8. Storage of Data
Your personal data will be stored only for as long as necessary to fulfill the purposes for which it was collected. Once those purposes have been met, we will securely delete or anonymize your data, unless legal or regulatory obligations require us to retain it for a longer period. We retain your personal data as long as it is needed to provide you with the services for which it was collected, such as operating our Website. If you file a complaint or we anticipate potential litigation, we may retain your data for a longer period. Additionally, certain legal and regulatory requirements may compel us to hold on to your information for compliance purposes. You have the right to request the deletion of your data under certain circumstances.Please refer to the "Your Rights" section (11) for more details. In some cases, we may anonymize your data, making it no longer personally identifiable. This anonymized data may be used for research or statistical purposes indefinitely, without further notice to you.
9. Disclosures of your personal data
Within Tandem, only authorized personnel, based on their roles and responsibilities, may access personal data. This access is strictly limited to what is necessary for performing their duties. Your personal data may be shared with our data processors (such as technical service providers), but only when necessary for them to carry out their assigned tasks. These third-party companies are prohibited from sharing or using this information for any other purpose. Tandem has ensured that each contract with these companies includes measures to safeguard your data.In some cases, your personal data may be shared with authorized third parties, such as public authorities legally permitted to request such information. We may need to share personal data with the following third parties:
- Service providers acting as processors, such as: Microsoft Azure (EU), which provides data hosting services in connection with the website and/or platform.
- Other suppliers who may provide services such as IT and system administration.
- Professional advisors, acting as processors or joint controllers, including lawyers, bankers, auditors, and insurers, who offer consultancy, legal, banking, insurance, and accounting services.
- Regulatory authorities, local governments, or other public agencies, acting as processors or joint controllers, who may require data for reporting purposes.
We only permit service providers to process your personal information if they take appropriate steps to protect it. We impose contractual obligations to ensure that these providers use your data solely to provide services to us and you, with no other purposes. Additionally, we may share information with law enforcement and regulatory agencies to comply with legal and regulatory requirements
10. Data Security
We are committed to ensuring the confidentiality, integrity, availability and security of your personal data. In accordance with the GDPR, we endeavour to implement the appropriate technical and organisational measures to guarantee the level of security that is most appropriate to the risks incurred when processing personal data.
We also take steps to prevent, as far as possible, any loss, accidental destruction, alteration or unauthorised access to your personal data.Your personal data may be transferred to third countries located outside the European Union. In such cases, we systematically take all appropriate measures to verify and, if necessary, guarantee that the recipients of the data comply with an adequate level of protection equivalent to the European regulations, by signing standard contractual clauses adopted by the European Commission.
11. Your rights
In accordance with the GDPR, you have the following rights regarding your personal data:
Right to InformationYou have the right to receive information about how we process your personal data. We inform you through this policy and by answering your questions.
Right to AccessYou have the right to receive confirmation from us regarding whether we process your personal data. You also have the right to access the personal data and certain information about the processing itself (e.g., the purpose of the processing).
Right to RectificationYou have the right to have incorrect personal data corrected without undue delay. You also have the right to supplement incomplete data.
Right to Erasure (Right to be Forgotten)You have the right to have your personal data erased under certain circumstances.
The right to erasure does not apply if processing is necessary for
- Exercising the right to freedom of expression and information.
- Compliance with a legal obligation under Union or Member State law
- Establishment, exercise, or defense of legal claims.
The right may also be limited if the data is still necessary for the purpose or if there are compelling legitimate grounds for processing.
However, the right to erasure always exists in the case of direct marketing upon objection under Article 21.2 GDPR.
Right to Restriction of ProcessingYou have the right to require the restriction of processing if:You contest the accuracy of the data.The processing is unlawful.The data is no longer needed for the purposes but necessary for legal claims.While awaiting verification of overriding interests after you objected to processing under Article 21.1 GDPR.
Right to ObjectYou have the right to object to processing based on:
- Public interest
- Exercise of official authority
- Legitimate interests pursued by us.
Processing ceases unless there are compelling legitimate grounds overriding your interests or for establishing, exercising, or defending legal claims.
Processing for direct marketing purposes ceases immediately upon your objection.
Right to Data PortabilityYou have the right, in certain cases, to receive the data you provided and to have it transferred to another data controller.
This applies when:The processing is automated.Based on your consent or a contract.
Rights in Relation to Automated Decision-MakingYou have the right not to be subject to automated decision-making, including profiling, which produces legal or similarly significant effects.
Exceptions apply if:
- Necessary for the performance of a contract
- Permitted by Union or Member State law
- Based on your explicit consent.
Right to Lodge a Complaint
According to Article 77 GDPR, you have the right to lodge a complaint with a supervisory authority if you believe the processing violates GDPR.
More information and complaint forms can be found on the websites of national Data Protection Authorities
How to Contact Us or File a ComplaintShould you wish to exercise your rights over your personal data, please contact us:By e-mail:
dpo@tandemhealth.ai
By post: Tandem Health AB – Attn.: Data Protection Officer, Kungsklippan 12, 112 25 Stockholm, Sweden
By contacting the local regulatory authorities (e.g., CNIL, ICO, AEPD).
However, we would appreciate the opportunity to deal with your concerns before you approach any regulator — please contact us first.
Updates to the Website Personal Data PolicyTandem Health continually works to improve our services. Therefore, we may update this policy.
When changes are made, we will publish the updated version on our website and indicate the date of the latest update.
For updates of significant importance to the processing of your personal data, we will notify you by email or through a notice on our website, in accordance with applicable legislation.
Please visit this page regularly to stay informed about how we process your personal data.
Last updated: September 1st, 2024