Privacy Policy
Protecting your privacy and your personal data (within the meaning of Article 4(1) of the General Data Protection Regulation (EU) 2016/679 – “GDPR”) is one of our top priorities. It is essential to us that our users feel safe and comfortable when using our services.
This privacy policy applies to all of Evela Health’s offerings: our website, the web app (after registration) and our mobile apps for iOS and Android. Sections that apply only to a specific offering are marked accordingly.
Note for users resident in Switzerland
For persons whose habitual residence is in Switzerland, the provisions of the revised Swiss Federal Act on Data Protection (revFADP) apply in addition. Where this policy refers to the GDPR, the corresponding provisions of the revFADP apply by analogy; the data subject rights listed are available to you in a comparable manner under the revFADP as well.
A. General information
Applies to: Website · Web app · Mobile app
A.1 Controller and Data Protection Officer
The controller within the meaning of Art. 4(7) GDPR is:
Evela Health GmbH, Chausseestraße 58d, 10115 Berlin, Germany
You can reach our Data Protection Officer at datenschutz@evela.health or at our postal address with the addition “the Data Protection Officer”.
A.2 Your rights
You have the following rights with regard to the personal data concerning you:
· Right of access (Art. 15 GDPR)
· Right to rectification (Art. 16 GDPR)
· Right to erasure (Art. 17 GDPR; “right to be forgotten”)
· Right to restriction of processing (Art. 18 GDPR)
· Right to object to processing (Art. 21 GDPR)
· Right to data portability (Art. 20 GDPR)
You also have the right to lodge a complaint with a data protection supervisory authority in the Member State of your residence, your place of work or the place of the alleged infringement. The supervisory authority responsible for us is:
Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59-61, 10555 Berlin, phone: +49 30 13889-0, email: mailbox@datenschutz-berlin.de
For users whose habitual residence is in Switzerland, the following authority is additionally competent: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland, www.edoeb.admin.ch
For users whose habitual residence is in Austria, the Austrian Data Protection Authority (DSB), Barichgasse 40-42, 1030 Vienna, www.dsb.gv.at, is a possible point of contact.
Where you have given us consent, you may withdraw it at any time with effect for the future – informally by email to info@evela.health. The lawfulness of the processing carried out until withdrawal remains unaffected.
A.3 Additional note on your right to object
Where processing is based on legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right to object at any time. This also applies where your data are processed for direct marketing purposes.
A.4 No obligation to provide personal data
You are neither legally nor contractually obliged to provide us with personal data. However, if you wish to use our service, processing of the data listed is necessary. If you do not provide it, you will not be able to use our Premium offering.
A.5 No automated decision-making including profiling
In the course of evaluating activity and health data, no decision is made that is based solely on automated processing – including profiling – and that produces legal effects concerning you or similarly significantly affects you.
B. Website only
Applies to: evela.health (public, without login)
B.1 When accessing our website
When you access our website, your browser automatically transmits data to our server, which we store in log files: IP address, date/time of the request, content of the request, access status/HTTP status code, amount of data transferred, referrer URL, browser, operating system, language and version of the browser software.
These data are stored for reasons of technical security for a maximum period of seven days. The legal basis is Art. 6(1)(f) GDPR.
B.2 Symptom check / quiz on our landing page
In the interactive symptom check we process: your answers regarding complaints and symptoms as well as information on your age and health insurance situation, your first name, your email address, the consents given together with their timestamp, and technical metadata (timestamp, truncated IP address as proof of consent).
The information on symptoms and age constitutes special categories of personal data within the meaning of Art. 9(1) GDPR (health data). The legal basis is your explicit consent pursuant to Art. 9(2)(a) GDPR via the mandatory checkbox at the end of the quiz; for first name and email address it is Art. 6(1)(b) GDPR.
We store your quiz data for twelve months from your last interaction. If you conclude a contract within this period, the data will continue to be processed within the contractual relationship; otherwise they will be deleted automatically. You can request deletion or withdraw consent at any time informally at datenschutz@evela.health.
B.3 Registration for the email newsletter
If you have consented, you can subscribe to our newsletter. We process your email address in order to send you a confirmation email and the newsletter. The legal basis is Art. 6(1)(a) GDPR. You can withdraw at any time via the unsubscribe link in each newsletter.
B.4 Registration for business contact
You can register on our website for business contacts. We process your first and last name, company name (if applicable), email address and website. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in business contacts).
B.5 Cookies
Our website uses cookies – small data packets stored on your device either temporarily (session cookies) or permanently. Technically necessary cookies are stored on the basis of Art. 6(1)(f) GDPR. Where consent has been obtained for cookies and similar recognition technologies, processing is based solely on that consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG); consent can be withdrawn at any time.
B.6 Analytics and marketing tools on the website
Google Analytics
This website uses Google Analytics (Google Inc.). Google Analytics uses cookies; the information collected is generally transmitted to a Google server in the USA. IP anonymisation is enabled. Google Inc. is certified under the EU-US Data Privacy Framework.
Google Tag Manager
The Google Tag Manager (Google Ireland Ltd.) is an auxiliary service and processes personal data only for technically necessary purposes. It ensures the loading of other components but does not access their data.
Meta Pixel (Facebook/Instagram Ads)
We use the Meta Pixel (Meta Platforms Ireland Ltd.). It records actions on our website (events, e.g. page views, start and completion of the Evela quiz, newsletter sign-up) and transmits them to Meta – to measure advertising effectiveness, to deliver targeted advertising (custom/lookalike audiences) and to optimise ad delivery. The data processed include, among others, IP address, browser/device information, URL and referrer, timestamp and a cookie identifier (“_fbp”). We also use “Advanced Matching”: certain details (e.g. email address) are hashed in your browser before being transmitted.
The legal basis is your explicit consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG via our cookie consent banner. Without your consent, the pixel is not loaded. For the joint processing of event data there is an agreement pursuant to Art. 26 GDPR.
B.7 Amazon Associates (affiliate programme)
We participate in the Amazon EU Associates Programme. Some links on this website may be affiliate links; if you make a purchase, we may receive a commission – at no additional cost to you. Amazon and its partners may use cookies and tracking technologies to recognise that a visit came via our link. The legal basis is your consent (Art. 6(1)(a) GDPR) via our cookie consent banner and, additionally, Art. 6(1)(f) GDPR.
B.8 Evela Health’s social media pages
We operate company pages on Facebook, Instagram and LinkedIn. Insofar as Meta provides us with statistical analyses (“Page Insights”), we are joint controllers with Meta within the meaning of Art. 26 GDPR; the respective responsibilities are set out in Meta’s Page Insights addendum. Meta assumes primary responsibility for informing data subjects and for handling their data subject rights.
We process the content you share on our pages (posts, comments, direct messages) as well as publicly visible profile data. The legal basis is Art. 6(1)(f) GDPR.
We advise you never to share health data or other sensitive data with us via social media pages.
C. Web app only
Applies to: after registration / login
C.1 Information transmitted by your browser
Each time our web app is accessed, we collect the data that your browser transmits to our server: IP address, date and time of the request, content of the request, access status/HTTP status code, amount of data transferred, referrer, browser, operating system, language and version. Stored for reasons of technical security for a maximum of seven days. Legal basis: Art. 6(1)(f) GDPR.
C.2 Registration / user account
To use the services, prior registration is required. We use your email address to communicate with you on matters relating to the contract or appointments. The legal basis is Art. 6(1)(b) GDPR.
Users with employer-funded access
To verify your eligibility, you log in with your company email address and additionally provide your first name and a password of your choice. We send an individual activation code to the email address provided. No information whatsoever about your registration or use is passed on to your employer.
DAK Hamburg pilot customers
The DAK-Gesundheit participation documents are available at www.evela.health/dak. Users register there and provide their email and postal address. The postal address is used to verify eligibility, as the offering is a regional pilot for women insured with or resident in Hamburg.
C.3 Access data / log files (backend)
When the application is accessed, your device automatically transmits access data to the backend hosting provider: IP address, date/time, time zone, content of the request, access status, amount of data transferred, referrer URL, device operating system, app version. These data are neither combined with other data sources nor used to identify individual users. Legal basis: Art. 6(1)(f) GDPR.
C.4 Questionnaires and data analysis
Intake questionnaire
When you first log in, we ask you to provide voluntary information on your age group, the status of your menopause and your interests, in order to offer you personalised recommendations. The processing of these data, including your health data, is based on your explicit consent pursuant to Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR.
Evela Score
Each day you can document your well-being. The Evela Score sums up your answers and gives an indication of the status of your symptoms.
If you have given the separate, optional consent to use your health data for research purposes, we use these data for statistical analyses and scientific research. They are stored in pseudonymised form; any sharing with scientific partners is carried out – where possible – exclusively in anonymised form. Further details can be found in our separate “Information on the optional use of health data for research purposes”.
For Premium users, data from the Evela Score are shared with medical experts in order to prepare the consultation. The legal basis is your explicit consent (Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR).
Health Assessment
A Health Assessment is carried out to prepare the expert consultations. Data and answers are shared with the medical experts. The purpose is to develop an individual well-being plan (nutrition, exercise, mental health, sleep). Legal basis: explicit consent.
C.5 Expert consultation
As a Premium user you can book expert consultations; the consultation takes place via video conference. The conversation is not recorded. Your expert may take notes, solely in order to support you as effectively as possible. Legal basis: Art. 6(1)(b) GDPR; for the health data, your explicit consent (Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR).
C.6 Analytics tools in the web app
PostHog: We use PostHog to understand how users interact with the web app and how we can improve the user experience. PostHog is operated without cookies; the data are hosted on servers in Germany. The legal basis is our legitimate interest in improving our offering (Art. 6(1)(f) GDPR).
Plausible: Plausible is used to analyse traffic. The tool works entirely without cookies and does not collect any personally identifiable information. The legal basis is Art. 6(1)(f) GDPR.
C.7 Feedback
You can give us feedback – via a standardised questionnaire by email or informally. We process the data you provide (first and last name) for the purpose of continuous improvement. Participation is voluntary; the legal basis is your consent (Art. 6(1)(a) GDPR).
C.8 Support / contacting us
When you contact us, we process the data you provide in order to respond to your request. The legal basis is Art. 6(1)(b) GDPR where a contractual relationship exists or is intended, otherwise Art. 6(1)(f) GDPR.
C.9 Sharing with external treating physicians
If, in the context of an expert consultation, you wish to receive further medical care, your health data stored with us may be forwarded to a treating physician at your explicit request. This is done solely for that purpose and only with your explicit consent. Transmission to any other third parties is excluded. Legal basis: Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR.
D. Mobile app only
Applies to: iOS (App Store) · Android (Google Play)
For the mobile app, the following specifics apply in addition to Sections A and C (registration, questionnaires, expert consultation – these functions are identical). Paid subscriptions are concluded via our web app; payment is processed there (see E.1). No billing takes place within the mobile app itself.
D.1 Push notifications
After your consent, the mobile app sends push notifications via Firebase Cloud Messaging (Google Ireland Limited). A device-specific token is collected for this purpose. The legal basis is Art. 6(1)(a) GDPR. You can disable push notifications at any time in your device settings. For additional information on processing by Google, please refer to Google/Firebase’s privacy information.
D.2 Data protection disclosures in the app stores
Apple and Google additionally provide their own data protection disclosures in their stores (“App Privacy” and “Data safety” respectively). These disclosures are the responsibility of the respective store operators and reflect the same data processing described in this privacy policy.
E. Applies to all offerings
Applies to: Website · Web app · Mobile app
E.1 Payment processing
To process paid offerings, we use the payment service provider Stripe (Stripe Payments Europe, Ltd., Ireland). In all cases, the purchase contract is concluded via our web app; users of the mobile app are directed to the web app for this purpose. Stripe processes the payment data you enter. We ourselves do not receive complete card details. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
E.2 Use of service providers / categories of recipients
Like any company, we use technical service providers (hosting, video conferencing, appointment scheduling, forms, email delivery, cloud storage). We have concluded data processing agreements with all providers ensuring that they process the data solely in accordance with our instructions. Legal basis: Art. 6(1)(f) GDPR in conjunction with Art. 28 GDPR.
To provide the server infrastructure for our website we use IONOS Deploy Now (IONOS SE, Montabaur, Germany). For email communication we use Google Workspace (Google Ireland Limited, Dublin); Google stores the data on servers operated within the EEA.
E.3 Transfers to countries outside the EU/EEA
Some of our processors are located outside the EU/EEA. Before any transfer, we ensure that an adequate level of data protection exists – for example, through an adequacy decision of the EU Commission (e.g. Canada, Israel) or by concluding the EU Standard Contractual Clauses. For processors in the USA, we additionally verify certification under the EU-US Data Privacy Framework.
Addition for Switzerland: For users resident in Switzerland, the disclosure of personal data abroad is governed by the revFADP. Disclosure to countries without an adequate level of protection is based on the Federal Council’s list of adequate countries (Annex 1 to the Data Protection Ordinance) or on the Standard Contractual Clauses recognised by the FDPIC in the version adapted for Switzerland.
E.4 Storage period and deletion
As a rule, we store your data for as long as your user account exists or until you withdraw your consent or request deletion. After that, we delete your data and retain only what we are legally required to keep (e.g. due to commercial or tax retention obligations). Aggregated and anonymised data that can no longer be attributed to you remain stored.