Privacy Policy

    Privacy Policy for Levahealth AB

    1. General

    Levahealth AB ("LEVA", "we", "us", "our", org. no. 559361-1279) is the data controller for the processing of your personal data in connection with our services.

    We value your privacy and always process your personal data in accordance with applicable legislation, including the General Data Protection Regulation (GDPR), the Patient Data Act (PDL) and other relevant healthcare legislation.

    This policy explains how we collect, use, store and share your personal data.

    The policy applies to everyone who uses our website, our digital services and the medical services we offer.

    2. What personal data we collect

    The data we process can be divided into the following categories:

    Basic information

    Name, personal identity number, address, telephone number and email address.

    Health data

    Information about medical history, medications, risk factors, SCORE2 calculation, blood pressure, blood tests, referrals and statements from CACS/CT heart (via radiological partners), and medical records.

    Communication and support

    Information you provide when contacting us, for example via email, messages or video consultations.

    Technical data

    IP address, device information, cookies and usage data from our website.

    Payment information

    Information about completed payments via payment services such as Stripe or Swish. We do not store complete card details.

    3. Purpose and legal basis

    We process your personal data for the following purposes:

    Providing healthcare services

    Record-keeping, risk assessment, diagnostics, statements and medical recommendations.

    Legal basis: Legal obligation (GDPR Art. 6.1 c) and processing of health data for healthcare purposes (GDPR Art. 9.2 h and the Patient Data Act).

    Administration and payment

    Invoicing, payment processing and accounting.

    Legal basis: Contract (GDPR Art. 6.1 b) and legal obligation.

    Communication

    Contact before and during care, video meetings and sending reminders and necessary information.

    Legal basis: Contract and legitimate interest.

    Website and cookies

    Operation, improvement and security of the website and analysis of user behaviour.

    Legal basis: Legitimate interest and/or consent (for non-essential cookies).

    4. Handling of medical records

    As a healthcare provider, we are required by the Patient Data Act to maintain patient records.

    Medical records are stored in a medical records system that meets the requirements of the Patient Data Act and associated security regulations.

    Records must be kept for at least ten (10) years and as a general rule cannot be deleted on request.

    However, you have the right to:

    • access log extracts showing who has read your records
    • request correction through additions
    • request blocking of information in your records

    5. Retention periods

    Medical records

    At least 10 years under the Patient Data Act.

    Payment and accounting records

    7 years under the Accounting Act.

    Communication and support cases

    Up to 12 months.

    Other data (e.g. website data)

    Stored for as long as necessary for the purpose.

    6. Sharing of personal data

    We only share your data when necessary.

    • medical records systems and patient administration
    • video meetings and digital communication
    • email and SMS services
    • web hosting and CMS
    • analytics tools (e.g. Google Analytics)
    • payment services (e.g. Stripe and Swish)

    Healthcare partnerships

    With radiological partners (e.g. Evidia), laboratories and other medical partners to carry out examinations and provide medical feedback.

    Technical service providers

    We use external providers as data processors for, among other things:

    Authorities

    Personal data may be disclosed to authorities when required by law.

    7. Cookies

    We use cookies on our website to improve functionality, analyse traffic and provide a better user experience.

    Some cookies are necessary for the website to function, while others are used for analytics.

    You can control cookies yourself via your browser.

    8. Security

    We process personal data with strict confidentiality and use technical and organisational safeguards to protect the data.

    Access to medical records is logged in accordance with the requirements of the Patient Data Act.

    9. Your rights

    Under the GDPR, you have the right to:

    • receive information about how we process your personal data
    • request correction of inaccurate data
    • request restriction of processing or object to certain processing
    • request data portability
    • request erasure where processing is not based on record-keeping obligations or other legal obligations

    Special rules apply to medical records under the Patient Data Act.

    If you wish to exercise your rights, contact us using the details below.

    10. Minors

    Our services are aimed at adults. The age limit for using the service is 18 years for LEVA's health assessment. For the heart scanning service (CT heart and Calcium score), the age limit is 40 years.

    11. Complaints

    If you have complaints about how we process your personal data, you can contact us.

    You also have the right to file a complaint with the Swedish Authority for Privacy Protection (IMY).

    12. Contact details

    Levahealth AB

    Email: info@levahealth.se