Privacy & GDPR.
How Supar Health collects, processes, stores, and protects your personal and health data. We treat your information with the rigour a clinical platform demands.
01Who we are
Supar Health ApS (referred to as "we", "us", "Supar Health") is a Danish-registered company headquartered in Copenhagen, Denmark. We are the data controller for the personal data processed through the Supar Health platform.
If you have any questions about this Privacy Policy or how we process your data, please contact our Data Protection Officer at [email protected].
02The data we collect
We collect the minimum personal data needed to provide the Supar® test and the Health Trajectory Report. The categories of data we process include:
- Account information. Name, email address, password (hashed), phone number, billing address.
- Health information. Date of birth, sex assigned at birth, suPAR test results, any clinical context you choose to provide, and the interpretation provided by the partner clinician.
- Laboratory data. Sample identifiers, intake metadata, and laboratory results linked to your test.
- Payment information. Processed by our payment provider; Supar Health does not store full card details.
- Technical data. IP address, browser type, device information, cookie identifiers, and aggregated platform analytics.
03How we use your data
We process your personal data only for the following purposes:
- To deliver the suPAR test you have ordered and to return the result and interpretation to you
- To support clinical interpretation by the qualified clinician interpreting your result
- To maintain your secure dashboard, including longitudinal tracking across repeat tests
- To process payment and to comply with accounting and tax obligations
- To communicate with you about your account, your test, or material changes to the platform
- To improve the platform through aggregated, de-identified analytics
- To meet our regulatory obligations under European data protection and clinical regulations
04Legal basis for processing
We process your personal data under one or more of the following lawful bases (GDPR Art. 6 and Art. 9):
- Performance of a contract - to deliver the test and report you have ordered
- Explicit consent - for the processing of health data (GDPR Art. 9(2)(a))
- Legitimate interests - for improving platform security, fraud prevention, and aggregated analytics, where these do not override your rights
- Legal obligations - for accounting, tax, and regulatory record-keeping requirements
05Sharing your data
We do not sell your personal data. We share data only as required to deliver the service or as required by law:
- Partner clinicians and partner clinics involved in interpreting your result
- Our laboratory, which processes your sample under strict confidentiality
- Service providers such as payment processors, infrastructure providers, and email delivery - all bound by data processing agreements compliant with GDPR
- Regulatory authorities, where we are legally required to disclose data
All third parties processing data on our behalf operate under data processing agreements that meet GDPR requirements and the EU Standard Contractual Clauses where applicable.
06Data retention
We retain your data only as long as is necessary for the purposes for which it was collected:
- Active account data is retained while your account is active and for a reasonable period thereafter to support re-engagement and longitudinal tracking
- Test results and clinical records are retained for the period required by applicable healthcare record retention laws
- Financial records are retained for the period required by Danish accounting law (typically five years)
- Marketing and analytics data are retained for shorter periods and may be anonymised earlier
You may request deletion of your data at any time, subject to legal retention obligations.
07Your rights under GDPR
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data, subject to legal exceptions
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent at any time for processing based on consent
- Lodge a complaint with the Danish Data Protection Agency (Datatilsynet) or the supervisory authority in your country of residence
To exercise any of these rights, contact [email protected].
08Security
We apply technical and organisational measures appropriate to the sensitivity of health data, including encryption in transit and at rest, access controls, audit logging, and regular security reviews. Our infrastructure is hosted in the EU.
09International transfers
Your data is processed within the European Union and the European Economic Area. Where any service provider operates outside the EEA, we use the Standard Contractual Clauses approved by the European Commission to ensure your data continues to receive equivalent protection.
10Cookies and analytics
We use a minimal set of cookies for essential platform function and aggregated, privacy-respecting analytics. We do not use third-party advertising trackers. A detailed cookie disclosure is available on request.
11Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated to active users by email. The current version is dated at the top of this page.
12Contact
Questions or requests regarding your personal data: [email protected].