Privacy & Cookies Policy of the Evermind App and Website

Full policy

This Privacy Policy applies to any collection and/or processing of personal data (hereinafter “Personal Data”) performed as a result of your use of the app Evermind (the “App”) and the related website evermind.health (the “Website”). Note that this App might collect personal sensitive information that is health-related (hereinafter “Sensitive Data”). If you do not agree with this Policy, please do not access or use the App and the Services.

1. Who collects, controls and process your personal data?

Telefónica Innovación Alpha S.L. (hereinafter “Alpha”) is part of the Telefónica Group and has its social address at Ronda de la Comunicación, Distrito Telefónica, 28050 Madrid, España.,

Alpha is the Data Controller of all Personal Data collected through the App. Alpha will not share your personal data with any other Data Controllers. Only Alpha and its sub processors, following its instructions, will have access to your personal information as described in this Privacy Policy.

Where the App is offered by an employer (Customer) to its employees, Alpha may provide aggregated insights related to usage of the App, so that they can understand its impact. For example, we may provide information on what percentage of people who used the App have found it to be beneficial. These insights will never include personal information and your employer will not be able to know your name, email address nor see any raw data you have entered into the App.

Alpha may choose to conduct a study with invited users, some of whom may be paid for their participation. In this case, users will be invited by Alpha or a third party agency and Alpha will process personal data of those participants following the same purposes described in this Policy, including the arrangement of payments for participation.

You can contact Alpha at hello@evermind.health for any privacy related matter. Telefonica’s Data Protection Office contact is DPO_telefonicasa@telefonica.com

2. Why do we collect personal data about you and what do we do with it?

Help you manage your stress

The main purpose of the the App application is to help you better understand and manage your stress. In order to achieve that purpose, we collect and process information, including personal data. We analyze information from the answers that you share with us in order to offer you recommendations that may help you manage your stress As part of the main purpose and through the different functionalities of the App, we will also process your information to show you insights about your usage of the App and how stressed you think you are. The personal data processed for this purpose may be considered health data.

Your consent is the basis for the collection and process of personal data to manage your stress, including data collected through questionnaires. You can remove your consent at any time by contacting us in hello@evermind.health using if possible the same e-mail address with which you registered in the App.

Provision of basic App services:

If you create an account in our App, we will process some personal data for providing basic services of the App such as registration, authentication or support.

As we strictly need some personal data for the functioning of the App, the lawful basis of this processing is the performance of a contract, specifically the Terms & Conditions of the App. Without that information the App wouldn’t be functional. Sensitive data is not collected or processed for this purpose.

Improving the functioning of the application and our services:

We process personal data to improve the Website and application performance, usability and to provide a better service. This includes aspects related to performance, navigation, availability and usability. To do this we consider things like how often and for how long you use the App, how you navigate between screens, the activities you use, and which screens you spend more time on. We might also ask for your feedback through email or the App. We will not process any sensitive data for this purpose. In some cases the functionality of the application uses third party services to support analytics and navigation and these functions may involve cookies as described in our cookies policy.

In case any of these cookies collects personal data, your consent is the basis for collecting and processing personal data for this purpose. Sensitive data is not collected or processed for this purpose.

We are working to improve the recommendations within the App on an ongoing basis. To do this we may also process data, but only after it has been anonymized in a way that no longer identifies you. We may also use this anonymized data to improve research that supports the creation of products and services similar to the the App.

Inviting you to use the App or any other new product that might be of interest

If you sign up on the Website to register your interest in the App, we will process your personal data to send you an invitation to use the App. We may retain your personal data for some time (see section 5) in order to invite you to try other new products from Alpha.

Marketing:

We process basic personal data to send you information about our services or products, we will not personalize marketing in any way using your personal information. We may use third party services (such as Mailchimp or Typeform) to facilitate communication such as promotional emails.

3. What personal data do we collect about you and how?

Evermind’s functionalities require the collection of personal data. Sometimes you provide us with data, sometimes data about you is collected or inferred through your use of the App or generated by us through analysis.

Since our service is focused on helping you manage your stress, some of the personal information that you share or we collect from you might be related to health conditions or stress behaviors. This is not directly sought by the App, but answers to questions may relate to a medical condition. The App and any information and/or services provided by the App are not intended to be used in the detection, diagnosis, prevention, monitoring, prediction, prognosis, therapy, treatment or alleviation of any condition, disease or vital physiological processes or for the transmission of time sensitive health information. See our Terms & Conditions.

When you sign up on the Website to register your interest in the App, we collect:

When you create an account within the App, you share with us the following information:

When you use the App and answer our questionnaires and tests, you share with us the following information:

We collect through cookies (read our cookies policy) the following information:

We infer from your activity in the App the following information:

We process information to improve the user experience. Based on analysis of how users use the application we can make judgements like if loading times or slow, or if information is too hard to find, and use this to improve the user experience.

4. Do we share personal data about you with others?

We do not share any personal information about you with our customers or any other Data Controllers. We will only share aggregated information that will never be related to any identified or identifiable person.

We may share some of your personal data with service providers for specific activities such as hosting (e.g. AWS) or analytics (e.g. Mixpanel). For more information, please read our cookies policy. We only authorize our service providers to process your information following our instructions. We make sure that our service providers erase all your personal information right after their services are finished. Some of our service providers may be located outside the EEA, including in countries (such as the United States) whose level of data protection may not be the same as that of the country of origin of our users. We take the appropriate measures to ensure those providers comply with EEA standards in every processing of personal data they perform on our behalf, by requiring guarantees such as Standard Contractual Clauses or Privacy Shield certificates.

Internal team members shall process your personal data following professional responsibilities and contractual obligations only for the purposes established in this Privacy Policy. We take appropriate measures to guarantee the fair and confidential use of all personal data by our employees.

5. How long do we keep your data?

We may retain your personal data for different periods of time, depending on the type of data involved and the purposes of the processing, but generally, following these criteria:

6. What rights do you have related your personal data and how can you use them?

The data protection laws give you a series of rights regarding the personal information that we manage about you. Specifically, the rights of access, rectification, erasure, limitation, objection, portability, as well as not being subject to automated decisions and to remove your consent at any time.

You can exercise these rights by contacting us at hello@evermind.health, using if possible the same e-mail address with which you registered in the App and identifying the right you want to request. In the event that you decide to exercise one of these rights through a representative, it will be necessary to provide with the request, the documentation that proves this condition.

You also have the right to file a complaint with a Data Protection Control Authority (e.g., the Information Commissioner’s Office).

In order to register and use our services you must be over 16 years old. Therefore, by signing up you confirm that you meet this condition. We may contact you to confirm this. We do not knowingly collect information from those younger than 16 years. If you are a parent or guardian and believe that your child has used the App you may contact us at hello@evermind.health and we will delete all related personal data.

7. How do we keep your data safe?

Alpha is responsible for ensuring the security, integrity and confidentiality of your personal information. Therefore, as part of our commitment and in compliance with current legislation, we have adopted the most demanding and robust security measures and technical means to prevent their loss, misuse or access without your authorization.

We protect all communications between the App, Website and the servers in line with best practice by using TLS for encryption and server authentication. We use ISO 27001 certified systems in order to protect your registration information including email and password. We store your personal data in an encrypted database.

Also, we promise to act quickly and responsibly in the event that the security of your data may be in danger, and to inform you if necessary.

8. Cookies Policy

What are cookies?

Cookies are small data files that are placed on your computer or mobile device when you visit a website or use an app. Cookies are widely used by online service providers in order to (for example) make services work, or to work more efficiently, as well as to provide reporting information.

Cookies set by the Data Controller are called “first party cookies”. Cookies set by parties other than the Data Controller are called “third party cookies”. Third party cookies enable third party features or functionality to be provided on through the App you are using (such as advertising, interactive content and analytics). The third parties that set these third party cookies can recognize your computer both when it visits the Website or service in question and also when it visits certain other websites or services.

Why do we use cookies and other tracking technologies?

We use third party cookies for several reasons. These cookies enable us and the third parties we work with to track and target the activity of our users. For example, we use cookies for analytics, configuration, and other purposes. Every cookie we use is described in more detail below.

What cookies do we use?

App cookies:

Mixpanel: we use Mixpanel in our App – a service offered by Mixpanel Inc. (Mixpanel), to collect technical data from our App and Website in a pseudo-anonymous manner so that we can better understand how users interact with our App. Mixpanel is used to be able to better understand and track activities within the App as well as to inform you based directly on your activities. Mixpanel is certified under the Privacy Shield agreement and offers a guarantee to comply with the European data protection regulations.
You can find more information about Mixpanel at https://mixpanel.com/terms.

Website cookies:

Google Analytics: We use the “Google Analytics” analysis service from Google Inc. (Google). Google Analytics is designed to record how users interact with a website. Events are recorded such as the initial, or frequent visits of the Website. The events can be used to record other user interests as well, for example, for certain sections of the Website or certain topic areas. Google is certified under the Privacy Shield agreement and offers a guarantee to comply with the European data protection regulations.
You can view the privacy policy from Google here: https://www.google.com/policies/privacy

Facebook Pixel: Our Website uses Facebook Pixel provided by Facebook Inc. (“Facebook”). This conversion-tracking cookie will be set when a user clicks an ad on Facebook. If a user visits certain pages on our Website before the cookie has expired, we and Facebook can see that the user clicked the ad and was redirected to this page. We will receive information about the total number of users who have clicked our ad on Facebook and been redirected to a page with a conversion-tracking tag. However, we will not receive any information that may be used to identify specific users. If you would like to opt out of this data processing, you can use the settings and opt out options provided by Facebook under https://www.facebook.com/ads/preferences/edit

How can I deactivate cookies?

Browser Controls: You can set or amend your web browser controls to accept or refuse cookies. If you choose to reject cookies, you may still use our Website though your access to some functionality and areas of our Website may be restricted. As the means by which you can refuse cookies through your web browser controls vary from browser-to-browser, you should visit your browser’s help menu for more information.

Disabling Most Interest Based Advertising: Most advertising networks offer you a way to opt out of Interest Based Advertising. If you would like to find out more information, please visit http://www.aboutads.info/choices/ or http://www.youronlinechoices.com

You can also withdraw consent and exercise your GDPR rights following the instructions of section 6 of this Privacy Policy.

Effective From: 18th November 2019