Data Protection Information for the App “IVA”
1. Scope of Application of the Data Protection Information
The controller operates an app with which you can plan and document aesthetic medical treatments. The patient data stored here is not analyzed. Only usage data can be analyzed anonymously for research purposes, whereby no conclusions can be drawn about the person of the app user.
This data protection information applies to our app for mobile operating systems and devices (hereinafter referred to as “app”). It explains the type, purpose and scope of data collection when using the app.
Please note that when downloading our app via an app store, you must register or identify yourself with the respective app store operator (e.g., via a Google or App-le ID). The data protection guidelines and terms of use of the app store operators apply, which may differ from the data protection laws of the European Union. We have no influence on these data protection guidelines.
2. Responsible Entity
The responsible entity for the data processing described in this data protection information is:
Smart Medical Applications GmbH
Rathingstr. 8
30559 Hannover
Telephone: (+49)151/16584879
E-Mail: info@iva.software
Data Protection Officer
You can reach our data protection officer using the following contact details:
Althammer & Kill GmbH & Co. KG
E-Mail-Adresse: kontakt-dsb@althammer-kill.de
3. Type, Scope, Purpose, and Legal Basis of Data Processing
Purpose and Legal Basis of Data Processing
Unless more specific provisions are made in this data protection information, we process your personal data when you use the app to provide the functionality of the app, to ensure the security of the app or – if necessary and legally permitted – to contact you. The legal basis is Art. 6 para. 1 lit. b GDPR (fulfillment of contract) and our legitimate interest in providing a functional app (Art. 6 para. 1 lit. f GDPR). If a corresponding consent has been requested, the processing is conducted exclusively based on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, as far as the consent includes the storage of cookies or access to information in the user’s terminal device (e.g., for device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time. Details can be found in the following explanations.
Processed data categories
If you use this app, the following of your personal data will be processed:
User Data/Practitioner Data:
- Email address & login details for two-factor authentication
- Profile data: first/last name, qualification, skill level, role(s)
- Contact data: landline number, mobile number, address, country
- Usage & Technical Data: Device identifiers, device type, OS version, device number, IP address, metadata
- Location data
- In-app purchase/subscription information (active feature subscriptions)
Registration
You can register in the app to use additional functionalities of the app. We will only use the data you enter for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject the registration. In the event of significant changes, for example to the scope of the offer or technically necessary changes, we will use the e-mail address provided during registration to inform you in this way. The data entered during registration is processed for the purpose of implementing the user relationship established by the registration and, if necessary, for the initiation of further contracts (Art. 6 para. 1 lit. b GDPR). The data collected during registration will be stored by us for as long as you are registered on this app and will then be deleted. Statutory retention periods remain unaffected.
Access Rights of the App
To provide our services, the app requests the access rights listed below, which enable us to access certain functions of your device.
- Location data: The location data is used to determine and automatically insert the location information in the patient consent form.
- Device identifier (e.g., type of device, operating system version, device number): Used for troubleshooting and performance optimisation.
The access authorizations granted are used exclusively to provide the associated app functionalities.
The providers of the app stores may process the data.
The legal basis for access is your consent, which you gave during installation (Art. 6 para. 1 lit. a GDPR). You can change the app’s access permissions at any time. In this case, however, the app or certain app functions may no longer work properly.
Sentry
We use the service of Sentry. The provider is Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105.
The tool is used to ensure the technical stability of our service by monitoring system stability and detecting code errors. Sentry uses cookies and similar technologies to log and monitor errors that can be detected in the source code and to improve the technical functionality and performance of our app. To respond to error messages and possible speed slowdowns, we transmit anonymized error log data about your use of the app to Sentry, which is evaluated there. This is metadata, such as information about the operating system you are using, details of the device, the programming language used, possible causes of errors and your server.
User data is transmitted in encrypted form and deleted after 90 days.
The legal basis for data processing is Art. 6 para. 1 sentence 1 lit. f GDPR, i.e., our legitimate interest in enabling you to make the best possible use of our app and the services offered on it.
Sentry may not process your personal data for its own purposes. We have secured this by concluding an order processing contract, https://sentry.io/legal/dpa/. We have concluded EU standard contractual clauses with Sentry to ensure that a level of data protection comparable to that in the EU/EEA is guaranteed in accordance with Art. 46 (2) GDPR when data is transferred to a third country such as the USA. Sentry is also certified under the Data Privacy Framework (DPF), which is available at the following link: https://www.dataprivacyframework.gov/list The DPF is an agreement between the EU and the USA that ensures that DPF-certified US companies comply with the data protection requirements of the GDPR.
Sentry uses the cloud infrastructure of Google LLC, 1600 Amphitheatre Parkway Mountain View, California 94943 USA. Google LLC. is certified under the Data Privacy Framework. This is an adequacy decision within the meaning of Art. 45 GDPR, which provides adequate protection of your personal data following EU standards.
Further information on Sentry’s terms of use and data protection can be found at https://sentry.io/terms/ and https://sentry.io/privacy/.
Contact Us
If you contact us (e.g., via the contact form, by email, telephone, fax, or via another channel), we will store and process your request, including all resulting personal data (e.g., name, request) to process your request. This data is processed based on Art. 6 para. 1 lit. b GDPR, provided that your request is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on your consent (Art. 6 para. 1 lit. a GDPR) and on our legitimate interests (Art. 6 para. 1 lit. f GDPR), as we have a legitimate interest in the effective processing of the inquiries addressed to us. The data you send to us via a contact request will remain with us until you ask us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory statutory provisions – in particular, statutory retention periods – remain unaffected.
Encryption
This app uses encryption for security reasons and to protect the transmission of confidential content, such as the inquiries you send to us via the app. This encryption prevents the data you transmit from being read by unauthorized third parties.
Hosting
App data is stored locally on your device and with:
Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg. AWS may store IP addresses for up to 90 days. Safeguards: Data Privacy Framework & Standard Contractual Clauses (Art. 46 GDPR).
We have concluded an order processing contract with our hoster, which ensures that it processes the data based on our instructions and in compliance with the GDPR.
In-App Purchases
The permanent use of all functional areas of the IVA App may require a paid subscription, which is concluded through the respective app store provider (Apple App Store for iOS devices or Google Play Store for Android devices). The technical handling of the purchase process, subscription activation, renewal, cancellation and billing is carried out exclusively by the respective store operator via the user account associated with that platform (Apple ID or Google account).
We do not receive payment data such as credit card numbers, banking information, or other financial details. These data are processed solely by the store provider in accordance with the store provider’s own terms and privacy policies. We only receive information necessary to determine whether a subscription is active (e.g. subscription status, duration, renewal or cancellation information).
For this purpose, the App communicates with the interface (API) provided by the respective store, which returns the subscription status in order to enable or restrict access to subscribed features. The legal basis for this processing is Art. 6(1)(b) GDPR (contract performance), as the retrieval of the subscription status is required to provide the paid functions, as well as Art. 6(1)(f) GDPR (legitimate interest) in preventing misuse and ensuring that only authorised users have access to premium content.
If a subscription is cancelled in the app store, the premium functions remain available until the end of the contractual period communicated by the store provider. After expiry, access is automatically restricted.
4. Recipients of Personal Data
For the provision and technical operation of the IVA App, as well as for the delivery of support services, we make use of external (IT) service providers. These service providers act on the basis of a data processing agreement and process personal data solely in accordance with our documented instructions and exclusively for the purposes defined by us, as required by Art. 28 GDPR.
The following service providers are used, among others:
- Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg
We use AWS for data hosting and storage purposes. Data is processed on servers located within the EU. Access to data by the provider is restricted to the extent necessary for maintenance, technical support and security. - Sentry – Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA
We use Sentry to ensure the technical stability and reliability of the app through error analysis, crash reports and performance monitoring. In this context, technical diagnostic data (e.g., device type, operating system version, error conditions and metadata) may be transferred. Processing is carried out on the basis of Standard Contractual Clauses (Art. 46 GDPR)and the provider’s certification under the EU-U.S. Data Privacy Framework, where applicable. - RevenueCat, Inc., 1032 E Brandon Blvd, #3003 Brandon, FL 33511, USA
We use RevenueCat for the management of in-app subscriptions and verification of entitlement status. RevenueCat may process the following categories of personal data: - Purchase and transaction data (e.g., purchase date, renewal, cancellation, expiration date)
- Subscription and entitlement status (active / inactive access rights)
- In-app user or device identifiers (e.g., anonymised user ID, if assigned)
- Information on trial periods or introductory offers
Processing by RevenueCat is limited to what is technically necessary to operate, manage and validate subscription access. RevenueCat does not receive payment data (e.g., credit card numbers or bank information); such data is processed exclusively by the respective app store provider.
All listed service providers are contractually bound to comply with applicable data protection regulations and may not process data for their own purposes.
International transfers to Sentry and RevenueCat are safeguarded by Standard Contractual Clauses in accordance with Art. 46 GDPR, in combination with additional technical and organisational measures such as encryption and access control.
5. Data Transfer to Third Countries
The service provider used by us, Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA, is located in the United States. Pursuant to Art. 45(1) GDPR in conjunction with the adequacy decision of the European Commission for the EU–U.S. Data Privacy Framework (DPF) dated 10 July 2023, and based on the provider’s certification under the DPF, the transfer of personal data to the United States does not require any additional specific authorization.
The certification status of the provider can be verified at:
https://www.dataprivacyframework.gov/list
In the event that this legal basis should cease to apply in the future, we have additionally concluded the Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR with the provider in order to ensure an adequate level of data protection for data transfers to the United States.
For the administration and verification of in-app subscriptions, we use the service provider RevenueCat, Inc., 1032 E Brandon Blvd, #3003 Brandon, FL 33511, USA, which is also located in the United States. RevenueCat has contractually committed to the application of the Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, supplemented by appropriate technical and organisational safeguards.
The data processing agreement and SCCs can be reviewed at:
https://www.revenuecat.com/dpa/
Transfers to Sentry and RevenueCat are therefore based either on an adequacy decision under Art. 45 GDPR or, alternatively, on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, ensuring an appropriate level of protection for personal data.
International Availability & Country-Specific Data Protection Provisions
This app is available in a total of 36 countries. For users in the 27 Member States of the European Union, the General Data Protection Regulation (GDPR) applies. For users in Switzerland, the revised Swiss Data Protection Act (revDSG) applies. For the additional countries listed below, national privacy rules apply alongside—but not in priority to—GDPR unless mandatory domestic law requires otherwise.
United Kingdom (England)
Processing is carried out under the UK GDPR / Data Protection Act 2018. Supervisory authority: Information Commissioner’s Office (ICO), www.ico.org.uk.
Switzerland
Processing follows the revised Swiss Data Protection Act (revDSG). Transfers from the EU/EEA rely on appropriate safeguards under Art. 46 GDPR.
Australia
Processing is subject to the Australian Privacy Act. International transfers rely on appropriate safeguards (e.g., Standard Contractual Clauses).
New Zealand
Processing follows the New Zealand Privacy Act. Transfers from the EU/EEA use GDPR-compliant safeguards.
Singapore
Processing follows the Personal Data Protection Act (PDPA). Transfers occur only with appropriate safeguards under Art. 46 GDPR.
Israel
Processing follows the Israeli Privacy Protection Regulations. Transfers rely on contractual safeguards (e.g., SCC).
Chile
Processing follows Ley 19.628 on the protection of personal data. GDPR-level protection applies additionally.
United Arab Emirates (UAE – including Dubai/Abu Dhabi)
Processing follows Federal Law No. 45/2021. Transfers occur only with appropriate safeguards under Art. 46 GDPR.
South Africa
Processing follows the Protection of Personal Information Act (POPIA). Processing is purpose-limited and safeguarded in accordance with GDPR principles.
Basis for International Data Transfers
Transfers to these countries rely exclusively on:
- Standard Contractual Clauses (SCC) under Art. 46 GDPR
- Adequacy decisions where applicable
- Technical and organizational security measures (TOMs)
No processing for the recipients’ own purposes occurs in these countries.
6. Storage Period
Unless a more specific storage period has been specified in this data protection information, your personal data will remain with us until the purpose for processing the data no longer applies. Discontinuation of the purpose regularly occurs when you log out of the app.
If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, deletion will take place after these reasons no longer apply.
Data that is stored exclusively on your end device remains there until you delete it yourself.
7. Automated decision making
No automated decision-making takes place.
8. Your Rights
You are entitled to the following data protection rights within the framework of the GDPR:
Right to information (Art. 15 GDPR): You have the right to request information about your personal data stored by us.
Right to rectification (Art. 16 GDPR): You have the right to request the rectification of inaccurate personal data concerning you. Considering the purpose of the processing, you also have the right to request the completion of incomplete personal data.
Right to erasure (Art. 17 GDPR): You have the right to request the erasure of your personal data.
Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of the processing of personal data concerning you.
Right to data portability (Art. 20 GDPR): You have the right to have personal data that we process automatically, based on your consent or in fulfillment of a contract, handed over to you or another controller in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done as far as it is technically feasible.
Right to withdraw your consent (Art. 7 para. 3 GDPR): If you have given your consent to the processing of your data, you have the right to withdraw this consent at any time with effect for the future.
Right to complain (Art. 77 GDPR): If you believe that we are not complying with data protection regulations when processing your personal data, you have the right to complain to a data protection authority.
In cases where data processing is based on Art. 6 para. 1 sentence 1 lit. e or f GDPR, you have the right to object to data processing on grounds relating to your situation (right to object under Art. 21 GDPR).