logo

Privacy Statement App

Privacy statement for the use of Vivy App

(Version 1.1, April 2022)

Vivy GmbH ("Vivy" / "us" / "we") offers you the opportunity to gather information about your health and fitness level through quizzes and other activities and to store this information in your profile in the Vivy App. Based on this profile, the Vivy App will provide you with information about a healthier lifestyle and the prevention of diseases. The protection of your data is very important to us. Therefore, your health data is stored exclusively on your smartphone and is not accessible to Vivy or third parties. Please note that Vivy does not give medical advice and is not bound to medical confidentiality. Please take the time to read this privacy statement carefully.

Overview:

Privacy statement for the use of Vivy
(Version 1.1, April 2022)

General part
§ 1 Name and address of the data controller
§ 2 Contact details of the data protection officer
§ 3 Registration
§ 4 Customer Service
§ 5 Provision of unfiltered recommendations, content and information through health messages
§ 6 Your rights in relation to your data
§ 7 Right of complaint to a supervisory authority

Special functions
§ 8 On-boarding Quiz
§ 9 Health quizzes
§ 10 Virtual Doctors Appointment
§ 11 Personalized messages
§ 12 Search for a doctor
§ 13 Medication plan - interaction check
§ 14 Diary
§ 15 Receipt of the newsletter
§ 16 Use of tracking and analysis tools

General part

Below you will find the essential information about the processing of your data in the Vivy App and your rights associated with it. First, the basic functions of the Vivy App are described. Additional functions, which are generally only activated with your explicit consent, are described in detail in the section "Special Functions".

§ 1 Name and address of the data controller

This privacy statement applies to the processing of your personal data by Vivy GmbH as the responsible controller for this data processing. In the following you will find our contact details:

Vivy GmbH

represented by the managing directors

Mr. Roland Kirch and Dr. Catharina Schauer
Schützenstraße 18
10117 Berlin, Germany
email: support@vivy.com

§ 2 Contact details of the data protection officer

Vivy has appointed a company data protection officer. You can contact him at the above address or at the following email address: privacy@vivy.com or via the telephone number +49 30 568 39530.

§ 3 Account Management

What categories of personal data do we process? If you want to create a user account in the Vivy App in order to use the Vivy App, you first need a QR code and a PIN provided to you by your health insurance company, which you have to scan with your smartphone (QR code) and to provide (PIN) during the registration process. The QR code contains information about the name of your health insurance company and your insurance tariff as well as additional internal IDs, the QR ID, the Target ID and the Consumer Key. The QR code information is uploaded to your profile on the Vivy App as part of the scanning process. Only the QR ID and the name of your health insurance will be sent to and stored on the Vivy servers, while all other information contained in the QR code is solely processed and stored on your device.

In addition, we collect your communication data when you register for the Vivy App in order to create your user account. This includes your name as you want to be called in the app, your email address and your phone number. Even before you enter this data you will be asked for the country from which you are using the Vivy App.

You can change your phone number and password anytime via the “Settings” section in the Vivy App. Please click on “Account” and start with the change process.

What do we use your personal data for? The storage of the data you provide during the registration process is used to provide your user account and to complete your profile on the basis of which content is made available to you.

The QR ID serves as your no-name identifier for Vivy to perform certain tasks like reflecting your registration and acceptance of our Terms of Use on our servers. In addition, Vivy forwards the QR ID to your health insurance company after your initial registration in the Vivy App in order to confirm your registration in the Vivy App towards your health insurance company. Vivy will not get to know your real name or other data stored on your device.

The name of your health insurance company is used by Vivy for the statistical evaluation of how many insured persons of an insurance company have registered for the first time in the Vivy App in a certain period of time. The evaluation is carried out on the basis of anonymised data - a reference to you or your profile can no longer be established.

The Target ID and the Consumer Key may be used by your health insurance company to send you personal messages or to update your profile within the Vivy App.

Only your health insurance company knows which person is behind the internal IDs. For Vivy and all data exchange with the Vivy servers, like your acceptance of our Terms of Use, you are just a certain QR ID or in other words a random number.

What is the legal basis for this specific data processing? The legal basis for the data processing is the fulfillment of our contract with you for the use of the Vivy App.

Is it obligatory or voluntary to supply your personal data? If it's obligatory, what are the consequences of failure to supply the personal data? The processing of your personal data during the registration process is obligatory for using the Vivy App. Any failure to supply the data required will block the finalization of the registration process and thus your ability to use the Vivy App.

What are the choices and means Vivy has provided for you to limit the processing of your personal data? Vivy only requests your personal data which is necessarily required to open your Vivy account. Besides, all of personal data not necessarily to be stored on Vivy servers will be solely stored on your device.

How long do we store your personal data during this data processing? Your data will be stored securely and will be deleted when you request Vivy to delete your data or when you initiate an account deletion. You also have the option of deleting your profile data, which is only stored on your smartphone, by deleting the Vivy App itself.

With whom do we share your personal data during this data processing? The data processed during registration are processed on servers of Amazon Web Services EMEA S.A.R.L., based in Luxembourg. The data processing takes place in Frankfurt am Main, Germany. Amazon Web Services EMEA S.A.R.L. acts as a processor of Vivy in compliance with data protection regulations.

For the 2-factor-authentication via SMS we use the service of Twilio Inc. 375 Beale Street, Suite 300, San Francisco, CA 94105, for which we forward your phone number. Twilio Inc. is acting as a processor for us.  The provider of this tool fulfills the highest data protection standards and processes your data on the basis of approved binding corporate rules in accordance with Article 47 of the GDPR. You can find Twilio’s privacy statement under https://www.twilio.com/legal/privacy .

§ 4 Customer Service

What categories of personal data do we process? If you contact us, we process your contact data and any other information you provide.

What do we use your personal data for? We use the provided data to process and document your request or feedback.

What is the legal basis for this specific data processing? The legal basis for the processing are our (pre-) contractual obligations.

Is it obligatory or voluntary to supply your personal data? If it's obligatory, what are the consequences of failure to supply the personal data? The usage of Vivy’s customer service happens voluntarily. Thus, all of your personal data processed in context with contacting the customer support is based on your voluntary supply of such data.

What are the choices and means Vivy has provided for you to limit the processing of your personal data? Vivy only processes your contact details necessarily required to provide you with a functioning customer service.

With whom do we share your personal data in this data processing? For answering and documenting customer inquiries, we use the customer service tool Zendesk, a customer service platform of Zendesk Inc., 989 Market Street #300, San Francisco, CA 94102. Zendesk Inc. acts for us as a processor. Zendesk fulfills the highest data protection standards and processes your data on the basis of approved binding corporate rules in accordance with Article 47 of the GDPR.

You can find the privacy statement of Zendesk Inc. under https://www.zendesk.com/company/customers-partners/privacy-policy/ .

How long do we store your personal data during this data processing? We anonymize completed requests after 180 days. The anonymized inquiries remain stored for statistical purposes for another 24 months and are then deleted.

§ 5 Provision of unfiltered recommendations, content and information through health messages

What categories of personal data do we process in this data processing? We use the name of your insurance company for the provision of health news (see § 3 "Registration").

What do we process your personal data for in this data processing? The purpose of the functionality is to provide you with tips for a healthier lifestyle, offers and additional services as well as further information. This content can come from Vivy as well as from your health insurance company. However, since only Vivy sends the information directly to your smartphone, we need the name of your insurance company to ensure that you do not receive information from other health insurance companies. The processing takes place exclusively on your smartphone.

What is the legal basis for this data processing? The legal basis for the processing are our (pre-)contractual obligations.

Is it obligatory or voluntary to supply your personal data? If it's obligatory, what are the consequences of failure to supply the personal data? Processing of the name of your health insurance is obligatory for usage of the Vivy App. The respective information is provided during the registration process by scanning the QR code. In case you should not scan the QR code registration within the Vivy App will not be possible.

What are the choices and means Vivy has provided for you to limit the processing of your personal data? Vivy decided to only process the name of your insurance but no other personal data when providing you with relevant information from your insurance.

With whom do we share your data in this data processing? Your personal data will not be shared with third parties in this data processing.

How long do we store your personal data during this data processing? Your collected data is stored until it is no longer required for the purpose for which it was collected. Your data will be deleted if you request the deletion of your user account.

§ 6 Your rights in relation to your data

Access: You have the right to request information from us at any time about the data stored about you. This also applies to the recipients or categories of recipients to whom this data is passed on, the purpose and duration of storage.

Correction and deletion: You also have the right to demand correction and deletion of your personal data.

Objection to processing: The legal basis for processing of personal data for the performance of tasks in the public interest or for the protection of legitimate interests in accordance with this clause is your consent. You can withdraw your consent to the processing of your personal data at any time with effect for the future. In the event of your withdrawal of consent, we shall refrain from any further processing of your data for the above-mentioned purposes, unless there are compelling reasons for processing that are worthy of protection and outweigh your interests, rights and freedoms, or the processing is necessary for the assertion, exercise or defense of legal claims.

The data processing may be objected to for reasons arising from the specific situation of the data subject.

Data portability: Furthermore, you can request a copy of all data processed by Vivy at any time.

Additional rights: Notwithstanding the foregoing, you are entitled to exercise all other rights set forth in the Philippine Data Protection Act of 2012.

How can you exercise your rights? To exercise these rights, please contact Vivy GmbH, Schützenstraße 18, 10117 Berlin or send an email to support@vivy.com .

§ 7 Right of complaint to a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to complain to a data protection authority. You may do so by contacting the data protection authority in your usual place of residence or at our headquarters. The address of the supervisory authority responsible for Vivy is

Berlin Commissioner for Data Protection and Freedom of Information

Friedrichstrasse 219

10969 Berlin, Germany

Special functions

In addition to the basic functions of the Vivy App, we offer you, among other things, individualized services with which you can build up your profile and, based on this profile, obtain specific information on how to improve your health and thus your lifestyle. In addition, Vivy provides you with further services such as virtual appointments with doctors or the medication plan and interaction check. The provision of certain functions may depend on the insurance tariff you have booked with your health insurance company.

§ 8 On-boarding Quiz

What categories of personal data do we process? After registration, you can complete your profile with an on-boarding quiz. In doing so, we process information about your health, your fitness or other information about your lifestyle. These data are in particular health data. You can change the data you have entered at any time in the settings or delete it by revoking your consent.

What do we use your personal data for? The processing of your data serves exclusively to complete your profile and takes place solely on your smartphone. In addition, you have the option to receive certain recommendations and other information about a healthy lifestyle based on your profile (see § 11 "Personalized messages").

What is the legal basis for this data processing? The execution of the on-boarding quiz is voluntary. The legal basis for this function is your consent. You can revoke this consent at any time with effect for the future in the menu item "Settings". However, the legality of the storage of data based on your consent until revocation is not affected by this.

With whom do we share your personal data during this data processing? Your personal data will not be shared with third parties during this data processing.

How long do we store your personal data during this data processing? Your data collected during the on-boarding quiz is stored exclusively on your smartphone. You alone decide how long this data will be stored. You can delete the data either by deleting the app or by withdrawing your consent (see above).

§ 9 Health quizzes

What categories of personal data do we process? You have the possibility to constantly complete your profile by taking quizzes. We process information about your lifestyle, state of health, possible previous illnesses, etc. These data are in particular health data.

Why do we process your personal data? Your answers to the individual quiz questions are analyzed on the basis of scientific test procedures.

Please note in this respect, that the feature of health quizzes does not replace the consultation of a doctor, but is only based on statistical and empirical surveys.

The processing of your data serves exclusively to complete your profile. In addition, you have the option to receive certain recommendations and other information about a healthy lifestyle based on your profile (see § 11 "Personalized messages").

What is the legal basis for this data processing? The execution of the health quizzes is voluntary. The legal basis for this function is your consent. You can revoke this consent at any time with effect for the future in the menu item "Settings". However, the legality of the storage of data based on your consent until revocation is not affected by this.

With whom do we share your personal data during this data processing? Your personal data will not be shared with third parties during this data processing.

How long do we store your personal data during this data processing? Your data collected through the health quizzes will be stored solely on your smartphone. You alone decide how long this data is stored. You can delete the data either by deleting the app or by withdrawing your consent (see above).

§ 10 Personalized messages

What categories of personal data do we process? You can receive personalized content (offers, tips and information) based on your specific profile. Content is sent to your Vivy App. You will only receive information that Vivy or your health insurance company thinks might be of interest to you. This is achieved by matching the content of a message with your profile data. These data are in particular health data. The filtering of messages takes place solely on your smartphone.

Why do we process your personal data? We process your data in order to send you only such messages that could be of interest to you based on your user and health profile.

What is the legal basis for this data processing? The filtering of messages based on your user and health profile is voluntary. The legal basis for this function is your consent. You can revoke this consent at any time with effect for the future in the menu item "Settings". However, this does not affect the legality of the processing of your data that took place on the basis of your consent until the revocation.

With whom do we share your personal data during this data processing? Your personal data will not be shared with third parties in this data processing.

How long do we store your personal data during this data processing? Your data will be processed exclusively on your smartphone and only at the moment a message is sent to your Vivy App. There is no additional storage of data which is already in your user and health profile.

§ 11 Search for a doctor

What categories of personal data do we process? With the app function "Doctor search" you have the possibility to find a doctor in your area by entering a specific field of expertise. The indication of the field of expertise in the context of the doctor search is health data. Vivy App uses the localization function of your smartphone to display doctors of the field of expertise you are searching for and provides the possibility to have the localization of the doctor shown within the Vivy App by using the Google Maps API. Only information on latitude and longitude of the position of the respective doctor will be shared with Google Maps.

What do we process your personal data for? The purpose of this function is to enable you to easily find a doctor associated with your health insurance. The search is based on a regularly updated list of doctors associated with your health insurance on your smartphone. Once you have entered a field of expertise, all doctors who practice in that field will be displayed. The processing is done solely on your smartphone. There is no exchange with the Vivy servers.

What is the legal basis of this data processing? The input of information about the field of expertise you are looking for in the Vivy App is voluntary. The legal basis for the comparison with the list of doctors is your consent. You can revoke this consent at any time with effect for the future in the menu item "Settings". However, the legality of the storage of the data that has taken place on the basis of the consent until the revocation is not affected by this.

The input of an address or granting the permission to access your smartphone’s localization data is voluntary. The legal basis for the processing are our (pre-)contractual obligations.

With whom do we share your personal data during this data processing? We do not share your data with third parties within the scope of this function.

How long do we store your personal data during this data processing? Your data will be processed exclusively on your smartphone and only at the moment you use the doctor search function. There is no storage of the doctor search or the field of expertise you entered for later use - neither on your smartphone nor on the Vivy servers.

§ 12 Medication plan - interaction check

What categories of personal data do we process? With the help of the medication plan, you can have yourself reminded of the time you have to take your medication. In addition, we use the interaction check you provide in the app for your medication to inform you about possible interactions of the medication you are taking. This information is health data.

Why do we process your personal data? The purpose of this function is to remind you to take your medication at the right time and to inform you about any drug interactions. After you have entered your medication, Vivy will inform you in the app about possible existing interactions with other medication.

Please note, that the drug interaction feature is not intended as a substitute for professional medical advice, diagnosis or treatment, but only serves as a first indication of possible interactions. You should always contact a doctor to further clarify possible interactions of your medication displayed in the Vivy App.

What is the legal basis for this data processing? The entry of medications in the app is voluntary. The legal basis for checking the drugs for interactions is your consent. You can revoke this consent at any time with effect for the future in the menu item "Settings". However, the legality of the storage of data based on your consent until revocation is not affected by this. Please note that you will then no longer be able to use this app function and will not be informed about interactions.

With whom do we share your personal data during this data processing? Your personal data will not be shared with third parties.

How long do we store your personal data during this data processing? Your collected data is solely stored on your smartphone. You alone decide how long this data will be stored. You can delete the data either by deleting the app or by revoking your consent (see above).

§ 13 Diary

What categories of personal data do we process? You have the option of manually entering data on your general health and fitness status into the Vivy App and also saving it in the form of a diary to monitor your development. In addition, you can also grant the Vivy app access to your Apple Health app - if you have an iPhone - or to your Google Health Kit App - if you have an Android smartphone - and share the data stored there with your Vivy App.

Finally, you have the possibility to measure your stress level by scanning your finger with the camera of your smartphone. By placing your finger on the smartphone camera for one minute, the stress measurement takes place. The illumination of your fingertip enables the analysis of your blood vessels. Based on this analysis, the Vivy App determines your heart rate variability and thus your stress resistance.

Why do we process your personal data? We use your data to further build up your profile with further data on your health and fitness status, to send you individualised health tips and messages based on this and also to enable you to track your health development.

What is the legal basis for this specific data processing? The usage of the diary function and respective entries of your data is voluntary. The legal basis for this function is your consent. You can revoke this consent at any time with effect for the future in the menu item "Settings". However, the legality of the storage of data based on your consent until revocation is not affected by this.

With whom do we share your personal data during this data processing? Your personal data will not be shared with third parties in this data processing.

How long do we store your personal data during this data processing? Your data collected is stored exclusively on your smartphone. You alone decide how long this data will be stored. You can delete the data either by deleting the app or by withdrawing your consent (see above).

§ 14 Receipt of the newsletter

What categories of personal data do we process? You have the possibility to receive a newsletter from us with further information. The newsletter contains current information about Vivy and about the further development of the Vivy App. For this we use your email address.

What do we use your personal data for in this data processing? The purpose of this offer is to provide you with regular updates on the further development of the Vivy App. We will introduce you to new functionalities and inform you about news of our service offer. To provide you with these product recommendations in the Vivy App, we need your contact data.

What is the legal basis for this specific data processing? The use of your contact data is based on your consent. You can revoke this consent at any time with effect for the future in the menu item "Settings" or by sending your revocation to support@vivy.com . However, the legality of the storage of your contact data, which was carried out on the basis of your consent until the revocation, is not affected by this.

With whom do we share your data during this data processing? We do not pass on your data to third parties.

How long do we store your personal data during this data processing? We use your contact data for the provision of our newsletter until they are no longer required for this purpose. The newsletter will be provided until you revoke your consent or delete your Vivy account.

§ 15 Use of tracking and analysis tools

What categories of personal data do we process? We use the tracking and analysis tool Crashlytics, which uses information about your smartphone (operating system and version of the operating system).

We also record which screens in the app you opened, the time you spent on it and your interactions with the screens. In addition, we record information about which device you use and its settings (e.g. version of the device’s operating system, screen resolution etc.). Since we anonymize your IP address before we collect the data, it is not possible to match the collected data to your user profile. The collected data is only used in aggregated form and is not analyzed individually. Vivy uses its own tracking solution and does not involve third party companies.

Why do we process your personal data? We use your data to analyze the usage of our app in order to improve our features and optimize your user experience.

We need the information about your device shared with Crashlytics to measure the functionality of the Vivy App. This enables us to collect error and crash reports about the app in a timely manner and thus take necessary measures to ensure the Vivy App's functionality.

What is the legal basis for this data processing? The legal basis is your consent. You can revoke this consent at any time with effect for the future. However, the legality of the storage of the data based on your consent until revocation is not affected by this. You can send your revocation at any time to Vivy Customer Service at support@vivy.com .

With whom do we share your personal data during this data processing? If you have given your consent, we will use the tool of the provider Crashlytics Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) to evaluate the use of our app. Crashlytics of Google LLC receives information about your device status, e.g. device ID and operating system information, which is necessary for a failure analysis. Your IP address will only be forwarded in anonymized form. You can find details about the privacy statement of Google LLC under policies.google.com/privacy .

How long do we store your personal data during this data processing? Your data is stored until it is no longer required for the purpose for which it was collected. Crashlytics data is deleted after 180 days.

Vivy App Privacy Statement Links