This is an English translation provided for convenience. If there is any discrepancy, the
Swedish version is the legally binding version.
Ebba Health AB (corporate ID 559485-2518) ("Ebba", "we") is the data controller for the processing of personal data described in this privacy policy. We process personal data in accordance with the EU General Data Protection Regulation (GDPR). When we provide healthcare, Swedish healthcare regulation also applies, including the Patient Data Act (patientdatalagen) and rules on medical record-keeping.
1. When does this policy apply?
This policy applies when you:
- use our digital services (web and app)
- contact us or communicate with us (e.g. email, SMS or WhatsApp)
- are in contact with licensed healthcare professionals through Ebba (care contact)
2. What personal data do we process?
We process personal data to the extent needed to provide the service, meet legal requirements and run our operations. Examples of categories:
- Identity and contact details: name, personal identity number (personnummer), phone number, email address.
- Identification and security data: data related to login and identification with BankID, and security-related logs.
- Payment details: data needed for payment and subscription management (card details are handled by our payment service provider).
- Communication data: messages and content you send to us in our channels (e.g. email, SMS, WhatsApp, in-app).
- Health and care data: data about health, lifestyle and treatment that you provide or that is documented by healthcare professionals during care contact.
- Technical data: IP address, device data, logs and data about how you use the service. Our website may use cookies and similar technologies (see our cookie policy).
3. Why do we process personal data, and on what legal basis?
Below is an overview of typical purposes and legal bases.
3.1 Providing the service and managing accounts
- Purpose: creating and managing accounts, providing features, customer support and necessary communication.
- Legal basis: contract (GDPR Art. 6(1)(b)).
3.2 Healthcare and medical record-keeping
- Purpose: carrying out care contacts, assessments and follow-up, documentation and medical record-keeping.
- Legal basis: legal obligation (GDPR Art. 6(1)(c)) and processing necessary for healthcare (GDPR Art. 9(2)(h)), in accordance with the Patient Data Act and other applicable legislation.
3.3 Payment and finance
- Purpose: managing payments, subscriptions, any fees, bookkeeping and financial administration.
- Legal basis: contract (GDPR Art. 6(1)(b)) and legal obligation (GDPR Art. 6(1)(c)).
3.4 Security, quality and development
- Purpose: operations, troubleshooting, preventing misuse, improving the user experience and ensuring information security.
- Legal basis: legitimate interest (GDPR Art. 6(1)(f)). Where the processing concerns health and care data, GDPR Art. 9(2)(h) may also apply where required for care and quality.
3.5 Analytics and session recording
- We use product analytics tools to understand how the service is used and to troubleshoot problems. This includes aggregate statistics on page views and events.
- Session recording ('session replay') of user interactions is not currently used. If we enable session recording in the future, it will only happen after your explicit consent in the cookie banner, with automatic masking of input fields and with flows that handle health and care data specifically excluded.
- Legal basis: consent (GDPR Art. 6(1)(a) and ch. 9 § 28 of the Swedish Electronic Communications Act) for non-essential analytics.
3.6 Marketing (where applicable)
- Purpose: sending news, offers and product updates, and measuring the effect of marketing. The legal basis for marketing communication to you as a consumer is consent (GDPR Art. 6(1)(a) and ch. 9 § 19 of the Swedish Electronic Communications Act). For existing customers, we may in limited cases send information about similar services based on legitimate interest (GDPR Art. 6(1)(f)), provided you have been offered a simple way to unsubscribe in every message.
- Unsubscribing: every marketing email contains an unsubscribe link. You can also contact privacy@ebba.health to unsubscribe.
- Important information: you cannot normally unsubscribe from necessary service and security messages, for example confirmations, reminders and information required to provide the service or meet legal requirements.
3.7 AI support within the Service
- The Service uses AI support that helps you with advice on food, exercise and motivation. The AI support provides continuous support and motivation, collects information from you, and can suggest tips and content. The AI support does not make medical decisions. All medical assessment, treatment and prescribing is carried out by licensed healthcare professionals.
- Personal data provided to the AI support is processed in accordance with this policy. AI providers we engage act as data processors under agreements that ensure GDPR compliance and, for health data, the requirements of the Patient Data Act. Some AI services may involve processing outside the EU/EEA with appropriate safeguards (see section 6).
- Legal basis: contract (GDPR Art. 6(1)(b)) for AI support included in the Service, and GDPR Art. 9(2)(h) where the AI support processes health and care data within the scope of care. You are informed that you are interacting with AI support when you use it.
4. Where is personal data stored?
- Patient records are kept in medical record systems used for care administration and record-keeping.
- Our application data and databases are hosted on AWS within the EU (Stockholm region).
- Some services for our marketing website/analytics may also involve processing outside the EU/EEA (see section 6).
5. Who do we share personal data with?
We share personal data only to the extent necessary to provide our services, meet legal requirements or protect our operations.
5.1 Categories of recipients
Personal data may be shared with the following categories of recipients:
- Healthcare professionals who need the data to provide safe and correct care.
- Providers of medical record systems and care administration used for record-keeping and care-related documentation.
- Providers of IT operations and infrastructure, for example for hosting, data storage and technical operations.
- Providers of communication services, such as email, SMS, video and other digital communication channels.
- Payment service providers for handling payments and subscriptions.
- Providers of analytics and development services used to improve functionality, security and the user experience.
- Authorities and other public bodies, where we are required to by law or an official decision.
5.2 Data processors
The providers we engage process personal data on our behalf and according to our instructions, as data processors. We enter into data processing agreements that ensure personal data is processed in accordance with GDPR and applicable healthcare legislation.
6. Transfers outside the EU/EEA
We aim to process personal data within the EU/EEA. Some technical services (for example for analytics, communication and operations) may involve transfers to, or access from, countries outside the EU/EEA. For such transfers we use appropriate safeguards, for example the European Commission's Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework where applicable, or another approved transfer mechanism. For health data, additional safeguards apply under the Patient Data Act.
7. How long do we keep personal data?
We keep personal data no longer than necessary for the purposes above, unless longer storage is required or permitted by law.
- Patient records: as a general rule at least 10 years after the last entry, under the Patient Data Act.
- Accounting records: in accordance with the Swedish Accounting Act (normally 7 years).
- Other data: for as long as needed to provide the service, handle claims, or until you withdraw consent (where consent is the basis).
8. Security
We use technical and organizational measures to protect personal data, including:
- authorization management and access controls
- logging and monitoring where relevant
- encryption and secure communication channels
- incident management procedures and continuous security work
9. Your rights
You have rights under GDPR, including the right to:
- request access (a copy of your data)
- request rectification
- request erasure (does not apply in all cases, e.g. normally not to patient records)
- request restriction of processing
- object to processing based on legitimate interest
- request data portability where processing is based on contract or consent
- object to, or request human review of, processing based on automated decision-making under GDPR Art. 22, if such processing is used to assess suitability for or access to the Service. However, no medical decisions are made automatically in the Service. All medical decisions are made by licensed healthcare professionals.
To protect your privacy, we may need to verify your identity.
Complaints
You can lodge a complaint with the Swedish Authority for Privacy Protection (IMY). For care-related matters, you can also contact the Health and Social Care Inspectorate (IVO) or the Patient Advisory Committee (Patientnämnden).
10. Changes to this policy
We may update this privacy policy. The latest version is always available on our website. If there are significant changes, we will inform you in an appropriate way.