Privacy Policy

DATA PROTECTION STATEMENT

Drafted on 5 December 2018

1. Name of the register

Ocusweep View service register

2. Controller

Name: Ocuspecto Oy (“Ocuspecto”, “we” or “us”)

Address: Kaarinantie 700, 20540 Turku

E-mail address: info@ocusweep.com

3. Contact person for the register

Name: Matti Aalto

Address: Ocuspecto Oy, Kaarinantie 700, 20540 Turku

Telephone: +358 40 7469389

E-mail address: info@ocusweep.com

4. The purpose for the processing of personal data

Ocusweep View service (“Service”) enables user’s access to their Ocusweep test
results and share the results in selected social media accounts, if desired.

Personal data will be collected and processed so that Ocuspecto can provide the
Services to its customers.

Data will be processed to identify the Service users and to ensure that only
authorised persons can access the service and only the parts of the Services
meant for them and that they can access only the information that is meant to be
seen by them.

Data can also be used to implement the Service, for customer service purposes
and to convey service bulletins and information to users.

5. The content of the register

For service users, the following information may be stored and processed:

  • First name and surname

  • Birth year

  • User name

  • Password

  • E-mail address

  • Phone number

  • Ocusweep vision tests performed for users and results thereof

  • Information on the usage of the Service

  • Acceptance of Terms of Service and Privacy Policy

6. Regular sources of information

We collect personal data from the users of the Service, and e.g. from opticians
who perform Ocusweep vision tests for users and who request us to send the test
results to users. Information is also automatically collected when using the
Service.

7. Usage of Cookies

We may use "cookies" which enable us to recognize the user in the Service. Usage
of cookies is common in the Internet. Cookies are a programming technology that
helps in browsing the Internet based services and to modify the Service
according to the user’s requirements. Cookies are small text files placed on the
hard drive of the user’s computer or other device, allowing the computer to be
recognized by our Service and avoiding continuous need for logging in when using
the Service. User may refuse to accept cookies and delete existing cookies using
the settings on their Internet browser. If user prevents the use of cookies,
they may be unable to access or use fully certain parts of our Service and we
cannot guarantee the usability of the Service in such case. By accepting this
Privacy Policy user accepts the usage of cookies.

8. Regular destinations of disclosed data

We may hand over your personal data for justified use in accordance with the
applicable data protection laws and regulations. We engage subcontractors to
perform parts of the service. They may have access to personal data so that they
can perform their duties but only to the extent required for their performance.
Ocuspecto has appropriate agreements with these parties.

Ocuspecto may use the information also to develop and market its own products
and services.

We may also provide access to information to our subsidiaries or affiliated
companies and other parties belonging to our group of companies.

User may also share their information in social media via the service or to
opticians registered for our service and other service providers within the
Service.

We do not otherwise grant access to the user’s health information to third
parties.

9. Transfers of data to countries outside the European Union or the European
Economic Area

Your health information will be processes within the European Union or the
European Economic Area. Your other personal information will be transferred
outside of the European Union or the European Economic Area only when allowed by
the EU General Data Protection Regulation.

The authentication service providers we use (Google and OnlineCity ApS) are
registered in the EU – U.S. Privacy Shield framework that protects the
fundamental rights of anyone in the EU whose personal data is transferred to the
United States for commercial purposes.

10. The principles on securing the data file / register

All data will be stored electronically.

Information will be collected into Ocusweep service database. Only
administrators will have access to the database. Such access is protected with
user right management. User interface will only show data that is necessary for
the tasks of the respective person. The views of the user interface as well as
the access rights have been defined based on role and user.

We will use appropriate technical and organizational means to secure the
personal data from inappropriate access, accidental or unlawful destruction,
amendment, distribution and transfer as well as from other unlawful processing.

11. Information storage time

After having received contact information of a potential user so that we can
send them the test results we will store the information for 90 days. This will
enable the user to view their own test results. If the user will not open the
link during the aforesaid period, we will erase the contact information from our
system.

If the user opens the link, we will create a user profile for them. User can
erase their user profile from the system if they so desire.

We store personal information of the user according to the applicable laws and
only as long as required for the purposes described in this Privacy Policy
statement. When the purposes for processing of the user’s personal data no
longer exist, we will erase their personal data.

If the user has not logged in to their registered account during the last five
years we will erase their personal information including user credentials from
our data base. No one, not even the user, can thereafter reactivate the account
and restore the information. We make observations on the usage of our services
and may store information in anonymized form to our own database.

Please note, that some of our services may include public interactive and
communication elements, like ability to post comments and participate in
discussion forums. Your user name and the content you post may remain there even
if we remove your personal information and account. If you do not want to be
identified based on your user name or content that you post, pay attention to
the contents you create.

12. What are your rights?

You have the right to inspect what information related to you has been stored in
the Ocuspecto personal data files. You have a right to have incomplete,
incorrect, unnecessary or outdated personal data deleted or updated.

If we have asked for your consent for direct marketing, you have a right to
unsubscribe from direct marketing messages and customer and other surveys and to
request that we stop processing your personal data for direct marketing
purposes. However, we may still send you notifications concerning our services,
such as information on changes or service failures and interruptions.

If you want to utilise your rights stated above please contact us via e-mail at
info@ocusweep.com or use the contact addresses specified above. Users of the
service will need to send the request from the e-mail address or telephone
number they have registered in the Service as their contact information and the
response will only be sent to that e-mail address or phone number.

You can remove your personal information from the user profile management page
within the Service also by yourself.

In addition to the rights described above you are entitled to make a complaint
to the data protection authority, especially in the European Union country where
you have your domicile or permanent work place or where the claimed breach of
data protection regulation occurred.

13. Amendments to this data protection statement

Ocuspecto may from time to time and at its discretion make amendments to this
data protection statement without prior notice. If this data protection is
amended in a material manner, we will inform all registered users about such
amendment.