Lundborgkliniken is now Noid Health | Listen to our podcast: Hälsomysteriet

Privacy Policy

How we handle your personal data under GDPR

This privacy policy explains how Noid Health AB collects and processes your personal data. It also describes your rights towards us and how you can exercise them.

If you have questions about your personal data, you are always welcome to contact us at info@noidhealth.se.

1. Data controller

Noid Health AB (“Noid Health”), corporate registration number 556955–5872, Göteborgsvägen 74, 433 63 Sävedalen, Sweden, telephone 031-13 32 00, is the data controller for the processing of your personal data when you use Noid Health’s services.

Noid Health’s processing of personal data complies with the General Data Protection Regulation (EU) 2016/679 (the “GDPR”).

When you use Noid Health’s services, we process your personal data on the basis of a contract with you as the data subject. Processing also takes place to fulfil legal obligations under law and decisions by public authorities and, for certain processing activities, with your consent.

2. Why we process your personal data

The main reason we process your personal data is to maintain the quality of our health-optimising work and enable efficient administration. If we do not have a complete picture of your health, this can also lead to less effective assessment and treatment.

Where providing certain personal information is voluntary, we make this clear to you.

We process your personal data for the following purposes:

  • Assessing and responding to enquiries about our services, such as health screenings and treatments.
  • Providing our services to you and managing internal processes.
  • Managing the product or service and other matters you have with us.
  • Updating your medical record.
  • Communicating directly with you when needed.
  • Managing and keeping notes on our communication with you.
  • Managing and reviewing our business operations, including accounting.
  • Meeting our requirements for good governance, such as internal reporting and compliance.
  • Analysing and developing statistics for our digital platforms, IT systems and the results of our email marketing. By analysing how visitors use our website with the help of Google Analytics, we can improve the user experience for future visitors.
  • Sending you relevant information via text message, email, telephone, post, our IT systems, social media and digital channels, for example Facebook Custom Audiences and Google Custom Match. Offers may relate to products and services we believe may be of interest to you.
  • Developing new products and services, and reviewing and improving existing products and services.
  • Complying with legal and statutory requirements and guidance.
  • Producing customer insights and analyses for ourselves and our business partners. This may take place as part of providing products or services, improving them, or assessing and improving the operation of our businesses.
  • Sharing information with partners where necessary, for example other clinics and doctors.

It may occur that health-optimising partners, such as authorised research facilities, are looking for individuals with certain health conditions to take part in research aimed at improving their health. Your contact details may then be used to invite you to receive more information about such research opportunities.

3. Personal data we process

We process basic personal data such as name, address, email address, national identity number (personnummer) and telephone number.

We also process information about your health and lifestyle, as well as other information required for us to be able to offer you treatment or other services.

We only process personal data when we have a legal basis for doing so.

4. Personal data relating to minors

If the Client is a minor, consent from a parent or guardian is required.

Noid Health takes all reasonable and practical measures to ensure that a minor’s personal data is not processed without the consent of a parent or guardian.

5. Handling of personal data in our services and channels

Medical records

We process your personal data in order to provide our health services. Most information about you is kept in your medical record, where we gather information about your health and the results of examinations and treatments.

Appointment booking

Information about you may also be held in systems needed to administer our health work, for example for scheduling, booked appointments and payment details. This is currently handled in the same system as the medical records.

Treatment communication

Communication about your treatment plans and your personal health always takes place behind secure login in our medical records system or during meetings with our treating staff.

An exception applies to reminders, quality follow-up, booking information and other important information where we, as a healthcare provider, have a legal basis for communicating by email, text message or letter. The purpose is to support you in the best possible way in our work together on your health optimisation.

Invoicing system

Invoice payment is not our standard method of payment. In order to process a payment by invoice, we need payment information.

If payment is financed by an external party, such as your employer or an insurance company, Noid Health receives information from that party. This information is limited to what is directly relevant to the payment: your identity and confirmation of the funding, including any restrictions or conditions.

The external funder processes your personal data outside of Noid Health’s control. For such processing, we refer you to the funder’s own privacy policy.

Processing of payment information is necessary for us to be able to fulfil our contract with you. Once payment has been completed, we no longer process the payment information but delete it from our systems.

We are, however, required to retain accounting records, such as invoices showing name and address, for bookkeeping purposes. This information must currently be retained until the end of the seventh year after the end of the calendar year in which the financial year was closed, in accordance with Chapter 7, Section 2 of the Swedish Bookkeeping Act (bokföringslagen).

Newsletter

If you are a customer of ours or have chosen to subscribe to our newsletter, we process your email address in order to send you the newsletter. Your first name may also be used to personalise the content.

Our newsletters contain a link to unsubscribe. When you click the link, our processing of your personal data for this purpose ends and you will no longer receive newsletters.

The legal basis for this processing is our legitimate interest in customer care and marketing.

Social media

Noid Health is present on several social media platforms, where you can communicate with us through chat and messaging features.

Personal data you provide to us there, such as your profile name, images or information in messages, is not used by us in any system or channel other than the platform in question.

6. Accurate and up-to-date information

We check that the personal data we process about you is not incorrect or misleading.

Since our services depend on your information being accurate and up to date, we ask you to inform us of any relevant changes. You can report changes by contacting us using the contact details in this policy.

To ensure the quality of the data, we have adopted internal rules and established routines for checking and updating your personal data.

7. Recipients of personal data

Your personal data may sometimes need to be transferred to, or shared with, others where necessary or justified.

Staff

At Noid Health, only staff who are involved in your health matter and treatment, or who otherwise need the information to carry out their work in connection with your treatment, may access information about you as a Client.

Noid Health is responsible for ensuring that access to client data is limited to what treatment staff need in order to perform their duties.

Health Optimizing clinics

Noid Health is a clinic that is part of the Health Optimizing group.

Under Article 20 of the GDPR (EU) 2016/679, you have the right to request that data be transferred between clinics, should this become relevant. Any such request should always be directed to Noid Health.

We have specific routines for this that comply with the GDPR.

Suppliers and subcontractors

Your personal data is shared with companies that provide various types of health services when the test analysis is not carried out by us.

Our suppliers are always bound by confidentiality obligations and may not process your data in any way other than in accordance with our instructions.

8. Retention of personal data

All client data is stored in our systems for five years, or until the Client requests that the data be deleted by contacting us, whichever occurs first.

Client data may be retained for a longer period if needed in order to provide services to the Customer. All customer data is, however, reviewed every five years. Unnecessary files and files that are no longer relevant are securely deleted.

If a Client passes away, the Client’s personal data is deleted immediately after we have received notification from a family member or other contact person.

9. Consent to the processing of personal data

We obtain your consent before processing your personal data for the purposes described above, unless we have another legal basis for the processing. If another legal basis is used, we will inform you of it and of our legitimate interest in processing your personal data.

Your consent is voluntary but necessary for us to work together. You can withdraw it at any time by contacting us.

If we need to use your personal data for a purpose other than the one originally stated, we will inform you of the new purpose and ask for your consent before the processing begins. If we have another legal basis for the new processing, we will inform you of this.

10. Processing of personal data not related to our health work

Marketing communication

In order to market our services and products, we process your name, address and email address. We use this information to reach you by email, digital channels and post.

Development and improvement of our services

We measure traffic on our website in order to evaluate, improve and develop our services, products and systems. This includes technical data from your device and information about your activity on the website.

See also the information about cookies and the management of your consent via the Cookie Information tool.

Recruitment

When you apply for a job with us, we process personal data such as name, telephone number and CV.

Noid Health has a legitimate interest in processing this data in order to make a fair and legitimate selection among applications based on qualifications.

11. Sharing with third parties

If we share your personal data with business partners and third parties, for example for research or reporting purposes, we will inform you of what the data will be used for and with whom it will be shared.

No personal data is shared for these purposes without your consent. You can object to this type of disclosure at any time.

We do not transfer your personal data to a third country without informing you and obtaining your consent.

12. Processing within the EU/EEA

Noid Health only processes your personal data in Sweden or within the EU/EEA.

Your personal data is not transferred to, or processed in, a country outside the EU/EEA without you being informed that the transfer can take place lawfully and securely.

13. Use of cookies

What is a cookie?

A cookie is a small data file stored on your computer, tablet or smartphone. A cookie is not a program and cannot contain malicious software or viruses.

How the website uses cookies

Certain cookies perform functions that are necessary for the website to work. Cookies also help us understand why you visit the website, so that we can continuously optimise and adapt it to your needs and interests.

Cookies can, for example, remember items placed in a shopping basket, whether you have visited the website before, whether you are logged in, and your preferred language and currency.

We also use cookies to target our advertising to you on other websites. In most cases, we use cookies as part of our service to show you content that is as relevant to you as possible.

Under the various categories, you can see which specific services store cookies and why they do so.

How long are cookies stored?

The length of time a cookie is stored on your device and in your browser varies. A cookie’s lifetime is calculated from your most recent visit to the website. Once its lifetime expires, the cookie is automatically deleted.

How to decline cookies

You can decline all cookies and/or third-party cookies at any time by changing the settings in the browser on your computer, tablet or smartphone. Where these settings are located depends on which browser you use.

If you decline all cookies and/or third-party cookies, certain functions and services on the website will not work, as they depend on cookies.

How to delete cookies

You can delete cookies you have previously accepted. The method depends on which browser, for example Chrome, Firefox or Safari, and which device, for example smartphone, tablet, PC or Mac, you are using.

Tools for deleting cookies are often found under the privacy and security settings, but their location can vary between browsers.

14. Security

We protect your personal data through internal information security rules. These rules include instructions and measures that protect the data against destruction, loss or alteration, as well as against unauthorised disclosure, access or insight.

We have established routines for granting access to employees who process sensitive personal data and information about personal interests and habits. We monitor their actual access through logging and oversight.

To prevent data loss, we regularly back up our data. We also protect the confidentiality and authenticity of the data through encryption during storage and transfer.

We will notify you as soon as possible of any security breach that poses a high risk to you.

15. Your rights

Under the GDPR, you have a number of rights you can exercise in relation to our processing of your personal data. If you would like to exercise your rights, please contact us at info@noidhealth.se.

Right to information and a register extract

You have the right, once a year and free of charge, to receive information about whether we process personal data about you, as well as further information about the processing.

Right to rectification and erasure

You have the right to have incorrect personal data about you corrected. Under certain conditions, you also have the right to have your personal data and other information about you deleted.

In certain cases, and for specific types of processing, Noid Health has a continued legal obligation to retain your personal data, for example under the Swedish Bookkeeping Act.

Right to restriction of processing

Under certain conditions, you have the right to have the processing of your personal data restricted.

Understand your body before it has to ask for attention.

Start with a free 20-minute call, book a screening directly, or call us and we’ll help you find the right starting point.

031-13 32 00