We are Clinova Limited (or simply “Clinova”). Clinova is a UK based, global digital healthcare company providing health and wellness solutions. Healthwords is our flagship digital product. Throughout this Notice "we", "us", "our" or "Healthwords" means Clinova Limited (including our Healthwords app). Clinova is registered with the Medicines and Healthcare products Regulatory Agency ("MHRA") as a manufacturer of a Class 1 Medical Device (for our app, as patient health self-management software).
"You" and "your" mean you, the person reading this Privacy Notice. We know that you are trusting us with certain pieces of information about you. In what follows, we have taken care to explain how we use this information. Clinova is committed to making the world a healthier place while making sure our actions are not only legal, but ethical, moral, and just. When it comes to your data, we strive to go above and beyond to protect your privacy. You can read more about our core values in the Clinova credo, which is also on our website.
Our aim is to help make the world a healthier place, but we also care how we do this. From the beginning of our story, we have been guided by the belief of doing the right thing, making sure our actions are legal, ethical, moral and just. We will ensure all contact between people is based on trust and absolute integrity and this will be of benefit to all parties. We expect and require all associations and external partners to be organised by a similar ethos.
We are committed to producing innovative, high quality, efficacious and safe healthcare solutions. We have a duty to protect customers, patients, children, parents, pharmacists, doctors, nurses and anybody else that is involved in recommending or using our products. We will ensure that our products have passed the appropriate standards related to research, regulations, licensing, legal requirements, manufacturing, scientific testing, packaging and marketing. We will never stop innovating, creating, developing and researching. We aim to provide real and lasting satisfaction.
We will need knowledge, imagination, skill, diversity and teamwork to succeed. We will seek to recruit and partner with the best. Remuneration will be fair. Loyalty and performance will be rewarded. We must recognise our people’s merits and provide them with adequate opportunities to advance their knowledge, roles and positions. The work environment will safe, clean and attractive. We accept that our people’s religious beliefs, family responsibilities and personal wellbeing are more important than Clinova, and we will at all times help our partners fulfil and prioritise their private duties. We will ensure that competent and fair leaders run our places of work.
We are a UK-based international company and we will strive to respect local traditions, customs and sensitivities as long as our actions fall within the realms of English Law and good UK corporate governance. We must always pay appropriate and fair tax and our principal tax base will always remain Her Majesty’s Revenue and Customs. We have a duty to respect the communities and environment in which we live and work
Healthcare is for the patient, not for the profit, but to enable us to continue our journey we must make a reasonable financial reward. New solutions must be discovered, research must be continued, and tomorrow’s products created. Our products will be priced fairly and competitively. We will make mistakes and we will ensure our financial position can protect us in the bad days. We will aim to develop products that provide innovative, novel, practical and cost-effective solutions. We will offer solutions to people’s needs rather than selling products; this is and always has been our only priority.
We believe that when we look back, the big things will be the small things and the small things will be the big things. Our industriousness will be the basis of our achievements. We will try our best to make sure that the values of our business remain a priority for everyone, every day, at every level of our organisation. We promise to continue to help make the world a healthier place.
We collect information from you, from other organisations and automatically via our Platform if you:
We explain what categories of information we collect (and how) in this section, and what we do with each of the categories in the next section.
You provide us with the following categories of information about you
We need some of this information to hold up our end of the bargain – like your basic Contact information and Log-in details.
Some information is optional – like information about your Health. What you choose to provide us with will affect how many of Healthwords’s features you can use and how well our Platform works for you.
You must keep your profile information up to date – please tell us promptly about any changes (e.g. you alter your address)
We automatically collect the following categories of data from you each time you use our Platform, including
Pending your explicit approval, we will automatically collect the following categories of data from you each time you use our Platform
Location data will include specific geographic locations (such as through GPS, Bluetooth, or WiFi signals) which we use (if you ask or permit us to), so that we can deliver content, advertising or other Platform features that are dependent on knowing where you are, like showing you where your closest chemists/pharmacies, doctors or travel clinics are, or providing local pollen alerts.
Location data may be collected in combination with device ID so that we can recognise your mobile browser or device when you return to the Platform.
Delivery of your location to the Platform will involve us checking any of the following:
Remember, you are always free to opt-in or opt-out of location sharing.
We use Hotjar in order to better understand our users’ needs and to optimize this service and experience. Hotjar is a technology service that helps us better understand our users’ experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our service with user feedback. Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices. This includes a device's IP address (processed during your session and stored in a de-identified form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display our website. Hotjar stores this information on our behalf in a pseudonymized user profile. Hotjar is contractually forbidden to sell any of the data collected on our behalf.
For further details, please see the ‘about Hotjar’ section of Hotjar’s support site.
This section explains the different purposes we use your personal information for, the types of personal information we use for each purpose, and the legal reason(s) (or the "legal basis") for each purpose.
We may process your personal information for multiple purposes and legal bases.
Below is an explanation of what each legal basis means.
We may use the categories (explained in the previous section) as follows:
How we use your information | Types of information | Legal basis Find out more |
---|---|---|
To provide you with the Platform, information offered via the Platform, products and services offered via the Platform, and information which you request, including: | ||
| Log-in Contact Identity Communications Health | Contract Explicit consent to Health data |
| Log-in Contact Identity Communications Health | Contract Explicit consent to Health data |
| Log-in Contact Communications | Contract |
| Log-in Contact Communications | Contract |
| Log-in Contact Identity Health | Contract Explicit consent to Health data |
| Log-in Contact Identity Communications Health | Legitimate interests Explicit consent to Health data |
| Log-in Contact Identity Health | Legitimate interests Explicit consent to Health data |
| Log-in Contact Identity Health | Legitimate interests Explicit consent to Health data |
| Log-in Contact Identity Health | Legitimate interests Explicit consent to Health data |
| Log-in Contact Identity Health | Legitimate interests Explicit consent to Health data |
| Log-in Contact Identity Health | Legitimate interests Explicit consent to Health data |
| Log-in Contact Identity Health | Legitimate interests Explicit consent to Health data |
| Log-in Contact Identity Health | Contract Explicit consent to Health data |
| Log-in Contact Identity Health | Contract Explicit consent to Health data |
To enhance your ability to access and use and our Healthwords Now machines, including: | ||
| Log-in Identity Location Contact Health | Contract Explicit consent to Health data |
| Log-in Contact Communications | Consent |
| Log-in Contact Communications | Consent (to location information) Legitimate interests (in providing Healthwords Now locations) |
| Log-in Contact Location | Legitimate interests (in providing Healthwords Now product availability) |
| Log-in Contact Identity Communications | Legitimate interests |
| Log-in Contact Identity Communications | Legal Obligation Explicit consent to Health data |
| Log-in Automatically collected information | Legitimate Interests |
| Log-in Automatically collected information | Legitimate Interests |
| Log-in Contact Automatically collected information | Legitimate Interests |
| Log-in Contact Identity Communications Automatically collected information Health | Legitimate Interests Explicit consent to Health data |
If you purchase products offered via our Symptom Check assessments or via our Shop: | ||
| Contact Identity Automatically collected information Health | Contract Explicit consent to Health data |
| Automatically collected information | Legitimate interests |
| Log-in Contact Identity Automatically collected information Health | Contract |
How we use your information | Types of information | Legal basis Find out more |
---|---|---|
We may send you promotional updates & marketing via email, SMS, and in-app notifications, if: | ||
| Contact Identity Automatically collected information Marketing Health | Consent Explicit consent to Health data |
| Contact Identity Automatically collected information Marketing Health | Consent Explicit consent to Health data |
| Contact Identity Automatically collected information Marketing Health | Consent Explicit consent to Health data |
| Contact Automatically collected information Marketing | Legitimate interests |
We may send you promotional updates & marketing via email, SMS, and in-app notifications, if: | ||
| Contact Automatically collected information Marketing | Legitimate interests Explicit consent to Health data |
| Contact Automatically collected information Marketing | Legitimate interests |
| Contact Automatically collected information Marketing | Legitimate interests | You can opt-in or opt-out of further marketing at any time by:
|
How we use your information | Types of information | Legal basis Find out more |
---|---|---|
The Healthwords app does not use cookies. We do use tracking pixels in our emails, so we know when an email is opened, how long it is open for, and when it is deleted. | Marketing Automatically collected information | Legitimate interests (strictly necessary tracking pixels, cookies or similar technologies, as applicable) Consent (all other tracking pixels, cookies or similar technologies, as applicable) |
You may provide us with the certain device permissions if you use our Platform on a mobile device.
Photo Library Usage | Photo Library access is required to enable you to add a profile picture. It may also be required if you wish to use certain features (e.g. a dermatology feature). |
Camera | Camera access is required if you choose to take a photo for your profile photo or to upload in the process of using a dermatological assessment feature. |
Calendars & Reminders | Calendar access is required to sync your device calendar for select features (e.g. our medication reminders or our period/ovulation tracker). |
Location Permission | Location permission is required to help you find the nearest pharmacies, doctors, or travel clinic locations, and may also be used to provide you with pollen/allergen alerts for your location. |
Apple Health Data Usage | Permission to access your Apple Health data is required to sync the health data collected by the Health app to help provide you with better assessments and recommendations. |
We may anonymise or pseudonymise, and aggregate any of these categories of information, including identity, and automatically collected information.
What does it mean?
Pseudonymised data is data from which you cannot be identified unless that data is combined with additional information that ties you to the data (which we will always keep separate, secure, and private). For example, if a list of accounts has a number randomly assigned to each of them, but we also have a list linking each random number to the original user’s account number. We are strongly committed to keeping this additional information separate and safely protected.
Anonymised data is data from which you can never be explicitly identified. For example, the number of people who downloaded our app in the last 12 months would be an aggregate statistic, and would contain no information whatsoever about individual downloads.
Our use of aggregated information (such as statistical data or customer profile information) is critical to our understanding of how users engage with our Platform for the purposes of improving it. This information significantly enhances our ability to optimise development of our Platform and bring greater benefits to our users.
We may provide some aggregated data to our partners or other third parties in relation to the products or services that they provide, or to promote our Platform. Where this aggregate information is derived from your personal data, we will ensure that your personal data is removed so that you cannot be re-identified from aggregate information retained or used for these purposes.
While our anonymisation and aggregation of data is based on our legitimate interest in developing and improving our services, you may let us know if you would prefer we do not use your data for this purpose. This will not affect any data which has already been anonymised, but it will stop your personal data being used for this purpose going forward. Please contact us at info@clinova.co.uk if you would like to ask about your data not being used to help us improve and develop our Platform and services.
In accordance with applicable data protection law, we rely on one or more of the following grounds when processing your data:
What do our legal grounds for processing information mean? | ||
Contract: | We collect, store and process your personal information if it's necessary for performing a contract you have with us (including our Terms), or where you have asked us to take specific steps before entering into that contract. | |
Legal Obligation: | We may need to process your personal information to comply with applicable legal obligations and statutory obligations and regulatory rules and guidance, including under applicable UK, EU and local law (including data protection law), and/or any court orders. | |
Legitimate interests: | Processing your personal information is sometimes necessary for us to do the following activities, in our own interest or sometimes in the interests of a third party (like our rewards programme partners). Our legitimate interests are:
| |
Consent: | We'll use your personal information to send you promotional or marketing content if you have given us consent to us doing so, where required by law. You can opt-out of further marketing at any time by selecting the “unsubscribe” link at the end of all our promotional updates and marketing to you, by sending us an email at info@healthwords.ai or by changing your marketing preferences in your online account(s) (if this feature is available). For more information, please refer to our promotional updates and marketing section. | |
Explicit consent: | We may use more sensitive personal information about you, namely health data, if you clearly and separately consent to us doing so (in addition to complying with our contract with you, or one of the other lawful grounds listed above). |
We may share your personal information with:
These organisations will only use your information to the extent necessary to perform their support functions to us, and with appropriate contractual protections.
These organisations will only use your information to the extent necessary to perform their support functions to us, and with appropriate contractual protections.
We will also share your personal information with third parties:
The Platform may, from time to time, contain links to external sites, including links to purchase medications from our online pharmacy partners and links to open up your mobile devices' map app.
We are not responsible for the privacy notices or the content of such sites. Your use of external sites will be governed by their respective terms and privacy information.
We are based in the United Kingdom (UK). We may transfer your personal information to one or more countries outside the UK (including to the EEA), where we (or other companies within the Clinova group) or our Platform providers maintain operations. We will take steps to ensure that your data is held safely in such circumstances.
The servers used to process your personal information collected from this website are located in the United Kingdom, but we collect data from wherever users are situated. The information that we collect may therefore be transferred to the United Kingdom from any other country in which you may be located.
Why do we transfer it?
We may transfer your personal information outside the EEA
Company | Country | Transfer safeguard |
---|---|---|
Heroku (SalesForceDotCom, or "SFDC") | United States | Depending on the relevant processing: Salesforce Processor Binding Corporate Rules Standard Contractual Clauses |
Google LLC, Google Ireland Limited, | United States | Standard Contractual Clauses |
MongoDB, Inc, ObjectLabs Corporation (MongoDB, MLab) | United States | Standard Contractual Clauses |
Your personal information will be kept by Healthwords:
If you opt-out of our sending you promotional updates and marketing, or if you object to any other processing of your personal information, we may keep a record of your objection for the legitimate purpose of ensuring that we can continue to respect your wishes and not contact you further during the term of your objection.
We may retain aggregate information indefinitely, for research purposes and to help us develop and improve our Platform. You can never be identified from aggregate information retained or used for these purposes.
Your personal information will be kept by Healthwords:
for as long as you have the Healthwords app, and
for six years after you delete the Healthwords app or close your Healthwords account. This retention period allows us to monitor issues and, if necessary, address any legal proceedings that relate to our Terms & Conditions (which you have agreed to) and maintain our legitimate operations safely and legally. This may include keeping personal information required for our tax reporting requirements, to comply with the expectations of financial and data protection regulators, to help prevent fraud and other financial crime, and to enforce the relevant terms of agreement or otherwise identify, issue or resolve legal proceedings.
If you opt-out of our sending you promotional updates and marketing, or if you object to any other processing of your personal information, we may keep a record of your objection for the legitimate purpose of ensuring that we can continue to respect your wishes and not contact you further during the term of your objection.
We may retain aggregate information indefinitely, for research purposes and to help us develop and improve our Platform. You can never be identified from aggregate information retained or used for these purposes.
Payments on the Platform are made through our payment gateway provider, Stripe. When you make a purchase via our Platform, we will provide credit or debit card information directly to Stripe which operates a secure server to process payment details, encrypting your credit/debit card information and authorising payment. Information which you supply to Stripe is not within our control and is subject to Stripe's own privacy policy and terms and conditions.
We take reasonable steps (including physical, technical and organisational measures) to protect your personal information from unauthorised access and against unlawful processing, accidental loss, destruction and damage. We offer industry-standard practices and security measures to safeguard and secure the personal information we collect. Our security policies and Notice are periodically reviewed and enhanced as necessary and only authorised personnel have access to personal information.
Unfortunately, transmission of information via the internet is not perfectly secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information submitted to us and any transmission is at your own risk.
Protecting the safety of children when they use the Internet is important to us.
Our Platform is intended for use only by persons who are at least 16 years of age.
If you are under the age of 16 your parent or guardian must consent on your behalf where we ask for consent in relation to the use of your information.
All intellectual property rights in any content of the Platform (including text, graphics, software, photographs and other images, videos, sound, trade marks and logos) are owned by us or our licensors.
Except as expressly set out here or in our Terms, nothing in this Notice or our Terms gives you any rights in respect of any intellectual property owned by us or our licensors and you acknowledge that you do not acquire any ownership rights by downloading content from the Platform.
You may not print off, copy, store or otherwise replicate pages from the Platform (in whole or in part) without our express prior permission. In the event you print off, copy, store or otherwise replicate pages from the Platform (only as permitted by us), you must ensure that any copyright, trade mark or other intellectual property right notices contained in the original content are reproduced.
You have options and choices over how we use your personal information
If you are in the UK or EEA, you have the right under certain circumstances:
Where the processing of your personal information by us is based on consent, you have the right to withdraw that consent without detriment at any time by contacting us at info@clinova.co.uk. You can also change your marketing preferences at any time as described in our promotional updates and marketing section.
If you wish to exercise any of these rights in relation to the personal information we hold about you, or wish to change your preferences at any time, please contact us:
Please note that we may require you to verify your identity before allowing you to access your personal information.
If you remain unhappy with a response you receive from us, you can also refer the matter to your data protection supervisory authority:
https://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm
The Information Commissioner is the supervisory authority in the UK and can provide further information about your rights and our obligations in relation to your personal data, as well as deal with any complaints that you have about our processing of your personal data.
Any changes we make to this Notice will be posted on this page and, in relation to substantive changes, will be notified to you by e-mail.
This policy was last updated on 7 January 2021.
If have any questions about this Privacy Notice, please contact us: