Last Updated: Aug 12, 2019
1.2 The Services
Delivered in the form of an application (the “App”), Natural Cycles is a digital fertility contraceptive cleared by regulators in the US and Europe. The App can also be used as a pregnancy planner and to track a pregnancy. In addition to the App, Natural Cycles has the Website, including a webshop (the “Webshop”) where we sell Natural Cycles’ and business partners’ products, and social media channels (collectively referred to as the “Services”).
NaturalCycles Nordic AB
Reg. no 556952-7657
111 37 Stockholm, Sweden
Natural Cycles may process the following kinds of personal data about you (collectively referred to as “Personal Data”):
|Account Data||includes registration date, payment plan and whether you have an active subscription or not.|
|Contact Data||includes address, billing address, delivery address, email address and telephone number.|
|Device Data||includes device identifier, your mobile operating system, the type of mobile browser you use and time zone setting.|
|IP Data||includes your approximate position based on your IP address.|
|Identity Data||includes first name, last name, username and date of birth.|
|Marketing Data||includes your preferences in receiving marketing from us.|
|Profile Data||includes your feedback and survey responses.|
|Sensitive Data||includes health and sex data, referred to as special categories of Personal Data as defined in article 9 of the European Union’s General Data Protection Regulation (“GDPR”), such as information on whether you are using the App to prevent, plan or follow a pregnancy as well as your contraceptives history, body temperature, menstruation and intercourse data, ovulation, pregnancy test results and personal notes.|
|Transaction Data||includes details about purchases and payments, but excluding bank account and full payment card details (we do however receive card expiration date and some payment card digits from our payment service providers in order to allow access to the App).|
|Usage Data||includes details of your use of the Services, such as traffic data and the features that you access.|
|User Data||includes data provided by you when setting up an account with Natural Cycles and using the App, such as Contact, Identity, Marketing and Sensitive Data as well as other Personal Data that you may provide in connection with such use.|
3.1 Information you give us
Natural Cycles process Personal Data provided by you when registering for an account, signing up for a subscription, and using the App, making a purchase on the Webshop, using our social media platforms, answering surveys, contacting our customer support or otherwise corresponding or interacting with us and our Services.
You can choose to connect the App to Apple Health Kit. We will then collect personal data that you share with us from this application.
When signing up for the App, you will be requested to consent to our use of your Sensitive Data (please note that you will need to consent in order for the App to work). You have the right to withdraw your consent at any time by changing the setting in the App, or by contacting us at email@example.com. If you provide sensitive data to us by other means than the app – for example via support – this is described in greater detail in section 4.1.
It is important that the Personal Data we hold about you is accurate and current. Please keep us informed if your Personal Data changes during our relationship with you.
3.2 Information we automatically collect about you and your device
3.3 Information we receive from suppliers
We receive Device and Usage Data about you from analytics providers such as Google Analytics and Transaction and Contact Data from our payment service providers.
4.1 To enable and provide the Services
It follows from the nature of our Services that we must process such Personal Data that you add to the Services to enable and provide them. This includes to administer the Services and our relationship with you, to calculate your daily fertility or to provide information about a pregnancy, to secure the quality and develop the Services and to communicate and provide customer support, as further explained below. Consent for processing sensitive personal data must be obtained in order for the app to work.
4.1.2 To administer the Services and our relationship with you
We use your User and IT Data to administer the Services and our relationship with you. This includes setting up your account for the App, troubleshooting, system testing as well as notifying you of changes to the Services or technical issues and reaching out to you via in-app messages to ensure your correct and optimal use of the App.
Lawful Basis: Contract, Consent, Legitimate interest in running the business, provide and ensure the proper function and use of the Services
Natural Cycles uses an algorithm that is sensitive to subtle patterns in a woman’s cycle to determine her daily fertility; it does this by analyzing the User Data that is added to the App. If you are using the App to track a pregnancy, it will provide information about the pregnancy based on the User Data that you add to it. Hence, Natural Cycles uses automated methods for processing of User Data in order to provide you with an adequate App.
4.1.3 To calculate your fertility or provide information about a pregnancy
Lawful Basis: Contract, Consent
We process your User, Usage and Account Data to monitor and analyze how our customers engage and interact with the Services so that we can secure the quality and develop the Services to better align them with your usage patterns and preferences. While we have access to Personal Data for the purpose of analytics, the results are aggregated and stripped of any Personal Data.
4.1.4 To secure the quality and develop the Services
We may also contact and enable you to complete surveys. We use the Profile Data from these surveys to better understand how we can improve your user experience.
Lawful Basis: Contract, Consent, Legitimate interest to analyze how our customers use the Services and to develop and improve them
We will process Personal Data that you provide in inquiries to our customer support, on our social media channels or through contact forms provided by us at congresses and events, for the purpose of communicating with you and act on complaints. What type of Personal Data we collect for this purpose depends on the nature of your inquiry. If you are a User, our support agents may request access to your User Data if necessary to appropriately respond to your inquiry. Such access is subject to strict access controls and security measures to protect your integrity.
4.1.5 To communicate with you and provide customer support
When you interact with us publicly on our social media channels, ensure that you do not submit any Personal Data that you do not want to be seen by other people. We recommend that you also read through the privacy policies of such platforms.
Lawful Basis: Contract, Consent, Legitimate interest to respond to your inquiries, as far as Personal Data is processed to communicate with you on matters that are not related to your agreement with us
We use your Identity, Contact, Transaction and Account Data to process purchases and manage the delivery of products from the Webshop and subscriptions. This includes logistics, preventing fraudulent payments and contacting you regarding your purchase.
4.2 To process purchases and deliver the Services
Women’s health is important to Natural Cycles and we invest in scientific research in sexual and reproductive health in order to advance women’s health. We also conduct research for the purpose of evaluating the effectiveness and suitability of the App for different user groups. Thirdly we use the results of our research to communicate the benefits and limitations of Natural Cycles to healthcare professionals. All our published research is subjected to independent peer review and has ethical approval from the relevant professional bodies.
4.3 To conduct research
If we have your consent, we will use your User Data and other Personal Data that you may provide, in pseudonymized form whenever possible (see the Glossary for more information on pseudonymization), for clinical studies, scientific articles and other research purposes as may be disclosed when your Personal Data is collected. However, Personal Data is anonymized and aggregated before any such publications are shared outside of Natural Cycles (see the Glossary for more information on anonymization). We may also contact you with requests to participate in specific research projects run by us or our business partners.
Natural Cycles also contribute to research carried out by selected universities, institutions and other parties by sharing anonymized data with them. For the avoidance of doubt, we do not share any Personal Data with such external parties.
Lawful Basis: Consent
4.4.1 Marketing Communication
Lawful Basis: Legitimate interest to market ourselves and our Services
We use tools that help us identify and reach out to existing and new customers, by matching cookies, device identifiers and hashed (a pseudonymisation technique) email addresses of people who have been using our Services with people on social media platforms to create so called “Custom Audiences” (this enables us to send targeted ads to people who have been using our Services), and “Lookalike Audiences” (this enables us to send targeted ads to people who have similar traits to our Custom Audience). The social media platforms will not share the hashed email address with third parties or other advertisers and will delete it promptly after the match process is complete. Please note that we do not share any Sensitive Data or group users based on sensitive data for the purpose of Custom and Lookalike Audiences.
4.4.2 Social media marketing – custom audiences, lookalike audiences and advertising
Lawful Basis: Legitimate interest to market ourselves and our Services
You may also be contacted and enabled to complete surveys or take part in interviews for marketing purposes. We will process the Profile Data that you provide in such surveys and interviews to analyze user preferences, improve and assess the effectiveness of marketing activities, use as marketing material or other promotional purposes as disclosed when your Personal Data is collected.
4.4.3 Surveys and interviews
Lawful basis: Consent
You always have the right to opt-out of receiving marketing communication or having your data being processed to identify Custom and Lookalike Audiences from us by opting out, by adjusting your settings in the App or contacting us at firstname.lastname@example.org.
4.4.4 Marketing opt-out
4.5 To comply with legal obligations
Natural Cycles has been classified as a medical device intended for use as contraception by an EU Notified Body and the United States Food and Drug Administration (FDA). This means that we are subject to medical device regulations which may require the collection and processing of your Personal Data. There are also other legal provisions that require the processing of your Personal Data, such as accounting and fraud prevention laws.
Lawful Basis: Legal Obligation
Lawful basis: Consent
Natural Cycles never sell your Personal Data and we conduct extensive assessments before engaging any processor to ensure that they have appropriate technical and organizational measures in place that provide adequate protection of your Personal Data. Anyone who is processing Personal Data on our behalf is bound by contractual obligations to keep Personal Data confidential and secure, and to use it only for the purposes as instructed by us.
Natural Cycles may share your Personal Data:
If you choose to share your Personal Data with any third person (e.g. a partner), you accept that you have done so at your own risk.
6.2 Payment service providers
We do not process your financial data such as bank account and full credit card number. That information is provided directly to our payment service providers. Our payment service providers are themselves responsible for the processing of your personal data which means that you will be requested to enter into separate agreements directly with them. The personal data you provide to them will be stored in accordance with their privacy policies, which we recommend you to read carefully.
Any payment transactions carried out by our payment service providers are encrypted and subject to compliance with the Payment Card Industry Security Standard (“PCI DSS”) regulations. PCI DSS requirements help ensure the secure handling of payment information.
6.3 International transfers
Your Personal Data may be transferred and processed in countries outside the EU/EEA where Natural Cycles’ affiliates or service providers are located. Such international transfers are carried out in accordance with applicable laws and are subject to at least one of the following safeguards to protect your Personal Data:
If your Personal Data is processed in the United States, it may also be subject to protection by federal and state regulations, as well as agency policy and guidance by the Federal Trade Commission.
All information you provide to us is transferred using TLS encryption (HTTPS) and stored on secure servers. We use generally accepted industry standards, technologies, procedures and methods, such as firewalls, encrypted storage, pseudonymization, regular software updates, security scans, access control, audit logging and review of admin actions as well as external penetration tests to protect the integrity of your Personal Data and to prevent unauthorized access. We also have policies and other organizational measures in place, including recurrent employee training on data protection and strict procedures to deal with any suspected personal data breach.
The Website may contain links to other websites. Please note that we do not accept any responsibility or liability for personal data that may be collected through these websites or services. We recommend that you read their privacy policies before you submit any personal data to them or use their services.
9.1 Your rights
You have the right to:
If you have any concerns regarding our processing of your Personal Data, you have the right to file a complaint with the Swedish Data Protection Authority (Sw. Datainspektionen), or your local supervisory authority.
9.2 How to exercise your rights
You may contact us in writing at any time to exercise your rights, preferably using the email address that is associated with your user account. We may need to request specific information from you to help us confirm your identity.
We do our best to respond to your request within a few days, and at least within one (1) month. If the request is complicated or if we have received a large number of requests, we may need to prolong our response time with one (1) additional month.
You can exercise your rights at no cost to you. However, we may charge you a reasonable fee if your request is clearly unfounded, repetitive or excessive.
Our Services are not subject to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). While we maintain and use Personal Data, we are not a “Covered Entity” or “Business Associate” as defined by HIPAA.
|Anonymized data||means that the identifying information is irreversibly removed so that an individual is not identifiable. Anonymized data is not Personal Data.|
|App||Natural Cycles’ application|
|Consent||means that you have expressed your agreement to our processing of your personal data for a specific purpose by a statement or clear opt-in. You can withdraw your consent at any time by changing your settings in the App, contacting us at email@example.com or following the instructions provided when the consent was collected.|
|Legal obligation||means that the processing of your Personal Data is necessary for compliance with a legal obligation that we are bound by, e.g. medical device regulations or accounting laws.|
|Legitimate interest||means that we assess that we have a legitimate interest in conducting and managing our business that, considering and balancing any potential impact on you and your rights, we do not consider are overridden by the impact on you. Please contact us if you would like to know more about how we have conducted this balance of interest.|
|Pseudonymized data||means that identifying information is replaced with something else so that additional information is needed to re-identify an individual. Pseudonymization is a security measure.|