Kelaa Privacy


Soma Analytics UG (haftungsbeschraenkt) (“Soma”, “we” or “us”) is committed to ensuring that your privacy in connection with your use of our website, applications, other products, services and features thereof is respected and protected. Should we ask you to provide certain information by which you can be identified when using our applications, website or services, then you can be assured that it will only be used in accordance with this privacy statement. Please read the following carefully to understand our practices regarding your personal information and how we will collect and use your personal information. For the purposes of the The EU General Data Protection Regulation 2018 (GDPR) we are the data controller.

1. Information collected as part of the Kelaa Mental Resilience service and app.

 

Soma Analytics is the company behind Kelaa Mental Resilience (Kelaa).  We may collect and process the following information about you. In each data category we explain what type of data we may collect, explained by concrete examples. Next to it we outline why we collect this type of data and what purposes it is being used for.

 
Information we collect
What we do with it
Contact information

E.g. first name and email address
Soma Analytics uses contact information to:

Provide the services as an email account is required in order to sign up. We consider this to be a contractual obligation.

Improve the product by requesting feedback from users. We consider this to be a legitimate interest but you still have the right to object.

Support and troubleshooting if required. We consider this to be a contractual obligation.

Update and inform e.g. to send email reminders, provide release updates and support communications. We consider this to be a contractual obligation.

Demographic information

E.g. age, gender, department, and level
Kelaa uses demographic information to:

Provide the service by personalising and tailoring the content presented to you. We consider this to be a contractual obligation.

Improve the product by understanding how different demographics interact with the app. We consider this to be a legitimate interest but you still have the right to object.

Support and troubleshooting if required. We consider this to be a contractual obligation.

If you are part of an organisation account, this information, is presented to your organisation in an aggregated and anonymised format for the purpose of identifying patterns and trends across different group profiles. We require your consent to do this.
Device information and technical characteristics

E.g. Phone model, operating system, app version, timezone, unique identifier for push notifications, IP address and HTTP codes
Kelaa uses device information and technical characteristics to:

Provide the service e.g. deliver push notifications. Timezone is necessary to ensure sessions are unlocked at the correct time and that notifications are received in the correct timezone. We consider this to be a contractual obligation.

Improve the product by understanding what operating systems and devices we should support as well as the uptake and impact of new product releases. We consider this to be a legitimate interest but you still have the right to object.

Support and troubleshooting, if required. We consider this to be a contractual obligation.

Keep your data safe and secure. We consider this to be a legitimate interest but you still have the right to object.

If you are part of an organisation account, this information is presented to your organisation in an aggregated and anonymised format for the purpose of understanding the uptake of the app across different mobile platforms and new Kelaa releases. We require your consent to do this.
Questionnaire Scores

E.g. Your answers to questionnaires in the app about mental resilience, wellbeing and stress

We consider this to be sensitive data and will never share it with third parties.


Kelaa uses your questionnaire answers to:

To provide you with a score for wellbeing, energy and resilience. They are also used to recommend personal goals and details of your company employee assistance helpline if required. We consider this to be a contractual obligation.

In order to use Kelaa, you must give permission to process this data as this is a fundamental part of your journey on the app. Opting out will prevent you from continuing with the setup and will require us to delete all your information and your Kelaa account.

Improve the product by understanding how effective the app is in improving wellbeing and user engagement with the feature and the app generally. We consider this to be a legitimate interest, but still require your consent.

Support and troubleshooting, if required. We consider this to be a contractual obligation, but still require consent.

If you are part of an organisation account, this data is presented to your organisation in an aggregated and anonymised format for the purpose of providing insights into overall company wellbeing. We require your consent to do this.



Goals and Sessions

E.g. Information about your journey in the app such as which goal you select, which daily sessions you take, if you like a daily session and your inputs to exercises in the daily sessions.

We consider this to be sensitive data and will never share it with third parties.

Kelaa uses Goal and session data to:

Provide you with the service and tailor and customise the content you receive. We consider this to be a contractual obligation.

In order to use Kelaa, you must give permission to process this data as this is a fundamental part of your journey on the app. Opting out will prevent you from continuing with the setup and will require us to delete all your information and your Kelaa account.

Improve the product by measuring how popular different goals are in order to develop more relevant goals for you. We consider this to be a legitimate interest, but still require your consent.

Support and troubleshooting if required. We consider this to be a contractual obligation, but still require consent.


If you are part of an organisation account, goals selected is presented to your organisation in an aggregated and anonymised format for the purpose of tailoring organisation support to popular wellbeing topics. We require your consent to do this.
Sleep

E.g. The raw activity data for a night and derived sleep parameters including, e.g. the time to fall asleep, the sleep duration, sleep efficiency and start and stop times.

The sleep tracking feature is optional.

We consider this to be sensitive data and will never share it with third parties.

Kelaa uses sleep tracking data to:

Provides you with insights on your sleep quality and behaviour. This data is also used to personalise and tailor the content presented to you. We consider this to be a contractual obligation.

In order to use the sleep tracker, you must give permission to process this data. Opting out will prevent you from using the sleep tracker to track your sleep.

Improve the product by understanding how people interact with the sleep tracker and with Kelaa generally. The data is also used to understand how effective Kelaa is in improving sleep. We consider this to be a legitimate interest, but still require your consent.

Support and troubleshooting if required. We consider this to be a contractual obligation, but still require consent.


If you are part of an organisation account, this information is presented to your organisation in an aggregated and anonymised format for the purpose of creating a wellbeing strategy around improving sleep. We require your consent to do this.
Usage

E.g. Last login, when you start and complete a session.
Kelaa uses usage data to:

Improve the product by understanding how frequently users interact with the app. For this purpose we may also conduct a drop-out analysis to understand the context in which users may or may not continue to use the app. We consider this to be a legitimate interest but you still have the right to object.

Support and troubleshooting if required. We consider this to be a contractual obligation.

If you are part of an organisation account, this information is presented to your organisation in an aggregated and anonymised format for the purpose of understanding how popular the app is, and to drive future engagement campaigns. We require your consent to do this.
Email Analytics

E.g. Open rates
Kelaa uses email analytics data is used to:

Improve the product by optimising and improving the emails we send to users and to remind you again if you haven't responded. We consider this to be a legitimate interest but you still have the right to object.
Error reporting and logs

E.g. actions associated with an error.

Kelaa uses error reporting and logs data to:

Support and troubleshooting if required. We consider this to be a contractual obligation.

Create a more reliable and stable product for our users. We consider this to be a legitimate interest but you still have the right to object.

Keep our servers secure and your data protected. We consider this to be a legitimate interest but you still have the right to object.

Information in connection with a support query

e.g. screenshots
Information in connection with a support query is used to:

Provide you with technical support or to answer any questions you may have. We consider this to be a contractual obligation.
Tracking and web analytics

E.g. Cookies on our registration portal. Further information may include unique device identifiers, IP address, information about your browser and operating system, referrer URLs.


Tracking and web analytics on our portal to:

Optimise and improve our portal. We consider this to be a legitimate interest but you still have the right to object.

2.    Information we share with third parties

 

2.1.        Information in relation to an organisation account

The Kelaa Mental Resilience application was designed for companies, organisations and workplaces, who make Kelaa available to their employees or members of their organisation. If you have registered to use Kelaa through a code or other registration credential provided by a company or organisation (“organisation account”) the organisation will have access to aggregated and anonymised usage information. We go to great lengths to make sure that the information shared with your employer or organisation is not personally-identifiable, in fact Kelaa automatically hides the identity of groups with less than 20 members in order to protect the identity of individuals in that group.

The data is used by your employer to inform their wellbeing strategy  and understand the uptake of the app across the organisation.

The consequences are positive and will help your employer create a better working environment for your and all their staff. We require your consent to process your information for this purpose.

The following information may be reported to your organisation in an aggregated and not personally-identifiable way:

 

2.2.        Third party data controllers and processors outside the EEA

In certain areas outlined below we share data with third party recipients who may collect and/or process the data. We do not share data with countries that are not considered “adequate” by EU standards. We only share data with third parties in the US that have signed up to the EU-US privacy shield.

We will not disclose any data to government agencies except where required by law.

 

3.    Security

 

Any information users provide to us through our applications, website or services will be held in our secure servers located in Ireland, which uses state-of-the-art, multi-layered security methods, and in accordance with applicable privacy laws.

We restrict access to the Data to those Soma Analytics employees or other parties who need access to such Data in order to provide the services. We maintain appropriate physical, electronic and procedural safeguards to protect an individual’s Data. This includes firewalls, individual passwords and encryption. We take all appropriate measures to safeguard an individual’s data against unauthorised or unlawful processing and use, accidental loss, destruction, damage, theft, disclosure or modification and to ensure its integrity.

We do not share sensitive information to any third party without an individual’s specific consent or unless required by law.

 

4.   Data storage

 

Your data is stored and processed in Ireland (EU). We are using Amazon AWS, the leading cloud computing platform, allowing us to access state of the art data centre infrastructure and security facilities.  Amazon AWS is ISO 27001 certified. Even though the data is securely stored in Ireland (EU), we cannot exclude the possibility that Amazon AWS is subject to US law enforcement requests.

We retain personal data by default for a maximum period of three years.

If you are part of an organisation account, the retention period may be different. In this case the retention period agreed with your organisation overrules our standard retention period.

 

5.    Individual rights

 

5.1.  Right to requested information

Upon request by email to support@soma-analytics.com, we will notify you of the data which we store about you and how we have analysed your data to arrive at a conclusion.

 

5.2.  Right to correct information

If you believe that any information we are holding on you is incorrect or incomplete, please email us as soon as possible and we will promptly correct any information found to be incorrect. From the 25th May 2018, demographic information such as Age, Gender, Department and Level can be changed directly from the Settings area of the application.

 

5.3.    Right to withdraw your consent

Where we require consent to process sensitive information, you have the right to withdraw your consent at any time. Before the 25th May 2018 you can do this by sending an email to support@soma-analytics.com, and after the 25th May 2018, changes can be made directly from the settings area of the app. You have the option to unsubscribe from our emails at anytime,  directly within the email.

If you no longer want us to process your questionnaire,  goals, sessions and sleep to provide the Kelaa service, please let us know by emailing support@soma-analytics.com. As questionnaires, goals and sessions  are fundamental components of Kelaa, we would need to delete all your data and deactivate your account from future use. In the case of sleep, we would simply delete all of your sleep data.

 

5.4.     Right to restrict processing

You have the right to restrict the processing of your personal data where you have a particular reason for wanting the restriction e.g. while you wait for your data to be corrected. Please let us know by emailing support@soma-analytics.com.

 

5.5.      Right to withdraw from our products and services

If you wish to withdraw from our products and services or wish to remove the information which we hold about them, Please let us know by emailing support@soma-analytics.com.

 

5.6.      Right to lodge a complaint

If you have any concerns with the content of this privacy notice, you have the right to lodge a complaint with a relevant supervisory authority.

6.    Links to other websites

 

This Privacy Policy applies only to Soma Analytics. Our applications, website or services may frame or contain references or links to other websites not operated or controlled by us (the “Third Party Services”). The policies and procedures we described here do not apply to the Third Party Services.

 

7.       The use of Soma Analytics products and services by minors

 

An individual must be 16 years of age  to sign up as a registered user of our products and services Individuals under the age of 16 may use our products and services only with the involvement and consent of a parent or legal guardian, under such person’s account and otherwise subject to these Terms.

 

8.       Changes

 

Soma Analytics UG reserves the right to change or update this policy at any time by updating this page. We will also notify users of our product and services via email (registered email address). We encourage individuals to periodically review this page for the latest information on our privacy practices. If the ownership or control of all or part of our Products or their assets changes, we may transfer your information to the new owner.

 

9.       Contact

 

Questions, comments and requests regarding this privacy policy are welcomed and should be addressed to support@soma-analytics.com or mail Unit 6, 104 Clifton Street, London EC2A 4DF, United Kingdom.

 

The name of our Data Protection Officer is Diego Martin-Serrano who can be contacted using the above details.

 

This Privacy Policy is effective and was last updated on May 15th, 2018