What we hold, and what is yours.
Much of what people share with this practice is health information, given at some of the most vulnerable moments of a life. This page sets out plainly what is collected, why, where it rests, who else can see it, and how to get it back or have it removed.
- Version
- 2026-05
- Effective
- Last updated
1. Who is responsible for your information
The controller of the personal information described in this notice is Olvaro AB, a Swedish limited company (aktiebolag), company registration number 556804-4597, registered at Slånstigen 2, 776 36 Hedemora, Sweden, trading as Life By Love.
Two places are involved and they are not the same one. Olvaro AB is the company that answers for your information — the controller, registered in Sweden at the address above. The practice is run from Auckland, New Zealand: that is where your care is delivered from and where the people who read your record work. Section 2 says which law follows from that, and section 10 says what it means for information crossing borders.
You can reach us about anything on this page — including to ask for a copy of your information, to have it corrected or removed, or to withdraw a consent you have given — at [email protected]. That address is also the route for anyone who does not hold an account with us: you do not need to be a client to make a request, and we will answer you on the same terms.
If you would rather write on paper, the registered address above reaches us. Post goes to Sweden while the practice is in New Zealand, so email is the faster route and nothing on this page requires you to write to us. For company matters rather than your own record, the address is [email protected].
Two people hold administrative access to the platform. There is no third party with a login to it.
2. Which law applies
The controller is registered in Sweden, the practice is delivered from Aotearoa New Zealand, and it serves people living in New Zealand, the United Kingdom and the European Economic Area. This notice is therefore written to satisfy both the New Zealand Privacy Act 2020 and its Information Privacy Principles, and the EU General Data Protection Regulation (GDPR) together with the UK GDPR. Where the two differ, we apply whichever gives you the stronger protection, rather than the one that happens to apply to you.
3. The short version
The rest of this notice is precise. This part is true and short.
- Health information you give us is treated as special-category data. Most of it is held in a separate database, apart from everything else and asked to sit in the Oceania region, and when a practitioner opens something of yours there, that is recorded — section 7 says what that log does and does not cover. Part of the practitioner's written record still sits in the main database; section 8 says exactly which part, and what protects it there.
- We do not sell your information, we do not share it with data brokers, and we do not use it — ever — to target advertising.
- You can download your record, or ask us to erase it, from inside your own account, without emailing anyone or waiting for us. Neither is total, and section 11 sets out exactly where each one stops.
- The public website loads analytics that set cookies only if you agree, and declining costs you nothing.
- We never see or hold your card number.
4. What we collect, and when
If you only read the website. We record that a page was viewed, on our own servers, without cookies, against an identifier that rotates daily and that we do not use to build a picture of you. Section 5 says exactly how that identifier is made and why we will not call it anonymous. We also receive a small amount of aggregate traffic and security data from the infrastructure that serves the site, and the booking tool on our public pages contacts its own provider on every visit — both are in section 5.
If you subscribe to the newsletter. Your email address, the exact wording of the consent you were shown, your subscription preferences — and a record of the sign-up itself: the network address and browser you used, the town that address placed you in, the page that referred you, and the campaign link you arrived on, where there was one. We would rather list that than call it nothing else. Section 12 says what happens to it if you unsubscribe, which is less than you might assume.
If you search the site. The words you typed, and — so that we can tell which searches return nothing useful — a record that the search happened, with a coarse location derived from your connection and the kind of device you used. We treat search text on this site as sensitive in its own right: on a perinatal-health site, what somebody searches for is frequently a statement about their health.
If you become a client. In addition to the above: your name and contact details; your date of birth and the profile details you choose to give; the answers you give in intake, consent and assessment forms; notes and summaries written by your practitioner about your sessions; journal entries, reflections, photographs, meals and measurements you record yourself; messages you exchange with the practice; documents relating to your care, including records migrated from the practice's previous client-management system; appointments, including any address a session is held at; and the agreements you have signed.
If you connect a wearable ring. Only if you choose to, and only then: sleep, readiness, temperature-deviation, heart-rate-variability and activity observations, imported from your device account so your practitioner can read them alongside your journal. You can disconnect it at any time, and doing so also withdraws the authorisation held at the device provider.
If you use the peer-support community. What you post, comment on, react to and bookmark, and the direct messages you send. Please treat what you write in a shared space as visible to other members. On a perinatal support community, posts routinely contain health information about the person writing them — that is what the space is for, and it is why community content is held to the same standard as the rest of your record.
If you pay for something. A record of the transaction, what it was for, and whether it has been paid. Your card number never reaches us. Payments are handled entirely by our payment provider, Stripe; only the card brand and last four digits come back.
If you comment on our social-media posts. Your public username and the text of your comment reach a queue so that a person can reply to you. You have no account with us and we did not ask you for this — so if you would rather we did not hold it, write to the address in section 1 and we will remove it.
5. What is collected automatically
Our own page counting. Cookieless and on our own servers. A visit is identified by a short code worked out from your network address, your browser's identifying string and the date. The address itself is never stored, and the code changes every day, so it cannot follow you from one day to the next. Stored beside it: the page, the page that referred you, the country your connection is in, and the broad kind of browser and device.
We are not going to call that anonymous. The recipe has no secret in it, so somebody who already knew your address could work the same code out and confirm a match — and we work it out a second time when you subscribe to the newsletter, so that we can tell which link brought you. So we treat it as information about a person: we hold it in our legitimate interests in knowing which articles are read, and you can object, under section 11. What it is not is something stored on your device, which is why it is not part of the cookie question below and keeps running whatever you choose there.
Infrastructure analytics. The platform that hosts and protects the website collects a basic measure of traffic at the network edge, before the page is built. We treat this as strictly necessary to operating and defending the site and it cannot be switched off — so we tell you about it here rather than asking you a question you cannot act on.
Bot protection. The site search, and the sign-up and sign-in forms, are protected by a challenge service that receives your network address in order to distinguish people from automated abuse. It keeps no record afterwards. Search has been protected this way for some time; the same check was switched on for sign-up and sign-in when this notice was published, so signing up or signing in now sends your network address to that service too. We would rather tell you that than let you find it in a network log.
The booking widget on our public pages. Every page of the public website loads a booking tool from Practice Better, the practice-management system described in section 9. It loads whether or not you ever book, so that provider receives your network address, your browser's identifying string and the page you were on, from an ordinary visit. It is the one automatic collection on the public site that goes to somebody other than us, and it is not currently gated behind a choice you make. Section 10 says where our arrangements with that provider stand.
Video playback. The videos in programmes and articles are delivered by a specialist provider that measures playback quality. Your network address is never sent to it, and nothing is stored on your device for video at all. That was not always true: until this notice was published the provider stored an identifier in your browser that lasted a year, and it did that without asking you. The change that stops it went live with this page.
Analytics cookies — only with your agreement. If you accept them, a third-party analytics service is loaded and will set cookies in your browser and receive your network address. You can decline, and change your mind later, from the cookie banner and from the standing link in the site footer. Declining is exactly as easy as accepting, and nothing on the site stops working if you decline. We do not use analytics to profile what you read for advertising, and no health information is ever sent to an analytics provider. Nothing analytics-related loads before you have been asked: the control that decides refuses every request until there is a published privacy notice to ask you against, so a provider you have not agreed to receives nothing at all.
Email opening and clicks — only with your agreement. Our newsletter and campaign emails can tell us whether a message was opened and which links were clicked, and record the network address and browser that did so, against your subscription. We do this only where you have agreed to it, you can withdraw that agreement at any time from the same place you gave it and without unsubscribing, and withdrawing it does not affect any email you must receive about your care or your account. Messages we are obliged to send you — a booking confirmation, a password reset, an invoice — are not tracked in this way.
Site search and AI answers. When you search, the words you typed are sent to the search and language-model services that produce the results and the short summary above them. The material those services search is our own published articles — not anybody's records.
6. Why we are allowed to hold it
Under the GDPR every use of your information needs a specific lawful basis, and information about health needs a second one on top. Ours are set out below. Under the New Zealand Privacy Act the same processing is carried out under Information Privacy Principles 1-4 — collected for a lawful purpose connected to our function, directly from you, and only what is necessary for it.
| What we do | Our lawful basis | For health information |
|---|---|---|
| Delivering the care you have engaged us for — your clinical record, journals and food diaries, intake and progress forms, session notes, tasks, and the documents and recordings that belong to that care | Performing our contract with you — Art. 6(1)(b) | Art. 9(2)(h), the provision of health or social care under contract with a health professional, subject to the professional duty of secrecy in Art. 9(3) |
| Booking, moving and cancelling appointments, and reminding you about them | Performing our contract with you — Art. 6(1)(b) | Art. 9(2)(h), on the same footing as the care itself: an appointment with a nutrition practitioner is a statement about your health even when the record holds nothing clinical |
| Importing observations from a wearable ring you have connected | Your consent — Art. 6(1)(a) | Your explicit consent — Art. 9(2)(a), recorded when you connect and withdrawn when you disconnect |
| Quoting packages, taking deposits and instalments, issuing invoices, handling refunds, and administering memberships | Performing our contract with you — Art. 6(1)(b); and, for the accounting records a business must keep, legal obligation — Art. 6(1)(c) | Not applicable — no health information is put into payment records |
| Generating, stamping and storing the agreements and consent forms your care is built on | Performing our contract with you — Art. 6(1)(b) | Art. 9(2)(h) while your care is running; and, for the copy retained afterwards, Art. 9(2)(f), the establishment and defence of legal claims |
| Registering and authenticating you, and revoking access when you leave | Performing our contract with you — Art. 6(1)(b) | Art. 9(2)(h), because on this platform an account is an account for care |
| Running the peer-support community | Performing our contract with you — Art. 6(1)(b) | Your explicit consent — Art. 9(2)(a): posting health information about yourself in a shared space is something you choose to do, and you can stop |
| Acting on reports about member content or conduct, and keeping the record of what was decided | Our legitimate interests — Art. 6(1)(f) — in a community that is safe to be in | Not applicable |
| Sending messages you must receive about your account, bookings and care; and sending the newsletter you asked for | Performing our contract with you — Art. 6(1)(b) — for the first; your consent — Art. 6(1)(a) — for the newsletter | Not applicable — care emails are deliberately empty of health information |
| Measuring whether marketing emails were opened and which links were clicked | Your consent — Art. 6(1)(a) | Not applicable |
| Counting page views, and detecting bots and request bursts | Our legitimate interests — Art. 6(1)(f) — in knowing what the site is for and in not being abused | Not applicable |
| Recording which cookie categories you accepted or refused | Legal obligation — Art. 6(1)(c): we are required to be able to demonstrate the consent we relied on | Not applicable |
| Answering your search and summarising the articles it returned | Our legitimate interests — Art. 6(1)(f) — in a site whose search works | You are never asked for health information in order to search, and nothing you search is joined to you: the words are kept in a shared dictionary of search wording with no person attached to it, and the record that a search happened carries no account identifier and no network address. We still treat the text itself as sensitive — see section 4 — which is why it is held that way and cleared on a clock |
| Publishing our own content to social platforms, and reading back how it performed | Our legitimate interests — Art. 6(1)(f) — in reaching the people we exist to help | Not applicable |
| Running the practice: what needs attention, what an administrator changed, and that somebody was contacted | Our legitimate interests — Art. 6(1)(f) — in a practice that is accountable for what it does | Not applicable |
Where we rely on legitimate interests we have weighed them against your interests and rights, and you can object — see section 11. Where we rely on consent, each consent is separate, withdrawing one does not affect the others, and withdrawing is as easy as giving.
7. Health information, and the consent we ask you for
Most of what you tell this practice is information about your health, and at some of the most vulnerable moments of a life. Two things follow.
We hold it under a duty of confidence. The care itself rests on Art. 9(2)(h) — the provision of health or social care — which carries the professional secrecy duty in Art. 9(3). Inside the separate health store, when your practitioner or an administrator opens something of yours, a line is written: who opened it, whose record it was, what they opened, and when. Creating, changing, exporting and erasing it are logged the same way, and so is any grant of access to your message thread — that one is logged before the access is handed over, and refused if it cannot be.
Three limits on that, because "every access is logged" is the easy sentence and it is not the true one. Your own reading of your own record is mostly not logged: the log exists to hold the practice to account, not you. The summary screens the practice works from are not logged either — so a practitioner can see that you journalled, and on which days, without a line being written; what they cannot open without a line being written is what you actually wrote. And the log sits beside the action rather than in front of it: the reading or the change happens first and the line is written after, so if writing it fails the thing has already been done and what follows is an error we have to chase — not a refusal. The access grant above is the one place it genuinely works as a gate, and we would rather tell you where that line falls than let you assume it runs everywhere. The parts of your record kept outside that store — chief among them the session write-up described in section 8 — are not covered by the log at all, and that is the reason we are moving the write-up.
Where a feature needs your explicit consent, we ask for that feature. When you activate your account we ask — Art. 9(2)(a), separately for each, in the wording put in front of you on the screen — for your health information to be held and used for your care, which is the one that is required because without it there is no care to give; and then, each on its own and each refusable, for secure messaging with your practitioner, for a private health journal, for attaching photographs to it including meal and body photographs, and for your practitioner to keep written notes about your sessions. Two more are asked at the moment you reach them rather than at activation: connecting a wearable ring, asked when you connect it, and taking part in the peer-support community, asked when you join. In every case we record the exact wording you were shown, the version of this notice it was shown against, and the date. As we add features that use health information in a new way, each will ask you for its own consent, at the point it is offered — a single consent given once at activation is not treated here as covering everything that comes after it.
You may withdraw any consent at any time, and withdrawing one does not affect the others. One of them you can withdraw yourself: disconnecting a wearable ring withdraws that consent and revokes the authorisation held at the device provider, in a single act. For the others there is no button yet. Write to us at the address in section 1 and a person will do it and tell you what it changed — we would rather say that than describe a control that is not there. Withdrawal does not undo what was lawfully done before it, and for some features it will mean we can no longer provide that part of your care; we will tell you which, at the point you withdraw, rather than afterwards.
We do not use your health information for marketing, we do not use it to target advertising, and we do not disclose it to any insurer, employer or government agency. We disclose it only with your consent, or where the law compels us — and if we are ever compelled, we will tell you unless we are forbidden from doing so.
8. Where your information rests
This matters more here than it usually does, so it is worth being exact.
Health information is held separately. Your journal, your health observations, your session notes, your form responses, your consent records, the documents uploaded about your care, and the log of who has looked at them, live in a dedicated database and file store of their own. They are deliberately kept apart from the rest of the platform, and the separation is architectural rather than a matter of access rules: it is a different store, not the same store with stricter permissions.
Everything else — your account, the newsletter list, community content, bookings, payments and invoices — is held in the main database, hosted in eastern North America.
Where the health store sits is something we ask for, not something we are promised. We ask our hosting provider to place it in the Oceania region, and that is where it runs. But a regional placement of this kind is a request the provider makes a best effort to honour when the store is first created — it is not a commitment it gives us and not something any hosting contract guarantees, so we will not describe it to you as one. The same would be true of any further region we added later. Placement is a real and deliberate choice and we make it; the legal work of moving information between countries is done by the safeguards in section 10, not by the map.
Many of the fields that carry your words are encrypted one by one. Your journal reflections, your messages, the session notes your practitioner keeps in that store, your answers to intake and assessment forms and any correction you ask for on them, the replies you write to tasks, the notes you add when you book, the file names of the documents about your care, the tokens that connect a wearable ring, and the values, units and original records of your health observations are each encrypted before they are written, so that they are unreadable even to somebody holding a copy of the database. Where a field is in that set the protection does not degrade: if the system cannot encrypt it, it refuses to write it at all rather than write it in the clear.
Not every field is in that set, and you should know which are not. Encryption here is applied column by column, not table by table, so on a single row some fields are protected that way and others are not. Some are deliberately left readable because the database has to search, sort or match on them — the kind of measurement taken and the date it was taken, for instance, though not the measurement itself. Others are simply not covered yet, and they are not trivial ones:
- the numbers you log alongside a written journal entry — mood, energy, stress, sleep hours and quality, and the activities and tags you attach — are readable, although the reflection written beside them on the same row is not;
- where a form answer is a file you uploaded, the file's name and where it is stored are readable, although the answers you typed are not;
- the category a document about your care is filed under is readable, although its file name is not — and a category can say as much as a name does;
- the address an in-person session is held at is readable, although the note you wrote when you booked it is not;
- the homework a practitioner sets you is readable, although the reply you write to it is not;
- the record that you connected a wearable ring — which provider, your identifier at that provider, and any error it reported — is readable, although the tokens themselves are encrypted.
Some older rows are also still stored as they were written, before the field they sit in was brought into the scheme, and have not yet been converted; part of the health-observation series is in that state today, waiting on the key-handling work described at the end of this section. Everything named in this paragraph and the list above is protected by the separation and the access logging described above wherever those reach it, by the small number of people who hold access at all, and by the controls in section 10 — but not by encryption of the field itself. Telling you where that line falls is more use to you than calling the whole database encrypted.
The largest thing held outside the health store is your practitioner's write-up, and we would rather name it than round it off. It is not the only one — the list above already names several, and community content, bookings and the programmes you are enrolled on sit in the main database too — but it is the most clinical. The write-up your practitioner makes around a session — the summary, the action items and any preparation materials, the notes kept against your place in a group session, and the feedback recorded about it — is stored in the main database rather than the health store, because it is bound to the appointment it belongs to and the two cannot be read across a boundary. It is treated as health information wherever it sits, and it is covered by the same rights of access and erasure as the rest of your record. What it does not have today is either of the two protections described above: it is stored in the main database without field encryption, and it is not covered by the detailed access log the separate health store keeps. We have decided to encrypt it where it stands and then to move it into the health store — that is a stated intention rather than an idea, work we have committed to and not work we are considering — and it has not been done. Two things have to happen first, and neither is a formality: one of those columns currently holds two different kinds of text under one rule and has to be separated before it can be encrypted, and encrypting records already written means holding a key in a way that can be recovered, which is being arranged. We would rather tell you that this protection is coming than describe it as though it were already here. Until it is, what stands in for it is the rest of this section — the limits on who can reach the platform at all, described in section 1 — together with the controls in section 10.
9. Who else sees it
We use a small number of service providers. Each receives only what it needs, and each is instructed to use it only for us and never for itself; section 10 says where the written agreements behind that instruction stand today. Three of them we name, because of what they hold or what they cost you to be unaware of — Practice Better, which still holds the live clinical record for clients whose care began there; Google Drive, which holds the documents belonging to your care and the backups; and Stripe, which takes your payment. The rest we describe by category rather than listing every company, because that list changes and a stale list is worse than an honest category. A current, named list of our sub-processors is available on request from the address in section 1.
- Platform and security infrastructure — hosts and serves the entire platform, protects it from abuse, renders documents to PDF, and answers the site search and writes the short summary above the results. Every byte on the platform passes through it, including health information.
- Practice Better, the practice-management system the practice runs on — and this is not an archive of old records. The practice has used this platform for years, and for clients seen through it that platform still holds the live record of their care: appointments, the practitioner's clinical notes, completed intake and consent forms, journals, message threads, and attachments that exist nowhere else. If your care began there, that is where your record is being kept today, and it will stay in use for some months yet while care moves across to this platform. It is also the system behind the booking widget on our public website, so it sees the network address of anyone who visits a page carrying that widget, whether or not they book. Section 10 says where our arrangements with that provider stand, and does not dress them up.
- Email delivery — sends our messages. Receives your address and name. The emails we send you about your care are deliberately empty of health information: a notification tells you there is something to read, and you read it in the portal, not in your inbox.
- Document storage, calendar and backup — Google Drive, and the Google calendar service alongside it — holds signed agreements and the documents belonging to your care, provides calendar invitations for bookings (which carry your name and email address), and receives the encrypted off-site backup of both databases.
- Payments — Stripe — processes payments and holds its own record of them, as it is obliged to. Receives your email address and the amount. No health information and no account identifier is ever sent to it.
- Wearable device provider — only if you connect a ring, and only then. It remains the controller of your device account, which is yours and not ours to delete.
- Video delivery and playback measurement — for the videos in programmes and articles. It receives an opaque viewing-session identifier and the browser details that travel with any request. Your network address is not sent to it at all — not in full and not shortened. Section 5 says what it stores in your browser.
- Code and content hosting — receives the name and email of the administrator who published a change. No client's information reaches it.
- Your browser's push service — delivers push notifications if you turn them on. Payloads are deliberately content-free: what is disclosed is that a notification happened, not what it said.
- Website analytics — only if you accept analytics cookies, and only on the part of the site that carries them. If you have not accepted, no analytics provider receives anything from you at all.
- Social platforms — receive the posts we publish, which we write. Nothing from your client record is sent to them: no health information, no journal, no appointment, no account identifier. What movement there is runs the other way — when somebody comments publicly on one of our posts, or writes a public post we are following, the platform passes that text and the public username to us, and section 4 says what happens to it then.
We do not sell your information, we do not share it with data brokers, and we do not permit any of these providers to use it for their own purposes.
10. Sending information overseas
Several of the providers in section 9 are in the United States, and your health records are held in the Oceania region while you may be in Europe or the United Kingdom. Moving personal information out of the EEA or the UK requires a safeguard under Chapter V of the GDPR, and moving it out of New Zealand requires comparable protection under Information Privacy Principle 12.
Most of these providers publish a standard data processing agreement built on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum for transfers from the United Kingdom. Putting those agreements in place is work we are doing now, and not all of them are in place yet. The list below says which, so that you are not left to assume:
- Document storage, calendar and backup — Google Drive — agreement being accepted now.
- Email delivery — agreement being accepted now.
- Code and content hosting — agreement being accepted now.
- Platform and security infrastructure — agreement published by the provider and not yet accepted; next after the three above.
- Payments — Stripe — agreement published by the provider and not yet accepted; next after the three above.
- Video delivery and playback measurement — agreement published by the provider and not yet accepted.
- The practice-management system — Practice Better — no agreement recorded with us, and the provider is where the live clinical record of some clients still sits. It is the most significant item on this list and we are not going to describe it as anything smaller.
- Social platforms — no agreement. What is still being decided is whether one is owed at all: a platform publishing posts we wrote is acting for itself rather than on our instructions.
- Your browser's push service — no agreement, and none to have. We hold no account with whichever service your browser chooses, and what we hand it carries nothing to read.
- The wearable device provider — in Finland, inside the EEA. No transfer safeguard is needed here and none is claimed.
Until an agreement is in place, what stands in for it is the protection described in section 8 — the separation, the field-level encryption and the access logging — together with our own control over what each provider may do: every one of them receives only what it needs, is instructed to process it only for us, and is not permitted to use it for its own purposes. That is a real protection. It is not the same thing as a Chapter V safeguard and we are not offering it as one, which is why the list above is written plainly rather than summarised away. You can ask us at any time which of these agreements are in place, and we will tell you which, and from what date, at the address in section 1.
The off-site backup deserves its own sentence, because it is the largest single movement of information the practice makes: it carries a complete copy of both databases — including the health database — to Google Drive, in the United States, on a schedule. It is encrypted before it leaves us, with a key that provider does not hold, so what arrives is a file it cannot read. Its transfer agreement is one of those being accepted now, and until it is accepted the encryption is what protects the copy.
11. Your rights
You have the right to see what we hold about you, to correct it if it is wrong, to erase it, to take it with you in a machine-readable form, to restrict what we do with it, to object to processing we carry out on the basis of our legitimate interests, and to withdraw a consent at any time without giving a reason. Under the New Zealand Privacy Act you have the corresponding rights of access and correction under Information Privacy Principles 6 and 7.
Two of these you can exercise yourself, right now, without asking anybody. If you have a portal account, open Settings → Privacy:
- Download your data gives you a machine-readable copy of your record — journal entries, the messages you sent, health observations, form responses, consents and the rest. Three things it is not, and we would rather say them than let you find out. It hands you records, not files: a document, a progress photo or a session recording appears as a reference to the file, and the file itself is fetched from the portal in the usual way. It leaves out your practitioner's own write-up and assessments of you, on the footing that what you can take with you is what you provided — that is a narrower thing than your right to see what we hold, so if you want those, ask us under section 1 and we will answer that separately. And it reaches what is in our databases, not the smaller number of places information also rests outside them. The copy states its own gaps: every download carries a machine-readable list of what it did not include, so you are not left to guess which of these applied to you.
- Delete your account erases your record and then tells you what it could not
reach. Some things are kept on purpose. It is not a short list, so here are the groups rather than
a number:
- records the law requires us to keep — the financial record of what you bought and paid, and the proof of the consents and agreements you gave and when;
- the log of who looked at your health information, which is a protection for you;
- other people's words. A message somebody sent to you, a reply another member wrote under your post, and your practitioner's account of a session you shared with other clients all stay. They are that person's record, written in their words, and removing you from a paragraph would destroy somebody else's. They can name you and describe your situation;
- material the practice wrote for everybody, and figures you contributed to that carry no name;
- copies held by the organisations in section 9 — which we ask to delete, and in some cases cannot compel.
If your care began on Practice Better, the practice-management system described in section 9, erasing your account here does not erase your record there. That system still holds the live clinical record for the clients seen through it, and we do not yet have an established route to have that record deleted on request. We are not prepared to tell you that you have been erased while part of your record sits somewhere we have not reached: if you ask us to erase you, we will say plainly what remains there and what we have asked for.
If you would rather ask a person, or you do not have an account, write to the address in section 1. We will answer within one month, and if a request is genuinely complex we will tell you inside that month rather than at the end of it. There is no charge.
Correcting something is a request you make to us rather than a button. For an answer you gave on one of our forms you can raise a correction in the portal, and your practitioner either applies it or tells you why not. For anything else — and for restricting or objecting to what we do — write to us and a person will deal with it.
Withdrawing consent does not undo what was lawfully done beforehand, and it may mean we can no longer provide care that depends on the information you have withdrawn.
12. How long we keep it
The table below is the honest state of this, including the parts still being settled. Where a period has not been fixed we say so, rather than implying one.
One thing to read the table with. Three of the periods below are settled as policy: the ten years for your clinical record, the seven years for accounting records, and the thirteen months for email opens and clicks. Only the last of those three runs on an automatic clock. The first two are how long the practice keeps the record, decided and written down, and there is no nightly job that removes them at the end of it. The other rows that carry a number are working figures — they are set in the system and the deletions really run on them nightly, but they have not yet been ratified, so a number there may change once it is. Where a row says not yet fixed, there is no number and nothing is deleting on a clock; that is a gap we are showing you rather than a period we are hiding.
| What | How long | Why |
|---|---|---|
| Your clinical record — journal, forms, session notes, health observations, documents | Kept while you are a client, and for ten years after your last session with us | Ten years is the general limitation period in Swedish law — Preskriptionslagen — which is how long a consumer may bring a claim against a business. The record is kept for that long for two reasons: so that it is still here if you come back to us after a gap, and so that we can answer a claim if one is ever made. It is not used for any other purpose during that time — not for marketing, not for research, and not to build a picture of you |
| The record of the consents you gave | Kept as evidence of what you agreed to and when, including after erasure | It is the proof of the basis we relied on; deleting it would remove your evidence as well as ours |
| The log of who looked at your health record | Kept, and it survives erasure of the records it describes | It is a protection for you. It is not free of health information: where you asked for an answer about your health to be corrected, your own reason for asking can sit in it |
| Invoices, payments and accounting records | Seven years, and not deleted on request | The Swedish Accounting Act — Bokföringslagen — requires a business to keep its accounting records, invoices and payment records among them, for seven years. That is a separate and shorter period than the one for your clinical record above, and the two are not run together. It is also the one thing here we cannot delete on request, whatever else we erase for you |
| Signed agreements, and the record of which version you accepted | The record of what you accepted and when is kept, including after erasure. The agreement itself is deleted with the rest of your record if you ask us to erase you | Section 16 promises we can always tell you which version of this notice applied to you when you signed; that promise is what the acceptance record is for. No separate period is set for it |
| Email opens and clicks | 13 months (395 days), then deleted automatically | Long enough for a year-on-year comparison and a month of overlap; not long enough to build a history of you. This is the one settled period here that a nightly job actually enforces |
| The engagement summary worked out from those opens and clicks | Not yet fixed — and it outlives the opens and clicks it came from | Deleting the underlying events does not delete this summary, which keeps dates of its own. Setting a period for it is part of the same decision as the other rows marked not yet fixed |
| Website page views and system events | 13 months (395 days), then deleted automatically | The same purpose, so the same period |
| Search text and search events | In our own database the search words are blanked, and the event rows deleted, on a fixed clock. Two other places the same words pass through are not yet on that clock — the file archive the events are written to, and the log kept by the service that answers the search | The clock that runs is long enough to tune relevance and find searches that return nothing, and the aggregate count survives the text that makes it sensitive. The two stores without one are a known gap and are being brought into it; we would rather name them than let the first sentence stand for all three |
| Bot and burst detection counters | 30 days | A row is useless the moment its one-minute window closes; this is a storage cap, not a judgement |
| Your cookie choice | Three years | It must outlive the consent it evidences by long enough to answer a question about it. Republishing this notice re-asks you in any case |
| Your newsletter subscription, and what stays after you unsubscribe | Kept. No period is set, and unsubscribing does not delete anything | Unsubscribing marks the subscription as ended rather than removing it, precisely so that we do not email you again by accident. What stays is more than your address: the wording you consented to, the dates, and what was recorded when you signed up — the network address and browser you signed up from, the town that address placed you in, the page that referred you, and the campaign link you arrived on. Ask us to erase your record and those are cleared; unsubscribing on its own does not clear them |
| Operational notices and moderation records naming you | Not yet fixed. No period is set for either | These are the record of a decision taken about member content, and the practice's own alerts about its systems. Both need a period, both hold identifying detail — a moderation record holds an administrator's network address as well as the reason — and neither has one yet. We would rather show you the gap than print a number nothing is enforcing |
| Public comments captured from social media | Not yet fixed. Removed on request | A period is being set. In the meantime, ask us and we will remove it |
| Encrypted off-site backups | Not yet fixed, and longer than anything else here. Old archives are not being deleted today | An erasure cannot be written into an encrypted archive without destroying the integrity that makes it a backup. Our written answer is that the erasure is recorded and re-applied by hand before any restored copy is used, and that old archives are removed once they are no longer needed. The first is a procedure a person follows, not something the system does; the second is not yet happening at all — the account that writes the backups deliberately cannot delete them, so removing an old one is a manual act on a schedule nobody keeps yet. This is the weakest row in this table and we would rather you read it here |
13. Automated decisions
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you. No algorithm here decides whether you are accepted as a client, what you are charged, what care you are offered, or whether your account is closed. Those are decisions a person makes.
Some things here are automated, and none of them is a decision of that kind. Our site search uses a language model to summarise the published articles it found — the material summarised is our own writing, not anybody's record. Your journal can work out its own patterns from the entries you have written — how your mood, sleep and energy have moved over recent weeks — and show them back to you; they are drawn from your own words and numbers, they are shown to you, and by themselves they decide nothing. And which newsletter you receive follows from the lists you subscribed to and from a person choosing what to send: we do not score how you engage with our email and send you something different because of the score.
One automatic rule can shut you out of your own account, and you should know about it before it happens. If a message we send is rejected outright by your mail provider as undeliverable — the mailbox does not exist — our system stops sending to that address. Every other reason for stopping still lets through the messages you need in order to reach your account. This one does not: it also stops verification, activation and password-reset email. Nothing in the site will lift it, and no administrator can override it from the screen they use. If that has happened to you, write to us from another address at the address in section 1 and we will clear it by hand.
14. Children
This practice supports adults. Accounts are not offered to anybody under 16 and we do not knowingly collect information about children.
Where you tell us about your pregnancy, your baby or your family as part of your own care, that information forms part of your record and is protected in exactly the same way.
15. If you think we have got this wrong
Please tell us first. Write to the address in section 1. We would rather know, and we can usually fix it faster than anybody else can.
If you are not satisfied with our answer, you have the right to complain to a data protection regulator, and you can do so without going through us:
- In New Zealand — the Office of the Privacy Commissioner, privacy.org.nz.
- In the European Economic Area — the supervisory authority of the country you live or work in, or where you believe the problem occurred. Each Member State's authority is competent to hear your complaint, and the European Data Protection Board publishes the current list at edpb.europa.eu.
- In the United Kingdom — the Information Commissioner's Office, ico.org.uk.
16. Changes to this notice
Every version of this notice carries a version identifier and an effective date, both shown at the top of this page. When we make a material change we will tell you before it takes effect; where the change affects care you are already receiving, we will ask you again rather than assume. Republishing this notice also resets the cookie choice recorded against the previous version, so you will be asked once more.
We keep previous versions, and we will give you one on request — write to the address in section 1 and say which version or which date you want. The version named in any agreement you have signed is the version that was in force when you signed it.
If anything here is unclear, or you want to know exactly what is held about you before deciding whether to ask for it, you are welcome to write. A question about your own information is never a nuisance.