the EU/EES. For supporting IT services (e.g. hosting, support tooling, analytics), some suppliers may process limited technical or administrative data outside the EU/EES — currently the USA. Where that happens we rely on approved transfer mechanisms: EU adequacy decisions where available, and the EU standard contractual clauses with supplementary safeguards. [⚠️ List the actual third-country vendors and the data categories involved before publishing.]
We never sell your data, and we never use your health data for advertising.
6. AI in your care
Our clinicians may use AI-based tools to support their work — for example drafting documentation from consultations or organizing the information you have shared.
- A licensed clinician always makes, and is responsible for, every medical decision. AI never decides your diagnosis, treatment, or prescriptions.
- AI-assisted documentation is always reviewed by clinical staff before it enters your record.
- If you do not want AI-assisted transcription used in your consultation, tell your clinician — your care is not affected.
- Our AI tool vendors process data under data-processing agreements and are barred from using your data to improve their products or for any purpose of their own. [⚠️ List the specific AI tools/vendors and where they process data before publishing.]
AI in quality assurance. As part of the quality-assurance and statistics work described in §3, we may also use AI tools to analyze pseudonymized patient data — data with your name, personal identity number, and contact details removed — to find patterns across our patients and improve the care we deliver. This processing happens within the EU/EES, under the same data-processing agreements and no-secondary-use terms as above, and its results never change any individual patient's care without a licensed clinician's review and decision.
7. Sharing with other care providers (sammanhållen vård- och omsorgsdokumentation)
[⚠️ Include this section only if/when the clinic joins a shared-records system (e.g. NPÖ via the EHR). Required disclosures per lag (2022:913):]
We participate in shared healthcare documentation, which means other care providers involved in your care can request access to your records with your consent (in emergencies, access is possible if you cannot consent). You have the right to block (spärra) your records from other providers at any time — contact us [or self-service: describe]. Note that the fact that blocked records exist, and which provider holds them, remains visible to other providers.
8. Quality registries (kvalitetsregister) and medical research
[⚠️ Include if participating.] Before any data about you is added to a national quality registry, we will inform you. You have an unconditional right to opt out and to have your data erased from the registry at any time.
Research. Post-viral conditions are under-researched, and we want to change that — but your data is only ever used for research under Swedish research law: after approval by the Ethics Review Authority (Etikprövningsmyndigheten) and with separate information to you about the specific project (etikprövningslagen; GDPR Art. 9(2)(j)). This policy is not a research consent. At registration you can separately choose whether we may contact you about future research projects — declining (or saying nothing) never affects your care.
9. How we protect your data
Encrypted transmission (all traffic over open networks is encrypted), multi-factor authentication via e-identification for all patient access, role-based access control with logged and audited record access, pseudonymization where possible, and EU/EES data residency. Our quality management system (per SOSFS 2011:9) includes systematic risk analysis and incident handling.
10. Retention summary
| Data | How long |
|---|---|
| Patient record | ≥ 10 years after last entry (statutory) |
| Care statistics and quality-assurance compilations | 5 years from compilation (journal data itself: per the row above) |
| Booking/administrative data | [X — align with bookkeeping needs] |
| Invoicing/accounting records | 7 years (bokföringslagen) |
| Platform usage data and feedback (product improvement) | 3 years from collection, or until you object |
| Marketing (soft opt-in and consents) | Until you opt out, or [12] months after your last patient contact |
| Technical/access logs | [X — per HSLF-FS 2016:40 log-review routine] |
11. Your GDPR rights
Access, rectification, restriction, objection, and portability apply — subject to the patient-record limits in §4. Consent-based processing (marketing, optional features) can be withdrawn at any time without affecting your care. Contact the DPO (§1) for any request; we respond within one month.
Complaints about data handling: Integritetsskyddsmyndigheten (IMY) — imy.se. (Complaints about the care itself are described in the Terms, §10.)
12. Changes
Material changes are announced on this page and, where appropriate, to you directly. The date at the top shows the current version.