What is GDPR?
1. What is the GDPR and what does this mean for me?
GDPR stands for the General Data Protection Regulation, which is a new, European-wide law that regulates how companies and organisations are allowed to handle the personal data of EU-residents. The GDPR comes into effect on 25 May 2018.
Don’t you worry, this will not affect your use of KRYs services - your account with KRY will work just as usual! However, you are given the right to influence how your personal data is used. Your rights are described in detail in our integrity policy.
2. What is meant by “personal data”?
Personal data is any information relating to an identifiable individual. It can identify you as an individual directly or indirectly (i.e. in combination with other information) and can include name, identification number, location data, or other factors specific to the physical, genetic, mental, economic, cultural or social identity of the person.
3. How does KRY handle my personal data? What type of security do you have?
Our goal is to always provide you with high quality healthcare and in order for us to do so, we collect personal data from you, as described above. Access to your data is restricted to the people providing you with the healthcare, or as part of our ongoing quality assurance and product development. We safeguard your personal data and here at KRY wee constantly work with assuring the security of our systems. We do this by utilizing a combination of in-house experts, automatic and manual testing and regular audits by independent third parties.
4. What kind of personal data does KRY handle about me?
We handle basic contact details, such as name, address, personal identification number and phone number. We also process medical data, submitted by you, and retrieved from other caregivers with your consent.
5. So, where do you store my personal data?
KRY store the majority of the personal data in our purpose built secure system. This system is hosted on servers provided by a third party that acts as data processor to us, located within the EU (primarily on Ireland).
6. Does this mean you send my data outside of Sweden or / the EU?
We do not store any of your sensitive personal data (such as data relating to your health) outside of the EU. Occasionally, some of your personal data might be processed by our partners outside of EU. If personal data is transferred to our partners outside of the EU, such transfer will only be conducted on the condition that the transfer is legal under applicable data protection laws.
7. For how long do you store my personal data?
When it comes to medical personal data, there are patient safety legislations that requires us to keep medical records for a certain period of time.
Non-medical personal data will only be kept as long as necessary in order for us to provide the services in a satisfactory manner to you, in accordance with the GDPR, and other applicable legislation.
8. I would like to be “forgotten” and that you remove all my personal data from your systems. How do I go about it, how is this done and how long will it actually take?
When you are a patient, then most of your personal data processed by us is of medical character. In accordance with patient safety legislation medical records must be kept for a certain period of time, in accordance with applicable national legislation, and the right to be forgotten is not covered by that legislation.
However, when it comes to other personal data such as data provided when you signed into the KRY app (excluding any personal data that we are under an obligation to store under mandatory law, relating to your health), you are always free to contact our support function at firstname.lastname@example.org and we will assist you with your requests.
If you request to be forgotten, non-medical data will be removed from our systems as quickly as possible but no later than within thirty (30) days as of your request. We will notify you in writing and confirm which personal data has been erased and as per which date.
9. If I have further questions regarding personal data processing by KRY, who should I contact?
You are always welcome to contact us at email@example.com. We will do our best to contact and assist you with your query within short.
Is it secure?
All information at KRY is heavily encrypted. Your identity is verified using BankID and your doctor's identity is verified using the SITHS-card.
How is my information stored?
All information concerning appointments and medical records is subject to strict confidentiality in accordance with national legal frameworks. Video meetings are not recorded and therefore not documented in any way aside from your updated medical chart as in an ordinary visit to a doctor.
Who is able to see my symptom description?
Only treating healthcare providers have access to your symptom description. Before the meeting, your healthcare provider will review the symptom description you provided in connection with your booking to prepare your meeting.