The security of your personal data with respect to the use of the SIVA-MVP Mobile Application is very important to us. We take the protection of your data very seriously. Personal data is all information that can lead to your identification (hereinafter “Personal Data”).
1. Information about SIVA-MVP Mobile Application
The SIVA-MVP Mobile Application is a mobile application that manages the SIVA-MVP wearable, which is a device worn by individuals to learn about their cough for wellness purposes. Please note that neither the SIVA-MVP Mobile Application nor the SIVA-MVP wearable are medical devices, and do not provide medical advice, nor should they be considered a substitute for any form of professional health services.
“Personal Data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
The Controller of your Personal Data is: SIVA Health AG.
If you have any problems, questions or suggestions, please contact SIVA Health AG.
SIVA Health AG
3. Collection of Data
The SIVA-MVP Mobile Application configures your SIVA-MVP wearable to record audio and acceleration data in order to detect cough events, as well as the number of steps walked. This data is securely encrypted and can only be unlocked by a private key stored in your personal SIVA-MVP Mobile Application. The recorded data will be transmitted by the SIVA-MVP wearable for further processing to the Controllers’ cloud infrastructure. Additionally, the SIVA-MVP Mobile Application collects your responses to questions that may be of interest in relation to your cough events (e.g., when you consumed food). Every time you open the SIVA-MVP Mobile Application, it captures your approximate geographical location (on purpose with reduced accuracy of 11.1 km / 6.9 miles). This information is then used to obtain weather, air quality, and pollen data as additional, potentially relevant information with respect to your cough events.
To identify you as a user of the SIVA-MVP Mobile Application, we ask you for your access code and a password. This access code and password can be conveniently entered by scanning a QR code provided to you. We associate all data with your access code. Only you, or – in case of using the the SIVA-MVP Mobile Application in a study setting – the principal investigator of the study will be able to associate any of the recorded data to any other Personal Data.
4. Processing of Data
The SIVA-MVP Mobile Application will enable the temporary decryption of the data recorded by the SIVA-MVP wearable in a secure environment within the Controller’s cloud infrastructure. An automatic algorithm will then analyze the data for the occurrence of cough events. The time of the cough events will be stored in a secure database, together with the number of steps walked and the weather, air quality, and pollen data obtained based on the user’s approximate geographical location.
Short segments of maximally 1 second duration around the identified cough events will be additionally scanned by an additional automatic algorithm for the presence of speech. Those segments that contain no speech will be anonymized and stored in a separate secure storage for the purpose of quality control. In the quality control process, these anonymous data segments that do not contain speech may be reviewed by human listeners to check the correct performance of the cough detection algorithm.
Any decrypted original data recorded by the SIVA-MVP wearable will be immediately deleted after processing to guarantee that neither the Controller’s personnel nor third parties are able to access the original data.
In specific study settings, additional processing may occur based on additional informed consent given by you as participant of such a study.
The list of cough events and associated metadata as laid out above is made available to you in form of graphical charts via a secure web interface using your access code and password.
In specific study settings, the list of cough events and associated metadata may additionally or exclusively be made available to the principal investigators of the study based on additional informed consent given by you as participant of such a study.
The processing of the data is carried out by the Controller in data processing centres in the European Union.
If necessary, the Controller may commission external service providers to process your data (such as call centers, technical service providers, hosting providers or IT companies). Depending on the type of service, your data may be accessible to these service providers for the purpose of providing the service. The Controller obligates all service providers to protect your data by exercising care in selecting the service provider and by obliging the service provider to ensure compliance with data protection. The updated list of these parties can be requested from the Controller at any time.
5. Purposes of Use
The collected data will be used to provide you with insights into when and how much you cough. These insights are considered wellness information. Please note that neither the SIVA-MVP Mobile Application nor the SIVA-MVP wearable are medical devices, and do not provide medical advice, nor should they be considered a substitute for any form of professional health services. The accuracy of the data collected through the SIVA-MVP Mobile Application and the SIVA-MVP wearable has not been validated to match that of dedicated medical devices or scientific instruments.
In specific study settings (which will require you providing additional informed consent), the data collected will be used according to the respective study protocol.
The service provider SIVA Health AG uses technical and organizational security measures to protect data against manipulation, loss, destruction or access by unauthorized persons (use of a certified infrastructure). These security procedures are continuously adapted to new technological developments.
7. Right of Access to, Rectification, Erasure or Restriction of Processing, Right to Object to Processing, Right to Data Portability
You have the right to request from the Controller (1) access to and (2) rectification or (3) erasure of your Personal Data or (4) limitation of the processing of your Personal Data, as well as (5) to object to the processing of your Personal Data. Furthermore, you have (6) a right to data portability. Simply send an e-mail to the Controller of your Personal Data: firstname.lastname@example.org or contact the Controller at the address mentioned in section 2 above.
8. Right to Withdraw Consent at Any Time
You have the right at any time to withdraw your consent to the processing of your Personal Data for the future. For clarifications sake such withdrawal will, however, not affect the lawfulness of processing based on consent before its withdrawal. Again, just send an e-mail to the Controller of your Personal Data: email@example.com or contact the Controller at the address mentioned in section 2 above.
9. Data Retention
We will only retain Personal Data for as long as is necessary for us to render the service you have requested or to which you have given your consent, or to fulfill the purposes as set out in this document except where otherwise provided by law (e.g. in connection with a pending litigation). In specific study settings (which will require you providing additional informed consent), data is retained according to the respective study protocol. You have the right at any time to request the person responsible to block or remove your Personal Data. Again, you may send an e-mail to the Controller of your Personal Data: firstname.lastname@example.org or contact the Controller at the address mentioned in section 2 above.
10. Right to Lodge a Complaint with a Supervisory Authority
In Switzerland, you can lodge a complaint with the competent data protection authority (https://www.edoeb.admin.ch) if you do not agree with the processing of your Personal Data.
If you are resident in the EU, you also have the right to lodge a complaint with your national data protection authority or with the European Data Protection Supervisor (https://edps.europa.eu/) if you do not agree with the processing of your Personal Data.
Last updated: 6 April 2022