Genia Patient Support System Privacy Policy (User Accounts in the United States of America)

Effective Date: 1 Nov 2021.

Integrity and privacy around the personal information that you and your personal network save in your Genia Account is the basic pillar of our service. In this Privacy Policy we explain how the Swedish company Upstream Dream (Swedish organization number 556948-3455) and its business associate in the US Motivo Management LLC, also referred to below as “we” or “Genia”, handle that information in accordance with your assignment to us.

The policy also describes what information we collect and why (for example account and customer support information), as well as what we are allowed to do with that information.

This Privacy Policy applies to all information that we have received or that has been created through your use of patient support system Genia.

How can this policy be changed?

We need to update this policy to keep pace with changes in the services, our business and laws applicable to us and you. Whatever those changes are, we will always maintain our commitment to respect and protect your privacy.

We post revisions to this policy, along with their effective date, on our website www.geniaapp.com, so you can stay informed of any changes.

We will ask for your consent to such changes if required by applicable law; in other cases, please note that your continuation of Genia use after any change means that you agree with, and consent to be bound by, the new privacy policy.

If you disagree with any changes in this policy and do not wish your information to be subject to the revised policy you can close your account at any time, and we can send your Genia data to you in excel-format (by registered mail).

A. INFORMATION TYPES AND HOW INFORMATION IS HANDLED

What information does Genia collect about me and why?

Your personal observations

Your personal observations that you and your personal network create about the account holder and save in the Genia account are saved in the key person’s personal Genia database. By ”account holder” we mean the person who is patient in relation to the care units that you can export reports to using Genia.

This information is stored on behalf of the account holder in the personal Genia account. We provide the account and only monitor the use of the Genia-service.

Please note! Personal observations, for example information about how the account holder and other people in the network are doing or what medicines they are taking, is fully private in nature and shall only be readable by you and the relatives that have access to the personal network.

Please note! Healthcare does not have access to the information. It belongs to the household, the private sphere, and can only be shared with healthcare through reports that are exported from Genia.

Comments in the Genia in app news feed is, if activated, an exemption. This information is available to other Genia users.

Information from the app Apple Health

Information from the app Health (Apple) can be collected from your Apple devices such as your iPhone and Apple Watch, and from other Bluetooth devices that are connected to third party apps. If you activate the function, a connection between Apple Health and Genia, data from Apple Health can be read by the account holder’s personal database in Genia.

Information read from the Health app is treated the same way as personal observations, see above.

Your username, email address and contact settings.

This information is saved in our customer database, a so-called customer relations management-system for the purpose of:

Your personal identification number.

Personal identification numbers (for example patient registry or research study identifiers) are stored by us and is needed when you export reports to healthcare (for example when a pre-visit report is sent in before a meeting).

Our customer relations management-system does not contain personal identification numbers.

Statistics about:

We work with statistics about our users in order to:

Please note! Statistics can only be created about the above data. Genia shall not create statistics about your personal observations in Genia (for example your lung function from Apple Health or how you are feeling according to a note in Genia).

What is Genia’s approach to information collected from children?

In Genia, personal information can be collected about children (for example when the account holder is a child, i.e. the person who is patient in relation to the care units that you can export reports to using Genia). Such collection is done by custodians or with parental consent. If we by mistake receive information in a way that is not permissible under existing laws and regulations, we will delete that information without delay as soon as we become aware.

B. ACCESS TO THE INFORMATION IN GENIA

Does Genia share my personal information or content?

Genia never sells personal user information (for example for commercial purposes). We only hand out personal information when instructed by you and under the following circumstances:

Does Genia have access to my notes and personal observations?

Privacy protection and integrity around your account is of paramount importance. Genia employees do not have the right to see your personal information or content that is stored in Genia. But it might be the case that we need to take actions in individual cases in order to answer your support requests.

Does Genia have the right to make my information available to anyone outside the users in the personal network?

No, Genia cannot hand out information without your explicit assignment. Information you share in Genia in-app Newsfeeds is an exemption, if activated, as it becomes available to other Genia users.

C. DATA STORAGE AND TRANSFER

Where is my data stored?

When you use the Genia app on your mobile device, content you save will be stored locally on that device and that content will be also be replicated on our servers, which are located in the United States for account holders that have signed up in the United States.

Please be aware that personal information and content submitted to Genia will be transferred to a data center in the United States. If you post information to Genia you are confirming your consent to such information, including personal information and content, being hosted, processed and accessed in the United States. You can at any time request activity logs around your account (when information is stored in the services).

The personal information and the content that is stored in Genia will be transferred to a datacenter in United States. If you save the information in Genia, you confirm that you agree that the information, including the personal information, is stored in the cloud service.

Data privacy laws or regulations in your home state and country may differ from those in Sweden where Upstream Dream is incorporated, often they are less strict, but Genia complies with the strict rules of GDPR (Directive 95/46/EC, General Data Protection Regulation) regarding collection, use and storage of the personal information you collect and create.

Please note that Upstream Dream AB (reg no. 556948-3455) is the data controller for all user information and administrative information associated with your Genia service. However, the personal observations created in the service are of a private nature in accordance with GDPR 2 art 2 item (c) and is therefore not part of our data controller responsibility as far as the information itself is concerned. However, Genia is responsible under GDPR for the technical aspects of your personal database.

How can I access or correct information that Genia holds about me?

If you wish to (i) access any personal information that we hold about you; or (ii) request that we correct or delete the personal information that we hold about you, you may contact andreas.hager@ genia.se. We will comply with such requests to the extent required by law and our policies, and subject to any limitations in our systems.

How secure is my data?

Genia is committed to protecting the security of your information and takes reasonable precautions to protect it. We use industry standard encryption to protect your data in transit. This is commonly referred to as transport layer security (“TLS”) or secure socket layer (“SSL”) technology. However, Internet data transmissions, cannot be guaranteed to be 100% secure, and as a result, we cannot ensure the security of information during its transmission between you and us; accordingly, you acknowledge that you do so at your own risk.

Once we receive your data, we protect it on our servers using a combination of administrative, physical and logical security safeguards. The security of the information stored locally in your mobile device is dependent upon you making use of the security features on your device. We recommend that you take the appropriate steps to secure all computing devices that you use with our applications.

If Genia learns of a security system breach, we may attempt to notify you and provide information on protective steps, if available, through the email address that you have provided to us or by posting a notice on our website.

D. INFORMATION DELETION

What happens if I want to stop using Genia?

You can delete content you have posted to Genia at any time, and you can stop using the Genia service at any time. If you delete information and material (for example pictures) from Genia and then sync your account, it will no longer be accessible to you or others who may access the service, but residual copies of your deleted content may continue to exist on the Genia’s back-up and archiving systems for up to one year due to the nature of those systems’ operations. Contact us for more detailed information on how different information is stored and saved.

If you deactivate your account, the content in your account will not be deleted unless you purposely delete that information and sync your account before you deactivate your account.

E. CONTACT US

How do I contact Genia?

Genia welcomes your feedback regarding this privacy policy. If you have questions, comments or concerns about this policy, please contact us by email at andreas.hager@ genia.se or by postal mail at:

Upstream Dream AB

Alviksvägen 43

167 53 Bromma, Sweden

Attention: Legal Department