Learning to Sleep AB offers easily accessible and results-based CBT treatment for sleep problems and thus contributes to solving one of the greatest health challenges of our time. For our patients, the treatment should lead to a greater quality of life and thus increased mental and physical well-being. The treatment must be conducted with respect for the patient's self-determination and integrity. Thus, we strive to comply with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA).
This policy explains how we collect and process your personal information when you use Learning 2 Sleep L2S AB's service (the "Service"). This policy also governs the use of data collected through our app or through any of our websites, including the Learning to Sleep website. This policy describes what rights you have towards us and how you can assert your rights.
This policy may need to be changed or updated if features are changed or added to the service. In that case, you will be informed of this in order to have the opportunity to take a position on changes before they take effect. By continuing to use the Service thereafter, you accept the changes.
This policy covers:
- Who we are
- What personal information we collect
- How we use your personal information
- How we process your personal information
- Storage and data security
- Your Rights
Who we are
Learning 2 Sleep L2S AB is a registered caregiver and conducts health care by offering treatment for sleep problems (primary insomnia) with the help of cognitive behavioral therapy (CBT). The treatment is online-based, which means that the patient via an app-based treatment support can assimilate information and perform homework between sessions with a licensed psychologist. Contact with a licensed psychologist takes place online via voice or video calls. The treatment is available to individuals over 18 years of age. Learning 2 Sleep L2S AB only conducts psychological assessment and treatment of insomnia and within the business there is no prescription of drugs or treatment of other medical conditions. Learning 2 Sleep L2S AB is headquartered at Södergatan 19 in Malmö.
Personal information we collect
The following personal data is collected and processed by Learning 2 Sleep L2S AB when you use our service:
Personal information: When you create a user account in our service, you provide contact information such as name, social security number, mobile number and e-mail address.
As a patient, you can seek care from us via your own registration. This can be done via the contact form on our website where you fill in basic contact information such as name, e-mail address and telephone number. This information is temporarily stored to be able to contact you for booking an appointment. If you choose to book an appointment with us, we always need your social security number to be able to open a personal record in our patient administration system.
Alternatively, you can download the Learning to Sleep app to book an appointment immediately. To log in to the app and book an appointment, you identify yourself with a mobile BankID. Your social security number and first and last name are saved in a personal record in our patient administration system. You will also be asked to provide your mobile number and email address.
Health information: When you use the service, you are asked to share information about your physical and mental health. It can e.g. is about information related to your sleep problem, your medical history or your mental state. Health information is collected via questionnaires in the service or orally via conversations with your psychologist. This information is entered in the patient record. Health information entered in the medical record may also include a diagnosis and performed or planned care interventions. Psychologists add information to patient records one as part of its obligation to you as a patient. All information belonging to the patient record is covered by strong secrecy and the “Patient Data Act (2008: 355)” which regulates record keeping.
Payment Information: If you make payments through our service, your credit and debit card information is processed directly by a third-party processor that stores all payment information and transaction information. We will only retain information about transactions on secure servers and we will not retain your credit or debit card information.
Technical Information: When you use the service, device information is collected from your mobile device (or computer) e.g. IP address, language, type of browser and version of this, operating system and date and time of your visit.
NOTE! Audio and video are not recorded. When you use the service, device information is collected from your mobile device (or computer) e.g. IP address, language, type of browser and version thereof, operating system and date and time of your visit.
When you use our application or app, we may automatically collect the following information if permitted by your device settings:
(a) technical information, including the address used to connect your mobile phone or other device to the Internet, your login information, system and operating system type and version, browser or app version, time zone setting, operating system and platform and your location (based on IP address) ; and
(b) information about your visit, including products and services that you have viewed or used, app response times, and interaction information (such as keystrokes).
We work with partners who provide analytics and advertising services (only for our services and not for third-party advertising). This includes helping us understand how users interact with our services, providing our ads on the Internet and measuring the performance of our services and our ads. Cookies and similar technologies may be used to collect this information, such as your interactions with our services.
How we use your information
Your personal information is mainly used to provide, perform and improve the service. Learning 2 Sleep L2S AB processes your personal data for the following purposes based on the following legal grounds:
- To provide the service: Your personal and contact information will be processed in order to administer your account and to provide you with the service (ie in order to fulfill the agreement between us).
- To develop and improve the service: Technical data, general feedback and aggregate statistics may be used as a basis for developing and improving the service and the user experience. This is done with the support of legitimate interests, e.g. Learning 2 Sleep L2S AB's interest in developing and streamlining its way of offering and conducting care. This is not about making any decisions about you. Instead, it is about improving our service so that we can deliver a better experience for you and to achieve our goal of offering an effective and easily accessible sleep treatment.
- To communicate with you: Your personal and contact information (such as email and mobile phone numbers) may be used to send you notifications and notifications such as booking confirmations and reminders. This is done to provide the service and for other legitimate interests, including Learning 2 Sleep L2S AB's interest that booked appointments are not forgotten and to be able to send important information to you as tips on how to maintain a good night's sleep after treatment. You can turn off notifications in your settings or choose to stop subscribing to our emails.
- To give you treatment and keep a patient record, etc .: Your personal information is needed to carry out assessment and treatment of your sleep problem. Your personal data will also be used to keep patient records and prepare other documentation to meet other requirements under the Patient Data Act and other applicable laws. Some of the information can e.g. need to be reported to national health records.
- To provide customer service: Your personal information (except health information) may be used to respond toquestions, solve problems or receive comments and grievances related to the service (eg technical bugs). This is done in order to provide you with the service and for other legitimate interests, including Learning 2 Sleep L2S AB's interest in the service working to conduct meetings with you and others.
- To get aggregate statistics: Your personal data (including health data) may be used to create aggregate statistics in aggregate form, where the data is deidentified. Statistics can, for example, concern how often meetings are canceled or rebooked and how many are absent from a booked meeting. It can also be about the average age and geographical spread of users of the service. Health information is processed when necessary based on Learning 2 Sleep L2S AB's role as a care provider. Other personal data is processed on the basis of legitimate interests, including Learning 2 Sleep L2S AB's interest in developing and improving the service and its use.
Your information can be shared with others
Sometimes we may need to transfer or share your personal information with others, but only when this is necessary or justified. For example, your personal information may be shared with:
- People who work with us: Your personal information may be shared with people who work at Learning 2 Sleep L2S AB, but only if the person participates in the care of you or for other reasons need the information to perform their work in health care.
- Referrals: Your psychologist may, in consultation with you, decide that there is a need to send a referral to another care provider. In the referral, your personal and health information is shared so that the receiving care provider can take a position on the referral and any care needs.
- Authorities: Learning 2 Sleep L2S AB may need to disclose information to supervisory authorities such as the Swedish Health and Care Inspectorate (IVO) and other authorities, e.g. The National Board of Health and Welfare and the Police.
- Suppliers and subcontractors: Your personal information (but not health information) may be shared with selected companies that deliver different types of services to Learning 2 Sleep L2S AB. The service provider only has access to information that appears in Learning 2 Sleep L2S AB's service and is never given access to your health information or other information that is in your patient record. Service providers are covered by the same privacy rules that apply to Learning 2 Sleep L2S AB and may only process personal data in accordance with instructions from us.
Your data is processed within the EU / ESS
Learning to Sleep AB will only process your personal data in Sweden or within the EU / ESS. Your personal data will not be transferred to any other country outside the EU / ESS without your express consent. Data is always processed in accordance with data protection legislation.
As long as your data is saved
Generally, your information is stored only for as long as it is necessary to provide good and secure processing and to fulfill the purpose of the service.
Generally, your information is stored in the service for as long as you have your account. Obsolete accounts are deleted after 12 months. Technical data is normally deleted or deidentified 14 days after the meeting.
To fulfill legal obligations as a caregiver, your personal and health information will be stored for a longer period of time. According to the Patient Data Act, which regulates record keeping, your patient record must be kept for at least 10 years after the last note.
Data storage and security
We store all your personal and health information on secure servers. To log in to the service, identification with BankID is required.
We do not store credit or debit card information. Payments are processed through a third party payment provider that is fully compliant with Level 1 Payment Card Industry (PCI) data security standards. All payment transactions are encrypted with SSL technology.
You have the right to receive information about and control how your personal data behandlas by Learning 2 Sleep L2S AB. Below is a brief summary of your rights:
- Right to information: You have the right to receive more information about the privacy and security regulations that apply to your personal data and the processing of them.
- Right to Correction: You have the right to request correction of incorrect or incomplete information about yourself.
- Right to delete: You have the right to request that your data be deleted if it is no longer necessary to fulfill the purpose for which it was collected. The same applies if there is no legal basis for processing the data.
- Right of Restriction: You have the right to request that the processing of your personal data be restricted until invalid data has been corrected or until an objection from you has been investigated.
- Right to object: You have the right to object to the processing of your personal data for legitimate interests. In these cases, Learning 2 Sleep L2S AB must show that there are legitimate reasons for processing your personal data. Otherwise, Learning 2 Sleep L2S AB must stop processing your data.
- Data Portability: You have the right to have your personal information provided in a general, structured and machine-readable format.
- Right to oppose direct marketing: If you do not want us to process your personal data for direct marketing, you can report this to us. Each newsletter informs you about your possibility to unsubscribe from further newsletters.
Learning 2 Sleep L2S AB is responsible for the processing of your personal data as above. Learning to Sleep AB complies with Swedish data protection legislation, which includes the Data Protection Ordinance (GDPR).
If you have questions about your personal information, you can always contact us by sending an e-mail to firstname.lastname@example.org.
You have the right to submit a complaint to the Data Inspectorate if you believe that your personal data has been handled incorrectly by us.