The purpose of this Privacy Notice (“Notice”) is to describe how mama health technologies GmbH (“mama health technologies” “we”, “us”, “our”) collects, uses and shares information about you through our mama health patient app (“mama health” “platform” “app”) in accordance with applicable data protection and privacy laws.
Please read this Notice carefully to understand what we do. If you do not understand any aspects of this Notice please feel free to contact us at the address indicated at the end of this Notice.
"mama health patient app", “mama health Platform”, “Platform” or “Service” is an AI educational tool that collects and analyses information from users suffering from specific medical conditions, in order to provide personalized answers and educational content. The answers provided by the tool are based on medically validated sources and the experience of other users. The use of the platform is strictly educational, and therefore not intended to be used for medical purposes.
“User”, “Data Subject” refers to the identifiable natural person using the mama health patient app to whom the Personal Data and Sensitive Data refers.
“Personal Data” or “Personal Information” refers to any information that directly, indirectly, or in connection with other information allows for the identification of the User .
“Pseudonymized Data” refers to Personal Data that can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
"Anonymous Data" refers to information which does not relate to an identified or identifiable natural person.
"Anonymized Data" refers to user data rendered anonymous in such a manner that the recipient is not reasonably able to identify the data subject, taking into account all means reasonably likely to be available to the recipient.
“Applicable Privacy Laws” refers to all applicable laws and regulations, including laws and binding regulations of the European Union and their member states, Switzerland, the United Kingdom, the United States of America and Canada that apply to the Processing of Personal Data by mama health technologies GmbH when providing the mama health patient app to users in different countries.
“Processing” refers to any operation or set of operations which is performed on Personal Data.
“Controller” refers to the person or legal entity responsible for determining the purpose and means of the Processing of your Personal Data.
“Processor” refers to an individual or legal entity that processes Personal Data on behalf of a Controller.
“Sensitive Personal Information”, “Sensitive Data” or “Special categories of Personal Data” refers to any Personal Information that reveals information considered sensitive according to the Applicable Privacy Law (e.g.:data concerning health).
We collect and use your information listed in “INFORMATION WE COLLECT” and only for the purposes listed in this Privacy Notice.
Personal Data is collected and processed only in accordance with the relevant legal basis as mandated by the Applicable Privacy Laws.
This Notice details the processing of personal information gathered through your use of our Platform.
This Notice does not cover information collected outside of the mama health patient app, including data from other services provided by mama health technologies GmbH, such as our website and any third party services.
This Notice does not apply to the processing of anonymous data, however it covers the process of anonymization of personal data.
As set forth in the Terms of Use, you must be at least sixteen (16) years old to use or access the Platform. If you are under the age of 16, please do not attempt to register with us at this Platform or provide any personal information about yourself to us. If we learn that we have collected personal information from a child under the age of 16, we will promptly delete that information. If you believe we might have any information from a child under the age of 16, please Contact Us at privacy@mamahealth.com
The Data Controller for any Personal Information processed in connection with our Platform is:
mama health technologies GmbH
August-Bebel-Straße 88, 14482 Potsdam
mama health technologies GmbH will process the following categories of personal data of users:
| Categories of personal data | Special category of data | Examples of data processed |
|---|---|---|
| Common data - Physical characteristics | No | gender |
| year of birth | ||
| Common data - Other Personal | No | appointments booked |
| feedback given | ||
| feedback rating (stars) | ||
| flagged issues/inquiries | ||
| Common data - Home&Family | No | country of residence and postal code |
| Common data - Usage data | No | access token |
| app settings | ||
| cookies | ||
| device information | ||
| language | ||
| usage logs, crashes, errors | ||
| Identifiers - Personal Information | No | e-mail address |
| name | ||
| voice (if users choose to record their input via microphone) | ||
| Identifiers - Online | No | IP address |
| Health information | Yes | chat content (patient's history - kind of anamnesis guided by AI chatbot) |
| chat content ( Questions section - Q&A based patients shared experiences) | ||
| current symptoms - type of disease - symptom's impact on daily life (scale value) - current treatments - official diagnosis (yes/no) - challenges in managing disease | ||
| dashboards (statistics about patient's condition) | ||
| tailored report based on the health information shared by users | ||
| uploaded medical documentation (images or files) | ||
| voice (Chat content - patient's history - kind of anamnesis guided by AI chatbot) |
Personal Information is collected:
We process your Personal Information in order to provide you with our Platform and its main functionalities. Our processing activities include the following:
Your Personal Information will only be processed if we have a legitimate ground to do so. For a more detailed description of each purpose and processing activity and the connected legal grounds, please consult the table available under "1. Processing under the EU's GDPR - Why do we process your data".
We may process your personal information because:
We need to provide you with the requested Service and honor our contractual obligations with you;
You have given us your consent to do so. We will only process your sensitive data on the basis of your consent;
The processing is in our legitimate interest and it is not overridden by your rights. We may have a legitimate interest in ensuring platform security (prevent unauthorized access, fraud and detect any anomalies), as well as in collecting feedback and inquiries regarding the App in order to improve our Service, and to send you communications with general information about the Platform;
To comply with applicable laws and regulations we may be subject to.
We may share your Personal Information with our employees and trusted business partners when necessary to fulfill the purposes outlined in this Privacy Notice.
Recipients may include, for example:
Third-party IT service providers who help operate and host our Platform and Services;
Third parties involved in complying with legal obligations, or establishing, exercising, or defending rights or claims (such as courts, regulators, law enforcement, government authorities, attorneys, and consultants);
Third party business partners with whom we share anonymized and aggregated insights resulting from the anonymization of the data we collect when you use our Platform. These third parties will not have access to your personal data but only to the aggregated and anonymized information derived from your data.
These third parties will have access to your personal information to perform their services. When this occurs, we implement reasonable contractual and technical safeguards to limit their use of the information solely for the purpose of providing the contracted service. When our service providers act as Data Processors, we will ensure that they only process your personal data under appropriate confidentiality and security obligations and in accordance with our instructions and with this Notice.
Note that the recipients of your Personal Data may be located outside of your country of residence. Further details on international transfers of Personal Data are available in the dedicated section of the Privacy Notice applicable to you.
We maintain appropriate security safeguards to protect your Personal Information and only retain it for a limited period of time.
The security of your Personal Information is important and we are committed to protecting the information we collect. We maintain reasonable administrative, technical and physical safeguards designed to protect the Personal Information you provide or we collect against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure or use.
In the event of a breach of our security safeguards, we will assess the extent of harm (if any) to individuals, and comply with reporting and notification obligations in accordance with the applicable law.
We also take measures to delete your Personal Information or keep it in a form that does not permit identifying you when this information is no longer necessary for the purposes for which we process it, unless we are required by law to keep this information for a longer period. When determining the retention period, we take into account various criteria, such as the nature and length of our relationship with you, possible re-enrolment with our products or services, the impact on the services we provide to you if we delete some information from or about you, mandatory retention periods provided by law and the statute of limitations.
If you have any questions about personal information we have about you or need to update your information, or wish to unsubscribe, you can contact us at the contact details provided in the Contact Us section at the end of this Notice.
For more detailed information on your data protection rights and how to exercise them please consult the dedicated section that applies to your country of residence.
You can contact us at any time at the following email address: privacy@mamahealth.com
Alternatively, you can also reach us per mail at: privacy@mamahealth.com
mama health technologies GmbH
August-Bebel-Straße 88, 14482 Potsdam
mama health patient app may contain links to websites operated by third parties. We are not responsible and have no control over how they operate or how they process data. We encourage you to read their privacy notices before using those websites.
Cookies are small text files stored on users' devices by the server of the website they are visiting and contain information about the user's navigation that can be read by the same server in subsequent browsing sessions. Cookies do not harm the device and enable a better browsing experience.
Our solution uses cookies. To know more please consult our Cookie Policy.
This Notice may be subject to changes and reviews.
All personal data processed is subject to this Privacy Notice effective at the time it was collected.
Any changes to this Notice will be posted on this page and, if necessary, notified to you.
We encourage you to consult our Notice periodically so that you are always informed about how we process your personal data.
This Privacy Notice was last updated on 27/05/2026
This section applies and provides you with further information if you are located within the European Economic Area in accordance with the EU General Data Protection Regulation 679/2016 ("GDPR").
Only for the purposes mentioned under section “why do we process your data” the Data Controller is:
mama health technologies GmbH
August-Bebel-Straße 88, 14482 Potsdam
If you have any questions related to how we process your personal data you can contact us at any time by sending an email to: privacy@mamahealth.com
To further strengthen your data protection, we've appointed a dedicated Data Protection Officer (DPO), who you can contact if you have any questions about how your personal data is processed, or if you believe your privacy rights may have been infringed.
You can contact our DPO by sending an email to: dpo@mamahealth.com
We will process your personal data for the following purposes:
| Purpose | Activities | Legal basis (art. 6 and art. 9) | Provision of personal data | Data Categories |
|---|---|---|---|---|
| Analysing user behaviour |
Analysing user behaviour
We use cookies and other tracking technologies to analyse and understand how users interact with our app. Please refer to our Cookie Policy linked at the bottom of this Privacy Notice for detailed information on the cookies we use. |
|
These data will only be processed if you consented to the setting of cookies in the cookie banner. You can withdraw your consent at any time. Withdrawing your consent does not affect the lawfulness of the processing prior to the withdrawal. | Common data - Usage data |
| Identifiers - Online | ||||
| Anonymization and Aggregation of Patient Data |
Identifiers removal and aggregation of Patient Data to generate Insights to be used in the Patient App
Patient-provided data is aggregated and processed to remove identifiers in order to create dashboards showing trends in patient pathways, common symptoms, and treatment journeys, to be used within the patient app. Identifiable information is removed, and relevant medical details (e.g. symptoms, medications, side effects) are extracted from patient narratives. Any residual identifiers in chat data are also deleted. An aggregation threshold is applied. Uploaded documents are parsed for relevant text, which may be included in the analysis. Original medical documents (e.g., doctor reports) are retained in the database, but not altered. Data within the patient interface is not processed for this purpose and is only used to support patient follow-up queries. |
|
These data will only be processed if you give your explicit consent. You can withdraw your consent at any time without affecting the lawfulness of the processing prior to the withdrawal of consent. | Common data - Physical characteristics |
| Common data - Home&Family | ||||
| Health information | ||||
|
Identifiers removal and aggregation of Patient Data to generate insights shared with third parties
Patient-provided data is aggregated and processed to remove identifiers in order to generate insights and dashboards showing trends in patient pathways, common symptoms, and treatment journeys for third party healthcare stakeholders. Identifiable information is removed, and relevant medical details (e.g. symptoms, medications, side effects) are extracted from patient narratives. Any residual identifiers in chat data are also deleted. An aggregation threshold is applied. Uploaded documents are parsed for relevant text, which may be included in the analysis. Original medical documents (e.g., doctor reports) are retained in the database, but not altered. Data within the patient interface is not processed for this purpose and is only used to support patient follow-up queries. Our Third party business partners access only anonymized, statistical views of the data. Additionally, they can interact with an AI tool to explore these insights without accessing raw or identifiable data. |
|
These data will only be processed if you give your explicit consent. You can withdraw your consent at any time without affecting the lawfulness of the processing prior to the withdrawal of consent. | Common data - Physical characteristics | |
| Common data - Home&Family | ||||
| Health information | ||||
|
Identifiers removal and aggregation of Patient Data to generate insights for scientific research
Patient-provided data is aggregated and processed to remove identifiers in order to generate insights for scientific research and publication (e.g. in peer-reviewed journals and preprint repositories). Identifiable information is removed, and relevant medical details (e.g. symptoms, medications, side effects) are extracted from patient narratives. Any residual identifiers in chat data are also deleted. An aggregation threshold is applied. Uploaded documents are parsed for relevant text, which may be included in the analysis. Original medical documents (e.g., doctor reports) are retained in the database, but not altered. Data within the patient interface is not processed for this purpose and is only used to support patient follow-up queries. |
|
These data will only be processed if you give your explicit consent. You can withdraw your consent at any time without affecting the lawfulness of the processing prior to the withdrawal of consent. | Common data - Physical characteristics | |
| Common data - Home&Family | ||||
| Health information | ||||
| Communicating with users |
Sending of communications
We may send you e-mail from time to time with generic information and suggestions to help you use our Platform and its functionalities, or inform you about any updates or new features. |
|
Your data is processed automatically when you successfully create an account. You can object to the processing at any time and unsubscribe from these communications. | Common data - Usage data |
| Identifiers - Personal Information | ||||
| Identifiers - Online | ||||
| Ensure platform security |
Collection of browsing and traffic data to ensure system security
We automatically collect browsing and usage data in order to prevent unauthorised access, unlawful use or fraud and detect anomalies on our Platform. |
|
We collect these data automatically when you use our app. The processing of this data is in our legitimate interest of ensuring system security and preventing unlawful or unauthorized use. You may object to the processing at any time. | Common data - Usage data |
| Identifiers - Online | ||||
| Processing users' feedback and inquiries about the service |
Processing users' feedback and inquiries
Users can leave a star-rating or a feedback message in the app to let mama health know their opinion on the app. Users can also choose to contact us via e-mail for any inquiries or they can book an appointment via Calendly with one of our employees to discuss any aspects of the app. Users are advised to not share any sensitive information for this purpose. We will process users' feedback to address any existing issues and improve our service. |
|
Your data will only be processed if you decide to leave a feedback or get in touch with us. The processing is based on our legitimate interest in addressing users’ inquiries comprehensively and to collect feedback about the app for the improvement, functionality and user-friendliness of the app. In any case you can object to the processing at any time. | Common data - Other Personal |
| Identifiers - Personal Information | ||||
| Provision of the service to patients |
Account creation and management
In order to be able to use our platform, users need to create a profile that reflects their condition. To complete registration, users need to provide their name and email address, country of residence and year of birth and also health related information including their current symptoms, treatments, diagnosis, health insurance and difficulties in managing their health condition. Once an account has been created, users can log in again by providing their e-mail address and the access token they receive per e-mail. Users can also log in via Google/Apple Sign-in. |
|
The provision of your data is necessary in order to access and use our platform. For special categories of data (health information), we rely on your explicit consent to process this data. You can withdraw your consent at any time without affecting the lawfulness of the processing until that point. In that case, however, we will no longer be able to provide you with the app and you will be redirected to delete your account. | Common data - Physical characteristics |
| Common data - Home&Family | ||||
| Common data - Usage data | ||||
| Identifiers - Personal Information | ||||
| Health information | ||||
|
Chat content collection, storage and further elaboration
Through an AI chatbot, patients are guided to share their symptom story, much like a doctor's anamnesis. This conversational interaction allows patients to provide relevant information, including through voice input and document uploads (e.g., doctor's letters). Once the anamnesis is completed, the shared information personalizes the platform's Q&A functionality, enabling patients to ask questions that are informed by their unique health narrative. All answers provided will include sources. Users can also contact us at support@mamahealth.com if they encounter any issues with these functions and we will process their inquiries as soon as possible. |
|
The provision of your data is necessary in order to use the chatbot function of the platform. For special categories of data (health information), we rely on your explicit consent to process this data, you can withdraw your consent at any time without affecting the lawfulness of the processing until that point. In that case, however, we will no longer be able to provide you with the app and you will be redirected to delete your account. | Common data - Other Personal | |
| Identifiers - Personal Information | ||||
| Identifiers - Online | ||||
| Health information | ||||
|
Dashboard creation
Once the anamnesis is complete, the app generates a dashboard. The "analysis" dashboard provides users with an overview of key statistics related to their condition with personalized insights based on the available information. |
|
The provision of your data is necessary in order to use this function and your data is collected and analyzed automatically by us. For special categories of data (health information), we rely on your explicit consent for processing. You can withdraw your consent at any time without affecting the lawfulness of the processing until that point. In that case, however, we will no longer be able to provide you with the app and you will be redirected to delete your account. | Common data - Physical characteristics | |
| Common data - Usage data | ||||
| Identifiers - Personal Information | ||||
| Health information | ||||
|
Detailed report generation
At any point, users can access the "Report" section of the app and download their tailored report generated by AI based on the data provided to the chatbot as well as the information provided during onboarding. Users can update their information with every new entry in the chatbot and download the updated PDF. Users are advised that the Report is generated using AI models that elaborate the information provided and these may contain errors and are only provided for informational purposes. |
|
The provision of your data is necessary in order to use this function and your data is collected and analyzed automatically by us. For special categories of data (health information), we rely on your explicit consent for processing. You can withdraw your consent at any time without affecting the lawfulness of the processing until that point. In that case, however, we will no longer be able to provide you with the app and you will be redirected to delete your account. | Health information |
Your personal data will be processed primarily within the European Union and the European Economic Area. Should we transfer data to service providers or other third parties outside the EU/EEA, such data transfers will take place only to third countries with an Adequacy Decision in place approved by the European Commission or, in case of no Adequacy Decision, based on Standard Contractual Clauses provided by the European Commission and additional security measures to ensure data security.
We will retain your personal data only as long as necessary to fulfill the purposes for which we collected it, including purposes related to fulfilling legal, tax or accounting obligations.
A longer retention period may be required in the event of a legal complaint or in the event of disputes related to our existing contractual relationships.
To determine the retention period of personal data, we take into account:
If personal data is no longer necessary for the purposes or legitimate interests pursued by us, and no other legal basis applies, we will delete your data.
We inform you that you have the right to:
The exercise of rights is not subject to any formal constraints and is free of charge.
You can exercise your data protection rights and contact us with any data privacy related concerns and requests by sending an email at privacy@mamahealth.com.
You also have the right to lodge a request or complaint with the competent data protection authority.
A list and contact details of local data protection authorities is available here.
This section applies and provides you with further information if you are located within the United Kingdom under the Data Protection Act 2018 and/or the UK GDPR (meaning Regulation (EU) 2016/679 of the European Parliament and of the Council of 27th April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018)
mama health technologies GmbH
August-Bebel-Straße 88, 14482 Potsdam
To further strengthen your data protection, we've appointed a dedicated Data Protection Officer (DPO), who you can contact if you have any questions about how your personal data is processed, or if you believe your privacy rights may have been infringed.
You can contact our DPO by sending an email to: dpo@mamahealth.com
As we do not have a physical establishment in the UK, we have appointed Data Protection Representative Limited (trading as DataRep) as our Representative in the UK for the purposes of Article 27 UK GDPR.
Please note when mailing inquiries, it is essential that you mark your letters for “DataRep” and not “mama health technologies GmbH” for it to reach us.
We will process your personal data for the following purposes:
| Purpose | Activities | Legal basis (art. 6 and art. 9) | Provision of personal data | Data Categories |
|---|---|---|---|---|
| Analysing user behaviour |
Analysing user behaviour
We use cookies and other tracking technologies to analyse and understand how users interact with our app. Please refer to our Cookie Policy linked at the bottom of this Privacy Notice for detailed information on the cookies we use. |
|
These data will only be processed if you consented to the setting of cookies in the cookie banner. You can withdraw your consent at any time. Withdrawing your consent does not affect the lawfulness of the processing prior to the withdrawal. | Common data - Usage data |
| Identifiers - Online | ||||
| Anonymization and Aggregation of Patient Data |
Identifiers removal and aggregation of Patient Data to generate Insights to be used in the Patient App
Patient-provided data is aggregated and processed to remove identifiers in order to create dashboards showing trends in patient pathways, common symptoms, and treatment journeys, to be used within the patient app. Identifiable information is removed, and relevant medical details (e.g. symptoms, medications, side effects) are extracted from patient narratives. Any residual identifiers in chat data are also deleted. An aggregation threshold is applied. Uploaded documents are parsed for relevant text, which may be included in the analysis. Original medical documents (e.g., doctor reports) are retained in the database, but not altered. Data within the patient interface is not processed for this purpose and is only used to support patient follow-up queries. |
|
These data will only be processed if you give your explicit consent. You can withdraw your consent at any time without affecting the lawfulness of the processing prior to the withdrawal of consent. | Common data - Physical characteristics |
| Common data - Home&Family | ||||
| Health information | ||||
|
Identifiers removal and aggregation of Patient Data to generate insights shared with third parties
Patient-provided data is aggregated and processed to remove identifiers in order to generate insights and dashboards showing trends in patient pathways, common symptoms, and treatment journeys for third party healthcare stakeholders. Identifiable information is removed, and relevant medical details (e.g. symptoms, medications, side effects) are extracted from patient narratives. Any residual identifiers in chat data are also deleted. An aggregation threshold is applied. Uploaded documents are parsed for relevant text, which may be included in the analysis. Original medical documents (e.g., doctor reports) are retained in the database, but not altered. Data within the patient interface is not processed for this purpose and is only used to support patient follow-up queries. Our Third party business partners access only anonymized, statistical views of the data. Additionally, they can interact with an AI tool to explore these insights without accessing raw or identifiable data. |
|
These data will only be processed if you give your explicit consent. You can withdraw your consent at any time without affecting the lawfulness of the processing prior to the withdrawal of consent. | Common data - Physical characteristics | |
| Common data - Home&Family | ||||
| Health information | ||||
|
Identifiers removal and aggregation of Patient Data to generate insights for scientific research
Patient-provided data is aggregated and processed to remove identifiers in order to generate insights for scientific research and publication (e.g. in peer-reviewed journals and preprint repositories). Identifiable information is removed, and relevant medical details (e.g. symptoms, medications, side effects) are extracted from patient narratives. Any residual identifiers in chat data are also deleted. An aggregation threshold is applied. Uploaded documents are parsed for relevant text, which may be included in the analysis. Original medical documents (e.g., doctor reports) are retained in the database, but not altered. Data within the patient interface is not processed for this purpose and is only used to support patient follow-up queries. |
|
These data will only be processed if you give your explicit consent. You can withdraw your consent at any time without affecting the lawfulness of the processing prior to the withdrawal of consent. | Common data - Physical characteristics | |
| Common data - Home&Family | ||||
| Health information | ||||
| Communicating with users |
Sending of communications
We may send you e-mail from time to time with generic information and suggestions to help you use our Platform and its functionalities, or inform you about any updates or new features. |
|
Your data is processed automatically when you successfully create an account. You can object to the processing at any time and unsubscribe from these communications. | Common data - Usage data |
| Identifiers - Personal Information | ||||
| Identifiers - Online | ||||
| Ensure platform security |
Collection of browsing and traffic data to ensure system security
We automatically collect browsing and usage data in order to prevent unauthorised access, unlawful use or fraud and detect anomalies on our Platform. |
|
We collect these data automatically when you use our app. The processing of this data is in our legitimate interest of ensuring system security and preventing unlawful or unauthorized use. You may object to the processing at any time. | Common data - Usage data |
| Identifiers - Online | ||||
| Processing users' feedback and inquiries about the service |
Processing users' feedback and inquiries
Users can leave a star-rating or a feedback message in the app to let mama health know their opinion on the app. Users can also choose to contact us via e-mail for any inquiries or they can book an appointment via Calendly with one of our employees to discuss any aspects of the app. Users are advised to not share any sensitive information for this purpose. We will process users' feedback to address any existing issues and improve our service. |
|
Your data will only be processed if you decide to leave a feedback or get in touch with us. The processing is based on our legitimate interest in addressing users’ inquiries comprehensively and to collect feedback about the app for the improvement, functionality and user-friendliness of the app. In any case you can object to the processing at any time. | Common data - Other Personal |
| Identifiers - Personal Information | ||||
| Provision of the service to patients |
Account creation and management
In order to be able to use our platform, users need to create a profile that reflects their condition. To complete registration, users need to provide their name and email address, country of residence and year of birth and also health related information including their current symptoms, treatments, diagnosis, health insurance and difficulties in managing their health condition. Once an account has been created, users can log in again by providing their e-mail address and the access token they receive per e-mail. Users can also log in via Google/Apple Sign-in. |
|
The provision of your data is necessary in order to access and use our platform. For special categories of data (health information), we rely on your explicit consent to process this data. You can withdraw your consent at any time without affecting the lawfulness of the processing until that point. In that case, however, we will no longer be able to provide you with the app and you will be redirected to delete your account. | Common data - Physical characteristics |
| Common data - Home&Family | ||||
| Common data - Usage data | ||||
| Identifiers - Personal Information | ||||
| Health information | ||||
|
Chat content collection, storage and further elaboration
Through an AI chatbot, patients are guided to share their symptom story, much like a doctor's anamnesis. This conversational interaction allows patients to provide relevant information, including through voice input and document uploads (e.g., doctor's letters). Once the anamnesis is completed, the shared information personalizes the platform's Q&A functionality, enabling patients to ask questions that are informed by their unique health narrative. All answers provided will include sources. Users can also contact us at support@mamahealth.com if they encounter any issues with these functions and we will process their inquiries as soon as possible. |
|
The provision of your data is necessary in order to use the chatbot function of the platform. For special categories of data (health information), we rely on your explicit consent to process this data, you can withdraw your consent at any time without affecting the lawfulness of the processing until that point. In that case, however, we will no longer be able to provide you with the app and you will be redirected to delete your account. | Common data - Other Personal | |
| Identifiers - Personal Information | ||||
| Identifiers - Online | ||||
| Health information | ||||
|
Dashboard creation
Once the anamnesis is complete, the app generates a dashboard. The "analysis" dashboard provides users with an overview of key statistics related to their condition with personalized insights based on the available information. |
|
The provision of your data is necessary in order to use this function and your data is collected and analyzed automatically by us. For special categories of data (health information), we rely on your explicit consent for processing. You can withdraw your consent at any time without affecting the lawfulness of the processing until that point. In that case, however, we will no longer be able to provide you with the app and you will be redirected to delete your account. | Common data - Physical characteristics | |
| Common data - Usage data | ||||
| Identifiers - Personal Information | ||||
| Health information | ||||
|
Detailed report generation
At any point, users can access the "Report" section of the app and download their tailored report generated by AI based on the data provided to the chatbot as well as the information provided during onboarding. Users can update their information with every new entry in the chatbot and download the updated PDF. Users are advised that the Report is generated using AI models that elaborate the information provided and these may contain errors and are only provided for informational purposes. |
|
The provision of your data is necessary in order to use this function and your data is collected and analyzed automatically by us. For special categories of data (health information), we rely on your explicit consent for processing. You can withdraw your consent at any time without affecting the lawfulness of the processing until that point. In that case, however, we will no longer be able to provide you with the app and you will be redirected to delete your account. | Health information |
In the event that we transfer your personal data outside the United Kingdom, we ensure that your data is protected in a manner which is consistent with the UK GDPR. Therefore, and if required by applicable law, appropriate safeguards are implemented, which typically include: relying on an adequacy decision from the UK authorities; using the European Commission’s standard contractual clauses (with required UK addendums); or ensuring the transfer is covered by an approved framework like the EU-US Data Privacy Framework with the UK extension. Technical and organizational measures are also taken where necessary to ensure data remains protected during the transfer.
We inform you that you have the right to:
The exercise of rights is not subject to any formal constraints and is free of charge.
You may exercise your rights by contacting us at the following address privacy@mamahealth.com
You have the right to submit a complaint at any time to the Information Commissioner’s Office (ICO), the UK data protection supervisory authority (www.ico.org.uk).
If you are located in Switzerland, mama health technologies GmbH (controller, we, us), processes your personal data as a Data Controller in accordance with the Swiss Federal Act on Data Protection (FADP).
mama health technologies GmbH
August-Bebel-Straße 88, 14482 Potsdam
As we do not have a physical establishment in Switzerland, we have appointed Data Protection Representative Limited (trading as DataRep) as our Representative in Switzerland in accordance with Art. 14 of the Swiss Federal Act on Data Protection (FADP).
Please note when mailing inquiries, it is essential that you mark your letters for “DataRep” and not “mama health technologies GmbH” for it to reach us.
We may transfer some of your personal data to service providers based in other countries, such as Germany and the USA. We ensure that your data is only disclosed outside of Switzerland if an appropriate level of data protection is guaranteed by one of the following safeguards: a treaty under international law; data protection clauses in an agreement with our contractual partners; specific guarantees drawn up by the competent federal body; standard data protection clauses that the FDPIC has approved, issued or recognized beforehand.
In accordance with the FADP, you have the right to:
You may exercise your rights as set out in the FADP by contacting the Data Controller at: privacy@mamahealth.com
You also have the right to submit a complaint at any time to the Federal Data Protection and Information Commissioner (FDPIC), the Swiss data protection authority (https://www.edoeb.admin.ch).
If you are a U.S. resident and to the extent where we are subject to U.S. state privacy laws in the context of the provision our platform, the following additional data protection safeguards shall apply:
We may process Personal Information concerning the past, present, or future physical or mental health status of Washington State residents (consumer health data), making it subject to the provisions of the Washington My Health My Data Act (hereinafter MHMD Act). The information included in this Notice describes the collection of consumer health data as mandated by the MHMD Act, including the indication of consent as a legal basis, which is equally applicable for purposes of the MHMD Act. In addition to the privacy rights outlined below, Washington state residents may have the following rights:
to confirm whether we are collecting, sharing, or selling consumer health data concerning them and to access such data, including a list of all third parties and affiliates with whom we shared or sold the consumer health data and an active email address or other online mechanism that the consumer may use to contact these third parties.
to withdraw consent from our collection and sharing of consumer health data concerning the consumer.
to have consumer health data concerning them deleted and exercise that right by informing us of their request for deletion.
You may exercise these rights by submitting a request to mama health technologies GmbH at the contact details provided in the Contact Us section of this Notice. We may request additional information from you to authenticate your request.
We will not discriminate against you should you decide to exercise your consumer rights under the Act.
Where applicable, mama health technologies GmbH complies with the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Acts of 2020 (CPRA) (hereinafter CCPA) requirements concerning the exercise of your rights and with other U.S. state laws with similar requirements. We provide the following rights to all residents of the U.S., regardless of where they live:
Right to Opt-Out of Third-Party Sales and Sharing of their personal data
Right to request disclosure of their personal information obtained during the previous 12 months.
Right to request deletion of personal information if it is no longer required to satisfy one of the objectives specified in Cal. Civ. Code Sec. 1798.105
Right to obtain a copy of their personal information and request to transfer certain information to another organization.
Right to request that any incorrect personal information concerning them provided by a company be corrected.
Right to restrict the usage and disclosure of their sensitive personal information to “use that is necessary to execute the services or deliver the products reasonably expected by an ordinary consumer who requests such goods and services.”
Right to obtain “meaningful information about the logic involved” in automated decision-making processes, as well as a description of the process’s expected outcome with respect to the consumer.
Right to Opt-Out of Automated Decision-Making Technology.
You can exercise your rights by submitting a request via email or per post at the contact details provided in the Contact Us section of this Notice.
If you are a resident of Canada, we respect your privacy and ensure your Personal Information is protected in accordance with Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”) and any applicable provincial privacy laws, such as those in Alberta ("Personal Information Protection Act of Alberta", or “PIPA Alberta”), British Columbia ("Personal Information Protection Act of British Columbia" or “PIPA BC”), and Quebec ("Act Respecting the Protection of Personal Information in the Private Sector" or “Quebec Private Sector Act”).
The information provided in this Privacy Notice applies to the processing of personal information of residents of Canada; in addition to that, the following applies:
mama health technologies GmbH with registered address in August-Bebel-Straße 88, 14482 Potsdam is accountable for the Personal Information under our control.
To further strengthen your data protection, we've appointed a dedicated Data Protection Officer (DPO), who you can contact if you have any questions about how your personal data is processed, or if you believe your privacy rights may have been infringed.
You can contact our DPO by sending an email to: dpo@mamahealth.com
We are committed to safeguarding your data, however, providing sensitive data (health related information about you) carries inherent residual risks due to its nature, such as unauthorized access or data breaches, which we mitigate through strict security safeguards.
Please note that, as we are based in the EU we might transfer your personal data outside of Canada for processing, where it may also be accessed by the courts, law enforcement, and national security authorities of that jurisdiction. To ensure that an appropriate level of data protection is guaranteed, and if required by applicable law, we implement appropriate safeguards when transferring personal data.
Under Canadian law, valid consent means you understand the nature, purpose, and consequences of how your data is collected, used, or disclosed.
Where our Processing is based on your consent under the GDPR, this is also considered valid consent under Canadian federal and provincial laws. Where we rely on our legitimate interest or legal requirements under the GDPR, this Notice serves as notice for your deemed or implicit consent under laws like PIPA Alberta and PIPA BC.
The following rights are granted in addition to your rights as a Data Subject under the GDPR. Where you exercise both your GDPR and Canadian data protection rights simultaneously, mama health technologies GmbH will guarantee those rights in addition to each other.
You have the right to challenge the accuracy and completeness of your Personal Information and request access to the data we hold about you.
Accessing Your Data: You may request to know what Personal Information we have, how it is used, and to whom it has been disclosed. We will respond to your written request as quickly as possible and no later than 30 days, providing access at minimal or no cost.
Correcting Your Data: If your information is inaccurate or incomplete, you may request that we amend it. We will update the data and, where appropriate, send the corrected information to any third parties who have access to it.
Withdrawing consent: You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal
How to Exercise These Rights: To submit an access or correction request, please contact us at the address indicated in the "Contact us" section of this Notice.
If you have any concerns regarding how mama health technologies GmbH handles your Personal Information, you have the right to challenge our compliance. We have simple complaint handling procedures in place and will investigate all complaints.
If you are unsatisfied with our internal resolution, you also have the right to escalate your complaint to the relevant regulatory bodies, including the Office of the Privacy Commissioner of Canada (OPC), or the applicable provincial privacy commissioner in Alberta, British Columbia, or Quebec.
If you are located in Japan, mama health technologies GmbH (controller, we, us), processes your personal information in accordance with the Japanese Act on the Protection of Personal Information (Act No. 57 of 2003) ("APPI") and any other applicable laws.
By inputting your personal data, including sensitive information under the APPI, into the app, you agree that we collect your personal data.
We may transfer some of your personal data to service providers based in foreign countries, such as the USA. Where we transfer personal data to service providers located outside Japan, such service providers act solely as our processors (service providers) and process personal data on our behalf and under our instructions, and do not use such personal data for their own purposes.
We ensure that we will make such cross border transfer only if an appropriate level of data protection measures required by the APPI is guaranteed by either the adequacy decision made by the Japanese government or data protection clauses in an agreement with the data recipients that mandate the recipients to continuously implement data protection measures required by the APPI. Information regarding the data protection system of the recipient country and the details of the data protection measures implemented by the recipients will be provided upon request.
To the extent the APPI applies, Anonymous Data shall mean "Anonymized Personal Information," which is defined Article 2 Paragraph 6 of the APPI. We will prepare Anonymous Data and share the same with our business partners, who act as independent business operators, in accordance with the APPI.
We will prepare Anonymous Data in accordance with the requirements under the APPI. Specifically, we will implement the following steps:
Remove descriptions that enable the identification of a specific individual.
Remove personal identification codes
Remove any other information linked to personal information
Remove unique or distinctive descriptions
Take other measures taking into account the nature of the personal information database.
The Anonymous Data we will create and transfer to third parties includes aggregated and anonymized insights derived from patient conversations, such as disease-related topics, treatment experiences, and patient journey patterns.
All data is fully anonymized and aggregated prior to transfer in accordance with the APPI requirements, ensuring that no individual patients can be re-identified with reasonable effort by the receiving party.
We will transfer Anonymous Data to our business partners through secure, access-controlled digital channels, such as encrypted file transfers or restricted-access platforms (e.g., a secure analytics dashboard or cloud-based data environment). Access is granted only to authorized recipients and is subject to contractual data use restrictions.
In accordance with the APPI, you may have the right to:
request disclosure of your personal information (and, where applicable, records of provision of such data to third parties).
have inaccurate or incomplete personal information corrected, added and deleted without undue delay to ensure that data is accurate and as current as possible.
to request that we delete or suspend processing all of your personal information if we process your personal information beyond the scope necessary to achieve the purpose set forth herein or in a manner that may encourage or induce unlawful or improper conduct, or if we obtain your personal information by deception or other wrongful means.
request that we suspend transferring your personal information if we transfer it in a manner violating the measures set forth in the APPI.
request that the use of, deletion of, or provision to third parties of your personal information be suspended where such personal information is no longer necessary for our use, where a data breach or other incident involving the leakage, loss, or damage of your personal information has occurred, or where the handling of your personal information is likely to harm your rights or legitimate interests.
withdraw your consent and opt out from receiving marketing emails.
You may exercise any of the above rights by contacting us at privacy@mamahealth.com. If you contact us to exercise any of the foregoing rights, we may need to ask you for additional information to verify your identity.
If you have questions or concerns about our privacy policies or information practices, please contact us at privacy@mamahealth.com. We may charge a reasonable fee and require a certain period of time to respond to requests, as permitted under the APPI.
Our Service is an AI educational tool for users suffering from specific medical conditions to collect and analyze their information. We process your personal data solely for this purpose.
The Service is not intended to be used for the diagnosis, treatment, prevention, or mitigation of any disease and does not provide medical advice. Also, the Service is not intended to function as a medical device under Japanese law.